Articles

Geo-blocking, VPN blocks and AI agents

Usually fixed by: Bot protection or CDN admin

A shopper in Manchester asks an AI assistant about your store. The assistant doesn't visit from Manchester. It visits from a cloud data center, quite possibly in another country. If your site blocks, challenges or redirects visitors by location or network, that one fact can decide whether the assistant sees your real store, the wrong store, or nothing at all.

Where AI agents actually come from

When a person asks an assistant a question, the page request doesn't come from their phone or laptop. It comes from the assistant's servers. The same is true for AI search crawlers and for browser agents that run in the cloud. That has three consequences:

  • The country is the server's, not the shopper's. Agent traffic is concentrated in the regions where AI companies run their infrastructure. Those are rarely the same as your customers' locations.
  • The network is a data center. Agent requests come from cloud and hosting providers, the same networks that a lot of abusive automation uses. Reputation lists often score them as high risk.
  • Addresses change. Agents that run on shared cloud infrastructure don't always come from fixed, published IP ranges.

None of this is a sign of bad intent. It's simply how AI agents work. But it means rules written with human visitors in mind can treat agents very differently from the people they're acting for.

Four rules that catch agents

Country blocks

Some sites block whole countries, often to cut fraud or because they don't ship there. If an assistant's servers sit in a blocked country, every request it makes for every shopper is turned away, including shoppers in countries you serve.

VPN, proxy and data center blocks

Blocking "anonymizing" networks or hosting providers is a common anti-fraud and anti-scraping setting. It catches nearly all AI agent traffic, because nearly all of it comes from hosting providers. It's one of the most common reasons an assistant can reach a competitor's site but not yours.

Automatic geo-redirects

Many international stores redirect visitors to a country site based on IP address. An agent fetching your UK product page for a UK shopper may be sent to your US site instead, then quote US prices, US stock and US delivery times. The answer looks confident and is wrong. Some redirects go to a country picker page, which leaves the agent with no product at all.

Location-based content

Some sites quietly change prices, currency, product ranges or policies based on the visitor's location, without changing the URL. An agent then describes a version of your store the shopper will never see.

What to do instead

The aim is to keep the protection you need while letting verified agents see the right content.

1. Separate legal requirements from preferences

Some location rules are required: sanctions, licensing, or content you're not allowed to show in certain places. Keep those, and get advice on how they apply to automated visitors. Many others are preferences, such as "we don't ship there, so block it". For those, ask whether blocking the server's location actually achieves anything. You already check the delivery address at checkout, which is where a shipping restriction belongs.

2. Let verified agents past location and network rules

Most CDNs and bot management tools can tell verified bots apart from other traffic. Add an exception so that verified AI assistants and AI search agents skip the country, VPN and data center rules that are about fraud or scraping. Put it in the right place in your rule order, and never base it on the user agent alone. Our guide to setting up your CDN for AI agents covers rule order, and telling real AI crawlers from fakes covers verification.

Don't allow whole cloud providers. Lifting a data center block for an entire cloud network lets in every scraper hosted there. Allow verified agents, and keep the block for everything else.

3. Let the URL decide the country, not the IP address

Give each country or language its own URL, such as northwind.example/en-gb/ or uk.northwind.example, and serve the content that URL promises, whoever asks. If you want to steer people to their local site, show a banner suggesting it instead of redirecting. Agents and people can then follow the link that matches the shopper. Mark the alternatives with hreflang so agents and search engines can find them:

<link rel="alternate" hreflang="en-gb" href="https://northwind.example/en-gb/boots/trail-runner/">
<link rel="alternate" hreflang="en-us" href="https://northwind.example/en-us/boots/trail-runner/">
<link rel="alternate" hreflang="x-default" href="https://northwind.example/boots/trail-runner/">

Our guide to languages, currencies and regions goes further on international setups.

4. Make the default page useful

Some agents will still land on your default site. Make sure it's a real store, not a country picker. State which country and currency the prices are in, and link clearly to the other country sites. Put the same information in your structured data, so an agent knows the price it read is in US dollars and not pounds. See machine-readable prices.

5. Use rate limits for the rest

For traffic you can't verify, from data centers or anywhere else, rate limits are usually a better tool than outright blocks. They stop bulk scraping while still letting through a small number of requests made on someone's behalf. See rate limits for AI agents.

How to find out if this affects you

Look forWhereWhat it suggests
Country, ASN, "hosting" or "anonymous proxy" rulesCDN, WAF or bot management settingsAgents may be blocked or challenged by location or network
Redirects based on IP countryCDN rules, e-commerce platform settings, geolocation apps or pluginsAgents may see the wrong country's store
403s, challenges or 302 redirects for ChatGPT-User, Claude-User or Perplexity-UserCDN or server logsReal agent visits are being turned away or sent elsewhere
Assistants quoting the wrong currency or pricesAsk a few assistants about your productsA redirect or location-based content is reaching agents

An AgentScore scan helps too. Its requests come from cloud servers, like real agents' requests do, and it compares what AI agents get from your home page, product, pricing and cart pages with what a normal browser gets from the same servers. It can't show what visitors in every country see, so a block that only applies to certain countries may not show up. Pair it with a look at your rules and logs. Our guide to finding the errors AI agents hit in your logs shows how to pull out agent requests and their status codes.

A short checklist

  1. List every location and network rule on your CDN, WAF, bot tool and e-commerce platform, and note which are legally required.
  2. Add an exception for verified AI assistants and AI search agents to the rules that aren't.
  3. Replace automatic IP redirects with country URLs, hreflang and a suggestion banner.
  4. Make sure your default site shows real products, with the currency and country stated.
  5. Check your logs for agent requests that get 403s, challenges or redirects, and re-run AgentScore after each change.
← All articles Test your site with AgentScore →

Can AI agents use your site?

Get your free AgentScore in under a minute. No sign-up needed.