An AEO audit (also called an answer engine optimization audit) is a structured review of whether a website is built to be cited and recommended by AI answer engines like ChatGPT, Perplexity, Claude, and Google's AI Overviews. It examines the technical infrastructure that determines whether AI crawlers can access your site, whether AI engines can understand it, know who you are, and what you do, and whether your content is positioned and structured in a way that allows it to be extracted and cited in AI-generated answers.
It's the AEO equivalent of an SEO technical audit, and for most sites, the findings are significant. Most AEO audits start at the crawler. This one starts two steps earlier.
A complete answer engine optimisation audit starts upstream, with Excavation (who is behind the business) and Positioning (what the business is for, and who it is for). It then works through the five layers of the PRISM Framework—Platform, Recognition, Intelligence, Signal, and Momentum—and ends with a prioritised list of what to fix, in the order it should be fixed.
AEO in plain language
AEO (Answer Engine Optimization aka Answer Engine Optimisation) is the practice of optimising a website to be cited by AI answer engines, not just ranked by search engines like Google or Bing. The two disciplines share some foundations but have meaningfully different technical requirements.
For a fuller explanation of what AEO is and why it matters, see What is an AEO consultant? What matters for an AEO audit is that the requirements are specific and auditable. There are clear things a site either has or doesn't have that determine whether it gets cited and recommended. That is the plain meaning of an AEO audit: a structured check of which of those things are in place, and which are not.
AEO audit, GEO audit, AI visibility audit: the same work under different names
People find me because they aren't being cited in AI answers and want to know why. Whether they ask for an AEO audit, GEO audit, AI visibility audit, LLM SEO audit, or an AI readiness check doesn't matter. The labels are being invented faster than the field is settling, and underneath them the work is the same: can AI answer engines reach the site, do they know who you are, can they understand what you know, does anyone independent corroborate it, and is any of it compounding. The terminology is worth understanding if you want to understand the nuance—SEO vs AEO vs GEO covers the distinctions properly—but it changes nothing about what I review in an audit. What matters is whether all five layers are covered, not what the invoice calls it.
What an AEO audit reviews
A proper AEO audit isn't a single check. It's a review across five distinct layers, each of which can independently prevent a site from being cited by AI engines.
My AEO audits cover five core layers, based on the PRISM Framework. Before I conduct a single technical check, we dive into the most important piece: the foundation. It's what everything downstream is built on, which is why we spend time here first. There's no point building a beautiful house on land you don't want to live on.
Before the checklist: excavation and positioning
I've worked with many people who "fell" into the world of online business, finding themselves selling dog toys because it was a popular niche, starting an agency because it felt easy, or promoting network marketing because the reward seemed worthwhile. But where there is no purpose or passion, drive can only take us so far.
I find that excavating, on a deeply personal level, the reasons someone is building their business, what drives them, how they love to work, when they are most productive, and how they like to spend their days around work provides a level of solidity that's not seen in other people who don't do this type of work first.
Only once we've excavated this information can we move into positioning and branding someone in the way that will work for them, their customers, and the machines who will recommend them.
These two steps cannot be substituted; they provide the basis for the rest of the audit. There is no software application or AI system that can pull this out of somebody. It's the part I've spent fifteen years learning how to do.
The AEO audit checklist: five PRISM layers to review
We run through these five layers together: live and sequentially, because there's no point earning momentum on nothing. That sequence is the AEO audit process in practice; five layers, audited in order, because a fix at layer three does nothing while layer one is still holding the door shut.
- Platform: can the crawlers get in? Crawler access in
robots.txt, JavaScript dependency,llms.txtand sitemap, Core Web Vitals. - Recognition: does AI know who you are? Schema, the entity graph, and consistent entity signals wherever the business appears.
- Intelligence: can AI understand what you know? Answer-first content structure, topical authority, semantic SEO.
- Signal: does anyone else say this about you? Independent mentions, reviews, links, and what the engines say today when asked.
- Momentum: is your infrastructure getting smarter, or just older? Whether all of it is maintained, monitored, and owned once the audit is done.
1. Platform: can the crawlers get in?
Crawler access. Whether AI crawlers—GPTBot (ChatGPT), ClaudeBot (Claude), PerplexityBot (Perplexity), and Google-Extended (Gemini)—are explicitly allowed in the site's robots.txt. This is the single most common and most easily overlooked failure point. Cloudflare Radar data from June 2025 found that 546 of the 3,816 domains in the top 10,000 with a discoverable robots.txt file carried directives aimed specifically at AI bots, with GPTBot named in 312 of them. What a count of directives cannot show is which of them were decisions and which were defaults. More than once in an audit, a client has vaguely remembered asking their dev team to block all AI bots, back in 2023. Blocking was free then, because nothing was being given away. When ChatGPT search launched in October 2024, citation became something a business could win or lose, but very few reopened the file.
One crawler name is not one company. Each major engine now runs multiple agents with different jobs. A blanket rule implemented before that split can block the ones that matter. Anthropic lists three: ClaudeBot, which "helps enhance the utility and safety of our generative AI models by collecting web content"; Claude-SearchBot, which "navigates the web to improve search result quality for users"; and Claude-User, which fetches a page when someone asks Claude a question that needs the live web. OpenAI splits the same way and documents it plainly: GPTBot "is used to crawl content that may be used in training our generative AI foundation models", OAI-SearchBot "is used to surface websites in search results in ChatGPT's search features", and ChatGPT-User visits a page when a person asks ChatGPT something that needs the live web. OpenAI created these settings so they're independent: "a webmaster can allow OAI-SearchBot in order to appear in search results while disallowing GPTBot to indicate that crawled content should not be used for training". One caveat belongs with that: OpenAI states that because ChatGPT-User's requests are initiated by a person, "robots.txt rules may not apply", so a disallow there is not a dependable way to stop live retrieval. Blocking ClaudeBot keeps your content out of model training, which may be what you want, and decides nothing at all about whether Claude can cite you in an answer. In an audit, I check each agent separately, because "we blocked the AI bots" and "we're invisible in AI answers" are two different decisions that businesses make by accident at the same time.
Google-Extended is not the AI Overviews switch. Google says Google-Extended is the control for whether crawled content may be used to train and ground the Gemini models, and states plainly that it "does not impact a site's inclusion in Google Search". Appearing in AI Overviews depends on ordinary Googlebot crawling and indexing, and the controls publishers have over it are snippet controls such as nosnippet and max-snippet. Some AEO checklists conflate the two, which means a site can follow the checklist exactly and still be answering the wrong question.
robots.txt** isn't always in charge of the decision.** The CDN or WAF sitting in front of the site is an enforcement point, and it answers first: if the edge refuses an AI crawler, robots.txt is never read, because the crawler never reaches it. As of 15 September 2026, Cloudflare sorts AI crawlers into three categories: Search, Agent, and Training. And on new domains with ad-monetised pages, training and agent crawlers are blocked by default while search crawlers remain allowed. Mixed-purpose crawlers are held to the most restrictive rule that applies to them, so a crawler doing both training and search is blocked outright when training is blocked. And the old one-click "Block AI bots" toggle, switched on by many site owners during 2025 and never revisited since, is deprecated as of the same date and replaced by the new defaults. A site can pass every robots.txt check in this article and still be invisible because of a setting someone switched on eighteen months ago. An audit checks the edge as well as the file.
This is not only a Cloudflare question. Vercel, Netlify, and the closed platforms each have their own control, in a different place, and most of them cannot tell one kind of crawler from another.
Nor is every block a mistake. Keeping the training crawlers out while letting the search and user agents in is a legitimate strategy, and the two move on different clocks: a live fetch reflects the page as it stands this morning, while training data is fixed until the next model is built. What an audit establishes is that the setting was chosen rather than inherited, and that everyone involved knows which of the two doors is open.
JavaScript dependency. Whether the site's core content is delivered in the initial HTML response or rendered by JavaScript after page load. AI crawlers do not execute JavaScript. A site whose content depends on JavaScript to render may be technically empty to the engines that determine AI discoverability. This is the most significant structural issue in JS-heavy frameworks when not using server-side rendering correctly. You can run a free Platform-layer check to see for yourself.
llms.txt** and sitemap.** Whether the site has an llms.txt file at the root (an emerging standard that allows you to specify how AI systems should interpret and use your content), a current sitemap.xml, and whether those files are referenced correctly in robots.txt. Adoption is uneven, and Google has confirmed it does not support llms.txt, so it belongs in an audit as a low-cost signal worth having rather than as a foundation. It is not a substitute for bot access, crawlability, and HTML-first rendering, and any checklist that presents it as one has the order wrong.
IndexNow. Whether the site notifies engines when something changes, rather than waiting to be re-crawled. IndexNow is a protocol for telling participating engines the moment a URL is published, updated or removed; Microsoft Bing, Yandex, Naver, Seznam.cz and Yep support it, and Google doesn't. It costs nothing but time to implement and it shortens the gap between publishing a fix and the fix being seen.
Core Web Vitals and load speed. How does a real-world user experience your website? We measure three specific aspects of a web page that Google uses as a ranking factor: loading speed, interactivity, and visual stability.
What a pass looks like
- Crawler access: GPTBot, ClaudeBot, PerplexityBot, OAI-SearchBot, Claude-SearchBot, and Google-Extended are all explicitly named and allowed in
robots.txt. No blanket disallow rules are catching them accidentally. The file is reachable at the root domain. - JavaScript rendering: Core content—headings, body copy, schema—is visible in the HTML source with JavaScript disabled. AI crawlers do not render JavaScript. If your content only exists after JS execution, it may be invisible to every crawler on this list.
- llms.txt: A plain-text file exists at
yourdomain.com/llms.txt. It lists key pages with one-line descriptions and states attribution preference. It is referenced or linked fromrobots.txt. - Core Web Vitals: Main content loads quickly, the first interaction responds without lag, and nothing shifts around as the page settles. Google's thresholds for LCP, INP, and CLS are met on mobile, not just on desktop.
- IndexNow: Publishing or updating a page pings the participating engines automatically, rather than relying on the next scheduled crawl.
- Edge and CDN: The AI crawler categories at the CDN are set deliberately rather than left at whatever the default became, no legacy "block AI bots" switch is still on from a previous era, and the edge's own logs show verified AI crawlers being served real pages rather than challenges or 403s.
AEO Audit Checklist
Excavation, positioning, and the five layers to review before you're citable in AI search. One A4 page, print-ready.
2. Recognition: does AI know who you are?
Schema and entity graph. Whether the site has correct, complete JSON-LD structured data; specifically a Person or Organisation entity, Service entities for each offer, FAQPage schema on relevant pages, and Article schema on content. Each entity should be linked internally via @id references so the answer engine sees a coherent, connected picture of who the business is. Missing or malformed schema is a common reason for a site being readable but not citable. Schema markup for founders covers what to implement, and in what order.
Entity signals. Whether the same name, title, location, and description appear consistently across the site's schema, copy, and external references. AI engines build confidence in a source by recognising it repeatedly across the web. Inconsistent signals mean the engine can't form a confident entity model. And sources without confident entity models don't get cited. This is one of the core AEO benefits of doing the structural work properly: once the entity is established, confidence compounds. Entity SEO is the longer explanation of how that model gets built.
First-party corroboration. Whether the sameAs links in your schema point to real, active profiles that agree with each other. LinkedIn, directory listings, platform profiles: these are the profiles you control and they are what an engine follows to confirm that the entity on your site is the same entity it has seen elsewhere. Abandoned or conflicting profiles weaken that link rather than strengthening it.
E-E-A-T. Whether evidence of experience, expertise, authoritativeness, and trust exist, in a form a machine can read. A named author attached to every article, with a bio and qualifications. An About page written as a source of record rather than an origin story. Dates, credentials, and specifics that can be checked against something outside the site. While schema states who you are, E-E-A-T is whether anything on the page supports the claim. Schema without evidence is an assertion. Evidence without schema is unreadable. Recognition needs both.
What a pass looks like
- Schema markup: A
Personentity, aProfessionalServiceentity,Serviceschema on each offering,Articleschema on every content page, andFAQPageschema on every article and service page. All entities linked via@idreferences. Zero errors in Google's Rich Results Test. - Entity signals: Name, job title, and business description are identical across the site, LinkedIn, and all external profiles.
- First-party corroboration:
sameAslinks in thePersonschema point to verified external profiles. No conflicting descriptions across platforms. - E-E-A-T: Named authors and reviewers (if required), with credentials that back up the schema.
3. Intelligence: can AI understand what you know?
Content architecture and structure. Whether key pages lead with a direct, self-contained answer in the first 40–60 words. Whether FAQ blocks exist on relevant pages and are correctly marked up with FAQPage schema. Whether the content hierarchy is designed for machine extraction rather than a narrative or marketing-style flow. This is what an AEO content audit examines, and it is the closest thing to a generative engine optimization checklist—a page-by-page review of whether each section is formatted to be lifted and cited.
Topical authority and semantic SEO. How cohesive is your content? We check whether it's clear, creates authority, and forms a connected web. When crawling, answer engines look for linked, related pages rather than scattered ones, and for clear answers to the questions people are asking. And if you're not publishing any content, we'll get to that too.
What a pass looks like
- Content structure: Every page opens with a direct, self-contained answer paragraph in the first 40–60 words.
FAQPageschema is present and wired to the frontmatterfaqs:array. No key answer is buried three or four paragraphs into a section. - Topical authority: Each core topic has a pillar page with supporting articles linked to and from it, using the same words for the same concepts throughout. No orphan pages, and no two pages competing to answer the same question.
- Semantic SEO: Entities and concepts are named consistently across the site, related pages link to each other rather than leaving the relationship to be inferred, and each page states its subject plainly instead of implying it. Recognition establishes who you are; this is whether an engine can map what you know.
4. Signal: does anyone else say this about you?
Third-party corroboration. Whether anyone other than you says what you say about yourself. This is the layer you can't write your way into: an engine weighs what independent sources report far more heavily than a site's own claims, which is why confidence either accumulates here or stalls here.
Independent mentions. Whether the business appears in places it didn't publish itself: guest articles, podcast appearances, press, industry roundups, community answers. Relevance matters more than volume. A handful of mentions in the right context does more than a hundred scraped directory listings.
Reviews and testimonials. Whether third-party reviews exist on the platforms AI engines read, and whether they name the business the same way the site does.
Case studies with named outcomes. Whether the work has been written up anywhere with specifics attached: who it was for, what was wrong, what changed, and by how much. A case study carrying a real number is citable in a way a testimonial is not, because it gives an engine something concrete to attribute rather than a sentiment to summarise.
Backlinks. Whether trusted, relevant sites link to the business: referring domains that make sense for the work, not raw link counts.
Competitor watch. Whether the AI answers to the business's core questions name someone else. A spot check across ChatGPT, Claude, Perplexity, and Google's AI Overviews, using the questions buyers ask, is the fastest read on whether the other four layers are working. How to get cited by ChatGPT walks through this check in detail.
What a pass looks like
- Independent mentions: The business is named on sites it doesn't own, in contexts a buyer would find credible, within the last twelve months.
- Reviews: Reviews or testimonials sit on third-party platforms, naming the business exactly as the site does.
- Case studies: At least one written-up engagement with a named situation and a measurable outcome, published somewhere an engine can read it.
- Backlinks: Referring domains are topically relevant and live—no dead links, no link-farm listings.
- Competitor watch: Asking the business's core buyer questions across ChatGPT, Claude, Perplexity, and AI Overviews returns the business by name at least once.
5. Momentum: is your infrastructure getting smarter, or just older?
Momentum comes last for a reason: there is nothing to build on until the first four layers are in place. It is also the one layer an audit cannot fix on the day. The other four are assessed and corrected; this one is assessed and scheduled, because momentum is made in the months after the audit rather than during it. It's not to be mistaken for maintenance, which holds a position: the schema stays valid, the sitemap stays current, nothing rots. Momentum compounds: each new page makes the next one easier to place, each citation makes the next more likely, each entity confirmed somewhere else strengthens the ones already established. A site can be perfectly maintained and completely static. What the audit checks here is whether the foundations can carry work that accumulates, and what the first phase of that work should be. The audit doesn't create momentum. It sets the conditions for it: what gets built next, on what cadence, and who owns it.
Infrastructure upkeep. Whether the architecture is solid, fast, clean, and updated regularly. Whether new crawlers are being invited in explicitly as they appear, and whether new pages reach the sitemap when they are published. New AI user agents arrive several times a year, so a robots.txt written eighteen months ago is already out of date.
Schema and llms.txt kept in step. Whether structured data and llms.txt are updated as the business compounds and pages are added, renamed or removed. Schema that describes a site which no longer exists does more harm than no schema at all.
Content freshness and coverage. Whether key pages are genuinely updated, with a dateModified that reflects real changes rather than a bumped date. Whether the content is consistent, clear, organised, and relevant—it's not about volume, it's about clarity and authority. What needs pruning, what needs expanding, and which buyer questions still have no page at all.
Monitoring. Whether Search Console is connected, including the Generative AI features report, and whether AI prompt tracking is running for the business's own questions and its competitors'. Whether anyone is reading the bot analytics: which AI crawlers arrived, how often, and what they were served. Search Console tells you what happened after a crawl; the server and edge logs tell you whether the crawl happened at all. Without monitoring there is no way to tell which parts of the work landed with the most impact.
Ownership. Momentum belongs to whoever picks the work up when the audit ends: someone internal, a developer, or me. A fix list with no owner is where most audits quietly stop. Name the person and the cadence, and the work accumulates. Leave it open and the site drifts back to where it started, which is why so many sites have been audited before and are still invisible.
The compounding half. Everything above keeps a site where it is. Momentum is the work that moves it: publishing into the questions that have no page yet, rewriting the pages already being cited so they answer more completely, extending the entity graph as the business adds services or people, and building third-party signal steadily rather than in a burst. What the audit produces at this layer is a phased plan—what happens in the first month, what happens in the first quarter, and what triggers the next review.
What a pass looks like
- Upkeep:
robots.txt, sitemap, and crawler list reviewed within the last quarter. - Sync: Schema and
llms.txtmatch the pages that currently exist. - Freshness: Key pages carry an accurate
dateModified, and the content behind it has genuinely changed. - Monitoring: Search Console and its Generative AI features report are connected, AI prompt tracking is running, and bot analytics show which AI crawlers are arriving and how often.
- Ownership: One named person, one review cadence, written down.
- Compounding: There is a plan for the next quarter's pages, entities, and signals, not only a maintenance checklist.
Google Search Console now reports impressions that came from its generative AI features separately from ordinary search results, which is the closest thing to a citation log that any engine currently gives publishers. This is mine, June to September 2026. Of 2,493 AI impressions across the site, 2,167 landed on a single article—almost nine in ten. That concentration is the point of monitoring at this layer: it shows which page is carrying the work, so the next round of effort goes where it compounds instead of where it feels productive.
What an audit covers beyond AEO
An AEO audit that only looks at AEO will miss the reason most sites are invisible.
When I run an Infrastructure Audit, answer engine optimisation is one of five areas on the table. The others are brand and positioning, site infrastructure, systems and tech stack, and content architecture, because the problems tend to bleed into each other. A booking flow that breaks on mobile, a CRM that doesn't talk to the site, five different descriptions of the same business across five platforms: none of those are AEO problems, and every one of them shapes whether a citation is worth having when it arrives.
I'm not only an SEO/AEO consultant, or only infrastructure, or only systems. I came through marketing, advertising, and branding before any of this, which is why positioning and JSON-LD can sit in the same conversation without one being treated as the soft part. That blend is the reason my audits can follow a problem across layers instead of stopping at the edge of one discipline.
Most audits arrive as a PDF. A consultant promises one on a sales call, disappears for two weeks, runs your domain through a set of tools, and comes back with forty pages you can't read and an invoice to match.
This is a working session that we do together. You watch the checks happen live. When your robots.txt comes up on screen and there's a line in it nobody remembers writing, you see it at the same moment I do. When I flip your site to disable JavaScript and all you see is a blank page, you finally understand what the crawlers see. The frustration turns into a list. That recognition is most of the value, and it arrives before a single fix has been made.
What comes out is a prioritised checklist within 48 hours, in plain language, that any developer can act on. What also comes out, and matters more to anyone who has bought an audit before and got nothing from it, is that you can see your own site the way an engine sees it, which means you can tell, from then on, whether the next person you hire is telling you the truth.
AEO audit tools vs a human-led audit
Free AEO tools are useful, and they all measure the same narrow thing: presence. Whether branded as AEO auditing and evaluation platforms, visibility graders, or prompt trackers, that's what they measure. A grader fetches a page, checks a handful of signals, and returns a score. A tracker asks a set of prompts on a schedule and reports how often a brand appeared. Both types of tools answer "Are you there?" But neither of them answers "Why not, and what do I change first?"
There is a structural reason for that. Presence can be measured from outside a business. Almost everything that produces presence cannot. A tool can see that robots.txt blocks GPTBot. It cannot see that the positioning describes a business the founder no longer runs, that three service pages answer the same question in slightly different words, or that the real reason nobody cites the site is that nobody outside it has ever mentioned the business.
The free Platform-layer check on this site is deliberately narrow for exactly that reason. It tests Platform-layer access and nothing else: it does not check whether AI understands who you are, trusts what you say, or recommends you to anyone. Those are layers two to five, and they need a person. That is the difference between a tool and an AEO auditor: the tool reports the state of the markup, and a person reads the business behind it.
A tool tells you whether the door is open. An audit tells you why nobody is coming in.
What comes out of a good AEO audit
A well-executed AEO audit produces three things. What arrives is not a dashboard export or a score out of a hundred. An AEO audit report is a working document.
A clear current-state picture. Which of the five layers are present and functioning, which are absent, and which are present but incorrectly implemented. This is not a generic traffic-light report created in private using an SEO software application. It's a specific, accurate diagnosis.
A prioritised fix list. What to address first, second, and third for maximum early impact. Some fixes (crawler access, robots.txt) take minutes for a competent AEO consultant and unblock everything else. Others (schema implementation, content restructuring) take longer but produce compounding returns. The priority order matters, and maintenance is key as a site scales.
Implementation-ready specifications. For schema work in particular, an audit should produce the actual JSON-LD that needs to be implemented—not a description of what to implement. A developer should be able to take the audit output and work from it directly, without further interpretation.
This is what separates a real AEO audit from a tool report. Tools flag what's missing. A proper audit tells you exactly what to put in its place.
Who needs an AEO audit
An AEO audit comes before any other AI visibility work for a business that is actively trying to appear in AI-generated answers and isn't, that wants to move away from relying on social media for traffic, or that suspects it has answer engine optimization gaps but can't tell where they are.
Specifically:
- Established businesses using ChatGPT, Claude, or Perplexity to check their AI visibility and finding their competitors but not themselves
- Sites that have done SEO work but remain invisible in AI-generated answers, because SEO and AEO have different technical requirements
- Sites that recently launched or relaunched and have never had an AEO consulting review
- Sites that look beautiful but aren't generating traffic, leads, or sales
- Any site running on a JavaScript-heavy framework or a closed platform—Kajabi, Squarespace, Wix, Systeme.io, GoHighLevel's website builder, WordPress with a visual page builder like Elementor or Divi, or a vibe-coded site. These are the highest-risk configurations for answer engine optimization gaps
How to get an AEO audit done
AEO auditing is part of the Infrastructure Audit, a deep half- or full-day diagnostic that reviews excavation and positioning, plus a site's discoverability infrastructure across all five layers of the PRISM Framework. It covers crawler access, schema, entity signals, content architecture, llms.txt, Core Web Vitals, topical authority, third-party signals, and the maintenance plan that keeps all of it current, and produces a prioritised fix list in plain language, ready to hand to any developer. If you are comparing AEO audit services, the thing worth comparing is scope: which of the five layers each one covers, and whether positioning is among them.
If your site isn't appearing in AI-generated answers and you don't know why, the Infrastructure Audit is where you find out. If you want a faster, lower-cost first look, the PRISM Diagnostic gets straight to the core issue in 60 minutes for USD $350. The Diagnostic is the ten-minute appointment with a prescription at the end. The Audit is the two hours on the table.
Aimee Q Devlin is a Systems and Infrastructure Architect based in San Miguel de Allende, Mexico. She works with founders and operators of established businesses who are ready to rebuild their systems properly—including the infrastructure that makes those systems discoverable. The PRISM Diagnostic is where engagements begin.
Frequently asked questions
What is an AEO audit?
An AEO audit is a structured review of whether a website is built to be cited by AI-powered answer engines—ChatGPT, Perplexity, Claude, and Google's AI Overviews. It examines crawler access, schema and entity signals, JavaScript dependency, content structure, llms.txt configuration, the independent sources that corroborate the business, and whether any of it is being maintained. The output is a prioritised list of what's wrong and exactly what needs to change, in language any developer can work from.
What does an AEO audit checklist cover?
An AEO audit checklist covers the five PRISM layers: Platform (AI crawler access in robots.txt, JavaScript rendering, llms.txt and sitemap), Recognition (schema markup, the entity graph, and consistent entity signals), Intelligence (answer-first content structure, topical authority, semantic SEO), Signal (independent sources that corroborate the business), and Momentum (whether the infrastructure is maintained and improving over time). Each layer can independently prevent a site from being cited by AI engines.
What does an AEO audit include?
An AEO audit includes a review of five layers: Platform (AI crawler access, JavaScript rendering, llms.txt), Recognition (schema markup and entity signals), Intelligence (answer-first content structure), Signal (independent corroboration), and Momentum (maintenance and ownership). Each layer is checked in order, and the output is a prioritised fix list rather than a single score.
Can an AEO audit check JavaScript-heavy sites?
Yes, JavaScript rendering is one of the five layers reviewed. The main AI crawlers (GPTBot, ClaudeBot, and PerplexityBot) don't execute JavaScript, so the audit checks what is present in the initial HTML response, independent of what a human sees in a browser. A quick first check is available through the free AI crawler checker on this site.
Is a GEO audit the same as an AEO audit?
In practice, yes. GEO (generative engine optimisation) tends to emphasise appearing inside AI-generated answers, and AEO (answer engine optimisation) tends to emphasise being cited as the source of one. The emphasis differs but the technical requirements don't. Both depend on crawler access, schema and entity signals, answer-first content structure, independent corroboration, and maintenance. A review that covers those five layers is the same review, whichever of the two words is on the invoice.
How does an AEO audit work?
An AEO audit works in sequence, one layer at a time. Platform first: can the AI crawlers reach the site at all. Then Recognition: does the engine know who the business is. Then Intelligence: is the content structured so an answer can be extracted from it. Then Signal: does anyone independent corroborate any of it. Momentum last: is the infrastructure being maintained and improved, and by whom. The order matters, because a fix at one layer does nothing while an earlier layer is still blocking. The output is a prioritised list of what to change, in the order to change it.
How long does an AEO audit take?
A focused AEO audit typically takes a half day, covering crawler access, schema, entity signals, content structure, and technical configuration. When the scope extends to include content architecture, full systems review, and business infrastructure, a full day is more appropriate. The right scope is determined in a short pre-audit conversation.
What does an AEO audit cost?
The Infrastructure Audit, which includes a full AEO and discoverability review, starts from $1,500 for a half-day session. The scope and investment are confirmed before any commitment is made. For a small site, the half day is usually enough. If you want a lower-cost first look, the PRISM Diagnostic is USD $350 for 60 minutes.
What is the difference between an SEO audit and an AEO audit?
An SEO audit reviews the factors that affect search engine rankings—backlinks, keyword targeting, on-page optimisation, technical crawlability for Googlebot. An AEO audit reviews the factors that affect AI citation—schema markup, entity signals, AI crawler access (GPTBot, ClaudeBot, PerplexityBot), JavaScript dependency, and answer-first content. It also covers two things an SEO audit rarely touches at all: whether independent sources corroborate the business, and whether the infrastructure is being maintained rather than just left in place. The two disciplines overlap in some areas but have distinct requirements that a standard SEO audit typically doesn't cover.
How often should you run an AEO audit?
At minimum, whenever the site undergoes significant changes—a redesign, a framework migration, new pages, or changes to hosting and deployment. For businesses actively building AI visibility, a light-touch review every six months is reasonable, since the standards and crawlers in this space are evolving quickly. The first audit is the most important: it establishes the baseline.
Can I run an AEO audit myself with free tools?
Partly. Free tools will tell you whether AI crawlers are blocked in robots.txt, whether your schema validates, and whether your pages load quickly, which covers most of the Platform layer and part of Recognition. What they cannot judge is whether your positioning is right, whether your content answers the questions buyers ask, whether any independent source corroborates you, or which fix matters most. The free AI crawler checker on this site covers Platform-layer access only. The rest needs someone looking at the business, not just the markup.
›Sources
- Your site, your rules: new AI traffic options for all customers, Cloudflare, 1 July 2026
- Block AI bots, Cloudflare Docs, accessed 17 September 2026
- Google crawlers, Google Search Central, accessed 17 September 2026
- Does Anthropic crawl data from the web?, Anthropic, accessed 17 September 2026
- Overview of OpenAI crawlers, OpenAI, accessed 17 September 2026
- IndexNow, IndexNow, accessed 17 September 2026
- Introducing ChatGPT search, OpenAI, 31 October 2024
- From Googlebot to GPTBot: who's crawling your site in 2025, Cloudflare, 1 July 2025