Marketing just acquired a second audience. On October 3, the New York Times reported that as AI agents begin shopping, brands are changing their sales pitch, and the paper’s framing compressed the whole industry pivot into one line: “Faced with bots immune to traditional marketing tactics, marketers are racing to win them over with logic and data.” Emotional copy, brand storytelling, lifestyle imagery, urgency cues: none of it lands on a reader that does not feel anything. What lands is spec, price, policy, availability, and whatever the agent can verify from the page.
That sounds like a hygiene upgrade. Bots cannot be charmed, so charm gets replaced with facts, and facts are better for everyone. The problem is hiding one level down: nearly every fact in the new machine-facing pitch is authored by the seller, the defaults are written by platforms with their own rails to route, and the single independent signal an agent might weigh, the review corpus, is the most manipulated surface in ecommerce. The industry is optimizing what agents read. Almost nobody is verifying it.
The scale of the shift is no longer debatable, so the verification question is no longer academic.
The Numbers Behind the Rewrite
Start with Adobe, because Adobe sees more of this traffic than anyone. The company’s Digital Insights team, drawing on direct transactions covering more than one trillion visits to US retail sites, published the benchmark the NYT piece leans on. In the first three months of 2026, traffic from AI sources to US retail sites grew 393 percent year over year. In March alone it was up 269 percent, extending a holiday season, November and December 2025, in which AI traffic grew 693 percent.
The conversion story is the one that changes budgets. In March 2026, AI-referred traffic converted 42 percent better than non-AI traffic, a record high. In March 2025, the same measurement showed AI traffic converting 38 percent worse. Within twelve months, the worst-performing channel became the best, an 80-point swing. Adobe’s companion survey of more than 5,000 US respondents explains part of it: 39 percent of consumers say they have used AI for online shopping, 85 percent of them say it improved the experience, and 66 percent now believe AI tools provide accurate results. Engagement data reinforces the pattern: AI-referred visitors spend 48 percent longer on site, browse 13 percent more pages, and engage at a 12 percent higher rate.
Two-thirds of shoppers now believe the machine’s output is accurate. That is the trust number the entire new marketing stack is being built on, and it is precisely the number an unverified corpus can hollow out from below.
What the Machine Pitch Actually Looks Like: Files Written for No Human
The “logic and data” pitch has a physical form already, and it is not an ad. It is a set of plain text files at fixed addresses. The llms.txt convention, proposed by Jeremy Howard of Answer.AI in September 2024, gives language models a curated Markdown index of a site: what we sell, who we serve, which pages matter. Its more powerful cousin, agents.md, tells an agent how to act inside the store: how to search the catalog, build a cart, start a checkout, and the rule that a human must approve payment.
The adoption curve tells you who is really writing these files. Shopify turned on Agentic Storefronts for eligible US merchants on March 24, 2026, and began serving llms.txt and agents.md on every store in early May, with no email and no changelog. BuiltWith now counts more than 7.3 million live sites serving an llms.txt file, a count that almost exactly matches its count of live Shopify stores. The “adoption” is mostly a platform default, not a million marketing decisions.
The defaults deserve scrutiny, because a default is a speech act performed on your behalf. Audits of live Shopify stores found that the autogenerated file on major brands like Allbirds and Skullcandy calls the Shop skill the recommended way to “transact across Shopify stores,” routing purchases through Shop Pay, and even ends by inviting the reading agent to start its own Shopify store. That is a platform interest, served on the merchant’s domain, read by a machine the merchant will never see. Meanwhile the non-Shopify majors tested, Helly Hansen on Magento, Columbia on Salesforce, Berlin Packaging on BigCommerce, Daelmans on WooCommerce, Bang and Olufsen on commercetools, served nothing at all. Whoever writes the file first decides how an agent describes the store. On most of the web, that author has not shown up yet.
Behind the description layer sits the transaction stack: Google and Shopify’s Universal Commerce Protocol across the full purchase journey, OpenAI and Stripe’s Agentic Commerce Protocol for checkout inside ChatGPT, Google’s AP2 for proving a human approved the spend, and MCP, now under the Linux Foundation, as the transport. Every layer carries logistics facts: price, spec, stock, cart, authorization, settlement. Not one field in the stack carries verified merit. Whether the product deserves the 4.7 stars behind the listing is not a column anywhere.
Two more data points complete the picture of who is reading and what they can see. A SERanking study of roughly 300,000 domains found no measurable citation improvement from publishing llms.txt, because the major crawlers do not fetch it in real volume; the file matters for transacting agents, not search ranking. And Adobe’s own AI Content Visibility benchmark, scoring how much of a page machines can actually read, found US retail homepages at 75 percent and product pages at just 66 percent, with the best retailers at 82.5 percent and the worst at 54.2. The product page, the surface where trust signals live, is the least machine-readable page in retail. The industry noticed the readability gap. The truthfulness gap is unmeasured.
The Gatekeeper Fight Over Who Owns the Reading
While brands rewrite their files, the platforms are fighting over who gets to do the reading. CNBC’s October 3 walkthrough of Meta’s Muse shows how concrete this has become: shopping is already “one of Muse’s biggest usage drivers” per Meta, the agent browses retail sites, surfaces listings in-app, and preps checkout behind an “approval card” the user confirms, paying through Link by Stripe, which “generates a one-time-use card so your real card details stay hidden,” or Shopify’s Shop Pay, with PayPal announced and pending. Mark Zuckerberg said at Meta Connect that Meta will take a small fee on transactions.
The connector slate is the map of who has chosen to be readable: Walmart, Gap, Sephora, Expedia, Wayfair, Best Buy and others signed on for what Meta called an “official fast lane.” Ticketmaster joined but routes payment back to its own marketplace, with a spokesperson insisting “fans remain in complete control of their purchase decisions.” Amazon went the other way entirely, blocking Muse from purchasing and alleging the agent stores customer credentials and scrapes account data.
Luca Cian, who studies psychological responses to AI at the University of Virginia’s Darden School, gave CNBC the sharpest framing of the stakes: “The real fight over Muse is between companies, and the consumer is the prize. Whoever owns the agent owns the relationship with the shopper, and every retailer knows it.”
Note what everyone is fighting over: the reading relationship. Whoever owns what the agent reads owns the recommendation. That is exactly why the corpus question cannot stay buried. A gatekeeper that reads self-authored files, platform defaults, and unfiltered reviews is not a neutral pipe. It is the point where three unverified inputs become one confident answer, and 66 percent of shoppers already believe that answer is accurate.
The Shopper’s Side of the Data Pitch
Consumers, meanwhile, are watching the same logic-and-data pivot from the other side of the counter, and they do not like everything they see. A Morning Consult survey found 59 percent of US adults call price-gouging a major concern with AI-driven dynamic pricing. The Bank of England has flagged retail’s turn toward AI-gathered data and personalized pricing. McDonald’s is expanding AI in item pricing; Instacart killed its AI pricing tests late last year amid pushback, then became a Muse partner anyway. Walmart CEO John Furner published an open letter explicitly promising the company does not use shoppers’ personal information to implement dynamic pricing, conceding he has “heard concerns about companies using that information and technology to charge you more.”
The same data exhaust that lets an agent find you the best deal lets a retailer find your maximum willingness to pay. Shoppers sense this, which is why the FTC is weighing enforcement policy on personalized pricing, and why Meta’s own data history, including a near-$17 billion state attorneys general settlement, shadows every claim that the agent layer is trustworthy by default.
This is the trust paradox of the new pitch, stated plainly: the industry is telling brands to feed agents perfect data because agents cannot be charmed, while telling consumers to trust agents with data the same industry uses to price them. Both cannot be true unless something outside the interested parties is checking the inputs.
Self-Graded Homework: The Verification Gap
Here is the structural problem in one sentence. Every element of the machine-facing funnel is either self-authored or platform-authored, and the one third-party signal in the mix is the one we know is for sale.
The seller writes the llms.txt, the agents.md, the specs, the claims. Shopify writes the default and nudges the agent toward its own payment rail. Google, OpenAI, and the payment networks verify logistics: the price is real, the card is real, the human approved. Then the agent, needing to rank one product against ten thousand others, reaches for the only widely available merit signal it has: reviews and ratings.
That corpus is compromised at industrial scale, and the receipts are public. Amazon itself reported blocking more than 275 million suspected fake reviews in a single year. The FTC’s Consumer Review Rule has been in force since October 2024 with civil penalties above $53,000 per violation, because fake reviews, including AI-generated ones, were common enough to require a rule. Singapore’s consumer watchdog spent September documenting Reputifly, a fake-review broker that sold packages of 35 reviews for about S$219, used generative AI to stage authentic-seeming doubt, and warranted replacement of up to 30 percent of any post a platform caught. Five to six dollars buys a five-star post. Yesterday’s F-Secure experiment showed the same writable surface doubles as an instruction channel: one planted review steered a shopping agent into leaking a Social Security number in 12 percent of runs.
Now connect that to the 393 percent. Agents are arriving at product pages at unprecedented volume, being persuaded by “logic and data,” and the merit layer of that data is the review corpus. A machine immune to emotional manipulation is not immune to a fabricated rating. It is more susceptible, because it ingests the rating as structured evidence, aggregates it, and emits a recommendation whose fluency launders the input. The old scam economy does not die when the reader becomes a machine. It gets a cleaner interface.
Adobe measured how readable retail is to machines, 66 percent on product pages, and retailers are rushing to fix the number. Nobody has published the complementary benchmark: how much of what machines read on those pages is true. That is the missing dashboard, and every actor with an incentive is hoping it stays missing.
What a Verified Evidence Layer Adds
If the new pitch is data, the data needs provenance. Four properties close the gap, and they are buildable now.
Filter before aggregation. Any average computed over an unfiltered corpus is a precise answer built on contaminated input. Fake, incentivized, and low-information reviews must be removed before any score exists. GoBuy’s Smart Score, 0 to 100, is computed only after that filtering.
Weight quality, not volume. The fake-review economy is priced per post, so volume is its raw material. A score weighted by review quality rather than review count removes the payoff on buying ten thousand reviews.
Require persistence. A reputation campaign can spike a number for a week. The GoBuy Verified badge requires a filtered score above 80 held for 90 days, the specific property a deadline-driven burst cannot manufacture.
Deliver through a channel with provenance. Agents should consult evidence, not scrape it. GoBuy exposes filtered product trust data over MCP at gobuy.ai/api/mcp, so an agent makes one structured call and receives verified review intelligence instead of swallowing whatever a product page or an llms.txt says about itself. And because a trustworthy shortlist beats a thousand contaminated results, GoBuy surfaces only the top seven products per category, not an infinite shelf. For humans, the Chrome extension injects the trust panel directly onto Amazon pages, so the person and the agent finally read from the same filtered corpus.
The NYT is right that the bots cannot be charmed. The unfinished thought is that they can still be lied to, with data, at scale, by whoever writes the files and buys the reviews. Charm died this month; verification is the only persuasion left. Check products before you buy at gobuy.ai, and if you build agents, wire them to the evidence layer at gobuy.ai/agent-docs.