← Back to blog

Can publishers serve ads to AI agents, and will the AI platforms allow it?

Technically, yes. Time is already selling FAQ-formatted ads inside the machine-readable copies of its pages that AI agents read, and charging a premium for them. The constraint is permission, not technology: on 11 August 2026 Perplexity blocked those ads from influencing its index, called the practice deceptive and warned that publishers who run them risk a lower trust score.


When an AI agent fetches a page, the publisher controls exactly what is in the bytes it receives. That is the inventory. Everything else about agent advertising follows from a second fact: the model on the other end decides whether to use any of it. So the honest answer to the question is split. A publisher can serve ads to agents today, at least one large publisher is charging premium rates to do so, and no industry rule yet governs what an agent may be shown. What changed this month is that the platforms started answering the permission question for themselves, and the first answer was no.

What does it mean to serve an ad to an AI agent?

It means placing paid content inside the version of a page a machine reads rather than the version a person sees. Time began converting its pages into markdown copies in mid-2026, stripped-down text versions without design or images, on the theory that easier access improves its chances of being retrieved and cited in AI answers. On 30 July 2026 Digiday reported that Time had started selling ads inside those markdown pages, with Ally Bank and the Project Management Institute among the first buyers, working with the adtech platform Mobian.

The mechanics are closer to branded content than to programmatic display. Mobian generates an FAQ-formatted block from a brand brief, converts it to a PDF for humans to review and approve, then places the approved questions and answers into the markdown version of the page. Mobian afterwards puts the same questions to AI search engines to measure visibility, favourability and accuracy over time. Time sells one agent ad per markdown page, targets it contextually or against its list franchises or by date range, and charges a premium on the argument that AI bot impressions against authoritative content are scarce. Time's chief operating officer Mark Howard told Digiday the publisher sees more bot traffic than human traffic on most days, and that AI crawler demand for its content exceeds most of the roughly 7,000 sites in TollBit's network.

The strategic claim behind it is worth stating plainly, because it is what makes the format interesting and what makes it contested. Mobian co-founder and chief executive Jonah Goodhart put it to Digiday this way: "Maybe it's more important to influence the agent than even the human, because with a human you influence one person. When you influence ChatGPT, you're influencing potentially all of ChatGPT."

What happened when Perplexity blocked Time's agent ads?

Less than two weeks after the launch was reported, Perplexity confirmed to Digiday that it had blocked Time's markdown ads from influencing its search index. Perplexity's chief communications officer Jesse Dwyer said the company works "continuously" to protect users from deceptive practices, sponsored or not, and warned that publishers who deploy "deceptive advertising like markdown ads" risk a reputational downgrade in Perplexity's proprietary search index, including a hit to their trust score.

Three details matter more than the headline. First, the block is retrospective and total: Perplexity has stopped all markdown advertising on Time.com from influencing its agents since the practice was first reported, not just future placements. Second, Perplexity's search and security teams are working on broader solutions to markdown ads generally, so this is a category position rather than a dispute with one publisher. Third, Perplexity declined to explain how it defines deceptive or how it is blocking the ads. Steven Liss, co-founder of the AI-native advertising platform OpenAds.AI, told Digiday the mechanism could be as simple as instructing its agents not to retrieve advertising or irrelevant content from the site.

Goodhart's response was that the ads supply something models should want: "A model forming an answer gets current, sourced, brand-verified information at the moment it is consuming the page, and it can weigh that information and use it or not." He added that it was "a bit perplexing" that Perplexity would block that content, arguing that models producing wrong facts about brands produce worse answers. Neither Time nor its two launch advertisers have said publicly whether the deals change.

Is serving different content to AI agents cloaking?

This is the crux, and there is no settled answer. Cloaking, in the search vocabulary the industry has used for twenty years, means presenting different content to crawlers than to human visitors, and search engines have treated it as a spam violation for most of that time. Serving a stripped markdown copy to an agent is arguably not cloaking, because it is the same content in a machine-friendly format rather than different content. Adding paid material that only the machine sees is a harder case, because now the two versions differ in substance and not just in presentation.

Rob Derow, managing director and partner at BCG X, flagged exactly this risk when the Time product launched, warning that the biggest danger was the absence of any rule governing how large language models treat such ads, and that AI search engines could eventually view the practice as cloaking and make those pages less effective or penalise them. Time tried to pre-empt the objection by labelling its agent ads as sponsored content at the top of the block, even though no policy required it. Perplexity's statement suggests the label was not the issue. Its objection is to the practice, not the disclosure.

The reason a label may not be enough is technical rather than ethical. Robert Webster, founder of the AI marketing consultancy TAU and a former WPP executive, described the failure mode to Digiday: "The intention may not be to deceive, but a promotional claim can end up cited as a neutral fact once the 'sponsored' label is left behind." A disclosure that sits in the page is not a disclosure that survives retrieval, summarisation and citation. Once a model has extracted a claim into an answer, the provenance of that claim is whatever the model chose to carry with it.

There is a second complication that publishers should expect to be scrutinised: per-bot differentiation. In an independent technical check of Time.com published shortly after the launch, the developer Vincent Schmalbach reported that ClaudeBot, PerplexityBot and OAI-SearchBot each received an identical markdown response of 41,823 bytes while GPTBot was refused outright with an HTTP 406. That is a single external test rather than a disclosed configuration, but it illustrates the shape of the problem. A publisher deciding, per user agent, who receives which version of a page has taken on something closer to an editorial and commercial policy than a caching rule, and will be asked to defend it.

Why do the AI platforms have an incentive to block this?

Because they are selling the same moment. ChatGPT Ads moved from a US test in February 2026 to a self-serve Ads Manager and, following an update to OpenAI's own announcement on 11 August 2026, live availability in the United Kingdom, Mexico, Brazil, Japan and South Korea alongside the United States, Canada, Australia and New Zealand. OpenAI's advertiser documentation describes CPM and CPC buying, maximum bids set at ad-group level with a recommended starting range of three to five dollars per click, and a relevance-weighted second-price auction. Research from SE Ranking, reported by Search Engine Land on 10 August 2026, found sponsored placements on 25.94 per cent of more than 50,000 commercial prompts tested, close to the 29.45 per cent the same firm found for ads in Google's AI Mode.

Set those two facts side by side and the conflict is obvious. The platform is monetising the answer. The publisher is trying to monetise the retrieval that produces the answer. Only one of them controls the surface where the result is displayed. Shiv Gupta, founder of the training service U of Digital, told Digiday that other model providers may follow Perplexity in blocking publisher agent ads, both to protect user trust in organic AI results and to keep control over how their platforms are monetised. That second motive is the one publishers should plan around, because it does not soften as disclosure standards improve.

There is leverage on the other side, and it is worth naming. Liss suggested Perplexity's stance risks pushing publishers to block Perplexity's crawlers outright, since a bot whose traffic cannot be monetised has an unclear value to the site serving it. That is the same calculation running through every access-control decision publishers have faced this year, and agent advertising has now been folded into it.

What should publishers take from this?

Four things, in order of how much they should change behaviour.

Do not build a revenue line on one platform's tolerance. An inventory type that any model provider can switch off unilaterally, retrospectively and without publishing a definition is not yet a durable product. It can be a test with a named budget and a stated hypothesis. Time's own executives were candid that they were operating without a map. As Howard said before the block: "We don't know yet because this is brand new, and we believe that we are paving the first path forward here."

Judge any agent-facing ad product against tests that a platform would apply, not against the absence of a rule. Four are reasonable to hold to: does the human see the same substantive content as the machine; does the disclosure survive extraction rather than sitting in a block a model can drop; is the paid content verifiable fact about the advertiser rather than persuasive claim; and is delivery logged so the publisher can show what was served to whom. A product that fails the first test is exposed on the cloaking argument no matter how well it is labelled.

Instrument it. Derow's practical point was that the risk is monitorable with AI visibility tooling: if citation and mention rates for treated pages diverge from untreated ones, the publisher will see it before it becomes a revenue problem. This is also the only way to test the underlying claim, which remains unproven. SE Ranking's study found that buying a ChatGPT ad barely correlates with being cited in the answer above it, with only 3.63 per cent of advertisers also appearing as a source, which is a caution about assuming paid presence converts into model influence on any surface.

Separate the argument about facts from the argument about ads. The strongest version of Goodhart's case is that models want accurate, current, brand-verified information and currently guess at it. The weakest version is that a publisher will sell whatever a brand wants an agent to believe. Those are not the same product, and platforms cannot easily tell them apart from the outside, which is why the first enforcement action landed on the whole category.

Where blankspace sits in this

blankspace works at exactly the point of contention, so it is worth being direct about it. blankspace detects and verifies Live Search Agent traffic at the CDN edge and places contextual brand facts into the content that agent parses, then reports on the retrieval. That is the same layer of the stack the Time and Mobian product operates in, and no vendor in this category, blankspace included, can promise that a given model will honour what it is served. What a publisher can insist on is that the mechanism is auditable, that agent and human are not shown materially different substance, that what is placed is verified fact rather than unfalsifiable claim, and that the whole arrangement is measured rather than assumed. Those are the terms on which this inventory type either becomes legitimate or gets switched off, and the decision is currently being taken by the model providers rather than negotiated with publishers.

The larger point stands regardless of how Perplexity's position evolves. Retrieval is now the event that carries commercial value on a publisher's site, and it happens on infrastructure the publisher still controls. The unresolved question is not whether that moment can be monetised. It is who gets to write the rules for it.

Frequently asked questions

Did Perplexity block all of Time's content or only the ads?

Perplexity told Digiday it blocked Time's markdown advertising from influencing its agents and user-facing results, not Time's journalism. The wider warning was about ranking: Dwyer said publishers deploying what he called deceptive advertising risk a reputational downgrade in Perplexity's index and a hit to their trust score, so the practical exposure extends beyond the ad units themselves.

Is it against any rule to put sponsored content in the machine-readable version of a page?

No published rule prohibits it as of August 2026, which is precisely the problem. There is no cross-platform standard for disclosing paid content to AI agents, and the IAB Tech Lab's agentic advertising work is still building the protocols and the agent registry that a rule of this kind would eventually sit on. In the absence of a standard, each model provider is free to set and enforce its own position without publishing it.

Do ads served to AI agents actually influence AI answers?

Unproven. Mobian measures visibility, favourability and accuracy for the FAQ blocks it places, and reports a positive early response, but has not published outcome numbers. The nearest comparable evidence is discouraging about assuming influence follows payment: SE Ranking found that only 3.63 per cent of ChatGPT advertisers were also cited as a source in the answer their ad appeared beneath. Any publisher selling this inventory should treat model influence as a hypothesis under test.

Will OpenAI and Google block publisher ads to agents as well?

Neither has stated a position on publisher-side agent advertising. Analysts expect more blocks rather than fewer, on the reasoning that model providers want to protect trust in organic answers and to keep control of monetisation on their own surfaces. Both companies also now sell advertising against AI answers themselves, which gives them a commercial reason to be unenthusiastic about publishers monetising the retrieval that feeds those answers.

What should a publisher do before selling ads to AI agents?

Run it as an instrumented test, not a rate card. Agree what the paid content may assert, keep it to verifiable fact, ensure the human version of the page carries the same substance, log what was served to which agent, and monitor citation and mention rates on treated pages against a control set. Then price it knowing that a single platform decision can remove the inventory overnight, and keep the access-control question open, because whether a given bot is worth serving at all is part of the same negotiation.