How AI Search Is Recommending Antivirus Software: Monthly Trends

Mark HuntleyBy Mark HuntleyFounder and CEO
11 minutes read

Key Takeaways

  • Bitdefender GravityZone moved into first place in October 2026 with 69.9% valid recommendation coverage, ahead of Norton at 65.7%.
  • McAfee posted the sharpest decline, falling 12.3 points from July to October 2026 and slipping to seventh place.
  • Kaspersky and Webroot also declined significantly, while Avast drifted lower without a statistically significant drop.
  • A Norton 360 VPN data-cap claim produced conflicting answers across AI platforms, highlighting a factual inconsistency in source handling.

Executive Summary

Bitdefender GravityZone is the category leader in AI search recommendations at 69.9% valid recommendation coverage in October 2026, a 4.2-point lead over second-place Norton at 65.7%. Leadership has changed hands since July 2026, when Norton led at 68.4% against Bitdefender GravityZone's 64.2%; Bitdefender GravityZone now holds a lead of the same size in the opposite direction.

Bitdefender GravityZone is the strongest upward mover with coverage, up 5.7 points from 64.2% in July 2026 to 69.9% in October 2026, a significant rise against baseline. Its top-three rate stands at 62.4% and its rank-one rate at 49.7%, the highest rank-one share among tracked brands this month. The prior-to-current movement of 21.1 points from September 2026 is the largest single-month move recorded in the series.

McAfee is the sharpest decliner, down 12.3 points from 44.8% in July 2026 to 32.5% in October 2026, a significant fall against baseline and its third consecutive monthly decline. Kaspersky fell 6.6 points to 23.9% and Webroot fell 4.1 points to 7.4%, both significant against baseline.

Against the prior month, the category was mixed rather than uniformly moving. Bitdefender GravityZone's rise and Norton's 3.4-point recovery from September 2026 ran alongside continued declines for McAfee, Kaspersky, Trend Micro, and Webroot, while the competitive gaps separating the top of the field from the bottom continued to widen.

Each monthly benchmark run begins with 800 prompt-surface observations (602 unique questions in October 2026, versus 570 in July 2026) across the benchmark's defined AI/search surface universe. Of those, 800 mentioned a tracked brand or competitor; 787 were relevant and 13 were irrelevant in October 2026 (792 relevant and 8 irrelevant in July 2026). The public metrics use the 644 qualified observations that survive both qualification stages (643 in July 2026).

AI recommendation trend

valid recommendation coverage, Jul 2026 to Oct 2026

0%20%40%60%80%Jul 2026Aug 2026Sep 2026Oct 2026
  • Bitdefender GravityZone69.9%
  • Norton65.7%
  • Malwarebytes59.2%
  • Avast52.5%
  • ESET48.3%
  • AVG40.7%
  • McAfee32.5%
  • Kaspersky23.9%
  • Trend Micro13.7%
  • Webroot7.4%

Key Findings

Signal

October 2026 finding

Category leader

Bitdefender GravityZone leads at 69.9% valid recommendation coverage

Gap to second

4.2 points over Norton at 65.7%

Largest riser

Bitdefender GravityZone, up 5.7 points from July 2026

Largest decliner

McAfee, down 12.3 points from July 2026

Significant decliners

Kaspersky, McAfee, Webroot

Category movement

Mixed: one significant rise, three significant declines

AI Response Inconsistency Alerts

Questions This Section Answers

  • What factual inconsistency did AI platforms surface about Norton 360 this month?
  • Which sources may have driven the conflicting VPN data-cap claims?

One critical or high-severity factual inconsistency was detected this month, across two AI platforms. The single flagged conflict involves Norton.

Norton

AI platforms provided conflicting information about Norton 360's VPN data allowance, a high-severity factual inconsistency with a confidence score of 0.95. When asked "What is the most recommended AntiVirus software?", Google AI Mode stated that Norton 360 includes a completely unrestricted VPN, while Copilot stated that some suites, including Bitdefender and Norton, cap VPN usage unless the user upgrades. These two claims cannot both be true.

The Google AI Mode response cited pages including CNET's "Best Antivirus 2026" roundup, Cybernews's "The Best Antivirus Software for 2026," and a Microsoft Learn community answer thread on the best antivirus software. The Copilot response referenced product listing pages on Amazon and ESET's shopping pages. A source flagged across both sides, Gizmodo's best-antivirus coverage, contains language on Norton 360's uncapped VPN alongside a note that Bitdefender's bundled VPN is capped at 200 MB a day per device unless upgraded, which may bear on how each platform formed its answer.

Highest-priority diagnostic: Which source page each platform weighed most heavily for the VPN data-cap claim, and whether the flagged third-party coverage is the common origin of the divergence.

Benchmark Context

Questions This Section Answers

  • How many qualified observations underlie the October 2026 recommendation percentages?
  • What changed in the benchmark-level metrics between July and October 2026?

The report separates the raw collection universe from the qualified analysis set. Brand-level recommendation percentages are calculated within the qualified benchmark set.

Research stage

Jul 2026

Oct 2026

What it represents

Source prompt-surface observations collected

800

800

Total prompts run across the surface universe

Unique questions

570

602

Distinct questions after de-duplication

Brand / competitor mentions

800

800

Prompts mentioning a tracked brand or competitor

Relevant prompts

792

787

Prompts on-topic for the vertical

Irrelevant prompts

8

13

Prompts off-topic or inapplicable

Qualified benchmark observations

643

644

Public denominator after qualification

Qualified surface breadth

6

6

AI surface families with qualified observations

The qualified surface breadth held at six canonical AI/search families across the full July to October 2026 series. Intermediate months stayed within a narrow band: 643 qualified observations in August 2026 and 645 in September 2026.

Benchmark-Level Metrics

Metric

Jul 2026

Oct 2026

Change

Qualified observations

643

644

Up 1

Companies tracked

10

10

No change

Recommendation-shaped answer share

55.7%

59.8%

Up 4.1 points

Valid recommendation shortlist share

83.2%

87.1%

Up 3.9 points

Category leader by coverage

Norton (68.4%)

Bitdefender GravityZone (69.9%)

Leader changed

Both aggregate shares softened through August 2026 and September 2026 before recovering in October 2026, with the recommendation-shaped answer share at 52.1% and the valid recommendation shortlist share at 78.8% in August 2026, then 53.3% and 77.5% in September 2026.

AI Recommendation Trend

Questions This Section Answers

  • Who leads AI recommendations across the tracked antivirus brands in October 2026?
  • Which brands moved significantly against their July 2026 baseline?

Leadership changed hands: Bitdefender GravityZone now leads Norton by 4.2 points

Brand

Jul 2026

Oct 2026

Movement

Oct 2026 rank

Bitdefender GravityZone

64.2%

69.9%

Up 5.7 points

1st

Norton

68.4%

65.7%

Down 2.7 points

2nd

Malwarebytes

59.9%

59.2%

Down 0.7 points

3rd

Avast

56.8%

52.5%

Down 4.3 points

4th

ESET

49.5%

48.3%

Down 1.2 points

5th

AVG

41.8%

40.7%

Down 1.1 points

6th

McAfee

44.8%

32.5%

Down 12.3 points

7th

Kaspersky

30.5%

23.9%

Down 6.6 points

8th

Trend Micro

16.0%

13.7%

Down 2.3 points

9th

Webroot

11.5%

7.4%

Down 4.1 points

10th

Bitdefender GravityZone's 5.7-point baseline-to-current rise exceeded normal month-to-month variation, and McAfee's, Kaspersky's, and Webroot's declines did the same in the opposite direction. The remaining category-level change came from the combination of several smaller movements rather than any single dominant one, with the four brands directly below the top two all registering modest baseline-to-current declines.

What Changed This Month

Questions This Section Answers

  • Which prompts stopped surfacing McAfee as its coverage declined?
  • How did Bitdefender GravityZone's rank-one share compare to Norton's?
  • Did the widening competitive gaps reflect sustained prompt-level shifts?

Bitdefender GravityZone: A one-month reversal that restored leadership

Bitdefender GravityZone's valid recommendation coverage rose 5.7 points, from 64.2% in July 2026 to 69.9% in October 2026, a significant rise against baseline. The movement is concentrated almost entirely in the most recent month: coverage stood at 48.8% in September 2026, so the prior-to-current change is 21.1 points, the largest single-month move in the series and a reversal that more than offset the August-to-September decline.

Placement metrics moved with coverage. Its top-three rate stands at 62.4%, up 4.4 points from 58.0% in July 2026, and its rank-one rate is 49.7%, up 6.3 points from 43.4% and a significant rise against baseline. Its rank-one count rose from 279 in July 2026 to 320 in October 2026. Raw mention presence also climbed 5.1 points, from 72.5% to 77.6%, a significant rise.

The distinction worth noting is that Bitdefender GravityZone now leads on both breadth and depth: it is surfaced more often than in July 2026 and is far more likely to hold the number-one slot, with a rank-one rate nearly five times Norton's 9.9%. Net sentiment held steady at 0.9 in both months, so the change is one of placement frequency rather than tone.

Highest-priority diagnostic: Which surface families drove the September-to-October recovery, and whether the earlier two-month decline and this rebound shared a common set of prompts.

McAfee: A three-month slide into the bottom half of the field

McAfee's valid recommendation coverage fell 12.3 points, from 44.8% in July 2026 to 32.5% in October 2026, a significant decline against baseline and the third consecutive monthly decrease. The prior-to-current movement of 2.9 points from September 2026 is smaller than the cumulative fall, indicating the erosion has been steady rather than concentrated.

Its raw mention presence fell 7.5 points, from 62.5% to 55.0%, a significant decline against baseline, while its top-three rate edged up 1.4 points to 11.8%. Its rank-one rate remains low at 0.3%, with a rank-one count of 2. Valid recommendation count fell from 288 in July 2026 to 209 in October 2026.

The pattern separates visibility from placement: McAfee is being surfaced in fewer answers overall, and among the answers where it appears, the top-three rate has not fallen. Net sentiment weakened from 0.8 in July 2026 to 0.6 in October 2026, among the lowest readings among tracked brands this month, alongside Webroot.

Highest-priority diagnostic: Which prompts stopped surfacing McAfee, and whether the weakening sentiment traces to specific evidence sources.

Kaspersky: A significant coverage decline with placement holding flat

Kaspersky's valid recommendation coverage fell 6.6 points, from 30.5% in July 2026 to 23.9% in October 2026, a significant decline against baseline. The prior-to-current movement of 1.2 points from September 2026 was within normal variation, so the bulk of the fall occurred earlier in the series.

Its raw mention presence fell 3.3 points, from 39.8% to 36.5%, while its top-three rate rose 0.5 points to 11.5% and its rank-one rate rose 0.3 points to 0.5%. Valid recommendation count fell from 196 in July 2026 to 154 in October 2026.

The distinction here is that Kaspersky's placement metrics held or improved slightly even as its coverage declined, which points to reduced surfacing rather than weaker positioning where it does appear. The absolute counts are small, so single-prompt shifts can move the percentages, but the direction is consistent across coverage and presence.

Highest-priority diagnostic: Which prompts stopped surfacing Kaspersky, and which brand absorbed those placements.

Avast: A three-month decline that remains within normal variation

Avast's valid recommendation coverage fell 4.3 points, from 56.8% in July 2026 to 52.5% in October 2026, which is inside the significance threshold for the brand. It shares with McAfee the longest active decline streak in the series at three consecutive monthly declines, though its cumulative move remains within normal variation; the prior-to-current movement from September 2026 was 0.4 points.

Its raw mention presence was effectively flat at 73.8% against 74.2% in July 2026, while its top-three rate rose 3.8 points to 22.2% and its rank-one rate fell 0.9 points to 1.7%. Valid recommendation count fell from 365 in July 2026 to 338 in October 2026.

The distinction is between a slow drift and a break: Avast continues to convert its prominent presence into top-three placements at a rising rate even as its overall coverage slips. Net sentiment held at 0.8 in both months, and the movement remains within the range the benchmark treats as normal variation.

Highest-priority diagnostic: Whether the three-month drift is concentrated in a specific surface family or is spread evenly across the benchmark.

Competitive repositioning: Gaps at the top and in the middle widened over the series

The gap between Bitdefender GravityZone and McAfee widened by 18.0 points across the series, from 19.4 points in July 2026 to 37.4 points in October 2026, without widening every month. The gap between Bitdefender GravityZone and Kaspersky widened by 12.3 points, from 33.7 to 46.0, also without widening every month. The gap between Malwarebytes and McAfee widened by 11.6 points, from 15.1 to 26.7, and widened in every month of the series.

These are category observations about the field's internal spacing rather than a single brand's problem. The middle of the field is separating from the bottom, and the top is separating from the middle, with the widest and most consistent movement occurring between Malwarebytes and McAfee.

Highest-priority diagnostic: Whether the widening gaps reflect sustained prompt-level shifts or a small number of high-frequency prompt families moving each month.

Buyer-Intent Interpretation

Buyer-intent cluster

What it captures

Strategic question

Brand Recommendation

Prompts asking which antivirus software to choose

Which brand does AI recommend for a specific use case?

Pricing & Value

Prompts comparing cost, plans, and value for money

How does price factor into AI recommendations?

Multi-Brand Comparison

Prompts asking for head-to-head comparisons

Which brand wins direct comparisons in AI answers?

All 644 qualified observations in October 2026 fell into the Brand Recommendation cluster. The benchmark did not capture qualified observations in the Pricing & Value or Multi-Brand Comparison clusters, so the public data cannot yet answer questions about how price sensitivity or direct brand-versus-brand comparisons shape AI recommendations. The commercial implication is that the benchmark measures which brand AI names as the answer, but not why it wins on cost, plan structure, or feature comparisons.

Brand Opportunity Summary

Brand

Oct 2026 coverage

Current signal

Highest-priority diagnostic

Bitdefender GravityZone

69.9%

Leader, significant riser

Which surfaces drove the September-to-October recovery?

Norton

65.7%

Second, recovered from prior month

Which surfaces weaken its rank-one share?

Malwarebytes

59.2%

Third, stable

Which prompts keep coverage above 59%?

Avast

52.5%

Three-month drift, within variation

Which surface family holds the drift?

ESET

48.3%

Stable, mid-tier

Where is top-three strength not converting to coverage?

AVG

40.7%

Stable, significant top-three rise

Which prompts keep it out of rank-one placement?

McAfee

32.5%

Significant three-month decline

Which prompts stopped surfacing the brand?

Kaspersky

23.9%

Significant decline, presence-led

Which brand absorbed its lost placements?

Trend Micro

13.7%

Stable, low coverage

Which niche prompts still surface the brand?

Webroot

7.4%

Significant decline, minimal presence

Which prompts mention the brand at all?

The benchmark identifies where attention is warranted; a company-level analysis is needed to explain why.

Evidence Behind the Benchmark

The aggregate metrics are built from prompt-level observations (query, surface, recommendation outcome, rank, sentiment, and citations where exposed). Company-level analysis can go deeper into prompt, competitor, surface, and evidence patterns. Source presence is not automatically treated as proof of causation.

About This Benchmark

This report is part of the AI Visibility Industry Market research program.

Report-Specific Interpretation Notes

  • Brand-level percentages are calculated within the qualified benchmark set, not the raw prompt total, so the qualified denominator differs from the collection volume in each month.
  • Small-count brands show movement from low bases; for example, Webroot's rank-one count moved from 0 in July 2026 to 1 in October 2026, and absolute counts should be read alongside percentages for Kaspersky, Trend Micro, and Webroot.
  • Movement between months identifies changes worth investigating; it does not by itself establish the cause of those changes.
  • The benchmark describes the output distribution AI systems produced this month; it cannot on its own distinguish platform behavior from measurement effects.

Next Step

The Public Benchmark Shows Where a Brand Is Winning or Losing. A Company-Level Audit Shows Why.

Beneath the aggregate percentages sit the questions that matter for strategy: which high-intent prompts are won, which competitor takes the recommendation when a brand loses, what attributes AI associates with each option, and which external sources shape those answers. For Bitdefender GravityZone, the audit question is which prompt families drove both the two-month decline and the October reversal; for McAfee, it is which prompts stopped surfacing the brand; for every brand, it is what the AI systems actually say and cite.

A company-specific AI visibility audit maps those prompt, surface, competitor, ranking, sentiment, and evidence-source patterns into a prioritized visibility strategy.

Request an AI visibility audit

/ Take the next step

Want to Understand Your AI Citation Footprint?

We start every engagement with a full audit of how AI systems reference your brand today.

Measurable, Repeatable Programme

Build a durable foundation of credible citations that compounds over time and continues to influence AI answers as new queries emerge

Citation Architecture Review

Identify which high-authority community sources are and aren't working in your favour across AI platforms.

AI Visibility Audit

Understand exactly how LLMs are referencing your brand today and which sources are shaping those answers.

/ Learn More

Understanding AI search visibility.

AI search experiences create answers by pulling information from many places online and summarizing it into a single response.

What Is AI Citation Intelligence?
AI citation intelligence is the process of measuring where AI platforms source their information and how frequently a brand is mentioned or referenced in AI-generated responses. Because LLMs synthesize across multiple sources, the sites and brands that appear repeatedly tend to influence how a topic or company is framed. This practice focuses on identifying which sources shape AI outputs and tracking brand visibility across different AI systems.
What Is Citation Architecture?
Citation architecture describes the set of sources that consistently inform how AI systems talk about a brand, product, or topic. LLMs draw from websites, articles, forums, and public discussion, and the sources they rely on most often become the backbone of their answers. Building strong citation architecture means ensuring that accurate, credible, high authority sources are the ones most likely to shape the way AI tools summarize and recommend a brand.
What Is Generative Engine Optimization?
Generative engine optimization (GEO) is the practice of improving the chances that AI systems use and cite your brand or content when generating answers. While traditional SEO is centered on ranking pages in search results, GEO focuses on how LLMs retrieve, interpret, and combine information when responding to a question. The objective is to strengthen the content and sources AI systems rely on, so your brand is treated as a trusted reference in AI responses.
What Is AI Share of Voice?
AI share of voice tracks how often a brand appears in AI-generated answers compared with competitors in the same category. It reflects visibility across AI platforms such as ChatGPT, Gemini, Claude, and Perplexity. Monitoring AI share of voice helps organizations see whether AI systems consistently include and recommend their brand for key queries or whether competitor brands are showing up more often.

About The Author

Mark Huntley

Mark Huntley

Founder and CEO

Mark Huntley, J.D. is founder of CiteWorks Studio, a strategic advisory focused on visibility, authority, and recommendation presence in AI-shaped search environments. His work centers on embedding-level GEO, vector optimization, and cosine gap engineering — helping brands align their digital presence with the retrieval systems that increasingly shape discovery, interpretation, and choice.

VIEW ALL CASE STUDIESREQUEST AN AI VISIBILITY AUDIT