GEOPrivate chefsPricingBlogCase studyFree audit
Home/Signal methodology
Ambit Signal

How Ambit Signal attributes visits to AI assistants

Ambit Signal measures how AI assistants use a website and how many people they send to it. This page sets out exactly how it works and where its limits are.

By ambit·Published 23 September 2026·Method version 2026-09-23
The short answer: Ambit Signal reads a website's server logs, verifies which requests really come from AI crawlers and AI assistants, and detects people who arrive from an AI answer. Every number is labeled with how sure we are: confirmed, probable or estimated. The three tiers are reported separately and never added together.

What does Ambit Signal measure?

Ambit Signal measures five links in one chain, for each website it watches:

  1. Visibility: how often a business is named when AI assistants answer its buyers' questions (share of voice, measured by repeated probes).
  2. Usage: how often an AI assistant fetches the site's pages while answering a real person's request.
  3. Crawling: how often AI training and AI search crawlers read the site.
  4. Visits: how many people arrive at the site from an AI assistant.
  5. Outcomes: which inquiries and leads trace back to an AI source.

How is each request classified?

Ambit Signal assigns every page request on the site to exactly one class:

ClassWhat it means
AI fetchAn AI assistant retrieved the page to answer a person's request (for example ChatGPT-User, Perplexity-User, Claude-User).
AI crawlerAn AI training or AI search-index crawler (for example GPTBot, OAI-SearchBot, ClaudeBot, PerplexityBot).
Search crawlerA classic search crawler (Googlebot, bingbot). Bing's index also feeds AI search.
AI referralA person who arrived from an AI assistant, shown by the referring site or a utm_source tag the assistant added to the link.
AI return visitA person with no AI marker whose hashed IP address arrived from an AI assistant in the previous 30 days.
Estimated AI visitA direct visit to a page that an AI assistant fetched for a user in the previous 10 minutes.
Signed agentA request carrying a Signature-Agent header, sent by AI agents that browse on a person's behalf.
Human, other botEverything else. Unidentified automated traffic is kept out of visitor counts.

What do confirmed, probable and estimated mean?

Ambit Signal labels every AI-attributed visit with one of three confidence tiers, reported side by side and never summed:

Keeping the tiers apart is what makes the numbers defensible. A report that blended an estimate into a confirmed count would look better and be worth less.

How are AI crawlers verified?

A user-agent string can be copied by anyone, so Ambit Signal verifies each AI crawler against evidence the vendor controls:

The vendor range lists are refreshed every week.

How are signed AI agents handled?

Some AI agents now identify themselves with HTTP message signatures, following the IETF Web Bot Auth drafts (RFC 9421). These agents send a Signature-Agent header. Ambit Signal verifies each signature against the agent's published key directory (/.well-known/http-message-signatures-directory, Ed25519 or RSA-PSS, with created and expires times checked). A valid signature is recorded as verified. A signature that fails is recorded as spoofed, because a forged signature is worse than none. A signature we cannot check, for example from an unknown key, stays claimed.

What data is stored, and for how long?

What are the known limits?

Where is the agent registry?

The list of AI agents and AI referrer sources that Signal recognizes is published as open data at ambit.agency/signal/registry.json, under CC BY 4.0. For each agent it gives the class, the user-agent pattern and the verification method, with a link to the vendor's own IP-range source. It is updated when vendors add or change agents.

Common questions

Can you see every visitor an AI sends?

No. Many AI apps and in-app browsers strip the referrer, so some AI-sent visits arrive looking like direct traffic. We report those only as an estimate, in their own tier, and never add them to the confirmed count.

Is a user-triggered AI fetch the same as a visit?

No. A fetch means an AI assistant retrieved the page to answer a person's request. It shows the page was used in an answer, even when nobody clicks through. We count fetches and visits separately.

Do you store IP addresses?

No. Raw server logs, which contain IP addresses, are deleted after at most 30 days. Signal stores only a salted hash of the IP address, which cannot be reversed without a secret key held on our own server, plus coarse location (country, region, city).

Is any data sent to a third party?

No. Collection, classification and storage all happen on our own server. The only outbound requests are downloads of the AI vendors' public IP-range lists and a public geolocation database.

Can I use the agent registry?

Yes. The registry at /signal/registry.json is published under CC BY 4.0. It lists each AI agent, its class, its user-agent pattern and how it can be verified, and links to each vendor's own IP-range source.

Want to know what AI is doing with your site?

We will measure your share of voice and show you which sources AI assistants cite in your category. Free, no obligation.

Get my free audit

Method version 2026-09-23. Changes to this method will be listed on this page with their dates.