BlogFindings

Cloudflare's agent readiness score names four check groups and counts three

Cloudflare announced Agent Readiness diagnostics and an Answer Engine Optimization tab on 6 August 2026. The post sorts its site checks into quick wins, technical groundwork, advanced integration and commerce, and states that the commerce group is informational for now and not counted in your score.

15 min read Lantad

Lantad measured none of what follows. We have not run the diagnostics against a hostname, we hold no access to the AEO early access programme, and we have no figure for what it scores any site. What this post does is read the announcement closely, because two of its design decisions are stated plainly in the text and both change how a reader should interpret a number that comes out of it. The first is that one of the four groups of checks is left out of the score on purpose. The second is that the AEO metrics are computed against a category benchmark run once and reused, rather than against model queries issued at the moment you press scan. Neither is a defect. Both are the kind of thing answer engine optimization dashboards usually leave a buyer to work out, and Cloudflare wrote them down.

In short

  • Cloudflare published From ranking to recommended on 6 August 2026, announcing Agent Readiness diagnostics and an Answer Engine Optimization tab in its dashboard, and the post states that by Cloudflare's count fewer than half of all HTML page requests now come from a human.
  • Cloudflare's Agent Readiness diagnostics sorts its checks into four named groups, quick wins, technical groundwork, advanced integration and commerce, and the announcement states that the commerce group, covering x402, ACP, UCP and AP2, is informational for now and not counted in your score.
  • Cloudflare's AEO metrics are scored against a per-category benchmark that the announcement says is run once per category and reused across all accounts in that category, so a scan reads a stored snapshot rather than issuing live model queries.
  • Cloudflare's AEO tab probes what the 6 August 2026 post calls the leading assistants, named there as Anthropic's Claude and OpenAI's GPT, with the word today marking that list as current rather than settled.
  • Lantad has not run Cloudflare's Agent Readiness diagnostics, holds no access to the AEO early access programme, and measured none of the figures above. Every statement here is read from the two Cloudflare pages named and dated in this post.
The order Cloudflare's post of 6 August 2026 describes for its Agent Readiness diagnostics, drawn from its own sentence about what the scan does. Reported from that post, not run by Lantad.

What Cloudflare announced on 6 August 2026

The post opens on a claim about who is actually requesting pages. Cloudflare writes that by our count, fewer than half of all HTML page requests now come from a human, and immediately qualifies it: not all of those machines are agents acting for a person. That qualification is worth keeping, because the gap between a bot request and an agent acting for a buyer is where most of the confusion in this category lives.

It also says where the products came from. Cloudflare describes talking to site owners who were staring at access logs full of AI bots and could not tell whether those bots were capable of using the site, and reports hearing two questions: can agents actually use my site, and am I getting recommended. Diagnostics answers the first. The AEO tab answers the second.

Diagnostics is described as the technical checkup within Agent Readiness. In Cloudflare's words it scans your site the way an agent reads it: it works out whether it is allowed in and whether it can discover your content, fetches a clean machine-readable copy, and finds the interfaces it can call. It runs those checks against a hostname and rolls the results into a single agent-readiness view, from Not Ready to fully agent-native.

Two details in that description are better than the category norm and deserve saying so. Every check comes back as pass, fail or neutral, which means a check that could not be run is visually distinct from a check that failed. And each one carries what the post calls an evidence trail showing the exact request and response we saw. A verdict you can open and inspect is a different object from a verdict you have to trust, and this is the same standard we hold our own AI visibility output to. The full description is in Cloudflare's announcement, published the same week it opened a developer preview that puts a WebMCP interface on any site it fronts.

  • Can agents actually use my site? Diagnostics Runs checks against a hostname and returns a single agent-readiness view, from Not Ready to fully agent-native, with each check marked pass, fail or neutral.
  • Am I getting recommended? AEO tab Probes assistants with likely customer prompts in your inferred category and reports citation rate, prominence, mention rate and share of voice.
  • Who is actually requesting my pages? AI Operator Activity Shows crawl and referral traffic per operator, plus the errors they hit, which the post says is possible because the requests pass through Cloudflare.
  • What does any of it score my site? Not measured here Lantad has not run the diagnostics and holds no result from it. Nothing in this post is a Lantad measurement of Cloudflare's product.
The two questions Cloudflare says it heard from site owners, and which of the two tools it says answers each. Quoted from the post of 6 August 2026.

Which agent readiness checks count toward the score

The checks are grouped by effort, and the post names all four groups with their contents. Quick wins holds a crawler-readable robots.txt, an XML sitemap, AI-crawler rules, and serving clean Markdown to agents. Technical groundwork holds Content Signals that state how your content may be used, an API catalog, link headers, and agent login instructions. Advanced integration holds OAuth discovery, MCP and A2A agent cards, a skills index, Web Bot Auth, and WebMCP. Commerce holds x402, described in the post as an extension of the classic HTTP 402 Payment Required status code, along with ACP, the Universal Commerce Protocol and AP2.

Then one sentence, attached to the commerce group only: this is informational for now, and not counted in your score. That is the finding, and it is Cloudflare's own disclosure rather than something anyone had to dig out. Four groups are displayed. Three are scored.

The reasoning is not stated, but the shape of the decision is legible. Cloudflare introduces that group as the emerging agent-payment standards, and a score that penalised every site on the web for not implementing an emerging standard would say more about the calendar than about the site. Marking them informational keeps the checks visible without letting adoption timing drag a number. The status code underneath x402 is one we have written about before, when pay per crawl priced AI crawlers with a code the specification leaves undefined, and the same caution belongs anywhere a score turns on how new a standard is.

The practical consequence for a reader is about what a single agent-readiness figure is made of. Strip the unscored group and what remains is dominated by things a client can observe without executing anything: a robots.txt it can parse, a sitemap it can fetch, a Markdown copy it can request, headers it can read, and metadata sitting at known paths. Two of those we have covered directly, because Cloudflare's Content Signals line asks while the Disallow lines under it block, and the machine copy of a page is not always the same document as the human one, which is what happened when a publisher began selling sponsored blocks inside the markdown AI crawlers read.

GroupWhat the post lists in itCounted in the score
Quick winsCrawler-readable robots.txt, XML sitemap, AI-crawler rules, clean Markdown for agentsYes
Technical groundworkContent Signals, API catalog, link headers, agent login instructionsYes
Advanced integrationOAuth discovery, MCP and A2A agent cards, skills index, Web Bot Auth, WebMCPYes
Commercex402, ACP, Universal Commerce Protocol, AP2No, informational for now
The four check groups named in Cloudflare's post of 6 August 2026, their listed contents, and whether the post says they count toward the score. Compiled from that post on 7 August 2026.

Where the AEO numbers come from

The AEO tab works differently from the diagnostics, and the post explains the pipeline rather than presenting the output as an oracle. Cloudflare says it infers your industry and category from your site, giving health and fitness as an industry and sports apparel as a category, then probes the leading assistants with likely customer prompts. The assistants named are Anthropic's Claude and OpenAI's GPT, prefixed with the word today, which reads as a statement about the current list rather than a final one.

The part that decides how to read the numbers is the benchmark. Cloudflare builds a panel per industry and category before scoring any specific site, querying assistants with likely prompts in that category without naming your brand, and recording which sites are cited, where they appear and how prominently. Then, in its own words, rather than re-querying models every time a site owner runs a scan, we run this panel once per category and reuse the baseline across all accounts in that domain. The first benefit it lists is zero latency: results load instantly from a snapshot rather than waiting for live model queries.

That is a real engineering trade and both sides of it are worth naming. Reusing one panel makes two sites in the same category directly comparable, because they were scored against the same corpus of answers rather than against two separate rolls of a non-deterministic system. It also means the recency of your number is the recency of the panel, and the announcement does not state how often a panel is re-scored. If you change your site and re-scan, what moves is your position against a stored baseline.

Cloudflare does address variance within the panel. It states that assistants rarely answer the same question the exact same way twice, and that it uses AI Gateway to prompt each assistant multiple times across different models. Repeated sampling is the right response to that, and it is the same reason we read a paper on how many prompts an AI visibility measurement needs before shipping our own tracked prompt sets. One further line is unusually specific for a launch post: we also use exact text analysis rather than a model grading its own output. Self-judging pipelines are common in this category and rarely disclosed, so saying it in the announcement is worth noting.

The AEO scoring pipeline as described in Cloudflare's post of 6 August 2026, including the reuse of one panel per category. Reported from that post, not observed by Lantad.

What a citation rate is a share of

We published four questions on 28 July 2026 for judging any product in this category, our own included, under a single framing test: whether each number tells you its denominator. Applying it to a launch post is a fair test, because a launch post is where a vendor decides what to say plainly and what to leave for the documentation. On this one, three of the four AEO metrics carry their denominator in the sentence that defines them.

Citation Rate is defined as the share of answers in your category that cite your site as a source. That names the denominator outright: answers in the category panel, not queries a human typed, not impressions, not traffic. Share of Voice is defined as your slice of citations against those for your competitors, which again says what the total is. Mention Rate is how often assistants name your brand in the answer, and Cloudflare draws the distinction we would draw, that read alongside citation rate it separates awareness from attribution.

Prominence is the one defined without a unit. The post says it captures how much of the answer is actually yours and how early it lands, which is two quantities described in words rather than one measure with a stated scale. That may well be resolved in the product documentation, and this is a blog post rather than a spec, so the observation is narrow: as announced on 6 August 2026, prominence is described but not dimensioned.

The distinction the metric set is reaching for is a real one and it is under-served across the whole category. Being selected as a citation and having your sentences reach the answer text are separate events that dashboards routinely collapse into one number, which is the argument in the measurement framework we read where more AI citations did not mean more of your page in the answer. Any product that splits mention from citation, and citation from influence, is measuring three things that genuinely differ, and our own position on what a share figure is a share of has been that stating the basis in the report matters more than the number itself.

MetricDefinition given in the postDenominator named
Citation RateThe share of answers in your category that cite your site as a sourceYes, answers in the category
Share of VoiceYour slice of citations against those for your competitorsYes, competitor citations
Mention RateHow often assistants name your brand in their answerYes, read against citation rate
ProminenceHow much of the answer is actually yours and how early it landsNo unit stated in the post
The four AEO metrics as defined in Cloudflare's post of 6 August 2026, and the denominator each definition names. Read from that post on 7 August 2026.

What a network can measure that an outside scanner cannot

One claim in the post is straightforwardly true and cannot be matched from outside: because the requests actually pass through Cloudflare, these tools measure rather than estimate where possible. The AI Operator Activity panel is the example. It reports real crawl and referral traffic per operator, who reads your content, who sends visitors back, and the errors they hit on the way, naming 403 blocked and 404 dead link. No external scanner can produce that, because the data is your server logs. The pattern Cloudflare points at, the operator that crawls thousands of your pages but refers no one, is only visible to something sitting in the request path.

The same position shows up in the Radar API. Cloudflare documents an endpoint at /radar/agent_readiness/summary/{dimension}, and its response schema for agent readiness summaries carries both totalDomains, described as total domains attempted in the scan, and successfulDomains, described as domains successfully scanned excluding errors, alongside a date field for the scan the figures came from. Publishing the attempted count and the successful count separately is publishing the denominator and the attrition, which is more than most population figures in this field come with.

What a network cannot do is scan a site that is not behind it. That is the honest division rather than a competitive point. An outside scanner can be pointed at any hostname, including a competitor's, without that site's consent or cooperation, which is what fetching a page as a named crawler and reading the response does. A network tool sees the truth about traffic but only for its own customers. Each answers a question the other cannot.

One boundary is worth stating precisely rather than implying. The AEO panel probes two vendors' assistants as of 6 August 2026. Our own registry covers nine vendors, but that is a registry of crawler tokens rather than of assistants, and we said as much when six of the nine vendors we track published exactly one crawler token. Those are different populations and comparing the counts directly would be a category error, which is also why our research page says what its sample is before it says what it found.

Sitting in the request path

  • Real crawl and referral traffic per operator
  • The 403 and 404 responses operators actually received
  • Population summaries with attempted and successful domain counts
  • Limited to hostnames served by that network

Fetching from outside

  • Any hostname, with no cooperation from the site
  • What a named crawler receives in the response body
  • The same comparison run against a competitor
  • No visibility into who actually requested the page
Which questions each vantage point can answer, from the capabilities each describes in its own documentation. A division of labour, not a comparison of results.

What to check on your own site first

None of this changes the order the checks run in, and the order is the part a site owner can act on today without waiting for early access to anything.

Permission comes first, because nothing below it matters until it passes. RFC 9309 fixes the robots exclusion file at /robots.txt and specifies how a group is matched to a crawler name, which is why a rule can be present, correct in syntax and still apply to nobody. Reading your own file the way a named crawler reads it is a two minute job with a robots.txt tester and it is the check most often skipped.

Then the text. Whether the words are in the served HTML, rather than assembled afterwards by a script, is the single quantity underneath almost every question anyone asks in this field, and it is what prose parity measures. Cloudflare's quick wins group puts a clean machine-readable copy in the same tier for the same reason: a client that will not run your scripts needs the sentences to be in the response. We publish a markdown twin of every page on this site on that principle rather than as a feature.

Only after those two does an agent interface earn attention. It is third in the order and it is never a substitute for the first two, because a tool surface on a page a fetch-only client reads as empty is a second storey on an empty first one.

A closing note on our own numbers, since this post has spent its length reading someone else's. Lantad's AI Visibility Score puts 50 of its 100 points on parity, 25 on access and the remaining 25 on structure and schema. Those are configured weights, which makes them a decision somebody made rather than a finding anybody measured, and what our method does and does not do says so before it says anything else. The same question we asked of Cloudflare's citation rate applies here, and we asked it of ourselves first.

  • Is the client permitted to fetch at all Per-crawler robots.txt matching under RFC 9309, plus whatever your CDN decides before the request reaches your origin. Nothing below this matters until it passes.
  • Is the text present in the served response Fetch without a browser and read the body. This is prose parity, and it is what a retrieval client quotes from when it quotes you.
  • Is there a clean machine-readable copy A Markdown or equivalent representation a client can request directly. Cloudflare files this under quick wins for the same reason we publish one.
  • Does the page expose callable agent interfaces MCP, agent cards, WebMCP and the payment protocols. Third in the order, and in Cloudflare's own scoring the commerce part of it is not counted at all.
The order these checks run in, and where an agent interface sits within it. A sequence, not a score.

Written by

Lantad

Published .

Cloudflare announced two dashboard tools on 6 August 2026. Agent Readiness diagnostics checks whether an agent can get into your site and read it. An Answer Engine Optimization tab reports whether assistants name you when a customer asks a question in your category. The post is titled From ranking to recommended, it is credited to Matthew Conroy and Jack Galilee, and it is the most detailed public account so far of what a large network thinks an AI crawler needs from a page.

Common questions

Does Cloudflare's agent readiness score include the commerce checks?

No. Cloudflare's post of 6 August 2026 lists commerce as one of four check groups, covering x402, ACP, the Universal Commerce Protocol and AP2, and states directly that this is informational for now, and not counted in your score. The other three groups, quick wins, technical groundwork and advanced integration, are the ones the single agent-readiness view is built from.

Which AI assistants does Cloudflare's AEO tool query?

As announced on 6 August 2026, the post names Anthropic's Claude and OpenAI's GPT, introduced with the word today, which marks the list as current rather than settled. It also states that Cloudflare uses AI Gateway to prompt each assistant multiple times across different models, because assistants rarely answer the same question the exact same way twice.

Are AEO results based on live model queries when you run a scan?

Not according to the announcement. Cloudflare states that rather than re-querying models every time a site owner runs a scan, it runs one panel per category and reuses that baseline across all accounts in that category, and lists zero latency as the first benefit because results load from a snapshot rather than waiting for live model queries. The post does not state how often a panel is re-scored.

Has Lantad tested Cloudflare's Agent Readiness or AEO tools?

No. Lantad has not run the diagnostics against a hostname, holds no access to the AEO early access programme, and has taken no measurement of either product. Everything in this post is read from Cloudflare's announcement of 6 August 2026 and its Radar API reference for agent readiness summaries, both read on 7 August 2026.

See what AI can read on your site

Run a free scan and get a graded report of exactly what AI crawlers can and cannot read, with ranked fixes.