There is a meeting happening in a lot of companies this week. Someone pulls up a traffic chart, points at a line that did not fall, and says the update missed us. Everyone exhales and goes back to the roadmap. That meeting is being held about nine days too early, and the confidence coming out of it is the most expensive thing in the room.
Google released the September 2026 spam update at 09:15 Pacific on September 24, applied globally and to all languages, and said the rollout may take up to two weeks to complete. Two weeks from the announcement puts the far edge of the window around October 8. As of today that rollout is still open, which means every conclusion drawn from it is provisional, including the comfortable ones.
The part worth paying attention to is not the headline. It is the shape of the impact, because this one did not arrive in a single hit and then settle.
Hold those last two numbers next to each other, because the asymmetry between them governs every sensible decision available right now. Detection reaches you in days. Recovery, by Google's own account, takes months. Any plan that assumes those two clocks run at the same speed is already wrong.
What the September 2026 spam update actually did
The September 2026 spam update enforces Google's existing spam policies rather than introducing new ranking criteria, and the reporting on the sites it moved points consistently at scaled content abuse, templated programmatic page sets and thin affiliate structures.
Google did not specify which policies the update targets, whether a particular classification system was retrained, or why this rollout was given a longer window than previous ones. What exists instead is the observed pattern, and practitioners tracking it closely have been fairly consistent about what they are seeing. In his running notes on the rollout, Glenn Gabe reported big drops across a number of sites, spanning verticals and spanning countries including the United States, the United Kingdom, France, Italy and Germany, and when he dug into those drops he found scaled content abuse, programmatic scaling and thin affiliate situations. Lily Ray noted early signs that the update was hitting sites built on highly templated, probably machine generated page sets.
None of that is a new category of offence. Google has published its spam policies for years. What changed is enforcement intensity against a class of page that got dramatically cheaper to produce, which is a point we have made before about why programmatic page sets carry site level trust risk rather than page level risk.
| WINDOW | WHAT WAS OBSERVED | WHAT IT MEANS FOR YOUR MEASUREMENT |
|---|---|---|
| September 24 | Google announced the release at 09:15 Pacific, global, all languages, rollout up to two weeks | The announcement date is not the impact date. Nothing you measured on day one was the update |
| September 25 to 27 | The first wave showed itself clearly, with heavy drops reported across multiple countries and verticals | A site that fell here has a dated event to anchor its diagnosis against, which is the easier position to be in |
| September 28 to 29 | Movement cooled noticeably and the reporting quieted | This is the trap. A lull inside an open rollout reads exactly like the end of one |
| September 30 | A second distinct change landed, with site owners reporting large drops dated specifically to that day | Confirmation that holding through the first wave was not a verdict. A second pass reached sites the first did not |
| October 1 to 8 | Remainder of the stated two week window, with the update still the open incident on the ranking dashboard | Any conclusion filed before this closes is provisional, including a conclusion of no impact |
Read the fourth row again. A second wave arriving six days after the first, and reaching sites the first wave did not, is the single most useful fact available about this rollout, and it is the one least represented in the advice being published about it.
The two week window is itself the anomaly, and Google's own incident record makes that precise rather than impressionistic. Every other spam update this year was announced with the words that the rollout may take a few days to complete. September is the only one of the four that was announced with up to two weeks, and it is the only one with no completion time recorded against it.
| 2026 SPAM UPDATE | WHAT GOOGLE SAID AT RELEASE | RECORDED DURATION |
|---|---|---|
| March 2026, released March 24 | The rollout may take a few days to complete | 19 hours and 30 minutes. Logged complete on March 25 |
| June 2026, released June 24 | The rollout may take a few days to complete | 2 days and 1 hour. Logged complete on June 26 |
| August 2026, released August 18 | The rollout may take a few days to complete | 2 days and 16 hours. Logged complete on August 21 |
| September 2026, released September 24 | The rollout may take up to two weeks to complete | No end time recorded. Open for more than ten days and counting |
Three rollouts that resolved inside three days, and one that has now been open more than three times as long as the longest of them. Google widened its own estimate by roughly a factor of five for this update before anyone had measured anything, which is the clearest available signal that something about the scope of this one is different. Read the fourth row as an open question rather than a closed one.
Why a phased rollout breaks your measurement baseline
A phased rollout corrupts week over week comparison because the comparison period itself contains part of the treatment, so the baseline you are measuring against has already absorbed some of the change you are trying to detect.
The mechanics are simple and they catch experienced teams. Compare the week of September 28 to the week of September 21 and your prior week already contains the first wave. The delta you compute is the difference between two partially affected periods, which systematically understates the total effect. Compare to early September instead and you get a cleaner read, but you also pick up every unrelated seasonal and competitive change from the intervening weeks. There is no window inside an open rollout that is both clean and current.
The second problem is that detection sensitivity is not uniform across your site. A wave that strips thirty percent of traffic from a programmatic directory holding four percent of sessions moves the sitewide line by just over one percent, which is inside normal noise for most properties. The sitewide line is the worst possible instrument for this, and it is the one in the meeting.
Days between Google's announced spam updates in 2026, indexed to the longest interval at 92 days (derived from Google's own announcement dates: March 24, June 24, August 18, September 24)
That compression matters for planning. The gap between spam updates has fallen from 92 days to 37 across this year, which means the old advice to fix the problem and wait for the next update now describes a shorter wait. It also means evaluation windows increasingly overlap, so a site still carrying unresolved damage from August was being assessed again in late September before it had any chance to demonstrate a change.
“Detection arrives in days and recovery takes months. A team that treats those as the same clock will spend October making changes it cannot possibly measure until the new year.”
The September 2026 spam update is not the only thing that moved
Attribution during this window is genuinely hard because several Google surfaces changed at the same time as the September 2026 spam update, and more than one of them is capable of moving a click number without any change in ranking position.
Google moved AI Mode onto Gemini 3.8 Flash during the same period, and that release initially shipped missing links and citations before the issue was fixed. A version that omits citations and a version that restores them produce materially different referral behaviour from identical rankings. Separately, AI Overviews were observed carrying more external links, and citation cards were being tested at the bottom of the answer rather than at the right hand side. A citation that moves from the side rail to the foot of the answer is the same citation with a different click through rate.
So a referral decline inside this window has at least four plausible causes, and distinguishing them requires looking at something other than sessions. We walked through why a single traffic number cannot separate these effects in our note on how AI driven traffic changes contaminate attribution signals.
| WHAT MOVED | WHAT CHANGED | HOW IT SHOWS UP IN YOUR REPORTING |
|---|---|---|
| The spam update | Enforcement against scaled content abuse, programmatic page sets and thin affiliate structures | Ranking positions fall for a concentrated set of pages. Impressions drop alongside clicks |
| AI Mode on Gemini 3.8 Flash | Shipped initially without links and citations, then fixed | Clicks fall while impressions and positions hold steady, then partially recover with no action from you |
| AI Overviews citation placement | Citation cards tested at the bottom of the answer instead of the right side | Click through rate declines on queries where you are still cited. Position data looks untouched |
| AI Overviews link volume | More external links appearing in answers | Click distribution flattens across more sources. Your share falls even as total citations rise |
Note the second and third rows. Both produce a traffic loss with stable rankings, which is exactly the signature teams are currently misreading as a spam penalty. Remediating content quality in response to a citation layout test is a month of work aimed at nothing.
How to separate a spam hit from everything else
A spam update hit has a distinctive fingerprint: the loss concentrates in a definable page class rather than spreading evenly, impressions fall with clicks rather than clicks falling alone, and the drop dates to a specific day inside the rollout rather than drifting.
Run the test at the level where the damage lives, not at the level where the dashboard defaults. Segment by directory, by template and by how each page set was produced, then look for the pattern.
Those four tests take an afternoon and they are worth doing before the window closes, because the evidence they rest on is cleanest while the daily data is still fresh and the dates are still unambiguous. A properly scoped technical and content audit is the version of this that survives contact with a board meeting, but the afternoon version is enough to stop a bad decision.
What to do while the rollout window is still open
The correct posture before October 8 is evidence collection rather than remediation, because the asymmetry between a two week detection window and a recovery that Google describes in months means a premature fix destroys your ability to attribute the outcome.
That is not a counsel of inaction. There is real work available, and it is the work that holds its value whichever way the rollout lands.
| IF THIS IS YOUR SITUATION | WHAT THE EVIDENCE SUPPORTS | WHAT TO DO BEFORE THE WINDOW CLOSES |
|---|---|---|
| Clear dated drop, concentrated in one page class | A policy hit on an identifiable class of pages | Snapshot the affected URLs and their daily data now, then fix or remove the class. Do not expect fast reversal |
| Traffic down, impressions flat, no concentration | An answer surface presentation change, not a ranking change | Leave the content alone. Instrument citation presence and placement separately from clicks |
| Flat sitewide, untested at segment level | Nothing yet. The sitewide line is too blunt to support a conclusion | Segment by directory and template before claiming you were unaffected. The second wave reached sites the first missed |
| Carrying unresolved damage from the August update | Overlapping evaluation windows with little time to demonstrate change | Prioritise the oldest offending page class. Compressed intervals mean the next assessment arrives sooner than it used to |
| Large generated page set, currently untouched | Exposure without a hit, which is a timing outcome rather than an endorsement | Treat it as borrowed time. Audit the set against the published spam policies on your own schedule |
The last row is the one worth sitting with. A generated page set that has not been hit by four spam updates in a year has not been approved, it has been missed, and the interval between chances to catch it has shrunk from 92 days to 37. We argued the economics of that bet when content saturation started undercutting the returns on scaled production.
One more piece of housekeeping, and it is the cheapest insurance available. Separate your reporting into ranking presence, answer surface presence and referral clicks as three distinct lines before the next update rather than during it. A single sessions number cannot distinguish a ranking loss from a citation layout test, and those call for opposite responses. Building that separation into standing reporting and analytics is a one time cost that pays out at every future update.
Questions teams are asking about the September 2026 spam update
See where you are cited today
A free snapshot audit of your rankings and AI citations before we ever talk.
Tyler leads work at the intersection of SEO and generative engines at Something Inc., helping B2B brands get ranked and cited across every major AI engine.