How does AEO work for Australian legal, health and finance firms?
The reviews and testimonials most businesses lean on as AI-citation evidence are banned outright for health services and tightly restricted for legal and financial advice, so regulated firms need a different evidence base entirely.

A Melbourne physiotherapist, a Sydney solicitor and a Brisbane mortgage broker have the same problem right now, for three different legal reasons. None of them can publish the kind of client testimonial that AI engines lean on as evidence everywhere else, and all three are starting to notice that a competitor with looser standards, or no licence at all, is getting cited in their place.
I run Outercite, where we track how AI search engines cite Australian businesses across ChatGPT, Claude, Gemini, Perplexity, Grok and DeepSeek. The regulated professions ask us a version of the same question: the standard AEO playbook assumes you can publish reviews, before-and-after stories and client outcomes freely. What do you do when the regulator has banned or fenced off most of that evidence?
What does AEO mean for a regulated Australian professional services firm?
The same goal as anywhere else, getting named as a cited source when someone asks an AI engine a buying question, but built on a narrower evidence base. Health services cannot use testimonials about clinical care at all. Legal and financial advertising must clear a higher bar for accuracy and balance than a typical retail or hospitality business. The generic AEO advice to "publish more reviews" is not just unhelpful here, in health it is advice to break the law.
Key takeaway
For legal, health and finance firms, the compliance rules are not a marketing constraint on top of AEO. They are the actual shape of the problem, because they remove the single most common form of citation evidence other industries rely on.
Why can't professional services firms just use testimonials like everyone else?
Because three different regulators say no, or say something close to it, and each says it differently. Health has an outright statutory ban. Legal advertising is governed by a general truth-in-advertising standard rather than a testimonial-specific rule. Financial services sits in between: testimonials are allowed, but only if they are genuine, current and presented alongside a balanced view of risk.
What does AHPRA actually ban for health practitioners?
Under section 133(1) of the Health Practitioner Regulation National Law, a person must not advertise a regulated health service using testimonials or purported testimonials about the service, full stop, regardless of whether the statements are true (AHPRA, 2026). That covers your own website copy, a client quote in a case study, and a Google review you choose to embed on your site. The maximum penalty for a breach was raised from $5,000 to $60,000 for an individual and from $10,000 to $120,000 for a body corporate, a twelvefold increase now in force in every state and territory (Kennedys Law, 2025). AHPRA tightened this further in September 2025 with an outright ban on influencer testimonials for cosmetic procedures specifically.
What can Australian law firms say about themselves?
Rule 36 of the Australian Solicitors’ Conduct Rules 2015 does not name testimonials, but it requires that any advertising, marketing or promotion not be false, misleading or deceptive, and separately bars a solicitor from claiming to be an "accredited specialist" unless actually accredited by the relevant law society. In practice this means a testimonial is not banned the way it is in health, but a cherry-picked or unverifiable one is a misleading-advertising problem waiting to happen, which is a slower, murkier standard to self-police than a flat prohibition.
What do ASIC's rules mean for financial services firms?
ASIC finalised an updated Regulatory Guide 234 on advertising financial products and services on 9 June 2026, folding in the old guidance on past performance and adding expanded direction on testimonials and celebrity endorsements: they must reflect a genuine, current, informed opinion, and any advertised benefit has to sit alongside a balanced view of the risks rather than being given undue prominence (ASIC, 2026). That is workable, but it is real compliance overhead a plumber posting a five-star review does not carry.
Does this actually change what AI engines cite, or is it just an advertising problem?
It shows up directly in what gets cited, and the clearest evidence is from insurance. An analysis of 2.4 million citation records across 28,725 domains, drawn from Google AI Overviews and ChatGPT’s search feature between November 2025 and July 2026, found that spam and grey-area domains, sites built to simulate legitimate financial guidance with no Australian Financial Services Licence and no accountable business behind them, made up 1.97% of ChatGPT’s Australian insurance citations, against just 0.10% on Google, a nineteen-fold gap between the two engines (Insurance Business, 2026). One unlicensed domain alone was cited 5,366 times, briefly ranking as the thirteenth most-cited source in that category.
Consumer demand for AI-generated financial guidance is not hypothetical either. Research commissioned by the Council of Australian Life Insurers found three in five Australians would rely on AI-generated financial advice when making money decisions, and almost one in five had actually received life insurance advice from a tool such as ChatGPT in the previous quarter (CALI, 2026). Licensed firms that are absent from that conversation are not neutral bystanders. The gap does not stay empty, it fills with whoever the model can find, licensed or not.
Key takeaway
A licensed Australian advice firm being invisible in AI search is not a null result. On the evidence from insurance, the space it leaves gets filled by unlicensed content nineteen times more often on ChatGPT than on Google.
So what can a compliant firm actually publish to get cited?
Everything the rules above do not touch, and it turns out to be most of the material AI engines actually prefer to cite anyway, because engines weight sourced, specific, verifiable content over generic praise. We go into how that evidence gets weighed in how AI decides who to cite; the professional-services version of that list looks like this.
- Answer-first explainers of the questions clients actually ask. "What does a conveyancing settlement cost in NSW" or "when does income protection insurance pay out" are citable answers; a generic services page is not.
- De-identified case outcomes and methodology, not client quotes. "We settled 40 property disputes in FY26 with a median timeline of 11 weeks" is a fact you can defend under any of the three rulebooks; a named client saying you are "the best" is not.
- Verifiable credentials. AHPRA registration numbers, an AFSL number, Law Society accreditation dates, all machine-checkable and none of them a testimonial.
- Regulatory and industry commentary in your own name. Explaining a rule change, like the RG 234 update above, is exactly the kind of source-worthy, dated, factual content models prefer over an opinion.
- Genuine, current, attributed reviews where your profession actually allows them, disclosed and balanced per the ASIC guidance where relevant, never lifted out of context.
How should a professional services firm start?
Start by finding out where you already stand before publishing anything new.
- List the 10 to 15 questions a real client asks before choosing a firm like yours, in plain language, not your marketing copy.
- Run each one against ChatGPT, Claude, Gemini and Perplexity, and note whether you are named, who is named instead, and whether the source cited even holds the relevant licence or registration.
- Audit your own site copy against the rule that actually applies to you: section 133 for health, Rule 36 for legal, RG 234 for financial services. A testimonial banned outright is the easiest fix; a merely non-compliant one is the more common finding.
- Build the evidence types above, credentials, de-identified outcomes, dated regulatory explainers, before chasing volume of content.
- Repeat the prompt set on a schedule rather than once. The Australian businesses that treat AI visibility as an ongoing measurement problem, not a one-off audit, are covered in how do Australian businesses track AI search citations.
On our end, tracking a regulated firm works the same way as tracking any other business: we run real prompts against all six engines on a schedule, and every candidate citation is analysed by a judge model, then confirmed or disputed by an independent verifier model before it counts. Nothing about that pipeline changes for a regulated industry; what changes is what you have available to publish once you know where the gaps are.
Key takeaway
This is general information, not legal, health or financial advice. Confirm current obligations with your own regulator or professional body before changing what you publish.
Sources
- Testimonials banned in advertising a regulated health service under section 133(1) of the Health Practitioner Regulation National Law: AHPRA, 2026.
- Maximum advertising-breach penalty raised from $5,000 to $60,000 (individual) and $10,000 to $120,000 (body corporate): Kennedys Law, 2025.
- ASIC finalised updated Regulatory Guide 234 on advertising financial products and services, including expanded testimonial and celebrity-endorsement guidance, on 9 June 2026: ASIC, 2026.
- Grey-area and spam domains made up 1.97% of ChatGPT’s Australian insurance citations versus 0.10% on Google, from a study of 2.4 million citation records across 28,725 domains: Insurance Business, 2026.
- Three in five Australians would rely on AI-generated financial advice; almost one in five received life insurance advice from an AI tool in the prior quarter: Council of Australian Life Insurers, 2026.
Want to see where your firm actually stands today? Start a 21-day free trial and track your citations across all six engines.

