The gap Who we serve Pricing AEO explained Insights FAQ About Run your AI visibility check
How AI works

The firewall protecting your website is also hiding it from AI

AI agents now build most of an answer from what they read on your site, live. A 37,927-question study found blocked sites get recommended half as often. What is probably blocking yours.

Picture two ways an AI assistant like ChatGPT can find out about your firm:

  • It already "knows" something from training, the way a person might recall a fact from memory.
  • It goes and actually visits your website right now, reads the page, and builds its answer from what's there.

For years, AI mostly worked the first way. That's why the advice was to get your firm mentioned in enough places that a model would eventually "know" you. A new study says that's not how it works anymore. Today's AI agents build 90%-plus of a finished answer from what they fetch on the spot, not from what they learned in training, according to ora research's September 28 study, "AX is the New AEO." So when a prospective client asks an AI who to hire, the answer depends less on what the model already knows about your firm and more on whether it can actually get onto your site and read it, right now.

Two panels: on the left an AI assistant reads a law firm's website directly and names the firm; on the right a bot-protection wall blocks the assistant, which builds its answer from other sites instead
Two ways an AI finds out about your firm: what it remembers from training, and what it can read on your site right now.

For a lot of law firms, it can't.

What the study actually did

The researchers took 1,056 real businesses and split them into two groups: sites an AI agent could actually read, and sites it couldn't. They held everything else equal, how well known the business already was, how often it got mentioned elsewhere online, so the only real difference between the two groups was whether the AI could open the site. Then they ran 37,927 buyer-style questions, "what does this cost," "what do they offer," through four different AI agent setups and watched what happened.

When the AI could read a business's own site, it clearly recommended that business one time in five. When it couldn't, about one time in nine, roughly half as often. The paper includes a real example that makes this easy to picture: asked about Twilio, the AI answered straight from Twilio's own help pages in seven steps. Asked the same kind of question about HashiCorp, it got blocked on HashiCorp's own pricing page twice, gave up, searched the open web seven times, and built its answer off two of HashiCorp's competitors' blogs instead. It still sounded confident. It just wasn't talking about HashiCorp anymore.

Getting blocked isn't free for the AI either. Every answer it managed to build off a blocked site cost 64% more to produce, in extra searches and retries, before it gave up.

The AI is leaving you out, not making you up

The number that matters most for a law firm isn't the recommendation rate. Facts stated wrong barely moved in the study, from 4% to 6%. Facts that never got mentioned at all jumped from 29% to 45%. The AI is leaving pieces of the truth out about your firm, because it never found them.

Being talked about doesn't fix this

You'd think the answer is more mentions, more citations, more directory listings. The study checked that too, and once it controlled for whether the AI could actually read the site, being mentioned elsewhere had basically no effect on whether the business got recommended. Being findable gets your name said. It doesn't get your website read, and being read is what actually decides the recommendation.

What's probably blocking you

Most firms aren't blocking AI on purpose. Your site is likely sitting behind a bot-management layer, Cloudflare is the most common one, that was set up years ago to stop scrapers and credential-stuffing bots. Nobody configured it with ChatGPT in mind, because ChatGPT didn't exist yet. By default, it doesn't know the difference between an attacker and the assistant your next client just asked about you.

A few specific things trip an agent up even on a site nobody thinks of as walled off. Pages built mostly in JavaScript, where the real content only shows up after the browser runs code an agent skips. A "Just a moment..." challenge screen a person clicks through without noticing, that an agent can't. Bot rules written to block by user agent, which catch AI crawlers by name right along with whatever they were actually built to stop. None of it shows up when you open the site yourself. It only shows up when something that isn't a browser tries to get in.

One thing to check this week

Ask whoever manages your site's bot protection a simple question: does it let OpenAI's, Anthropic's, and Google's agents through, or does it challenge them the same way it challenges everything else? If nobody can answer that with certainty, that's the answer. Selectio's audits check exactly this, what AI can actually reach about your firm, your practices, and your lawyers, and where the wall needs to come down.


Can AI actually read your site?

The free, live check runs the questions your clients ask across ChatGPT, Perplexity, Gemini, Claude, and Google's AI Overviews, and shows what each engine can reach about your firm, your practices, and your lawyers, and which firms it names in your place.

Run your AI visibility check