AI Engines Agree Vanta Leads Compliance Automation. They Cite Almost None of the Same Sources.
TL;DR
- We analyzed 240,000 AI engine responses to 10,000 enterprise buyer-intent queries about compliance automation, GRC and integrated risk management, across six engines and four markets. Vanta led with 139,000 mentions, ahead of Drata at 123,000, and the two held first and second place in every market. The six engines converged on that shortlist from largely separate evidence: cited-domain overlap averaged 0.11 as a Jaccard coefficient, where 1 means identical, and only two of the 15 engine pairs reached 0.20. Of the 3,464,000 pages they cited, 41.7% sit on a vendor's own site, and only 1.6% were dead.
Compliance buyers now open an AI engine before they open a vendor site. The shortlist that engine returns shapes the evaluation before anyone fills in a contact form, so we wanted to know what the engines actually say in one category, measured at scale rather than inferred from a handful of prompts. That shift raises its own accountability question: when an AI shortlist shapes a compliance buyer's evaluation before a human reviews anything, the transparency standard has to come from somewhere. The same discipline applies once that shortlisted vendor becomes part of your software supply chain — see securing your software supply chain for the vendor-risk practices that should follow an AI-assisted shortlist. What legal-sector AI adoption teaches SaaS companies about accountability and trust covers the parallel playbook the legal industry already built. (For the practical side of AI in this category — how security teams actually use AI to read and triage audit and compliance documents once they've picked a tool — see how cybersecurity teams use AI to analyze compliance, audits and security reports.)
Key Takeaways
- Vanta recorded 139,000 mentions and Drata 123,000, together 22.2% of every brand mention in the study. Thirteen brands were named by all six engines; 60 of the 99 brand strings were named by only one.
- Mention volume and position move independently. Vanta was the most frequent first-named vendor in only the three Google-operated engines; ServiceNow held that position in ChatGPT and Perplexity, LogicGate in Microsoft Copilot, and MetricStream was named earlier than Vanta on average in four of the six.
- Cited-domain overlap between engines averaged 0.11 as a Jaccard coefficient, where 0 is disjoint and 1 is identical. The highest pair was 0.27, and only two pairs reached 0.20.
- 41.7% of all cited pages sit on a vendor's own site, but vendor sites are the largest source class for ChatGPT alone. The other five engines read mostly unclassified comparison and roundup pages.
- Only 1.6% of cited pages were dead, and Vanta and Drata held first and second place in all four markets.
What We Analyzed and How
We issued 10,000 enterprise buyer-intent queries about compliance automation, GRC software and integrated risk management to six AI engines: ChatGPT, Perplexity, Gemini, Microsoft Copilot, Google AI Overview, and Google AI Mode. Every query ran in four markets (United States, Canada, India, Germany), producing 40,000 responses per engine and 240,000 in total during August 2026.
For every response we recorded length, cited sources and the type of site each one sits on, whether each cited URL still resolved, each brand named, and the ordinal position of that brand's first appearance. The corpus contained 3,464,000 cited sources, 99 brand strings and 99 distinct product entries once plan, edition and category-noun spellings of one product were merged. If you want to run this count on your own brand, the step-by-step version is in how to measure AI share of voice across engines.
Two limits are worth stating up front. The engines are commercial services without pinned model versions, so a repeat run would not reproduce identical responses. And the query set is purposive rather than randomly sampled, so we report descriptive statistics only and make no claims of statistical significance. Full methodology and validity limits are in the complete benchmark report.
Which Vendors Do AI Engines Name Most in Compliance Automation?
Vanta led the category with 139,000 mentions, followed by Drata at 123,000 and MetricStream at 89,000. ServiceNow was 3,000 behind MetricStream at 86,000. Thirteen brands were named by all six engines: Vanta, Drata, MetricStream, ServiceNow, Secureframe, Sprinto, IBM, LogicGate, OneTrust, AuditBoard, Diligent, Compliancy Group and Hyperproof.
The core is wider than in other categories of this series and the tail is long. The four leading brands took 37.0% of all mentions across 99 brand strings. Below them, 60 brand strings were named by exactly one engine, none above 7,000 mentions, and many are healthcare compliance services, audit firms or secure messaging tools that one engine pulled into the category from a HIPAA or SOC 2 query. At product level, 72 of the 99 entries recorded fewer than 10,000 mentions and 32 recorded exactly 1,000.
The category's two buying motions sit side by side in the leading group. The compliance automation platforms (Vanta, Drata, Secureframe, Sprinto) and the enterprise risk suites (ServiceNow, MetricStream, Archer, IBM OpenPages, LogicGate) were both returned, by every engine, to overlapping questions. Which of the two kinds of vendor opens the response depends on the engine.
Do the Engines Agree Because They Read the Same Sources?
No. They agree on names while reading largely separate evidence.
We measured overlap between each pair of engines as a Jaccard coefficient on their cited domains, where 0 means no shared domains and 1 means identical sets. The mean across all 15 engine pairs was 0.11. The highest value was 0.27, between Google AI Mode and Google AI Overview, two surfaces operated by the same parent. The second highest was 0.22, between Gemini and Perplexity, two engines from different companies. Those were the only two pairs to reach 0.20. The lowest was 0.03.
Microsoft Copilot was the most isolated engine in the study. Its overlap with every other engine ran from 0.03 to 0.08. It also drew on 43 distinct domains against Google AI Mode's 257 and ChatGPT's 218. The mechanics behind that split, which sources each engine is built to prefer, are in how the major AI engines choose which sources to cite.
Our finding: six engines reading substantially different parts of the web arrived at substantially the same list of names. Earning a citation on a domain one engine reads does not place you in front of the other five.
There is one shared front page. Vanta's own domain was the most-cited domain for three engines: ChatGPT, Google AI Overview and Perplexity. Google AI Mode's most-cited domain was Sprinto's, Gemini's was Scytale's, and Microsoft Copilot's was a statistics aggregator that no other engine cites in quantity.
Where Does the Evidence Come From?
Mostly from ChatGPT. It supplied 1,690,000 of the 3,464,000 cited sources, 48.8% of the corpus on its own. Google AI Mode added 735,000 and the two together account for 70.0%. Microsoft Copilot supplied 152,000 and Gemini 124,000.
41.7% of all cited pages sit on a domain belonging to a vendor named in the answer. That number is carried almost entirely by ChatGPT, which drew 59.2% of its citations from vendor sites and is the only engine where vendor sites are the largest source class. For the other five, the largest class is pages outside every type we track: comparison sites, consultancies and roundups. Vendor sites ran from 19.7% of Microsoft Copilot's citations to 37.9% of Gemini's. Analyst and review sites carried 6.1% of the corpus. Government domains, the regulatory texts themselves, carried 1.6%, all of it cited by ChatGPT.
ChatGPT's three most-cited domains were Vanta's own site at 99,000 citations, Drata's at 90,000 and ServiceNow's at 81,000. Microsoft Copilot's were the statistics aggregator at 38,000 and two smaller third-party sites at 15,000 and 7,000.
For a vendor, that is two instructions rather than one. Documentation, framework and integration pages on your own domain serve the engine that cites most. Third-party comparison pages serve the other five. Google states a page needs no special optimization to be eligible for AI Overviews or AI Mode beyond standard indexing and Search eligibility (Google Search Central, "AI features and your website", retrieved 2026-09-16) — so the documentation and integration pages already on your domain are already eligible; the gap is usually structure and clarity, not a missing technical flag.
How Reliable Are the Sources AI Engines Cite?
Of the 3,464,000 cited URLs we tested, 55,610 did not resolve, a dead-link rate of 1.6%. Gemini and Perplexity recorded no dead links at all. The highest rate was 7.9%, for Microsoft Copilot, on one of the smallest citation volumes in the study. ChatGPT, at 2%, still accounted for 33,800 of the dead pages, 60.8% of the total, because it cites the most.
The definition matters. Many sites answer an automated request with a 403 because the page sits behind a bot wall. The page exists; the crawler was turned away. We count a page as dead only when it returns not-found, gone or a server error, or its host cannot be reached after a retry. On that definition, the pages these engines lean on are almost all there.
The first step is still knowing which of your URLs the engines cite at all; the per-engine workflow is in tracking AI citations, mentions and sources. But in this category, link decay is not the lever. The inclusion problem is.
Which Vendor Gets Named First?
Three different vendors, depending on the engine.
Gemini, Google AI Mode and Google AI Overview all open with Vanta. ChatGPT and Perplexity open with ServiceNow. Microsoft Copilot opens with LogicGate.
That split does not follow mention volume. ServiceNow is fourth by mentions at 86,000 and LogicGate eighth at 49,000. Neither Drata, second by mentions, nor MetricStream, third, opens the response in any engine.
Mean ordinal position tells a third story. MetricStream was read earlier than Vanta in four of the six engines, and those four include all three where Vanta opens the response most often. In Gemini, MetricStream averaged 1.8 against 3.3 for Vanta. Vanta's earliest mean position anywhere was 2.0, in Perplexity, an engine it does not open.
Prominence and frequency are separate quantities here. A visibility score that reports only how often you are named describes one of three things that happened.
Response length varies just as widely. ChatGPT averages 542.9 words and Perplexity 132.4, a factor of 4.1 on identical queries. Perplexity's responses also ended without terminal punctuation, our proxy for truncation, in 42% of cases against 0% at Microsoft Copilot, and Microsoft Copilot anchored 63% of its answers to an explicit date against 0% at Google AI Mode. No engine refused a single query.
| AI engine | Mean words | Cited sources | Dead-link rate | Opens with |
|---|---|---|---|---|
| ChatGPT | 542.9 | 1,690,000 | 2% | ServiceNow |
| Microsoft Copilot | 456.9 | 152,000 | 7.9% | LogicGate |
| Gemini | 478.3 | 124,000 | 0.0% | Vanta |
| Google AI Mode | 338.0 | 735,000 | 0.5% | Vanta |
| Google AI Overview | 217.6 | 438,000 | 1.4% | Vanta |
| Perplexity | 132.4 | 325,000 | 0.0% | ServiceNow |
Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.
Do AI Recommendations Change by Country?
Not at all in the leading two positions, and that is the surprise.
Vanta was first and Drata second in all four markets. Third place alternated between MetricStream in the United States and Germany and ServiceNow in India and Canada.
| Market | First | Second | Third |
|---|---|---|---|
| United States | Vanta | Drata | MetricStream |
| Canada | Vanta | Drata | ServiceNow |
| India | Vanta | Drata | ServiceNow |
| Germany | Vanta | Drata | MetricStream |
Brands ranked by mentions within each market; n = 60,000 responses per market. Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.
Compliance is jurisdictional by definition. GDPR applicability, data residency and sector regulation genuinely differ across those four markets, yet the returned vendor set did not, and no market-specific vendor entered the leading positions anywhere. 37 of the 99 product entries were recorded in all four markets, including every one of the ten most-mentioned. On this evidence the engines treat compliance automation as a global software market rather than a regulated local one, and market-specific visibility work in this category is currently addressing a difference the engines are not making. Nor is it a compliance-specific quirk: our attack surface management study ran the identical protocol and found its own two leading vendors first and second in every market, with only the order changing in one.
Where Did the Engines Disagree?
On narrow capability claims, not on the shortlist.
The sharpest split was over single-control-set coverage, the claim that one platform's control set satisfies several frameworks without separate mapping work. Microsoft Copilot, and some Perplexity responses, named CATAAM, Strac and Compliance One as platforms that meet the requirement in full. ChatGPT and the three Google-operated engines treated the same requirement as only partly met, by Vanta and Drata. The vendors in the first group sit far down the mention distribution: CATAAM recorded 8,000 mentions across the whole study, Strac 8,000 and Compliance One 3,000, against 139,000 for Vanta.
The engines also split on HIPAA fit. ChatGPT returned Vanta and Drata for healthcare software companies. Gemini returned Compliancy Group and Medcurity for clinical practices. Same question, different products, depending on which kind of buyer the engine assumed.
Then the tails. Microsoft Copilot alone returned 14 product entries no other engine named, among them MetricStream Risk and Klarity Health. Gemini alone returned 14, ChatGPT 9 and Perplexity 8, among them IBM OpenPages with Watson and VelocityEHS Risk Management. Even after merging plan and edition spellings, the corpus held 99 product entries: MetricStream and Diligent appeared as 5 entries each, ServiceNow and Archer as 4. Some of that is real product breadth. Some is naming drift, and only consistent naming lets a measurement consolidate it.
A plausible explanation for the capability disagreements is that broad positioning is stabilized by a wide base of writing, while a narrow capability claim is settled by whichever single page an engine happened to read. The study measures what the engines returned, not why, so this remains an interpretation rather than a finding.
What Should Vendors Do With This?
Treat the six engines as six channels. Mean cited-domain overlap was 0.11 and only two of 15 pairs reached 0.20. Work that moves one engine cannot be assumed to move the others, and a program scoped to a single engine leaves five unmeasured.
Track three numbers, not one. Mention volume, first-mention share and mean position ordered the leading vendors three different ways. One combined score hides which of the three is moving.
Serve ChatGPT from your own domain and the other five from third-party pages. ChatGPT draws 59.2% of its citations from vendor sites and supplies 48.8% of the corpus. The other five draw between 19.7% and 37.9% from vendor sites and read mostly comparison and roundup pages.
Write the framework-mapping claim in plain terms. State which frameworks you cover and how much control reuse is genuine. The engines disagree on exactly this point, and a clear statement gives them something to resolve it with. How to structure that so an engine can extract it is the subject of the GRC content strategy for AI search visibility.
Do not localize, and do not budget for link rot. Vanta and Drata led all four markets in the same order, and only 1.6% of cited pages were dead. Sentiment is not a lever either: every leading brand with a recorded score sat between 0.62 and 0.81 on a scale from negative one to one, too narrow a band to separate any two of them.
Frequently Asked Questions
How many AI responses did this compliance automation study analyze?
240,000 responses, from 10,000 enterprise buyer-intent queries issued to six AI engines across four markets in August 2026. The corpus contained 3,464,000 cited sources and 99 distinct product entries.
Which compliance automation vendor has the highest AI search visibility?
Vanta, with 139,000 mentions across the study, ahead of Drata at 123,000 and MetricStream at 89,000. Thirteen brands were named by all six engines tested, and Vanta led in all four markets.
Which vendor do AI engines name first for compliance automation?
It depends on the engine. Vanta opened Gemini, Google AI Mode and Google AI Overview. ServiceNow opened ChatGPT and Perplexity. LogicGate opened Microsoft Copilot. MetricStream, which opened none, was read earlier than Vanta on average in four of the six engines.
Do all AI engines cite the same sources for compliance software recommendations?
No. Mean cited-domain overlap between engine pairs was 0.11 as a Jaccard coefficient, where 1 is identical. The highest overlap recorded anywhere was 0.27, between two surfaces run by the same parent, and only two of the 15 pairs reached 0.20.
What percentage of AI-cited sources are dead links?
1.6% across the full corpus of 3,464,000 cited URLs. The rate ranged from 0.0% for Gemini and Perplexity to 7.9% for Microsoft Copilot.
What should compliance automation vendors do with this data?
Treat each AI engine as a separate channel rather than optimizing for one. Serve ChatGPT from owned-domain documentation and framework pages, since it draws the most from vendor sites; serve the other five engines through third-party comparison and roundup content, since that is what they read most. State framework-mapping claims in specific, plain terms, since that is where engines disagree most.
Final Thoughts
The engines agree about vendors and disagree about evidence. Thirteen of 99 brand strings were named by all six, the four leading brands took 37.0% of all mentions, and Vanta and Drata led every market in the same order, while the engines behind those answers shared a mean of 0.11 of their cited domains and vendor sites were the largest source class for only one of the six.
For a vendor in this category the shape matters more than any single number. Visibility is concentrated into roughly a dozen names the engines reuse across markets and phrasings, and it is reached through six largely separate evidence bases that share one vendor's front page and little else. Entering that group is a different problem from opening the response once inside it, and it has to be solved once per engine.
The full methodology, the per-engine tables, the source-type breakdown and the validity limits are in the complete benchmark report.
Revision note: the corpus behind this post was reprocessed under corrected citation-counting, dead-link and product-naming rules. Citation totals, dead-link rates, source overlap, source-type shares and product-entry counts changed materially from the first edition, and the figures above supersede it. The response corpus itself is unchanged.
Disclosure: GrackerAI publishes this research and sells AI search visibility measurement for the category it covers. The study measured how AI engines describe vendors. It did not test, evaluate, or rank any vendor's product, and no vendor paid for or requested placement.