An AI visibility audit investigates whether AI systems can retrieve, understand and potentially use information about an organisation. That sounds simple, but it contains three separate questions—and each requires different evidence.
The first question is technical: can the relevant systems reach the website and retrieve usable content? The second concerns meaning and authority: can they identify the organisation and support its claims? The third concerns selection: does a particular answer system choose to mention or cite it for a particular prompt?
The crucial distinction: passing a technical access audit does not guarantee an AI mention. It removes or identifies one class of barrier. It does not prove authority, relevance or future answer selection.
The three layers of AI visibility
A useful audit says which layer it measures. A weak one collapses all three into a single percentage and leaves the buyer unable to tell whether a low result came from a firewall, thin evidence, an ambiguous entity or one volatile prompt.
What a technical AI visibility audit checks
Declared crawler policy
A robots.txt file can state different rules for different user-agent tokens. Those distinctions matter. OpenAI’s official crawler documentation, for example, describes OAI-SearchBot and GPTBot as independent controls: one relates to ChatGPT search visibility and the other to training use. Treating every AI-related identity as one generic “AI bot” can lead to the wrong recommendation.
Observed access
Published policy is not the same as delivered access. A website can permit retrieval in robots.txt while its CDN, firewall or security layer returns a challenge page or denial. A defensible audit records policy and live observations as separate evidence classes.
Identity and purpose
Crawlers, special-purpose clients and user-triggered fetchers should not automatically be grouped together. Google’s crawler documentation explicitly distinguishes common crawlers, special-case crawlers and user-triggered fetchers. Google-Extended is also described as a product token controlling certain content uses, not as a conventional crawler that independently fetches pages.
Machine-readable delivery
The review should consider redirects, status codes, response headers, canonical signals, sitemap availability and whether meaningful content appears in the response. Optional conventions such as llms.txt may be observed, but absence alone should not be presented as a technical failure.
What the customer report should contain
| Section | What good evidence looks like |
|---|---|
| Scope | Exact origin, paths, date, identities and limitations tested. |
| Declared policy | Identity-by-identity outcomes supported by the relevant robots.txt lines. |
| Observed access | Status, headers and response classification reported separately from policy. |
| Assessment limits | A clear statement of what the test cannot prove. |
| Remediation | Prioritised, developer-ready changes tied to confirmed findings. |
| Human review | A check for misleading templates, challenge pages, false assumptions and inconsistent signals. |
The output should also tell the customer what not to change. Blocking training-associated use may be an intentional policy choice; it should not be automatically labelled an error merely because another organisation chooses differently.
Questions to ask before buying
- Does the provider distinguish access, authority and answer selection?
- Are crawler identities graded individually and by purpose?
- Does the report show exact evidence, not only a score?
- Are live observations made with an honestly identified crawler?
- Will a human review the findings?
- Are fixes specific enough for a developer to implement?
- Does the provider state what the audit cannot guarantee?
Which Digital Dominator audit fits?
The AI Access Check is designed for a single organisation that needs an evidence-backed verdict on declared policy, basic site guidance and the response observed by Digital Dominator’s identified audit crawler. The Full AI Access Audit adds deeper CDN, WAF, edge, redirect, TLS, response and challenge analysis, plus expanded remediation, a walkthrough and a free post-fix re-check.
Both are specialist technical diagnostics. Neither is presented as a complete measure of brand authority, competitor performance or prompt-by-prompt visibility.
Start with evidence
Australian prices include GST. Every paid report is human-reviewed and delivered within five business days.
Sources and further reading
OpenAI: Overview of OpenAI crawlers
Google: Overview of crawlers and fetchers
Google: Common crawlers and Google-Extended
How to audit brand visibility across AI systems
Digital Dominator: AI Visibility Audit Australia
Digital Dominator: AI Website Audit Australia