Imagine you're a bouncer at a nightclub, but instead of checking IDs, you just wave in anyone wearing a specific brand of sneakers. It doesn't matter who's inside the shoes — the brand is the credential. That's how AI-search citation selection works right now: platforms trust domains, not content. This paper maps exactly how thin that trust layer is, and how cheaply it can be gamed. The committed claim: AI-search platforms have a measurable, exploitable preference for specific source domains, and ordinary users can plant fabricated content on those domains that gets cited in AI-generated answers within hours. The authors tested this across 10 platforms — including major commercial AI-search systems — analyzing 17,211 citation instances over 6,356 unique source domains. Citations are heavily concentrated: the top-20 domains per platform captured between 20.5% and 70.8% of all citations. More critically, 15 of 22 tested publication platforms tied to those preferred domains had low or medium barriers for account creation and posting. The experimental design is the load-bearing part. The researchers created a fabricated concept — essentially a made-up term with no prior web presence — then published posts containing this marker on various platforms with different domain-preference ranks. Within seven days, 8 of 10 AI-search platforms cited the fabricated concept. A single post on a high-preference domain had more citation impact than over 20 matched posts on low-preference domains. The asymmetry is stark: domain reputation is doing all the work, content quality is doing almost none. The commercial angle is the punchline. The team spent $14 on a GEO (Generative Engine Optimization) service, which produced 13 public posts across various platforms. One AI-search platform cited GEO-posted content with the researchers' designed markers within one hour. That's the attack surface priced in real dollars: for less than the cost of a sandwich, you can inject content into an AI-search answer pipeline. The measurement framework itself — combining cross-platform citation mapping, publication-barrier classification, and marker-controlled experiments — is the methodological contribution. Prior work on AI search manipulation has been largely anecdotal or theoretical. This paper operationalizes the threat by showing the full chain: identify preferred domains, measure publication barriers, plant content, observe citation uptake. The marker-controlled design is clever: by using a fabricated concept with zero prior web presence, any citation of that term is unambiguously attributable to their planted posts. What this paper does NOT do is propose defenses. It's a measurement paper, not a solutions paper, and that's an honest framing. The authors also don't test adversarial content — the planted posts were benign fabrications, not misinformation designed to cause harm. The gap between 'we can get cited' and 'we can get harmful content cited and believed' is real but probably not large. The bigger question this paper participates in: as AI search replaces traditional search as the primary information gateway, who controls what gets into the answer? Traditional SEO was a cat-and-mouse game between publishers and Google's ranking algorithm. GEO — generative engine optimization — is the next iteration, but with a crucial difference: the user never sees a list of sources to evaluate. They see a synthesized answer with citations buried in footnotes. The selection layer between web content and user-facing answers is now opaque, concentrated, and demonstrably fragile.