Answer Engine Optimization
A comprehensive field guide to the standards, systems, evidence, public implementations, governance controls, and measurement practices that determine whether an answer engine can discover, use, attribute, and safely act on an organization’s knowledge.
Central thesis: AEO is not a page-writing technique or a single specification. It is a governed evidence-distribution system spanning search eligibility, retrieval, citation, content rights, verified identity, structured feeds, agent tools, transactions, and evaluation.
Orientation and enterprise position
What can be stated with confidence, what remains conditional, and what an enterprise should do now.
Operate AEO as a governed evidence supply chain.
Maintain canonical entities, claims, evidence, validity, rights, and ownership. Publish those facts through web pages, structured data, feeds, APIs, RAG systems, and agent interfaces.
Do not treat visibility tactics as durable controls.
Most GEO experiments begin after content is already inside a candidate context. They do not prove durable live-engine crawling, retrieval, citation, traffic, or revenue impact.
Invest first in authoritative source quality, technical eligibility, policy consistency, provenance, runtime validation, verified access, and repeatable evaluation. Treat content rewrites as bounded experiments—not as the architecture.
Ten operating principles
- Optimize evidence rather than generic “AI-friendly” prose.
- Model availability, discovery, retrieval, citation, representation, and action as separate stages.
- Maintain one canonical source of truth for consequential entities and claims.
- Publish unique, primary, verifiable information with explicit scope and limitations.
- Use feeds and APIs for volatile facts such as price, inventory, events, and availability.
- Separate search indexing, model training, user-directed retrieval, advertising, licensing, and transactions.
- Treat crawler directives as preferences, not authentication or authorization.
- Require runtime validation and conformance—not just schemas and TypeScript types.
- Measure fidelity and business outcomes rather than citation count alone.
- Place draft protocols behind adapters and maintain explicit version and migration policy.
Terms, boundaries, and knowledge model
AEO terminology is not standardized. A shared internal vocabulary prevents architecture, marketing, and measurement from collapsing into one ambiguous concept.
Search Engine Optimization
Optimizes crawlability, indexability, relevance, quality, ranking, search presentation, and qualified visits. The primary surface is typically a ranked result or rich result.
Answer Engine Optimization
Optimizes whether information is selected, attributed, represented accurately, and connected to an outcome in direct-answer and conversational systems.
Generative Engine Optimization
Commonly describes visibility and influence in generated answers. Academic GEO research focuses heavily on citation and answer-context behavior.
Agent-facing optimization
Makes data, controls, workflows, and transactions discoverable and safely usable by agents through semantic UIs, tools, APIs, and domain protocols.
Recommended scope
Use AEO as the enterprise umbrella. Treat SEO as its public-search foundation, GEO as its generative-answer measurement and experimentation subset, and agent experience as its execution layer.
| Layer | Primary question | Typical result | Primary owner |
|---|---|---|---|
| SEO | Can users and search engines find and rank the content? | Search result, rich result, referral | Web platform, editorial, SEO |
| AEO | Can an answer system use and represent the evidence? | Answer, citation, recommendation | Knowledge platform, editorial, analytics |
| Rights policy | What automated uses are permitted or licensed? | Preference, offer, entitlement | Legal, rights, platform security |
| Agent experience | Can an agent perform a bounded action safely? | Tool invocation, workflow, transaction | Product, identity, platform engineering |
| Evaluation | Did the system retrieve, cite, represent, and create value? | Evidence vector and business metrics | Analytics, AI evaluation, governance |
Standards and specification landscape
No technology below is an AEO umbrella specification. Each controls one part of the evidence, rights, discovery, interaction, or transaction stack.
| Layer | Technology | Status | Controls | Enterprise stance |
|---|---|---|---|---|
| Web delivery | HTTP, URLs, HTML, accessibility semantics | Mature | Addressability, representation, interaction semantics | Foundation |
| Crawl preferences | Robots Exclusion Protocol, RFC 9309 S03 | Standards-track RFC | Path access preferences for conforming crawlers | Adopt; never use as security |
| Discovery | Sitemaps | De facto mature | Canonical URL discovery and update metadata | Adopt |
| Freshness | IndexNow S07 | Implemented ecosystem | Changed and deleted URL notifications | Adopt as an adapter |
| Semantics | Schema.org 30.0 S05 | Mature vocabulary | Entities, properties, and relationships | Adopt; generate from canonical data |
| LLM context | llms.txt S23 | Community proposal | Curated documentation and context manifest | Use for known consumers; not ranking |
| AI-use preferences | IETF AIPREF vocabulary S21 | Active Internet-Draft | Emerging permission and restriction vocabulary | Watch and prototype only |
| Licensing | RSL 1.0 S19 | Industry specification | Machine-readable usage, licensing, and compensation terms | Pilot with legal and enforcement controls |
| Bot identity | Web Bot Auth S20 | Draft + reference code | Cryptographically signed automated HTTP traffic | Pilot for valuable access |
| Site answers | NLWeb S18 | Open reference project | Natural-language site interfaces and MCP exposure | Bounded pilot |
| Browser tools | WebMCP S16 | Community Group draft | JavaScript tools exposed by web applications | Pilot behind adapters |
| Commerce | OpenAI ACP S13 | Open, platform-led | Catalog ingestion, discovery, checkout integration | Pilot for ChatGPT commerce |
| Commerce | UCP S15 | Versioned specification | Catalog, identity, checkout, order lifecycle | Pilot with conformance and version pinning |
| Measurement | GEO research benchmarks S26 | Research | Visibility, citation, absorption, manipulation, fidelity | Use as experimental methods, not production proof |
A published schema is not sufficient evidence of interoperability. Enterprise maturity requires versioning, runtime validation, reference clients and servers, negative tests, conformance, security guidance, compatibility policy, and operational telemetry.
The answer-engine pipeline
AEO is a partially observable pipeline. Success at one stage does not imply success at the next.
Operating flow
The detailed stages below are grouped into five control domains.
| Stage | Question | Controls | Common failure |
|---|---|---|---|
| Availability | Can the system reach the resource? | DNS, HTTP, CDN, authentication, entitlements | WAF challenge, authorization failure, unstable URL |
| Discovery | Can it find the resource? | Internal links, sitemaps, feeds, IndexNow | Orphaned URL or incomplete feed |
| Crawl or fetch | Can it retrieve and render it? | REP, bot policy, rendering, status codes | Blocked crawler, empty client-rendered body |
| Index or ingest | Can it normalize and retain it? | Canonicals, data quality, parsing, deduplication | Duplicate, low-quality, or contradictory record |
| Retrieval | Does it match the question and subqueries? | Topical relevance, entity alignment, coverage | Content is related but not answer-bearing |
| Context allocation | Does it survive ranking and token limits? | Distinctiveness, evidence density, position | Candidate is retrieved but omitted |
| Synthesis | Can the evidence support a useful answer? | Clear claims, procedures, comparisons, limits | Marketing prose without extractable evidence |
| Citation | Is the source visibly attributed? | Provenance, source identity, engine policy | Evidence is used without visible citation |
| Fidelity | Is the source represented correctly? | Dates, scope, exceptions, conflict handling | Outdated or overgeneralized answer |
| Outcome | Does the result create approved value? | Referral, conversion, tool and transaction design | Zero-click value loss or unsafe action |
A page may be indexed but never retrieved; retrieved but not cited; cited but not materially used; used but misrepresented; accurately represented but unable to create a visit or authorized action.
Evidence hierarchy and effective practice
The available evidence supports foundational quality and relevance more strongly than universal “AI optimization” tactics.
Technical eligibility and source quality
Accessible, indexable, canonical, current, original, evidence-bearing content is the strongest durable foundation.
Extractable, semantically clear structures
Definitions, comparisons, procedures, numbers, explicit qualifications, and consistent entities improve machine usability.
Generic GEO rewriting recipes
Formatting-only tactics, mass FAQ generation, artificial chunking, and proprietary scores lack stable cross-engine evidence.
Evidence hierarchy
- Official platform documentation and first-party telemetry.
- Standards documents, conformance suites, and production-derived code.
- Controlled, reproducible experiments with released code and datasets.
- Repeated multi-engine observational studies with transparent methods.
- Single-engine snapshots and limited audits.
- Vendor correlations, proprietary scoring models, and anecdotal checklists.
Practices supported by the strongest evidence
Publish non-commodity knowledge
- Original research and first-party measurements
- Primary documentation and product specifications
- Direct expert experience and tested procedures
- Explicit trade-offs, limitations, and failure modes
Google emphasizes unique, expert-led, useful content over commodity summaries. S01
Make claims independently interpretable
- State subject, claim, scope, qualifier, and effective date
- Attach supporting evidence and methodology
- Declare exceptions, jurisdiction, version, and owner
- Separate current facts from historical context
Use evidence-bearing structures
- Definition and decision blocks
- Comparison and compatibility tables
- Procedures, timelines, formulas, and tested examples
- Version histories and deprecation notices
Use systems of record for volatile truth
- Prices, inventory, variants, and shipping
- Events, business hours, offers, and availability
- Product eligibility and transaction status
- Feeds and APIs with versioned validation
What the research does—and does not—show
Foundational GEO research
The original GEO work introduced GEO-Bench and reported visibility gains of up to 40% within its experimental setting. The result demonstrates that already-selected documents can influence generated-answer visibility. It does not establish durable organic crawling, retrieval, traffic, or revenue effects across live platforms. S26
Critical survey of 2023–2026 evidence
A July 2026 survey characterizes GEO as a stochastic pipeline and finds no reviewed technique demonstrating stable, longitudinal, cross-platform causal impact on organic discoverability and downstream behavior. Topical relevance and context position are among the more reproducible effects. S27
Citation selection versus evidence absorption
Recent research distinguishes appearing in a citation list from materially contributing language, facts, evidence, or structure to the answer. A citation KPI therefore cannot substitute for influence or fidelity measurement. S28
Competition and congestion effects
C-SEO Bench reports that many conversational SEO methods become ineffective across domains and multiple adopters. Techniques can lose differentiation when competing publishers apply the same patterns. S29
Any optimization system that changes claims, emphasis, evidence, dates, or qualifications must pass factual-equivalence checks, editorial review, controlled experiments, and rollback gates.
Platform field guide
Each platform separates crawler purposes, indexing, citations, commerce, and user-directed actions differently. Policy must be purpose-specific.
Generative search remains rooted in Search.
Google states that AI Overviews and AI Mode use core Search ranking and quality systems, the Search index, query fan-out, and grounding. No special AEO schema, llms.txt, artificial chunking, or AI-specific writing style is required. S01
- Meet Search technical requirements and snippet eligibility.
- Prioritize unique, useful, non-commodity content.
- Use Merchant Center and business data for applicable verticals.
- Use Search Console generative-AI reporting where available.
Citation telemetry is improving but remains partial.
Bing Webmaster Tools reports citations, cited pages, grounding queries, intents, topics, citation share, and comparison views. Microsoft explicitly warns that citation counts do not indicate ranking, authority, placement, or causal contribution. S10 S11
Search, training, user retrieval, and ads are separate purposes.
OpenAI publishes distinct identities for search discovery, foundation-model training, user-directed access, and advertisement validation. Product feeds and ACP add separate discovery, eligibility, checkout, and payment integration paths. S12 S13
Automated search and user-directed fetchers require separate policy.
Anthropic distinguishes ClaudeBot, Claude-SearchBot, and Claude-User. Perplexity distinguishes PerplexityBot and Perplexity-User and publishes IP lists for WAF configuration. User-directed fetch semantics can differ from automated crawling. S24 S25
Purpose-based crawler registry
| Purpose | Examples | Policy decision | Verification |
|---|---|---|---|
| Conventional search | Googlebot and conventional search crawlers | Allow public canonical content unless excluded intentionally | Published IP/DNS methods where available |
| Answer-search indexing | OAI-SearchBot, Claude-SearchBot, PerplexityBot | Allow or deny based on visibility and rights policy | User agent plus published network identity |
| Foundation-model training | GPTBot, ClaudeBot | Separate explicit policy | Provider identity and logs |
| User-directed retrieval | ChatGPT-User, Claude-User, Perplexity-User | Apply application authorization; REP may be insufficient | Verified source plus user/session controls |
| Ads and submitted commerce | OAI-AdsBot and product-feed processors | Separate sponsored and organic treatment | Submission workflow and platform identity |
| Licensed retrieval | Contracted crawlers and agents | Require identity, entitlement, metering, and audit | Cryptographic signatures or strong workload identity |
Policy, rights, identity, and trust
Crawler preferences, usage rights, licensing offers, verified identity, authorization, payment, and enforcement are separate control planes.
Rights and access sequence
A machine-readable preference alone cannot authorize or settle access.
REP and AIPREF
RFC 9309 expresses path-access preferences. AIPREF is developing vocabulary and HTTP attachment mechanisms for AI usage preferences. Neither creates authentication or automatic legal enforcement. S03 S21
RSL
RSL 1.0 defines machine-readable usage, licensing, attribution, compensation, and reporting terms. It still requires legal adoption, identity, entitlement, and enforcement infrastructure. S19
Web Bot Auth
Web Bot Auth reference code applies HTTP Message Signatures to automated traffic. Its repository warns that the software has not been audited, and the related standards work remains active. S20
The missing enterprise component: a policy compiler
Do not manually maintain robots.txt, HTTP headers, RSL documents, WAF rules, crawler allowlists, feeds, and agent permissions as disconnected files. Generate them from one governed policy model and reject contradictions during CI.
content_class: public-editorial
uses:
conventional_search: allow
answer_grounding: allow_with_attribution
model_training: deny
user_directed_fetch: allow
commercial_republication: license_required
access:
anonymous: true
verified_bot_preferred: true
rate_limit: 120/minute
licensing:
discovery: /.well-known/rsl.xml
training:
mode: paid
currency: USD
unit: crawl
owners:
policy: legal-content-rights
technical: edge-platform
Illustrative crawler policy
# Public conventional search
User-agent: Googlebot
Allow: /
# ChatGPT search discovery
User-agent: OAI-SearchBot
Allow: /
# OpenAI foundation-model training
User-agent: GPTBot
Disallow: /
# User-directed retrieval still requires application authorization
User-agent: ChatGPT-User
Allow: /
Sitemap: https://www.example.com/sitemap.xml
RFC 9309 explicitly defines crawler rules that compliant clients are requested to honor. Protect sensitive, subscriber, employee, rights-limited, or personalized content with authentication, authorization, entitlement checks, signed URLs, rate limits, and audit logs—not with robots.txt.
Agentic web and commerce layers
Answer visibility and safe execution are different disciplines. An answer may lead to an action, but AEO cannot authorize the action by itself.
Semantic UI remains the universal fallback.
Agents may inspect rendered pixels, DOM structure, accessibility trees, forms, and state. Native controls, stable accessible names, visible validation, and deterministic recovery improve both human and agent operation.
WebMCP exposes JavaScript tools.
The July 2026 Community Group draft enables web applications to provide tools to AI agents. It is not a W3C Standard, and authorization, confirmation, output contracts, and long-running behavior remain active design areas. S16
NLWeb is a broad reference architecture.
NLWeb provides implementation code for natural-language site interfaces and MCP exposure. Its maintainers describe the code as proof-of-concept rather than a definitive solution. S18
Commerce is a multi-plane system
| Plane | Responsibility | Representative mechanisms |
|---|---|---|
| Discovery | Find products, services, and relevant offers | Search index, feeds, ACP, UCP catalog |
| Product truth | Provide current price, inventory, variants, policies | PIM, commerce API, structured feed |
| Interaction | Cart, checkout, order lifecycle | ACP checkout, UCP capabilities |
| Agent identity | Identify the automated operator | HTTP Message Signatures, workload identity |
| User mandate | Prove what the user authorized | Consent, mandate, confirmation, scoped tokens |
| Payment | Transfer usable credentials without exposing raw secrets | Delegated payment, tokenization, PSP integration |
| Merchant authorization | Apply inventory, risk, entitlement, and transaction policy | Server-side decision services |
| Audit and dispute | Reconstruct intent, state changes, payment, and outcome | Immutable events, signatures, receipts, trace IDs |
Platform-specific commerce path
ACP connects merchants and ChatGPT through structured catalogs, product APIs, checkout sessions, lifecycle events, and delegated payment patterns. Organic discovery, ads eligibility, product-feed eligibility, and checkout participation remain distinct states. S13 S14
Capability-oriented interoperability
UCP defines versioned profiles, capability negotiation, catalog, identity linking, checkout, orders, and several authentication options. Version compatibility and capability negotiation are explicitly separate concerns. S15
Minimum agent-action controls
- Authenticated user or workload identity
- Least-privilege authorization and rights policy
- Typed inputs plus server-side validation
- Read/write and consequential-action classification
- Idempotency, replay protection, and transaction limits
- Explicit confirmation before consequential operations
- Structured success, failure, and recovery responses
- Auditable decisions, state transitions, and external evidence
Public implementation evidence
Code reveals whether an idea is production-derived, implementable, reference-grade, draft-oriented, or primarily a research harness.
| Layer | Public code | Class | What it proves | Gap exposed |
|---|---|---|---|---|
| Crawl policy | Google robotstxt S09 | A | Robots parsing and matching can be deterministic and testable | Parser behavior still differs across implementations and edge cases |
| Structured semantics | Google schema-dts S06 | B | Schema.org can provide generated TypeScript authoring contracts | Compile-time typing does not prove runtime, semantic, or platform validity |
| Freshness | Microsoft IndexNow WordPress plugin S08 | B | CMS events can publish URL-change notifications automatically | Derived pages, headless domains, noindex rules, retries, and rate limits require stronger orchestration |
| LLM context | llms.txt parsers and integrations S23 | C | Documentation manifests can be parsed into LLM context | No evidence of public answer-ranking or citation advantage |
| Licensing | RSL validators and integrations S19 | B/C | Usage, attribution, payment, and reporting terms can be machine-readable | Identity, enforcement, payment collection, and legal adoption are external |
| Bot identity | Cloudflare Web Bot Auth S20 | C | Signed automated traffic can be generated and verified | Unaudited code and evolving protocol compatibility |
| Site answers | NLWeb S18 | C | Sites can run natural-language interfaces over their own data | Ranking, memory, actions, storage, and authorization remain implementation choices |
| Browser tools | WebMCP specification and tooling S16 | C/D | Tools can be declared, inspected, polyfilled, and evaluated | Confirmation, schemas, navigation, streaming, and security are not final |
| Commerce | UCP specification, samples, SDKs S15 | B | Versioned capability discovery and runtime commerce contracts are implementable | Adoption, domain breadth, and migration policy remain emerging |
| Conformance | MCP conformance framework S31 | B | Protocol compatibility can be tested continuously in CI | AEO lacks an equivalent cross-layer conformance suite |
| GEO optimization | GEO, C-SEO Bench, AutoGEO S26 S29 S30 | R | Content changes can be tested under controlled answer contexts | No complete proof from live discovery through durable business outcome |
Implementation lessons
Policy must compile to every carrier
Public auditing tools and repository issues show how easily robots rules, headers, manifests, licenses, WAF behavior, and feeds become contradictory. One policy model should generate them all.
Freshness requires a dependency graph
A content mutation may change canonical pages, author pages, topics, search collections, feeds, sitemaps, localized variants, and retrieval indexes. A direct-page hook is insufficient.
Types are not validation
Compile-time interfaces improve authoring. Production publication needs runtime schema checks, semantic truth checks, visible-content parity, and target-platform validation.
Conformance separates a format from a protocol
Executable negative tests, version fixtures, compatibility behavior, and CI integration are stronger maturity signals than a schema or example payload.
The most mature AEO-adjacent systems are narrow and testable: REP parsing, typed schemas, feed ingestion, message signatures, and protocol conformance. The broad claim “optimize a page and gain durable AI visibility” remains the least mature part of the stack.
Enterprise reference architecture
Keep the canonical knowledge model independent of presentation and protocol adapters. Place policy, identity, validation, and evaluation around every projection.
Canonical claim object
Consequential facts should have identity, evidence, temporal validity, rights, and ownership independent of the page or protocol through which they are published.
interface CanonicalClaim {
id: string;
subjectId: string;
predicate: string;
statement: string;
status: "draft" | "approved" | "deprecated";
confidence: "verified" | "supported" | "provisional";
validFrom?: string;
validThrough?: string;
lastReviewedAt: string;
jurisdictions?: string[];
audiences?: string[];
exceptions?: string[];
rightsClass?: string;
evidence: Array<{
sourceUrl: string;
sourceType: "primary" | "secondary" | "internal";
retrievedAt: string;
excerptHash?: string;
}>;
owner: {
team: string;
approver?: string;
};
supersedes?: string;
}
Publication and release gates
- Resolve the authoritative entity and claim identifiers.
- Validate evidence, scope, dates, ownership, and rights.
- Compile usage policy into every downstream carrier.
- Generate HTML, JSON-LD, feeds, APIs, and agent representations.
- Run type, runtime, semantic, parity, and platform validation.
- Calculate affected URLs and derived representations.
- Publish, invalidate caches, update sitemaps, and notify indexes.
- Run protocol conformance and security tests.
- Measure discovery, retrieval, fidelity, value, and negative outcomes.
- Feed results into claims, policy, and adapter revisions.
Measurement and evaluation
A single AEO score hides the pipeline. Use a vector of independent outcomes and preserve the conditions under which each observation was made.
AEO = [E, D, I, R, C, A, F, V, X] — eligibility, discovery, ingestion, retrieval, citation, absorption, fidelity, value, and execution.
| Dimension | Meaning | Example measures |
|---|---|---|
| E — Eligibility | Technically permitted and accessible | HTTP success, crawler access, feed acceptance, authorization |
| D — Discovery | Found through crawl, feed, link, or API | Discovery latency, sitemap coverage, IndexNow acceptance |
| I — Ingestion | Indexed or loaded into retrieval | Index coverage, canonical resolution, parsed records |
| R — Retrieval | Selected for relevant question families | Retrieval rate, candidate frequency, query-family coverage |
| C — Citation | Displayed as a source | Citation rate, prominence, share, cited URLs |
| A — Absorption | Materially contributes to the answer | Claim overlap, evidence contribution, structural influence |
| F — Fidelity | Represented accurately and currently | Claim accuracy, qualifier retention, contradiction rate |
| V — Value | Produces useful engagement or conversion | Referral, qualified engagement, assisted conversion, revenue |
| X — Execution | Supports successful authorized action | Task completion, confirmation, recovery, error and escalation rate |
Minimum evaluation protocol
- Define representative user intents and query families.
- Create controlled paraphrases rather than one exact prompt.
- Test multiple engines, locales, sessions, and dates.
- Record whether external search or retrieval activated.
- Capture cited URLs, ordering, and visible presentation.
- Compare answer claims with canonical claims and evidence.
- Measure evidence absorption separately from citation.
- Detect omissions, unsupported claims, and stale facts.
- Track referrals, conversions, and zero-click value proxies.
- Test agent actions independently with authorization and recovery.
- Retain model, engine, date, locale, context, and experimental conditions.
- Use holdouts, controlled changes, and rollback when testing rewrites.
Measurement cautions
- Run-to-run variability can exceed the effect being measured.
- Source overlap across engines may be low.
- Search activation may change by prompt wording and freshness.
- Paid placement, merchant feeds, and organic retrieval must be separated.
- A citation can be visible without materially supporting the answer.
- Increased visibility can amplify an incorrect or outdated claim.
- Competitive adoption can erase an isolated optimization advantage.
Threat model and negative outcomes
AEO creates adversarial incentives around ranking, evidence selection, attribution, rights, identity, and transactions.
- Scaled low-value content and citation bait
- Fake statistics and manufactured authority
- Prompt injection and retrieval poisoning
- Entity impersonation and stale claims
- Conflicting visible and structured data
- Tool poisoning and intent substitution
- Excessive permissions and data leakage
- Replay, duplicate, and unauthorized actions
- Misleading confirmations and incomplete rollback
- Compromised third-party tools or content
- WAF false positives and spoofed user agents
- Policy signals stripped during syndication
- Paid and organic metrics mixed together
- Zero-click substitution without attribution
- Unenforced or unmetered licensed access
Required controls
Evidence integrity
- Source hashing and versioned retrieval snapshots
- Claim-level provenance and ownership
- Freshness, validity, and supersession controls
- Structured-versus-visible parity checks
Access integrity
- Verified bot or workload identity where consequential
- Least-privilege, purpose-bound authorization
- Rate, replay, idempotency, and anomaly controls
- Signed and auditable action records
Optimization integrity
- Factual-equivalence and semantic-diff checks
- Human review for material claims
- Experiment cohorts, holdouts, and rollback
- Detection for manipulative or hidden content
Economic integrity
- Separate organic, sponsored, licensed, and transactional attribution
- Meter and reconcile licensed access
- Preserve payment and user mandate evidence
- Measure negative substitution and opportunity cost
Enterprise implementation roadmap
Sequence the program from observability and truth management toward agentic execution. Do not begin with automated rewriting.
Baseline and govern
- Inventory answer surfaces and crawler purposes
- Audit REP, WAF, CDN, feeds, and indexing
- Establish initial query corpus and baselines
- Identify strategic entities and claims
- Assign owners and evidence states
Build the evidence layer
- Define entity and claim identifiers
- Attach provenance, validity, and rights
- Remove contradictions and obsolete content
- Generate structured output from canonical data
- Implement policy compilation and consistency checks
Evaluate and pilot
- Run controlled topic cohorts and paraphrase tests
- Measure retrieval, citation, absorption, fidelity, value
- Pilot one bounded read-only agent interface
- Add protocol conformance and security gates
- Document results and reject unsupported tactics
Near-term platform backlog
| Workstream | Deliverable | Acceptance criteria |
|---|---|---|
| Evidence model | Entity, claim, evidence, validity, ownership schemas | All strategic claims have source, owner, date, status, and successor path |
| Policy compiler | Canonical policy to REP, headers, licenses, WAF, feeds | No contradictory generated carriers; diff and approval history retained |
| Publication graph | Content events and dependent-URL invalidation | Derived pages, feeds, sitemaps, and indexes update from one event |
| Runtime validation | Schema, semantic, parity, and platform gates | Release blocked on invalid or contradictory output |
| Evaluation harness | Multi-engine query corpus and fidelity checks | Repeatable runs retain prompts, dates, engines, sources, and outcomes |
| Agent pilot | Read-only, identity-bound answer or lookup tool | Authorization, structured output, audit, rate, and recovery validated |
Decision guide
A practical maturity position for current technologies and practices.
Adopt now
REP testing, sitemaps, publication events, IndexNow adapters, canonical claims, Schema.org generation, runtime validation, provenance, platform telemetry, purpose-based crawler policy.
Pilot behind adapters
RSL, Web Bot Auth, NLWeb, WebMCP, ACP, UCP, controlled GEO experiments, licensed retrieval, bounded agent tools.
Watch
AIPREF progression, Web Bot Auth RFC work, browser confirmation contracts, cross-engine telemetry, citation provenance, commerce mandate convergence.
Avoid
Universal AEO scores, mass AI rewrites, llms.txt ranking claims, user-agent-only trust, manual policy duplication, schema-only interoperability, citation-only success metrics.
Procurement questions for AEO vendors
- Which pipeline stage does the product actually observe or control?
- Which claims are supported by official telemetry versus inferred experiments?
- Can results be reproduced across engines, sessions, locales, and dates?
- How are citation, absorption, fidelity, referral, and conversion separated?
- Does the system modify factual content, and how is equivalence validated?
- Can the organization export prompts, evidence, raw observations, and history?
- How are paid, organic, feed-driven, and sponsored results distinguished?
- What rights, crawler, and data-retention policies apply to submitted content?
- Does it provide an API, versioning, audit trail, and rollback?
- What evidence would falsify the vendor’s recommendation?
Maintenance and provenance protocol
This guide is designed to be updated as standards, crawlers, telemetry, public code, and research change.
10:11 America/Bogota
Update cadence
Monthly watch
- AIPREF vocabulary and attachment drafts
- Web Bot Auth specifications and implementations
- WebMCP draft, tests, and browser support
- ACP, UCP, and commerce protocol releases
- Crawler identities, IP lists, and platform controls
Quarterly evidence refresh
- Official Google, Bing, OpenAI, Anthropic, and Perplexity guidance
- New telemetry and reporting capabilities
- Public repositories, conformance, and security issues
- Peer-reviewed and reproducible GEO research
- Enterprise evaluation findings and negative outcomes
Change-control rules
- Record source publication date, retrieval date, and source type.
- Prefer normative specifications and first-party documentation.
- Separate platform claims from cross-platform conclusions.
- Label drafts, community reports, industry specifications, and research distinctly.
- Do not promote a tactic based on one engine, one run, or one vendor correlation.
- Update maturity only when implementation, validation, conformance, or adoption evidence changes.
- Retain superseded findings and the reason for revision in a changelog.
- Re-run threat and rights analysis when adding any agent action or transaction.
Open questions to monitor
- Will AIPREF produce stable semantics for training, search, grounding, and inference use?
- Will verified bot identity converge on broadly interoperable HTTP signature profiles?
- Can citation provenance travel from generated sentence to canonical claim and licensed source?
- Will platforms expose standardized retrieval, citation, absorption, and fidelity events?
- How will paid placement, licensing, organic answers, and transactions be independently audited?
- Which agent and commerce protocols will achieve durable multi-platform conformance?
- How should multimodal evidence retain rights, source, transformation, and temporal validity?
Source registry
Primary standards, platform documentation, public code, and research used to support this guide. Sources were verified or retrieved on July 23, 2026 unless otherwise noted.
Standards and foundational web controls
- S01Google: Optimizing for generative AI featuresPrimary
- S02Google: How Search worksPrimary
- S03RFC 9309: Robots Exclusion ProtocolNormative
- S04RFC 9969: IAB Workshop on AI-CONTROLPrimary
- S05Schema.org release historyPrimary
- S07IndexNow documentationPrimary
- S21IETF AIPREF vocabulary draftDraft
- S22IETF AIPREF HTTP attachment draftDraft
- S23The
/llms.txtproposalProposal
Platform controls and telemetry
- S10Bing AI Performance in Webmaster ToolsPrimary
- S11Bing expanded AI visibility insightsPrimary
- S12OpenAI crawler overviewPrimary
- S13OpenAI Agentic Commerce ProtocolPrimary
- S14OpenAI product feed referencePrimary
- S24Anthropic crawler guidancePrimary
- S25Perplexity crawler guidancePrimary
Agent, commerce, licensing, and public implementation
- S06Google
schema-dtsCode - S08Microsoft IndexNow WordPress pluginCode
- S09Google robots.txt parser and matcherCode
- S15Universal Commerce Protocol specificationSpecification
- S16WebMCP Draft Community Group ReportDraft
- S18NLWeb reference implementationCode
- S19RSL 1.0 specificationIndustry spec
- S20Cloudflare Web Bot AuthCode / draft
- S31MCP conformance test frameworkCode
Research and benchmarks
- S26GEO: Generative Engine OptimizationResearch
- S27Critical survey of GEO, 2023–2026Research
- S28Measurement framework for citation selection and absorptionResearch
- S29C-SEO BenchResearch code
- S30AutoGEOResearch code