AI visibility audit: a 7-step GEO audit you can run free

By David Quaid Published

An AI visibility audit, or GEO audit, is an SEO audit with one more layer on top: retrieval. It checks whether AI crawlers can get into your site, whether your pages are in the indexes ChatGPT, Claude and Gemini search, and whether you rank for the searches those assistants run, and you can do every step free.

There's no "AI readiness score" in here, because no AI company publishes one. I'll use nytimes.com as the worked example instead: it blocks almost every AI crawler by name, on purpose, which makes each gate easy to see.

What an AI visibility audit is

An AI visibility audit follows the path a page has to travel before an AI assistant can cite it.

When a prompt needs current information, the assistant rewrites it into one or more searches (the fan-out), sends them to a search engine and reads what comes back, which OpenAI describes for ChatGPT search and Google calls query fan-out. So the crawler has to be let in before the page can be indexed, and the page has to be indexed before it can rank for the searches the assistant runs. Break any link and the page is invisible.

Most pages ranking for this term audit the answers instead (prompts in, mentions counted). That's tracking, Step 7, and it tells you what happened, never why.

AI visibility audit vs SEO audit (GEO audit)

A GEO audit, which is the same thing as an AI visibility audit, is an SEO audit with more crawlers and more than one index, and that's the whole difference.

Google's guide to AI features and your website says a page has to be indexed and eligible to show in Search with a snippet to appear as a link in AI Overviews or AI Mode, and "There are no additional technical requirements."

That's why, after more than 20 years in SEO, I still say GEO is SEO: the assistants lean on search engines, so Rank = Authority + Relevance decides what gets read. What changes is the plumbing. Robots.txt and firewalls treat OAI-SearchBot, Claude-SearchBot and CCBot separately from Googlebot, and ChatGPT and Claude search through other engines. Schema, llms.txt, XML sitemaps and Core Web Vitals stay hygiene, not levers.

How to run an AI visibility audit in 7 steps

To run an AI visibility audit in 7 steps, start at your own server and work outward, the way a crawler does:

  1. Check AI crawler access in robots.txt.
  2. Check firewalls that block AI crawlers.
  3. Check Common Crawl's record of your site.
  4. Check the AI search indexes.
  5. Find the fan-out queries for your key prompts.
  6. Check where you rank for each fan-out query.
  7. Track AI citations over time.

Step 1: Check AI crawler access in robots.txt

Check AI crawler access in robots.txt first, because most AI crawlers read it before they fetch anything, and it's the easiest place to shut one out by accident.

The names matter. OpenAI runs GPTBot for training and OAI-SearchBot for search, and its crawler documentation says sites that opt out of OAI-SearchBot won't be shown in ChatGPT search answers (navigational links aside). Anthropic splits ClaudeBot (training) from Claude-SearchBot (search), and Google-Extended covers Gemini without touching Google Search.

We fetched the New York Times' robots.txt on October 7, 2026, and these groups were in it exactly as shown (other groups sit between them):

User-agent: CCBot
Disallow: /

User-agent: Claude-SearchBot
Disallow: /

User-agent: Google-Extended
Disallow: /

User-agent: GPTBot
Disallow: /

User-agent: OAI-SearchBot
Disallow: /

Googlebot shares the main group with User-agent: *, which only closes paths like /search and /ads/, and a comment at the top says using NYT content to develop AI is prohibited without written permission. That's policy. On your site, look for the same kind of line where nobody decided it should be. OpenAI says a fix takes about 24 hours to reach ChatGPT search.

Step 2: Check firewalls that block AI crawlers

Check firewalls that block AI crawlers next, because a firewall can refuse a bot that robots.txt allows, and robots.txt will NEVER tell you.

The bot gets an error page (usually a 403) and leaves. Cloudflare began blocking AI crawlers by default on new domains on July 1, 2025, and since its September 15, 2026 update, new domains that show ads start with AI training disallowed and Agent bots blocked on pages with ads, with Search bots still allowed. Security plugins and hosts do it more quietly.

Your browser won't show it, because the firewall only blocks the bot. Our AI visibility checker (Step 4) sends requests with each bot's user agent from our server, and Crawl Record (Step 3) names the blocker from the error page Common Crawl saved. On Cloudflare, start with our guide to Cloudflare AI Crawl Control.

Step 3: Check Common Crawl's record of your site

Check Common Crawl's record of your site, because it's a public log of what a real crawler got from your server.

Common Crawl is a nonprofit, founded in 2007, that publishes a free web archive, and AI training leans on it (OpenAI's GPT-3 paper drew 60% of its training mix from a filtered copy). Its newest crawl, CC-MAIN-2026-39, ran September 4 to 17, 2026 and holds 2.17 billion pages.

Each line in Common Crawl's index is one fetch: the address, when CCBot got it, the HTTP status and the archive file it sits in. A 200 in the main archive means the page was saved, a 403 means something refused CCBot (Step 2, showing up in the data), and a robots.txt capture with no pages behind it means the bot visited and either robots.txt sent it home or the crawl never got further. Crawl Record, our Common Crawl checker, runs that lookup for a page, a site or a site with its subdomains across the newest 3, 6 or 12 crawls, explains each miss, and warns when a saved copy is nearly empty (usually a page built with JavaScript, which CCBot doesn't run).

Step 4: Check the AI search indexes

Check the AI search indexes next, because an assistant can only cite a page its search engine has indexed.

For ChatGPT that's Bing: ChatGPT search sends rewritten queries to search partners, and OpenAI's help page points to Microsoft's privacy statement for how they're handled. Claude's web search reportedly runs on Brave (TechCrunch reported in March 2025 that Anthropic had added Brave Search to its subprocessors), and Brave won't crawl a page Googlebot can't. Gemini and AI Overviews read Google's own index.

Search Console's URL Inspection tool shows Google's indexed version of a page, and Bing Webmaster Tools has its own. For Claude and ChatGPT we built our AI visibility checker: it checks one page against Claude's web search, ChatGPT and Common Crawl for whether it can be fetched, shows up in that source's results and is allowed in by robots.txt.

If a page is missing from every index, look at Authority before anything technical.

Step 5: Find the fan-out queries for your key prompts

Find the fan-out queries for your key prompts, because those searches are what you actually have to rank for, and they're rarely the words a person typed.

Pick the questions buyers ask, not your keyword list. OpenAI's help page shows ChatGPT turning a long question into a short search and then more specific follow-ups, and Google's Gemini API documentation says the model writes its own searches and runs them. Here's one prompt from our fan-out study.

For the prompt "how to get my website to show up in chatgpt" (one run on each engine, October 7, 2026):

  • ChatGPT searched "OpenAI search crawler OAI-SearchBot website ChatGPT searchable site controls robots.txt" and "OpenAI ChatGPT search website OAI-SearchBot robots.txt webmaster", and cited four pages, all from OpenAI's own help center and developer docs.
  • Claude searched "how to get website show up ChatGPT search results" and cited six pages, mostly marketing blogs (HubSpot's among them) plus OpenAI's help center.
  • Gemini searched "how to get site indexed by chatgpt search openai bot" and "how to optimize website for chatgpt web search", and cited 13 pages, from a Rank Math help article to two Reddit threads.

None of the five searches is the prompt as typed, and the three engines ended up reading almost entirely different pages.

The wording moves between runs, so run each prompt more than once and look for the brands and topics that come back every time, then make sure one of your existing pages answers each of them. Fan-Out, our query fan-out tool, shows the real searches ChatGPT, Claude and Gemini ran, across one run or three. It can't show Google AI Mode's searches (nobody outside Google can).

Step 6: Check where you rank for each fan-out query

Check where you rank for each fan-out query in the engine that assistant reads: Google's top 10 for Gemini and AI Overviews, Bing for ChatGPT, Brave for Claude.

Fan-Out puts your Google position beside every search; for Bing and Brave, search the repeat queries yourself in a private window.

This is where GEO turns back into SEO. An assistant reads what its search returns, and search returns the pages with the most Authority and Relevance, so a page on page three for the query ChatGPT runs is very unlikely to be read. The fixes are the old ones: a page whose name (slug, title, headings) matches the query, and links to give it Authority, because a page on its own is only a claim.

Step 7: Track AI citations over time

Track AI citations over time with the free reports the engines give you, and treat everything else as a sample.

Bing Webmaster Tools added an AI Performance report as a public preview on February 10, 2026: citations of your pages in Microsoft Copilot, Bing's AI-generated summaries and some partner integrations, by URL, plus the grounding queries the AI used to pull your content. That's an engine showing you its own fan-out (how to read the Bing AI Performance report).

Google Search Console counts AI Overviews and AI Mode clicks inside the Web search type, and since June 2026 its Generative AI performance report shows those impressions by page, country, device and date, though not by query. Our AI performance report lines that export up with Bing's, page by page. Paid trackers run a fixed list of prompts through ChatGPT, Claude and the others on a schedule, but they sample rather than observe: a zero means their prompts didn't surface you, not that you're absent. Keep the prompt list fixed and compare inside one tool. Our AI visibility checker can email you a weekly report too.

What most people overlook in an AI visibility audit

What most people overlook in an AI visibility audit is that each assistant has two gates, its own bot's rules and the index it searches, and passing one says NOTHING about the other.

The NYT file shows it for all three. Googlebot is allowed, so NYT can stay in Google's index and in reach of AI Overviews, while the Google-Extended line keeps it out of Gemini's grounding at no cost to its rankings. Bingbot falls under the * group, but OAI-SearchBot is blocked, and OpenAI says that keeps a site out of ChatGPT search answers whatever Bing holds. And nothing in the file stops Brave, though Claude-SearchBot is blocked by name.

Small sites, in my experience, fail the other way around: every bot allowed, and the page still missing from Bing and Brave because nothing links to it. That's an Authority problem, and no robots.txt edit fixes it.

Free GEO audit tools

The free GEO audit tools below cover all seven steps between them: three are ours, two belong to the search engines.

ToolWhat it checksSteps
Crawl RecordYour pages in Common Crawl's newest crawls, why a crawl missed you, saved robots.txt rules for 12 AI bots1 to 3
AI VisibilityFetch, search results and robots.txt for Claude's web search, ChatGPT and Common Crawl, plus live requests as each bot1, 2, 4
Fan-OutThe searches ChatGPT, Claude and Gemini ran, with your Google top 10 position for each5, 6
Google Search ConsoleURL Inspection, Generative AI performance report (AI Overviews and AI Mode impressions)4, 7
Bing Webmaster ToolsURL Inspection, AI Performance report4, 7

One check sits outside the seven steps: whether Google's Knowledge Graph knows your brand as an entity. Our knowledge panel checker shows the record Google holds, its type and its ID, and puts a competitor's beside it.

For the paid trackers too, see our pick of the best GEO tools.

AI visibility audit FAQ

Short answers to the AI visibility audit questions that follow the steps.

How long does an AI visibility audit take?

An AI visibility audit takes as long as your prompt list. Steps 1 to 4 run once per site and go quickly with the tools above; Steps 5 and 6 repeat for every prompt, three runs each, and that's where the time goes.

How often should you run an AI visibility audit?

Run an AI visibility audit monthly, and again after any change to your host, CDN, firewall or robots.txt, the changes that break access overnight. Monthly also matches Common Crawl, which has published a crawl every month since at least June 2025.

Can ChatGPT do an SEO audit?

ChatGPT can do part of an SEO audit if you hand it the data, but on its own it can't see your logs, your Search Console or which indexes hold your pages. When it opens a page you point it to, it does so as ChatGPT-User, which OpenAI says may not follow robots.txt, so that fetch says nothing about OAI-SearchBot.

How do you measure AI visibility?

You measure AI visibility with what the engines report (Bing's AI Performance citations and grounding queries, Search Console's Generative AI performance report) and with samples from prompt trackers. Those tell you how often you're cited; the seven steps tell you why, and they're the part you can fix.

Do you need paid tools for an AI visibility audit?

You don't need paid tools for an AI visibility audit: every step above runs on free tools, and a paid prompt tracker only adds the trend line in Step 7. Buy one after the access, indexing and ranking problems are fixed, not before.

References

  1. robots.txt, The New York Times (fetched October 7, 2026).
  2. Searching the web with ChatGPT, OpenAI Help Center.
  3. AI Features and Your Website, Google Search Central (last updated December 10, 2025). developers.google.com/search/docs/appearance/ai-features
  4. Overview of OpenAI Crawlers, OpenAI. developers.openai.com/api/docs/bots
  5. Does Anthropic crawl data from the web, and how can site owners block the crawler?, Claude Help Center (Anthropic).
  6. Google's common crawlers (Google-Extended), Google for Developers (last updated July 14, 2026).
  7. Cloudflare Just Changed How AI Crawlers Scrape the Internet-at-Large; Permission-Based Approach Makes Way for A New Business Model, Cloudflare (July 1, 2025).
  8. Content Independence Day: no AI crawl without compensation!, Cloudflare Blog (July 1, 2025).
  9. Have it both ways: stay discoverable in search while disallowing AI training, Cloudflare Blog (September 15, 2026). blog.cloudflare.com/accountable-mixed-use-ai-crawlers/
  10. Common Crawl, Common Crawl Foundation.
  11. Language Models are Few-Shot Learners, Brown et al., OpenAI (2020), Table 2.2.
  12. September 2026 Crawl Archive Now Available, Common Crawl (September 19, 2026).
  13. Anthropic appears to be using Brave to power web search for its Claude chatbot, TechCrunch (Kyle Wiggers, March 21, 2025).
  14. Brave Search Crawler, Brave.
  15. URL Inspection tool, Search Console Help (Google).
  16. Introducing the Bing Webmaster Tools URL Inspection Tool, Bing Webmaster Blog (September 10, 2020).
  17. Grounding with Google Search, Google AI for Developers (last updated September 23, 2026).
  18. Introducing AI Performance in Bing Webmaster Tools Public Preview, Bing Webmaster Blog (February 10, 2026). blogs.bing.com/webmaster/2026/2/Introducing-AI-Performance-in-Bing-Webmaster-Tools-Public-Preview/
  19. Common Crawl blog (monthly crawl archive posts from June 2025 to September 2026), Common Crawl.