CiteWorks Studio

How AI Search Is Recommending VPN Services: Monthly Trends

Mark HuntleyBy Mark HuntleyFounder and CEO
8 minutes read

Key Takeaways

  • Proton VPN remained the category leader in August 2026 at 80.7% recommendation coverage, with NordVPN second at 77.1% and the lead gap narrowing slightly to 3.6 points.
  • No tracked VPN brand showed movement beyond normal month-to-month variation, indicating a stable competitive structure despite softer coverage across the top tier.
  • ExpressVPN posted the largest decline, falling 3.6 points to 67.4%, while Windscribe was the only brand to gain coverage, rising 1.7 points to 27.6%.
  • The benchmark reflects 709 qualified observations, and all qualified prompts fell into the Brand Recommendation cluster, limiting insight into pricing, value, or direct comparison behavior.

Executive Summary

The VPN Services category was quiet in August 2026. Proton VPN led valid recommendation coverage at 80.7%, down 3.2 points from 83.9% in July, with NordVPN close behind at 77.1% (down 3.0 points from 80.1%). No brand moved beyond normal month-to-month variation, and the category held a stable competitive structure with the same leader for a second consecutive month.

Windscribe was the only brand to gain coverage, rising 1.7 points to 27.6% from 25.9% in July, though the move stayed within normal variation. ExpressVPN saw the sharpest absolute decline, down 3.6 points to 67.4% from 71.0%, also within normal bounds. The overall picture is broad, modest softening across the top tier rather than a single decisive shift.

Across the full series, Proton VPN has held the leadership position in both months, while the gap to second place narrowed from 3.8 points in July to 3.6 points in August. The category is marked by high presence rates across most tracked brands, with the meaningful differences showing up in how often each brand is actually recommended rather than simply mentioned.

Each monthly run begins with 800 prompt-surface observations (534 unique questions in July; 574 in August) across the benchmark's defined AI/search surface universe. Of those, 800 mentioned a tracked brand or competitor in both months; 798 were relevant and 2 were irrelevant in July, while all 800 were relevant in August. The public metrics use the 707 qualified observations in July and 709 in August that survive both qualification stages.

AI recommendation trend

valid recommendation coverage, Jul 2026 to Aug 2026

  • Proton VPN-3.2%
    Jul 202683.9%
    Aug 202680.7%
  • NordVPN-3.0%
    Jul 202680.1%
    Aug 202677.1%
  • Surfshark-3.0%
    Jul 202677.1%
    Aug 202674.1%
  • ExpressVPN-3.6%
    Jul 202671.0%
    Aug 202667.4%
  • Private Internet Access-0.1%
    Jul 202629.6%
    Aug 202629.5%
  • Windscribe+1.7%
    Jul 202625.9%
    Aug 202627.6%
  • Mullvad VPN-3.4%
    Jul 202629.1%
    Aug 202625.7%
  • CyberGhost VPN-0.3%
    Jul 202616.7%
    Aug 202616.4%
  • TunnelBear-1.2%
    Jul 202613.6%
    Aug 202612.4%
  • IPVanish-1.8%
    Jul 20269.0%
    Aug 20267.2%

Key Findings

Signal

August 2026 finding

Category leader

Proton VPN at 80.7% valid recommendation coverage, down 3.2 points from July

Leader gap

Proton VPN leads NordVPN by 3.6 points (80.7% vs 77.1%)

Largest riser

Windscribe up 1.7 points to 27.6% coverage from 25.9%

Largest decliner

ExpressVPN down 3.6 points to 67.4% from 71.0%

Significant movement

None; all ten tracked brands classified as stable

Qualified surface breadth

All six AI surface families represented in both months

Benchmark Context

The report separates the raw collection universe from the qualified analysis set. Brand-level recommendation percentages are calculated within the qualified benchmark set.

Research stage

Jul 2026

Aug 2026

What it represents

Source prompt-surface observations collected

800

800

Total prompt-surface observations before qualification

Unique questions

534

574

Distinct questions represented in the run

Brand / competitor mentions

800

800

Prompts mentioning a tracked brand or competitor

Relevant prompts

798

800

Prompts relevant to the benchmark's scope

Irrelevant prompts

2

0

Prompts excluded as not relevant

Qualified benchmark observations

707

709

Public denominator for brand-level metrics

Qualified surface breadth

6

6

AI surface families with at least one qualified observation

The qualified benchmark observations in each column are the denominator used throughout the brand-level tables below.

Benchmark-Level Metrics

Metric

Jul 2026

Aug 2026

Change

Qualified observations

707

709

+2

Companies tracked

10

10

Flat

Recommendation-shaped answer share

51.9%

50.6%

Down 1.3 points

Valid recommendation shortlist share

84.3%

81.5%

Down 2.8 points

Category leader by coverage

Proton VPN (83.9%)

Proton VPN (80.7%)

Stable

The recommendation-shaped answer share and valid recommendation shortlist share both edged lower in August, which suggests the qualified set carried slightly fewer structured recommendation formats than in July. The decline in the shortlist share is consistent with the broad softening in coverage rates across most brands in the same month.

AI Recommendation Trend

The competitive structure held steady in August with Proton VPN maintaining the leadership position, though the entire top tier eased lower in lockstep. No brand broke out of the pack, and no brand fell out of its established tier.

Recommendation Coverage by Brand

Brand

Jul 2026

Aug 2026

Movement

Aug 2026 rank

CyberGhost VPN

16.7%

16.4%

Down 0.3 points

8th

ExpressVPN

71.0%

67.4%

Down 3.6 points

4th

IPVanish

9.0%

7.2%

Down 1.8 points

10th

Mullvad VPN

29.1%

25.7%

Down 3.4 points

7th

NordVPN

80.1%

77.1%

Down 3.0 points

2nd

Private Internet Access

29.6%

29.5%

Down 0.1 points

5th

Proton VPN

83.9%

80.7%

Down 3.2 points

1st

Surfshark

77.1%

74.1%

Down 3.0 points

3rd

TunnelBear

13.6%

12.4%

Down 1.2 points

9th

Windscribe

25.9%

27.6%

Up 1.7 points

6th

No single brand exceeded normal month-to-month variation in August. The category-level movement came from the combination of several smaller declines across the top tier, with only Windscribe moving against the prevailing direction.

What Changed This Month

Proton VPN: Leader Holds, Gap Narrows Slightly

Proton VPN remained the coverage leader at 80.7% in August, down 3.2 points from 83.9% in July. The decline was the second largest absolute move in the category but stayed below the significance threshold.

Presence remained strong at 95.8%, up 0.5 points from 95.3%, while top-three recommendation rate slipped 1.0 point to 45.4% from 46.4%. Rank-one rate held nearly flat at 14.8% versus 15.1%. Valid recommendation count was 572 out of 709 qualified observations, down from 593 out of 707.

The distinction to notice: Proton VPN's presence is nearly universal, but its lead now rests on being recommended frequently rather than on being the default first choice, where NordVPN holds a commanding 44.1% rank-one rate.

Highest-priority diagnostic: Which prompt patterns still place Proton VPN outside the top three, and which competitor takes the recommendation when it loses that position?

NordVPN: Strong Presence, Slipping Rank-One Position

NordVPN held second place at 77.1% coverage in August, down 3.0 points from 80.1% in July. Presence was essentially universal at 99.2%, up 0.2 points from 99.0%.

The sharper story is rank-one rate, which fell 3.1 points to 44.1% from 47.2% in July, while top-three rate slipped 1.2 points to 62.6% from 63.8%. Valid recommendation count was 547, down from 566. Despite the coverage decline, NordVPN still claims the default recommendation in nearly half of all qualified observations, with 313 rank-one placements.

The distinction to notice: NordVPN is mentioned in almost every response but is losing some first-position placements even as its top-three position holds relatively firm.

Highest-priority diagnostic: Which prompt types shifted away from NordVPN as the first recommendation, and what surfaced in its place?

ExpressVPN: Largest Absolute Decline

ExpressVPN saw the largest absolute coverage decline in August, down 3.6 points to 67.4% from 71.0% in July, though the move stayed below the significance threshold. Presence also slipped 1.6 points to 90.0% from 91.6%.

Top-three rate fell 3.1 points to 33.0% from 36.1%, while rank-one rate actually improved slightly, up 0.3 points to 7.8% from 7.5%. Valid recommendation count was 478, down from 502.

The distinction to notice: ExpressVPN is losing presence and top-three placement but holding its small share of first-position recommendations, suggesting its decline is about breadth of recommendation rather than loss of its highest-value spots.

Highest-priority diagnostic: Which prompts stopped recommending ExpressVPN altogether, and which brands absorbed those placements?

Windscribe: Only Riser

Windscribe was the only brand to gain coverage in August, up 1.7 points to 27.6% from 25.9% in July, though the move stayed below the significance threshold. Presence was essentially flat at 36.5% versus 36.8%.

Top-three rate slipped 0.8 points to 10.4% from 11.2%, and rank-one rate fell 0.6 points to 0.4% from 1.0%. Valid recommendation count was 196, up from 183. Net sentiment improved from 0.7 to 0.8.

The distinction to notice: Windscribe gained coverage while losing top-three and rank-one positions, meaning the additional recommendations are coming at lower placements rather than higher ones.

Highest-priority diagnostic: Which prompts newly included Windscribe in a recommendation list, and at what position did it appear?

Buyer-Intent Interpretation

Buyer-intent cluster

What it captures

Strategic question

Brand Recommendation

Prompts seeking a recommended VPN provider

Which brand owns the default answer across different use cases?

Pricing & Value

Prompts focused on cost, plans, and value comparisons

How do price perceptions shape which brand gets recommended?

Multi-Brand Comparison

Prompts asking for head-to-head comparisons

Which brand wins when two or more options are weighed directly?

All 709 qualified observations in August fell into the Brand Recommendation cluster, matching July's pattern where all 707 observations also landed there. The public benchmark therefore cannot yet answer questions about how pricing, value, or direct head-to-head comparisons influence which VPN brand AI systems recommend. The current evidence captures which brand is recommended, not why it wins on cost or comparison grounds.

Brand Opportunity Summary

Brand

Aug 2026 coverage

Current signal

Highest-priority diagnostic

CyberGhost VPN

16.4%

Stable; rank-one rate improved 1.1 points to 2.1%

Which prompts newly surfaced CyberGhost in first position?

ExpressVPN

67.4%

Largest absolute decline, down 3.6 points

Which prompts dropped ExpressVPN from recommendation lists?

IPVanish

7.2%

Steady decline; rank-one rate at 0.0%

Which prompt conditions, if any, produce an IPVanish recommendation?

Mullvad VPN

25.7%

Coverage down 3.4 points; sentiment strong at 0.9

Which prompts shifted away from Mullvad despite high sentiment?

NordVPN

77.1%

Rank-one rate down 3.1 points to 44.1%

Which prompts moved NordVPN from first to a lower placement?

Private Internet Access

29.5%

Essentially flat; rank-one rate up 0.9 points

Which prompts improved PIA's first-position placements?

Proton VPN

80.7%

Leader; coverage down 3.2 points

Which prompts moved Proton VPN out of the top three?

Surfshark

74.1%

Coverage down 3.0 points; presence up 1.0 point

Which prompts kept Surfshark mentioned but not recommended?

TunnelBear

12.4%

Coverage down 1.2 points; top-three rate down 1.8 points

Which prompts reduced TunnelBear's top-three presence?

Windscribe

27.6%

Only riser, up 1.7 points

Which prompts added Windscribe at lower placements?

The benchmark identifies where attention is warranted; a company-level analysis is needed to explain why these patterns are emerging.

Evidence Behind the Benchmark

The aggregate metrics are built from prompt-level observations (query, surface, recommendation outcome, rank, sentiment, and citations where exposed). Company-level analysis can go deeper into prompt, competitor, surface, and evidence patterns. Source presence is not automatically treated as proof of causation.

About This Benchmark

This report is part of the AI Market Discovery research program.

Report-Specific Interpretation Notes

  • All ten brands were classified as stable in August, meaning no movement exceeded the significance threshold. The category-level softening came from the combination of several smaller declines.
  • Brand-level percentages use the qualified benchmark set (709 observations in August), not the raw collection universe of 800 prompts.
  • Directional analysis identifies movements worth investigating; it does not by itself establish the cause of those movements.
  • Small absolute counts apply to lower-coverage brands such as IPVanish (51 valid recommendations), TunnelBear (88), and CyberGhost VPN (116). Interpret percentage movement for these brands with the counts in view.

Next Step

The Public Benchmark Shows Where a Brand Is Winning or Losing. A Company-Level Audit Shows Why.

The aggregate percentages raise questions that the benchmark alone cannot answer: which high-intent prompts is a brand winning or losing, which competitor takes the recommendation when a brand loses, what attributes do AI systems associate with each option, and which external sources shape those answers.

A company-specific AI visibility audit maps those prompt, surface, competitor, ranking, sentiment, and evidence-source patterns into a prioritized visibility strategy.

Request an AI visibility audit

/ Take the next step

Want to Understand Your AI Citation Footprint?

We start every engagement with a full audit of how AI systems reference your brand today.

Measurable, Repeatable Programme

Build a durable foundation of credible citations that compounds over time and continues to influence AI answers as new queries emerge

Citation Architecture Review

Identify which high-authority community sources are and aren't working in your favour across AI platforms.

AI Visibility Audit

Understand exactly how LLMs are referencing your brand today and which sources are shaping those answers.

/ Learn More

Understanding AI search visibility.

AI search experiences create answers by pulling information from many places online and summarizing it into a single response.

What Is AI Citation Intelligence?
AI citation intelligence is the process of measuring where AI platforms source their information and how frequently a brand is mentioned or referenced in AI-generated responses. Because LLMs synthesize across multiple sources, the sites and brands that appear repeatedly tend to influence how a topic or company is framed. This practice focuses on identifying which sources shape AI outputs and tracking brand visibility across different AI systems.
What Is Citation Architecture?
Citation architecture describes the set of sources that consistently inform how AI systems talk about a brand, product, or topic. LLMs draw from websites, articles, forums, and public discussion, and the sources they rely on most often become the backbone of their answers. Building strong citation architecture means ensuring that accurate, credible, high authority sources are the ones most likely to shape the way AI tools summarize and recommend a brand.
What Is Generative Engine Optimization?
Generative engine optimization (GEO) is the practice of improving the chances that AI systems use and cite your brand or content when generating answers. While traditional SEO is centered on ranking pages in search results, GEO focuses on how LLMs retrieve, interpret, and combine information when responding to a question. The objective is to strengthen the content and sources AI systems rely on, so your brand is treated as a trusted reference in AI responses.
What Is AI Share of Voice?
AI share of voice tracks how often a brand appears in AI-generated answers compared with competitors in the same category. It reflects visibility across AI platforms such as ChatGPT, Gemini, Claude, and Perplexity. Monitoring AI share of voice helps organizations see whether AI systems consistently include and recommend their brand for key queries or whether competitor brands are showing up more often.

About The Author

Mark Huntley

Mark Huntley

Founder and CEO

Mark Huntley, J.D. is founder of CiteWorks Studio, a strategic advisory focused on visibility, authority, and recommendation presence in AI-shaped search environments. His work centers on embedding-level GEO, vector optimization, and cosine gap engineering — helping brands align their digital presence with the retrieval systems that increasingly shape discovery, interpretation, and choice.

VIEW ALL CASE STUDIESREQUEST AN AI VISIBILITY AUDIT