CiteWorks Studio

How AI Search Is Recommending VPN Services: Monthly Trends

Mark HuntleyBy Mark HuntleyFounder and CEO
8 minutes read

Key Takeaways

  • Proton VPN led September 2026 recommendation coverage at 80.3%, holding first place for a third straight month despite a slight decline.
  • NordVPN and Surfshark remained close behind, with the top tier softening gradually since July rather than shifting dramatically.
  • TunnelBear was the only significant mover in September, falling to 7.4% coverage after a second consecutive monthly decline.
  • Private Internet Access rose to 33.3% coverage, suggesting steady gains in recommendation inclusion and top-three placement.

Executive Summary

Proton VPN remains the coverage leader in September 2026 at 80.3% valid recommendation coverage, a modest 0.4-point dip from August. The gap to second-place NordVPN stands at 3.9 points (80.3% vs 76.4%), with Surfshark close behind at 73.4%. The leader has held the top position across all three months of the series, though the entire top tier has eased lower since July.

TunnelBear is the month's only significant mover, falling 5.0 points from August to 7.4% coverage, down 6.2 points from 13.6% in July. This marks the second consecutive month of decline and places TunnelBear as the standout decliner in an otherwise stable category. Private Internet Access was the strongest upward mover, rising 3.8 points from August to 33.3% coverage, up 3.7 points from 29.6% in July, though the move stayed within normal variation.

Across the three-month series, the category shows a consistent pattern: high presence rates across most tracked brands, with the meaningful competitive differences showing up in how often each brand is actually recommended rather than simply mentioned. The top tier has softened gradually, while the middle tier shows signs of repositioning, most visibly in Private Internet Access's steady climb and TunnelBear's accelerating decline.

Each monthly run begins with 800 prompt-surface observations (534 unique questions in July; 574 in August; 593 in September) across the benchmark's defined AI/search surface universe. Of those, 800 mentioned a tracked brand or competitor in all three months; 798 were relevant and 2 were irrelevant in July, all 800 were relevant in August, and 799 were relevant and 1 was irrelevant in September. The public metrics use the 707 qualified observations in July, 709 in August, and 700 in September that survive both qualification stages.

AI recommendation trend

valid recommendation coverage, Jul 2026 to Sep 2026

0%25%50%75%100%Jul 2026Aug 2026Sep 2026
  • Proton VPN80.3%
  • NordVPN76.4%
  • Surfshark73.4%
  • ExpressVPN69.9%
  • Private Internet Access33.3%
  • Mullvad VPN26.3%
  • Windscribe24.6%
  • CyberGhost VPN17.3%
  • IPVanish9.4%
  • TunnelBear7.4%

Key Findings

Signal

September 2026 finding

Category leader

Proton VPN at 80.3% valid recommendation coverage, down 0.4 points from August

Leader gap

Proton VPN leads NordVPN by 3.9 points (80.3% vs 76.4%)

Largest riser

Private Internet Access up 3.8 points to 33.3% from 29.5% in August

Largest decliner

TunnelBear down 5.0 points to 7.4% from 12.4% in August

Significant movement

TunnelBear was the only brand with a significant move this month; all other nine brands were stable

Qualified surface breadth

All six AI surface families represented in all three months

Benchmark Context

The report separates the raw collection universe from the qualified analysis set. Brand-level recommendation percentages are calculated within the qualified benchmark set.

Research stage

Jul 2026

Sep 2026

What it represents

Source prompt-surface observations collected

800

800

Total prompt-surface observations before qualification

Unique questions

534

593

Distinct questions represented in the run

Brand / competitor mentions

800

800

Prompts mentioning a tracked brand or competitor

Relevant prompts

798

799

Prompts relevant to the benchmark's scope

Irrelevant prompts

2

1

Prompts excluded as not relevant

Qualified benchmark observations

707

700

Public denominator for brand-level metrics

Qualified surface breadth

6

6

AI surface families with at least one qualified observation

The qualified benchmark observations in each column are the denominator used throughout the brand-level tables below.

Benchmark-Level Metrics

Metric

Jul 2026

Sep 2026

Change

Qualified observations

707

700

-7

Companies tracked

10

10

Flat

Recommendation-shaped answer share

51.9%

49.0%

Down 2.9 points

Valid recommendation shortlist share

84.3%

81.0%

Down 3.3 points

Category leader by coverage

Proton VPN (83.9%)

Proton VPN (80.3%)

Stable

The recommendation-shaped answer share and valid recommendation shortlist share both trended lower across the series, with August (50.6% and 81.5%) sitting between the July and September levels. Coverage rates for most tracked brands also softened across the same period, though the benchmark cannot establish a causal relationship between these two trends.

AI Recommendation Trend

The category structure held steady in September, with Proton VPN maintaining leadership for a third consecutive month despite a gradual decline in its coverage rate. No brand outside TunnelBear moved beyond normal month-to-month variation, leaving the competitive tiers largely intact.

Recommendation Coverage by Brand

Brand

Jul 2026

Sep 2026

Movement

Sep 2026 rank

CyberGhost VPN

16.7%

17.3%

Up 0.6 points

9th

ExpressVPN

71.0%

69.9%

Down 1.1 points

4th

IPVanish

9.0%

9.4%

Up 0.4 points

10th

Mullvad VPN

29.1%

26.3%

Down 2.8 points

7th

NordVPN

80.1%

76.4%

Down 3.7 points

2nd

Private Internet Access

29.6%

33.3%

Up 3.7 points

5th

Proton VPN

83.9%

80.3%

Down 3.6 points

1st

Surfshark

77.1%

73.4%

Down 3.7 points

3rd

TunnelBear

13.6%

7.4%

Down 6.2 points

8th

Windscribe

25.9%

24.6%

Down 1.3 points

6th

TunnelBear was the only brand to exceed normal month-to-month variation in September. The rest of the category moved in smaller increments, with the most visible pattern being a slow convergence between the top tier and the middle tier while leaders eased and Private Internet Access climbed.

What Changed This Month

Proton VPN: Leader Holds With Narrowing Lead

Proton VPN remained the coverage leader at 80.3% in September, down 3.6 points from 83.9% in July and essentially flat against August's 80.7%. The two-month decline stayed within normal month-to-month variation.

Presence remained strong at 96.3%, up 1.0 point from 95.3% in July, while top-three recommendation rate slipped 1.4 points to 45.0% from 46.4%. Rank-one rate fell 2.4 points to 12.7% from 15.1%. Valid recommendation count was 562 out of 700 qualified observations, down from 593 out of 707.

The distinction to notice: Proton VPN's coverage lead now rests on consistent recommendation across a broad set of prompts rather than on dominance in first position, where NordVPN holds a 47.7% rank-one rate versus Proton VPN's 12.7%.

Highest-priority diagnostic: Which prompt patterns moved Proton VPN out of the top three, and which competitor absorbed those placements?

TunnelBear: Significant Two-Month Decline

TunnelBear was the only significant mover in September, with coverage falling 6.2 points from 13.6% in July to 7.4%, including a 5.0-point drop from August's 12.4%. The decline is spread across multiple signals.

Presence fell sharply, down 8.2 points from 18.7% in July to 10.4%, and top-three rate dropped 2.2 points from 4.5% to 2.3%. Valid recommendation count fell to 52 out of 700 observations, down from 96 out of 707 in July and 88 out of 709 in August. Rank-one placements remain negligible at 0.1%, though sentiment held steady at 0.7.

The distinction to notice: TunnelBear is losing recommendation credit across the board, with the decline concentrated in reduced presence rather than a shift in placement quality. The small absolute counts mean each placement carries outsized weight in the percentage movement.

Highest-priority diagnostic: Which prompt categories stopped surfacing TunnelBear altogether, and which competitors now occupy the recommendations it previously held?

Private Internet Access: Steady Climb Continues

Private Internet Access was the strongest upward mover, rising 3.8 points from August to 33.3% coverage in September, up 3.7 points from 29.6% in July. The move stayed within normal month-to-month variation but represents a consistent upward trajectory across the series.

Presence rose 3.7 points from 38.8% in July to 42.4%, and top-three rate improved 2.5 points from 3.7% to 6.1%. Rank-one rate edged up 0.3 points to 1.0%. Valid recommendation count climbed to 233 out of 700 observations, up from 209 out of 707 in July.

The distinction to notice: Private Internet Access is gaining coverage through both broader presence and improved top-three placement, though its rank-one rate remains low at 1.0%, meaning the gains are coming from secondary and tertiary positions.

Highest-priority diagnostic: Which prompts newly include Private Internet Access in their recommendation sets, and what attributes are driving the improved top-three placement?

NordVPN and Surfshark: Parallel Softening

NordVPN and Surfshark followed nearly identical trajectories in September, each down 3.7 points from July (NordVPN to 76.4% from 80.1%; Surfshark to 73.4% from 77.1%). Both saw 0.7-point declines from August.

NordVPN's presence held essentially universal at 99.3%, and its top-three rate actually improved 1.3 points to 65.1% from 63.8% in July. Surfshark's presence rose 1.9 points to 95.0%, while its top-three rate slipped 1.5 points to 54.0%. NordVPN's rank-one rate improved 0.5 points to 47.7%, while Surfshark's fell 0.8 points to 5.7%.

The distinction to notice: Both brands are being mentioned in nearly every response, but the coverage decline reflects which prompts recommend them at all, not how often they appear. NordVPN's strength in first position remains the category's defining single-brand signal.

Highest-priority diagnostic: Which prompt types no longer produce a NordVPN or Surfshark recommendation even though the brand is mentioned?

Buyer-Intent Interpretation

Buyer-intent cluster

What it captures

Strategic question

Brand Recommendation

Prompts seeking a recommended VPN provider

Which brand owns the default answer across different use cases?

Pricing & Value

Prompts focused on cost, plans, and value comparisons

How do price perceptions shape which brand gets recommended?

Multi-Brand Comparison

Prompts asking for head-to-head comparisons

Which brand wins when two or more options are weighed directly?

All 700 qualified observations in September fell into the Brand Recommendation cluster, matching the pattern in July and August where all observations also landed there. The public benchmark therefore cannot yet answer questions about how pricing, value, or direct head-to-head comparisons influence which VPN brand AI systems recommend. The current evidence captures which brand is recommended, not why it wins on cost or comparison grounds.

Brand Opportunity Summary

Brand

Sep 2026 coverage

Current signal

Highest-priority diagnostic

CyberGhost VPN

17.3%

Stable; rank-one rate up 2.1 points to 3.1%

Which prompts newly placed CyberGhost in first position?

ExpressVPN

69.9%

Recovered 2.5 points from August decline

Which prompts restored ExpressVPN to recommendation lists?

IPVanish

9.4%

Stable; rank-one rate at 0.0%

Which prompt conditions, if any, produce an IPVanish recommendation?

Mullvad VPN

26.3%

Coverage down 2.8 points from July; sentiment strong at 0.9

Which prompts shifted away from Mullvad despite high sentiment?

NordVPN

76.4%

Leader gap at 3.9 points; rank-one rate up to 47.7%

Which prompts moved NordVPN out of recommendation sets entirely?

Private Internet Access

33.3%

Strongest riser; top-three rate up 2.5 points

Which prompts drove the improved top-three placement?

Proton VPN

80.3%

Leader for third month; rank-one rate down 2.4 points

Which prompts moved Proton VPN out of the top three?

Surfshark

73.4%

Coverage down 3.7 points from July; presence up

Which prompts mention Surfshark but do not recommend it?

TunnelBear

7.4%

Significant decliner; coverage down 6.2 points

Which prompts stopped surfacing TunnelBear altogether?

Windscribe

24.6%

Coverage down 3.0 points from August

Which prompts removed Windscribe from recommendation lists?

The benchmark identifies where attention is warranted; a company-level analysis is needed to explain why these patterns are emerging.

Evidence Behind the Benchmark

The aggregate metrics are built from prompt-level observations (query, surface, recommendation outcome, rank, sentiment, and citations where exposed). Company-level analysis can go deeper into prompt, competitor, surface, and evidence patterns. Source presence is not automatically treated as proof of causation.

About This Benchmark

This report is part of the LLM Authority Index AI Market Discovery research program.

Report-Specific Interpretation Notes

  • Only TunnelBear moved beyond normal month-to-month variation in September, marking the first significant movement recorded in this three-month series. The remaining nine brands were classified as stable.
  • Brand-level percentages use the qualified benchmark set (700 observations in September), not the raw collection universe of 800 prompts.
  • Directional analysis identifies movements worth investigating; it does not by itself establish the cause of those movements.
  • Small absolute counts apply to lower-coverage brands such as TunnelBear (52 valid recommendations), IPVanish (66), and CyberGhost VPN (121). Interpret percentage movement for these brands with the counts in view.

Next Step

The Public Benchmark Shows Where a Brand Is Winning or Losing. A Company-Level Audit Shows Why.

The aggregate percentages raise questions that the benchmark alone cannot answer: which high-intent prompts is a brand winning or losing, which competitor takes the recommendation when a brand loses, what attributes do AI systems associate with each option, and which external sources shape those answers.

A company-specific AI visibility audit maps those prompt, surface, competitor, ranking, sentiment, and evidence-source patterns into a prioritized visibility strategy.

Request an AI visibility audit

/ Take the next step

Want to Understand Your AI Citation Footprint?

We start every engagement with a full audit of how AI systems reference your brand today.

Measurable, Repeatable Programme

Build a durable foundation of credible citations that compounds over time and continues to influence AI answers as new queries emerge

Citation Architecture Review

Identify which high-authority community sources are and aren't working in your favour across AI platforms.

AI Visibility Audit

Understand exactly how LLMs are referencing your brand today and which sources are shaping those answers.

/ Learn More

Understanding AI search visibility.

AI search experiences create answers by pulling information from many places online and summarizing it into a single response.

What Is AI Citation Intelligence?
AI citation intelligence is the process of measuring where AI platforms source their information and how frequently a brand is mentioned or referenced in AI-generated responses. Because LLMs synthesize across multiple sources, the sites and brands that appear repeatedly tend to influence how a topic or company is framed. This practice focuses on identifying which sources shape AI outputs and tracking brand visibility across different AI systems.
What Is Citation Architecture?
Citation architecture describes the set of sources that consistently inform how AI systems talk about a brand, product, or topic. LLMs draw from websites, articles, forums, and public discussion, and the sources they rely on most often become the backbone of their answers. Building strong citation architecture means ensuring that accurate, credible, high authority sources are the ones most likely to shape the way AI tools summarize and recommend a brand.
What Is Generative Engine Optimization?
Generative engine optimization (GEO) is the practice of improving the chances that AI systems use and cite your brand or content when generating answers. While traditional SEO is centered on ranking pages in search results, GEO focuses on how LLMs retrieve, interpret, and combine information when responding to a question. The objective is to strengthen the content and sources AI systems rely on, so your brand is treated as a trusted reference in AI responses.
What Is AI Share of Voice?
AI share of voice tracks how often a brand appears in AI-generated answers compared with competitors in the same category. It reflects visibility across AI platforms such as ChatGPT, Gemini, Claude, and Perplexity. Monitoring AI share of voice helps organizations see whether AI systems consistently include and recommend their brand for key queries or whether competitor brands are showing up more often.

About The Author

Mark Huntley

Mark Huntley

Founder and CEO

Mark Huntley, J.D. is founder of CiteWorks Studio, a strategic advisory focused on visibility, authority, and recommendation presence in AI-shaped search environments. His work centers on embedding-level GEO, vector optimization, and cosine gap engineering — helping brands align their digital presence with the retrieval systems that increasingly shape discovery, interpretation, and choice.

VIEW ALL CASE STUDIESREQUEST AN AI VISIBILITY AUDIT