Nine readings of one measurement run: 1,469 sites (490 known brands across 22 categories, plus 979 long-tail sites from the Tranco list), 27 signals, no numeric score. The charts do not all use the same base: each states whether it covers the full pool (1,469), only the categorised brands (490) or the reachable sites (846). Every chart is downloadable and shareable as-is.
1469 sites · scanned September 9, 2026
Four tiers, and an overwhelming majority stalled
83% of sites: no agentic signal.
83% of the scanned sites expose no agentic signal at all: no commerce profile, no llms.txt file, no authentication metadata. Hand-picked brands do three times better than the web's long tail (30% above “not ready” versus 10%), but “fully optimised” stays the exception: 23 sites out of 1,469.
Across all 1,469 sites in the full pool
1469 sites measured
83.6% at the “not ready” tier
5.7% “Agent Ready” or above
1 site in 18 reaches “Agent Ready”
61.4% of the 51 sites at the top are curated brands
Source: leaderboard pool, 1469 domains, scanned 2026-09-08.
Who is ready, who is not
Collaboration SaaS 79% · food delivery and public sector 0%.
Productivity SaaS, developer tools and CRM lead — sectors whose product is already, in essence, an API. At the other end, food delivery and the public sector sit at zero: not one of the 40 sites scanned in those two categories exposes a single agent-usable signal.
Source: leaderboard pool, 490 domains, scanned 2026-09-08.
One signal everywhere, the rest almost nowhere
sitemap 73% → llms.txt 21% → everything else under 8%.
The XML sitemap, inherited from classic SEO, is on 73% of sites — but it says nothing about agentic intent. The first genuine agentic signal, llms.txt, is at 21%. Below that the drop is steep: OAuth metadata under 8%, and the newest conventions (MCP, WebMCP, Web Bot Auth) on a handful of domains.
Source: leaderboard pool, 846 domains, scanned 2026-09-08.
What robots.txt declares, what the server does
53% of “I block AI” block nothing. 17% of “open” ones block.
One in two sites that declare they block AI robots in robots.txt in fact treat no AI crawler differently from an ordinary browser (66 of 125 measured). The reverse also happens: 17% of domains that declare nothing, or say they are open, still block at least one crawler. The declaration and the real behaviour are two different things. The broad campaign of 2026-08-24 measures the same gap with a looser criterion, and agrees.
Source: leaderboard pool, 788 domains, scanned 2026-09-08.
The jump between “almost ready” and “agent ready”
144 sites at a single signal. 13 have two, but in the same category.
Clearing the “agent ready” tier does not take more signals, but signals of a different nature: at least two distinct categories. 13 sites have two signals in a single category and stay stuck at “almost ready”; 24 sites with two signals split across two categories tip over. The most crowded cell is still (1 signal, 1 category): 144 sites, almost always llms.txt alone.
Source: leaderboard pool, 241 domains, scanned 2026-09-08.
“This site has an npm SDK”: a signal wrong one time in four
25% false positives, 19% verified official SDKs.
Searching a brand name on the npm registry and taking the first result yields a false positive 25% of the time: an unrelated same-name package (samsung → @browser-logos/samsung-internet, zoom.us → @types/d3-zoom). Only 19% are a verifiable official SDK. That is why this signal stays diagnostic and never has a “present” state.
Source: pilote 32 domaines choisis pour porter un nom de marque reconnaissable (orienté tech/SaaS) (32 domains, 2026-08-25) — a sample distinct from the leaderboard pool.
Note — N=32, sur-représentation délibérée d'entreprises tech/SaaS susceptibles d'avoir un SDK — un point de mesure de la fiabilité du signal, pas une prévalence populationnelle. Ventilation officiel / faux positif / tiers légitime issue d'une revue manuelle du premier résultat npm.
Competing agentic payment protocols: zero adoption
Probed blind across 1,000 domains and at seven publicly named adopters, neither ACP (OpenAI) nor x402 (Coinbase) serves a single valid discovery document. Anthropic's commerce blueprint of 2026-09-02 cites no third-party payment protocol — it builds on UCP, the Catalog and Sign in with Shop.
Source: leaderboard pool, 1000 domains, scanned 2026-09-08.
Note — Échantillon Tranco généraliste, distinct du pool leaderboard curé — mais le résultat mesuré est « zéro » (0 document ACP valide, 0 document x402 structuré), robuste à la composition de l'échantillon. AP2 et MPP ne sont pas sondables en aveugle et restent en desk-research.
UCP, the only protocol with measurable merchant adoption
4 real UCP profiles out of 55. Competing protocols with merchant docs: 0.
Of 55 e-commerce sites tested, four expose a complete, queryable UCP profile: allbirds, decathlon, glossier, gymshark. That is few, but it is four more than every competing protocol combined, none of which has usable merchant documentation. The direction is set by the Anthropic × Shopify announcement of September 2026.
Source: leaderboard pool, 55 domains, scanned 2026-09-08.
What an agent finds on the surface, by kind of convention
Discoverability 43% · API / Auth / MCP surface 9%.
Distinct from the ranking by line of business: here, the four families of agent-facing conventions. Sites do the passive work — making themselves discoverable (43%), making their content readable (29%), declaring a policy for robots (27%). Almost none expose the active surface: an API, authentication or an MCP connector an agent can actually call (9%).