The Agentic SEO Revolution: How Websites Win AI Agent Traffic
Schema for Machines: The New SEO of the Agentic Internet
The next discovery contest will not end at ranking a blue link. Websites will compete to be understood, trusted, selected and transacted with by software agents. Winning requires a machine-readable operating surface, not another layer of keyword copy.
Updated September 23, 2026 | 17-minute read | Includes the DN Agent Selection Optimization Grader
What Matters
Direct answer: Websites will not win the agentic internet through keywords or schema alone. They must expose accurate facts, discoverable capabilities, verifiable identity, bounded actions and measurable outcomes. DN recommends treating Agent Selection Optimization as a layer beside SEO, while recognizing that no manifest, markup format or optimization can guarantee citation or agent selection.
From ranking to selection
Traditional SEO helps a page become discoverable. Agent Selection Optimization, or ASO, helps an agent determine what a site offers, whether it is trustworthy, how to invoke it and what will happen next.
No single file solves it
Schema.org, sitemaps, crawler controls, llms.txt, ARD catalogs, A2A Agent Cards, MCP endpoints and WebMCP tools solve different parts of the machine-consumption problem.
Evidence beats metadata
Any publisher can declare that it is authoritative. Durable selection depends on verified identity, current prices, explicit permissions, reliable execution and observable outcome history.
DN Evidence Block
Research owner: Decentralised News Research Desk. Method: documentation-level assessment of Schema.org and Google structured-data guidance, OpenAI crawler controls, llms.txt, ARD, A2A Agent Cards, MCP and WebMCP. This is not a live cross-client ranking experiment.
- Structured data clarifies entities and can enable supported search features, but does not guarantee ranking, citation or display.
- ARD adds federated discovery for capabilities including MCP servers, A2A agents, skills, APIs and workflows.
- A2A Agent Cards describe identity, endpoints, skills and authentication; signed cards strengthen origin and integrity checks.
- MCP exposes structured tools and resources, while WebMCP brings structured tool invocation into browser experiences.
- Cryptographic authenticity does not establish competence, safety, commercial fairness or successful task outcomes.
Read the methodology and limitations · Review the primary sources
SEO Is Not Dead. Its Unit of Competition Is Expanding
Search optimization traditionally asks whether a crawler can discover a page, understand its subject and judge it useful enough to rank. AI search adds a citation question: can a system extract a clear, supportable answer and attribute it to the source? Agentic systems add a third challenge: can software safely act on what the publisher exposes?
A travel page may rank for “best hotel in Cape Town.” An answer engine may cite its comparison. An agent, however, needs much more before it books: live availability, total price, cancellation rules, identity, an authenticated action, user authorization and a receipt. Content becomes operational.
DN calls the resulting discipline Agent Selection Optimization. ASO is the practice of making a resource accurately discoverable, interpretable, comparable, callable and verifiable by agents while preserving user control. It does not replace SEO, accessibility, APIs or security. It coordinates them.
The Five-Layer Agent-Ready Website
| Layer | Agent question | Core mechanisms | Failure when absent |
|---|---|---|---|
| Human experience | Can a person inspect and control this? | Clear pages, accessible forms, policies, confirmations | Automation becomes opaque or inaccessible |
| Knowledge | What is this entity, offer or claim? | Semantic HTML, Schema.org JSON-LD, canonical URLs, feeds, sitemaps, concise source-backed copy | The agent misclassifies or cannot cite the resource |
| Capability | What can I do and how? | ARD ai-catalog.json, A2A Agent Cards, MCP tools/resources, WebMCP, OpenAPI | The agent can read but cannot reliably act |
| Trust | Who published this and is it safe? | Domain anchoring, signed metadata, authorization scopes, provenance, policies, status and incident history | Spoofing, stale metadata or excessive permissions |
| Transaction | What will it cost, and what proves completion? | Machine-readable offers, payment challenges, mandates, receipts, fulfillment evidence, refunds | Selection cannot become accountable commerce |
The Machine-Readability Stack, Without the Hype
1. Semantic HTML and Schema.org describe meaning
Schema.org vocabulary and JSON-LD can describe organizations, people, articles, datasets, products, offers, software and actions. Google says structured data provides explicit clues about page meaning and can make pages eligible for supported rich results. Eligibility is not a ranking or display guarantee, and Google's supported search features cover only part of the wider Schema.org vocabulary.
For agents, structured data is valuable because it reduces extraction ambiguity. A visible product price and a matching Offer object are easier to compare than a promotional sentence buried in a page. But structured data must match visible reality. Contradictory prices, fabricated ratings or stale availability make the site less trustworthy, not more agent-ready.
2. Crawler policy controls access
robots.txt, indexing directives and bot-specific controls answer whether automated systems may access a resource. OpenAI documents separate controls for OAI-SearchBot and GPTBot, allowing publishers to distinguish search visibility from potential model-training use. These are permission signals, not descriptions of the site's capabilities.
3. llms.txt offers orientation, not universal ranking power
The llms.txt proposal gives a site a concise Markdown overview and selected links for language-model use. Its 2026 revision recommends link relations that point to page-level Markdown and the applicable overview. It is an emerging convention rather than a universal, formally enforced ranking standard. Publishers should use it to reduce navigation cost, not claim guaranteed AI visibility.
4. ARD and ai-catalog.json publish discoverable capabilities
Agentic Resource Discovery, announced in 2026, defines a federated way to publish and search agentic resources. Its catalog can describe MCP servers, A2A agents, skills, APIs and workflows. Representative queries and capability metadata help registries match human intent to a resource. Domain-anchored identifiers and trust manifests make the discovery record more useful than a directory description alone.
ARD is strategically important because it moves discovery away from a single marketplace. A publisher can expose a catalog at its own domain, permit registries to index it and update one source of truth. The open question is adoption: specifications earn authority through interoperable clients, registry coverage and production use, not announcement logos.
5. A2A Agent Cards describe remote agents
The A2A specification requires an Agent Card describing identity, service endpoint, capabilities, skills and authentication requirements. Version 1.0 adds signed Agent Cards, which can cryptographically verify identity and metadata before interaction. Cards make agents legible to other agents, but a valid signature proves origin and integrity, not competence or honest outcomes.
6. MCP exposes tools and resources
MCP servers can expose callable tools, contextual resources and reusable prompts. The current specification includes authorization for restricted HTTP servers and security guidance. MCP makes a capability invocable, but discoverability, reputation, payment and quality measurement still require adjacent layers.
7. WebMCP turns browser interfaces into tools
WebMCP is a W3C Community Group draft API through which a page can expose structured tools to browser agents. An imperative interface can register JavaScript-backed functions, while the declarative direction can derive tools from annotated forms. It promises more reliable interaction than pixel guessing and DOM improvisation. As a draft, its syntax and browser support may change, so production implementations need progressive enhancement and ordinary human controls.
The DN Agent Selection Funnel
DN editorial framework The stages and optimization guidance below are Decentralised News analysis. Protocol requirements and documented capabilities are identified separately in the source-backed sections above.
| Stage | Pass condition | Metric to record | Common optimization mistake |
|---|---|---|---|
| Discover | The agent or registry finds the resource | Valid crawl, registry inclusion, retrieval frequency | Publishing a manifest that nothing indexes |
| Understand | The agent identifies entity, offer and constraints | Extraction accuracy and field completeness | Adding markup that contradicts the page |
| Shortlist | The resource fits task, policy and budget | Qualified selection rate | Optimizing raw mentions instead of suitable matches |
| Trust | Identity, provenance and permissions verify | Signature validity, freshness, incident record | Treating self-asserted metadata as evidence |
| Invoke | The tool accepts a valid request safely | Success rate, latency, permission denials | Giving broad scopes to reduce friction |
| Transact | Price, authority and settlement align | Total cost, mandate match, duplicate rate | Showing a price without binding it to fulfillment |
| Verify | The promised result is delivered | Completion quality, refund and dispute outcomes | Counting payment success as task success |
The DN Agent Selection Optimization Index
The DN-ASOI is a 100-point framework for evaluating whether a site can be selected and used by agents under controlled conditions. It measures evidence available at the tested URL and associated endpoints. It does not claim that any AI provider will rank or choose the site.
| Dimension | Weight | Evidence required |
|---|---|---|
| Access and control | 10 | Intentional crawler rules, indexability, sitemap and stable canonical URLs |
| Entity and content clarity | 15 | Visible facts aligned with semantic HTML and valid structured data |
| Capability discovery | 15 | Current machine-readable catalog, Agent Card or documented endpoint discoverable from the domain |
| Actionability | 15 | Typed tools or API operations with constraints, error behavior and safe human fallback |
| Identity and trust | 15 | Domain ownership, cryptographic verification where supported, provenance and security contact |
| Transaction readiness | 10 | Current price, authorization, total cost, receipt, cancellation and refund logic |
| Outcome evidence | 10 | Observed uptime, success, latency, quality and incident history |
| Governance and freshness | 10 | Last-verified dates, versioning, change log, deprecation policy and accountable owner |
Hard gates: “Callable” requires a documented structured action. “Verified” requires identity evidence beyond self-description. “Transaction-ready” requires explicit authority, price and recovery terms. A site failing a hard gate cannot earn that label regardless of its numeric score.
What would change the assessment: evidence of wider or weaker client adoption, a material specification revision, failed signature or authorization tests, stale catalogs, measured tool reliability, changed crawler policies, or proof that the published interface does not match production behavior.
DN Agent Selection Optimization Grader
Generate your readiness shortlist: score one production site or product surface using evidence you have personally verified. The article supplies the general framework; the grader converts your implementation choices into a prioritized readiness band.
Inputs: eight evidence categories. Output: a 0–100 readiness score, band and next action. Limitation: the result is a self-assessment and does not prove external ranking, security or commercial performance.
This grader assesses published evidence, not guaranteed ranking, selection, security or commercial performance.
A 90-Day Implementation Path
Days 1 to 30: make claims consistent
- Audit crawl rules, canonical URLs, status codes and sitemaps.
- Map organizations, authors, products, datasets and offers to appropriate structured data.
- Make prices, dates, limitations, disclosures and source provenance visible to humans.
- Separate search access, training preferences and authenticated private resources deliberately.
Days 31 to 60: publish the capability surface
- Create a concise
llms.txtwhere it genuinely improves orientation. - Publish an ARD-compatible
ai-catalog.jsonfor callable resources. - Expose A2A Agent Cards for agents, MCP server metadata for tools and OpenAPI where appropriate.
- Add WebMCP progressively to high-value forms or workflows, preserving human confirmation for consequential actions.
Days 61 to 90: prove trust and outcomes
- Add signed metadata where the governing protocol supports it.
- Enforce least-privilege authorization, explicit scopes and short-lived credentials.
- Measure qualified agent referrals, tool success, latency, total transaction cost, cancellations and refunds.
- Publish last-verified dates, version history, security contact and a machine-readable change feed.
What Publishers Should Measure
Pageviews alone cannot reveal whether agents create value. DN recommends a dual dashboard: conventional human discovery metrics alongside agent funnel metrics.
| Metric | Why it matters | Warning |
|---|---|---|
| Qualified agent referral rate | Shows whether machine discovery brings suitable tasks | User-agent identification is incomplete and spoofable |
| Citation-to-visit rate | Connects answer visibility to owned traffic | Not every platform exposes impression data |
| Discovery-to-invocation rate | Tests whether metadata describes a usable capability | A high rate can still represent abusive automation |
| Invocation success and correction rate | Measures functional reliability and misunderstood inputs | Success must be defined at the task level |
| Verified outcome per total cost | Measures buyer value after fees and retries | Cheap failure is not value |
| Permission-denial quality | Tests safe refusal and recovery | Reducing denials can weaken security |
The New Manipulation Surface
Agentic optimization will attract adversarial behavior. Capability stuffing can attach popular intents to irrelevant tools. Metadata can advertise a low price and return a different checkout. Prompt injection can hide in retrieved text. Signed manifests can faithfully authenticate a malicious publisher. Review farms can generate synthetic success signals.
This is why DN separates declaration, verification and performance. Declaration says what the publisher claims. Verification establishes identity, integrity and current configuration. Performance measures what happens during controlled use. No one layer should inherit trust from another.
Publishers should also avoid dark automation: defaulting to broad permissions, suppressing confirmation, hiding recurring charges or making cancellation harder for agents than purchase. The best agent experience is not maximum autonomy. It is the least friction compatible with informed user control.
The DN Opportunity: A Live Agent-Readiness Observatory
Decentralised News can turn this article into durable infrastructure by maintaining a versioned database of machine-readable web surfaces. The DN Agent-Readiness Observatory should test public URLs for structured-data validity, crawler accessibility, llms.txt, ARD catalogs, Agent Cards, MCP metadata, WebMCP exposure, signatures, freshness and transaction disclosures.
The defensible asset is not a one-time score. It is the longitudinal record: when a capability appeared, whether its identity verified, how often it succeeded, what it cost and how the publisher handled failures. Products can include free graders, verified profiles, alerts, datasets, an API, enterprise audits and clearly labelled sponsorships. Paid relationships must never alter scores, inclusion or conclusions.
What Would Prove the ASO Thesis Wrong?
The thesis would weaken if leading agents continued to rely mainly on visual browsing and private integrations while ignoring publisher-controlled structured interfaces. It would also weaken if closed platforms captured most agent transactions, if open discovery registries failed to gain coverage, or if structured tools produced no measurable improvement in task completion and user trust.
DN will watch four falsification signals: declining use of open manifests, weak cross-client interoperability, no relationship between readiness scores and successful outcomes, and publishers removing agent interfaces because abuse costs exceed commercial value.
Methodology, Limitations and Update Policy
Version 1.1, last verified September 23, 2026. DN-ASOI scores externally observable implementation evidence at a defined URL and time. Documentation establishes stated design. Validation tools establish syntax. Controlled calls establish limited operational behavior. None alone proves security, truthfulness or universal discoverability.
Scores must record the tested URL, protocol versions, evidence links and timestamp. Rescore after material catalog, schema, tool, authorization, payment, ownership or policy changes, and at least quarterly for active entries. Maintain a public change log and downloadable dataset when the sample becomes large enough for comparison.
Conflict policy: affiliate availability, sponsorship and commercial relationships never change a score, inclusion decision or conclusion. Any paid placement must be visually separated from the index.
Correction route: report a factual error, changed specification or broken source through the Decentralised News contact page. Material corrections should record the date, affected claim and evidence used.
Update Record
- Version 1.1, September 23, 2026: added the DN Evidence Block, explicit fact-versus-judgment labeling, action-gap guidance, static tool fallback, internal discovery links, measurement hooks, correction route and expanded freshness controls.
- Version 1.0, September 23, 2026: original publication framework and DN-ASOI methodology.
Continue Your Research
Frequently Asked Questions
What is Agent Selection Optimization?
ASO is DN's term for making a digital resource discoverable, understandable, callable, trustworthy and verifiable by AI agents while preserving human control.
Does ASO replace SEO?
No. SEO, accessible content and technical crawlability remain foundational. ASO adds capability, trust, transaction and outcome layers for systems that can act.
Will adding Schema.org markup guarantee AI citations?
No. Structured data can reduce ambiguity and may enable supported search features, but no honest publisher can guarantee ranking, citation or agent selection.
Is llms.txt an official web standard?
It is an emerging open proposal and convention, not a universal W3C or IETF requirement. Use it as an orientation aid and measure whether relevant clients consume it.
What is the difference between ARD and an A2A Agent Card?
ARD supports federated publication and discovery across many resource types. An A2A Agent Card describes one A2A server's identity, skills, endpoints and authentication.
What is the difference between MCP and WebMCP?
MCP connects AI applications to remote or local tools and resources. WebMCP is a draft browser API through which a webpage exposes structured tools to an in-browser agent.
Does a signed Agent Card prove an agent is safe?
No. A valid signature helps prove origin and integrity. It does not prove output quality, safe behavior or honest commercial terms.
What should a publisher implement first?
Fix crawlability, canonical URLs, visible factual clarity and structured-data consistency. Then add a capability interface only for workflows the publisher can secure, support and measure.
How can agent traffic be monetized?
Options include paid tools, metered data, outcome-based services, subscriptions, qualified leads, audits and API access. Pricing should be machine-readable and tied to authorization, receipts and recovery.
Can publishers allow AI search but block model training?
Some providers publish separate crawler controls. OpenAI, for example, documents OAI-SearchBot separately from GPTBot. Publishers should verify each provider's current policy rather than assume one rule applies universally.
Primary Sources and Standards
- Google Search Central: Introduction to structured data
- Google Search Central: AI features and your website
- Google: Search generative AI performance reports, June 3, 2026
- OpenAI: Overview of web crawlers
- The llms.txt proposal, version 2
- Google Developers Blog: Agentic Resource Discovery announcement
- ARD specification repository
- A2A Protocol specification
- A2A: Version 1.0 and signed Agent Cards
- Model Context Protocol: Tools
- Model Context Protocol: Resources
- WebMCP Community Group draft specification