Cloudflare released its AEO Visibility Dashboard on August 6, 2026, moving answer engine optimization measurement out of the SEO-tool startup layer and onto the CDN. The dashboard reports how often AI assistants cite your site, sitting beside per-operator crawl and referral logs drawn from your own traffic. It is available in early access by request, and no price is published anywhere.
Two things make this worth a careful read rather than a headline. First, the citation metrics probe exactly two assistant families — Anthropic’s Claude and OpenAI’s GPT — so nothing here covers Gemini, Perplexity, Copilot or Grok. Second, your score is not a live read of what those assistants said about you today: it is measured against a category baseline that Cloudflare computes once and reuses across every account in that category.
What follows is the launch itself and the methodology underneath it, not another tools roundup — for the category map, see our guide to the AI-visibility tool category Cloudflare just entered. Below: what shipped and what did not, what each metric is a percentage of, where the sampling argument breaks down, and which of the twenty agent-readiness checks are worth doing regardless of vendor.
- 01One new product, one existing one, one announcement.The AEO Visibility Dashboard is the new tool, released August 6, 2026 in early access. Agent Readiness is described by Cloudflare as the existing tool in the suite — it launched April 17, 2026 and was integrated into the dashboard on August 6, not introduced.
- 02Two assistants, not all AI search.Cloudflare states it probes the leading assistants, today Anthropic's Claude and OpenAI's GPT. No Gemini, no Perplexity, no Copilot. Every visibility number carries that scope limit, and Cloudflare's own hedge is the word today.
- 03Your Citation Rate is scored against a reused snapshot.Cloudflare runs its category panel once per category and reuses the baseline across all accounts in that category, so results load from a snapshot rather than a live model query. Neither primary states how often that snapshot refreshes.
- 04The press release criticises the method the dashboard uses.It calls prompt sampling limited in scale and prone to inconsistency — and the visibility metrics are produced by prompt sampling. The genuine network-layer advantage lives in the separate AI Operator Activity panel, not in Citation Rate.
- 05The advanced bucket grades you on drafts.Of the six checks Cloudflare names in Advanced integration, four are unratified: WebMCP's own spec says it is not a W3C Standard, Web Bot Auth is an IETF draft, Cloudflare calls the MCP Server Card a proposal currently in draft, and the Agent Skills index is a Cloudflare proposal. The checklist's published RFCs sit in a different bucket.
01 — What ShippedTwo products, one announcement — and only one of them is new.
The clean way to read August 6 is as a three-level taxonomy. The AEO Suite is the umbrella product line. The AEO Visibility Dashboard is the new tool inside it, described in Cloudflare’s press release as the newest addition to that suite. Agent Readiness is the third piece — and Cloudflare describes it verbatim as the existing tool in the suite. It launched on April 17, 2026 as the free scanner at isitagentready.com plus a Cloudflare Radar dataset. What happened on August 6 is that it moved into the Cloudflare dashboard.
That distinction matters because most coverage compresses it. Saying “Cloudflare launched Agent Readiness” is wrong by nearly four months. The accurate version: the visibility dashboard is new, the readiness scanner is not, and the news is that they now sit in one place. The engineering post that accompanies the launch — From ranking to recommended, by Matthew Conroy and Jack Galilee — carries the technical detail; the press release carries the positioning and both executive quotes.
AEO Visibility Dashboard
Citation Rate, Prominence, Mention Rate, Share of Voice and Industry Fit, produced by probing Claude and GPT with likely category prompts. Sits next to an AI Operator Activity panel built on observed crawl and referral traffic. Requestable from the Overview tab in the Cloudflare dashboard.
Agent Readiness
Cloudflare's own opinion of what an agent-ready site looks like, expressed as a scored checklist. The free public version is still live at isitagentready.com, and Agent Readiness is also embedded in Cloudflare URL Scanner, including programmatically via an agentReadiness option on its API.
AEO Suite
The name Cloudflare uses for the whole line. Its forward-looking-statements section explicitly lists as uncertain the timing of when AEO Suite or any of its related features will be generally available — so there is no GA date, and none of it should be budgeted as a shipped, priced product.
The pitch underneath the launch is a traffic argument. Cloudflare writes that by our count, fewer than half of all HTML page requests now come from a human — and immediately qualifies it: Not all of those machines are agents acting for a person, but that share is growing fast. Both halves matter. The denominator is HTML page requests observed across Cloudflare’s network, not all internet traffic and not visits, and “by our count” is a self-measurement hedge Cloudflare put there deliberately. For precise bot-versus-human figures with their bases stated, use our dated reference on bot-versus-human traffic rather than a number pulled from a live dashboard.
02 — The Five MetricsFive scores, five different denominators.
Every write-up of this launch lists the metric names. Almost none state what each number is a percentage of — and the bases genuinely differ. Prominence, for example, is conditional on having been cited at all, so it sits on a strictly smaller base than Citation Rate. A Prominence score that improves while your citation count shrinks is not progress; it is a smaller sample.
There is also a fifth metric that the press release omits. Industry Fit — a score measuring whether an AI assistant views your site alongside your actual competitors — appears in the engineering blog post but not in the release. Any “four metrics” framing of this product is incomplete. All five are produced by probing the same two assistant families.
| Metric | Cloudflare’s definition | What the number is a share of | Live or snapshot | What it cannot tell you |
|---|---|---|---|---|
| In both the blog post and the press release | ||||
| Citation Rate | The share of answers in your category that cite your site as a source | Answers sampled in the category Cloudflare inferred for you — not all AI answers, and not all queries about you | Snapshot | How you perform on branded queries. The panel prompts are unbranded by design. |
| Prominence | When you are cited, how much of the answer is actually yours and how early it lands | Only the answers in which you were cited — a strict subset of the Citation Rate base | Snapshot | Whether citations are growing. Read it next to Citation Rate or it will flatter a shrinking sample. |
| Mention Rate | How often assistants name your brand in their answer, whether or not your domain is cited as a source | The same sampled category answers as Citation Rate | Snapshot | Whether the mention was favourable. It counts naming, not sentiment. |
| Share of Voice | Your slice of citations against those for your competitors, so you can see who is winning the prompts you are losing | All citations in the sampled category panel, across you and the competitor set Cloudflare inferred | Snapshot | Anything dependable if the inferred competitor set is wrong — the category is derived from your site, not declared by you. |
| In the engineering blog post only — absent from the press release | ||||
| Industry Fit | A score that measures whether an AI assistant views your site alongside your actual competitors | Which brands consistently appear together in the same category panel | Snapshot | Its exact construction. The definition is blog-sourced only and the press release does not mention it at all. |
Cloudflare’s own reading of the gap between Mention Rate and Citation Rate is the most useful diagnostic in the set. Assistants naming you far more than they cite you, the blog argues, means you are on their radar but not yet earning the citation — a specific, targetable gap. The press release sharpens the same point: a brand mentioned but not cited has an authority problem, not an awareness problem. That is a fair and non-obvious read, and it is the part of the product we would actually use.
If you are assembling your own scorecard rather than adopting a vendor’s, the useful comparison is against a written spec. Ours is at how an AI-visibility score should be specified, and it exists precisely because most vendor metrics ship without a stated denominator.
03 — The SnapshotYour Citation Rate is scored against a reused baseline.
This is the single most consequential architectural fact in the launch, and Cloudflare states it plainly rather than burying it. The category panel your score is measured against is not run when you open the AEO tab. It was run once for your whole category, and every account in that category is scored against the same copy.
"Rather than re-querying models every time a site owner runs a scan, we run this panel once per category and reuse the baseline across all accounts in that domain."— Matthew Conroy and Jack Galilee, Cloudflare engineering blog, August 6, 2026
Cloudflare frames this as a benefit, and on latency it is one: the first listed advantage is zero latency, with results loading instantly from a snapshot rather than waiting for live model queries. It also makes the numbers comparable between accounts in the same category, which a per-account live query would not.
Four further design choices follow from the same primary, and each changes how you should report the output:
- Your category is inferred, not declared. Cloudflare infers your industry and category from your site. A mis-inferred category benchmarks you against the wrong competitor set, and every metric in the table above inherits that error.
- The panel prompts are unbranded. Cloudflare queries assistants with likely prompts in the category without specifying your brand. So the metrics describe unprompted category discovery, not how you perform when someone asks about you by name.
- Prompts are repeated to absorb model variance. Because assistants rarely answer the same question the same way twice, Cloudflare routes prompts through its AI Gateway and asks each assistant multiple times across different models. The number of repeats is not stated.
- Scoring uses a model judge, but not a self-judge. Workers AI does the work where genuine judgment is required, and Cloudflare says it uses exact text analysis rather than a model grading its own output. Read that precisely: the claim is not that no model grades anything.
04 — The Sampling ParadoxThe release criticises the method the dashboard uses.
Cloudflare’s strongest structural argument is that it sits at the network layer and can see what AI systems actually do, rather than inferring it from a sample. Stephanie Cohen, Cloudflare’s Chief Strategy Officer, puts it in the release: Cloudflare sees real crawl activity and real referrals across millions of sites, and that is what powers these tools. On the AI Operator Activity panel, that is straightforwardly true — it reports the real crawl and referral traffic on your site, per operator, including the errors those operators hit on the way, such as 403 blocked and 404 dead links.
The tension is that the citation metrics are not built that way.
“Most tools attempt to fill that gap by only sending test prompts to AI chatbots and sampling the responses — a method limited in scale and prone to inconsistency if not paired with other data signals.”
This line has no named speaker in the release. It is Cloudflare institutional copy, and it should not be attributed to any individual — including the two executive quotes that sit elsewhere in the same document.
And yet the AEO tab probes Claude and GPT with likely customer prompts and reads the answers, which is prompt sampling. That is not a gotcha and it does not make Cloudflare dishonest; the honest formulation is narrower and more useful. Cloudflare’s network-layer advantage is real, and it lives in the operator panel. The citation metrics rest on the same sampling technique as the rest of the category. The release compresses two different evidence types into one claim. PPC Land reached the same reading independently, writing that the blog post describes the AEO tab doing precisely what the release characterises as the limited method.
There is independent work on why sampled brand metrics wobble, and it needs to be cited carefully rather than borrowed as proof. A July 2026 arXiv preprint by Dmitrij Żatuchin decomposes the variance in LLM brand answers. Three scope limits travel with it. It is a single-author preprint that has not been peer-reviewed. It measures multilingual sentiment polarity rather than citation rate. And its corpus is 12,933 responses covering 20 Central and Eastern European brands in 8 languages across GPT-5.2, Gemini 3 Flash and Perplexity, so Claude is not in its model set. It is corroboration that sampled brand metrics are noisy. It is not a measurement of Cloudflare’s product.
Largest systematic facet
Share of the variance of a single response attributable to the language the query was asked in — the biggest systematic driver the preprint identifies. Cloudflare's panel is single-category and single-language, so the driver that matters most here is the one it never varies.
Almost no brand signal
Share of the variance of a single response attributable to which brand was being asked about (ICC 0.0146), against 34.8% from pure resampling. On the same denominator, re-asking the same question moves the answer far more than changing the brand does.
Brand-ranking reliability
Reported as staying near 0.01 for a single answer and about 0.36 at the full crossed design, across 12,933 responses for 20 Central and Eastern European brands in 8 languages on GPT-5.2, Gemini 3 Flash and Perplexity. Sentiment polarity, not citations.
"a single AI answer carries almost no brand-discriminating signal."— Dmitrij Żatuchin, arXiv preprint 2607.13304, July 14, 2026
The paper’s practical finding cuts both ways for Cloudflare. It reports that per unit of query budget, adding languages and models reduces relative-error variance far more than adding repeats — a repeat past the fifth reduces it by only 0.0003 — and that reliability is bought by spreading across languages and models, not by repeating one prompt. Cloudflare’s stated approach of prompting multiple times across different models matches that advice. A single-category, single-language panel probing two assistant families does not address the largest facet the paper identifies.
Cloudflare is also not the first platform to ship citation reporting. Microsoft got there twice already — see Bing’s own citation-share reporting and Microsoft Clarity’s citation measurement. What makes Cloudflare the interesting third entrant is not the metrics; it is that this is the first of the three to sit at the CDN layer, where the crawl and referral logs already are.
05 — Agent ReadinessDiagnostics, four effort buckets, and three check states.
The nesting here is easy to get wrong. Agent Readiness is the dashboard tab. Diagnostics is the technical checkup within Agent Readiness — Cloudflare’s own phrasing — and it is Diagnostics that produces the checks grouped into effort buckets. Diagnostics scores a site from “Not Ready” up to fully agent-native, rolling per-hostname checks into a single view.
Each check returns one of three states, not two: every check comes back as pass, fail, or neutral, with a note on why it matters, and an evidence trail showing the exact request and response we saw. The neutral state is doing real work — it is how the tool handles checks that do not apply to a given site type, and calling this a two-state checklist misreads the output.
Quick wins
A crawler-readable robots.txt, an XML sitemap, AI-crawler rules, and serving clean Markdown to agents. This is the bucket almost every site should clear regardless of what happens to the rest of the product — none of it is speculative and none of it depends on Cloudflare.
Technical groundwork
Content Signals that state how your content may be used, an API catalog, link headers, and agent login instructions. Mixed maturity: link headers and the API catalog are published RFCs, while Content Signals guides the IETF's proposed AI Preferences work rather than a ratified standard.
Advanced integration
The most forward-looking bucket and the one to treat with the most caution — four of the six checks Cloudflare names here are drafts or vendor proposals rather than ratified standards. Worth tracking, not worth treating as a compliance obligation.
Commerce — informational
Cloudflare is explicit that this bucket is informational for now, and not counted in your score. If you sell online, x402 is the one with the most existing coverage — but nothing in this bucket moves your readiness number today.
Remediation is genuinely well designed. Where a Cloudflare setting fixes a failing check, you get a Set up in Cloudflare deep link — Cloudflare names Markdown for Agents and managed robots.txt as examples. Where it does not, there is a Copy Agent Prompt button that proposes what your coding agent needs to build. That is a sensible acknowledgement that most of this list is engineering work, not a toggle.
The two tools also organise the same territory differently. The free scanner groups its checks by subject — discoverability, content accessibility, bot access control, API/auth/MCP discovery, and commerce. The August dashboard groups by effort — Quick wins, Technical groundwork, Advanced integration, Commerce. That is a product moving from “what standards exist” to “what should you do Monday,” which is a reasonable move. It also means the two do not hand you the same mental model, and that matters for the comparison in Section 08.
06 — Standards MaturityA readiness score that partly grades you on drafts.
The Advanced integration bucket is where a vendor scorecard quietly becomes an opinion about the future. Of the six checks Cloudflare names in it, four are drafts or vendor proposals rather than ratified standards — and one of them says so in its own text.
That line comes from the WebMCP specification itself. The same audit applied across the rest of the bucket: Web Bot Auth is an IETF draft, the MCP Server Card is described by Cloudflare’s own April post as a proposal currently in draft, and the Agent Skills index is a Cloudflare proposal — Cloudflare writes that it has proposed that sites make this information available at a well-known agent-skills path. The ratified work sits a bucket lower: the API Catalog, mapped to Technical groundwork, is published as RFC 9727 and Link headers as RFC 8288. That is a fair critique to make of any readiness score: part of it grades you on unratified work.
The table below is the full twenty-check list from the live free scanner, mapped to the August effort buckets, with each check’s standards status and the adoption figure where Cloudflare has published one. The verdict column is ours. Where a status could not be established from the sources read, the cell says so rather than guessing.
| Check | August effort bucket | Standards status | Adoption where Cloudflare published it | Our verdict |
|---|---|---|---|---|
| Discoverability — 4 checks | ||||
| robots.txt | Quick wins | Long-established web convention | 78% of the scanned set | Do now |
| XML sitemap | Quick wins | Long-established web convention | Not published | Do now |
| Link headers | Technical groundwork | Published RFC — RFC 8288 | Not published | Do if relevant |
| DNS-AID | Not named in the August buckets | Not classified in the sources we read | Not published | Watch |
| Content accessibility — 1 check | ||||
| Markdown content negotiation | Quick wins | Not classified in the sources we read | 3.9% of the scanned set | Do now |
| Bot access control — 3 checks | ||||
| AI bot rules | Quick wins | Not classified in the sources we read | Not published | Do now |
| Content Signals | Technical groundwork | Guide to the IETF’s proposed AI Preferences (aipref) work — not ratified | 4% of the scanned set | Do now |
| Web Bot Auth | Advanced integration | IETF draft | Not published | Watch |
| API, auth and MCP discovery — 8 checks | ||||
| API Catalog | Technical groundwork | Published RFC — RFC 9727 | With MCP Server Cards, fewer than 15 sites in the whole scanned set | Do if relevant |
| OAuth discovery | Advanced integration | Not classified in the sources we read | Not published | Do if relevant |
| OAuth Protected Resource | Not named individually in the August buckets | Not classified in the sources we read | Not published | Do if relevant |
| Auth.md | Not named individually; the Technical groundwork bucket lists agent login instructions | Not classified in the sources we read | Not published | Watch |
| MCP Server Card | Advanced integration | Cloudflare calls it a proposal currently in draft | With API Catalogs, fewer than 15 sites in the whole scanned set | Watch |
| A2A Agent Card | Advanced integration | Open protocol, self-described as an open standard; no ratifying body named in the sources we read | Not published | Watch |
| Agent Skills index | Advanced integration | Cloudflare proposal | Not published | Watch |
| WebMCP | Advanced integration | Draft Community Group Report — explicitly not a W3C Standard and not on the standards track | Not published | Watch |
| Commerce — 4 checks | ||||
| x402 | Commerce — unscored | Not classified in the sources we read | Not published | Watch |
| MPP — Machine Payment Protocol | Absent from the August list, which names AP2 instead | Not classified in the sources we read | Not published | Watch |
| UCP | Commerce — unscored | Not classified in the sources we read | Not published | Watch |
| ACP | Commerce — unscored | Not classified in the sources we read | Not published | Watch |
Two details fall out of that table. The first is the commerce discrepancy: the August blog post’s Commerce bucket names x402, ACP, UCP and AP2, while the live free scanner lists x402, MPP, UCP and ACP — and the scanner’s own skills index defines MPP as Machine Payment Protocol. The dashboard product and the free scanner do not check the same commerce list, so do not treat a free-scanner result as a preview of the dashboard one. If you want the background on the one with the most existing coverage, we have a walkthrough of x402, the payment standard in the unscored commerce bucket.
The second is that the deeper you go down the bucket list, the more you are optimising for a machine-identity future that has not settled. That is not an argument against doing any of it — it is an argument for sequencing. Cloudflare has been building toward this for a while; its earlier work on agent identity and temporary accounts is the same thesis from the access-control side.
07 — The Adoption BaselineThe bar is low, and Cloudflare published the numbers.
The strongest argument for doing this work is not the new dashboard. It is the adoption baseline Cloudflare published back in April, and it comes with an unusually well-specified denominator. Cloudflare Radar took the 200,000 most-visited domains on the internet, filtered out categories where agent readiness is irrelevant — redirects, ad servers, tunnelling services — and scanned what was left. Every figure below is a share of that filtered set, not of the web.
Agent-readiness signals across Cloudflare's scanned set · April 2026
Source: Cloudflare, April 17, 2026 — Radar scan of the 200,000 most-visited domains, minus filtered categoriesThe most striking figure is the one that does not fit on a bar chart. Across that entire scanned set, MCP Server Cards and API Catalogs together appear on fewer than 15 sites. Not fewer than 15 percent — fewer than 15 sites. On those two checks — the API Catalog in Technical groundwork and the MCP Server Card in Advanced integration — essentially nobody has shipped anything, which is worth holding in mind before treating a low readiness score as a competitive disadvantage.
The Markdown check carries a tension of its own, and it comes straight out of Cloudflare’s own testing. Of 7 agents Cloudflare tested as of February 2026, only 3 — Claude Code, OpenCode and Cursor — request content with an Accept: text/markdown header by default. So the scanner scores you on serving Markdown to agents while most of the agents Cloudflare itself tested do not ask for it. The denominator there is seven agents Cloudflare tested, not the agent population.
08 — Free vs Early AccessYou can run twenty of these checks today, free.
While the dashboard sits behind an early-access request, the free scanner is live with no account and no waitlist at the time of writing — and it publishes its own scope in machine-readable form. Its manifest states that it scans a website URL to check its AI agent readiness level from 0 to 5 across 20 checks covering discoverability, content accessibility, bot access control, API/auth/MCP discovery, and commerce. The homepage check list sums independently to the same total: 4 + 1 + 3 + 8 + 4 = 20. It also publishes 23 skill documents, each with a SHA-256 digest, at a well-known agent-skills index.
One published detail is easy to miss: llms.txt is not a default check. Cloudflare states it plainly — By default, we only check whether the site correctly handles Markdown content negotiation, and do not check for llms.txt — and adds that you can customise the scan to include it if you choose. That is a meaningful signal about where a major infrastructure vendor thinks the convention sits. It lines up with llms.txt adoption in practice and with Google’s position on llms.txt.
| Capability | isitagentready.com — free, live | AEO Suite in the Cloudflare dashboard — early access |
|---|---|---|
| Check scope | 20 checks in five subject groups, customisable by preset — All Checks, Content Site, or API / Application | Diagnostics checks grouped into four effort buckets; the total number is not published |
| Scoring scale | 0 to 5 readiness level | Not Ready through fully agent-native; each check returns pass, fail or neutral with an evidence trail |
| Citation metrics | None | Citation Rate, Prominence, Mention Rate, Share of Voice and Industry Fit — Claude and GPT only |
| Operator crawl and referral data | None | AI Operator Activity panel — per-operator crawl, referral and error data from your own traffic |
| Remediation | AI-generated recommendations, shipped with Cloudflare’s own disclaimer that AI can make mistakes and that it assumes no liability | Set up in Cloudflare deep links where a Cloudflare setting fixes it, plus a Copy Agent Prompt button for everything else |
| Commerce checks named | x402, MPP, UCP, ACP | x402, ACP, UCP, AP2 |
| Access and price | Live, no account and no waitlist at the time of writing | Early access by request from the Overview tab; no price published and no GA date given |
The practical read: run the free scanner first. It costs nothing, requires no waitlist, and the twenty checks it runs overlap heavily with what Diagnostics grades. Just do not assume the two produce identical results — the commerce row above is a concrete demonstration that they do not check the same list, and the April scanner and August dashboard organise their findings around different mental models.
09 — What To DoDo the quick wins; watch the rest.
The useful question is not whether to adopt Cloudflare’s scorecard. It is which of these checks you would want done even if this product disappeared tomorrow. Sorted by that test, the list separates cleanly.
Clear the quick wins bucket
A crawler-readable robots.txt, an XML sitemap, explicit AI-crawler rules, and clean Markdown served to agents. All four are cheap, none depends on an unratified spec, and Content Signals at 4% adoption across the scanned set means declaring your preferences still differentiates you.
Fix what actually blocks agents
Before optimising for citation, make sure crawlers can reach your content at all — redirect chains, blocked archives and 403s on the operator panel will cost you more than any missing agent card. The AI Operator Activity panel is the genuinely new data here, because it is your traffic, not a sample.
Track, do not chase, the advanced bucket
WebMCP, Web Bot Auth, MCP Server Cards and the skills index are drafts and proposals. Fewer than 15 sites in Cloudflare's whole scanned set carry an MCP Server Card or API Catalog. Implement them when a customer or agent integration needs them, not to move a score.
Caveat every citation number you pass on
Two assistant families, an inferred category, unbranded prompts, and a pre-computed panel with an undisclosed refresh cadence. State all four next to the number. A visibility score reported without its denominator is how measurement programmes lose credibility in their second quarter.
The forward view is the interesting part. Citation measurement is converging on the platforms that already hold the logs — Microsoft shipped it inside Bing Webmaster Tools and Clarity, and Cloudflare has now shipped it at the CDN layer, where crawl and referral data already lives. Our read is that this is where the category ends up: the sampling half of these products is commoditised and will converge on similar numbers, while the differentiator becomes whose observed-traffic data you already have. That argues for treating citation scores as a directional input and per-operator crawl and referral logs as the operational one.
It also raises the pressure on access decisions. Cloudflare has announced that on September 15, 2026 it will set new defaults for newly onboarding domains, blocking the Training and Agent crawler categories by default on pages that display ads while leaving Search allowed — existing customers can opt out in Security settings before then. That is on our Q3 2026 platform deadline calendar. Measuring citations while your crawl posture changes underneath you is a good way to misread the result, so decide the posture first. If you want the crawler-reachability side audited properly, start with auditing whether crawlers can actually reach your archive, and for the strategy layer our agentic SEO engagements start with exactly this sequence.
10 — ConclusionA real product, with a stated methodology to argue with.
The most valuable thing Cloudflare shipped is a methodology you can check.
The AEO Visibility Dashboard is a serious entry into AI-visibility measurement, and the honest case for it is not the metric list — other platforms have shipped citation reporting already. It is that Cloudflare sits where the crawl and referral logs are, and the AI Operator Activity panel turns that position into data no prompt-sampling tool can produce.
The case against over-reading it is equally well documented, and mostly by Cloudflare itself. Two assistant families. An inferred category. Unbranded prompts. A category panel computed once and reused, with no published refresh cadence. And a press release that criticises prompt sampling while the headline visibility metrics are produced by it. None of that makes the product bad; all of it belongs next to the number when you report it.
The practical move is unchanged by the launch. Run the free scanner today, clear the quick-wins bucket, instrument your own operator traffic, and treat the advanced-integration checks as a watch list rather than a compliance obligation — four of the six checks in that bucket are drafts or proposals, and fewer than 15 sites in Cloudflare’s entire scanned set carry an MCP Server Card or an API Catalog. The bar is low. That is the opportunity, and it does not require early access to act on. For the wider strategy, our full AEO guide and the counter-programming in Google’s statement on Reddit and ranking preference are the two companions to this piece.