If you publish content online, this week brought a change you cannot afford to miss. Google activated a new spam detection system built entirely on artificial intelligence. It is called SAFE, short for Scaled Abuse Forensics Examiner. This is not a lab experiment or a conference deck. It is already live and most likely part of the September 2026 Spam Update currently rolling out.
A recent article on Search Engine Journal analyzed the research paper Google published. What it describes is fundamentally different from any anti-spam system we have seen before. SAFE is not a better filter. It is an autonomous investigator that works around the clock.
The context makes this launch even more significant. The volume of AI-generated content has grown exponentially over the past two years, and Google has faced public criticism for search quality declining under that wave. SAFE is the technical answer to a problem that grew too large for human quality rater teams.
Four AI agents working as an investigation team
Previous spam detection systems relied on rules and pattern matching. If a site checks X suspicious criteria, it gets flagged. SAFE works differently. It uses four specialized AI agents that collaborate on each case.
The Root Agent is the orchestrator. It coordinates the investigation, distributes tasks, and synthesizes findings from the other three. The Content Understanding Agent analyzes the content itself, using LLM-based models to detect artifacts of automated generation and suspicious semantic patterns. The Behavior Understanding Agent identifies coordinated activity patterns: unnatural publishing timing, shared infrastructure across sites, suspicious volumes. The fourth, the Channel Cluster Understanding Agent, maps entire spam distribution networks using graph-based analysis.
Why does this combination matter? A single AI-generated article can pass a content filter on its own if it is prompted well enough. But when an agent correlates publishing behavior with linguistic analysis and network mapping, the equation shifts entirely. SAFE does not evaluate isolated pages. It evaluates operations.
Google also introduces a concept worth paying attention to: detecting violations of the spirit of its policies. SAFE does not only flag explicit rule violations like copied content, cloaking, or link schemes. It also catches content that technically follows the rules but violates their intent. The classic example: a site publishing 200 supposedly original articles per day, all auto-generated with minimal variation, does not break any specific rule. But it breaks the spirit of the rule that says content should be useful to users. SAFE recognizes that difference.
Three pages of research. And a strategic silence.
The research paper Google published is only 3 pages long. A standard academic paper on spam detection would run 15 to 25 pages with detailed methodology, datasets, performance metrics, and comparisons to existing systems. Google did not omit those details due to space constraints. It omitted them deliberately.
The logic is straightforward: the more you know about how a detector works, the easier it is to evade. This intentional opacity means two concrete things for anyone working in SEO or content marketing:
You cannot optimize your way past SAFE. There is no checklist of criteria to satisfy. Unlike AI agents that game SEO metrics by exploiting public and predictable rules, here the rules are hidden by design.
The only viable strategy is genuine quality. If you do not know exactly what SAFE looks for, you cannot build content to dodge it. You can only build content that has no reason to dodge anything.
Alongside SAFE, Google deployed S-CTS (Scalable Cluster Termination System), a companion system that identifies and shuts down entire spam site networks simultaneously. SAFE detects. S-CTS executes. Combined, they do not penalize individual pages. They dismantle infrastructure.
The shift from rule-based filters to an AI investigator reflects a broader trend. Google Search moved from simple matching to AI Overviews. Google Ads went from manual bidding to Smart Bidding. Now anti-spam makes the same transition. The common thread is reduced predictability: you can no longer reverse-engineer a system that learns and adapts continuously.
What to do if you use AI for content
Let us be direct: this is not about abandoning AI. It is about how you use it and why. We recently wrote about how creators who adopted AI now produce content that looks identical. SAFE now puts a real cost on that uniformity.
If your content strategy boils down to generating 20 articles per week with ChatGPT and publishing them on your site, you have a problem that just got worse. Not because AI writes poorly. But because Google can now systematically detect content that is grammatically correct yet lacks original perspective.
What works in practice:
AI as a tool, not the final author. At difrnt., we use AI for research, for structuring ideas, for early drafts. The perspective, the data from real projects, the local market context, and the argued opinions come from the team. The result is content that SAFE has no reason to flag. Not because it is optimized for the detector, but because it is not spam.
Authenticity signals. An article with real human input has characteristics that pure automation misses: references to specific experiences, opinions grounded in data from actual projects, contextualization for a local market. These signals are exactly what separates content that stays visible from content that gets filtered.
Controlled volume, not maximum volume. Three articles per week with real perspective are more valuable than 15 generic ones. This was true before SAFE. The difference is that Google now has a dedicated system enforcing this principle at industrial scale.
We do not yet know how aggressive SAFE will be or how many sites will be directly affected by the September 2026 Spam Update. But the direction is clear: Google is actively investing in the ability to distinguish authentic content from mechanically generated material. According to the paper, SAFE significantly accelerates the identification of novel synthetic threats compared to previous manual workflows. If your content strategy withstands that test, you are well positioned. If not, now is the time to adjust, not after you see the notification in Search Console.




