Short answer
Automate three things: the request, sent by the same trigger to every customer who reaches the same milestone; the monitoring, so a new review reaches a named owner within the hour; and the first draft of the reply. Do not automate who gets asked or what gets published. Two distinct legal points govern this under the FTC's Consumer Reviews and Testimonials Rule: incentives are allowed, but conditioning them on a positive rating is banned outright; asking only the customers you believe are happy is a separate question, and the FTC's answer is that the rule contains no specific prohibition against it — though the practice could still violate the FTC Act.
Why AI answers lean on reviews you do not control
When a buyer asks an assistant to shortlist vendors, the answer is assembled from sources the model treats as evidence. Your own website is one of them, and it is the weakest: everything on it is an assertion by an interested party. A review platform is different in kind, because your customers can contradict you there.
The scale of that difference has been measured. Seer Interactive analyzed 804,491 AI responses across 1,926 brands on four AI platforms. Review and trust sites came out as the second-largest citation source overall, and their weight grows 10 to 20 times between the awareness stage and the point where someone is ready to buy.
One number from that study is worth stating precisely, because it is usually quoted loosely. The study graded brands into tiers built on Trustpilot profiles specifically — Tier 0 being brands without a verified active profile — and found that Tier 3 brands, the fully optimized profiles, received 9.5 times more co-mentions than Tier 0. Co-mentions are what happens when a buyer asks about a competitor and your name comes back anyway. Two caveats follow from the method: the multiplier belongs to a fully optimized profile, not merely an existing one, and it was measured on one platform. Treat it as evidence that review presence compounds, not as a figure you can promise on any site.
The closer a prospect gets to a decision, the more the answer leans on pages you cannot edit. A visibility plan that stops at your own domain is absent from the source category that carries the most weight at exactly the wrong moment.
This is why review operations belong in a visibility budget rather than a customer-service one. It is the same reasoning that makes third-party presence central to getting cited by ChatGPT and Perplexity, and it is the part of generative engine optimization that has nothing to do with your content management system.
The line the FTC drew — and what it still allows
Before automating anything, know where the boundary sits, because most review tools will happily walk you across it. The FTC's Rule on the Use of Consumer Reviews and Testimonials went into effect on October 21, 2024, and it authorizes courts to impose civil penalties for knowing violations. Four points decide how you build the workflow.
- Incentives are not banned. The FTC states the rule does not prohibit giving incentives for reviews, provided there is no express or implied requirement that the review express a particular sentiment. Undisclosed incentives are a separate problem under the FTC Act.
- Paying for five stars is banned. Conditioning a reward on the rating is the practice the rule targets, on your own site and on third-party platforms alike.
- Talking to unhappy customers is fine. The rule does not prohibit contacting customers who post negative reviews to resolve the reported issue, and it does not prohibit asking satisfied customers to update a review.
- Ordering is not suppressing. Sorting reviews by helpfulness or rating is not review suppression under the rule. Removing or hiding negatives is a different matter.
- Asking only happy customers sits in a grey zone, not a safe one. Asked whether a business may request reviews only from customers it believes are satisfied, the FTC answers that "the rule does not contain a specific prohibition against such conduct," immediately followed by "but this practice could violate the FTC Act." Not banned by the rule text; not endorsed either.
The practical consequence is one design rule: no sentiment check should sit between the trigger and the request. It keeps you clear of the grey zone above, and it is also the stronger commercial choice — a profile made only of five-star reviews reads as bought, to buyers and to models weighing how credible your page is.
Two scope notes. This section describes US law; the UK has its own regime for reviews under the Competition and Markets Authority, so check its current guidance rather than assuming the FTC position transfers. And this is general information read directly from the FTC's own published guidance, not legal advice — for how any of it applies to your business, ask a lawyer.
Automating the ask
Most companies do not have a review problem. They have an asking problem: requests go out when someone remembers, which is to say after a good meeting and never after an ordinary one. Automation fixes that, and it is the single highest-value piece to build first.
- Pick a milestone, not a date. The trigger should be an event that means the customer has actually received value — a project marked delivered, a third successful login week, a ticket closed as resolved. Elapsed time since purchase is a weak proxy and produces requests to people who have not used anything yet.
- Send to everyone who reaches it. Same trigger, same message, no filtering. This is the legal requirement and the credibility requirement at once.
- One reminder, then stop. A single follow-up a week later recovers a meaningful share of non-responses. A third message costs you goodwill for nothing.
- Route to one platform per customer. Splitting the ask across three sites gets you three thin profiles. Decide which platform matters for that segment and send them there.
- Make the first click do the work. Deep-link to the review form itself, pre-filling nothing about the content. Every extra screen costs completions.
Any workflow engine handles this — the connection between your CRM or project tool and an email or SMS provider is a short chain, and the same pattern shows up in most operational automations. The hard part is agreeing on the milestone, which is a business decision, not a technical one.
Automate the detection, not the reply
The second workflow is monitoring. A new review should reach a named human quickly, with the text in front of them, rather than being discovered during a quarterly audit. Poll the platforms that expose an API, watch the rest with alerts, push everything into one channel, and attach an owner.
Response speed matters more than response polish. A negative review answered within a day reads as a company that is paying attention; the same answer three weeks later reads as damage control, and by then it has already been retrieved and summarized by whatever model a prospect was talking to.
Draft with AI, publish with a human. A generated reply that misstates what happened is a public statement about your own service that you cannot retract — and reviewers spot the pattern when every response opens the same way.
Two things should never be automated end to end: the decision about who gets asked, and the text that gets published under your name. Everything between those two — detection, routing, drafting, escalation, tracking — is fair game and is where the hours actually go.
Where to concentrate the effort
Not every platform is worth the same effort, and the honest answer to "which ones do the models cite" is that it depends on your category. The reliable way to find out is to ask the assistants themselves: pose the buying questions your prospects would ask and note which sites the answers actually reference. That list is your target, and it is usually shorter than the list a review tool will sell you.
In practice, three names cover most of the ground. If you have a physical location or serve a local market, Google Business Profile comes first — it feeds the same index behind Google's AI surfaces, so the work counts twice. If you sell software or a subscription to other businesses, G2 and Capterra are where buyers compare and where comparison pages get built. Trustpilot is the generalist, strongest in retail and services and the platform the study above actually measured. Pick the one your buyers use, finish it, and ignore the rest until it is genuinely complete.
Two things generalize. First, one complete profile with recent, detailed reviews beats four abandoned ones — an empty profile is a negative signal to a human and near-invisible to a model. Second, review text carries the useful information: reviews that describe what the customer needed and what happened give a model something to quote, while "great service, highly recommend" gives it nothing. You cannot dictate the content, but the request can ask an open question rather than requesting a rating, and that reliably produces longer answers.
Knowing whether it moved anything
Track the operational numbers monthly: requests sent, completion rate, average response time, reviews collected per platform. These tell you whether the machinery works, and they are the inputs you need if you want to put an honest ROI figure on the workflow later.
Whether it changed your AI visibility is a separate measurement, and it is not in Search Console. Write down the twenty questions a buyer would ask before choosing a company like yours, run them across ChatGPT, Perplexity, Gemini and Claude, and record who gets named. Repeat monthly, from a clean session, running each question more than once — answers vary between runs, so a single check proves very little. Expect the review work to show up over months rather than weeks; it accumulates.
Frequently asked questions
Can we offer a discount in exchange for a review?
Yes, with two conditions. The FTC states that its Consumer Reviews and Testimonials Rule does not prohibit giving incentives for reviews, as long as there is no express or implied requirement that the review express a particular sentiment. Disclose the incentive — the FTC notes that failing to do so could violate the FTC Act independently of the rule. What you cannot do is pay for five-star reviews: conditioning the reward on the rating is exactly the practice the rule targets.
Is it legal to only ask happy customers for a review?
It is not banned outright, and the FTC is precise about why. Asked this exact question, it answers that the rule does not contain a specific prohibition against such conduct, but that the practice could violate the FTC Act. So the rule text does not stop you, and the broader statute might. The design that avoids the question entirely is mechanical: the same trigger sends the same request to every customer who reaches the same milestone, with no sentiment check in between. It also produces a more credible profile — a wall of nothing but five stars reads as bought, to buyers and to models alike.
Can we ask a customer to remove or update a negative review?
The FTC is explicit that the rule does not prohibit contacting customers who post negative reviews to resolve the reported issue, and does not prohibit simply asking satisfied customers to update their reviews. Offering an incentive to take a negative review down is a different matter: the FTC notes it is not prohibited by the rule itself but could be an unfair practice under the FTC Act. Fix the problem, then ask — do not pay for silence.
Should we let AI write our review responses?
Draft yes, publish no. A generated reply that misstates what happened is a public statement about your own service that you cannot take back, and reviewers notice when three responses share the same sentence structure. The workable split is that automation handles detection, routing and a first draft; a human owns the last read before anything is posted.
If you would rather have this running than documented, that is our job — we wire the trigger to your own systems, set up the monitoring, and measure what the assistants say about you before and after. Book a call and we will start with where you stand today.
