Skip to main content
Your Website Does Not Need to Be AI Compliant

Your Website Does Not Need to Be AI Compliant

Share

A modern website needs to be clear, crawlable, coherent, and backed by an organization that knows what it is saying.

I’ve mostly avoided writing about AI here.

Not because I don’t think it matters. It clearly does. I’ve avoided it because I think brand—and the organizational work required to build one—is bigger than whatever technology happens to dominate the conversation at a given moment.

Artificial intelligence is already changing how people discover information, make decisions, evaluate organizations, and interact with digital systems. Those changes deserve serious attention.

What they do not deserve is surrendering strategic judgment to the technology itself.

We have a familiar tendency when transformative technologies arrive. A legitimate change becomes an imperative. The imperative becomes a category. The category acquires consultants, products, audits, dashboards, frameworks, and eventually a new vocabulary of things organizations are told they must urgently become.

“AI-ready.”

“AI optimized.”

“AI-native.”

And, increasingly, “AI compliant.”

That last one should make organizational leaders stop and ask a very simple question:

Compliant with what?

Compliance normally means something. Web accessibility, for example, has an established technical standard in the Web Content Accessibility Guidelines. WCAG 2.2 defines testable success criteria across three levels of conformance—A, AA, and AAA—and in 2025 was approved as the international standard ISO/IEC 40500:2025. That is what an actual technical standard looks like.

“AI compliance,” by contrast, is not currently a universal web standard—and as of this writing, in August 2026, it still isn’t one. There is no generally accepted specification declaring that a website built before some technological threshold is noncompliant with artificial intelligence.

Even NIST’s AI Risk Management Framework—one of the more substantial frameworks for thinking about the governance and trustworthiness of AI systems—is concerned with managing risks associated with organizations that design, develop, deploy, or use AI. AI RMF 1.0 is currently being revised, but it is not a compatibility specification that websites must satisfy before artificial intelligence can understand them.

That distinction matters because organizations are beginning to make substantial technology decisions under the assumption that AI has created an entirely new set of web requirements.

In many cases, it hasn’t.

AI did not suddenly make the web unreadable

If your goal is for information on your website to be found, interpreted, referenced, or surfaced by contemporary AI-powered search systems, much of the technical foundation is surprisingly familiar.

Google’s current guidance could hardly be more explicit. For a page to appear as a supporting link in AI Overviews or AI Mode, it must satisfy the existing technical requirements for Google Search. Google then states: “There are no additional technical requirements.” It also says websites do not need new machine-readable AI files, special AI markup, or a special Schema.org implementation to appear in those experiences.

Google’s more detailed 2026 guidance for optimizing websites for generative AI features makes the point even more forcefully. It tells site owners to prioritize effective SEO over what it calls “AEO/GEO hacks,” including unnecessary content chunking, manufactured mentions, special AI markup, and AI text files such as llms.txt. Its recommendations remain recognizable: build a clear technical structure, permit crawling, make important content discoverable, reduce unnecessary duplication, provide a good page experience, and publish useful, authoritative content.

OpenAI’s guidance for publishers is similarly undramatic. Any public website can potentially appear in ChatGPT search. Publishers that want their content discovered, surfaced, cited, and linked should make sure they are not blocking OAI-SearchBot and should manage access using familiar mechanisms such as robots.txt and noindex.

Microsoft offers a useful complication to this argument.

Bing describes AI grounding—the process through which AI systems retrieve current, authoritative information to support generated answers—as a significant evolution of search infrastructure. Traditional search indexing was built to help humans decide what to read. Grounding infrastructure increasingly helps AI systems decide what information they can responsibly use to construct an answer. Microsoft is explicit that those two jobs do not require identical infrastructure, even when they begin from the same foundation.

That distinction is important.

AI is changing the system. It does not automatically invalidate the system you already have.

A change in search, indexing, grounding, or retrieval infrastructure does not mean every website publishing into that infrastructure has suddenly become technically obsolete. In fact, Microsoft’s own Bing Webmaster Tools approaches AI visibility as an extension of an existing webmaster discipline: measuring which pages are cited, what grounding queries retrieve them, whether information is current, and whether content is sufficiently clear and structured to serve as useful evidence.

None of this suggests that AI changes nothing.

Organizations should not be treating AI Readiness like a fire that needs to be extinguished.
Organizations should not be treating AI Readiness like a fire that needs to be extinguished.

That creates a powerful new reason to care about clarity.

But clarity was already the requirement. AI does not create the need for organizational clarity. It exposes the consequences of not having it.

It suggests something much more useful:

AI changes the importance of certain fundamentals without necessarily changing the fundamentals themselves.

Old technology and bad technology are not the same thing

One of the most dangerous assumptions in technology strategy is that age is a proxy for inadequacy.

It isn’t.

A ten-year-old website that produces clean, accessible, server-rendered HTML; maintains coherent URLs; contains useful text; uses meaningful headings; permits legitimate crawlers; and accurately represents the organization behind it may be extraordinarily easy for both search engines and AI systems to interpret.

A website rebuilt last month using the newest application framework can be considerably worse.

Google itself acknowledges the distinction. Its current AI search guidance says perfectly semantic HTML is not required, while still recommending semantic structure where possible. It can process JavaScript-driven content, but Google also notes that search optimization for websites using JavaScript frameworks is generally more complex than for other kinds of websites.

This is not an argument against JavaScript, modern frameworks, headless architectures, composable systems, or rebuilding old websites.

It is an argument against confusing modernity with fitness.

Technology decisions should follow requirements. If a legacy content management system creates security risks, cannot support accessibility requirements, prevents appropriate structured data, produces unusable mobile experiences, creates serious performance problems, or makes effective governance impossible, there may be compelling reasons to replace it.

But “AI exists now” is not, by itself, a technical diagnosis.

Before an organization commits to replacing a web platform, leaders should be able to articulate what the current platform prevents the organization from doing—and what measurable capability the replacement will provide.

That was responsible technology governance before generative AI.

It remains responsible technology governance now.

The more important audit is probably not your platform

The rise of AI does create a valuable reason to reconsider a website, but perhaps not in the way many organizations expect.

  • Ask an AI system a straightforward question about your organization.
  • What services do you provide?
  • Who leads this division?
  • What does this product cost?
  • What are the admission requirements for this program?
  • Where do you operate?
  • What is your policy on this issue?
  • Why should someone choose you instead of a competitor?
  • Then consider where the machine might find the answer.

Perhaps the corporate website says one thing, a departmental website says another, a four-year-old PDF says something slightly different, and an old press release contradicts both. Perhaps three pages describe the same service using different terminology. Maybe an executive biography has been updated in one place but appears under an obsolete title in six others. Perhaps the canonical source for an important institutional fact is not apparent even to the people inside the organization responsible for maintaining it.

Artificial intelligence did not create any of those problems.

It simply encounters them.

And unlike a human visitor who may open one page, recognize the context, make an inference, and move on, an AI system may retrieve fragments from multiple sources and synthesize them into a single answer.

Suddenly the organization’s accumulated ambiguity becomes machine-visible.

This is where the AI conversation becomes much more interesting than whether the CMS was installed in 2017 or 2026.

The question becomes one of organizational coherence.

Who owns the information? Which source is authoritative? How is that authority communicated technically? How quickly are outdated facts corrected? Where does unnecessary duplication exist? Does the organization use consistent language for the same products, programs, people, places, and capabilities? Does the information architecture reflect the actual structure and priorities of the organization—or decades of accumulated internal politics and publishing convenience?

Those are not merely SEO questions.

They are governance questions.

And increasingly, they are brand questions.

A Sensible AI-readiness Checklist.

Question What You’re Evaluating
Can legitimate search and AI crawlers access important content? Crawlability and permissions
Can systems reliably identify the authoritative version of information? Content governance and canonicalization
Is important information expressed as meaningful, accessible web content? Semantic structure and machine readability
Are products, programs, people, locations, and services described consistently? Organizational and brand coherence
Are obsolete, duplicate, or contradictory sources still discoverable? Information lifecycle management
Can relationships between important information be understood? Information architecture and structured data
Can AI agents successfully complete relevant digital tasks? Interaction and application architecture
Does the existing platform prevent any of these capabilities? Actual justification for modernization

Platform replacement should be the conclusion of an assessment, not the premise of one.

Machine readability begins with organizational clarity

There has always been a machine-readable dimension to the web.

Titles, headings, navigation, links, metadata, addresses, dates, tables, structured data, and the semantic relationships expressed through HTML all give software information about what content is and how pieces of information relate to one another.

The AI era increases the value of that discipline.

Organizations should absolutely examine whether important content is accessible to legitimate crawlers. They should understand what their robots.txt directives permit and prohibit. They should review canonical URLs, redirects, internal linking, XML sitemaps, metadata, structured data, accessibility, performance, duplicate content, authorship, publication dates, and the amount of critical information trapped inside images, documents, proprietary interfaces, or scripts.

But the technical audit should be accompanied by a content and governance audit.

No amount of markup can resolve an organization that has not decided which of its own statements are authoritative.

You cannot schema-markup your way out of institutional confusion.

Organizations should also begin measuring how their information is actually participating in AI-mediated discovery. Google introduced dedicated Generative AI performance reporting in Search Console in June 2026, initially for a subset of sites. Microsoft’s AI Performance reporting in Bing Webmaster Tools is currently in public preview and reports citations, cited pages, grounding queries, and visibility trends across Microsoft AI experiences.

Again, the operative idea is not compliance.

It is readiness.

Understand the system you already have. Understand how machines encounter it. Understand where information breaks down. Then decide what actually needs to change.

The next phase is different: AI will not only read websites

There is, however, another development that deserves serious attention.

AI systems are beginning to move from retrieval toward agency.

The first generation of AI-mediated web interaction largely asks machines to locate and synthesize information. Increasingly, agents will also be expected to perform tasks: compare products, submit information, make reservations, manage transactions, navigate authenticated environments, or interact with organizational systems on someone’s behalf.

That development can create genuinely new architectural requirements.

Google’s current guidance on generative AI search identifies this as an emerging area. Browser agents may interact with websites by analyzing rendered pages, inspecting DOM structures, and interpreting accessibility trees. New protocols are also emerging to enable more direct interaction between agents and digital services.

For some organizations, that will justify new APIs, identity systems, transaction layers, structured interfaces, permissions architectures, or substantial changes to digital platforms.

But notice what happened there.

A specific capability created a specific requirement.

That is very different from declaring that every existing website needs to be rebuilt because artificial intelligence exists.

A university application system, an airline booking engine, an ecommerce checkout, a hospital scheduling environment, and a professional services website do not have identical agentic requirements. Their technology strategies should not pretend that they do.

AI readiness should therefore be driven by use cases, risk, organizational priorities, and user needs—not technological FOMO.

AI is another reader of the organization

This is ultimately why I think the conversation belongs inside brand strategy.

For years, organizations have treated websites primarily as communications artifacts. The website presents the organization to customers, prospects, employees, investors, students, donors, partners, journalists, communities, and other human audiences.

Artificial intelligence adds another audience.

Or, perhaps more accurately, another reader.

Machines are increasingly reading the organization before people do. They are finding its claims, comparing its language, identifying relationships, retrieving evidence, and assembling answers from the information the organization has placed into the world.

That creates a powerful new reason to care about clarity.

But clarity was already the requirement.

AI does not create the need for organizational clarity.

It exposes the consequences of not having it.

A fragmented organization produces fragmented information. A poorly governed brand produces competing descriptions of itself. A business without clear ownership of its messages eventually creates a digital environment in which neither humans nor machines can reliably determine what is true, current, distinctive, or important.

That is not an AI problem.

That is an operating-system problem.

The organizations that respond well to this moment will absolutely modernize technology where modernization produces meaningful capability. They will improve structured information, experiment with emerging protocols, rethink particular interactions, measure AI-mediated visibility, and make deliberate decisions about how intelligent systems should access and use their content.

But they will resist allowing technological urgency to become a substitute for strategic thought.

Because the AI-ready website is not necessarily the one built with the newest technology.

It is the one backed by the clearest organization.

Sources and further reading

Google Search Central, AI Features and Your Website — Google’s guidance for participation in AI Overviews and AI Mode, including its explicit statement that there are no additional technical requirements beyond existing Search requirements.

Google Search Central, Google’s Guide to Optimizing for Generative AI Features on Google Search (updated July 2026) — current guidance on crawlability, semantic HTML, JavaScript, structured data, AEO/GEO practices, llms.txt, measurement, and emerging agentic experiences.

OpenAI, Publishers and Developers FAQ — guidance on OAI-SearchBot, robots.txt, noindex, citations, discoverability, and publisher control over participation in ChatGPT search.

Microsoft Bing, Evolving Role of the Index: From Ranking Pages to Supporting Answers (May 2026) — Microsoft’s explanation of how AI grounding changes the role of search infrastructure without discarding the foundations of crawling, indexing, and authoritative information retrieval.

Microsoft Bing, Introducing AI Performance in Bing Webmaster Tools Public Preview (2026) — current reporting on citations, cited pages, grounding queries, and how publisher content appears within Microsoft AI experiences.

Google Search Central, Introducing Search Generative AI Performance Reports in Search Console (June 2026) — Google’s dedicated reporting for visibility within generative AI features in Search and Discover, initially rolling out to a subset of websites.

World Wide Web Consortium, Web Content Accessibility Guidelines (WCAG) 2.2 — a useful contrast to the loose language of “AI compliance”: a genuine conformance standard with defined, testable success criteria, approved as ISO/IEC 40500:2025.

National Institute of Standards and Technology, AI Risk Management Framework — an established framework for governing AI risk, not a compatibility standard that websites must satisfy to be “AI compliant.”

Post Main Image: Code Composition, Marc Stress
Post Image inline: Yellow Hydrant Tryptich, Marc Stress.

brand_operating_system_cover_stack.webp

The Brand Operating System

Brand compounds when it's a system. Depreciates when it's a campaign.

Get the Book