Skip to the book

NOMOS GBO · Prologue

The Internet No Longer Just Talks

For years, the internet supplied us with information. If we wanted a restaurant, it showed us the address. If we were researching a company, it found the website. If we wanted to buy a product, it laid out the options. A person still made the decision, filled in the form, paid the bill and took responsibility for what followed. Then generative AI arrived. These systems did more than return links: they read the information behind those links and answered us. They could sum up a company's work in a few sentences, compare products, explain complex documents and assess which sources appeared more trustworthy.

That change raised a new question: how does an AI system see us, and how does it represent us?

This is the question from which this book approaches GEO. A brand can be easy to find online yet be described incorrectly by AI. A company's genuine expertise can go unrecognised. Years of work can disappear behind more superficial sources. A machine can represent an entity using incomplete, outdated or contradictory information.

AI systems with access to tools are not confined to answering questions. They can arrange appointments, request quotations, fill in forms and draft emails. Their capabilities can also include comparing products, selecting suppliers, making reservations, changing files and releasing software. Under certain conditions, they can take part in payments and purchasing too. The internet no longer just talks. It is beginning to act.

When AI makes an inaccurate statement about a company, that is a problem of representation. When the same AI pays the wrong company, sends an unauthorised message or accepts a contract the user did not want, it is a problem of behaviour. An incorrect answer can be corrected, but its consequences may not be repairable. A wrong action can cost money, breach privacy, damage a reputation or leave people facing consequences that are difficult to reverse.

So it is not enough to ask, ‘Will AI understand us correctly?’ We also have to ask:

When should it choose us? When should it not? What evidence should it trust? What authority does it need to act? Should it ask a question when something is uncertain? Should it stop when risk increases? Can an operation be reversed if it makes a mistake? Can a person challenge the decision?

This book explores those questions through a framework we call Generative Behavior Optimization: GBO. In Turkish, the term is Üretken Davranış Optimizasyonu.

GBO is not a persuasion technique

The phrase ‘behaviour optimisation’ can easily be misunderstood. A company might want to force AI agents to choose it. A brand might try to influence their decision-making systems so that it receives more recommendations than its competitors. A platform might want to steer users' preferences towards its own commercial interests. The GBO advocated here is not about making an AI agent choose us more often. It is about enabling the agent to make the right choice when the conditions are right, and not to choose us when they are wrong. That distinction is the ethical centre of GBO.

A travel agent that keeps choosing the same hotel when it does not meet the user's needs has not been successfully optimised. Nor has a purchasing agent that chooses a company with unclear prices or capacity merely because it is more visible online. An AI assistant that sends a message on a user's behalf without their explicit approval may have finished quickly, but it has not behaved correctly. GBO optimises the appropriateness of actions, not their number. The right behaviour may be to select, refuse, ask a question or hand the matter to a person. Sometimes it is to do nothing.

A simple example

Imagine giving an AI agent this task: ‘Find a provider to build a multilingual client portal for our company.’ The agent searches online, finds several companies and reads their service pages. It compares prices, technical capabilities, delivery times and approaches to security. At this point, SEO and GEO alone are not enough. SEO helps the agent find the companies. GEO helps it understand what they do. But now it has to make a decision.

Before choosing a provider, it needs to know:

Does the company actually build client portals? Is multilingual delivery a genuine capability or just a marketing claim? Are authentication and data security included? Does the price include third-party licence fees? Is data migration charged separately? How long does support continue after delivery? Does the company currently have the capacity to take on the project? Does the actual service scope fit the user's budget? Is the agent authorised to request a quotation? Is human approval required before signing a contract?

If the information is missing, the agent must not fill the gaps with guesses. It should ask questions and refrain from acting on incomplete information. This is where GBO begins. Under GBO, a company's statement that ‘we build client portals’ is not enough. It must make its real capabilities, limits, pricing model, required inputs, suitability conditions, approval requirements and recovery methods intelligible to both people and machines. The agent needs more than a promotional page. It needs a behavioural contract.

The behavioural contract

Before an agent takes action concerning an entity, it should be able to answer seven basic questions:

Who is this? What can it actually do? What evidence supports that? Is it suitable for this situation? Does it have authority to carry out the operation? Can the action be performed safely? Can the previous state be restored if something goes wrong?

These seven questions form the core of GBO. If any remains unanswered, the agent must change its behaviour.

If evidence is missing, it should seek verification. If suitability is uncertain, it should return to comparison or ask for clarification. If authority is missing, it must stop the action concerned and approach someone entitled to authorise it. If the risk is unacceptable, the operation must not proceed. If reversal is impossible, that limit and the available remedies must be explained. The agent may proceed only with valid authority and acceptable risk. More stringent approval does not make a prohibited action legitimate.

In GBO, strong visibility cannot replace missing authority. Brand recognition cannot replace valid consent. A good price cannot compensate for weak security. A large number of sources cannot make an incorrect scope acceptable. The underlying logic is a set of gates, not an additive score. Every critical gate must be passed in its own right: the right match, sufficient evidence, valid authority, safe action, and defined conditions for reversal or compensation must be considered together. If one is missing, the agent must take a different path.

Where does GEO end and GBO begin?

GEO and GBO are complementary, not competing approaches. Misunderstanding a relevant fact undermines an agent's ability to behave reliably. But GEO work is not the only way to establish accurate information: verified organisational records, information supplied by the user or direct data access can provide that foundation too. Accurate representation alone still does not produce correct behaviour. An agent may understand a company's service perfectly and nevertheless choose wrongly because it has ignored the user's budget, authority or risk limit.

In that sense: SEO prepares for discovery. GEO prepares for representation. GBO prepares for behaviour.

SEO's primary object is the page. GEO's is representation. GBO's is the decision and the action. This book is not about gaining more clicks or citations. It asks how we can make correct behaviour possible when machines act upon people, organisations and the world.

The human is not a safety mechanism added at the end

Consider a system that treats a person as nothing more than a final approval button. It researches, decides and plans, then asks, ‘Do you approve?’ But a person's role is not simply to press that button. People set the goal, define acceptable risks and decide which actions to delegate. They grant authority and, when necessary, withdraw it. They challenge outcomes and seek remedies for mistakes. Human oversight is therefore not a safety add-on outside GBO. It is at its centre.

However capable an agent becomes, it must not create its own authority. Being able to do a task does not mean being authorised to do it. Being able to complete an operation does not make that operation right. Capability is not authority. Autonomy is not an irrevocable mandate.

What will this book do?

This book will not teach hidden tactics for forcing AI agents to choose a brand. It will not teach content production designed to deceive them. Nor will it advocate influencing decision systems through fabricated evidence, artificial reviews or manipulative machine-readable records. Its question is this: how should a person, company, service or institution prepare so that AI agents can assess it correctly and act safely in relation to it?

Better content, better data, an API or an agent protocol is not enough on its own. What is needed is a coherent behavioural architecture: accurate identity, clear capabilities, verifiable evidence, visible limits, valid permission, a safe route to action, human approval, records, reversal, challenge and compensation. We will call this the NOMOS Behavioral Contract Layer. The Turkish name is NOMOS Davranış Sözleşmesi Katmanı.

This layer does not merely tell an agent what it can do. It tells it when it may act, when it must not, and whose permission it needs. It explains the basis of its decisions, how it should stop if something goes wrong, and how a person can regain control.

The founding definition

The canonical definition used in this book is:

Generative Behavior Optimization — GBO — is the systematic structuring of identities, capabilities, evidence, limits, permissions, action pathways and compensation mechanisms so that generative and agent-based systems can behave correctly, on the basis of evidence, appropriately, with authority, safely, explainably and reversibly in relation to a person, brand, product, service, institution or source of information.

Reversibility in this definition does not mean that every effect of every action can be erased. Chapters eight and twelve treat stopping, withdrawing authority, technical rollback and compensation separately. Where an action cannot be reversed, its limits must be explained beforehand, and valid authority and acceptable risk are required. Compensation is not a complete restoration of the past.

Put more simply, GBO seeks to ensure that AI does not merely know the right thing, but does the right thing. And sometimes the right thing is to do nothing.

Notes and sources for this chapter

  1. GEO: Generative Engine Optimization

    Pranjal Aggarwal, Vishvak Murahari, Tanmay Rajpurohit, Ashwin Kalyan, Karthik Narasimhan and Ameet Deshpande. arXiv:2311.09735v3, 28 June 2024; first submitted 16 November 2023; KDD 2024.

    The study examines GEO in terms of visibility in generative engine responses. This book’s emphasis on representation and governance is the author’s conceptual extension; it should not be read as the paper’s sole or verbatim definition.

  2. LLM06:2025 Excessive Agency

    OWASP Gen AI Security Project. 2025.

    Excessive tool functionality, permissions and autonomy can increase excessive-agency risk. Permissions must not be left solely to a model’s interpretation of instructions; the systems performing operations must enforce them too.