When an AI engine answers a recommendation question, which software to buy, which adviser to trust, which provider is best, it is rarely reasoning from first principles. It is leaning on third-party sources that already organise the category: the review platforms, the directories, the aggregators. Those sources are the trust layer. The engine borrows their credibility and passes it to you as an answer.
The uncomfortable part is what sits inside that trust layer. A growing share of it is commercial, consolidated, and in some cases pay-to-play, and the engines treat it as neutral anyway. They do not audit it. Most users never see it. And almost no one is asking who now controls the sources AI relies on to decide who is credible.
The inclusion gate in software
In B2B software the pattern is now well documented. One 2026 analysis found that every tool ChatGPT mentioned in its answers had a profile on Capterra, and almost every one had a profile on G2. Being listed on these platforms functions as a basic inclusion signal: if you are not on them, you tend to be left out of the answer entirely. The review site is not one input among many. It is the gate.
And that gate is concentrating. Through acquisition, G2 has brought Capterra, Software Advice, and GetApp under one roof, and those brands together account for the large majority of citations in the software-review category. Separate analyses of tens of thousands of AI citations put G2 among the most-cited sources of any kind for software queries, listed alongside Wikipedia and Reddit. A single commercial entity has become one of the primary arbiters of which software AI recommends, and it is now selling vendors dashboards to track and improve their standing within it.
The quality signal that does not transfer
Here is the flaw that should give everyone pause. The platforms are treated as a credibility check, but the actual quality signals they hold barely move the answer. The same 2026 research found that review volume does not determine position in AI answers, and average review scores correlate with ranking at close to zero. In one example, a tool with under a hundred reviews on a platform outranked a competitor with several thousand for the same query.
So the engine uses presence on the platform as a legitimacy checkbox, then largely ignores the substance the platform exists to measure. It is borrowing the authority of the review site without using the reviews. The trust signal is hollow: real enough to gate who gets considered, too shallow to reflect who is actually good.
The financial-advice example, and the word "unbiased"
Software is the clearest case because it has been studied most, but the pattern is not confined to it. UK financial advice shows the same shape, in a higher-stakes setting, with a detail that makes the problem almost too on the nose.
Several of the directories that dominate AI answers for finding a financial adviser run on a paid model. One of the most prominent, Unbiased, states plainly that it is a subscription service for advisers and charges advisers a fee based on the value of each enquiry it passes them. The directory is funded by the advisers it lists. And by its own search behaviour, documented in third-party reviews, the default results favour advisers who have paid, with the full list available only if a user scrolls down and unchecks a box.
Read that back slowly. A platform called Unbiased surfaces paying advisers first by default. When an AI engine ingests that page to answer "best wealth management in the UK," it ingests the pay-prioritised view, because that is the default state of the page, and engines take the default. The commercial bias passes through silently and arrives at the user wearing the authority of a neutral directory whose very name asserts neutrality.
To be precise about the mechanism, because precision matters here: there is no evidence that paying these platforms buys an AI recommendation directly. The chain is indirect. Pay the platform, build the profile, the profile becomes the inclusion signal, the engine cites the platform. Indirect does not mean harmless. It means the bias is laundered through a step that looks neutral.
We put this directly to Claude, the AI model, asking whether it would lean on these aggregators when recommending software or a financial adviser, and why. Its answer was revealing. It said it likely would, because these platforms are structurally ideal sources: comprehensive, well-structured, current, and a precise match for a "best X" query in a way an individual brand's own site never is. More tellingly, it described treating a source's wide use and authoritative appearance as a proxy for credibility, and acknowledged that it does not, by default, check who funds that source. That is the whole problem stated by the system itself. The model is not auditing the neutrality of the trust layer. It is reaching for whatever looks authoritative and matches the question, and a paid directory can look exactly as authoritative as an independent one. A model's account of its own behaviour is illustration rather than proof, but here the illustration lines up precisely with what the citation data already shows.
Consumer retail shows the same structure again. Trustpilot, which surfaces consistently in AI answers about retail brands, is a for-profit company funded in large part by subscriptions sold to the very businesses it reviews. Its paid plans include tools that shape how reviews are collected and which are highlighted, such as review-invitation systems and widgets that display selected reviews. None of that is hidden or improper; it is a normal commercial model, openly operated. The point is narrower and the same as before: a platform whose revenue comes from the businesses it rates is not a neutral arbiter in the way the word "reviews" implies, yet AI engines lean on it as though it were. Across software, financial advice, and consumer retail, the recurring shape is a commercially funded source being treated as an objective one.
Why this is a real power question
Put the pieces together and the shape is clear. AI engines have outsourced a large part of their trust layer, the judgement of who is credible in a category, to commercial third parties. Those third parties are consolidating into fewer hands. Some of them are funded by the very organisations they rank. And the engines apply no visible audit to any of it, while treating the output as authoritative.
This is not only an industry observation. It echoes something researchers studying LLM behaviour have started to name directly: that the apparent neutrality of these systems is itself a position, and one that in practice tends to advantage established authority and whatever the existing record already treats as credible. An engine reaching for the most-referenced source is not being objective. It is inheriting and amplifying whoever already holds the authority, including authority that was bought.
The result is a new and largely invisible chokepoint in discovery. For two decades the gatekeeper was the search ranking, and an entire industry grew up to understand and influence it. The emerging gatekeeper is the trust layer AI borrows from, and it is less visible, more concentrated, and in places quietly commercial. The brands that get recommended by AI in these categories are increasingly the brands present, and often paying, in the aggregators the engines have decided to trust.
What to actually do about it
For brands and the people advising them, three things follow, and none of them is comfortable.
First, find out which third-party sources actually decide your category. The sources an engine leans on for "best CRM" are different from the ones it leans on for "best wealth manager," which are different again from consumer categories where Reddit, YouTube, and Wikipedia carry more weight. You cannot influence the trust layer until you know which platforms compose it for your specific queries. This is exactly what an AI visibility audit surfaces: not just whether your own site is optimised, but which gatekeepers now sit between you and the recommendation.
Second, decide, deliberately, whether to play in the commercial layer. Presence on the dominant aggregator may be close to mandatory for inclusion, which is a genuine cost-of-entry decision, not a marketing nicety. But going in with eyes open about what that presence is, and is not, buying matters. It buys consideration. It does not buy quality, and it should not be mistaken for an endorsement the engine has actually evaluated.
Third, push for the thing the system currently lacks: visibility into the trust layer itself. The healthiest version of AI search is one where users and brands can see which sources an answer leaned on and what those sources' incentives are. Until that exists, the burden falls on the brand to understand the gatekeepers, and on the buyer to remember that an AI recommendation is only ever as neutral as the sources underneath it.
AI did not remove the gatekeepers from discovery. It hid them one layer down, inside sources it borrows credibility from and never checks. Knowing who those sources are, and how they are funded, is becoming one of the more important questions a brand can ask about its own visibility.