IT and Cyber AEO REPORT

What's Driving AI Recommendations for IT Buyers in 2026

An evidence-based IT Sector AEO benchmark from 25,862 citations across 6 AI models and 1,000 buyer prompts.

Published: 16th June 2026

Executive Summary

AI answers are vendor-dominated.

Across six major AI models, vendor and provider websites account for 73.1% of all citations. Independent third-party sources, analysts, media, review aggregators, and comparison sites make up the remaining 26.9%. The “neutral expert” voice is a minority share of every answer.

Each model has a different appetite for vendor content.

Vendor share runs from 67.5% on Perplexity to 87.2% on Grok. Optimising for “AI search” as a single channel is a category error; these are five different distribution channels with five different rules.

The cited internet is small.

Just 14 domains are cited by all six models. The top 10 domains alone account for 12–28% of all citations, depending on the model. Earning a place on this short list is the highest-leverage AEO move available.

Specificity rewrites the answer.

Long-tail prompts push vendor share 6.9 percentage points higher and cut comparison/listicle citations roughly in half versus short-tail prompts. The longer the buyer’s question, the better a vendor’s own pages perform.

Cross-model consensus is rare.

Only 155 of 1,000 prompts see ≥4 of 5 main models naming the same top vendor. Cybersecurity has the strongest consensus (48 prompts); IT Distributors the weakest (17).

Models behave very differently when prompts get specific.

ChatGPT, Google AI Overview, and Perplexity reshuffle their source mix substantially. Gemini and Grok are roughly half as responsive. The same content strategy will not perform equally across models.

Long-tail prompts trigger ~3× more government and regulatory citations.

Official sources jump from 0.9% to 2.4% as questions get specific. For regulated categories, alignment with named frameworks is increasingly load-bearing.

Introduction

Answer Engine Optimisation (AEO) is the practice of optimising your earned and owned content to increase the percentage of times AI tools like ChatGPT, Claude, and Gemini recommend your business.

These models do not return ten blue links like their predecessor. They return one synthesised answer.

For B2B IT buyers, this is the new way to discover, research, and compare potential solutions.

The real question is what is driving these recommendations? Which sources do these models trust? Does it change when buyers ask vague questions versus specific ones? What can businesses do to increase their recommendations?

This report answers those questions with data from 25,862 citations across 1,000 commercial-intent prompts that mirror how real IT buyers research vendors.

Methodology

Dataset. 25,862 unique citations from 1,000 commercial-intent prompts about IT buying decisions, collected on 24 April 2026 via Spotlight (app.get-spotlight.com) across six AI models: ChatGPT, Gemini, Perplexity, Google AI Overview, Grok, and Google’s AI Mode.

Coverage. Five industries (B2B SaaS, Cybersecurity, IT Distributors, IT Services, IT Vendors), three buyer sizes (SME, Mid-Market, Enterprise), and two prompt styles (short-tail and long-tail). 1,000 prompts split evenly between UK and Ireland buyer framing.

Classification. Domains were classified into 12 source types using a curated lookup of ~280 common domains plus pattern rules. Citations were de-duplicated within each prompt × model × domain combination.

Limitations

Regional scope. Citations were collected for prompts framed in UK and Irish buyer language (500 prompts per market). AI models surface different domains for the same question in different countries, weighting regional sites, regulatory frameworks, and currency cues. The structural patterns reported here are likely portable to other English-speaking markets; the specific domains that win citations will differ.

Snapshot timing. Data was collected on 24 April 2026. AI models change behaviour continuously, index updates, ranking changes, and model upgrades all move citations. High-level patterns (vendor dominance, model-by-model differences, the long-tail effect) should be stable over months. Specific domain rankings will drift faster. Quarterly replication is recommended.

Prompt set. 1,000 prompts were selected by the analyst to mirror real B2B IT buyer language. The choice of 1,000 is a deliberate balance: large enough to surface stable patterns at the level of model, industry, and prompt length (200 per industry); small enough to keep collection and classification rigorous within a single cycle. A larger set would tighten confidence in the long tail of cited domains but would not change the headline findings.

Industry scope. Five IT sub-categories: B2B SaaS, Cybersecurity, IT Distributors, IT Services, IT Vendors were chosen for meaningful within-sector comparison while keeping per-industry sample size high. Extending the framework to other IT subsectors is the obvious next step.

 

Model coverage. Spotlight surfaces citations across the six LLMs listed above. Claude, DeepSeek, and Manus were outside the tool’s coverage at time of analysis. The vendor-dominance pattern likely holds across them; model-specific findings cannot be extrapolated.

Reproducibility Cues

The findings in this report are falsifiable. The following supporting materials are available on request:

Full prompt list

All 1,000 prompts, organised by industry, buyer size, and prompt-length category.

Source-type classification rules.

The full domain lookup (~280 entries) and pattern rules used to classify citations into 12 source types, including the explicit decision to default unrecognised domains to Vendor/Provider.

Aggregate results (CSV).

All 21 analyses as aggregated tables: per-model citation counts, source-type distributions, concentration metrics, the universal-domain set. Raw per-citation data is not released; aggregates are sufficient to verify every numerical claim.

Collection metadata.

25,862 unique citations after de-duplication within prompt × model × domain. Collected 24 April 2026 via Spotlight. Markets: UK and Ireland (500 prompts each).

 

Materials are released under a permissive citation licence; attribution to this report is the only condition. Requests: Adam G, [email protected]

Key Findings

Finding 1: Vendor-owned pages are the dominant citation source, by a wide margin

The data. 73.1% of all citations point to vendor or provider websites. Comparison and listicle pages account for 8.9%. Media and publisher sites 6.1%. Review aggregators 5.6%. Analyst firms 2.0%.

What’s happening. AI models lean heavily on first-party content because that is where the substantive product information lives. Feature pages, pricing, integrations, security posture, customer logos, and case studies. The “Wikipedia-style” mental model of AI citations, where models prefer neutral encyclopaedic sources, is not what these models do for commercial-intent IT queries. This is likely due to the lack of neutral sources for this niche.

What this means. Your own website is your primary AEO surface. If your product, comparison, integration, and use-case pages are thin, generic, or buried behind sales gates, you are invisible to the 73% of citations that go to vendor sites. The first AEO investment is making your owned content answer the buyer’s questions, a model that would otherwise answer for someone else.

Finding 2: Each model has a different content diet; treat them as separate channels

The data. Vendor citation share runs from 67.5% on Perplexity up to 87.2% on Grok. Comparison and listicle reliance range from 0.6% on Grok to 15.9% on Perplexity for short-tail queries.

What’s happening? Perplexity acts most like a researcher; it samples broadly across third-party sources, especially comparison content. Grok and Gemini behave more like product encyclopaedias; they go deep on vendor sites and rarely venture into independent commentary. ChatGPT and Google AI Overview sit in the middle, with the most balanced source mixes.

What this means. Stop treating AEO as one channel. Content optimised to win Perplexity citations (heavily linked from comparison pages, mentioned in listicles) will not necessarily win Grok citations (which prefer canonical vendor pages). Map content investments to the models your buyers actually use.

Finding 3: Only 14 domains achieve universal coverage, and they share recognisable traits

The data. Of more than 6,000 unique cited domains, only 14 were cited by all six models: clutch.co, cloudtango.net, google.com, capterra.co.uk, service.gov.uk, goodfirms.co, ey.com, proofpoint.com, gov.uk, checkpoint.com, accenture.com, enterprise-ireland.com, grantthornton.ie, and ionos.co.uk.

What’s happening. The list is dominated by three archetypes: structured directories with clean per-vendor pages (Clutch, Capterra, GoodFirms, Cloudtango), large established vendors with deep technical content (Proofpoint, Check Point, Accenture, IONOS), and high-trust government or “Big Four” institutional domains (gov.uk, EY, Grant Thornton, Enterprise Ireland). These are the domain types models default to when uncertainty is high.

What this means. Two priorities. First, claim and optimise your profiles on the structured directories; they are the cheapest universal citations available, and they multiply across every model. Second, build genuine institutional partnerships; industry bodies, government innovation programmes, and recognised analyst inclusion to earn the kind of high-trust signals that produce cross-model rather than single-model citations.

Finding 4: Specificity changes which sources get cited

The data. Comparing long-tail prompts to short-tail prompts:

Source Type

Vendor/Provider

Comparison/Listicle

Review Aggregator

Official/Regulatory

Long-tail

80.4%

4.4%

3.2%

2.4%

Short-tail

73.5%

9.0%

5.6%

0.9%

Direction

+6.9pp

-4.6pp

-2.4pp

+1.5pp

What’s happening. When a buyer asks “best CRM,” models hedge; they cite roundups and review aggregators because no single vendor is the answer. When a buyer asks, “best CRM in the UK for a 200-person mid-market manufacturer with HubSpot integration,” models commit. They go to vendor pages that match the constraints and reach for regulatory sources to validate eligibility. Long-tail queries are where vendors win or lose individually; short-tail queries are won by whoever owns the listicle.

What this means. Your highest-intent traffic is on the long tail, and your owned content is what wins it. Build pages that mirror the specificity of real buyer queries, by size, geography, integration, and use case. A single “Solutions for Manufacturing” page will not capture “ERP for a 750-person mid-market UK manufacturer with SAP integration.” Specific case studies, sub-industry pages, and FAQs.

Finding 5: Cross-model consensus is rare, and concentrated in regulated categories

The data. Of 1,000 prompts, only 155 reach a decisive consensus (≥4 of 5 main models naming the same top vendor). By industry: Cybersecurity 48, IT Services 33, B2B SaaS 31, IT Vendors 26, IT Distributors 17.

What’s happening? Cybersecurity has clearer category leaders, well-defined vendor categories, and stronger reliance on regulatory and analyst signals, which converges the answers. IT Distributors is the most fragmented because the category is regional, relationship-driven, and weakly represented in third-party content.

What this means. Where consensus exists, it is defensible and worth fighting for. Identify prompts where multiple models already agree on a leader, and either work to be that leader or disrupt the consensus with comparison content. Where consensus is weak, the prize is different: be the first vendor to build the structured, comparison-friendly content that establishes consensus on your terms.

Finding 6: Top-10 concentration ranges from 12% to 28%, and predicts your odds of being cited

The data. Top-10 domains as a share of all citations: Google AI Overview 12.1%, ChatGPT 12.6%, Perplexity 14.4%, Gemini 18.5%, Grok 27.6%.

What’s happening. Concentration measures how much a model relies on a small pool of trusted sources. Grok cites the same handful of vendor and analyst domains repeatedly. Google AI Overview pulls from a much wider set.

What this means. If your buyers use Grok, getting onto the top-10 list for your category is roughly 2× as valuable as getting onto Google AI Overview’s top 10 because Grok concentrates citations there. If your buyers use Google AI Overview or ChatGPT, breadth-of-mention matters more than top-of-list dominance. Your AEO targets should be model-specific, not generic.

Finding 7: Long-tail prompts triple government and regulatory citations

The data. Official and regulatory domains rise from 0.9% of short-tail citations to 2.4% of long-tail citations, a 2.7× increase. The pattern is strongest in cybersecurity and B2B SaaS.

What’s happening. When buyers add specifics like “GDPR-compliant,” “FCA-regulated,” “ISO 27001,” or “Cyber Essentials,” models reach for the underlying authority ie gov.uk, NCSC, regulator domains. These are not citations you can buy; they are citations earned by content that maps directly onto named frameworks.

What this means. Compliance content is no longer a footer page. For regulated buyer questions, model citation depends on whether your content is anchored to the same vocabulary the regulator uses. Name the framework. Quote the standard. Link to the source.

Strategic Implications

Content structure: the fact-block is the unit of work.

AI-citable content is not a long-form blog post. It is the fact-block. A self-contained, scannable unit that answers one specific buyer question with one specific answer, supported by structured data. Every product, integration, and use-case page should contain at least one per likely buyer question: a clear question heading, a direct answer in the first sentence, supporting specifics (numbers, names, frameworks, integrations), and structured markup.

Citation optimisation: own the vendor surface first.

With 73% of citations vendor-owned, the priority order is clear. (1) Owned content: product pages with unambiguous positioning, comparison pages naming competitors directly, integration pages per major partner, and customer pages with named logos. (2) Structured directories: Clutch, Capterra, G2, GoodFirms, Cloudtango. (3) Third-party comparison and listicle placement, weighted toward the models your buyers use. (4) Analyst and institutional signal: small share, disproportionately influential in regulated categories.

Authority: institutional signals matter more than backlinks.

The universal citation list is dominated by domains with institutional weight, not backlink count. Traditional SEO authority signals (DA, link velocity) are necessary but not sufficient for AEO. Analyst inclusion, government programme participation, regulator recognition, and audit firm citation earn cross-model visibility that backlinks alone cannot.

Distribution: optimise for the prompt, not the keyword.

Long-tail prompts have specific structures: role + size + geography + constraint. “CRM for UK Mid-Market” is generic. “CRM for 200–500 Employee UK Mid-Market Companies with HubSpot Integration” is specific in exactly the way buyers and models converge on. The keyword era optimised for what people typed; the AEO era optimises for what people ask.

Industry Breakdowns

The aggregate patterns in this report describe the IT industry as a whole. Each sub-category behaves differently within that frame. The five pages that follow break the data down by industry: top cited domains, source-type mix, cross-model consensus, and what the patterns mean for vendors operating in that segment.

A note on reading these: the “vs benchmark” column in each source-type table compares the industry to the cross-industry average. Positive numbers mean the industry over-indexes on that source type relative to other industries; negative numbers mean it under-indexes.

Cybersecurity

The most analyst-influenced and most regulated of the five industries. Top-domain rankings skew toward specialist security publishers and named pen-test/audit firms rather than household-name vendors. This is a sign that AI models recognise category specificity in this segment.

Top 10 cited domains

Top 10 cited domains in the Visibility Wins industry analysis:

Source-type mix

ource type mix table for the Visibility Wins industry analysis, comparing this industry against the benchmark average by source category.

Cross-model consensus. 48 of 200 prompts reached decisive consensus (≥4 of 5 models naming the same top vendor) the highest of any industry, and 2.8× the consensus rate in IT Distributors.

What this means for cybersecurity vendors. First, regulatory and analyst content is unusually load-bearing here. Cybersecurity is the only industry where Official/Regulatory citations exceed 2%, and Analyst citations approach 3%. Content that anchors to NCSC, ISO 27001, NIS2, and named analyst frameworks earns citations the rest of the IT industry can’t access. Second, the top-domain pattern shows AI models will cite small specialist firms that own a niche (deepstrike.io, vistainfosec.com, qualysec.com) over household-name security vendors. Category specificity beats brand size. If you compete in a defined sub-niche, claim it explicitly in your positioning rather than diluting into generic “cybersecurity solutions” language

IT Services

The most third-party-driven of all five industries, the lowest vendor share (65%) and highest comparison/listicle share (15.6%). Clutch.co dominates citations more decisively here than any single domain dominates any other industry.

Top 10 cited domains

Top 10 cited domains in the Visibility Wins IT services industry analysis, ranked by citation count and percentage of industry citations.

Source-type mix

Source type mix in the Visibility Wins IT services industry analysis, comparing this industry with the benchmark average by source category.

Cross-model consensus. 33 of 200 prompts reached a decisive consensus, second-highest of the five industries.

What this means for IT services firms. This is a Clutch-and-Cloudtango game. Together, those two directories account for 10.7% of all IT Services citations, nearly 1 in 9. Any IT services firm without complete, current, well-reviewed profiles on those two platforms is invisible to a meaningful share of AI-driven buyer research. Beyond directory presence, the high comparison/listicle share (15.6%, almost double the average) means third-party “best IT services firms in [region]” content is a primary distribution channel, and placement should be pursued actively. The lower vendor share (65%) tells you that your own website alone won’t carry you here; third-party validation is structurally more important in IT services than in any other IT sub-category.

IT Vendors

The most diversified citation pattern of the five industries. Top-10 share is just 10.9%, meaning citations spread across a wider domain pool than anywhere else. Consumer-tech publishers and community sites (PCMag, Reddit, YouTube, LinkedIn) appear in the top 10, alongside the usual analyst and directory mix.

Top 10 cited domains

Top 10 cited domains in the Visibility Wins IT vendor industry analysis, ranked by citation count and percentage of industry citations.

Source-type mix

Source type mix in the Visibility Wins IT vendor industry analysis, comparing this industry with the benchmark average by source category.

Cross-model consensus. 26 of 200 prompts reached a decisive consensus moderate.

What this means for IT vendors. This is the broadest, most diffuse citation environment in the IT industry. The implication cuts both ways: harder to dominate, easier to enter. With top-10 share at just 10.9%, no small handful of domains gates the answer, meaning brand-name authority alone won’t carry you, but conversely, vendors without entrenched analyst relationships have a real path in via consumer-tech publishers, community signal (Reddit, YouTube reviews), and structured-data presence on G2 and similar. The appearance of YouTube and LinkedIn in the top 10 is distinctive: video reviews and executive thought leadership generate more citation weight in IT Vendors than in any other industry. Investment in those formats has a clearer return here than elsewhere.

B2B SaaS

The most review-aggregator-driven industry. Capterra appears at #1 and #2 (UK and Ireland variants), and review platforms collectively account for 9.1% of all citations. Vendor share is high (76.9%), but the third-party share that exists is concentrated in structured directories rather than editorial comparison content.

Top 10 cited domains

Top 10 cited domains in the Visibility Wins B2B SaaS industry analysis, ranked by citation count and percentage of industry citations.

Source-type mix

Source type mix in the Visibility Wins B2B SaaS industry analysis, comparing this industry with the benchmark average by source category.

Cross-model consensus. 31 of 200 prompts reached a decisive consensus moderate.

What this means for B2B SaaS. Review aggregators are the single most important third-party surface in B2B SaaS, and Capterra (in both regional variants) is the most cited domain. Review velocity, recency, and quality on Capterra, G2, SoftwareAdvice, and SoftwareSuggest is more important here than in any other IT sub-category. Conversely, regulatory and analyst content under-indexes, readers are buying off ratings and feature comparisons, not compliance frameworks. The appearance of slashdot.org and toptenaiagents.co.uk in the top 10 reveals an underappreciated channel: niche listicle and aggregator sites for specific software categories punch above their weight. Identify the 2–3 listicle sites that own your category and pursue placement directly.

IT Distributors

The most fragmented and most trade-press-influenced of the five industries. Cross-model consensus is the lowest (17 prompts), media/publisher share is the highest (11.6%), and the top citations are channel-specific trade publications (IT Channel Oxygen, ChannelWeb).

Top 10 cited domains

Top 10 cited domains in the Visibility Wins IT distribution industry analysis, ranked by citation count and percentage of industry citations.

Source-type mix

Source type mix in the Visibility Wins IT distribution industry analysis, comparing this industry with the benchmark average by source category.

Cross-model consensus. 17 of 200 prompts reached a decisive consensus, the lowest of any industry. The category is genuinely fragmented in how AI models answer.

What this means for IT distributors. The trade press carries unusual weight in this category. IT Channel Oxygen and ChannelWeb together account for 6.2% of all IT Distributors citations. Earned media in those publications is structurally higher-value here than in any other IT sub-category. Review aggregators, by contrast, under-index dramatically (1.6% vs 5.6% average). Buyers and models don’t research distributors through review platforms. The low consensus rate is the strategic story: with only 17 of 200 prompts reaching decisive consensus, this is the category where building the cited-domain consensus is most achievable, because there isn’t an entrenched one to displace. First-mover advantage on structured comparison content for IT Distributors is meaningfully larger than in any other sub-category in this report.

AEO Optimisation Checklist

A 14-point framework drawn directly from the patterns in this report.

Owned content fundamentals

Every product page answers “what is this and who is it for” in the first 100 words.

Every product page list named integrations, named compliance frameworks, and named customer logos.

Comparison pages exist for every major competitor: naming them directly, with structured comparison tables.

Use-case and industry pages exist at the specificity level real buyers ask at (size + geography + constraint).

Structured data

FAQ schema on every page that answers buyer questions.

Product or SoftwareApplication schema on every product page.

Organization schema with sameAs links to G2, Capterra, Clutch, Crunchbase, LinkedIn.

Universal-domain presence

Claimed and fully completed profiles on Clutch, Capterra, G2, GoodFirms, TrustRadius.

Active customer reviews on at least two review aggregators in the last 90 days.

Inclusion in at least three high-authority third-party comparison or listicle pages.

Regulatory and institutional signal

Compliance content names the framework, quotes the standard, and links to the source regulator.

At least one institutional citation (analyst, industry body, government programme) per major product line.

Model-specific optimisation

Identified the two AI models your buyers use most, and audited content against each model's source-mix preferences.

Tracked AI citations as a metric

Conclusion

AI answer engines have already changed how B2B IT buyers research. Some categories have crystallised around stable consensus. Others have not.

AEO is not SEO with new acronyms. The cited surface is structured differently, the trust signals are weighted differently, and the rules vary by model in ways traditional search did not.

The opportunity for early adopters is the same that existed in early SEO: cost of action is low, the signal is still legible, and the competitive set has not yet caught up. Vendor-owned content remains the highest-leverage surface. Structured directories remain underclaimed. Compliance content remains thin. Specific, long-tail buyer pages remain rare. Each of those gaps is an AEO win available to organisations that act now.

The 73% vendor citation share is not a reason to wait for models to “favour neutral sources.” It is a window. The question is not whether AEO matters. It is whether your content is shaped to be cited.

Author: Adam Grant

Growth Manager, Visibility Wins

Adam Grant leads the Answer Engine Optimisation (AEO) team at Visibility Wins. Adam specialises in helping B2B IT companies become discoverable across Google and LLMs. His work focuses on building the content and authority signals that get brands recommended as trusted answers. 

Be Found. Be Trusted. Be Chosen.