<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/assets/feed.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Ghost Agent Labs blog</title>
    <link>https://ghostagentlab.com/blog/</link>
    <atom:link href="https://ghostagentlab.com/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <description>News, research and opinion on how AI agents use websites.</description>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 13:24:00 +0000</lastBuildDate>
    <image>
      <url>https://ghostagentlab.com/assets/feed-icon-144.png</url>
      <title>Ghost Agent Labs blog</title>
      <link>https://ghostagentlab.com/blog/</link>
      <width>144</width>
      <height>144</height>
    </image>
    <item>
      <title>What scanning 600 stores taught us about our own scanner</title>
      <link>https://ghostagentlab.com/blog/what-scanning-600-stores-taught-us/</link>
      <guid>https://ghostagentlab.com/blog/what-scanning-600-stores-taught-us/</guid>
      <pubDate>Fri, 09 Oct 2026 13:24:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Engineering</category>
      <description>Running AgentScore on 600 real stores exposed three bugs in our own scanner, and one run that looked perfect because almost nothing was tested. What we found, fixed and changed.</description>
      <content:encoded><![CDATA[<p>To write <a href="https://ghostagentlab.com/blog/agentscore-store-study-2026/">our study of online stores</a>, we ran AgentScore on 600 real websites in one day. The study taught us a lot about stores. It taught us even more about our own scanner: three bugs that tests on our own fixture sites never caught, and one run whose results looked perfect because almost nothing had been tested. Here's what we found, what we changed, and what it means for your score.</p>
          <h2>Why run the scanner at scale</h2>
          <p>Every AgentScore check is tested against small, carefully built example sites. That proves the check does what we meant. It doesn't prove we meant the right thing for the thousands of ways real stores are built. Scanning 600 stores, from many countries, platforms and sizes, was the first time AgentScore met that variety all at once, and the first time we read its results in aggregate, where a check that's wrong for many stores stands out.</p>
          <h2>Bug 1: AgentScore only spoke English</h2>
          <p>Several checks work by reading what a button or link says: finding the add-to-cart button, recognising the button that closes a cookie banner, spotting the link to the cart. All of them only knew English words. On a German store, "In den Warenkorb" wasn't recognised as an add-to-cart button, and "Alle akzeptieren" didn't count as a way to close the banner.</p>
          <p>In our first run, 61 stores whose pages weren't in English were reported as having no add-to-cart button at all. When we rescanned eight of them with the fix, AgentScore found the button on six. The other two turned out to be a different problem (see bug 3).</p>
          <p>There was a subtler issue underneath. The usual way to match whole words in code only understands the 26 letters of the English alphabet, so even a correctly translated phrase could fail to match at the edges of words in Russian or with accented letters. Japanese, Chinese and Korean don't put spaces between words at all.</p>
          <p><strong>What we changed:</strong> the words AgentScore looks for now live in one list covering 19 languages, including German, French, Spanish, Italian, Dutch, the Nordic languages, Polish, Turkish, Russian, Ukrainian, Japanese, Chinese and Korean, and matching works in every alphabet. It also changed which sites AgentScore recognises as stores, because finding the cart link is part of that: the same sample produced 230 stores instead of 219.</p>
          <h2>Bug 2: Real buttons reported as fake ones</h2>
          <p>AgentScore checks that your add-to-cart button is a real button, because agents look for buttons and links, not for text that happens to be clickable. To find the button, it looked for the smallest element whose text matched. Many shop themes write their buttons like this:</p>
          <pre><code>&lt;button type="submit"&gt;
  &lt;span&gt;Add to cart&lt;/span&gt;
&lt;/button&gt;</code></pre>
          <p>The smallest element containing "Add to cart" is the <code>&lt;span&gt;</code>, so AgentScore reported "a plain &lt;span&gt;, not a real button", on a perfectly good button. That's a false alarm, and an expensive one: in the study's second run, 57% of the stores where we found the button were flagged. After the fix, the true figure is 24%.</p>
          <p><strong>What we changed:</strong> when the matching text sits inside a real button or link, AgentScore now judges that button or link. A <code>&lt;div&gt;</code> styled to look like a button is still caught, because that really is a problem for agents.</p>
          <h2>Bug 3: Sold-out products counted against stores</h2>
          <p>AgentScore checks one product page per store. When that product was sold out, its buy button had been replaced by a disabled "Sold out" button, "売り切れ" on a Japanese store or "Agotado" on a Spanish one, and AgentScore reported that it couldn't find an add-to-cart button. That says nothing about the store's buttons, only about its stock.</p>
          <p><strong>What we changed:</strong> AgentScore now recognises a sold-out product, from its button in any of the 19 languages or from the product data saying it's out of stock. Then it does what a shopper would: it tries up to two other products. If they're all sold out, the check is marked as not tested, which never costs points. In the study, AgentScore moved past a sold-out product on 4 stores and skipped the check on 5 where everything it tried was sold out.</p>
          <h2>The run that looked perfect</h2>
          <p>One of our runs came back looking wonderful. Navigation scored 100%. Not one store had an unnamed button. No pop-ups blocked anything.</p>
          <p>It was wrong. After an update to how AgentScore opens pages in its browser, the browser on our scanning machine couldn't complete secure connections, and it couldn't load a single page. Every check that needs a real browser was skipped, on 245 of 245 stores. Skipped checks don't cost points, by design, so the scores went up instead of down.</p>
          <p>We caught it because the numbers were too good to be true, not because anything failed. That's not good enough, so we added a safeguard: our analysis now refuses to produce results if more than 10% of stores couldn't be opened in a browser. We fixed the scanning machine's setup, confirmed one scan by hand, and ran all 600 sites again.</p>
          <div>
            <p><strong>Your own scans are protected the same way.</strong> When AgentScore can't open your pages in a browser, your report says so and marks those checks as not tested. It never presents a skipped check as a pass. See <a href="https://ghostagentlab.com/blog/reading-your-agentscore-report/">how to read your AgentScore report</a>.</p>
          </div>
          <h2>What this means for your score</h2>
          <ul>
            <li><strong>Stores outside English-speaking markets</strong> get a fairer score, and some will see it rise, as buttons, banners and cart links are now recognised in their language.</li>
            <li><strong>Stores whose buttons wrap their text</strong> in another element no longer get a false "not a real button" finding.</li>
            <li><strong>A sold-out product</strong> no longer costs you points.</li>
          </ul>
          <p>All three changes are in AgentScore's current scoring version, 2026.10-v5. If you scanned your site before, <a href="https://ghostagentlab.com/agentscore/">run AgentScore again</a> to see your updated score.</p>
          <h2>What we took away</h2>
          <ul>
            <li><strong>Test against the real world, not only your examples.</strong> Each bug passed every test we had, because our test sites were built the way we expected sites to be built.</li>
            <li><strong>Be suspicious of good news.</strong> The broken run would have made a better headline than the real one. A result that's surprisingly good deserves the same scrutiny as one that's surprisingly bad.</li>
            <li><strong>Publish the limits.</strong> The study states what AgentScore can't see, such as checkouts that need items in the cart and requests that don't come from AI companies' verified addresses. Saying so is what makes the rest of the numbers worth trusting.</li>
          </ul>
          <p>Curious how AgentScore opens and reads your pages? <a href="https://ghostagentlab.com/blog/how-agentscore-renders-pages/">How AgentScore renders pages</a> explains the browser side, and <a href="https://ghostagentlab.com/blog/how-agentscore-works/">How AgentScore works</a> covers the scoring.</p>]]></content:encoded>
    </item>
    <item>
      <title>We scanned 234 online stores with AgentScore. Here's what trips up AI agents</title>
      <link>https://ghostagentlab.com/blog/agentscore-store-study-2026/</link>
      <guid>https://ghostagentlab.com/blog/agentscore-store-study-2026/</guid>
      <pubDate>Fri, 09 Oct 2026 13:23:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Research</category>
      <description>Most online stores let AI agents in, but many trip them up once inside: unnamed buttons, missing product data, and prices agents can't see. Results from 234 stores.</description>
      <content:encoded><![CDATA[<p>AI shopping agents are starting to research and buy on people's behalf. So we asked a simple question: if an AI agent visited a typical online store today, how far would it get? We ran AgentScore on 234 online stores to find out. The short answer: most stores let agents in, but many trip them up once they're inside.</p>
          <div>
            <div><strong>85</strong><p>Median AgentScore, out of 100</p></div>
            <div><strong>48%</strong><p>of stores have buttons or links with no name an agent can read</p></div>
            <div><strong>30%</strong><p>of stores don't put prices in the product page's HTML, where most agents look</p></div>
          </div>
          <h2>How we did it</h2>
          <p>We drew 600 websites at random from the online shops listed in <a href="https://www.wikidata.org/">Wikidata</a>, the public knowledge base, so the sample leans toward established retailers notable enough to have an entry, from many countries. On October 9, 2026 we ran the same automated <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> scan (scoring version 2026.10-v5) on each, and 544 could be scanned; the rest were unreachable, timed out or returned errors. 234 of those sites were identified as stores, with products or a cart, and those are the ones in this report. Another 12 stores showed a bot challenge even to an ordinary browser request from our cloud servers, so we couldn't see them at all and left them out.</p>
          <p>For each store, AgentScore checks three things:</p>
          <ul>
            <li><strong>Access:</strong> whether robots.txt rules, bot protection or CAPTCHAs stop AI assistants such as ChatGPT-User, Claude-User and Perplexity-User from reaching the home page, product pages and checkout.</li>
            <li><strong>Readability:</strong> whether content, product details and prices are in the page's HTML, or only appear after JavaScript runs.</li>
            <li><strong>Navigability:</strong> whether buttons, links and form fields have names agents can read, whether pop-ups block the page, and whether the add-to-cart button is a real, uncovered button.</li>
          </ul>
          <p>This version doesn't send an AI agent through a live shopping task, so the scores cover whether agents can get in, read and find their way, not whether they complete a purchase. The scan is read-only: it never submits forms, adds to cart or places orders. All scans ran from a single cloud location, so pop-ups and content that vary by country may differ for visitors elsewhere. We report results only in aggregate and don't name individual stores.</p>
          <h2>The scores</h2>
          <p>The median store scored 85 out of 100. 65% scored 80 or more, and 1% scored below 50.</p>
          <table>
            <thead><tr><th>AgentScore</th><th>Share of stores</th></tr></thead>
            <tbody><tr><td>0–49</td><td>1%</td></tr><tr><td>50–64</td><td>5%</td></tr><tr><td>65–79</td><td>29%</td></tr><tr><td>80–100</td><td>65%</td></tr></tbody>
          </table>
          <p>By category, the median store earned 92% of the available points for access, 94% for readability and 75% for navigability. Getting in and reading pages is mostly solved. Finding the way around is where agents struggle.</p>
          <h2>Finding 1: Most stores let AI assistants in</h2>
          <p>The good news: robots.txt rules blocked AI assistants or AI search on only 3% of stores. Counting every way we test, 14% of stores blocked or challenged AI assistants somewhere:</p>
          <ul>
            <li><strong>9%</strong> blocked or challenged a request that identified itself as an AI assistant, such as ChatGPT-User or Claude-User, on the home page, while the same request as a normal browser got straight through.</li>
            <li><strong>8%</strong> kept AI assistants or AI search out of product, pricing or cart pages, through bot protection or robots.txt.</li>
            <li><strong>5%</strong> had a CAPTCHA on the home page, which agents can't solve.</li>
          </ul>
          <p>One caution on the bot protection figures: our requests used the AI assistants' names but came from our own servers, not from the operators' verified addresses. A site that checks where AI agents really come from would rightly turn some of these away, so these are upper bounds on how often real assistants are blocked. The robots.txt figure reads the rules each site publishes, so it isn't affected.</p>
          <p>For the stores that do block assistants, the fix is usually a settings change, not a rebuild. See <a href="https://ghostagentlab.com/articles/bot-protection-ai-agents/">bot protection and CAPTCHAs</a> and <a href="https://ghostagentlab.com/articles/robots-txt-ai-agents/">robots.txt for AI agents</a>.</p>
          <h2>Finding 2: Product details are where readability slips</h2>
          <p>Most AI crawlers and assistant fetchers read the HTML a server sends and never run JavaScript. Here most stores do well: only 6% had less than 70% of their home page text in the HTML.</p>
          <p>Product pages are a different story:</p>
          <ul>
            <li><strong>63%</strong> of stores give price, currency and availability as structured data in the product page's HTML, the way agents read most reliably.</li>
            <li><strong>24%</strong> have no usable product structured data at all, so agents have to guess price and stock from the layout.</li>
            <li><strong>6%</strong> have product data that's incomplete or only in older microdata, and 7% only add it with JavaScript.</li>
            <li><strong>30%</strong> don't have prices in the product page's HTML at all.</li>
          </ul>
          <p>An agent that can't see a price can't compare you, and an agent that can't tell whether something is in stock will usually recommend a store where it can. See <a href="https://ghostagentlab.com/articles/structured-data-ai-shopping-agents/">product data AI shopping agents can read</a>.</p>
          <h2>Finding 3: Navigation is the weakest link</h2>
          <p>Navigability was the lowest-scoring category, and the most common problems in the whole study are here:</p>
          <ul>
            <li><strong>48%</strong> of stores have buttons or links with no name an agent can read, most often icon-only cart, search and menu buttons.</li>
            <li><strong>47%</strong> have elements that look clickable but aren't real buttons or links.</li>
            <li><strong>39%</strong> show a pop-up or banner that covers much of the page on arrival. On 28% of stores, it had no clearly labelled button to close it.</li>
            <li>Of 118 stores where we found the add-to-cart button, <strong>24%</strong> had one that isn't a real button, or is covered by something else, so an agent's click may not land.</li>
          </ul>
          <p>These are the same problems that trip up people using screen readers, and fixing them helps both. See <a href="https://ghostagentlab.com/articles/agent-friendly-buttons-forms/">buttons, links and forms agents can use</a>.</p>
          <h2>Finding 4: Checkouts mostly let agents through</h2>
          <p>AgentScore also loads each store's cart and checkout pages, without adding anything to the cart. Of 200 stores whose cart or checkout we could load, 8% blocked or challenged requests identifying as AI assistants there while browsers got through, and another 14% showed a CAPTCHA to every visitor. The same caution about verified addresses applies.</p>
          <p>Most checkouts only show their first step once something is in the cart, so we could inspect too few of them to report on guest checkout or checkout forms. See <a href="https://ghostagentlab.com/articles/agent-ready-checkout/">how to make checkout work for AI shopping agents</a> for what to look for in your own.</p>
          <h2>Finding 5: More stores speak to agents than we expected</h2>
          <p>Some stores now offer agents a direct way in. 53% publish an <a href="https://ghostagentlab.com/articles/llms-txt/">llms.txt</a> file, 32% offer an MCP server or WebMCP tools, and 29% publish an agentic checkout profile. These standards are young, so we expected far lower numbers. They suggest agent-ready commerce is arriving faster than most store owners realize.</p>
          <h2>The most common problems</h2>
          <p>Across every check that covered at least 50 stores, these fell short most often (a fail or a warning):</p>
          <table>
            <thead><tr><th>AgentScore check</th><th>Stores falling short</th></tr></thead>
            <tbody><tr><td>Buttons and links have names</td><td>48%</td></tr><tr><td>Clickable things are real buttons and links</td><td>47%</td></tr><tr><td>llms.txt guide for AI</td><td>47%</td></tr><tr><td>Pop-ups and banners can be dismissed by agents</td><td>39%</td></tr><tr><td>Product pages give price and stock in a form agents can read</td><td>37%</td></tr><tr><td>Form fields are labelled</td><td>34%</td></tr><tr><td>Prices are in the page HTML</td><td>30%</td></tr><tr><td>Page has main and navigation landmarks</td><td>28%</td></tr><tr><td>Clear page title, description, and headings</td><td>24%</td></tr><tr><td>AI agents aren't blocked or shown a CAPTCHA at the cart and checkout</td><td>22%</td></tr></tbody>
          </table>
          <h2>What the best stores do differently</h2>
          <p>We compared the top quarter of stores by AgentScore with the bottom quarter. These checks showed the biggest gap in pass rates:</p>
          <table>
            <thead><tr><th>Check</th><th>Top quarter pass</th><th>Bottom quarter pass</th></tr></thead>
            <tbody><tr><td>Product pages give price and stock in a form agents can read</td><td>100%</td><td>27%</td></tr><tr><td>Agents can check out through an agentic commerce protocol</td><td>72%</td><td>0%</td></tr><tr><td>llms.txt guide for AI</td><td>86%</td><td>16%</td></tr><tr><td>Agents can use your site through MCP or WebMCP</td><td>71%</td><td>2%</td></tr><tr><td>AI agents aren't blocked or shown a CAPTCHA at the cart and checkout</td><td>98%</td><td>41%</td></tr><tr><td>Prices are in the page HTML</td><td>94%</td><td>40%</td></tr></tbody>
          </table>
          <p>The leaders describe their products in a form agents can read, put prices in the HTML, publish an llms.txt file and offer agents a direct way in. Several of these are a one-time template or settings change, which makes them the cheapest points available to most stores.</p>
          <h2>What to fix first</h2>
          <div>
            <ol>
              <li><strong>Name your buttons, and make them real.</strong> Especially icon-only cart, search and menu buttons, and the add-to-cart button.</li>
              <li><strong>Put product data and prices in the HTML.</strong> Name, price, currency and availability as structured data, rendered on the server.</li>
              <li><strong>Get pop-ups out of the way</strong> on arrival, and give them a clearly labelled close button.</li>
              <li><strong>Check your door.</strong> If you're among the stores that block AI assistants, let verified assistants reach your home, product and checkout pages.</li>
            </ol>
          </div>
          <h2>See where your store stands</h2>
          <p>Run <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> on your own site. It's free, takes about two minutes, and shows exactly which of these problems apply to you, with a fix for each. To understand the bigger picture, start with <a href="https://ghostagentlab.com/articles/agent-readiness/">What is agent readiness?</a></p>
          <p>Method notes: scores use AgentScore scoring version 2026.10-v5. Percentages use the stores where each check could run; checks that didn't apply to a store, or couldn't be tested, are left out of that check's total. Scans ran on October 9, 2026, and sites change, so a store's score today may differ. Checks that read what buttons and links say, such as "Add to cart" or "Close", understand 19 languages, so stores in every language count toward every figure.</p>]]></content:encoded>
    </item>
    <item>
      <title>What an AI agent sees when it visits your store</title>
      <link>https://ghostagentlab.com/blog/what-an-ai-agent-sees/</link>
      <guid>https://ghostagentlab.com/blog/what-an-ai-agent-sees/</guid>
      <pubDate>Fri, 09 Oct 2026 13:22:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Perspective</category>
      <description>One product page, three views: the raw HTML an assistant reads, the rendered page a browser agent sees, and the accessibility tree it acts on.</description>
      <content:encoded><![CDATA[<p>When your team reviews a product page, they look at it in a browser, logged in, with the cookie banner long since accepted. An AI agent arriving for a customer gets none of that. Depending on the kind of agent, it reads your raw HTML, looks at the page as it's drawn, or works through the page's accessibility tree. Here is one fictional product page seen all three ways, and what each view gets wrong.</p>
          <h2>The page</h2>
          <p>Northwind Outfitters sells running gear at <code>northwind.example</code>. Its product page for the Trail Runner 2 looks good to a person: a large photo, the name, a price of $129, a row of size swatches, an "Add to cart" button and, on a first visit, a cookie banner across the bottom half of the screen. Like many modern stores, the page is built in the browser: the server sends a shell, and JavaScript fetches the product and fills it in.</p>
          <p>A shopper asks an AI assistant: "Find me a trail running shoe under $150 in a size 10 that I can get this week." Here is what Northwind's page looks like to the agents that might come to answer.</p>
          <h2>View 1: the raw HTML</h2>
          <p>AI assistants that fetch a page because someone just asked a question, and the crawlers behind AI search, usually request the page and read the HTML that comes back. Many don't run JavaScript at all. This is what Northwind's server sends:</p>
          <pre><code>&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;Northwind Outfitters&lt;/title&gt;
&lt;/head&gt;
&lt;body&gt;
  &lt;header&gt;&lt;a href="/"&gt;&lt;img src="/logo.svg"&gt;&lt;/a&gt;&lt;/header&gt;
  &lt;div id="app"&gt;Loading…&lt;/div&gt;
  &lt;script src="/assets/app.4f9c.js"&gt;&lt;/script&gt;
&lt;/body&gt;
&lt;/html&gt;</code></pre>
          <p>That's the whole story for this kind of agent. No product name, because the title is the store's name. No price, no sizes, no stock and no structured data. The assistant can't tell the shopper the Trail Runner 2 costs $129 or comes in a size 10, so it recommends a shoe from a store whose page it could read.</p>
          <p>Nothing on screen warns Northwind's team about this. The page looks perfect in every browser they own. It's the problem our guide to <a href="https://ghostagentlab.com/articles/javascript-content-ai-agents/">JavaScript-only content</a> is about, and the reason <a href="https://ghostagentlab.com/articles/structured-data-ai-shopping-agents/">Product structured data</a> and <a href="https://ghostagentlab.com/articles/machine-readable-prices/">machine-readable prices</a> belong in the HTML the server sends.</p>
          <h2>View 2: the rendered page</h2>
          <p>Browser agents run a real browser. They load the page, let the scripts run, and decide what to do next, often by looking at a screenshot. This agent gets much more:</p>
          <ul>
            <li>The photo, the name "Trail Runner 2" and the price, $129.</li>
            <li>The size swatches, though nothing on screen says which sizes are in stock: sold-out sizes are only a lighter shade of gray.</li>
            <li>The cookie banner, covering the bottom of the screen, including the "Add to cart" button.</li>
          </ul>
          <p>The agent has to deal with the banner first. If its buttons are clearly labelled "Accept" and "Reject", that's one extra step. If the only way out is a small "×" drawn in an image, the agent may click the wrong thing or give up. Either way, it costs a step on every visit where the agent starts with a fresh browser, and many do. Our guide to <a href="https://ghostagentlab.com/articles/cookie-banners-popups-ai-agents/">cookie banners and pop-ups</a> covers how to keep them out of the way.</p>
          <h2>View 3: the accessibility tree</h2>
          <p>Many browser agents don't act on pixels alone. They read the page's accessibility tree: the same outline of headings, buttons, links and fields that screen readers use, with a role and a name for each item. It's compact, and it tells the agent exactly what it can press. Here is a simplified version of Northwind's:</p>
          <pre><code>banner
  link (no name)
  button (no name)
main
  heading "Trail Runner 2" level 1
  text "$129.00"
  generic "8"
  generic "9"
  generic "10"
  generic "11"
  button "Add to cart"
dialog "We value your privacy"
  button "Accept all"
  button (no name)</code></pre>
          <p>Read it the way an agent would:</p>
          <ul>
            <li><strong>The logo link and the cart icon have no names.</strong> The agent can't tell which button is the cart. An <code>aria-label</code> or visible text fixes both.</li>
            <li><strong>The sizes aren't controls.</strong> They're plain boxes with a click handler, so they show up as "generic" rather than buttons or options. The agent may not realize it can choose a size at all, and nothing tells it which sizes are sold out. Real buttons or radio inputs, with the stock state in their names, solve it. See <a href="https://ghostagentlab.com/articles/variant-pickers-ai-agents/">variant pickers AI agents can use</a>.</li>
            <li><strong>The banner's "Reject" button has no name.</strong> It's an icon with no label. An agent that wants to decline cookies on the shopper's behalf can't find the option.</li>
          </ul>
          <p>The good news is in there too: one clear <code>h1</code>, a price as text, and an "Add to cart" button that is a real button with a real name. Those are the things that let an agent finish the job.</p>
          <h2>Same page, three stories</h2>
          <table>
            <thead><tr><th>What the agent needs</th><th>Raw HTML</th><th>Rendered page</th><th>Accessibility tree</th></tr></thead>
            <tbody>
              <tr><td>Product name</td><td>Missing</td><td>Yes</td><td>Yes</td></tr>
              <tr><td>Price</td><td>Missing</td><td>Yes</td><td>Yes, as text</td></tr>
              <tr><td>Sizes in stock</td><td>Missing</td><td>Only as shading</td><td>Sizes listed, stock missing, not selectable</td></tr>
              <tr><td>A way past the banner</td><td>Not applicable</td><td>Depends on the buttons</td><td>"Accept all" only</td></tr>
              <tr><td>Add to cart</td><td>Missing</td><td>Covered by the banner</td><td>Present and named</td></tr>
            </tbody>
          </table>
          <p>No single view is "the" agent view. A shopper's question might be answered from the raw HTML, and the purchase made by a browser agent working from the accessibility tree. A page has to work in all three.</p>
          <h2>How to see your own pages this way</h2>
          <ol>
            <li><strong>Raw HTML:</strong> open a product page, choose "View page source", and search for the price and the product name. If they're not there, agents that read the HTML don't have them.</li>
            <li><strong>Rendered page:</strong> open the same page in a private window at desktop size. What covers it on arrival is what a browser agent meets first.</li>
            <li><strong>Accessibility tree:</strong> in Chrome's developer tools, the Accessibility pane shows each element's role and name. Look for buttons and links with no name and for clickable things that show up as "generic".</li>
          </ol>
          <p><a href="https://ghostagentlab.com/agentscore/">AgentScore</a> does this comparison for you. It fetches your home page and key pages as a browser and as AI assistants, renders them in a real browser, and checks names, labels, banners and the add-to-cart button. Checks such as <strong>Content loads without JavaScript</strong>, <strong>Product pages give price and stock in a form agents can read</strong>, <strong>Buttons and links have names</strong> and <strong>Pop-ups and banners can be dismissed by agents</strong> map directly onto the problems above. <a href="https://ghostagentlab.com/blog/how-agentscore-renders-pages/">How AgentScore renders your pages</a> explains the details.</p>
          <div>
            <p><strong>For Northwind, four changes cover most of it:</strong> render the product name, price and stock in the HTML with Product structured data; give the logo, cart icon and banner buttons readable names; make the size swatches real controls that say when a size is sold out; and keep the banner off the "Add to cart" button. None of them changes how the page looks to a person. As we've argued before, <a href="https://ghostagentlab.com/blog/accessibility-is-agent-readiness/">accessibility work is agent readiness work</a>.</p>
          </div>]]></content:encoded>
    </item>
    <item>
      <title>Getting agent-ready before the holiday rush</title>
      <link>https://ghostagentlab.com/blog/holiday-season-agent-readiness/</link>
      <guid>https://ghostagentlab.com/blog/holiday-season-agent-readiness/</guid>
      <pubDate>Fri, 09 Oct 2026 13:21:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Guide</category>
      <description>Bot rules, sale prices, stock, promo pop-ups and code freezes: what to check before peak season so AI agents can still find, price and buy.</description>
      <content:encoded><![CDATA[<p>Peak season is when a broken journey costs the most, and it's also when the riskiest changes go live: tighter bot rules, sale prices, promo pop-ups, then a code freeze that makes anything you missed hard to fix. Here's what to check before the freeze, so AI agents shopping for your customers can still find you, read your prices and buy.</p>
          <h2>Why peak season is different</h2>
          <p>Every change made for peak is reasonable on its own. Security tightens bot protection to stop scalpers and card testing. Marketing adds a countdown banner and an email pop-up. Merchandising loads sale prices through a promotions app. Operations shortens cache times, or lengthens them to cope with load. Then engineering freezes the code.</p>
          <p>Each of those changes is made by a different team, often in a hurry, and none of them is tested with an AI agent in mind. An assistant asked to "find a gift under $50 that arrives before the 24th" needs to get past your bot rules, read the sale price, see that the item is in stock, close the pop-up and reach the cart. Any one of those can fail quietly, and you won't see it in your analytics.</p>
          <h2>A timeline for the weeks before the freeze</h2>
          <table>
            <thead><tr><th>When</th><th>What to do</th><th>Who</th></tr></thead>
            <tbody>
              <tr><td>Six or more weeks out</td><td>Run AgentScore on your home page and fix anything critical. Agree which journeys matter most at peak.</td><td>E-commerce lead, developers</td></tr>
              <tr><td>Four weeks out</td><td>Review planned bot protection changes with your CDN or security team. Check sale price and stock data on a test promotion.</td><td>Security, merchandising</td></tr>
              <tr><td>Two weeks out</td><td>Put promo pop-ups and banners live on staging or behind a flag, and check an agent can still reach the cart.</td><td>Marketing, developers</td></tr>
              <tr><td>Before the freeze</td><td>Rescan, set up scheduled journey tests with alerts, and agree what counts as an exception to the freeze.</td><td>E-commerce lead</td></tr>
            </tbody>
          </table>
          <h2>1. Bot protection tightened for peak</h2>
          <p>This is the change most likely to turn agents away. Common peak settings include stricter challenge thresholds, "under attack" modes that challenge every visitor, blocks on cloud and data center networks, and country blocks. Browser agents and assistants that fetch pages for people often run from cloud networks, so they get caught by rules written for scrapers.</p>
          <ul>
            <li>Ask for a list of every bot rule planned for peak, and who can change them during the freeze. CDN rules often sit outside the code freeze and change mid-season.</li>
            <li>Make sure the AI assistants you want are allowed by verified identity, not just by user agent. See <a href="https://ghostagentlab.com/articles/verify-ai-crawlers/">how to tell if an AI crawler is real</a>.</li>
            <li>Check cart and checkout separately from the home page. Many stores add extra protection there for peak.</li>
            <li>Prefer rate limits on the expensive actions, like payment attempts, over blanket challenges. See <a href="https://ghostagentlab.com/articles/rate-limits-ai-agents/">rate limits for AI agents</a> and <a href="https://ghostagentlab.com/articles/geo-blocking-ai-agents/">geo-blocking and AI agents</a>.</li>
          </ul>
          <p>AgentScore checks whether your bot protection treats AI assistants differently from a browser, and whether the cart and checkout show them a block or a CAPTCHA. Rescan after every bot rule change, not just once in October. For the settings themselves, see <a href="https://ghostagentlab.com/articles/bot-protection-ai-agents/">bot protection and CAPTCHAs</a> and <a href="https://ghostagentlab.com/articles/cdn-settings-ai-agents/">setting up your CDN for AI agents</a>.</p>
          <h2>2. Sale prices that agents can read</h2>
          <p>Promotion tools often change the price in the browser with JavaScript after the page loads. A shopper sees the sale price. An agent that reads the HTML sees the full price, or no price at all, and may quote the wrong figure to its user or skip you.</p>
          <p>Before peak, run a test promotion and check three places: the visible price in the page source (use View Source, not the inspector), the price in your product structured data, and the price in the cart. They should all agree. If a sale ends on a known date, say so:</p>
          <pre><code>"offers": {
  "@type": "Offer",
  "price": "39.00",
  "priceCurrency": "USD",
  "priceValidUntil": "2026-12-01",
  "availability": "https://schema.org/InStock"
}</code></pre>
          <p>Show the original and the sale price in text, such as "Was $59, now $39", rather than relying on a strikethrough alone. See <a href="https://ghostagentlab.com/articles/machine-readable-prices/">prices AI agents can read</a>.</p>
          <h2>3. Stock that stays accurate</h2>
          <p>At peak, stock changes by the hour. If your structured data says <code>InStock</code> after an item sells out, an assistant will send people to a product they can't buy. If it says <code>OutOfStock</code> for an item you restocked this morning, you lose the recommendation.</p>
          <ul>
            <li>Make sure <code>availability</code> in your product data comes from the same source as the "Add to cart" button, not a nightly export.</li>
            <li>Use <code>PreOrder</code> or <code>BackOrder</code> where they apply, and state delivery estimates in text.</li>
            <li>If you lengthen CDN cache times for load, check how stale product pages can get, and purge on stock changes for best sellers.</li>
          </ul>
          <h2>4. Promo pop-ups and banners</h2>
          <p>Email capture, spin-to-win wheels, countdown banners and free-shipping bars all multiply in November. An agent can only get past one if it has a real, labelled close button and doesn't cover the content behind it. A pop-up that sits over the "Add to cart" button means the agent's click lands on the pop-up instead.</p>
          <p>AgentScore checks that pop-ups and banners can be dismissed, and whether the add-to-cart button on a product page is covered by something else. Check again once peak promotions are live, because they're usually added after the last scan. See <a href="https://ghostagentlab.com/articles/cookie-banners-popups-ai-agents/">cookie banners and pop-ups</a>.</p>
          <h2>5. Promo codes, carts and checkout</h2>
          <p>Gift shopping by agent depends on the last few steps working. Make sure the promo code field is labelled, that a rejected code produces a clear error in text, and that the cart total updates in the page. See <a href="https://ghostagentlab.com/articles/cart-ai-agents/">carts AI agents can manage</a> and <a href="https://ghostagentlab.com/articles/error-messages-ai-agents/">error messages AI agents can understand</a>.</p>
          <p>Resist adding a CAPTCHA to checkout for peak. It stops agents at the very last step, after they've done all the work. Card testing is better handled by your payment provider's fraud tools and by rate limits on payment attempts. Keep guest checkout on. See <a href="https://ghostagentlab.com/articles/agent-ready-checkout/">checkout for AI shopping agents</a> and <a href="https://ghostagentlab.com/articles/guest-checkout-ai-agents/">guest checkout</a>.</p>
          <h2>6. Holiday policies in plain text</h2>
          <p>Assistants are often asked about delivery cut-off dates and extended returns. Put them on your shipping and returns pages as text in the HTML, with dates, not only in a banner image or a pop-up. See <a href="https://ghostagentlab.com/articles/policy-pages-ai-assistants/">policy pages AI assistants can read</a>.</p>
          <h2>Planning for the freeze itself</h2>
          <p>A code freeze protects you from risky changes, but it also means a problem found in December may wait until January. Three things help:</p>
          <ol>
            <li><strong>Agree that blocking AI agents counts as an incident.</strong> If an assistant can't reach your product pages or checkout, that should qualify for a freeze exception, the same as a broken payment form.</li>
            <li><strong>Test the money journeys on a schedule.</strong> <a href="https://ghostagentlab.com/ghost-agent/">Ghost Agents</a> run real journeys, such as search, choose a size and add to cart, stop at the payment form, and alert you when a journey that used to pass starts failing, with a step-by-step replay.</li>
            <li><strong>Watch your logs, not just analytics.</strong> Most agents don't run your analytics tag. A rise in blocked or failed agent requests shows up in server and CDN logs first. See <a href="https://ghostagentlab.com/articles/agent-errors-in-logs/">finding the errors AI agents hit</a>.</li>
          </ol>
          <div>
            <p><strong>Before the freeze, check:</strong></p>
            <ul>
              <li>Every peak bot rule has been reviewed, and verified AI assistants still get through to product pages, cart and checkout.</li>
              <li>Sale prices appear in the page source and in structured data, and match the cart.</li>
              <li>Stock status in product data updates when items sell out.</li>
              <li>Every promo pop-up has a labelled close button and doesn't cover "Add to cart".</li>
              <li>No new CAPTCHA at checkout. Guest checkout is on.</li>
              <li>Delivery cut-offs and holiday returns are written out on your policy pages.</li>
              <li>Scheduled journey tests and alerts go to someone who can act during the freeze.</li>
            </ul>
          </div>
          <p>Start with a fresh <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> scan, then work through the list. If you have more time, our <a href="https://ghostagentlab.com/blog/90-day-agent-readiness-plan/">90-day agent readiness plan</a> covers the rest.</p>]]></content:encoded>
    </item>
    <item>
      <title>Agent readiness for software companies: pricing, sign-up and docs</title>
      <link>https://ghostagentlab.com/blog/agent-readiness-for-saas/</link>
      <guid>https://ghostagentlab.com/blog/agent-readiness-for-saas/</guid>
      <pubDate>Fri, 09 Oct 2026 13:20:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Perspective</category>
      <description>For software companies, the pricing page is the product page and sign-up is the checkout. How to get pricing, trials, docs, llms.txt and MCP right.</description>
      <content:encoded><![CDATA[<p>Most agent readiness advice is written for online stores. But software buyers send AI agents to do research too: compare plans, check whether a tool integrates with what they already use, find the limits of a free tier, and start a trial. For a software company, the pricing page is the product page, the sign-up form is the checkout, and the docs are where the real evaluation happens.</p>
          <h2>How AgentScore sees a software site</h2>
          <p>AgentScore looks for the pages an agent acting for a customer would need, the way an agent would: links in your home page's HTML, then your sitemap, then common addresses such as <code>/pricing</code>. If it finds product pages or a cart, it treats the site as a store. If it finds a pricing page and no products or cart, it treats the site as software ("saas" in the scan's data). That changes what some checks look for.</p>
          <table>
            <thead><tr><th>Check</th><th>On a software site, it looks at</th></tr></thead>
            <tbody>
              <tr><td>AI agents can open your product, pricing and cart pages</td><td>Whether AI assistants can load your pricing page, not just a browser</td></tr>
              <tr><td>Prices are in the page HTML</td><td>Whether plan prices are in the HTML your server sends, before JavaScript runs</td></tr>
              <tr><td>Key pages are linked from the home page</td><td>Whether pricing is linked from the home page with an ordinary link</td></tr>
              <tr><td>Agents can find and press your add-to-cart or sign-up button</td><td>Whether the pricing page has a real, visible button such as "Start free trial" or "Buy Pro"</td></tr>
              <tr><td>Cart, checkout and agentic commerce checks</td><td>Nothing. They're marked "not tested", so they don't count against you</td></tr>
            </tbody>
          </table>
          <p>Everything else, from robots.txt and bot protection to structured data, named buttons and labelled form fields, applies the same way as for any site. See <a href="https://ghostagentlab.com/articles/agent-readiness/">what is agent readiness?</a> for the full model.</p>
          <h2>Pricing pages agents can read</h2>
          <p>Pricing pages are often the most designed page on a software site, and that's where agents struggle. Common problems:</p>
          <ul>
            <li><strong>Prices loaded by JavaScript.</strong> A monthly/annual toggle that fetches prices when clicked leaves the HTML with no prices at all. Put both sets of prices in the HTML and let the toggle show and hide them.</li>
            <li><strong>Features shown only as icons.</strong> A comparison table of tick and cross images says nothing to an agent unless each icon has a text label, such as "Included" or "Not included". See <a href="https://ghostagentlab.com/articles/image-alt-text-ai-agents/">image alt text</a>.</li>
            <li><strong>Units left implicit.</strong> Say "per user per month, billed annually" in text, not in a tooltip. Agents compare plans across vendors, and unclear units make you look more expensive or less clear than a competitor.</li>
            <li><strong>"Contact sales" with no explanation.</strong> If a plan is priced on request, say so in plain text and say what affects the price. An agent can then tell its user how to get a quote instead of guessing.</li>
          </ul>
          <p>A plain HTML table is still the clearest way to compare plans:</p>
          <pre><code>&lt;table&gt;
  &lt;caption&gt;Northwind plans, billed annually&lt;/caption&gt;
  &lt;tr&gt;&lt;th&gt;&lt;/th&gt;&lt;th&gt;Starter&lt;/th&gt;&lt;th&gt;Pro&lt;/th&gt;&lt;/tr&gt;
  &lt;tr&gt;&lt;th&gt;Price&lt;/th&gt;&lt;td&gt;$12 per user per month&lt;/td&gt;&lt;td&gt;$29 per user per month&lt;/td&gt;&lt;/tr&gt;
  &lt;tr&gt;&lt;th&gt;Single sign-on&lt;/th&gt;&lt;td&gt;Not included&lt;/td&gt;&lt;td&gt;Included&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</code></pre>
          <p>For more, see <a href="https://ghostagentlab.com/articles/machine-readable-prices/">prices AI agents can read</a>.</p>
          <h2>Sign-up and trials</h2>
          <p>An agent that has chosen your product for someone will try to start the trial. It needs a visible, real button with a clear label, then a form it can fill in: every field labelled, errors explained in text, and no surprises. See <a href="https://ghostagentlab.com/articles/agent-friendly-buttons-forms/">buttons, links and forms agents can use</a>.</p>
          <p>Some steps should stay with the person, and that's fine. Email verification, single sign-on, payment details for a card-required trial and accepting terms are all reasonable places for an agent to hand back to its user. The aim is for the agent to get as far as it should, then stop cleanly with a clear message, rather than fail at a CAPTCHA on the first screen. See <a href="https://ghostagentlab.com/articles/agent-friendly-sign-up-booking/">sign-up, booking and lead forms AI agents can finish</a>.</p>
          <p><a href="https://ghostagentlab.com/ghost-agent/">Ghost Agents</a> can test this journey for real: from the home page to pricing to the sign-up form, using test data you supply, with a step-by-step replay showing where an agent got stuck.</p>
          <h2>Docs are your product page for agents</h2>
          <p>For many software products, the docs decide the sale. Coding assistants and research agents read them to answer "does it support X?" and "how hard is it to set up?". Treat docs with the same care as marketing pages:</p>
          <ul>
            <li>Serve docs as HTML that works without JavaScript. Some docs sites are single-page apps that send an empty shell. See <a href="https://ghostagentlab.com/articles/javascript-content-ai-agents/">JavaScript-only content</a>.</li>
            <li>Keep public docs public. If setup guides sit behind a login, agents can't use them to recommend you. See <a href="https://ghostagentlab.com/articles/login-walls-ai-agents/">login walls and gated content</a>.</li>
            <li>Give each version a stable address and point old copies at the current one, so agents don't quote outdated instructions. See <a href="https://ghostagentlab.com/articles/canonical-urls-ai-agents/">canonical URLs</a>.</li>
            <li>Publish limits, supported integrations and security information as text, not only in PDFs or sales decks.</li>
          </ul>
          <h2>llms.txt for software companies</h2>
          <p><a href="https://llmstxt.org/">llms.txt</a> is a proposed convention, not a standard, and AI providers don't all say whether they read it. It's cheap to publish, though, and it suits software companies well, because your most useful pages are easy to list. Some docs platforms can generate one for you.</p>
          <pre><code># Northwind
&gt; Northwind is scheduling software for field service teams.
## Product
- [Pricing](https://northwind.example/pricing): plans, limits and what each includes
- [Start a free trial](https://northwind.example/signup): 14 days, no card required
## Docs
- [Getting started](https://northwind.example/docs/start)
- [API reference](https://northwind.example/docs/api)
- [Integrations](https://northwind.example/integrations)
## Trust
- [Security](https://northwind.example/security)
- [Status](https://status.northwind.example/)</code></pre>
          <p>AgentScore checks that an llms.txt file exists. It can't tell whether yours is up to date, so add it to your release checklist. See <a href="https://ghostagentlab.com/articles/llms-txt/">how to write an llms.txt file</a>.</p>
          <h2>MCP: your product, not just your website</h2>
          <p>For a software company, the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a> is about more than your website. An MCP server can let an assistant use your product itself on a customer's behalf: look up records, create tasks, run reports. That's product work, with sign-in and permissions to design carefully, and many software companies are already building one.</p>
          <p>There's no single agreed way to advertise an MCP server on a website yet. AgentScore's "Agents can use your site through MCP or WebMCP" check looks for a server card at <code>/.well-known/mcp.json</code>, an MCP link in the page, a mention in llms.txt, or WebMCP tools in the page. If you have a server, mentioning it in llms.txt and your docs is the simplest start. See <a href="https://ghostagentlab.com/articles/mcp-webmcp-for-websites/">MCP and WebMCP for websites</a>.</p>
          <h2>Where to start</h2>
          <ol>
            <li>Run <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> on your home page. If "Key pages are linked from the home page" doesn't pass, agents may not be finding your pricing page.</li>
            <li>View the source of your pricing page and check every price and plan feature is there as text.</li>
            <li>Make "Start free trial" a real, clearly labelled button, and check the sign-up form's fields are labelled.</li>
            <li>Publish an llms.txt that links to pricing, sign-up, docs and your trust pages.</li>
            <li>Test the journey from home page to sign-up with a <a href="https://ghostagentlab.com/ghost-agent/">Ghost Agent</a>.</li>
          </ol>]]></content:encoded>
    </item>
    <item>
      <title>How to explain agent readiness to your board</title>
      <link>https://ghostagentlab.com/blog/explain-agent-readiness-to-your-board/</link>
      <guid>https://ghostagentlab.com/blog/explain-agent-readiness-to-your-board/</guid>
      <pubDate>Fri, 09 Oct 2026 13:19:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Guide</category>
      <description>A one-page way to explain agent readiness to your board: what's changing, the risks, what to measure and what to ask for, without hype or invented numbers.</description>
      <content:encoded><![CDATA[<p>Your board doesn't need to know what robots.txt is. It needs to know what's changing, what that risks for the business, what you're doing about it, and how it will know the work is paying off. Here's a way to say all of that on one page, without hype and without numbers you can't stand behind.</p>
          <h2>The one-page version</h2>
          <p>Start with this structure. Each heading is one or two sentences. Fill in the bracketed parts with your own findings.</p>
          <div>
            <p><strong>What's changing.</strong> People are starting to ask AI assistants to research, compare and buy on their behalf. Those assistants visit our website the way a customer would, but they read it differently.</p>
            <p><strong>Why it matters to us.</strong> If an assistant can't get in, can't read our prices or can't complete a purchase, it recommends someone else, and we never see the lost customer in our reports.</p>
            <p><strong>Where we stand.</strong> [Our AgentScore, the main issues it found, and whether AI agents can complete our most important journey today.]</p>
            <p><strong>What we're doing.</strong> [Three to five fixes, who owns each, and when they'll be done.]</p>
            <p><strong>What we need.</strong> [Time, tools or decisions, each with a review date.]</p>
          </div>
          <p>That's it. Everything below is about filling it in well.</p>
          <h2>Explaining the shift without hype</h2>
          <p>Boards have heard a lot about AI. The quickest way to lose the room is a slide of large market forecasts. You don't need them. The argument for agent readiness is modest and easy to defend:</p>
          <ul>
            <li>AI agents already visit websites for people. You can show this from your own server or CDN logs.</li>
            <li>Nobody knows how fast this will grow. That's a reason to be ready cheaply now, not to wait for certainty.</li>
            <li>Much of the work also improves accessibility, search and site quality, so it isn't a bet on one trend. See <a href="https://ghostagentlab.com/blog/accessibility-is-agent-readiness/">accessibility work is agent readiness work</a> and <a href="https://ghostagentlab.com/blog/seo-to-agent-readiness/">SEO got you found. Agent readiness gets you chosen</a>.</li>
            <li>The failure is silent. A blocked agent doesn't complain. It goes elsewhere. That makes it the kind of risk a board should want someone to own.</li>
          </ul>
          <p>If you quote any outside figure, cite the source on the slide. If you can't, describe the trend in words instead.</p>
          <h2>The risks, in board language</h2>
          <table>
            <thead><tr><th>Risk</th><th>What it looks like</th><th>Usually owned by</th></tr></thead>
            <tbody>
              <tr><td>Lost revenue</td><td>AI assistants are blocked by bot protection, can't see prices, or fail at checkout, so they recommend or buy from a competitor.</td><td>E-commerce or digital lead</td></tr>
              <tr><td>Being misquoted</td><td>Assistants give customers the wrong price, stock or return policy because our pages are hard to read or out of date.</td><td>Marketing and content</td></tr>
              <tr><td>Impostors</td><td>Scrapers pretend to be well-known AI agents to get past our defenses. Opening the door carelessly makes this worse.</td><td>Security</td></tr>
              <tr><td>Content and legal</td><td>Decisions about AI training on our content, our terms of service, and responsibility for purchases an agent makes for a customer.</td><td>Legal, with marketing</td></tr>
              <tr><td>Blind spots</td><td>Our analytics can't see most AI agents, so decisions are made on incomplete data.</td><td>Analytics or digital lead</td></tr>
            </tbody>
          </table>
          <p>The point of the table is that this is a cross-team issue with no natural home. Ask the board to agree one accountable owner. See <a href="https://ghostagentlab.com/blog/who-owns-agent-readiness/">who owns agent readiness?</a></p>
          <h2>What to measure</h2>
          <p>Pick a few measures you can report every quarter, and show the trend rather than a single figure.</p>
          <ul>
            <li><strong>AgentScore, by category.</strong> Access, Readability and Navigability tell you whether agents can get in, understand your pages and find their way around. The free scan doesn't test Task completion, so don't present its score as proof that agents can buy.</li>
            <li><strong>Journey pass rate.</strong> Whether AI agents can complete your most important journeys, such as checkout or sign-up, from scheduled <a href="https://ghostagentlab.com/ghost-agent/">Ghost Agent</a> tests.</li>
            <li><strong>Agent traffic.</strong> How many requests come from AI assistants and search agents, how many are verified, and how many are impostors, from your logs. See <a href="https://ghostagentlab.com/articles/measure-ai-agent-traffic/">how to measure agent traffic</a>.</li>
            <li><strong>Visits and orders from AI assistants.</strong> People who click through from an assistant's answer. See <a href="https://ghostagentlab.com/articles/ai-referral-traffic/">tracking visits and sales from AI assistants</a>.</li>
            <li><strong>Time to fix.</strong> How long a critical finding, such as AI agents being blocked, stays open.</li>
          </ul>
          <p>Be careful with attribution. You can show that more agents get through and more journeys pass. You usually can't prove exactly how much revenue that produced, and the board will trust you more if you say so. For a fuller set, see <a href="https://ghostagentlab.com/articles/agent-readiness-kpis/">agent readiness KPIs</a>.</p>
          <h2>What to ask for</h2>
          <p>Keep the ask small and staged, with a review point after each stage. A typical shape:</p>
          <ol>
            <li><strong>A baseline.</strong> A scan, a look at agent traffic in your logs, and one tested journey. This needs a few days of people's time, not a project.</li>
            <li><strong>Fixes.</strong> Developer and content time to work through the findings. Much of it overlaps with work already on the accessibility and SEO backlog, so say where it does.</li>
            <li><strong>Ongoing testing and monitoring.</strong> Tools that keep watching after the fixes, because a theme update or a new bot rule can undo them.</li>
            <li><strong>Decisions.</strong> Time from legal and security to settle policy questions such as AI training crawlers and verified agents.</li>
            <li><strong>Optional experiments.</strong> Newer interfaces such as <a href="https://ghostagentlab.com/articles/mcp-webmcp-for-websites/">MCP and WebMCP</a> or <a href="https://ghostagentlab.com/articles/agentic-commerce-protocols/">agentic commerce protocols</a>, framed as small trials with a date to decide whether to continue.</li>
          </ol>
          <p>Our <a href="https://ghostagentlab.com/blog/90-day-agent-readiness-plan/">90-day agent readiness plan</a> maps well onto the first three stages.</p>
          <h2>Questions you'll probably get</h2>
          <h3>Are we letting AI companies take our content?</h3>
          <p>No. AI training crawlers and the assistants that fetch pages for a customer use different names, so you can block one and allow the other. That's a policy choice to make once, with legal. See <a href="https://ghostagentlab.com/blog/block-or-allow-ai-crawlers/">should you block AI crawlers?</a></p>
          <h3>Does this open us up to bots?</h3>
          <p>Not if it's done properly. The goal is to let in the agents you want, checked by verified identity, and keep blocking the rest. See <a href="https://ghostagentlab.com/articles/verify-ai-crawlers/">how to tell if an AI crawler is real</a>.</p>
          <h3>What happens if we do nothing?</h3>
          <p>Probably nothing you'll notice, which is the problem. Some customers' assistants will fail on the site and choose a competitor, and it won't show up in any report you currently read.</p>
          <p>To fill in "Where we stand", run a free <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> scan. It takes under a minute and gives you a score out of 100 and a list of what to fix.</p>]]></content:encoded>
    </item>
    <item>
      <title>Seven agent readiness mistakes to avoid</title>
      <link>https://ghostagentlab.com/blog/agent-readiness-mistakes/</link>
      <guid>https://ghostagentlab.com/blog/agent-readiness-mistakes/</guid>
      <pubDate>Fri, 09 Oct 2026 13:18:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Guide</category>
      <description>Seven common agent readiness mistakes, from blocking AI assistants with training crawlers to measuring agents with JavaScript analytics, and how to avoid each.</description>
      <content:encoded><![CDATA[<p>Most agent readiness problems aren't decisions anyone made. They're side effects of sensible work: a security rule, a design choice, a tracking setup. Here are seven mistakes that are easy to make and easy to miss, why each one matters, and what to do instead.</p>
          <h2>1. Blocking AI assistants along with training crawlers</h2>
          <p>Many sites decide not to let AI companies train on their content, which is a fair choice. The mistake is blocking everything with "AI" in its name, including the assistants that fetch a page because a customer asked a question right now. Those are different agents with different names: <code>GPTBot</code> collects training data, while <code>ChatGPT-User</code> and <code>OAI-SearchBot</code> fetch pages for ChatGPT users and search. Anthropic draws the same line between <code>ClaudeBot</code> and <code>Claude-User</code>.</p>
          <pre><code># Opt out of AI training
User-agent: GPTBot
User-agent: ClaudeBot
User-agent: Google-Extended
Disallow: /
# Everyone else, including AI assistants and AI search
User-agent: *
Allow: /</code></pre>
          <p><strong>Instead:</strong> decide on training and on assistants separately. See <a href="https://ghostagentlab.com/blog/block-or-allow-ai-crawlers/">should you block AI crawlers?</a> and <a href="https://ghostagentlab.com/articles/robots-txt-ai-agents/">robots.txt for AI agents</a>. The same split applies to bot protection rules, which often block by category rather than by name.</p>
          <h2>2. Putting a CAPTCHA at checkout</h2>
          <p>A CAPTCHA at checkout is often added to stop card testing, and it works on bots. It also stops every AI agent at the very last step, after it has searched, compared, chosen a size and filled the cart. That's the most expensive place to lose a customer.</p>
          <p><strong>Instead:</strong> use your payment provider's fraud tools and rate limits on payment attempts, and keep challenges for traffic that is actually suspicious. AgentScore checks whether AI agents are blocked or shown a CAPTCHA at the cart and checkout. See <a href="https://ghostagentlab.com/articles/agent-ready-checkout/">checkout for AI shopping agents</a> and <a href="https://ghostagentlab.com/articles/bot-protection-ai-agents/">bot protection and CAPTCHAs</a>.</p>
          <h2>3. Prices that only appear with JavaScript</h2>
          <p>Many sites build product and pricing pages in the browser. A person sees the price a moment after the page loads. Many AI agents read the HTML your server sends and never run the scripts, so they see a product with no price, or a placeholder. They may skip you, or tell their user to check the site.</p>
          <p><strong>Instead:</strong> make sure prices are in the HTML, through server-side rendering or static generation, and in your product structured data. Check by viewing the page source, not the browser's inspector, which shows the page after scripts run. See <a href="https://ghostagentlab.com/articles/machine-readable-prices/">prices AI agents can read</a> and <a href="https://ghostagentlab.com/articles/javascript-content-ai-agents/">JavaScript-only content</a>.</p>
          <h2>4. Icons with no names</h2>
          <p>A magnifying glass for search, a bag for the cart, a cross to close a pop-up. People know what they mean. Browser agents choose what to click by each control's name, the same way screen readers do, and an icon with no text or label has no name at all. To the agent, the cart button isn't there.</p>
          <pre><code>&lt;button aria-label="Open cart"&gt;
  &lt;svg aria-hidden="true"&gt;…&lt;/svg&gt;
&lt;/button&gt;</code></pre>
          <p><strong>Instead:</strong> give every icon-only button and link a label, and use real <code>&lt;button&gt;</code> and <code>&lt;a&gt;</code> elements rather than clickable boxes. See <a href="https://ghostagentlab.com/articles/agent-friendly-buttons-forms/">buttons, links and forms agents can use</a> and <a href="https://ghostagentlab.com/blog/accessibility-is-agent-readiness/">accessibility work is agent readiness work</a>.</p>
          <h2>5. Publishing llms.txt and forgetting it</h2>
          <p>llms.txt is a proposed convention for giving AI a short guide to your site. It's quick to write, which is also why it goes stale: a file written at launch still links to last year's collections, a retired plan, or a returns page that moved. An out-of-date guide can be worse than none, because it points agents at the wrong answer.</p>
          <p><strong>Instead:</strong> give llms.txt an owner and add it to the checklist for site changes, alongside the sitemap. Note that AgentScore checks that the file exists, not whether what it says is still true, so that part is up to you. See <a href="https://ghostagentlab.com/articles/llms-txt/">how to write an llms.txt file</a>.</p>
          <h2>6. Trusting user agents</h2>
          <p>A user agent is a name a visitor gives itself, and anyone can use any name. If you allow a list of AI agents by user agent alone, scrapers borrow those names to get in. If you block by user agent, you may turn away a real assistant while impostors simply change their name.</p>
          <p><strong>Instead:</strong> verify identity. The large operators publish their IP ranges, and many crawlers can be confirmed with a reverse DNS lookup. Newer agents can sign their requests with Web Bot Auth, which your CDN may already check for you. See <a href="https://ghostagentlab.com/articles/verify-ai-crawlers/">how to tell if an AI crawler is real</a> and <a href="https://ghostagentlab.com/blog/signed-requests/">why we sign every request our agents send</a>. Ghost Agent Labs' Verification page checks every request that claims to be a known agent and shows the impostors.</p>
          <h2>7. Measuring AI agents with JavaScript analytics</h2>
          <p>Analytics tools such as Google Analytics count visitors by running a script in the browser. Most AI agents don't run it, so they never appear. A report that shows no AI agents isn't evidence that none came. It may mean they came and the tag didn't see them, or that they were blocked before the page loaded.</p>
          <p><strong>Instead:</strong> measure agents from your server or CDN logs, which record every request whether or not scripts run. Keep analytics for the people who click through from an assistant's answer, which it can see. See <a href="https://ghostagentlab.com/articles/measure-ai-agent-traffic/">why your analytics can't see AI agents</a>, <a href="https://ghostagentlab.com/articles/ai-referral-traffic/">AI referral traffic</a> and <a href="https://ghostagentlab.com/blog/agent-traffic-is-not-bot-traffic/">agent traffic isn't bot traffic</a>.</p>
          <h2>What these have in common</h2>
          <p>None of these mistakes shows up from inside the business. The site looks fine in a browser, the dashboards look normal, and the security team sees fewer bad bots. The cost lands on customers using an assistant, who quietly go elsewhere.</p>
          <table>
            <thead><tr><th>Mistake</th><th>Quick check</th><th>Usually fixed by</th></tr></thead>
            <tbody>
              <tr><td>Assistants blocked with training crawlers</td><td>Read /robots.txt and your bot rules for AI categories</td><td>SEO, bot protection or CDN admin</td></tr>
              <tr><td>CAPTCHA at checkout</td><td>Ask your security team what protects the checkout</td><td>Bot protection or CDN admin</td></tr>
              <tr><td>JavaScript-only prices</td><td>View source on a product page and search for the price</td><td>Developer</td></tr>
              <tr><td>Icons with no names</td><td>Tab through the header and listen with a screen reader</td><td>Developer</td></tr>
              <tr><td>Stale llms.txt</td><td>Open /llms.txt and click every link</td><td>SEO or content team</td></tr>
              <tr><td>Trusting user agents</td><td>Ask how "allowed" AI agents are identified</td><td>Bot protection or CDN admin</td></tr>
              <tr><td>JavaScript analytics only</td><td>Ask where agent traffic numbers come from</td><td>Analytics or digital lead</td></tr>
            </tbody>
          </table>
          <p>A free <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> scan catches several of these in under a minute. For the journeys themselves, <a href="https://ghostagentlab.com/ghost-agent/">Ghost Agents</a> show whether an agent can actually finish them.</p>]]></content:encoded>
    </item>
    <item>
      <title>How AgentScore renders your pages in a real browser</title>
      <link>https://ghostagentlab.com/blog/how-agentscore-renders-pages/</link>
      <guid>https://ghostagentlab.com/blog/how-agentscore-renders-pages/</guid>
      <pubDate>Fri, 09 Oct 2026 13:17:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Engineering</category>
      <description>Which pages AgentScore opens in a headless browser, with what settings and safeguards, how it looks for WebMCP tools, and what it never does.</description>
      <content:encoded><![CDATA[<p>Some AI agents read your HTML exactly as your server sends it. Others drive a real browser, run your scripts and look at the finished page. To score your site for both, AgentScore looks at your key pages twice: once as served, and once rendered in a headless browser. Here is exactly what that browser does, how we keep it safe, and what it deliberately never does.</p>
          <h2>Why render at all</h2>
          <p>Several checks only make sense as a comparison between the page before and after JavaScript. <strong>Content loads without JavaScript</strong> measures how much of the rendered page's text was already in the HTML: 70% or more passes, 30% to 70% is a warning, and less than that fails. <strong>Structured data describes your business and products</strong>, <strong>Product pages give price and stock in a form agents can read</strong> and <strong>Prices are in the page HTML</strong> all look for the same thing: data that only appears once scripts have run, which agents that read the HTML never see. Our guide to <a href="https://ghostagentlab.com/articles/javascript-content-ai-agents/">JavaScript-only content</a> covers why that matters.</p>
          <p>The Navigability checks need a rendered page too: whether a button is visible or a banner covers the screen depends on layout, which only exists once a browser has drawn the page.</p>
          <h2>Which pages we render</h2>
          <p>A scan renders at most four pages, each in its own browser session:</p>
          <table>
            <thead><tr><th>Page</th><th>When it's rendered</th><th>What we look at</th></tr></thead>
            <tbody>
              <tr><td>Home page</td><td>Every scan</td><td>The Navigability checks, image alt text, text and structured data after JavaScript, WebMCP tools</td></tr>
              <tr><td>Product page</td><td>When we find one and it loads for a browser</td><td>The add-to-cart button, prices and product data after JavaScript, WebMCP tools</td></tr>
              <tr><td>Pricing page</td><td>When we find one and it loads for a browser</td><td>The sign-up or buy button, prices after JavaScript, WebMCP tools</td></tr>
              <tr><td>Checkout</td><td>Only when the HTML we were sent has no form fields and the checkout didn't send us back to the cart</td><td>The form fields a checkout builds with JavaScript</td></tr>
            </tbody>
          </table>
          <p>The cart is fetched but not rendered. <a href="https://ghostagentlab.com/blog/how-agentscore-works/">How AgentScore works</a> explains how key pages are found and lists every page a scan requests.</p>
          <h2>The browser and its settings</h2>
          <ul>
            <li><strong>Chromium, headless.</strong> The engine behind Chrome, driven by Playwright.</li>
            <li><strong>A fresh, isolated session for every page.</strong> No cookies or storage carry over, so every page sees a first-time visitor.</li>
            <li><strong>A desktop screen, 1280 by 900 pixels,</strong> and a desktop Chrome user agent. These requests aren't signed, so your site treats them as it would any desktop visitor.</li>
            <li><strong>No downloads and no service workers.</strong></li>
            <li><strong>Up to 20 seconds to load.</strong> We wait for the HTML to be parsed, then up to 5 more seconds for network activity to settle, so content built in the browser and consent banners have time to appear. Pages with chat widgets or analytics beacons rarely go quiet, so after 5 seconds we inspect whatever is there.</li>
          </ul>
          <p>If a page fails to load or render, the checks that depend on it are marked "not tested" with a note explaining why. A render failure never counts as a fail.</p>
          <h2>What we inspect once it's drawn</h2>
          <p>On the home page, a script reads the finished page and records:</p>
          <ul>
            <li>Every visible button and link, and whether it has a name an agent can read: its text, an <code>aria-label</code>, a referenced label, a title, or the alt text of an image inside it.</li>
            <li>Every visible form field, and whether a label is connected to it. Fields with only placeholder text are counted separately, as a warning.</li>
            <li>The largest fixed or sticky element covering at least 15% of the screen, leaving out ordinary header bars along the top, and whether it has a clearly labelled button such as "Accept", "Close" or "No thanks".</li>
            <li>Things that look clickable but aren't buttons or links, the <code>&lt;main&gt;</code> and <code>&lt;nav&gt;</code> landmarks, and images with no <code>alt</code> attribute.</li>
          </ul>
          <p>On product and pricing pages, we look for the main action by its text, such as "Add to cart", "Buy now", "Start free trial" or "Sign up". We scroll it into view, check whether it's a real button or link, and ask the browser what element sits at its center. If that's a cookie banner rather than the button, an agent's click would land on the banner, and <strong>Agents can find and press your add-to-cart or sign-up button</strong> fails.</p>
          <h2>The WebMCP probe</h2>
          <p>WebMCP is a proposal for a browser feature, <code>navigator.modelContext</code>, that lets a page offer tools directly to an AI agent in the browser, such as "search products" or "add to cart". It isn't generally available in browsers yet, so sites that support it check for it first, roughly like this:</p>
          <pre><code>if ("modelContext" in navigator) {
  navigator.modelContext.registerTool({
    name: "search_products",
    description: "Search the Northwind catalog by keyword",
    inputSchema: { type: "object", properties: { query: { type: "string" } } },
    execute: async ({ query }) =&gt; searchCatalog(query),
  });
}</code></pre>
          <p>Before your scripts run, we add a stand-in for <code>navigator.modelContext</code> that writes down the name of every tool a page registers. A page that checks for WebMCP then registers its tools just as it would in a browser that supports it. We also look for forms marked up with a <code>toolname</code> attribute. We run the probe on the home, product and pricing pages and record names only: our stand-in never calls a tool. The result feeds <strong>Agents can use your site through MCP or WebMCP</strong>, where a missing setup is a warning, never a fail. Our guide to <a href="https://ghostagentlab.com/articles/mcp-webmcp-for-websites/">MCP and WebMCP for websites</a> explains both.</p>
          <h2>Keeping the browser safe</h2>
          <p>A service that opens any URL it's given is a target: someone could submit an address that points at an internal network or a cloud metadata service. So every connection the scanner makes is checked:</p>
          <ol>
            <li><strong>Only http and https.</strong> Other schemes are refused.</li>
            <li><strong>Public addresses only.</strong> Every address a host name resolves to must be publicly routable. Private, loopback, link-local, shared, reserved, documentation and multicast ranges are refused, for IPv4 and IPv6, including IPv4 addresses hidden inside IPv6 ones. Cloud metadata addresses are always refused.</li>
            <li><strong>Checked twice.</strong> Each request the page makes is checked before it goes out. Then all browser traffic, WebSockets included, passes through a small proxy that looks up the host name itself and connects only to addresses that pass. A host can't answer with a public address for the check and a private one for the connection.</li>
            <li><strong>Limits on plain fetches.</strong> Requests made without the browser are checked again at every redirect, follow at most five redirects, time out after 15 seconds and stop reading at a size limit, 5 MB for an ordinary page.</li>
          </ol>
          <h2>What the browser never does</h2>
          <ul>
            <li>It never clicks, types, signs in, adds to cart or submits a form. The only interaction is scrolling the main button into view to see what's on top of it.</li>
            <li>It doesn't dismiss your cookie banner. We measure the page as a first-time visitor meets it, because that's how most agents arrive.</li>
            <li>It doesn't pretend to be an AI agent. Comparisons between agents use plain requests, as described in <a href="https://ghostagentlab.com/blog/scanner-wears-other-names/">Why our scanner sometimes wears other agents' names</a>.</li>
            <li>It doesn't test a mobile layout, and it can't see a checkout that only opens with items in the cart. Checks that depend on one say "not tested" rather than guess.</li>
          </ul>
          <p>Finishing a real task is a different job. That's what <a href="https://ghostagentlab.com/ghost-agent/">Ghost Agents</a> do in the app: real AI agents run your journeys, stop at the payment form, and give you a step-by-step replay. The free scan marks Task completion as not tested and scores the other three categories.</p>
          <div>
            <p><strong>To reproduce a finding:</strong> open the page in a private window at desktop size and compare "View source" with what's on screen. If the price, product details or button is on screen but not in the source, agents that read the HTML don't get it. If a banner sits over the button on arrival, a browser agent meets it first.</p>
          </div>]]></content:encoded>
    </item>
    <item>
      <title>Reading your AgentScore report: what to fix first</title>
      <link>https://ghostagentlab.com/blog/reading-your-agentscore-report/</link>
      <guid>https://ghostagentlab.com/blog/reading-your-agentscore-report/</guid>
      <pubDate>Fri, 09 Oct 2026 13:16:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Product</category>
      <description>What each part of an AgentScore report means, from the verdict and statuses to severity and score impact, and how to turn it into a fix list.</description>
      <content:encoded><![CDATA[<p>An AgentScore report gives you a number, a sentence and a list of checks. The number tells you where you stand. The list tells you what to do about it, as long as you read it in the right order. This guide walks through each part of the report, in the free scan and in the Ghost Agent Labs app, and shows how to turn it into a short list of fixes with an owner for each.</p>
          <h2>Start at the top: score, band and verdict</h2>
          <p>The score is out of 100. It falls into one of four bands, and the verdict under it says what the band means:</p>
          <table>
            <thead><tr><th>Score</th><th>Band</th><th>Verdict</th></tr></thead>
            <tbody>
              <tr><td>80 and up</td><td>Good</td><td>AI agents can use this site well.</td></tr>
              <tr><td>60 to 79</td><td>Fair</td><td>AI agents can mostly use this site, but some things get in their way.</td></tr>
              <tr><td>40 to 59</td><td>Weak</td><td>AI agents will struggle on this site.</td></tr>
              <tr><td>Below 40</td><td>Poor</td><td>Most AI agents will fail on this site.</td></tr>
            </tbody>
          </table>
          <p>If any check failed, the verdict ends with <strong>Biggest issue</strong>: the summary of the failed check that carries the most weight. It's the single best place to start. If nothing failed, there's no biggest issue, and your work is in the warnings.</p>
          <p>One thing to know before you share the number: the free scan doesn't run an AI agent through a task, so Task completion shows as "n/a" and the score is worked out over Access, Readability and Navigability. A 72 means 72% of the points that could be tested. <a href="https://ghostagentlab.com/blog/how-agentscore-works/">How AgentScore works</a> has the arithmetic.</p>
          <h2>Then the categories</h2>
          <p>Each category gets a bar and its points, such as Access 20/25. The app shows the same thing as a share of the category's points, so Access 20/25 reads as 80/100. Use the bars to see where points are being lost, not to rank your work: a low Navigability bar with one failure in it can matter less than a single Access failure.</p>
          <p>Access comes first for a reason. If AI agents are blocked by your bot protection or robots.txt, they never see the pages the other two categories are about.</p>
          <h2>What each status means</h2>
          <table>
            <thead><tr><th>Status</th><th>What it means</th><th>Counts toward the score</th></tr></thead>
            <tbody>
              <tr><td>Passed</td><td>Agents will be fine here.</td><td>Full weight</td></tr>
              <tr><td>Warning</td><td>It works, but agents will stumble, or a newer standard is missing.</td><td>Half weight</td></tr>
              <tr><td>Failed</td><td>This stops or seriously misleads agents.</td><td>Nothing</td></tr>
              <tr><td>Not tested</td><td>The check couldn't run on your site.</td><td>Left out entirely</td></tr>
            </tbody>
          </table>
          <p>Checks are listed failures first, then warnings, then passes, then not tested. Each one has a one-line summary of what was found, often with an example, such as how many buttons have no name or which assistant was blocked.</p>
          <h2>Don't skip "not tested"</h2>
          <p>A "not tested" check never costs you points, and its summary always says why it was skipped. The reasons fall into a few groups:</p>
          <ul>
            <li><strong>It doesn't apply.</strong> Guest checkout, checkout fields, product data and agentic commerce are for stores. If the scan found no products or cart, they're skipped.</li>
            <li><strong>It needs a full cart.</strong> The scanner never adds anything to a cart, so a checkout that only opens with items in it can't be inspected.</li>
            <li><strong>A page couldn't be rendered.</strong> If the browser couldn't load a page, the checks that depend on it are skipped and say so. If it happens on every scan, ask a developer to check whether that page loads for a first-time desktop visitor.</li>
            <li><strong>It isn't in the free scan.</strong> "An AI agent completes a real task" is always not tested there.</li>
          </ul>
          <p>Read these anyway. If you run a store and the report says no product page was found from the home page or sitemap, that's worth knowing in itself: agents look for products the same way the scanner does.</p>
          <h2>Fixes, severity and score impact</h2>
          <p>Every warning and failure comes with a fix: the specific change to make. In the free report, you see the findings straight away and unlock the fixes with your email address. In the app, every fix is shown.</p>
          <p>The app's <strong>Findings</strong> page adds three things that make the list easier to work through:</p>
          <ul>
            <li><strong>Severity.</strong> A failure on a check with weight 4 or more is Critical, weight 2 or 3 is High, and weight 1 is Medium. A warning is Medium on a check with weight 3 or more, otherwise Low. A missing llms.txt is labelled Opportunity: worth doing, but a new standard, weighted lightly.</li>
            <li><strong>Score impact.</strong> How many points your overall score would gain if that finding were fixed. On a store where every Access check was tested, a failed <strong>Bot protection lets AI agents through</strong> is worth about 7 points; a missing llms.txt is worth about 1. The numbers depend on which checks could be tested on your site, so read them from your own report.</li>
            <li><strong>Why it matters and who usually fixes it.</strong> Open "Why it matters and how to fix it" under any finding for a plain-English reason, the fix, and the role that usually owns it: Developer, Bot protection or CDN admin, SEO or content team, or E-commerce platform admin.</li>
          </ul>
          <p>The Readiness page shows the top four as <strong>Biggest wins</strong>. The Findings page lets you filter by severity, and <strong>Export CSV</strong> downloads every finding with its severity, score impact, summary, why it matters, fix, who usually fixes it and the scan date, ready for a ticketing tool.</p>
          <h2>How to decide what to fix first</h2>
          <ol>
            <li><strong>Fix Access failures first.</strong> Blocked assistants, challenges on arrival and CAPTCHAs at the checkout stop agents before anything else matters. These usually sit with whoever runs your CDN or bot protection, and are often a settings change rather than a project. Our guide to <a href="https://ghostagentlab.com/articles/bot-protection-ai-agents/">bot protection and AI agents</a> covers the common causes.</li>
            <li><strong>Then the remaining Critical and High findings, by score impact.</strong> Content that only appears after JavaScript, a banner covering the add-to-cart button, and product pages with no price data are typical.</li>
            <li><strong>Group by owner, not by category.</strong> Sort the CSV by "Usually fixed by" and send each person their own short list. One ticket per owner moves faster than one long list for everyone.</li>
            <li><strong>Pick up cheap warnings along the way.</strong> Image alt text, page landmarks and a missing meta description are small changes that often ship with other work.</li>
            <li><strong>Leave opportunities until the basics pass.</strong> llms.txt, MCP and agentic commerce are worth doing, and score lightly for a reason: they help most once agents can already get in and read your pages.</li>
            <li><strong>Rescan after each batch.</strong> In the app you can rescan whenever you like and watch the trend. The free page reuses a domain's result for 24 hours.</li>
          </ol>
          <div>
            <p><strong>A rule of thumb:</strong> if a finding means agents can't get in or can't see your prices, it's this sprint. If it means they'll find it a little harder, it's this quarter. If it's a new standard, it's on the roadmap. Our <a href="https://ghostagentlab.com/blog/90-day-agent-readiness-plan/">90-day plan</a> lays that out week by week.</p>
          </div>
          <h2>What the report can't tell you</h2>
          <p>A high score means your site removes the common obstacles. It doesn't prove that an AI agent can find a product, choose a size and reach the payment step. That's what <a href="https://ghostagentlab.com/ghost-agent/">Ghost Agents</a> test in the app: real AI agents run your key journeys, stop at the payment form, and give you a step-by-step replay of where they got stuck. Use the report to clear the path, and <a href="https://ghostagentlab.com/articles/test-journeys-with-ai-agents/">journey tests</a> to prove it's clear.</p>]]></content:encoded>
    </item>
    <item>
      <title>Agent traffic isn't bot traffic</title>
      <link>https://ghostagentlab.com/blog/agent-traffic-is-not-bot-traffic/</link>
      <guid>https://ghostagentlab.com/blog/agent-traffic-is-not-bot-traffic/</guid>
      <pubDate>Fri, 09 Oct 2026 13:15:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Perspective</category>
      <description>Lumping AI agents in with scrapers hides customers. Why agent traffic needs its own categories, rules and reports, and how to start separating it.</description>
      <content:encoded><![CDATA[<p>Most websites sort their visitors into two piles: people and bots. People are customers. Bots are a cost, a risk, or noise to filter out of the reports. AI agents don't fit that split. Some of them are the closest thing your site has to a customer in the room, and treating them like scrapers means turning those customers away without knowing it.</p>
          <h2>The two-pile habit</h2>
          <p>The people-or-bots split made sense for a long time. Apart from search engine crawlers, which everyone learned to welcome, automated traffic was mostly scrapers, credential stuffers, inventory hoarders and uptime monitors. So the tools grew up around it. Bot protection scores each request on how human it looks. Analytics filters out known bots. Dashboards show "bot traffic" as one line, usually as a problem.</p>
          <p>AI agents arrive in that system looking like bots, because technically they are. But "bot" now covers software doing very different jobs for very different reasons, and some of those jobs are done for a specific person who wants to buy something.</p>
          <h2>Five kinds of automated visitor</h2>
          <table>
            <thead><tr><th>Kind</th><th>Examples</th><th>Why it's there</th><th>What it's worth to you</th></tr></thead>
            <tbody>
              <tr><td>AI assistants</td><td>ChatGPT-User, Claude-User, Perplexity-User</td><td>A person asked a question just now, and the assistant is reading your page to answer it</td><td>A live customer question about you</td></tr>
              <tr><td>Browser agents</td><td>Agents that run a real browser to complete a task, such as Ghost Agents</td><td>A person asked it to do something: compare, book, buy</td><td>A customer, part-way through a journey</td></tr>
              <tr><td>Search and AI search crawlers</td><td>OAI-SearchBot, Claude-SearchBot, PerplexityBot, Googlebot</td><td>Indexing pages so they can appear in search results and AI answers later</td><td>Visibility in tomorrow's answers</td></tr>
              <tr><td>AI training crawlers</td><td>GPTBot, ClaudeBot, CCBot, Google-Extended</td><td>Collecting content to train models</td><td>A business decision, not a customer</td></tr>
              <tr><td>Other bots</td><td>SEO tools, uptime monitors, link previews, scrapers</td><td>Their own reasons</td><td>Mostly a cost, sometimes useful</td></tr>
            </tbody>
          </table>
          <p>Google-Extended is a robots.txt token rather than a separate crawler, but it controls the same choice. Running through all five rows is a sixth problem: impostors. Scrapers often claim to be Googlebot or GPTBot to get past bot protection, so a name in a user agent proves nothing on its own.</p>
          <p>The top two rows are the ones the two-pile habit hurts most. An assistant fetch is one person's question. If it's blocked, that person gets an answer about somebody else. A browser agent that hits a CAPTCHA at checkout is an abandoned cart with no record of why. Neither shows up in your analytics, because most agents never run the tracking script, and both look like "bots" to a system tuned to stop bots.</p>
          <h2>What goes wrong when it's all one pile</h2>
          <ul>
            <li><strong>Blocking the wrong visitors.</strong> A rule written to stop scrapers stops ChatGPT-User too, and nobody notices because nobody is measuring it. Our guide to <a href="https://ghostagentlab.com/articles/bot-protection-ai-agents/">bot protection and AI agents</a> covers how this happens.</li>
            <li><strong>Making the wrong call on "AI".</strong> Blocking training is a reasonable choice. Blocking every AI user agent to achieve it also removes you from assistants and AI search. <a href="https://ghostagentlab.com/blog/block-or-allow-ai-crawlers/">Should you block AI crawlers?</a> splits the decision properly.</li>
            <li><strong>Reading growth as a threat.</strong> "Bot traffic is up" sounds like an attack. "Assistant fetches of our product pages are up" sounds like demand. They can be the same line on the same chart.</li>
            <li><strong>Missing the failures.</strong> If agent traffic is filtered out of reporting, so are the 403s, challenge pages and missing pages agents keep hitting. The journey breaks and the dashboard stays green.</li>
          </ul>
          <h2>Treat agent traffic as its own channel</h2>
          <p>The fix isn't to welcome every bot. It's to stop treating them as one thing. In practice that means four habits:</p>
          <ol>
            <li><strong>Measure it separately.</strong> Your server or CDN logs see every request, including the ones that never run JavaScript. Split them into the kinds above. <a href="https://ghostagentlab.com/articles/measure-ai-agent-traffic/">How to measure agent traffic</a> shows how.</li>
            <li><strong>Verify before you trust.</strong> Check a claimed agent against its operator's published IP ranges or reverse DNS, or a request signature where the operator signs its requests with Web Bot Auth. Our guides to <a href="https://ghostagentlab.com/articles/verify-ai-crawlers/">verifying AI crawlers</a> and <a href="https://ghostagentlab.com/blog/signed-requests/">signed requests</a> cover the methods.</li>
            <li><strong>Set rules per kind, not per "bot".</strong> Let verified assistants and AI search through to product, pricing, cart and checkout pages. Decide on training crawlers as a separate business question. Rate-limit and challenge the rest, and block impostors outright. <a href="https://ghostagentlab.com/articles/rate-limits-ai-agents/">Rate limits for AI agents</a> covers the middle ground.</li>
            <li><strong>Watch outcomes, not just volume.</strong> For each kind, track what it got back: pages served, redirects, blocks and missing pages. A rise in blocked assistant requests is a lost-sales signal, and should reach the same people as a broken checkout.</li>
          </ol>
          <div>
            <p><strong>One honest caveat:</strong> not every agent can be identified. Some browser agents use an ordinary browser's user agent and run from cloud addresses, so they look like people, or like a bot your protection doesn't recognize. Signed requests will help as more operators adopt them. Until then, the best evidence of how these agents fare is to <a href="https://ghostagentlab.com/articles/test-journeys-with-ai-agents/">run AI agents through your journeys</a> yourself.</p>
          </div>
          <h2>What it means for your reports</h2>
          <p>The most useful change is often the simplest: stop putting AI agents in the "bots" line. Give assistants, browser agents, AI search and training crawlers their own lines, alongside people, and report what each one got back. When a leader asks "is AI a threat or an opportunity for us?", that report answers with your own numbers instead of an opinion. Our guide to <a href="https://ghostagentlab.com/articles/agent-readiness-kpis/">agent readiness KPIs</a> suggests what to put in front of them each month, and <a href="https://ghostagentlab.com/articles/ai-referral-traffic/">tracking AI referral traffic</a> covers the visits and sales that follow.</p>
          <p>In the Ghost Agent Labs app, <strong>Agent traffic</strong> does this split from your server or CDN logs: people, search crawlers, AI training crawlers, AI assistants and autonomous agents, with each assistant's fetches grouped into sessions and a breakdown of how often agents were served, redirected, blocked or sent to missing pages. <strong>Verification</strong> separates verified agents from impostors.</p>
          <p>Your next customer may arrive as a request with a user agent you've never looked at. It's worth knowing which pile you've put it in.</p>]]></content:encoded>
    </item>
    <item>
      <title>SEO got you found. Agent readiness gets you chosen</title>
      <link>https://ghostagentlab.com/blog/seo-to-agent-readiness/</link>
      <guid>https://ghostagentlab.com/blog/seo-to-agent-readiness/</guid>
      <pubDate>Fri, 09 Oct 2026 12:22:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Perspective</category>
      <description>SEO decides whether AI agents find you. Agent readiness decides whether they can use your site and choose you. What carries over, and what's new.</description>
      <content:encoded><![CDATA[<p>For twenty years, SEO has answered one question: when someone searches, do they find you? AI agents add a second question that SEO was never designed to answer. When an agent arrives on someone's behalf, can it actually use your site? Getting found is still the start. Getting chosen now depends on what happens next.</p>
          <h2>What SEO was built for</h2>
          <p>Search engines crawl, index and rank. A person sees a list of results, clicks one, and does the rest themselves. Everything after the click is the person's job: reading the page, closing the cookie banner, finding the size selector, getting through checkout. If the site is awkward, people usually push through.</p>
          <p>SEO teams have become very good at the part before the click. Titles, descriptions, sitemaps, structured data, internal links, page speed, crawl budgets. All of that still matters.</p>
          <h2>What changes when an agent does the clicking</h2>
          <p>When someone asks an AI assistant to compare three running shoes, check which one is in stock in a size 10, and buy it, there is no results page and often no click by a person. The assistant fetches pages itself. A browser agent may open your site, search your catalog and try to add to cart.</p>
          <p>That shifts the work from the person to the agent, and agents don't push through. If the price isn't readable, the agent can't quote it. If a pop-up has no labelled close button, the journey ends there. If bot protection challenges the assistant's request, the person gets a competitor's answer instead of yours. Nobody tells you. The visit simply doesn't turn into anything.</p>
          <p>So the question moves from "do we rank?" to "when an agent arrives, can it get in, understand the page, find its way and finish the job?" That's what we mean by <a href="https://ghostagentlab.com/articles/agent-readiness/">agent readiness</a>.</p>
          <h2>Where SEO already gets you most of the way</h2>
          <p>The good news for SEO teams is that a lot of the groundwork is shared. Several AgentScore checks will look familiar.</p>
          <table>
            <thead><tr><th>SEO practice</th><th>What it does for AI agents</th></tr></thead>
            <tbody>
              <tr><td>A clean robots.txt</td><td>The same file controls AI assistants, AI search and training crawlers, each by its own name. See <a href="https://ghostagentlab.com/articles/robots-txt-ai-agents/">robots.txt for AI agents</a>.</td></tr>
              <tr><td>Clear titles, descriptions and headings</td><td>How an agent decides whether a page answers the question it was sent to ask. See <a href="https://ghostagentlab.com/articles/titles-descriptions-headings-ai/">titles, descriptions and headings AI agents understand</a>.</td></tr>
              <tr><td>Product structured data</td><td>Lets an assistant quote your price and stock correctly instead of guessing. See <a href="https://ghostagentlab.com/articles/structured-data-ai-shopping-agents/">product data AI shopping agents can read</a>.</td></tr>
              <tr><td>A valid XML sitemap</td><td>Helps agents find pages that aren't linked prominently. See <a href="https://ghostagentlab.com/articles/xml-sitemaps-ai-agents/">XML sitemaps for AI agents</a>.</td></tr>
              <tr><td>Image alt text</td><td>The only way an agent reading text knows what a product photo shows. See <a href="https://ghostagentlab.com/articles/image-alt-text-ai-agents/">alt text for AI agents</a>.</td></tr>
            </tbody>
          </table>
          <p>If your SEO is in good shape, you have a head start. But it's a head start, not the finish.</p>
          <h2>Where SEO stops and agent readiness carries on</h2>
          <h3>Being let in, not just crawled</h3>
          <p>SEO teams check that Googlebot can crawl. They rarely check how bot protection treats ChatGPT-User, Perplexity-User or a browser agent. A site can rank well and still challenge every AI assistant at the door, because the rules that protect it from scrapers were tuned for a world where the only good bots were search engines. See <a href="https://ghostagentlab.com/articles/bot-protection-ai-agents/">bot protection and CAPTCHAs</a>.</p>
          <h3>Content that exists without JavaScript</h3>
          <p>Google renders JavaScript, so a page built entirely in the browser can still rank. Most AI crawlers and many assistants don't run JavaScript. They read the HTML your server sends, and if the price or description only appears after scripts load, they see an empty page. See <a href="https://ghostagentlab.com/articles/javascript-content-ai-agents/">why AI agents can't see JavaScript-only content</a> and <a href="https://ghostagentlab.com/articles/machine-readable-prices/">prices AI agents can read</a>.</p>
          <h3>A page that can be used, not just read</h3>
          <p>SEO ends at the landing page. Agent readiness carries on through the page: buttons and links with names, form fields with labels, pop-ups that can be closed, and an add-to-cart button an agent can find and press. These look like accessibility concerns because they largely are. See <a href="https://ghostagentlab.com/blog/accessibility-is-agent-readiness/">accessibility work is agent readiness work</a>.</p>
          <h3>A task that can be finished</h3>
          <p>The biggest difference is the last step. An agent sent to buy something either completes the purchase or it doesn't. No ranking report tells you which. The only way to know is to send a real agent through the journey and watch. That's what <a href="https://ghostagentlab.com/blog/introducing-ghost-agents/">Ghost Agents</a> do, and it's why Task completion carries the most weight in <a href="https://ghostagentlab.com/blog/how-agentscore-works/">AgentScore</a>.</p>
          <h3>Measuring what agents bring</h3>
          <p>SEO is measured in rankings, impressions and organic sessions. Agents mostly don't run your analytics tag, so they don't show up in those numbers. Agent visits live in server and CDN logs, and the visits and sales that AI assistants refer need their own tracking. See <a href="https://ghostagentlab.com/articles/measure-ai-agent-traffic/">how to measure agent traffic</a> and <a href="https://ghostagentlab.com/articles/ai-referral-traffic/">tracking visits and sales that come from AI assistants</a>.</p>
          <h2>Found versus chosen</h2>
          <p>Here's the simplest way to put the difference to a leadership team.</p>
          <ul>
            <li><strong>SEO gets you found.</strong> It decides whether you're in the answer, and how prominently.</li>
            <li><strong>Agent readiness gets you chosen.</strong> It decides whether an agent that found you can confirm the price, check the returns policy and complete the order, or whether it gives up and picks a site it can use.</li>
          </ul>
          <p>An assistant that can't read your stock level has no reason to recommend you over a competitor whose stock level is right there in the HTML. Being found and then failing the agent is close to not being found at all.</p>
          <h2>What this means for SEO teams</h2>
          <p>This isn't a new discipline that replaces SEO. It's SEO's natural next step, and SEO teams are well placed to lead it. They already own robots.txt, titles, sitemaps and much of the content. They already work with developers on structured data and rendering. What's new is a set of partners SEO hasn't always needed: whoever runs bot protection and the CDN, and whoever owns checkout. We cover that split in <a href="https://ghostagentlab.com/blog/who-owns-agent-readiness/">who owns agent readiness?</a></p>
          <div>
            <p><strong>Three things an SEO lead can do this week:</strong></p>
            <ol>
              <li>Check robots.txt for rules that block AI assistants or AI search by accident, and decide separately what to do about training crawlers. Our <a href="https://ghostagentlab.com/blog/block-or-allow-ai-crawlers/">decision guide</a> helps.</li>
              <li>View the source of a top product page and confirm the price, stock and description are in the HTML, not added later by JavaScript.</li>
              <li>Run <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> on your home page and share the Access findings with whoever runs your CDN or bot protection.</li>
            </ol>
          </div>
          <p>If you want a structured path from there, our <a href="https://ghostagentlab.com/blog/90-day-agent-readiness-plan/">90-day agent readiness plan</a> breaks the work into three phases.</p>]]></content:encoded>
    </item>
    <item>
      <title>How AgentScore works: what's behind the 100 points</title>
      <link>https://ghostagentlab.com/blog/how-agentscore-works/</link>
      <guid>https://ghostagentlab.com/blog/how-agentscore-works/</guid>
      <pubDate>Fri, 09 Oct 2026 12:21:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Product</category>
      <description>How AgentScore turns its checks into a score out of 100: the four categories, how points are earned, which pages it visits, and what isn't scored yet.</description>
      <content:encoded><![CDATA[<p>AgentScore gives your website one number out of 100 for how well AI agents can get in, read your pages and find their way around. A single number is only useful if you trust it, so here is exactly how it's worked out: the four categories, how each check earns points, which pages the scanner visits, and what it doesn't score yet.</p>
          <h2>Four categories, 100 points</h2>
          <p>Every check belongs to one of four categories. Each category has a fixed number of points, set by how much it matters to an AI agent trying to do something for a customer.</p>
          <table>
            <thead><tr><th>Category</th><th>Points</th><th>The question it answers</th></tr></thead>
            <tbody>
              <tr><td>Access</td><td>25</td><td>Can AI agents get in, past robots.txt, bot protection and challenges?</td></tr>
              <tr><td>Readability</td><td>25</td><td>Can they understand your pages without guessing?</td></tr>
              <tr><td>Navigability</td><td>20</td><td>Can they find and use the buttons, links and forms they need?</td></tr>
              <tr><td>Task completion</td><td>30</td><td>Can an AI agent actually finish a real task, such as reaching checkout?</td></tr>
            </tbody>
          </table>
          <p>The background to these categories is in <a href="https://ghostagentlab.com/articles/agent-readiness/">our guide to agent readiness</a>. This post is about the mechanics.</p>
          <h2>How a check earns points</h2>
          <p>Each check ends in one of four results:</p>
          <ul>
            <li><strong>Pass</strong> earns the check's full weight.</li>
            <li><strong>Warning</strong> earns half. Something works, but agents will stumble on it.</li>
            <li><strong>Fail</strong> earns nothing.</li>
            <li><strong>Not tested</strong> is left out of the sum entirely. It never counts against you.</li>
          </ul>
          <p>Within a category, checks carry different weights, because some problems stop an agent cold and others only slow it down. A category's score is its points multiplied by the share of weight you earned among the checks that could be tested. If Readability's tested checks are worth 17 in total and you earn 13.5 of them, you get 25 &times; 13.5 &divide; 17, or 19.9 out of 25.</p>
          <p>The overall score adds up the categories that could be tested and scales the result to 100. So if Task completion wasn't tested and you scored 20 for Access, 17 for Readability and 11 for Navigability, your AgentScore is 48 out of a possible 70, which is 69.</p>
          <p>Most checks are rule-based rather than judged by an AI model, so the same site gets the same score from one scan to the next. When it moves, something on the site changed.</p>
          <h2>What the bands mean</h2>
          <table>
            <thead><tr><th>Score</th><th>Band</th><th>What we tell you</th></tr></thead>
            <tbody>
              <tr><td>80 and up</td><td>Good</td><td>AI agents can use this site well.</td></tr>
              <tr><td>60 to 79</td><td>Fair</td><td>AI agents can mostly use this site, but some things get in their way.</td></tr>
              <tr><td>40 to 59</td><td>Weak</td><td>AI agents will struggle on this site.</td></tr>
              <tr><td>Below 40</td><td>Poor</td><td>Most AI agents will fail on this site.</td></tr>
            </tbody>
          </table>
          <p>The one-line verdict at the top of a report also names your biggest issue: the failed check with the highest weight.</p>
          <h2>The checks, by category</h2>
          <p>Here is what each category looks at today. The weight is how much the check counts inside its category.</p>
          <h3>Access</h3>
          <ul>
            <li><strong>Bot protection lets AI agents through</strong> (weight 4). We request your home page as five AI agents and as a normal browser, and compare. If any agent is blocked or challenged while the browser gets through, it fails. If an agent gets less than half the browser's text, it's a warning.</li>
            <li><strong>robots.txt lets AI assistants and search agents in</strong> (3). Blocking one or two assistants or AI search agents is a warning; three or more is a fail. Blocked training crawlers are reported but not scored.</li>
            <li><strong>AI agents can open your product, pricing and cart pages</strong> (3).</li>
            <li><strong>AI agents aren't blocked or shown a CAPTCHA at the cart and checkout</strong> (3).</li>
            <li><strong>No CAPTCHA or challenge on arrival</strong> (2).</li>
            <li><strong>Shoppers can check out without an account</strong> (2).</li>
            <li><strong>llms.txt guide for AI</strong> (1), <strong>Agents can use your site through MCP or WebMCP</strong> (1) and <strong>Agents can check out through an agentic commerce protocol</strong> (1). These are newer standards, so a missing one is a warning, never a fail.</li>
          </ul>
          <h3>Readability</h3>
          <ul>
            <li><strong>Content loads without JavaScript</strong> (4): how much of the page's text is in the HTML before scripts run.</li>
            <li><strong>Structured data describes your business and products</strong> (3) and <strong>Product pages give price and stock in a form agents can read</strong> (3).</li>
            <li><strong>Clear page title, description, and headings</strong> (2), <strong>Valid sitemap</strong> (2) and <strong>Prices are in the page HTML</strong> (2).</li>
            <li><strong>Images have text descriptions</strong> (1).</li>
          </ul>
          <h3>Navigability</h3>
          <ul>
            <li><strong>Buttons and links have names</strong> (4) and <strong>Pop-ups and banners can be dismissed by agents</strong> (4).</li>
            <li><strong>Agents can find and press your add-to-cart or sign-up button</strong> (3) and <strong>Cart and checkout fields are labelled for agents</strong> (3).</li>
            <li><strong>Form fields are labelled</strong> (2), <strong>Page has main and navigation landmarks</strong> (2), <strong>Clickable things are real buttons and links</strong> (2) and <strong>Key pages are linked from the home page</strong> (2).</li>
          </ul>
          <p>Weights can change between scoring versions as we learn what trips agents up. Every report records the scoring version it used, so you can compare like with like.</p>
          <h2>What the scanner visits</h2>
          <p>AgentScore reads public pages only. It never adds anything to a cart, submits a form, signs up or places an order. In one scan it looks at:</p>
          <ol>
            <li><strong>Your home page</strong>, three ways: as a browser sees it before JavaScript runs, rendered in a real browser, and as five AI agents (ChatGPT-User, Claude-User, Perplexity-User, OAI-SearchBot and Googlebot).</li>
            <li><strong>Your robots.txt, sitemap and llms.txt</strong>, plus the well-known addresses where sites describe an MCP server or an agentic commerce profile.</li>
            <li><strong>Up to three key pages</strong>: a product page, a pricing page and the cart. It looks for them the way an agent would, in the links on your home page first, then in your sitemap, then at common addresses such as <code>/pricing</code> and <code>/cart</code>. Each is fetched as a browser and as an AI assistant, and product and pricing pages are rendered in a browser too.</li>
            <li><strong>Your checkout</strong>, found from the link on the cart page or at <code>/checkout</code>, fetched as a browser and as three AI assistants.</li>
          </ol>
          <p>Requests under the scanner's own name are signed so you can verify them. The requests that imitate AI agents are not, on purpose. We explain why in <a href="https://ghostagentlab.com/blog/scanner-wears-other-names/">Why our scanner sometimes wears other agents' names</a>. How it identifies itself and how to opt out are on the <a href="https://ghostagentlab.com/agentscore/bot/">AgentScore bot</a> page.</p>
          <h2>What isn't scored yet</h2>
          <div>
            <p><strong>Task completion.</strong> The automated scan doesn't run an AI agent through a task yet, so "An AI agent completes a real task" shows as not tested and your score covers Access, Readability and Navigability. In the Ghost Agent Labs app, <a href="https://ghostagentlab.com/blog/introducing-ghost-agents/">Ghost Agent tests</a> already send real AI agents through your journeys. Their results don't feed into AgentScore yet.</p>
            <p><strong>Store-only checks on other sites.</strong> Guest checkout, checkout fields, product data and agentic commerce only apply to stores. If we find no products or cart, they're marked not tested.</p>
            <p><strong>Anything behind a full cart.</strong> Many checkouts only open with items in the cart. Because the scanner never adds any, those checks often say "not tested" rather than guess.</p>
            <p><strong>Your choice on training crawlers.</strong> Blocking AI training is a business decision, not a readiness problem, so it costs no points.</p>
          </div>
          <h2>How to use your score</h2>
          <ol>
            <li>Read the verdict and the biggest issue first. It's the highest-weight failure.</li>
            <li>Fix failures before warnings, and Access before everything else: if agents can't get in, nothing else matters.</li>
            <li>Hand each finding to the right person. Most Access problems belong to whoever runs your CDN or bot protection; most Navigability problems belong to developers.</li>
            <li>Rescan after each fix. In the Ghost Agent Labs app you can rescan whenever you like. The free AgentScore page reuses a domain's result for 24 hours, so repeated requests don't hit your site again.</li>
          </ol>
          <p>Then go beyond the score: set up <a href="https://ghostagentlab.com/articles/test-journeys-with-ai-agents/">tests of your key journeys with AI agents</a>, so you know when a release breaks them.</p>]]></content:encoded>
    </item>
    <item>
      <title>Ghost Agents: testing your site with real AI agents</title>
      <link>https://ghostagentlab.com/blog/introducing-ghost-agents/</link>
      <guid>https://ghostagentlab.com/blog/introducing-ghost-agents/</guid>
      <pubDate>Fri, 09 Oct 2026 12:20:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Product</category>
      <description>Ghost Agents are real AI agents that run your checkout, search and sign-up journeys on a schedule, with pass rates, step-by-step replays and alerts.</description>
      <content:encoded><![CDATA[<p>A readiness score tells you what might trip an AI agent up. It can't tell you whether one actually gets from your home page to checkout. Ghost Agents do. They're real AI agents that work through your key journeys the way a customer's assistant would, on a schedule, and show you every step.</p>
          <h2>Why test with a real agent</h2>
          <p>Checks for labelled buttons, structured data and bot protection catch the common problems. But journeys fail in ways no rule predicts: a size picker the agent can't operate, a discount pop-up that appears on the second page, a checkout button that only shows after scrolling. People get past these without noticing. Agents often don't.</p>
          <p>This is what our team has done for human visitors for years with <a href="https://ghostinspector.com/">Ghost Inspector</a>: prove the journeys that make you money still work, and find out when a release breaks one. Ghost Agents bring the same idea to AI agents.</p>
          <h2>How a test works</h2>
          <p>You write a goal in plain English, the way a customer might ask an AI assistant. To make it quick, there are ready-made templates for the journeys that matter most:</p>
          <table>
            <thead><tr><th>Template</th><th>What the agent tries to do</th></tr></thead>
            <tbody>
              <tr><td>Checkout</td><td>Find a popular product, add it to the cart, and check out as a guest up to the payment step</td></tr>
              <tr><td>Product search</td><td>Use site search to find a product a customer might ask for, and open its page</td></tr>
              <tr><td>Sign-up</td><td>Create an account with a test email address, as far as the site allows without email confirmation</td></tr>
              <tr><td>Contact form</td><td>Find the contact or support form and fill it in with a short test question, without submitting it</td></tr>
            </tbody>
          </table>
          <p>On each run, the agent opens your site in a fresh browser and repeats a simple loop. It looks at the page as an agent sees it: the address, the visible text, and the buttons, links and fields with their names. It picks one action, such as click, type, choose an option, scroll, go back or finish. Then it acts, and looks again.</p>
          <h2>How you know it passed</h2>
          <p>An agent saying "done" isn't proof. So you choose pass conditions that are checked against the final page the agent reaches, without asking an AI model:</p>
          <ul>
            <li>The page address contains some text, such as <code>/checkout</code>.</li>
            <li>The page shows some text, such as "Thanks for signing up".</li>
            <li>The agent reached the payment step. This is the one to use for checkout tests.</li>
            <li>The agent reports the goal is done. This is used only if you set no other condition.</li>
          </ul>
          <p>AI agents don't behave the same way every time, so each check runs the journey several times (three is a good default) and reports a pass rate. A test where every run passes is passing. One where none pass is failing. One where results disagree is flaky: agents can do the journey, but not reliably, which for a customer's assistant can mean the same as not at all.</p>
          <p>Tests run when you click "Run now", every day, or every hour. When one fails, you can be alerted by email or Slack.</p>
          <h2>Replays: see exactly where it got stuck</h2>
          <p>Every run is recorded. The replay opens on the step where things went wrong, with a screenshot of what the agent saw, the action it took, and its reasoning, which often says in plain words what it couldn't find or press. If a journey used to work, you can compare the failed run with the last passing one to see what changed.</p>
          <p>That turns "agents can't check out" into something a developer can act on: "the cookie banner covers the checkout button and has no labelled close button".</p>
          <h2>Safe by design</h2>
          <p>A test agent that clicks around a live store has to be careful. Ghost Agents follow hard rules that the model can't talk its way past:</p>
          <ul>
            <li>They stop as soon as a payment form appears, and never enter card details. Reaching that point is how a checkout test passes.</li>
            <li>They refuse buttons that place orders, pay, or delete or cancel an account.</li>
            <li>They type only the test data you give the test, such as a test email address.</li>
            <li>They stay on the site being tested.</li>
            <li>Each run stops after 40 steps or five minutes, whichever comes first.</li>
          </ul>
          <p>They also identify themselves. Every request carries <code>GhostAgent/1.0 (+https://ghostagentlab.com/ghost-agent)</code> at the end of a normal Chrome user agent and is signed with Web Bot Auth, so your CDN can verify it's really us. We explain signing in <a href="https://ghostagentlab.com/blog/signed-requests/">Why we sign every request our agents send</a>, and the <a href="https://ghostagentlab.com/ghost-agent/">Ghost Agent</a> page covers how to allow or opt out.</p>
          <h2>What Ghost Agents don't do yet</h2>
          <p>We'd rather you knew the limits up front:</p>
          <ul>
            <li><strong>They don't feed AgentScore yet.</strong> Task completion is the AgentScore category these tests will fill. Until they're connected, the score covers Access, Readability and Navigability. See <a href="https://ghostagentlab.com/blog/how-agentscore-works/">How AgentScore works</a>.</li>
            <li><strong>One agent per run.</strong> Every agent gets the same instructions and tools, so results from different AI models can be compared, but running several side by side in one check isn't available yet.</li>
            <li><strong>No release triggers yet.</strong> Tests run on demand or on a schedule, not automatically after each deploy.</li>
            <li><strong>No payments.</strong> By design, a checkout test proves an agent can reach payment. It never completes one.</li>
          </ul>
          <h2>Where to start</h2>
          <div>
            <ol>
              <li>Run <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> and fix anything that keeps agents out, such as blocked assistants or a challenge page. A Ghost Agent can't test a journey it can't start.</li>
              <li>In the app, add your site and create a Checkout test (or Sign-up, if you sell software). Run it once by hand.</li>
              <li>Watch the replay, even if it passed. You'll learn how agents read your pages.</li>
              <li>Set it to run daily and turn on alerts, so you hear about the release that breaks agent checkout before your customers' assistants do.</li>
            </ol>
          </div>
          <p>For help choosing journeys and writing good goals, read <a href="https://ghostagentlab.com/articles/test-journeys-with-ai-agents/">How to test your key journeys with AI agents</a>.</p>]]></content:encoded>
    </item>
    <item>
      <title>Accessibility work is agent readiness work</title>
      <link>https://ghostagentlab.com/blog/accessibility-is-agent-readiness/</link>
      <guid>https://ghostagentlab.com/blog/accessibility-is-agent-readiness/</guid>
      <pubDate>Fri, 09 Oct 2026 12:19:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Perspective</category>
      <description>Many browser agents read pages through the accessibility tree. Where WCAG and agent readiness overlap, where they differ, and how to make fixes pay twice.</description>
      <content:encoded><![CDATA[<p>If your team has spent time making your site work with screen readers and keyboards, you've already done a large share of the work to make it work for AI agents. The reason is simple: many browser agents read a page through the same structure that assistive technology uses.</p>
          <h2>How a browser agent sees a page</h2>
          <p>A person looks at a page and sees layout, color and images. A browser agent, the kind that opens your site in a real browser to search, fill in forms and add to cart, needs something it can reason about and act on. It has two main options.</p>
          <ul>
            <li><strong>Screenshots.</strong> The agent looks at an image of the page and decides where to click. This works, but it's slow, and it struggles with small icons, overlapping elements and anything that looks clickable but isn't.</li>
            <li><strong>The accessibility tree.</strong> Browsers already build a structured version of every page for assistive technology: each heading, link, button and form field, with its role (what kind of thing it is), its name (what it's called) and its state (checked, expanded, disabled). Many agents read this tree, often alongside screenshots, because it tells them exactly what can be clicked and what each thing is for.</li>
          </ul>
          <p>The tooling used to build agents reflects this. Playwright's MCP server, a widely used way to give an AI model control of a browser, hands the model an accessibility snapshot of the page rather than pixels. In that snapshot, a button is a line like <code>button "Add to cart"</code>. A button with no name is just <code>button</code>, and the agent has to guess.</p>
          <pre><code>&lt;!-- What the agent can use --&gt;
&lt;button type="submit"&gt;Add to cart&lt;/button&gt;
&lt;button aria-label="Open cart"&gt;&lt;svg aria-hidden="true"&gt;…&lt;/svg&gt;&lt;/button&gt;
&lt;!-- What it can't --&gt;
&lt;div class="btn" onclick="addToCart()"&gt;&lt;svg&gt;…&lt;/svg&gt;&lt;/div&gt;</code></pre>
          <p>The last example has no role and no name. A screen reader user can't use it, and an agent reading the accessibility tree may not know it exists.</p>
          <h2>Where WCAG and agent readiness overlap</h2>
          <p>The <a href="https://www.w3.org/TR/WCAG22/">Web Content Accessibility Guidelines (WCAG) 2.2</a> are the standard most accessibility programs work to. Several of their success criteria line up closely with AgentScore checks.</p>
          <table>
            <thead><tr><th>WCAG 2.2 success criterion</th><th>Related AgentScore check</th></tr></thead>
            <tbody>
              <tr><td>4.1.2 Name, Role, Value</td><td>Buttons and links have names; Clickable things are real buttons and links</td></tr>
              <tr><td>1.3.1 Info and Relationships, 3.3.2 Labels or Instructions</td><td>Form fields are labelled; Cart and checkout fields are labelled for agents</td></tr>
              <tr><td>1.1.1 Non-text Content</td><td>Images have text descriptions</td></tr>
              <tr><td>2.4.1 Bypass Blocks, 1.3.1 Info and Relationships</td><td>Page has main and navigation landmarks</td></tr>
              <tr><td>2.4.2 Page Titled, 2.4.6 Headings and Labels</td><td>Clear page title, description, and headings</td></tr>
              <tr><td>2.1.2 No Keyboard Trap, 2.4.11 Focus Not Obscured (Minimum)</td><td>Pop-ups and banners can be dismissed by agents</td></tr>
            </tbody>
          </table>
          <p>The match isn't exact. WCAG asks more of each criterion than our checks test for, and our checks look at things from an agent's point of view. But the direction is the same: give every control a role and a name, label every field, describe every meaningful image, and structure the page so it can be navigated without seeing it.</p>
          <p>Our guide to <a href="https://ghostagentlab.com/articles/agent-friendly-buttons-forms/">buttons, links and forms agents can use</a> covers the fixes in detail, and <a href="https://ghostagentlab.com/articles/image-alt-text-ai-agents/">alt text for AI agents</a> covers product images.</p>
          <h2>Common accessibility gaps that also stop agents</h2>
          <ul>
            <li><strong>Icon-only buttons with no label.</strong> The cart, search and menu icons in a header are the usual culprits. Add visible text or an <code>aria-label</code>.</li>
            <li><strong>Placeholder text used as a label.</strong> It disappears when the field is filled in and isn't a reliable name. Use a real <code>&lt;label&gt;</code>.</li>
            <li><strong>Clickable boxes.</strong> A <code>div</code> with a click handler looks like a button to a person and like plain text to the accessibility tree. Use <code>&lt;button&gt;</code> or <code>&lt;a href&gt;</code>.</li>
            <li><strong>Menus that only open on hover.</strong> Neither keyboard users nor many agents can hover. Open them on click and focus too.</li>
            <li><strong>Custom size and color pickers.</strong> If a swatch has no name and no selected state, an agent can't tell which size it chose. Native radio buttons or properly labelled custom controls fix this.</li>
            <li><strong>Pop-ups without a labelled close button.</strong> See <a href="https://ghostagentlab.com/articles/cookie-banners-popups-ai-agents/">cookie banners and pop-ups that trap AI agents</a>.</li>
          </ul>
          <h2>Where they differ</h2>
          <p>Accessibility work won't cover everything, and some of it doesn't matter to agents at all.</p>
          <p><strong>Agent readiness needs more than accessibility.</strong> A perfectly accessible site can still block AI assistants in robots.txt, challenge them with bot protection, or load its prices with JavaScript that many AI crawlers never run. Screen readers work inside a real browser, so they see JavaScript content; many agents don't. Structured data, sitemaps and llms.txt matter to agents and have little to do with accessibility. That's why AgentScore has Access and Readability categories as well as Navigability.</p>
          <p><strong>Some accessibility work matters less to agents.</strong> Color contrast, text resizing, captions and motion settings are essential for people and largely irrelevant to software. Don't use agent readiness as a reason to deprioritize them. They serve customers, and in many places they're a legal requirement.</p>
          <p><strong>Bad ARIA hurts both.</strong> The W3C's own guidance is that no ARIA is better than bad ARIA. An <code>aria-label</code> that says "button", a <code>role="button"</code> on something that can't be pressed, or <code>aria-hidden="true"</code> on a real control misleads screen readers and agents alike. Native HTML elements are almost always the better choice.</p>
          <div>
            <p><strong>A note for leaders:</strong> in the EU, the European Accessibility Act has applied to many e-commerce services since June 2025, so many retailers already have accessibility programs underway. If yours does, put agent readiness alongside it rather than starting a separate project. The same fixes, the same developers and often the same tickets.</p>
          </div>
          <h2>How to use this</h2>
          <ol>
            <li><strong>Ask your accessibility lead for the latest audit.</strong> Unlabelled controls, missing form labels and keyboard traps in that report are agent readiness issues too. Fixing them pays twice.</li>
            <li><strong>Add an agent's view to your testing.</strong> Run <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> and compare its Navigability findings with your audit. Then send a <a href="https://ghostagentlab.com/blog/introducing-ghost-agents/">Ghost Agent</a> through checkout to see whether a real agent can finish.</li>
            <li><strong>Make it part of the definition of done.</strong> New components ship with names, labels and native elements. That's cheaper than fixing them later, for people and agents alike.</li>
          </ol>
          <p>Accessibility and agent readiness come from the same idea: a website should work for visitors who don't see it the way its designers do. More and more of those visitors are software acting for a person.</p>]]></content:encoded>
    </item>
    <item>
      <title>Why our scanner sometimes wears other agents' names</title>
      <link>https://ghostagentlab.com/blog/scanner-wears-other-names/</link>
      <guid>https://ghostagentlab.com/blog/scanner-wears-other-names/</guid>
      <pubDate>Fri, 09 Oct 2026 12:18:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Engineering</category>
      <description>AgentScore requests a few pages as ChatGPT, Claude, Perplexity and Googlebot, unsigned, to see how your site treats them. Here's exactly what and why.</description>
      <content:encoded><![CDATA[<p>If you look closely at your logs during an AgentScore scan, you'll see a few requests that say they're ChatGPT, Claude, Perplexity or Googlebot. They aren't. They're our scanner, borrowing those agents' user agents to see how your site treats them. Here's why we do it, exactly what we send, and what the result can and can't tell you.</p>
          <h2>The question we're trying to answer</h2>
          <p>One of the most common reasons an AI agent fails on a website has nothing to do with the website's design. The agent is turned away at the door. A bot protection rule, a firewall setting or a CDN feature decides that anything calling itself an AI agent gets a challenge page, an error, or a stripped-down page with no prices.</p>
          <p>Nobody notices, because people never see it. The site works perfectly in a browser. The only way to find out is to knock as the agent and compare what comes back with what a browser gets.</p>
          <p>We can't send the real ChatGPT to your site on demand. So for a handful of requests, our scanner sends the same <code>User-Agent</code> header those agents send, and compares the answer with a normal browser's.</p>
          <h2>Exactly what we send</h2>
          <table>
            <thead><tr><th>Name we use</th><th>What we request</th><th>Signed?</th></tr></thead>
            <tbody>
              <tr><td><code>AgentScore/1.0</code>, our own name</td><td>robots.txt, sitemaps, llms.txt, well-known files (MCP and agentic commerce discovery), and checks for common pages such as <code>/pricing</code> and <code>/cart</code></td><td>Yes</td></tr>
              <tr><td>A normal Chrome browser</td><td>The home page, your llms.txt, and the key pages, before and after JavaScript runs. This is the baseline everything is compared with</td><td>No</td></tr>
              <tr><td>ChatGPT-User, Claude-User, Perplexity-User, OAI-SearchBot and Googlebot</td><td>The home page, once each</td><td>No</td></tr>
              <tr><td>ChatGPT-User</td><td>The product, pricing and cart pages we found, once each</td><td>No</td></tr>
              <tr><td>ChatGPT-User, Claude-User and Perplexity-User</td><td>The cart and checkout, once each</td><td>No</td></tr>
            </tbody>
          </table>
          <p>The imitated requests use the user agent strings those operators publish, so they look the way the real thing does. We picked these agents because they're the ones that fetch pages for people in real time or power AI search, which are the visits most likely to turn into customers.</p>
          <p>Training crawlers such as GPTBot and ClaudeBot are handled differently. We read your robots.txt rules for them, along with every other AI agent we track, but we don't request pages as them. Blocking training is a business choice, and it doesn't cost points. Our guide to <a href="https://ghostagentlab.com/blog/block-or-allow-ai-crawlers/">blocking or allowing AI crawlers</a> covers that decision.</p>
          <h2>How we compare the answers</h2>
          <p>For each imitated request, we line the response up against the browser's:</p>
          <ul>
            <li><strong>Blocked:</strong> the agent got an error (HTTP 400 or above) where the browser didn't, or a challenge page such as "Just a moment" or "Verify you are human" where the browser got the real page.</li>
            <li><strong>Degraded:</strong> the agent got less than half the visible text the browser got, which usually means a placeholder or stripped-down page.</li>
            <li><strong>Same page:</strong> neither of the above.</li>
          </ul>
          <p>On the home page, any blocked agent fails the <strong>Bot protection lets AI agents through</strong> check, and a degraded one is a warning. A similar comparison, looking for errors and challenge pages (and, at checkout, CAPTCHAs), runs on your product, pricing and cart pages for <strong>AI agents can open your product, pricing and cart pages</strong>, and on the cart and checkout for <strong>AI agents aren't blocked or shown a CAPTCHA at the cart and checkout</strong>. <a href="https://ghostagentlab.com/blog/how-agentscore-works/">How AgentScore works</a> explains how those checks add up.</p>
          <h2>Why those requests aren't signed</h2>
          <p>Everything the scanner sends under its own name is signed with Web Bot Auth, so your CDN can prove it came from us. We explain how in <a href="https://ghostagentlab.com/blog/signed-requests/">Why we sign every request our agents send</a>.</p>
          <p>The imitated requests are deliberately unsigned. If we signed them, a CDN that recognizes and trusts our signature might wave them through, and we'd be measuring how your site treats Ghost Agent Labs, not how it treats ChatGPT. Unsigned, they get exactly the treatment any request with that name gets.</p>
          <h2>What the result can't tell you</h2>
          <p>Our imitation is honest about one thing it can't do: it can't pass identity checks. The requests come from our servers, not from OpenAI's, Anthropic's, Perplexity's or Google's, and they carry none of those companies' signatures.</p>
          <p>So if your bot protection verifies agents properly, checking published IP ranges or reverse DNS and blocking impostors, it may block our imitation too. That's the right behavior, and it will show up as a failed check. When that happens:</p>
          <ol>
            <li>Look at the evidence in the report. It shows which agents were blocked and what status they got.</li>
            <li>Check your CDN or bot protection settings: is the rule "block requests that claim to be an AI agent but fail verification", or "block AI agents"? The first is good practice. The second turns customers away.</li>
            <li>Confirm in your logs, or on the verification page in the Ghost Agent Labs app, that verified requests from the real agent are getting through.</li>
          </ol>
          <p>If the real agents get through and only impostors are blocked, you're in good shape, whatever the check says. Our guides to <a href="https://ghostagentlab.com/articles/verify-ai-crawlers/">telling whether an AI crawler is real</a> and <a href="https://ghostagentlab.com/articles/bot-protection-ai-agents/">bot protection that lets AI agents through</a> cover how to set that up.</p>
          <p>The opposite limit applies too. A site that treats these agents well when they come from our servers will probably treat the real ones well, but real products differ in details we can't copy, such as where their requests come from. Treat the result as a strong signal, not a guarantee.</p>
          <h2>Keeping it small</h2>
          <p>Imitated requests are a small part of a scan: a few page loads per agent at most, never a crawl. The scanner reads public pages only and never adds to a cart, submits a form or places an order. On the free AgentScore page, a domain's result is reused for 24 hours, so repeated requests for the same site don't cause repeated visits.</p>
          <div>
            <p><strong>If you see these requests in your logs:</strong> they'll arrive close together with a scan from <code>AgentScore/1.0</code>. The <a href="https://ghostagentlab.com/agentscore/bot/">AgentScore bot</a> page explains how to verify our signed requests and how to opt out, including from the comparison requests.</p>
            <p><strong>If you want to see the result:</strong> run <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> on your own site and open the Access checks.</p>
          </div>]]></content:encoded>
    </item>
    <item>
      <title>Should you block AI crawlers? A decision guide for leaders</title>
      <link>https://ghostagentlab.com/blog/block-or-allow-ai-crawlers/</link>
      <guid>https://ghostagentlab.com/blog/block-or-allow-ai-crawlers/</guid>
      <pubDate>Fri, 09 Oct 2026 12:17:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Perspective</category>
      <description>Blocking AI crawlers is several decisions, not one. How to decide on training crawlers, AI search and assistants, and how to enforce the policy.</description>
      <content:encoded><![CDATA[<p>"Should we block AI?" usually reaches a leadership meeting as one question. It's really three or four, because "AI crawlers" covers several kinds of software doing very different jobs. Block the wrong one and you vanish from the answers your customers are reading. Here's how to make the call, kind by kind.</p>
          <h2>Start by splitting the question</h2>
          <p>The major AI companies each run several agents, and each has its own name so you can treat them differently.</p>
          <table>
            <thead><tr><th>Kind</th><th>What it does</th><th>Examples</th></tr></thead>
            <tbody>
              <tr><td>Training crawlers</td><td>Collect pages to train future AI models</td><td>GPTBot, ClaudeBot, CCBot, Google-Extended (a control name, not a separate crawler)</td></tr>
              <tr><td>AI search crawlers</td><td>Index pages so AI search can cite and link to you</td><td>OAI-SearchBot, Claude-SearchBot, PerplexityBot</td></tr>
              <tr><td>Assistant fetchers</td><td>Fetch a page in real time because a person asked about it</td><td>ChatGPT-User, Claude-User, Perplexity-User</td></tr>
              <tr><td>Browser agents</td><td>Drive a real browser for a person: search, fill in forms, add to cart</td><td>Usually look like an ordinary browser</td></tr>
            </tbody>
          </table>
          <p>Our <a href="https://ghostagentlab.com/articles/robots-txt-ai-agents/">robots.txt guide</a> has the longer list and the exact names. The point for decision-makers is simpler: you can say yes to some and no to others.</p>
          <h2>The case for each, in business terms</h2>
          <h3>Assistant fetchers: almost always allow</h3>
          <p>Each visit stands in for a real person asking about you right now: "Is this in stock?", "What's their returns policy?", "Which of these three is cheapest?". Block them and the assistant answers without you, or recommends a competitor. For a store or a software company, this is the closest thing to a customer walking in.</p>
          <h3>AI search crawlers: allow, unless you also opt out of search</h3>
          <p>These build the index AI search draws on. They're the AI equivalent of being in Google's index, and they're how you get cited and linked. Few businesses that want search traffic would block Googlebot. The same logic applies here.</p>
          <h3>Training crawlers: a real choice</h3>
          <p>This is the one worth debating. Allowing training means your content may shape what AI models know, including about your brand and products. Blocking it keeps your content out of future training sets, and leaves AI search and assistants unaffected, because they use different names.</p>
          <ul>
            <li><strong>Lean towards blocking</strong> if your content is the product: publishers, research, courses, original reviews, anything you license or sell.</li>
            <li><strong>Lean towards allowing</strong> if your content mainly exists to sell something else: product pages, help centers, pricing. Being well understood by AI models is usually worth more to you than the content itself.</li>
          </ul>
          <p>Either answer is legitimate. That's why AgentScore reports blocked training crawlers but doesn't take points off for them.</p>
          <h3>Browser agents: you can't block them by name, so make them work</h3>
          <p>Browser agents mostly look like a normal browser, so robots.txt rules by name don't reach them. The useful question isn't whether to block them but whether they can complete a purchase or sign-up when they arrive. That's what <a href="https://ghostagentlab.com/blog/introducing-ghost-agents/">Ghost Agent tests</a> check.</p>
          <h2>A quick decision guide</h2>
          <table>
            <thead><tr><th>If you are...</th><th>Assistants and AI search</th><th>Training crawlers</th></tr></thead>
            <tbody>
              <tr><td>An online store</td><td>Allow</td><td>Usually allow; your product pages are there to be read</td></tr>
              <tr><td>A software or services company</td><td>Allow</td><td>Usually allow marketing and docs; your call on anything gated</td></tr>
              <tr><td>A publisher or content business</td><td>Allow if you want AI citations and referral traffic</td><td>Often block, or allow only under a licensing agreement</td></tr>
              <tr><td>Unsure</td><td>Allow</td><td>Decide deliberately; don't inherit someone's copied list</td></tr>
            </tbody>
          </table>
          <h2>Three mistakes that cost more than the decision</h2>
          <ol>
            <li><strong>Copying a "block all AI" list.</strong> These lists usually include assistant fetchers and AI search crawlers, so you drop out of AI answers along with training.</li>
            <li><strong>Deciding in robots.txt and forgetting the CDN.</strong> Bot protection, firewall rules and one-click "block AI bots" settings can override a friendly robots.txt. The agent never gets far enough to read it. See <a href="https://ghostagentlab.com/articles/bot-protection-ai-agents/">bot protection that lets AI agents through</a>.</li>
            <li><strong>Trusting the name.</strong> Anyone can claim to be ChatGPT or Googlebot. robots.txt is a request, not a lock: well-behaved agents follow it and scrapers ignore it. Stopping abusive traffic, including impostors using trusted names, has to happen at your CDN, by verifying who's really asking. See <a href="https://ghostagentlab.com/articles/verify-ai-crawlers/">how to tell if an AI crawler is real</a>.</li>
          </ol>
          <p>One more nuance: some operators treat an assistant fetch, made because a person asked about a specific page, like a person clicking a link, and say robots.txt may not apply to it. If you truly need to stop those visits, that's a CDN rule, not a robots.txt line. Most businesses want those visits most of all.</p>
          <h2>What to do this month</h2>
          <div>
            <ol>
              <li>Agree a written policy for each kind of agent: one line each, signed off by marketing, e-commerce and whoever owns your content rights.</li>
              <li>Have someone write it into robots.txt. Allowing assistants and search while opting out of training looks like this:
                <pre><code>User-agent: GPTBot
User-agent: ClaudeBot
User-agent: CCBot
User-agent: Google-Extended
Disallow: /
User-agent: *
Allow: /
Sitemap: https://northwind.example/sitemap.xml</code></pre>
              </li>
              <li>Ask whoever runs your CDN or bot protection to confirm its settings match the policy, and that it checks agents are genuine rather than trusting their names.</li>
              <li>Run <a href="https://ghostagentlab.com/agentscore/">AgentScore</a>. It reads your robots.txt as the AI agents we track would, and requests your pages as several AI assistants to see whether your bot protection lets them through. <a href="https://ghostagentlab.com/blog/scanner-wears-other-names/">Here's how that works</a>.</li>
              <li>Measure what happens next. <a href="https://ghostagentlab.com/articles/measure-ai-agent-traffic/">Count the agents that visit</a> and <a href="https://ghostagentlab.com/articles/ai-referral-traffic/">the visits and sales AI assistants send you</a>, and revisit the policy every quarter.</li>
            </ol>
          </div>
          <p>The default for most businesses is simple: let the agents that bring customers in, make a deliberate choice about training, and enforce both where it actually counts.</p>]]></content:encoded>
    </item>
    <item>
      <title>A 90-day agent readiness plan for e-commerce teams</title>
      <link>https://ghostagentlab.com/blog/90-day-agent-readiness-plan/</link>
      <guid>https://ghostagentlab.com/blog/90-day-agent-readiness-plan/</guid>
      <pubDate>Fri, 09 Oct 2026 12:16:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Guide</category>
      <description>A practical three-phase plan: let AI agents in, make pages readable and usable, then prove agents can finish checkout, mapped to AgentScore checks.</description>
      <content:encoded><![CDATA[<p>Agent readiness can feel like a long list of unrelated fixes. It's easier to run as three phases of about a month each: let AI agents in, help them understand and move around your site, then prove they can finish the jobs that make you money. Here's a plan an e-commerce team can start on Monday.</p>
          <h2>Before you start</h2>
          <p>Name one person to own the plan. It doesn't have to be a developer; on most teams it's someone in e-commerce, digital or SEO who can get time from the people who make the changes. Our post on <a href="https://ghostagentlab.com/blog/who-owns-agent-readiness/">who owns agent readiness</a> shows who usually fixes what.</p>
          <p>Then agree what "done" means. We suggest three outcomes by day 90:</p>
          <ul>
            <li>No critical AgentScore findings on your home page and key product pages.</li>
            <li>At least one money journey, such as product to checkout, tested by a real AI agent on a schedule.</li>
            <li>A monthly view of agent traffic and AI referrals that leadership can read.</li>
          </ul>
          <p>Notice that none of these is a target score. Scores are useful for tracking progress, but a site that loses ten points to an optional new standard can still serve agents well, and a site that scores well can still fail at the size selector. Aim at the outcomes.</p>
          <h2>Days 1–30: let agents in and get a baseline</h2>
          <p>The first month is about Access, because nothing else matters if agents are turned away at the door. It's also when you set the baseline you'll measure against.</p>
          <h3>Week 1: measure</h3>
          <ol>
            <li>Run <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> on your home page and save the report. <a href="https://ghostagentlab.com/blog/how-agentscore-works/">How AgentScore works</a> explains what's behind each category.</li>
            <li>Connect a data source, such as your CDN or server logs, so you can see which AI agents visit and how your site answers them. See <a href="https://ghostagentlab.com/articles/measure-ai-agent-traffic/">how to measure agent traffic</a>.</li>
            <li>List your three most valuable journeys: for most stores, search to product, product to cart, and cart to checkout.</li>
          </ol>
          <h3>Weeks 2–4: fix Access</h3>
          <table>
            <thead><tr><th>AgentScore check</th><th>Usually fixed by</th><th>Read</th></tr></thead>
            <tbody>
              <tr><td>robots.txt lets AI assistants and search agents in</td><td>SEO or content team</td><td><a href="https://ghostagentlab.com/articles/robots-txt-ai-agents/">robots.txt for AI agents</a></td></tr>
              <tr><td>Bot protection lets AI agents through</td><td>Bot protection or CDN admin</td><td><a href="https://ghostagentlab.com/articles/verify-ai-crawlers/">Tell if an AI crawler is real</a></td></tr>
              <tr><td>No CAPTCHA or challenge on arrival</td><td>Bot protection or CDN admin</td><td><a href="https://ghostagentlab.com/articles/bot-protection-ai-agents/">Bot protection and CAPTCHAs</a></td></tr>
              <tr><td>AI agents can open your product, pricing and cart pages</td><td>Bot protection or CDN admin</td><td><a href="https://ghostagentlab.com/articles/rate-limits-ai-agents/">Rate limits for AI agents</a></td></tr>
              <tr><td>llms.txt guide for AI</td><td>SEO or content team</td><td><a href="https://ghostagentlab.com/articles/llms-txt/">How to write an llms.txt file</a></td></tr>
            </tbody>
          </table>
          <p>Make one policy decision this month too: what you'll do about AI training crawlers, as distinct from the assistants that fetch pages for shoppers. Our <a href="https://ghostagentlab.com/blog/block-or-allow-ai-crawlers/">decision guide</a> walks through it. Settle it early, because it affects robots.txt and bot protection rules at the same time.</p>
          <div>
            <p><strong>End of month one:</strong> rescan. The AI assistants you want can reach your key pages, you've decided your position on training crawlers, and you have a baseline score and a first look at agent traffic.</p>
          </div>
          <h2>Days 31–60: make pages readable and usable</h2>
          <p>Month two covers Readability and Navigability: whether agents can understand your pages, and whether they can find their way around them. Most of this is developer work, so get it into the sprint plan early in the month.</p>
          <h3>Readability</h3>
          <ul>
            <li><strong>Content loads without JavaScript</strong> and <strong>Prices are in the page HTML.</strong> The highest-value fixes for most stores. See <a href="https://ghostagentlab.com/articles/javascript-content-ai-agents/">JavaScript-only content</a> and <a href="https://ghostagentlab.com/articles/machine-readable-prices/">prices AI agents can read</a>.</li>
            <li><strong>Structured data</strong> and <strong>product pages give price and stock in a form agents can read.</strong> See <a href="https://ghostagentlab.com/articles/structured-data-ai-shopping-agents/">product data AI shopping agents can read</a>.</li>
            <li><strong>Clear page title, description, and headings</strong>, <strong>image text descriptions</strong> and a <strong>valid sitemap.</strong> Usually SEO and content work. See <a href="https://ghostagentlab.com/articles/titles-descriptions-headings-ai/">titles, descriptions and headings</a>, <a href="https://ghostagentlab.com/articles/image-alt-text-ai-agents/">alt text for AI agents</a> and <a href="https://ghostagentlab.com/articles/xml-sitemaps-ai-agents/">XML sitemaps</a>.</li>
            <li><strong>Policy pages</strong> for shipping and returns that an assistant can quote accurately. See <a href="https://ghostagentlab.com/articles/policy-pages-ai-assistants/">shipping, returns and FAQ pages</a>.</li>
          </ul>
          <h3>Navigability</h3>
          <ul>
            <li><strong>Buttons and links have names</strong>, <strong>form fields are labelled</strong> and <strong>clickable things are real buttons and links.</strong> See <a href="https://ghostagentlab.com/articles/agent-friendly-buttons-forms/">buttons, links and forms agents can use</a>. If you have an accessibility audit, start there: <a href="https://ghostagentlab.com/blog/accessibility-is-agent-readiness/">much of it overlaps</a>.</li>
            <li><strong>Pop-ups and banners can be dismissed by agents.</strong> See <a href="https://ghostagentlab.com/articles/cookie-banners-popups-ai-agents/">cookie banners and pop-ups</a>.</li>
            <li><strong>Main and navigation landmarks</strong> and <strong>key pages linked from the home page.</strong> See <a href="https://ghostagentlab.com/articles/link-key-pages-home-page/">link your key pages from the home page</a>.</li>
            <li><strong>Site search and filters</strong> that agents can operate. See <a href="https://ghostagentlab.com/articles/site-search-filters-ai-agents/">site search and filters AI agents can use</a>.</li>
          </ul>
          <div>
            <p><strong>End of month two:</strong> rescan and compare category by category with your baseline. Agents should be able to read the price, stock and description on your product pages from the HTML alone, and move around without getting stuck on unnamed controls or pop-ups.</p>
          </div>
          <h2>Days 61–90: prove agents can finish the job</h2>
          <p>Month three is about Task completion, the category that carries the most weight. Checks can tell you a page looks usable. Only a real agent can tell you whether it is.</p>
          <ol>
            <li><strong>Test your money journeys.</strong> Set up <a href="https://ghostagentlab.com/blog/introducing-ghost-agents/">Ghost Agent</a> tests for the journeys you listed in week one, starting with product to checkout. Each check runs the agent several times, because agents vary, and Ghost Agents stop before paying. See <a href="https://ghostagentlab.com/articles/test-journeys-with-ai-agents/">how to test your key journeys with AI agents</a>.</li>
            <li><strong>Fix where they fail.</strong> The usual sticking points are the add-to-cart button, option selectors, checkout fields and a challenge at the cart. The relevant checks are <strong>Agents can find and press your add-to-cart or sign-up button</strong>, <strong>Cart and checkout fields are labelled for agents</strong>, and <strong>AI agents aren't blocked or shown a CAPTCHA at the cart and checkout.</strong> See <a href="https://ghostagentlab.com/articles/agent-ready-checkout/">agent-ready checkout</a>.</li>
            <li><strong>Review guest checkout.</strong> An agent buying for someone can't easily create an account for them. See <a href="https://ghostagentlab.com/articles/guest-checkout-ai-agents/">guest checkout: why AI shopping agents need it</a>.</li>
            <li><strong>Look ahead.</strong> Ask your platform and developers where you stand on <a href="https://ghostagentlab.com/articles/mcp-webmcp-for-websites/">MCP and WebMCP</a> and on <a href="https://ghostagentlab.com/articles/agentic-commerce-protocols/">agentic commerce protocols</a>. These are early and still changing, so they're weighted lightly in AgentScore. A decision and a plan are enough for now.</li>
            <li><strong>Set up reporting.</strong> Track the visits and sales AI assistants send you, alongside agent traffic from your logs. See <a href="https://ghostagentlab.com/articles/ai-referral-traffic/">tracking visits and sales that come from AI assistants</a>.</li>
          </ol>
          <div>
            <p><strong>End of month three:</strong> at least one money journey runs on a schedule with alerts, failures go to a named owner, and leadership gets a one-page monthly view: AgentScore by category, Ghost Agent pass rates, agent traffic and AI referrals.</p>
          </div>
          <h2>After day 90</h2>
          <p>Agent readiness drifts. A new pop-up campaign, a bot protection rule change or a redesigned product page can undo months of work in one release. Keep three habits:</p>
          <ul>
            <li>Rescan after every significant release, and at least monthly.</li>
            <li>Keep Ghost Agent tests running on your money journeys, and add one when you launch a new one.</li>
            <li>Add agent checks to your definition of done: named controls, labelled fields, prices in the HTML, and no new challenge pages on key paths.</li>
          </ul>
          <p>Start with a scan. It takes under a minute, and it'll tell you which month of this plan needs the most attention.</p>]]></content:encoded>
    </item>
    <item>
      <title>Who owns agent readiness?</title>
      <link>https://ghostagentlab.com/blog/who-owns-agent-readiness/</link>
      <guid>https://ghostagentlab.com/blog/who-owns-agent-readiness/</guid>
      <pubDate>Fri, 09 Oct 2026 12:15:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Perspective</category>
      <description>Agent readiness spans e-commerce, SEO, developers, security and legal. Who usually fixes what, and how to give the work one clear owner.</description>
      <content:encoded><![CDATA[<p>Ask who owns agent readiness and you'll often get a pause. SEO thinks it's a developer problem. Developers think it's a security setting. Security thinks it's marketing's call. Meanwhile AI agents are turned away, or get lost, and nobody hears about it. The work is spread across several teams by its nature. What it needs is one clear owner and a clear split of the rest.</p>
          <h2>Why it falls between teams</h2>
          <p>Agent readiness touches four layers of a website, and each layer has its own team.</p>
          <ul>
            <li><strong>The door:</strong> robots.txt, bot protection, CDN rules and rate limits decide whether an agent gets in.</li>
            <li><strong>The content:</strong> titles, descriptions, product data and policies decide whether it understands what it finds.</li>
            <li><strong>The page:</strong> buttons, forms, pop-ups and rendering decide whether it can move around and act.</li>
            <li><strong>The transaction:</strong> cart, checkout and accounts decide whether it can finish the job.</li>
          </ul>
          <p>No one team sees all four. Each sees its own layer working, and the failure shows up somewhere else: a lost recommendation, or an order that never happened.</p>
          <h2>Who usually fixes what</h2>
          <p>In the Ghost Agent Labs app, each AgentScore finding names a suggested owner under “Usually fixed by”, and the CSV export includes it too. Grouped together, the defaults look like this.</p>
          <table>
            <thead><tr><th>Team</th><th>What they usually own</th><th>AgentScore checks</th></tr></thead>
            <tbody>
              <tr><td>SEO or content team</td><td>The rules and text agents read first</td><td>robots.txt lets AI assistants and search agents in; llms.txt guide for AI; Clear page title, description, and headings; Images have text descriptions; Valid sitemap</td></tr>
              <tr><td>Bot protection or CDN admin</td><td>Who gets through the door, and where</td><td>Bot protection lets AI agents through; No CAPTCHA or challenge on arrival; AI agents can open your product, pricing and cart pages; AI agents aren't blocked or shown a CAPTCHA at the cart and checkout</td></tr>
              <tr><td>Developer</td><td>How pages are built and rendered</td><td>Content loads without JavaScript; Structured data describes your business and products; Product pages give price and stock in a form agents can read; Prices are in the page HTML; every Navigability check, from named buttons and labelled fields to pop-ups and checkout fields; Agents can use your site through MCP or WebMCP</td></tr>
              <tr><td>E-commerce platform admin</td><td>How the store and checkout are configured</td><td>Shoppers can check out without an account; Agents can check out through an agentic commerce protocol</td></tr>
            </tbody>
          </table>
          <p>Task completion, which comes from real agents running journeys, usually lands with developers once a test shows where an agent gets stuck. But the decision about which journeys matter belongs to the business.</p>
          <p>These are defaults, not rules. On a hosted platform, the "developer" fixes for a product page may really be theme settings an e-commerce manager can change. At a small company, one person may hold three of these roles.</p>
          <h2>The roles in more detail</h2>
          <h3>E-commerce and digital leaders</h3>
          <p>They own the outcome: whether AI agents can find, choose and buy from the site. That makes them the natural overall owner. They decide which journeys matter, set priorities when fixes compete for developer time, and own the platform settings that shape checkout, such as guest checkout. See <a href="https://ghostagentlab.com/articles/guest-checkout-ai-agents/">guest checkout: why AI shopping agents need it</a>.</p>
          <h3>Marketing and SEO</h3>
          <p>They own most of what agents read before they act: robots.txt, titles and headings, alt text, sitemaps and llms.txt. They also own measurement, because AI referrals belong next to search and social in channel reporting. See <a href="https://ghostagentlab.com/blog/seo-to-agent-readiness/">SEO got you found. Agent readiness gets you chosen</a> and <a href="https://ghostagentlab.com/articles/ai-referral-traffic/">tracking visits and sales that come from AI assistants</a>.</p>
          <h3>Developers</h3>
          <p>They own the largest number of fixes: rendering content and prices in the HTML, structured data, named controls, labelled fields, dismissible pop-ups and checkout fields. Much of this overlaps with accessibility, so the same people and practices often apply. See <a href="https://ghostagentlab.com/blog/accessibility-is-agent-readiness/">accessibility work is agent readiness work</a>. Developers also run <a href="https://ghostagentlab.com/articles/test-journeys-with-ai-agents/">agent tests</a> as part of release checks, and evaluate newer interfaces such as <a href="https://ghostagentlab.com/articles/mcp-webmcp-for-websites/">MCP and WebMCP</a>.</p>
          <h3>Security and CDN</h3>
          <p>They own the door. Bot protection, WAF rules, challenge pages and rate limits are where agents are most often blocked by accident, because those rules were written to stop scrapers. This team's job isn't to let everything in. It's to tell real agents from impostors, by verified identity rather than by name alone, and to treat the agents the business wants accordingly. See <a href="https://ghostagentlab.com/articles/bot-protection-ai-agents/">bot protection and CAPTCHAs</a>, <a href="https://ghostagentlab.com/articles/verify-ai-crawlers/">how to tell if an AI crawler is real</a> and <a href="https://ghostagentlab.com/articles/rate-limits-ai-agents/">rate limits for AI agents</a>.</p>
          <h3>Legal</h3>
          <p>Legal doesn't fix findings, but it shapes several decisions the other teams can't make alone:</p>
          <ul>
            <li>Whether to allow AI training crawlers, which is a content-licensing question as much as a technical one. See <a href="https://ghostagentlab.com/blog/block-or-allow-ai-crawlers/">should you block AI crawlers?</a></li>
            <li>What your terms of service say about automated access, and whether they accidentally forbid the agents you want.</li>
            <li>The terms and liability around purchases made by an agent for a customer, before you adopt an <a href="https://ghostagentlab.com/articles/agentic-commerce-protocols/">agentic commerce protocol</a>.</li>
            <li>Accessibility obligations, which often share fixes with agent readiness.</li>
          </ul>
          <h2>Making it work in practice</h2>
          <ol>
            <li><strong>Name one accountable owner.</strong> Usually the head of e-commerce or digital. They don't make every fix; they make sure each one has someone.</li>
            <li><strong>Route findings by owner.</strong> Export the findings as CSV and send each group to its team. Each finding explains why it matters in plain language, which helps when the team receiving it doesn't think of AI agents as its problem.</li>
            <li><strong>Agree the policy decisions once.</strong> Training crawlers, verified agents through bot protection, and guest checkout are decisions, not tickets. Settle them in one meeting with SEO, security, e-commerce and legal in the room.</li>
            <li><strong>Make failures visible to the owner.</strong> Run <a href="https://ghostagentlab.com/blog/introducing-ghost-agents/">Ghost Agent</a> tests on your money journeys and send alerts to the person who can act, not a shared inbox.</li>
            <li><strong>Review monthly.</strong> AgentScore by category, Ghost Agent pass rates, agent traffic and AI referrals, on one page.</li>
          </ol>
          <div>
            <p><strong>A simple test:</strong> if an AI assistant started being blocked from your product pages tomorrow, who would find out, and how? If the answer is "nobody" or "eventually", that's the gap to close first.</p>
          </div>
          <p>For a phased version of this, see our <a href="https://ghostagentlab.com/blog/90-day-agent-readiness-plan/">90-day agent readiness plan</a>. Or start by running <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> and seeing whose name comes up most.</p>]]></content:encoded>
    </item>
    <item>
      <title>Your next customer won't be human</title>
      <link>https://ghostagentlab.com/blog/next-customer-not-human/</link>
      <guid>https://ghostagentlab.com/blog/next-customer-not-human/</guid>
      <pubDate>Thu, 08 Oct 2026 12:11:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Perspective</category>
      <description>AI agents now read, compare and buy on people's behalf. Most websites can't see them, don't know if they succeed, and were never built for them. Here's what's changing.</description>
      <content:encoded><![CDATA[<p>For twenty-five years, websites have been built for two kinds of visitor: people, and the search crawlers that send people. A third kind is arriving fast. AI agents now read, compare, book and buy on people's behalf, and most websites can't see them, don't know whether they succeed, and were never designed for them.</p>
          <h2>A new kind of visitor</h2>
          <p>When someone asks an AI assistant "which of these running shoes is best for flat feet, and is it in stock in a 10?", a person never visits your site. Software does. That software comes in three broad kinds:</p>
          <ul>
            <li><strong>Training crawlers</strong>, such as GPTBot and ClaudeBot, collect pages to teach AI models. They shape what AI knows about you over months.</li>
            <li><strong>AI search and assistant fetchers</strong>, such as OAI-SearchBot, ChatGPT-User and Perplexity-User, fetch your pages in the moment to answer a question. They decide whether you're the answer today.</li>
            <li><strong>Browser agents</strong> drive a real browser for a person: searching your catalog, filling in forms, adding to cart, and in some cases checking out.</li>
          </ul>
          <p>The last two are the ones that matter most to revenue, because each visit stands in for a real customer with a real intent. If the agent can't find the price, read the return policy, or get past a pop-up, the customer doesn't get a worse experience on your site. They get a recommendation for someone else's.</p>
          <h2>Why nobody noticed</h2>
          <p>Most websites have no idea how many agents visit, for a simple reason: analytics tools count visitors with a JavaScript tag, and most agents never run it. Crawlers and assistant fetchers request the HTML and leave. Your dashboards show a quiet day while your server logs show a busy one.</p>
          <p>The agents that do run JavaScript often look like ordinary browsers, so they blend into the human numbers. Either way, the question "did the agent get what it came for?" goes unanswered.</p>
          <h2>What goes wrong</h2>
          <p>When we test sites with real agents, the failures fall into the same few patterns:</p>
          <ol>
            <li><strong>They're turned away at the door.</strong> A robots.txt rule written years ago, or bot protection that challenges anything that isn't a person, blocks the assistants that were trying to send customers.</li>
            <li><strong>They can't read the page.</strong> Prices and product details only appear after JavaScript runs, and there's no structured data to fall back on.</li>
            <li><strong>They can't find their way.</strong> Unlabelled icon buttons, menus that only open on hover, and cookie banners that cover the page stop an agent the way a locked door would.</li>
            <li><strong>They can't finish the job.</strong> The agent finds the product but can't choose a size, or reaches the cart but can't find the checkout button.</li>
          </ol>
          <p>None of these show up in a normal QA pass, because a person gets through every one of them without noticing.</p>
          <h2>The gap in today's tools</h2>
          <p>Two kinds of tools touch this problem, and neither solves it.</p>
          <p><strong>Bot management</strong> decides who to block. It's essential, and it's built to keep bad traffic out, which means good agents are often collateral damage. <strong>AI visibility</strong> tools track what chatbots say about your brand. That's useful too, but it measures the answer, not whether an agent could use your site to get there.</p>
          <p>What's missing is the thing we've always done for human visitors: test the experience. Can an agent actually complete the journeys that make you money, and does it still work after this week's release?</p>
          <h2>Agent experience</h2>
          <p>We think agent experience will become a discipline of its own, next to user experience and SEO. It has three parts, and they're how we've built Ghost Agent Labs:</p>
          <ul>
            <li><strong>Observe.</strong> See every crawler, assistant and browser agent that visits, from server and edge data rather than a JavaScript tag, and check which ones are real.</li>
            <li><strong>Test.</strong> Send real AI agents through checkout, sign-up and search on a schedule, and get alerted when they fail where a person would succeed.</li>
            <li><strong>Improve.</strong> Score agent readiness, fix the highest-impact problems first, and re-test to prove the fix worked.</li>
          </ul>
          <p>It's the same idea behind <a href="https://ghostinspector.com/">Ghost Inspector</a>, which has tested websites for human visitors for years, applied to the visitors that aren't human.</p>
          <h2>What to do this week</h2>
          <div>
            <ol>
              <li>Read your robots.txt and check you aren't blocking AI assistants or AI search by accident. Our guide to <a href="https://ghostagentlab.com/articles/robots-txt-ai-agents/">robots.txt for AI agents</a> walks through it.</li>
              <li>Ask your CDN or bot protection vendor how it treats verified AI agents, and whether it can tell real ones from fakes. See <a href="https://ghostagentlab.com/articles/verify-ai-crawlers/">how to tell if an AI crawler is real</a>.</li>
              <li>Add an <a href="https://ghostagentlab.com/articles/llms-txt/">llms.txt file</a> that points agents to your most important pages.</li>
              <li>Run <a href="https://ghostagentlab.com/agentscore/">AgentScore</a>. In under a minute, it shows how AI agents are let in, what they can read and what gets in their way.</li>
            </ol>
          </div>
          <p>Your next million visitors won't be human. The sites that are ready for them will win the customers they bring.</p>]]></content:encoded>
    </item>
    <item>
      <title>Why we sign every request our agents send</title>
      <link>https://ghostagentlab.com/blog/signed-requests/</link>
      <guid>https://ghostagentlab.com/blog/signed-requests/</guid>
      <pubDate>Thu, 08 Oct 2026 12:10:00 +0000</pubDate>
      <dc:creator>Ghost Agent Labs</dc:creator>
      <category domain="https://ghostagentlab.com/feeds/#type">Blog</category>
      <category domain="https://ghostagentlab.com/feeds/#topic">Engineering</category>
      <description>Anyone can copy a user agent. Here's how Ghost Agent Labs signs its scanner and Ghost Agent traffic with Web Bot Auth, and why every well-behaved agent should.</description>
      <content:encoded><![CDATA[<p>A user agent string is a name tag anyone can print. If AI agents are going to shop, book and sign up on people's behalf, websites need a better way to tell who's knocking. That's why every request our scanner and Ghost Agents send under their own name is cryptographically signed.</p>
          <h2>The problem with user agents</h2>
          <p>Every request a browser or bot makes carries a <code>User-Agent</code> header. Ours look like this:</p>
          <pre><code>AgentScore/1.0 (+https://ghostagentlab.com/agentscore/bot)
GhostAgent/1.0 (+https://ghostagentlab.com/ghost-agent)</code></pre>
          <p>That's useful, and it's a courtesy we'll keep. But it proves nothing. A scraper can send <code>GPTBot</code>, <code>ClaudeBot</code> or <code>AgentScore/1.0</code> just as easily as the real thing, and plenty do. So site owners face a bad choice: trust the label and let impostors in, or block the label and turn away the agents they actually want.</p>
          <p>The traditional fix is to check where the request came from: published IP ranges, or a reverse DNS lookup that resolves back to the operator's domain. That works for big crawlers with fixed infrastructure. It works badly for browser agents running in the cloud, where IP addresses change all the time, and it puts the burden on every website to keep lists up to date.</p>
          <h2>What Web Bot Auth does instead</h2>
          <p><a href="https://blog.cloudflare.com/web-bot-auth/">Web Bot Auth</a> is a proposal, now being worked on at the IETF and supported by Cloudflare's verified bots program, that lets an agent prove who it is the same way websites prove who they are: with a public key.</p>
          <ol>
            <li>The agent operator publishes its public keys in a directory at a well-known address on its own domain. Ours is <code>https://app.ghostagentlab.com/.well-known/http-message-signatures-directory</code>.</li>
            <li>Every request carries three extra headers: <code>Signature-Agent</code> (where to find the keys), <code>Signature-Input</code> (what was signed, when, and with which key) and <code>Signature</code> (the signature itself), following HTTP Message Signatures, <a href="https://www.rfc-editor.org/rfc/rfc9421">RFC 9421</a>.</li>
            <li>The website or its CDN fetches the key once, checks the signature, and knows for certain the request came from the operator, whatever IP address it arrived from.</li>
          </ol>
          <p>Anyone can copy a user agent. Only the holder of the private key can produce the signature.</p>
          <h2>How we do it</h2>
          <p>We sign with an Ed25519 key. Each signature covers the site's host name and our <code>Signature-Agent</code> header, carries a fresh random nonce, and expires after 60 seconds, so a captured signature can't be replayed against another site or reused later. The key ID is the key's standard JWK thumbprint, and the key directory itself is signed too, so nobody can swap in their own keys.</p>
          <table>
            <thead><tr><th>Requests</th><th>Signed?</th></tr></thead>
            <tbody>
              <tr><td>AgentScore requests under its own user agent: robots.txt, sitemaps, well-known files, page discovery</td><td>Yes</td></tr>
              <tr><td>Every Ghost Agent request, including images and scripts from other hosts</td><td>Yes</td></tr>
              <tr><td>AgentScore requests that deliberately imitate a browser or another agent, such as ChatGPT-User, to see how your site treats them</td><td>No, so your site treats them exactly as it would that visitor</td></tr>
            </tbody>
          </table>
          <p>That last row matters. Part of what AgentScore measures is whether your bot protection treats AI agents differently from people. If we signed those requests, a CDN that trusts us would wave them through and the test would tell you nothing.</p>
          <h2>Why this matters beyond us</h2>
          <p>Agents are becoming customers' representatives. When someone asks an assistant to reorder printer ink or book a table, the agent that arrives at your site is acting for a real person with a real wallet. The sites that win are the ones that can say yes to those agents confidently, without opening the door to every scraper wearing a borrowed name.</p>
          <p>Signed requests make that possible. A site can allow verified agents through a challenge page, give them a lighter rate limit, or simply count them accurately in analytics. None of that works if the identity is a string anyone can type.</p>
          <div>
            <p><strong>If you run an agent:</strong> sign your requests. Publish a key directory, add the three headers, and register with the CDNs your users' sites sit behind. It's a small amount of work, and it's the difference between being trusted and being blocked.</p>
            <p><strong>If you run a website:</strong> check whether your CDN or bot protection can verify Web Bot Auth signatures, and prefer it over IP allowlists for the agents you want. Then run <a href="https://ghostagentlab.com/agentscore/">AgentScore</a> to see how your site treats AI agents today.</p>
          </div>
          <h2>Checking it's really us</h2>
          <p>The details of what our agents do, what they won't do, and how to opt out are on the <a href="https://ghostagentlab.com/agentscore/bot/">AgentScore bot</a> and <a href="https://ghostagentlab.com/ghost-agent/">Ghost Agent</a> pages. We don't use fixed IP addresses yet, so if you want to allow us, please do it by signature or user agent rather than by IP.</p>]]></content:encoded>
    </item>
  </channel>
</rss>
