AI agents read your website, cite it, and buy from it. No Hacks tells you what's actually changed and whether it's worth acting on yet.
The web now has visitors who aren't human. AI agents read your website, cite it, and increasingly buy from it, acting for the people who used to visit themselves.
No Hacks is where you find out what actually changed, whether it's real, and whether your website is ready for it. The articles, weekly podcast, and newsletter stay plain and back every claim with receipts.
Available on+ more
Available on Apple Podcasts, Spotify, YouTube, and more
These articles get revised rather than archived. Start with the definitions, then the two references that track every new crawler and agentic browser as it ships.
New articles, the latest podcast episode, and a few links worth keeping. Practical strategies for making your website work for AI agents and the humans using it.
A reference to what each website access control is worth in court. robots.txt, terms of service, anti-bot systems, rate limits, login gates, and cease-and-desist letters, with what courts have actually held about each one and how settled each answer is, which tells you how much weight it carries.
Cloudflare launched Kitesurf, a browser for AI agents that treats rendering as optional: "visual perfection, smooth 60-fps scrolling is not" important. Four weeks earlier OpenAI retired Atlas, a browser built so a person could watch an agent work. Anything your website communicates only in painted pixels, the trust badges and the reassurances, is now definitively invisible to the visitor reading you.
Cloudflare's CFO told analysts that non-human traffic could be 1,000 times human traffic within five years and that humans will be "a rounding error on the internet." So I looked at my own crawler logs. The single largest AI crawler on nohacks.co arrived under Common Crawl's name and spent the day asking for my SSH keys, my .env files, and my MCP config.
Shopify switched on WebMCP for every Liquid storefront on August 5: catalog, cart, and checkout are now tools an AI agent can call, with nothing to install. I checked three real storefronts: search already returns products and prices in a stock Chrome, checkout dies on an internal error, and no agent is calling any of it. Why this is not another llms.txt, and what to test before the agents arrive.
The Ninth Circuit overturned the ban on Perplexity's shopping agents accessing Amazon, the second time in a month a platform reached for an old statute to block a machine visitor and lost. The courts keep declining to hold the switch. Cloudflare's defaults will happily hold it for you, and from September 15 that comes with real consequences for search too.
The web's machine-access fight is aimed at Google: block it, license to it, sue it. Meanwhile Meta's two crawlers became the majority of AI agent traffic, sending almost nothing back, and unless you are News Corp's size, nobody is holding that meeting for you.
On August 5 Shopify switched on a second way into every store on its platform, built for AI agents instead of people. Nothing to install, no merchant asked. I opened three unrelated stores, Allbirds, Brooklinen and Partake Foods, and asked each what it could do for a machine. All three answered with the same roughly 800 words, identical character f...
Most of what's sold as AI search optimization has never been tested by the people selling it, and this episode is me checking the biggest one against server logs. Ahrefs looked at 137,000 domains in June: 97% of llms.txt files got zero requests in May, and the biggest readers of the rest were SEO audit tools. I also lay out the line I use to sort e...
I came back from a month off the grid to find OpenAI had killed Atlas, its most glamorously launched product, nine months after the keynote. It barely matters, though. The automated, non-human visitor Atlas was sending to your website is still coming, through whatever shell comes next. Build for the visitor, not the browser.
I sat down with Malte Landwehr, who left VP of SEO at Idealo to become CPO and CMO at Peec AI, the platform that tracks what ChatGPT, Claude, Gemini, and Google AI Overviews actually cite. We open on the strangest finding of the year. GummySearch, a Reddit analytics tool that shut down last November, now sits behind about 0.1% of all ChatGPT citati...
This week I welcome Alisa Scharf, Chief AI Officer at Seer Interactive, to the podcast, to ask the question she fires back at every client who walks in wanting to "win at AI visibility." Her answer flips the whole project: fix what the models get wrong about you before you chase the category terms. We got into her research on why lower-authority we...
The user-agent string in the HTTP header has been there since the 1990s. The web was built with software navigating it on someone's behalf. For thirty years that someone was a human. That changes now. Matt Biilmann, CEO and co-founder of Netlify, was one of the first to take seriously what it means when the "user" navigating the web is an AI agent.