SEONew Release22 min readPublished August 8, 2026

AEO Visibility Dashboard · early access by request · two assistants probed

Cloudflare Now Scores Whether AI Assistants Cite You

Cloudflare released its AEO Visibility Dashboard on August 6, 2026, in early access by request with no published price. It scores how often Claude and GPT cite you — two assistant families, not all AI search — against a category baseline that is computed once and reused. The refresh cadence for that baseline is not published anywhere.

DA
Digital Applied Team
Senior strategists · Published August 8, 2026
PublishedAugust 8, 2026
Read time22 min
SourcesCloudflare primaries + arXiv preprint
Assistants probed
2
Anthropic's Claude and OpenAI's GPT, today
Visibility metrics
5
Industry Fit appears in the blog post only
Free scanner checks
20
isitagentready.com · 0–5 readiness scale
Published price
None
Early access by request; no GA date given

Cloudflare released its AEO Visibility Dashboard on August 6, 2026, moving answer engine optimization measurement out of the SEO-tool startup layer and onto the CDN. The dashboard reports how often AI assistants cite your site, sitting beside per-operator crawl and referral logs drawn from your own traffic. It is available in early access by request, and no price is published anywhere.

Two things make this worth a careful read rather than a headline. First, the citation metrics probe exactly two assistant families — Anthropic’s Claude and OpenAI’s GPT — so nothing here covers Gemini, Perplexity, Copilot or Grok. Second, your score is not a live read of what those assistants said about you today: it is measured against a category baseline that Cloudflare computes once and reuses across every account in that category.

What follows is the launch itself and the methodology underneath it, not another tools roundup — for the category map, see our guide to the AI-visibility tool category Cloudflare just entered. Below: what shipped and what did not, what each metric is a percentage of, where the sampling argument breaks down, and which of the twenty agent-readiness checks are worth doing regardless of vendor.

Key takeaways
  1. 01
    One new product, one existing one, one announcement.The AEO Visibility Dashboard is the new tool, released August 6, 2026 in early access. Agent Readiness is described by Cloudflare as the existing tool in the suite — it launched April 17, 2026 and was integrated into the dashboard on August 6, not introduced.
  2. 02
    Two assistants, not all AI search.Cloudflare states it probes the leading assistants, today Anthropic's Claude and OpenAI's GPT. No Gemini, no Perplexity, no Copilot. Every visibility number carries that scope limit, and Cloudflare's own hedge is the word today.
  3. 03
    Your Citation Rate is scored against a reused snapshot.Cloudflare runs its category panel once per category and reuses the baseline across all accounts in that category, so results load from a snapshot rather than a live model query. Neither primary states how often that snapshot refreshes.
  4. 04
    The press release criticises the method the dashboard uses.It calls prompt sampling limited in scale and prone to inconsistency — and the visibility metrics are produced by prompt sampling. The genuine network-layer advantage lives in the separate AI Operator Activity panel, not in Citation Rate.
  5. 05
    The advanced bucket grades you on drafts.Of the six checks Cloudflare names in Advanced integration, four are unratified: WebMCP's own spec says it is not a W3C Standard, Web Bot Auth is an IETF draft, Cloudflare calls the MCP Server Card a proposal currently in draft, and the Agent Skills index is a Cloudflare proposal. The checklist's published RFCs sit in a different bucket.

01What ShippedTwo products, one announcement — and only one of them is new.

The clean way to read August 6 is as a three-level taxonomy. The AEO Suite is the umbrella product line. The AEO Visibility Dashboard is the new tool inside it, described in Cloudflare’s press release as the newest addition to that suite. Agent Readiness is the third piece — and Cloudflare describes it verbatim as the existing tool in the suite. It launched on April 17, 2026 as the free scanner at isitagentready.com plus a Cloudflare Radar dataset. What happened on August 6 is that it moved into the Cloudflare dashboard.

That distinction matters because most coverage compresses it. Saying “Cloudflare launched Agent Readiness” is wrong by nearly four months. The accurate version: the visibility dashboard is new, the readiness scanner is not, and the news is that they now sit in one place. The engineering post that accompanies the launch — From ranking to recommended, by Matthew Conroy and Jack Galilee — carries the technical detail; the press release carries the positioning and both executive quotes.

New · August 6, 2026
AEO Visibility Dashboard
Early access by request · no published price

Citation Rate, Prominence, Mention Rate, Share of Voice and Industry Fit, produced by probing Claude and GPT with likely category prompts. Sits next to an AI Operator Activity panel built on observed crawl and referral traffic. Requestable from the Overview tab in the Cloudflare dashboard.

blog.cloudflare.com/aeo
Existing · April 17, 2026
Agent Readiness
Launched April 2026 · integrated into the dashboard August 6

Cloudflare's own opinion of what an agent-ready site looks like, expressed as a scored checklist. The free public version is still live at isitagentready.com, and Agent Readiness is also embedded in Cloudflare URL Scanner, including programmatically via an agentReadiness option on its API.

isitagentready.com
Umbrella
AEO Suite
Product line, not a single tool

The name Cloudflare uses for the whole line. Its forward-looking-statements section explicitly lists as uncertain the timing of when AEO Suite or any of its related features will be generally available — so there is no GA date, and none of it should be budgeted as a shipped, priced product.

Press release, August 6, 2026
Launch snapshot
Released August 6, 2026. Availability: early access only, requested from the Overview tab in the Cloudflare dashboard. No price is published in either the blog post or the press release, and no general-availability date was given — Cloudflare’s own forward-looking statements list GA timing as uncertain. One framing correction worth making early: this was not part of Agents Week. Cloudflare’s Agents Week 2026 tag page carries posts dated April 15–20, 2026, and the August 6 post does not appear on it.

The pitch underneath the launch is a traffic argument. Cloudflare writes that by our count, fewer than half of all HTML page requests now come from a human — and immediately qualifies it: Not all of those machines are agents acting for a person, but that share is growing fast. Both halves matter. The denominator is HTML page requests observed across Cloudflare’s network, not all internet traffic and not visits, and “by our count” is a self-measurement hedge Cloudflare put there deliberately. For precise bot-versus-human figures with their bases stated, use our dated reference on bot-versus-human traffic rather than a number pulled from a live dashboard.

02The Five MetricsFive scores, five different denominators.

Every write-up of this launch lists the metric names. Almost none state what each number is a percentage of — and the bases genuinely differ. Prominence, for example, is conditional on having been cited at all, so it sits on a strictly smaller base than Citation Rate. A Prominence score that improves while your citation count shrinks is not progress; it is a smaller sample.

There is also a fifth metric that the press release omits. Industry Fit — a score measuring whether an AI assistant views your site alongside your actual competitors — appears in the engineering blog post but not in the release. Any “four metrics” framing of this product is incomplete. All five are produced by probing the same two assistant families.

The five AEO Visibility Dashboard metrics with Cloudflare’s own definitions, the denominator each number is a share of, whether it is read live or from a snapshot, and what it cannot answer. All five are produced by probing two assistant families, Anthropic’s Claude and OpenAI’s GPT.
MetricCloudflare’s definitionWhat the number is a share ofLive or snapshotWhat it cannot tell you
In both the blog post and the press release
Citation RateThe share of answers in your category that cite your site as a sourceAnswers sampled in the category Cloudflare inferred for you — not all AI answers, and not all queries about youSnapshotHow you perform on branded queries. The panel prompts are unbranded by design.
ProminenceWhen you are cited, how much of the answer is actually yours and how early it landsOnly the answers in which you were cited — a strict subset of the Citation Rate baseSnapshotWhether citations are growing. Read it next to Citation Rate or it will flatter a shrinking sample.
Mention RateHow often assistants name your brand in their answer, whether or not your domain is cited as a sourceThe same sampled category answers as Citation RateSnapshotWhether the mention was favourable. It counts naming, not sentiment.
Share of VoiceYour slice of citations against those for your competitors, so you can see who is winning the prompts you are losingAll citations in the sampled category panel, across you and the competitor set Cloudflare inferredSnapshotAnything dependable if the inferred competitor set is wrong — the category is derived from your site, not declared by you.
In the engineering blog post only — absent from the press release
Industry FitA score that measures whether an AI assistant views your site alongside your actual competitorsWhich brands consistently appear together in the same category panelSnapshotIts exact construction. The definition is blog-sourced only and the press release does not mention it at all.

Cloudflare’s own reading of the gap between Mention Rate and Citation Rate is the most useful diagnostic in the set. Assistants naming you far more than they cite you, the blog argues, means you are on their radar but not yet earning the citation — a specific, targetable gap. The press release sharpens the same point: a brand mentioned but not cited has an authority problem, not an awareness problem. That is a fair and non-obvious read, and it is the part of the product we would actually use.

If you are assembling your own scorecard rather than adopting a vendor’s, the useful comparison is against a written spec. Ours is at how an AI-visibility score should be specified, and it exists precisely because most vendor metrics ship without a stated denominator.

03The SnapshotYour Citation Rate is scored against a reused baseline.

This is the single most consequential architectural fact in the launch, and Cloudflare states it plainly rather than burying it. The category panel your score is measured against is not run when you open the AEO tab. It was run once for your whole category, and every account in that category is scored against the same copy.

"Rather than re-querying models every time a site owner runs a scan, we run this panel once per category and reuse the baseline across all accounts in that domain."— Matthew Conroy and Jack Galilee, Cloudflare engineering blog, August 6, 2026

Cloudflare frames this as a benefit, and on latency it is one: the first listed advantage is zero latency, with results loading instantly from a snapshot rather than waiting for live model queries. It also makes the numbers comparable between accounts in the same category, which a per-account live query would not.

Four further design choices follow from the same primary, and each changes how you should report the output:

  • Your category is inferred, not declared. Cloudflare infers your industry and category from your site. A mis-inferred category benchmarks you against the wrong competitor set, and every metric in the table above inherits that error.
  • The panel prompts are unbranded. Cloudflare queries assistants with likely prompts in the category without specifying your brand. So the metrics describe unprompted category discovery, not how you perform when someone asks about you by name.
  • Prompts are repeated to absorb model variance. Because assistants rarely answer the same question the same way twice, Cloudflare routes prompts through its AI Gateway and asks each assistant multiple times across different models. The number of repeats is not stated.
  • Scoring uses a model judge, but not a self-judge. Workers AI does the work where genuine judgment is required, and Cloudflare says it uses exact text analysis rather than a model grading its own output. Read that precisely: the claim is not that no model grades anything.
The caveat to put in the client deck
Neither the blog post nor the press release states how often the category panel is re-run. That makes the refresh cadence undisclosed at the time of writing — and since Citation Rate is scored against that pre-computed panel, a month-over-month movement in your score may reflect a panel refresh rather than anything you changed. Do not guess a cadence, and do not report these figures as “what Claude and GPT said this week” until Cloudflare publishes one.

04The Sampling ParadoxThe release criticises the method the dashboard uses.

Cloudflare’s strongest structural argument is that it sits at the network layer and can see what AI systems actually do, rather than inferring it from a sample. Stephanie Cohen, Cloudflare’s Chief Strategy Officer, puts it in the release: Cloudflare sees real crawl activity and real referrals across millions of sites, and that is what powers these tools. On the AI Operator Activity panel, that is straightforwardly true — it reports the real crawl and referral traffic on your site, per operator, including the errors those operators hit on the way, such as 403 blocked and 404 dead links.

The tension is that the citation metrics are not built that way.

From the press release, unattributed institutional copy

“Most tools attempt to fill that gap by only sending test prompts to AI chatbots and sampling the responses — a method limited in scale and prone to inconsistency if not paired with other data signals.”

This line has no named speaker in the release. It is Cloudflare institutional copy, and it should not be attributed to any individual — including the two executive quotes that sit elsewhere in the same document.

And yet the AEO tab probes Claude and GPT with likely customer prompts and reads the answers, which is prompt sampling. That is not a gotcha and it does not make Cloudflare dishonest; the honest formulation is narrower and more useful. Cloudflare’s network-layer advantage is real, and it lives in the operator panel. The citation metrics rest on the same sampling technique as the rest of the category. The release compresses two different evidence types into one claim. PPC Land reached the same reading independently, writing that the blog post describes the AEO tab doing precisely what the release characterises as the limited method.

There is independent work on why sampled brand metrics wobble, and it needs to be cited carefully rather than borrowed as proof. A July 2026 arXiv preprint by Dmitrij Żatuchin decomposes the variance in LLM brand answers. Three scope limits travel with it. It is a single-author preprint that has not been peer-reviewed. It measures multilingual sentiment polarity rather than citation rate. And its corpus is 12,933 responses covering 20 Central and Eastern European brands in 8 languages across GPT-5.2, Gemini 3 Flash and Perplexity, so Claude is not in its model set. It is corroboration that sampled brand metrics are noisy. It is not a measurement of Cloudflare’s product.

Query language
Largest systematic facet
26.5%

Share of the variance of a single response attributable to the language the query was asked in — the biggest systematic driver the preprint identifies. Cloudflare's panel is single-category and single-language, so the driver that matters most here is the one it never varies.

Preprint, not peer-reviewed
Brand identity
Almost no brand signal
1.5%

Share of the variance of a single response attributable to which brand was being asked about (ICC 0.0146), against 34.8% from pure resampling. On the same denominator, re-asking the same question moves the answer far more than changing the brand does.

Same denominator
Reliability, one answer
Brand-ranking reliability
0.01

Reported as staying near 0.01 for a single answer and about 0.36 at the full crossed design, across 12,933 responses for 20 Central and Eastern European brands in 8 languages on GPT-5.2, Gemini 3 Flash and Perplexity. Sentiment polarity, not citations.

Claude not tested
"a single AI answer carries almost no brand-discriminating signal."— Dmitrij Żatuchin, arXiv preprint 2607.13304, July 14, 2026

The paper’s practical finding cuts both ways for Cloudflare. It reports that per unit of query budget, adding languages and models reduces relative-error variance far more than adding repeats — a repeat past the fifth reduces it by only 0.0003 — and that reliability is bought by spreading across languages and models, not by repeating one prompt. Cloudflare’s stated approach of prompting multiple times across different models matches that advice. A single-category, single-language panel probing two assistant families does not address the largest facet the paper identifies.

Cloudflare is also not the first platform to ship citation reporting. Microsoft got there twice already — see Bing’s own citation-share reporting and Microsoft Clarity’s citation measurement. What makes Cloudflare the interesting third entrant is not the metrics; it is that this is the first of the three to sit at the CDN layer, where the crawl and referral logs already are.

05Agent ReadinessDiagnostics, four effort buckets, and three check states.

The nesting here is easy to get wrong. Agent Readiness is the dashboard tab. Diagnostics is the technical checkup within Agent Readiness — Cloudflare’s own phrasing — and it is Diagnostics that produces the checks grouped into effort buckets. Diagnostics scores a site from “Not Ready” up to fully agent-native, rolling per-hostname checks into a single view.

Each check returns one of three states, not two: every check comes back as pass, fail, or neutral, with a note on why it matters, and an evidence trail showing the exact request and response we saw. The neutral state is doing real work — it is how the tool handles checks that do not apply to a given site type, and calling this a two-state checklist misreads the output.

Bucket 01 · Scored
Quick wins
robots.txt · XML sitemap · AI-crawler rules · Markdown

A crawler-readable robots.txt, an XML sitemap, AI-crawler rules, and serving clean Markdown to agents. This is the bucket almost every site should clear regardless of what happens to the rest of the product — none of it is speculative and none of it depends on Cloudflare.

Do this bucket first
Bucket 02 · Scored
Technical groundwork
Content Signals · API catalog · link headers · agent login

Content Signals that state how your content may be used, an API catalog, link headers, and agent login instructions. Mixed maturity: link headers and the API catalog are published RFCs, while Content Signals guides the IETF's proposed AI Preferences work rather than a ratified standard.

Do if relevant to your site type
Bucket 03 · Scored
Advanced integration
OAuth discovery · MCP + A2A agent cards · skills index · Web Bot Auth · WebMCP

The most forward-looking bucket and the one to treat with the most caution — four of the six checks Cloudflare names here are drafts or vendor proposals rather than ratified standards. Worth tracking, not worth treating as a compliance obligation.

Watch, do not chase the score
Bucket 04 · Not scored
Commerce — informational
x402 · ACP · UCP · AP2

Cloudflare is explicit that this bucket is informational for now, and not counted in your score. If you sell online, x402 is the one with the most existing coverage — but nothing in this bucket moves your readiness number today.

Zero score impact

Remediation is genuinely well designed. Where a Cloudflare setting fixes a failing check, you get a Set up in Cloudflare deep link — Cloudflare names Markdown for Agents and managed robots.txt as examples. Where it does not, there is a Copy Agent Prompt button that proposes what your coding agent needs to build. That is a sensible acknowledgement that most of this list is engineering work, not a toggle.

The two tools also organise the same territory differently. The free scanner groups its checks by subject — discoverability, content accessibility, bot access control, API/auth/MCP discovery, and commerce. The August dashboard groups by effort — Quick wins, Technical groundwork, Advanced integration, Commerce. That is a product moving from “what standards exist” to “what should you do Monday,” which is a reasonable move. It also means the two do not hand you the same mental model, and that matters for the comparison in Section 08.

06Standards MaturityA readiness score that partly grades you on drafts.

The Advanced integration bucket is where a vendor scorecard quietly becomes an opinion about the future. Of the six checks Cloudflare names in it, four are drafts or vendor proposals rather than ratified standards — and one of them says so in its own text.

WebMCP is not a W3C standard
The WebMCP specification — a Draft Community Group Report from the Web Machine Learning Community Group, dated July 28, 2026 — states verbatim: “It is not a W3C Standard nor is it on the W3C Standards Track.” Several aggregator pages describe it as an official W3C standard. They are wrong, and if you are being scored against it, the distinction is the difference between a compliance task and a bet.

That line comes from the WebMCP specification itself. The same audit applied across the rest of the bucket: Web Bot Auth is an IETF draft, the MCP Server Card is described by Cloudflare’s own April post as a proposal currently in draft, and the Agent Skills index is a Cloudflare proposal — Cloudflare writes that it has proposed that sites make this information available at a well-known agent-skills path. The ratified work sits a bucket lower: the API Catalog, mapped to Technical groundwork, is published as RFC 9727 and Link headers as RFC 8288. That is a fair critique to make of any readiness score: part of it grades you on unratified work.

The table below is the full twenty-check list from the live free scanner, mapped to the August effort buckets, with each check’s standards status and the adoption figure where Cloudflare has published one. The verdict column is ours. Where a status could not be established from the sources read, the cell says so rather than guessing.

All twenty checks published by Cloudflare’s free agent readiness scanner, grouped by that scanner’s own five subject categories, mapped to the August dashboard effort buckets, with standards status, published adoption where available, and our verdict. Adoption percentages are shares of the roughly 200,000 most-visited domains Cloudflare scanned in April 2026 after filtering out categories where agent readiness is irrelevant — not shares of the web.
CheckAugust effort bucketStandards statusAdoption where Cloudflare published itOur verdict
Discoverability — 4 checks
robots.txtQuick winsLong-established web convention78% of the scanned setDo now
XML sitemapQuick winsLong-established web conventionNot publishedDo now
Link headersTechnical groundworkPublished RFC — RFC 8288Not publishedDo if relevant
DNS-AIDNot named in the August bucketsNot classified in the sources we readNot publishedWatch
Content accessibility — 1 check
Markdown content negotiationQuick winsNot classified in the sources we read3.9% of the scanned setDo now
Bot access control — 3 checks
AI bot rulesQuick winsNot classified in the sources we readNot publishedDo now
Content SignalsTechnical groundworkGuide to the IETF’s proposed AI Preferences (aipref) work — not ratified4% of the scanned setDo now
Web Bot AuthAdvanced integrationIETF draftNot publishedWatch
API, auth and MCP discovery — 8 checks
API CatalogTechnical groundworkPublished RFC — RFC 9727With MCP Server Cards, fewer than 15 sites in the whole scanned setDo if relevant
OAuth discoveryAdvanced integrationNot classified in the sources we readNot publishedDo if relevant
OAuth Protected ResourceNot named individually in the August bucketsNot classified in the sources we readNot publishedDo if relevant
Auth.mdNot named individually; the Technical groundwork bucket lists agent login instructionsNot classified in the sources we readNot publishedWatch
MCP Server CardAdvanced integrationCloudflare calls it a proposal currently in draftWith API Catalogs, fewer than 15 sites in the whole scanned setWatch
A2A Agent CardAdvanced integrationOpen protocol, self-described as an open standard; no ratifying body named in the sources we readNot publishedWatch
Agent Skills indexAdvanced integrationCloudflare proposalNot publishedWatch
WebMCPAdvanced integrationDraft Community Group Report — explicitly not a W3C Standard and not on the standards trackNot publishedWatch
Commerce — 4 checks
x402Commerce — unscoredNot classified in the sources we readNot publishedWatch
MPP — Machine Payment ProtocolAbsent from the August list, which names AP2 insteadNot classified in the sources we readNot publishedWatch
UCPCommerce — unscoredNot classified in the sources we readNot publishedWatch
ACPCommerce — unscoredNot classified in the sources we readNot publishedWatch

Two details fall out of that table. The first is the commerce discrepancy: the August blog post’s Commerce bucket names x402, ACP, UCP and AP2, while the live free scanner lists x402, MPP, UCP and ACP — and the scanner’s own skills index defines MPP as Machine Payment Protocol. The dashboard product and the free scanner do not check the same commerce list, so do not treat a free-scanner result as a preview of the dashboard one. If you want the background on the one with the most existing coverage, we have a walkthrough of x402, the payment standard in the unscored commerce bucket.

The second is that the deeper you go down the bucket list, the more you are optimising for a machine-identity future that has not settled. That is not an argument against doing any of it — it is an argument for sequencing. Cloudflare has been building toward this for a while; its earlier work on agent identity and temporary accounts is the same thesis from the access-control side.

07The Adoption BaselineThe bar is low, and Cloudflare published the numbers.

The strongest argument for doing this work is not the new dashboard. It is the adoption baseline Cloudflare published back in April, and it comes with an unusually well-specified denominator. Cloudflare Radar took the 200,000 most-visited domains on the internet, filtered out categories where agent readiness is irrelevant — redirects, ad servers, tunnelling services — and scanned what was left. Every figure below is a share of that filtered set, not of the web.

Agent-readiness signals across Cloudflare's scanned set · April 2026

Source: Cloudflare, April 17, 2026 — Radar scan of the 200,000 most-visited domains, minus filtered categories
Has a robots.txtCloudflare notes most are written for search crawlers, not AI agents
78%
Declares Content SignalsAI usage preferences stated in robots.txt
4%
Passes Markdown content negotiationServes clean Markdown when an agent asks for it
3.9%

The most striking figure is the one that does not fit on a bar chart. Across that entire scanned set, MCP Server Cards and API Catalogs together appear on fewer than 15 sites. Not fewer than 15 percent — fewer than 15 sites. On those two checks — the API Catalog in Technical groundwork and the MCP Server Card in Advanced integration — essentially nobody has shipped anything, which is worth holding in mind before treating a low readiness score as a competitive disadvantage.

The Markdown check carries a tension of its own, and it comes straight out of Cloudflare’s own testing. Of 7 agents Cloudflare tested as of February 2026, only 3 — Claude Code, OpenCode and Cursor — request content with an Accept: text/markdown header by default. So the scanner scores you on serving Markdown to agents while most of the agents Cloudflare itself tested do not ask for it. The denominator there is seven agents Cloudflare tested, not the agent population.

Two vendor benchmarks, labelled as such
Cloudflare reports that it measured up to 80% token reduction in some cases from serving Markdown — keep that hedge intact; it is not a flat 80%. It also reports that an agent pointed at Cloudflare’s own documentation consumed 31% fewer tokens and reached the correct answer 66% faster than the average site that is not refined for agents. That benchmark is vendor-designed and vendor-run, and the comparison set is never enumerated. Useful as direction, not as a number to quote to a client.

08Free vs Early AccessYou can run twenty of these checks today, free.

While the dashboard sits behind an early-access request, the free scanner is live with no account and no waitlist at the time of writing — and it publishes its own scope in machine-readable form. Its manifest states that it scans a website URL to check its AI agent readiness level from 0 to 5 across 20 checks covering discoverability, content accessibility, bot access control, API/auth/MCP discovery, and commerce. The homepage check list sums independently to the same total: 4 + 1 + 3 + 8 + 4 = 20. It also publishes 23 skill documents, each with a SHA-256 digest, at a well-known agent-skills index.

One published detail is easy to miss: llms.txt is not a default check. Cloudflare states it plainly — By default, we only check whether the site correctly handles Markdown content negotiation, and do not check for llms.txt — and adds that you can customise the scan to include it if you choose. That is a meaningful signal about where a major infrastructure vendor thinks the convention sits. It lines up with llms.txt adoption in practice and with Google’s position on llms.txt.

Side-by-side comparison of Cloudflare’s free public agent readiness scanner and the early-access AEO Suite inside the Cloudflare dashboard, covering check scope, scoring scale, citation metrics, operator traffic data, remediation, the commerce checks each one names, and access terms.
Capabilityisitagentready.com — free, liveAEO Suite in the Cloudflare dashboard — early access
Check scope20 checks in five subject groups, customisable by preset — All Checks, Content Site, or API / ApplicationDiagnostics checks grouped into four effort buckets; the total number is not published
Scoring scale0 to 5 readiness levelNot Ready through fully agent-native; each check returns pass, fail or neutral with an evidence trail
Citation metricsNoneCitation Rate, Prominence, Mention Rate, Share of Voice and Industry Fit — Claude and GPT only
Operator crawl and referral dataNoneAI Operator Activity panel — per-operator crawl, referral and error data from your own traffic
RemediationAI-generated recommendations, shipped with Cloudflare’s own disclaimer that AI can make mistakes and that it assumes no liabilitySet up in Cloudflare deep links where a Cloudflare setting fixes it, plus a Copy Agent Prompt button for everything else
Commerce checks namedx402, MPP, UCP, ACPx402, ACP, UCP, AP2
Access and priceLive, no account and no waitlist at the time of writingEarly access by request from the Overview tab; no price published and no GA date given

The practical read: run the free scanner first. It costs nothing, requires no waitlist, and the twenty checks it runs overlap heavily with what Diagnostics grades. Just do not assume the two produce identical results — the commerce row above is a concrete demonstration that they do not check the same list, and the April scanner and August dashboard organise their findings around different mental models.

09What To DoDo the quick wins; watch the rest.

The useful question is not whether to adopt Cloudflare’s scorecard. It is which of these checks you would want done even if this product disappeared tomorrow. Sorted by that test, the list separates cleanly.

This week
Clear the quick wins bucket

A crawler-readable robots.txt, an XML sitemap, explicit AI-crawler rules, and clean Markdown served to agents. All four are cheap, none depends on an unratified spec, and Content Signals at 4% adoption across the scanned set means declaring your preferences still differentiates you.

Do it regardless of vendor
This month
Fix what actually blocks agents

Before optimising for citation, make sure crawlers can reach your content at all — redirect chains, blocked archives and 403s on the operator panel will cost you more than any missing agent card. The AI Operator Activity panel is the genuinely new data here, because it is your traffic, not a sample.

Instrument, then optimise
This quarter
Track, do not chase, the advanced bucket

WebMCP, Web Bot Auth, MCP Server Cards and the skills index are drafts and proposals. Fewer than 15 sites in Cloudflare's whole scanned set carry an MCP Server Card or API Catalog. Implement them when a customer or agent integration needs them, not to move a score.

Watch the specs
Before you report it
Caveat every citation number you pass on

Two assistant families, an inferred category, unbranded prompts, and a pre-computed panel with an undisclosed refresh cadence. State all four next to the number. A visibility score reported without its denominator is how measurement programmes lose credibility in their second quarter.

Name the denominator

The forward view is the interesting part. Citation measurement is converging on the platforms that already hold the logs — Microsoft shipped it inside Bing Webmaster Tools and Clarity, and Cloudflare has now shipped it at the CDN layer, where crawl and referral data already lives. Our read is that this is where the category ends up: the sampling half of these products is commoditised and will converge on similar numbers, while the differentiator becomes whose observed-traffic data you already have. That argues for treating citation scores as a directional input and per-operator crawl and referral logs as the operational one.

It also raises the pressure on access decisions. Cloudflare has announced that on September 15, 2026 it will set new defaults for newly onboarding domains, blocking the Training and Agent crawler categories by default on pages that display ads while leaving Search allowed — existing customers can opt out in Security settings before then. That is on our Q3 2026 platform deadline calendar. Measuring citations while your crawl posture changes underneath you is a good way to misread the result, so decide the posture first. If you want the crawler-reachability side audited properly, start with auditing whether crawlers can actually reach your archive, and for the strategy layer our agentic SEO engagements start with exactly this sequence.

10ConclusionA real product, with a stated methodology to argue with.

Where this leaves AEO measurement, August 2026

The most valuable thing Cloudflare shipped is a methodology you can check.

The AEO Visibility Dashboard is a serious entry into AI-visibility measurement, and the honest case for it is not the metric list — other platforms have shipped citation reporting already. It is that Cloudflare sits where the crawl and referral logs are, and the AI Operator Activity panel turns that position into data no prompt-sampling tool can produce.

The case against over-reading it is equally well documented, and mostly by Cloudflare itself. Two assistant families. An inferred category. Unbranded prompts. A category panel computed once and reused, with no published refresh cadence. And a press release that criticises prompt sampling while the headline visibility metrics are produced by it. None of that makes the product bad; all of it belongs next to the number when you report it.

The practical move is unchanged by the launch. Run the free scanner today, clear the quick-wins bucket, instrument your own operator traffic, and treat the advanced-integration checks as a watch list rather than a compliance obligation — four of the six checks in that bucket are drafts or proposals, and fewer than 15 sites in Cloudflare’s entire scanned set carry an MCP Server Card or an API Catalog. The bar is low. That is the opportunity, and it does not require early access to act on. For the wider strategy, our full AEO guide and the counter-programming in Google’s statement on Reddit and ranking preference are the two companions to this piece.

Measure AI visibility without fooling yourself

A visibility score without its denominator is a number nobody should act on.

We build AI-visibility measurement programmes that state their denominators — combining platform-native citation reporting, your own crawler and referral logs, and the agent-readiness work that pays off regardless of which vendor wins.

Free consultationExpert guidanceTailored solutions
What we work on

AI-visibility engagements

  • Agent-readiness audits — quick wins first, drafts last
  • Crawler reachability and archive discoverability fixes
  • Citation measurement with denominators stated
  • AI crawler access posture before the September defaults
  • Reporting frameworks your leadership can trust
FAQ · Cloudflare AEO Suite

The questions we get every week.

Cloudflare released the AEO Visibility Dashboard, described in its press release as the newest addition to its Answer Engine Optimization Suite, alongside an engineering post by Matthew Conroy and Jack Galilee. The dashboard reports how often AI assistants cite your site, plus a separate AI Operator Activity panel built on observed crawl and referral traffic. The other half of the announcement was integration rather than launch: Agent Readiness, which Cloudflare describes as the existing tool in the suite, was folded into the Cloudflare dashboard. Agent Readiness itself launched on April 17, 2026 as the free scanner at isitagentready.com plus a Cloudflare Radar dataset, so describing it as an August launch is wrong by nearly four months.
Related dispatches

Continue exploring AI visibility.