Skip to main content
Decentralised News Logo
The Agentic Web Readiness Index 2027: Is Your Website Ready for AI Agents?
Agentic Finance

The Agentic Web Readiness Index 2027: Is Your Website Ready for AI Agents?

By

Measure whether your website is ready for AI agents with DN’s 100-point index covering discovery, structured data, actions, permissions, payments and trust.

DN Agentic Finance Research · Batch 2, Pillar 2

DN Agentic Web Readiness Index 2027

Most websites are readable by browsers but unreliable for agents. DN introduces a 100-point system for measuring whether a site can publish discoverable capabilities, prove who controls them and support safe, auditable execution.

Published: September 20, 2026 · Updated: October 9, 2026 · Index: DN-AWRI v1.2 · Update cadence: Quarterly

What Matters

Agent readiness is not the same as SEO. Search engines mainly need to crawl, interpret and rank information. An AI agent may also need to compare an offer, understand terms, authenticate, request permission, execute an action, pay and recover from failure. A website becomes agent-ready only when machine understanding is paired with bounded, auditable action.

THE DN VERDICT

The Web Has a Machine-Action Gap

The human web communicates through pages, menus, buttons and visual context. Agents need explicit entities, stable identifiers, declared capabilities, predictable inputs, permission boundaries and machine-readable outcomes. A beautifully designed website can be nearly unusable to an agent. An unremarkable site with structured content and a dependable API may be far more valuable in the agentic economy.

Readable is not actionableA model may understand a product page yet have no safe way to reserve, purchase or modify anything.
Accessible is not authorizedA crawler being allowed to fetch a URL does not grant an agent permission to create an account or spend money.
Automated is not trustworthyAn endpoint without limits, confirmations, receipts and reversal rules expands the agent's blast radius.

The Eight-Layer DN Agentic Web Model

LayerWeightWhat DN measuresFailure signal
1. Discovery and capability publication14Crawlability, canonical URLs, sitemaps, ARD discovery, authoritative-domain catalogs and federated registriesCapabilities are hidden, stale, duplicated or inconsistently addressed
2. Semantic clarity13Accurate JSON-LD, explicit entities, prices, availability, dates, authorship and policiesThe agent must infer decisive facts from layout or prose
3. Action interfaces14Documented APIs, structured forms, MCP tools, A2A interfaces or equivalent action surfacesOnly brittle visual clicking can complete a task
4. Repository instruction readiness10AGENTS.md presence, scope, nested consistency, build and test commands, tool limits, secret handling and freshnessCoding agents guess how to build, test, change or secure the software
5. Permission and identity14Authentication, scopes, consent, least privilege, delegated authority and revocationAccess is all-or-nothing or authority cannot be proven
6. Transaction readiness13Machine-readable totals, payment options, confirmation, receipts, refunds and idempotencyCosts change silently or repeated requests duplicate a purchase
7. Reliability and recovery10Error schemas, status visibility, retry rules, cancellation, rollback and support escalationThe agent cannot distinguish pending, failed and completed actions
8. Trust and verification12Domain ownership, publisher verification, cryptographic trust metadata, provenance, audit logs and human appealThe publisher or capability cannot be verified, challenged or contained
FREE INTERACTIVE TOOL

DN Agentic Web Readiness Audit

Check only controls that are implemented and tested. The result is a diagnostic, not a certification.

0/100

Agent-Opaque

The site is primarily human-facing and machine interpretation or execution is unreliable.

Readiness gates: Discoverable: fail · Verifiable: fail · Executable: fail · Transactable: fail

ARD verification: Not published

Priority fixes
  • Discovery: Publish deliberate crawl rules, canonical URLs and an accurate sitemap.
  • Semantics: Add valid structured data and make decisive facts explicit.
  • Actions: Create a documented, schema-validated interface for priority tasks.

How the Score Works

DN-AWRI v1.2 = D(14) + S(13) + A(14) + I(10) + P(14) + T(13) + R(10) + V(12)

Scores are additive, but the headline score is not enough. The Instruction Readiness layer improves execution readiness but cannot satisfy discovery, authorization, transaction or publisher-verification gates by itself. DN reports four independent gates: Discoverable, Verifiable, Executable and Transactable. A site cannot receive transactable status unless it exposes a structured action interface, scoped authority, pre-commitment pricing and transaction evidence. An 82-point information site may be highly agent-readable without being safe for autonomous purchasing.

0–24: Agent-OpaqueBuilt primarily for human browsing. Machine interpretation is unreliable.
25–49: Agent-ReadableDiscoverable and partially structured, but actions remain fragile.
50–74: Agent-OperableCore tasks are structured, although permission or recovery gaps remain.
75–89: Agent-TransactableAgents can perform bounded economic actions with evidence and controls.
90–100: Agent-NativeDiscovery, action, trust and recovery are designed as one machine-facing system.

ARD: The Missing Discovery Layer

Agentic Resource Discovery (ARD) is an emerging approach for publishing an authoritative ai-catalog.json under an organization’s own domain. A catalog can describe MCP servers, A2A agents, OpenAPI tools, agent skills, nested catalogs, verification metadata and native connection endpoints.

ARD discovers and verifies capabilitiesIt helps agents locate machine-facing resources and connect them to an authoritative publisher domain.
MCP connects tools and resourcesIt standardizes how AI applications interact with exposed capabilities; it does not independently establish publisher trust.
A2A supports agent interactionAgent cards describe identities and capabilities for agent-to-agent coordination.
OpenAPI describes conventional APIsIt declares operations, inputs and outputs, but does not prove authorization, ownership or reliability.

ARD is not a replacement for MCP, A2A or OpenAPI. It is a discovery and verification layer that can point to those interfaces.

What Existing Standards Solve, and What They Do Not

MechanismUseful contributionNot sufficient for
robots.txtStandardized crawler access rules under the Robots Exclusion ProtocolDelegated authority, transaction permission or contractual consent
Schema.org / JSON-LDExplicit entities, attributes, relationships and potential actionsProving an endpoint is secure, current or authorized for autonomous execution
llms.txtA proposed convention for presenting concise, model-friendly site resourcesA universal authorization or security standard; adoption and interpretation vary
OpenAPI and APIsStructured inputs, outputs, authentication and predictable programmatic accessSafe delegation unless scope, confirmation and recovery are designed explicitly
MCPA standardized method for AI applications to connect with tools, resources and workflowsTrusting every exposed tool or eliminating the need for least privilege and validation
WCAGAccessible, operable and understandable experiences that often improve machine clarityMachine payment, identity, task state or agent-specific governance

DN treats llms.txt as an emerging convention, not a guaranteed ranking factor or authorization mechanism. Publishing one does not make a website agent-ready.

NEW IN DN-AWRI v1.2

AGENTS.md: The Repository Execution Layer

AGENTS.md is an open Markdown format for telling coding agents how to work inside a software repository. It can declare project context, build commands, tests, code conventions, security restrictions, pull-request rules and other instructions normally explained to a new developer. Nested files can provide narrower instructions for subprojects; the nearest applicable file takes precedence, while an explicit user instruction remains higher priority.

This is a material readiness signal for organizations whose products, APIs, MCP servers or agent services are maintained by software agents. It reduces repository exploration, prevents avoidable build and test failures and makes operational restrictions explicit. It does not publish a public capability, verify a publisher, authorize an action or secure a payment.

DiscoveryARD, catalogs and registries help external agents find capabilities.
ConnectionMCP, A2A and APIs expose callable tools and agent interfaces.
Repository executionAGENTS.md tells coding agents how to work safely in the codebase.
AuthorityIdentity, permissions and payment controls determine what an agent may do.

DN Repository Instruction Readiness Test

  1. Root discovery: a current AGENTS.md exists at the repository root.
  2. Scope clarity: nested files identify the directories and tasks they govern without unresolved conflicts.
  3. Executable setup: install, build, lint and test commands are complete enough to run.
  4. Verification: required checks and acceptance criteria are named.
  5. Security boundaries: secrets, production data, destructive operations and prohibited tools are addressed.
  6. Change discipline: code, documentation and pull-request expectations are explicit where relevant.
  7. Freshness: commands and paths match the current repository and are reviewed after material architecture changes.

Hard rule: the mere presence of AGENTS.md earns no automatic trust badge. DN must validate that referenced commands, scopes and restrictions are internally consistent and operational.

The Agent Discovery Protocol Stack

LayerPrimary purposeWhat it does not prove
ARDPublishing, discovering and verifying capabilitiesThat a capability performs reliably
MCP RegistryFinding registered MCP serversThat every server is secure or operational
MCPConnecting AI applications to tools and resourcesThat the publisher should be trusted
A2A Agent CardAdvertising an agent’s identity and capabilitiesThat tasks will be completed successfully
OpenAPIDescribing API operations and schemasThat an agent is authorized to use them
Agent marketplaceCommercial discovery and distributionIndependent reliability or ownership
Traditional directoryHuman-oriented listings and comparisonsEndpoint freshness or verified execution

The New Funnel: From Search Visibility to Agent Selection

Be discovered

Stable URLs, crawl rules, sitemaps and references allow an agent or retrieval system to locate the relevant resource.

Be understood

Structured entities, precise language, visible evidence and consistent identifiers reduce inference risk.

Be shortlisted

Price, availability, jurisdiction, reliability, policy and proof must be comparable with alternatives.

Be authorized

The agent proves who delegated the task and receives only the authority required to complete it.

Be transacted with

The site exposes a bounded action with known total cost, confirmation, receipt and repeat protection.

Be accountable

Every material action can be inspected, cancelled, disputed or escalated to a human.

DN Alpha Thesis: The Next SEO Metric Is Executability

Human traffic rewards attention. Agent traffic will increasingly reward decision confidence per unit of machine effort. The commercial winners may not be the sites producing the most content. They may be the sites that make accurate comparison and safe execution cheapest for an agent. DN calls this Machine Decision Yield: verified decision value divided by the tokens, latency, uncertainty and action risk required to obtain it.

Verified Capability Yield

Verified Capability Yield = successful verified executions ÷ discovery attempts

This DN metric measures whether published capabilities produce verified outcomes rather than merely appearing in a catalog. Supporting measurements include discovery success rate, publisher-verification rate, connection success rate, paid execution success rate, median discovery-to-execution time, cost per successful execution, stale capability rate and human-rescue rate.

Practical Roadmap by Organization

PublishersPrioritize authorship, dates, citations, canonical entities, article schema, accessible tables and stable update histories. Optimize for accurate extraction before autonomous action.
Commerce sitesExpose price, stock, variants, delivery, returns and total cost. Build idempotent cart and checkout interfaces with explicit confirmation.
Financial platformsAdd identity, jurisdiction, suitability, spend and loss limits, transaction simulation, audit logs and emergency revocation.
SaaS productsMaintain OpenAPI or MCP interfaces, scoped OAuth, stable error taxonomies, sandbox environments and durable task status.
Small businessesStart with structured services, prices, hours, locations, booking inputs and human escalation. Do not automate payment before the information layer is dependable.
Public institutionsProvide authoritative identifiers, accessible documents, versioned policies, multilingual content and clear rules separating information from official submission.

What Would Prove This Thesis Wrong?

The index would matter less if general browser agents become so reliable that structured interfaces deliver no measurable improvement in completion, cost or safety. It would also weaken if a single closed platform intermediates nearly all agent transactions, making open-web readiness commercially irrelevant. DN will test the thesis by tracking whether higher scores correlate with lower task failure, faster completion, fewer human rescues and higher verified conversion.

Methodology and Limitations

Version: DN-AWRI v1.2, September 2026. The index evaluates public and organization-reported controls across eight weighted layers, including repository instruction evidence where an applicable software repository exists. The self-audit above is educational. A verified DN benchmark requires technical inspection, structured-data validation, catalog and endpoint tests, repeated task execution, permission review and failure-recovery testing.

Repository evidence: Instruction Readiness is assessed from applicable root and nested AGENTS.md files, the current repository structure and reproducible setup and verification commands. Public scoring records the repository and commit tested, applicable instruction paths, test date and commands excluded for safety or access reasons. DN does not execute destructive commands, expose secrets or treat prose restrictions as proof that technical controls exist.

Evidence boundary: The presence of ai-catalog.json, an ARD listing, MCP endpoint or registry entry does not prove that a capability is safe, operational or authorized. Verified readiness requires publisher validation, endpoint testing, permission review and repeated task execution. Scores should be reported with the date, tested pages, task set, user role, geography and authentication state.

Change log: Version 1.2, October 9, 2026, adds Repository Instruction Readiness as an eighth scored layer, introduces validated AGENTS.md controls and rebalances the index to preserve a 100-point total. Version 1.1 added Agentic Resource Discovery, authoritative-domain catalogs, federated registry discovery, publisher verification and paid MCP endpoint controls. Version 1.0 established the original model and maturity bands.

Primary Sources

Frequently Asked Questions

What is an agent-ready website?

An agent-ready website can be discovered and interpreted by machines and provides safe, structured ways to perform relevant actions with explicit permission, confirmation and recovery.

Is agentic web optimization the same as SEO?

No. SEO focuses primarily on search discovery and ranking. Agentic readiness also covers comparison, execution interfaces, delegated authority, payments, reliability and accountability.

Does structured data improve AI visibility?

Structured data gives machines explicit clues about entities and page meaning. It can reduce ambiguity, but no markup guarantees inclusion, ranking, citation or selection by an AI system.

Does a website need an llms.txt file?

Not necessarily. It is an emerging convention and may make selected resources easier to find, but it is not a universal requirement, ranking guarantee or permission system.

Does allowing an AI crawler authorize an AI agent to transact?

No. Crawl access governs retrieval. A transaction requires separate identity, authority, consent, scope and confirmation controls.

Does every business need an MCP server?

No. A documented API or well-structured form may be sufficient. MCP becomes useful when an organization wants compatible AI applications to discover and invoke defined tools or resources.

Does publishing an ai-catalog.json file make a website agent-ready?

No. It makes capabilities easier to publish and discover. Complete readiness also requires accurate metadata, publisher verification, secure interfaces, scoped permissions, reliable execution, payment controls and failure recovery.

What is the most important first step?

Make decisive information explicit and consistent: identity, offering, price, availability, terms, dates and contact or escalation routes. Safe action interfaces should follow a dependable information layer.

Can an information-only publisher score highly?

Yes. A publisher can be highly agent-readable and trustworthy without offering transactions. DN reports maturity type and critical gates alongside the numerical score.

How often should readiness be tested?

Quarterly for stable sites and after any major redesign, API change, authentication change, checkout update or security incident.

Does AGENTS.md replace ARD, MCP or A2A?

No. ARD and registries support external discovery, MCP connects tools and resources, and A2A Agent Cards support agent-to-agent identity and capability publication. AGENTS.md supplies repository-level working instructions to coding agents.

Does every website need an AGENTS.md file?

No. It is most relevant when a website, API, MCP server or agent product has a software repository that coding agents maintain. Information-only sites without an applicable repository should be reported as not applicable rather than automatically unsafe.

Can a repository score highly because a file merely exists?

No. DN tests clarity, scope, command validity, security guidance, conflict handling and freshness. A stale or generic file can reduce confidence.

Can the DN score certify that a website is secure?

No. The self-audit is a diagnostic. Security certification requires deeper technical testing, threat modeling and evidence beyond public website signals.

Build for the Customers That Will Never See Your Homepage

The agentic web will reward sites that are clear enough to understand, structured enough to compare and controlled enough to trust.

Explore DN Agentic Finance Research
Disclosure: Decentralised News may earn revenue from selected commercial relationships. No affiliate availability changes the index methodology, score or editorial conclusion. This article is educational research, not legal, cybersecurity, investment or compliance advice. Independent testing is required before granting an autonomous system access to sensitive data, money or production infrastructure.

Get the most talked about stories directly in your inbox

Join the Decentralised News briefing for independent crypto, DeFi and AI analysis. No spam, unsubscribe anytime.