Ads for AI agents have produced what looks like their first public casualty. Time began inserting FAQ-formatted sponsored content into the markdown version of its webpages — the lightweight, plain-text rendition that AI crawlers and agents read instead of the full HTML page humans see. On August 11, 2026, Digiday reported that Perplexity had blocked all of that markdown advertising on Time.com from influencing its AI agents and user-facing search results, calling the practice deceptive.
The stakes reach well beyond one publisher and one answer engine. If agent-facing inventory is a legitimate new ad channel, every publisher watching bot traffic overtake human traffic has a revenue line to build. If it is cloaking by another name — serving different content to crawlers than to human visitors, the classic search-spam violation — then the first movers are gambling their standing in the AI search indexes that increasingly decide who gets cited at all.
This guide reconstructs what Digiday reported, how Time’s markdown-ad program actually works, why the cloaking framing is the one that matters, and what the fight previews for publishers and advertisers weighing agent-facing placements. We close with a risk ladder — a disclosure-to-deception spectrum for agent-facing tactics that no coverage of the story has laid out so far.
- 01Perplexity blocked Time's markdown ads as deceptive.Per Digiday's August 11 reporting, Perplexity blocked all markdown advertising on Time.com from influencing its AI agents and search results, and a spokesperson warned publishers running such ads risk a trust-score downgrade in its index.
- 02Time's program serves sponsored FAQs only to machines.FAQ-formatted sponsored content sits in the markdown version of Time's pages — read by AI crawlers, invisible to human readers. Ad-tech firm Mobian writes the copy from brand briefs; Ally Bank and the Project Management Institute were early advertisers.
- 03The traffic logic is real, and the risk is cloaking.Digiday reports Time sees more bot than human traffic on most days, and Cloudflare data puts bots above 50% of all web traffic. But serving crawlers different content than humans is the textbook shape of SEO cloaking — a precedent one consultant raised directly.
- 04This is a single-source story — attribute accordingly.All original reporting and on-record quotes come from Digiday. Perplexity published no blog post or statement of its own, Time did not comment on the block itself, and secondary outlets like Nieman Lab and ExchangeWire re-quote Digiday rather than adding facts.
- 05Disclosure placement, not disclosure itself, is the issue.Perplexity's warning covers deceptive practices “sponsored or not,” so a sponsor label would not rescue a placement humans never render. Digiday's reporting does not establish whether Time's markdown ads carry a sponsored label of their own. The dividing line the block draws is whether humans can see what agents are being fed, not whether a label exists.
01 — What HappenedWhat Perplexity blocked, per Digiday.
The facts of the block come from a single piece of original reporting: Digiday’s August 11, 2026 article. Per that reporting, Perplexity blocked all markdown advertising on Time.com from influencing its AI agents and its user-facing search results, characterizing the practice as deceptive. This was not a Perplexity press release — the company’s position reached the public entirely through spokesperson quotes given to Digiday’s reporter.
Perplexity’s chief communications officer Jesse Dwyer told Digiday the company works “continuously” to protect users from “deceptive practices, sponsored or not.” That last clause is the sharpest part of the statement: a sponsored label, in Perplexity’s stated view, does not rescue a placement that humans cannot see. Dwyer went further, warning that publishers deploying “deceptive advertising like markdown ads” risk a “reputational downgrade” — a hit to their trust score in Perplexity’s proprietary search index. Digiday also reported that Perplexity’s search and security teams are working on additional, broader measures against markdown ads.
Time’s side of the exchange is conspicuously quiet. Digiday states directly that Time did not respond to its request for comment on the blocking action. The only on-record Time voice anywhere in this story is chief operating officer Mark Howard reflecting on the program’s novelty in the July 30 launch coverage — “We don’t know yet because this is brand new ... paving the first path forward here” — remarks about the experiment itself, made before the block existed and never offered as a response to Perplexity’s move.
02 — The ProgramHow Time’s markdown ads actually work.
The program Perplexity moved against was itself only twelve days old as public knowledge. Digiday’s July 30 story described the mechanics: Time inserts FAQ-formatted sponsored content into the markdown (plain-text) version of its webpages — the rendition AI agents and crawlers consume. Human visitors loading the same URL in a browser see the normal HTML page, with none of that sponsored copy in it. Publishers maintaining a separate machine-readable layer is not new in itself — it is the logic behind the markdown-first content architecture and llms.txt spec — but selling ad space inside that layer is.
The ad-tech partner is Mobian. Per Digiday, Mobian generates the brand-approved FAQ copy from client briefs, seeds it into Time’s markdown layer, and then tracks which AI search engines surface it. Early advertisers included Ally Bank and the Project Management Institute. One agent ad runs per markdown page, and contextual targeting is available against Time franchises or date ranges. Notably, about 15% of the brands involved are powering their own markdown pages rather than using Time and Mobian’s system — a sign the tactic is already spreading beyond one publisher’s pilot.
Digiday reports that Mobian measures the placements on three scores — visibility, favorability and accuracy — but names them without defining them. The favorability and accuracy descriptions below are our reading of what each score implies, not Mobian’s published documentation.
Visibility
Mobian tracks which AI search engines pick up and surface the seeded FAQ content — the agent-era analogue of an impression, minus any standardized measurement body behind it.
Favorability
Beyond surfacing at all, the favorability score reads as a measure of how favorably AI engines present the advertiser when the seeded content influences an answer — sentiment as a media metric.
Accuracy
Read plainly, whether the AI engine reproduces the brand's claims faithfully — an implicit admission that agent-mediated ads can mutate between placement and delivery.
Time’s commercial logic was stated plainly by its COO in the July 30 story, before any blocking action existed. The quote below is the entire strategy in one sentence — and it is worth reading against Mobian’s own framing, from co-founder and CEO Jonah Goodhart, that “maybe it’s more important to influence the agent than even the human” (as quoted by Digiday).
"This is a growing traffic source, and therefore a growing source of inventory."— Mark Howard, Chief Operating Officer, Time, to Digiday (Jul 30, 2026)
03 — Why NowThe bot-traffic logic driving the experiment.
Time is not chasing a hypothetical audience. Per Digiday’s July 30 reporting, Time sees more AI-crawler requests than the majority of the roughly 7,000 publisher sites in TollBit’s network, and experiences more bot traffic than human traffic on most days — with especially large spikes around Time100 franchise launches. Those are Time-supplied figures with TollBit as the data partner, not an independent audit, but they rhyme with the broader industry picture: bot traffic now outpaces human traffic on many sites, and Cloudflare data cited in the same Digiday piece puts bots at more than 50% of all web traffic.
Seen from that vantage, the program is a rational answer to a genuine shift. The audience a publisher’s ad stack was built to monetize is shrinking as a share of requests; the audience reading the site is increasingly software. Some publishers respond by charging for access or weighing whether to block AI crawlers entirely; Time chose the opposite tack — treat the crawlers as an audience and sell advertisers a way to reach them. The dispute is not about whether that audience exists. It is about what you are allowed to feed it that you do not also show humans.
Of all web traffic
Cloudflare data cited in Digiday's July 30 report puts bot traffic above half of all web traffic. Exact bot-share figures vary by source and measurement period — treat as an order-of-magnitude signal, not a precise constant.
Publisher sites in TollBit's network
Time sees more AI-crawler requests than the majority of them, per Time's own data reported by Digiday — and more bot than human traffic on most days, spiking around Time100 launches.
Brands running their own markdown pages
Per Digiday, roughly 15% of participating brands power their own markdown pages rather than using the Time-Mobian system — early evidence the tactic spreads beyond one publisher.
04 — The Fault LineTwo websites, two audiences: the cloaking question.
Strip away the novelty and the structure of the practice is familiar. Serving one version of a page to crawlers and a different version to human visitors is the definition of cloaking — a violation search engines have penalized for two decades. BCG X managing director Rob Derow raised exactly that precedent in Digiday’s August 11 piece, flagging that markdown ads may constitute SEO cloaking. That is an industry consultant’s reading, not a ruling by any search engine — but it is the frame Perplexity’s “deceptive” language implicitly adopts.
The size of the gap between the two renditions makes the two-websites framing vivid. Digiday’s July 30 reporting described Time’s markdown pages as a small fraction of the weight of the HTML pages — figures of roughly 42KB for the markdown version against roughly 1.2MB of HTML circulated with that reporting, though we could not independently verify those exact byte counts and they should be read as reported, not confirmed. The precise numbers matter less than the architecture they illustrate: humans and Googlebot get one artifact, AI agents get another, and the sponsored content lives only in the second.
The subtler problem is what happens to a sponsored claim after an agent ingests it. Robert Webster, the former WPP executive who founded TAU, put it precisely in the same Digiday piece: “The intention may not be to deceive, but a promotional claim can end up cited as a neutral fact once the ‘sponsored’ label is left behind.” An answer engine that synthesizes a response does not carry the ad’s packaging with it. The label may exist at the point of placement and be absent at the point of consumption — which is where users actually form beliefs. Publishers deciding what AI crawlers can see now have to reason about that second-order path, not just the first-party page.
05 — ContextThe Perplexity paradox: the ad-quitter turned ad-cop.
There is a striking symmetry that no other coverage of this story has drawn out. The company now policing a publisher’s agent-facing ads is the same company that walked away from advertising on its own platform. Perplexity’s earlier retreat from advertising saw it stop accepting new advertisers on its own product in October 2025, after a nine-month tenure for its first ad-sales chief — a move eMarketer analyzed in February 2026 as marking a split in AI monetization models. Those are separate events on separate timelines from the Time block — but they share a stated principle: ads and answer-engine trust mix badly.
The trust evidence predates this fight. In the same February 2026 eMarketer piece — background context, not reaction to the markdown story — 63% of US adults said ads in AI search results reduce their trust in those results. Read against that number, Perplexity’s aggression makes commercial sense: its product is the credibility of its answers, and content engineered to sway those answers is a supply-chain attack on the thing it sells. The same eMarketer analysis sketched the diverging field as of February: Perplexity subscription-and-enterprise with no ads, OpenAI rolling out sponsored links in ChatGPT, Google testing ads in Gemini’s AI Mode, Anthropic staying ad-free as a stated differentiator. Where each platform sits on that spectrum predicts how it will treat agent-facing ads — a landscape we mapped in our comparison of how ChatGPT, Google, and Perplexity approach AI-search advertising.
The forward-looking read: platforms that sell ads themselves have a harder time drawing a bright line against publisher-side agent ads, while ad-free platforms can enforce purity cheaply. If that holds, expect the strictest enforcement from the platforms with the least ad revenue at stake — and expect advertisers to probe the platforms that blinked. U of Digital founder Shiv Gupta, quoted by Digiday, predicted other LLM providers may follow Perplexity’s blocking approach; at the time of writing, none had publicly done so.
06 — FrameworkThe agent-ad risk ladder: disclosure to deception.
Coverage of this story has been binary — Time did it, Perplexity blocked it. That flattens what is actually a spectrum. The ladder below arranges five agent-facing tactics from most disclosed to most deceptive, scoring each on three dimensions the dispute has surfaced: whether humans can see the content, whether a sponsor label is present, and which precedent — cloaking, deceptive advertising, or neither — it most resembles. The final column reasons from Perplexity’s stated position in Dwyer’s quotes to Digiday; it is our inference, not a confirmed Perplexity policy.
| Tactic | Human-visible? | Sponsor label? | Precedent risk | Likely Perplexity response* |
|---|---|---|---|---|
| Disclosed territory — both audiences see the same thing | ||||
| Sponsored content labeled in both HTML and markdown | Yes — identical content both surfaces | Yes, on both renditions | Neither — standard native advertising with symmetric disclosure | No stated objection — the asymmetry Perplexity called deceptive is absent |
| llms.txt-declared paid placements | Discoverable — declared in a public machine-readable file | Yes, by file format | No precedent yet — disclosure-by-spec is untested | Unknown — no platform has stated a position on declared placements |
| Asymmetric territory — agents see what humans cannot | ||||
| Sponsored FAQ blocks only in markdown (Time’s approach) | No — absent from the human HTML page | Not established — the reporting does not say; if unlabeled, this rung collapses into the one below | Cloaking analogue — different content per audience | Blocked — this is the documented case, per Digiday |
| Markdown-only promotional claims, no sponsor label | No | No | Cloaking and deceptive advertising — both precedents apply | Block plus trust-score downgrade — the scenario Dwyer’s warning describes most directly |
| Fully separate agent-only pages, no human equivalent | No — no human-facing counterpart exists | Varies | Strongest cloaking shape — an entire audience-specific shadow site | Likely blocked on sight if detected — inferred, no documented case yet |
* The response column is our reasoning from Perplexity’s spokesperson statements to Digiday — “deceptive practices, sponsored or not” and the trust-score warning — not a published Perplexity policy, which does not exist at the time of writing. The pattern in the ladder is the useful part: risk does not track the presence of a label, it tracks the size of the gap between what humans and agents are shown. Time’s approach sits in the asymmetric half however it is labeled — which is exactly the work Dwyer’s “sponsored or not” clause is doing.
07 — PlaybookWhat publishers and advertisers should actually do.
The honest state of the evidence: one publisher ran the experiment, one platform blocked it, no revenue figures exist in either direction, and the vendor’s own performance claims are soft — Mobian’s Goodhart described industry response as “extremely positive” to Digiday while declining to provide metrics supporting that characterization. Against that backdrop, the decision framework matters more than any individual data point. Our broader agentic advertising playbook covers the ad-ops mechanics; here is the position-taking.
Symmetric disclosure only
If you monetize agent traffic, keep sponsored content identical and labeled across HTML and markdown. You give up the stealth premium — and keep your standing in every AI index that follows Perplexity's lead.
Asymmetric markdown ads
Time's path. The inventory logic is real, but you are betting your trust score in indexes you cannot audit, on a tactic one platform has already called deceptive. Price that risk before the first insertion order.
Declared placements
Disclosure-by-spec — declaring paid agent-facing placements in a machine-readable file such as llms.txt — is untested but structurally symmetric. Whoever formalizes it first shapes the norm the platforms react to.
Demand delivery evidence
Visibility, favorability, and accuracy scores are vendor-defined with no independent audit. Ask how placements survive synthesis — Webster's warning that claims get cited as neutral fact cuts both ways when the claim is wrong.
Projecting forward: the likeliest equilibrium is not that agent-facing ads die, but that they bifurcate. Symmetric, labeled placements become a boring, legitimate line item — an extension of native advertising into a new rendering layer. Asymmetric placements get treated the way cloaking always has been: a detectable violation with index-level penalties, enforced most aggressively by the platforms whose business model depends on answer credibility. The open question is speed. Digiday’s reporting has one speculative marker on each side — Gupta predicting other LLM providers follow the block, and OpenAds.AI co-founder Steven Liss speculating Perplexity could go further and have its agents exclude Time’s advertising entirely. Neither had happened at the time of writing.
For brands, the practical takeaway is that influence over AI answers is increasingly earned through content that survives symmetric scrutiny — structured, factual, verifiable material that you would happily show a human. That is the core of the agentic SEO work we do: making brands visible to answer engines without the cloaking risk. And for teams weighing paid placements in AI surfaces as the platforms formalize them, our paid media practice treats agent-facing inventory the way the risk ladder does — an emerging channel to test with disclosure symmetry as the non-negotiable.
08 — ConclusionThe opening skirmish of a much longer war.
The dividing line is symmetry, not sponsorship.
The Time-Perplexity fight is small in scale — one publisher, one platform, one blocked ad format — and large in what it settles first. Per Digiday’s reporting, the first publicly reported enforcement action of the agent-ad era did not turn on whether the ads carried a sponsor label; it turned on asymmetry. Disclosure inside a layer humans never render would not have counted as disclosure. That is the precedent every publisher eyeing bot traffic as inventory now has to reason from.
Hold the epistemics honestly, too. This entire story rests on one outlet’s original reporting, spokesperson quotes, and vendor-stated traffic and performance claims — with no Perplexity policy document, no Time comment on the block, and no independent audit of any number involved. Analysis built on it should say so, the way this one has. What is verifiable is the architecture: the markdown layer exists, the sponsored content sits only there, and one answer engine decided that gap was deception.
The deeper signal is that AI platforms are becoming ad regulators whether they want the job or not. Every answer engine that synthesizes content into responses now has to decide what commercial influence it tolerates in its inputs — and its users’ trust rides on the answer. Publishers and advertisers who build for symmetric scrutiny will find that regime boring in the best way. Those who build for the gap between what humans and agents can see are betting that the referees stay slower than the tactic. August 11 looks like the first evidence they will not.