Is Your Website Invisible to AI Search? A GEO Primer
John Sabo 6 min read
More people are asking an assistant for a recommendation instead of typing a query into a search box. The answer they get is written by a model, and the model picks which businesses to mention. Generative engine optimization, or GEO, is the work of making sure your business is one of them.
It is not a trick and it is not a rewrite of everything you have published. It is a small set of technical and writing changes that make your site easy for a machine to read, quote, and trust.
How this differs from regular search
Search gave you ten blue links. An assistant gives you a paragraph, usually with a few sources named underneath. That changes what matters.
Ranking is not the goal anymore. Being quotable is. A model needs a sentence it can lift, attribute, and be confident about. If your site only has a photo of a storefront and a contact form, there is nothing to lift.
Step one: let the crawlers in
Each AI product sends its own crawler to read pages. OpenAI has GPTBot and OAI-SearchBot. Anthropic has ClaudeBot and Claude-Web. Perplexity has PerplexityBot. Google has Google-Extended. There are others, including Amazonbot, Applebot-Extended, CCBot, FacebookBot, and Bytespider.
Many websites block all of them without knowing it, because the site copied a robots.txt file from somewhere that treated every unfamiliar crawler as a threat. The result is a site that is technically perfect and completely absent from AI answers.
I do the opposite on my own site. I allow the search-oriented crawlers in, and I say so explicitly in robots.txt so it is obvious and auditable. If you would rather stay out of AI answers, that is a legitimate choice. Just make it a choice and not an accident.
Step two: publish an llms.txt
An llms.txt file is a short map of your site, written in plain markdown, that sits at your domain root. It lists the pages that matter and gives each one a one-line description.
Think of it as a summary you hand to a busy assistant instead of making it walk every room in the house. Your services, your about page, your contact details, your best articles, each on one line with a link.
It takes an hour to write and it is one of the cheapest things you can do for AI visibility. Mine is at lonosecurity.com/llms.txt if you want to see the shape of it. I also keep a longer version, llms-full.txt, with the whole text of the site and my articles.
Step three: structured data
Structured data is a block of labels inside your page that states facts in a format a machine reads without guessing. The common format is JSON-LD, and you never see it when you look at the site.
A good set for a small business says: this is my business name, this is my address, this is my phone number, these are the services I offer, these are the questions I get asked and the answers. That last one is called FAQPage, and it is the format most likely to get quoted back verbatim.
I put structured data on every page of my site, including a person record for me, because the assistant should be able to connect the business to a human with a name.
Step four: write like a practitioner
Google uses a phrase for this that stuck: Experience, Expertise, Authoritativeness and Trustworthiness. Usually shortened to E-E-A-T. Models weigh the same signals when they decide whom to cite.
In practice it means three things:
- Say who you are. A named person with a real background beats a logo and a slogan.
- Say what you have done. A specific case beats an adjective. "I recovered a Mesa family farm's Facebook portfolio" is worth more than "trusted expert."
- Answer one question per section. Write the answer first, in one plain sentence, then explain it. That first sentence is the one a model will quote.
None of that requires you to become a writer. It requires you to stop hiding behind marketing language.
A seven-item self-check
Run this on your own site. You can finish it in twenty minutes.
- Fetch your robots.txt. Are the AI crawlers allowed, deliberately?
- Do you have an llms.txt at your domain root?
- Does your home page contain one plain sentence describing what you do and who you do it for?
- Is your phone number and service area in structured data, not just in a footer image?
- Do you have three or more real questions answered in FAQ format somewhere on the site?
- Does your site display its content with JavaScript turned off? If it does not, some crawlers see an empty page.
- Does your site name a real person with real credentials?
Anything you answered no to is a gap. Number six surprises people most often, because the site looks fine in a browser.
Where this fits with security
I know why a security consultant is writing about this, and it is not a pivot. Both problems have the same root: a machine is trying to decide whether your site can be trusted, and your site is not giving it an answer.
The hardening service I offer covers both sides. Firewall setup and tuning, security headers, and TLS configuration on one side. Crawler access, llms.txt, structured data, and content fixes on the other. It ends with a monthly report showing how visible you are in AI answers, so you can see whether any of it worked.
Work with me
Every engagement starts with a free 30-minute consult and a written quote. If you would rather try the self-check first, do it and bring me what you found.
Book a free 30-minute consult at /book, or call 602.501.0772. I answer the phone.
John Sabo — Lono Security Chandler, Arizona · Phoenix Metro · Remote everywhere
John Sabo
John Sabo — 30 years in cybersecurity, GoDaddy WAF architect
Work with me
Every engagement starts with a free 30-minute consult and ends with a written quote.
Book a free consult