Australian buyer’s guide · AI visibility

What is an AI visibility audit?

The phrase now describes everything from a free prompt check to a detailed technical investigation. This guide explains the layers, the evidence a buyer should expect and the claims no credible provider should make.

Douglas Lord6 September 20268-minute guide

An AI visibility audit investigates whether AI systems can retrieve, understand and potentially use information about an organisation. That sounds simple, but it contains three separate questions—and each requires different evidence.

The first question is technical: can the relevant systems reach the website and retrieve usable content? The second concerns meaning and authority: can they identify the organisation and support its claims? The third concerns selection: does a particular answer system choose to mention or cite it for a particular prompt?

The crucial distinction: passing a technical access audit does not guarantee an AI mention. It removes or identifies one class of barrier. It does not prove authority, relevance or future answer selection.

The three layers of AI visibility

1. Access and retrievalrobots.txt policy, crawler identities, HTTP responses, redirects, sitemaps, CDN/WAF challenges and machine-readable content.
2. Understanding and authorityentity clarity, structured data, corroborating sources, reputation, relevance and consistency across the wider web.
3. Answer selectionWhether a particular engine mentions, cites or recommends the organisation for a defined prompt, location and point in time.

A useful audit says which layer it measures. A weak one collapses all three into a single percentage and leaves the buyer unable to tell whether a low result came from a firewall, thin evidence, an ambiguous entity or one volatile prompt.

What a technical AI visibility audit checks

Declared crawler policy

A robots.txt file can state different rules for different user-agent tokens. Those distinctions matter. OpenAI’s official crawler documentation, for example, describes OAI-SearchBot and GPTBot as independent controls: one relates to ChatGPT search visibility and the other to training use. Treating every AI-related identity as one generic “AI bot” can lead to the wrong recommendation.

Observed access

Published policy is not the same as delivered access. A website can permit retrieval in robots.txt while its CDN, firewall or security layer returns a challenge page or denial. A defensible audit records policy and live observations as separate evidence classes.

Identity and purpose

Crawlers, special-purpose clients and user-triggered fetchers should not automatically be grouped together. Google’s crawler documentation explicitly distinguishes common crawlers, special-case crawlers and user-triggered fetchers. Google-Extended is also described as a product token controlling certain content uses, not as a conventional crawler that independently fetches pages.

Machine-readable delivery

The review should consider redirects, status codes, response headers, canonical signals, sitemap availability and whether meaningful content appears in the response. Optional conventions such as llms.txt may be observed, but absence alone should not be presented as a technical failure.

What the customer report should contain

SectionWhat good evidence looks like
ScopeExact origin, paths, date, identities and limitations tested.
Declared policyIdentity-by-identity outcomes supported by the relevant robots.txt lines.
Observed accessStatus, headers and response classification reported separately from policy.
Assessment limitsA clear statement of what the test cannot prove.
RemediationPrioritised, developer-ready changes tied to confirmed findings.
Human reviewA check for misleading templates, challenge pages, false assumptions and inconsistent signals.

The output should also tell the customer what not to change. Blocking training-associated use may be an intentional policy choice; it should not be automatically labelled an error merely because another organisation chooses differently.

Questions to ask before buying

Which Digital Dominator audit fits?

The AI Access Check is designed for a single organisation that needs an evidence-backed verdict on declared policy, basic site guidance and the response observed by Digital Dominator’s identified audit crawler. The Full AI Access Audit adds deeper CDN, WAF, edge, redirect, TLS, response and challenge analysis, plus expanded remediation, a walkthrough and a free post-fix re-check.

Both are specialist technical diagnostics. Neither is presented as a complete measure of brand authority, competitor performance or prompt-by-prompt visibility.

Start with evidence

Australian prices include GST. Every paid report is human-reviewed and delivered within five business days.

Sources and further reading

OpenAI: Overview of OpenAI crawlers
Google: Overview of crawlers and fetchers
Google: Common crawlers and Google-Extended
How to audit brand visibility across AI systems
Digital Dominator: AI Visibility Audit Australia
Digital Dominator: AI Website Audit Australia