Google started its September 2026 spam update at 09:15 Pacific on 24 September. As of today it is still running, and that duration is the story.
The three spam updates before it this year finished fast: March in 19 hours 30 minutes, June in 2 days 1 hour, August in 2 days 16 hours. This one shipped with a stated window of "up to two weeks", and when Barry Schwartz asked whether that was a typo, John Mueller replied that it was "likely to take longer than some of the previous ones". Google's Search Status Dashboard still shows no completion entry.
If you run programmatic or AI-assisted pages at scale for clients, this is the update that matters most to you, and the correct response this week is probably not the one your gut is suggesting.
Why the previous one should have your attention
The August 2026 spam update ran for barely more than two days and did real damage. SE Ranking's analysis, shared with Search Engine Land, found that 16.71% of URLs sitting in the top 10 fell beyond position 100 for the same keyword, against 9.2% in a comparable period in July. A top 10 URL was roughly 1.8 times more likely to vanish from the top 100 than during normal churn. Top 10 volatility ran between 74.64% (real estate) and 85.55% (fashion and beauty), so no vertical was spared.
Worth being precise about what SE Ranking did and did not establish: they ran no URL-level or domain-level analysis of which pages lost rankings. The volatility figure is solid; the attribution to any particular tactic is not.
For that, Glenn Gabe's case studies from the August update are more useful, and more uncomfortable. One site in a YMYL niche lost rankings for over 200,000 queries, with the drops concentrated in heavily scaled programmatic content replicated across countries.
The policy being enforced is scaled content abuse, and Google's spam policies define it by purpose rather than production method: generating many pages primarily to manipulate rankings rather than help users. Whether a human, a template or a model produced the text is explicitly not the test. This cuts both ways, and the second direction gets ignored: automation is not itself a violation, and manual authorship is not itself a defence. A hand-written city page with the noun swapped is the same thing Google is demoting.
One change from earlier this year sharpens it further. On 15 May 2026 Google rewrote the opening line of its spam policies to cover "attempting to manipulate generative AI responses in Google Search". Tactics aimed at winning an AI Overviews or AI Mode citation now sit inside the same enforcement framework as link spam. If you have been building pages specifically to get quoted in an AI answer, that is the mechanism that acts on it.
SAFE, and the part the coverage is overselling
In the same stretch, Google Research published a paper titled "The Synthetic Gap: Automating Forensic Investigation of 'AI Slop' with the Scaled Abuse Forensics Examiner (SAFE)", covered by Search Engine Journal. SAFE is described as a multi-agent system that investigates coordinated synthetic content the way a human forensic team would: analysing content, account behaviour, infrastructure and the relationships between producers, rather than scoring pages one at a time.
The timing invited an obvious conclusion, and plenty of posts last week drew it. Two caveats are doing heavy lifting:
- Google has not confirmed that SAFE has anything to do with the September spam update.
- The paper is three pages long, withholds most results, and its described focus is synthetic media and coordinated channel abuse, not web page ranking.
So treat SAFE as a directional signal about where anti-abuse work is heading, not as an explanation of your rankings. The directional signal is still worth having: detection is moving from "does this page look generated" toward "does this network of pages behave like a coordinated operation". Page-level polish does not answer a network-level question. A thousand pages that each look fine individually, share one template, one publishing cadence and one thin value proposition, are a pattern.
What to actually do during a two-week rollout
The honest answer is that the most valuable action is restraint, paired with preparation.
Do not diagnose mid-rollout. Rankings move throughout a rollout and where a page sits on day three is not where it settles. A two-week window also overlaps with everything else changing in that period, so causation is close to unrecoverable. Google's standing advice after core updates is to wait at least a full week after completion before analysing Search Console, and the same logic applies here.
Do not make reactive changes you cannot attribute. Anything you alter now lands inside the noise. If you strip 400 pages this week and traffic recovers in three weeks, you will not know which did it.
Do baseline now, because the window is closing. Export Search Console performance data covering the weeks before 24 September, at page level, before the 16-month window eats it. Capture your indexed count and top pages by impressions too. Cheapest thing on the list, and the one people skip.
Do run a per-URL value audit, on paper. For each templated page, answer one question: what does this page contain that a user could not get from the template plus a database row? Original data, real pricing, genuine local specifics, actual inventory, expert commentary. If the honest answer is nothing, that page is scaled content regardless of how well written it is. Sort by that answer, not by traffic.
Do prefer consolidation to proliferation. Authority concentrated on one complete page tends to outperform the same signals split across five partial ones, and AI answer engines pick the source that answers fully over the fragment. Merging overlapping pages and redirecting is unglamorous and it is usually the highest-return move available.
Then wait for the dashboard to post completion, wait another week, and read the data.
Where this leaves scaled publishing
Scaled publishing is not dead and Google has never said it is. What has changed is that the margin for thin output has gone, and the enforcement is getting better at spotting patterns rather than pages. The teams that will come through the next four spam updates are the ones that decided, before publishing, that each page cleared a bar.
That pre-publish gate is the whole design idea behind TrafficForge. QualityForge Lite scores every page against 16 criteria (heading hierarchy, structured data, internal linking, word count, keyword density, FAQ coverage and the rest) and a page that fails does not get deployed. We are not going to claim a score makes anything spam-proof, because no tool can see whether your page offers something the template did not, and that judgement stays yours. What a gate does is stop the failure mode that produced most of the August casualties: nobody checked, at scale, and the checking happened afterwards in Search Console.
Get the per-page bar right and volume stops being the liability. Get it wrong and volume is the multiplier working against you.
FAQ
When will the September 2026 spam update finish?
Google's stated window is up to two weeks from 24 September, which points to roughly 8 October. John Mueller indicated it would likely run longer than recent updates. The only confirmation that counts is a completion entry on the Search Status Dashboard, so watch that rather than third-party trackers.
Does the September spam update target AI-generated content?
Google has not confirmed a specific target for this rollout. The relevant policy, scaled content abuse, is defined by purpose rather than production method: many pages made primarily to manipulate rankings instead of helping users. AI-written content that provides genuine value is not a violation, and human-written thin pages are not exempt.
Should I delete my programmatic pages now?
Not as a reflex, and not mid-rollout. Audit them against the question of what each page offers beyond a template and a data row, then consolidate or improve the ones that fail. Bulk deletion during an active rollout destroys your ability to attribute any recovery, and removing pages that were genuinely useful costs you traffic you did not need to lose.
Is Google's SAFE system what caused my rankings to drop?
There is no basis for that claim. Google published the SAFE research paper but has not connected it to the September spam update, and the paper's described scope is coordinated synthetic media rather than web page ranking. Treat it as an indication of where detection is heading, not as a diagnosis.
My traffic fell after 24 September. How do I know it was the spam update?
You largely cannot, yet. Check whether competitors in your set moved at the same time, whether the drop is concentrated in one template or spread evenly, and whether your visibility changed on non-Google surfaces too. Rule out technical causes (crawl blocks, server errors, accidental noindex) before assuming an algorithmic one, because those are more common and faster to fix.