What to ask your web team about AI agents: 20 questions
Questions to bring to developers, grouped like the self-check, with the standards they will recognise.
Am I Ready for Agents? editors · Reviewed September 2026
You do not need to know how to build any of this to ask good questions. Take the questions below to your web team, grouped by the five self-check areas. Each group names the standards and references a developer will recognise, and says what a clear answer sounds like.
Find: can agents find you?
- What does our robots.txt say today about GPTBot, OAI-SearchBot, ClaudeBot, PerplexityBot, Google-Extended and Applebot-Extended, and who decided it?
- Does our CDN, firewall or bot protection have an AI bot rule switched on, and is it set to log, challenge or block?
- Is our sitemap generated automatically, and does it include the pages we most want found?
- Should we publish an llms.txt file, and who would keep it current?
Standards and references
- RFC 9309: Robots Exclusion Protocol
- llms.txt proposal
- Cloudflare AI Crawl Control
- Vercel AI bots managed ruleset
Read: can agents read you?
- Which of our page templates deliver their main content in the first HTML response, and which need JavaScript to show it?
- Are any prices, stock levels, opening hours or policies shown only as images, PDFs or pop-ups?
- Which structured data do we publish on product, event, offer or article pages, and do we validate it?
- Can we give agents a markdown version of a page when they ask for one, and would we want to?
Standards and references
Act: can agents act on your site?
- Can our main task be completed end to end as a guest, and where do CAPTCHAs or other challenges appear on the way?
- Do we offer a documented API, an MCP server or WebMCP tools, and who maintains them?
- Do our sign-in and consent screens use a standard flow such as OAuth, and can a customer grant narrower permissions?
- If an agent fails halfway through, does it get a clear error message or a blank page?
Standards and references
- Model Context Protocol specification
- WebMCP proposal
- A2A protocol
- agents.json
- Cloudflare on task-based OAuth consent
Pay: can agents pay?
- Is the total price, including tax and delivery, in the page text before the last step?
- What does our fraud or payments tool do today with a purchase started by a verified agent?
- Have we looked at agent payment approaches such as x402, ACP, UCP or MPP, and what is our position?
- Who signs off on accepting, or declining, agent-initiated payments?
Standards and references
This edition does not review the ACP, UCP or MPP specifications; we name them because Cloudflare's scanner checks for them.
Trust: can agents be trusted, and trust you?
- Can we tell verified bots, for example ones that sign requests with Web Bot Auth, from bots that only claim a name?
- Are our returns, cancellation, privacy and terms pages public, current and readable without JavaScript or a login?
- What content signals, if any, do we send about AI training, search and AI input?
- Who owns our policy on AI agents, and where is it written down?
Standards and references
- Cloudflare, Web Bot Auth
- RFC 9421: HTTP Message Signatures
- Vercel verified bots
- Cloudflare Markdown for Agents (content signal header)
What should I not ask my web team to do?
Do not ask for a score on a particular scanner as the goal. Scanners check different things, and a high score is not the same as customers' agents finishing tasks. Ask instead which of the 20 questions above have clear answers, and which do not yet.