logo
|
Blog
    BotManagerBusiness Insight

    The Zero-Click Era: Can AI Really Be Trusted as a Customer?

    In the zero-click era, manage AI access to websites and APIs by allowing trusted agents while restricting, verifying, or blocking risky automation.
    Jul 20, 2026
    The Zero-Click Era: Can AI Really Be Trusted as a Customer?
    Contents
    SummaryDoes Zero-Click Mean Website Visitors Are Disappearing?What Is the Difference Between AI Search Crawlers and AI Agents?What Problems Can Arise from Allowing All AI Agents?Content and Data May Be Collected ExcessivelyEven Legitimate AI Agents Can Create System LoadAI Agents Can Affect Actual Business Processes, Not Just Retrieve InformationHow Should AI Agents Be Classified?1. Can the Identity of the Entity Accessing the Service Be Verified?2. What Is the Purpose of the Access?3. How Many System Resources Does It Consume?4. How Does It Affect Business Outcomes?How Should Allow, Restrict, Verify, and Block Policies Be Defined?How Should AI Agent Traffic Be Managed?Step 1. Identify the Automated Traffic Currently Accessing the ServiceStep 2. Classify Automated Traffic by PurposeStep 3. Set Policies for Individual Pages and APIsStep 4. Separate Detection Policies from Traffic ControlStep 5. Continuously Adjust PoliciesAfter Zero-Click, Businesses Must Design for Both Discoverability and Access ControlFAQQ1. Could Blocking AI Search Crawlers Negatively Affect GEO Visibility?Q2. Are All AI Agents Legitimate Bots?Q3. Can Legitimate AI Agents Also Cause Server Outages?Q4. Can robots.txt Manage All AI Agent Traffic?Q5. What Is the Difference Between BotManager and NetFUNNEL?

    Summary

    • The term “zero-click” has emerged as users increasingly receive answers generated by AI systems that collect and summarize information, rather than visiting websites directly.

    • Businesses need to allow search crawlers to access their content so that it can appear in AI search results. However, they should not grant the same level of access to every type of AI-based automation.

    • AI traffic serves different purposes, including search, model training, comparison, transactions, and attacks. It should therefore be classified according to identity, purpose of access, request volume, and business impact.

    • Bot management must evolve beyond simple blocking. Businesses will need to design policies that allow, rate-limit, further verify, or block each type of automated traffic.


    One of the terms that has repeatedly appeared in the AI marketing industry recently is zero-click.

    In the past, customers clicked links in search results, visited company websites, and browsed multiple pages to compare products or services. In generative AI search, however, AI systems summarize and answer questions using information from multiple sources. As a result, users can complete their research without visiting the original websites.

    According to research by Bain & Company, approximately 80% of consumers rely on AI-generated summaries or zero-click results for at least 40% of their searches. Consequently, traditional organic web traffic is estimated to decline by approximately 15% to 25%.

    This creates a new challenge for businesses:

    Businesses must allow AI systems to discover their content and cite it in their answers. However, they cannot give every type of automated traffic unrestricted access to their websites and APIs.

    For marketers, zero-click presents the challenge of determining how to include their brands in AI-generated answers. For service operators and security teams, however, it creates an even more complicated question:

    Should AI agents that visit websites on behalf of customers be treated as legitimate customers, or as bots that need to be controlled?


    Does Zero-Click Mean Website Visitors Are Disappearing?

    Zero-click refers to the decline in direct visits from users. However, it does not mean that all requests accessing corporate content on the internet will disappear.

    When users ask an AI system a question, the AI search service may explore webpages or reference a search index to locate the necessary information. In the future, AI agents may go beyond simply finding information. They may compare products on behalf of users, check inventory, and support reservation or purchasing processes.

    The differences between the traditional and AI-assisted customer journeys can be summarized as follows.

    Customer journey

    When performed directly by a person

    When AI is involved

    Information discovery

    The user clicks links in search results

    AI references multiple webpages and search indexes

    Product comparison

    The user visits each individual product page

    AI automatically collects and compares information from multiple products

    Price and inventory checks

    The user checks once or twice when necessary

    AI may repeatedly retrieve price and inventory data

    Reservations and purchases

    The user enters information directly

    AI may complete forms or transaction procedures on behalf of the user

    Status checks

    The user accesses the service directly

    AI periodically checks order, reservation, or delivery statuses

    Zero-click should therefore not simply be understood as a phenomenon in which website traffic disappears. Instead, it represents a shift in which the entities accessing websites expand from human users to search crawlers and AI agents.

    The problem is that not every automated request generated during this process provides the same level of value to a business.


    What Is the Difference Between AI Search Crawlers and AI Agents?

    Until recently, businesses primarily classified automated traffic into the following two categories:

    • Good bots, which perform useful functions such as search engine indexing

    • Bad bots, which perform activities such as scraping, account attacks, and macro-based automation

    However, the AI environment has created various types of automated traffic that fall between these two categories.

    OpenAI, for example, separately operates OAI-SearchBot, which is used for search visibility, and GPTBot, which may be used for model training. Website operators can allow OAI-SearchBot to access their content so that it can appear in search results and citations, while separately deciding whether to allow model training through their GPTBot policies.

    Similarly, beginning in July 2026, Cloudflare expanded its classification system so that AI-based automated access could be managed according to Search, Agent, and Training behaviors, rather than grouping all automated AI access under a single “AI Bot” category.

    Type of automated traffic

    Primary purpose

    Basic response approach

    Search crawlers

    Expose content in search results and AI-generated answers

    Allow access while managing crawling policies

    Model-training crawlers

    Collect data for AI model training

    Determine access according to the company’s data policies

    User-initiated AI agents

    Search for information, compare products, and carry out user requests

    Allow limited access after verifying identity and request volume

    Transactional AI agents

    Perform login, shopping cart, reservation, and payment processes

    Strengthen authentication and authorization verification

    Price and inventory scrapers

    Repeatedly collect pricing, inventory, and promotional data

    Apply rate limits or block access

    Malicious automation

    Perform account attacks, inventory hoarding, macro-based activity, and API abuse

    Detect and block

    In other words, the use of AI technology alone does not determine whether automated traffic is legitimate or malicious.

    Businesses must consider who is accessing the service, what the entity is attempting to do, how many resources it consumes, and how it affects actual business operations.


    What Problems Can Arise from Allowing All AI Agents?

    To increase brand visibility in AI search results, corporate content needs to be discoverable by search crawlers. However, allowing all automated requests for this reason can create new operational burdens for websites and APIs.

    Content and Data May Be Collected Excessively

    Limited crawling for search visibility serves a different purpose from repeatedly scraping all available pricing, product, and technical information.

    Real-time information such as product prices, inventory levels, available seats, and promotions is particularly likely to be requested repeatedly at short intervals. This type of access may continuously place load on servers and databases without directly contributing to search visibility.

    Even Legitimate AI Agents Can Create System Load

    Even an AI agent with no malicious intent may generate significantly more requests than a human user when simultaneously comparing products or checking prices and inventory on behalf of multiple users.

    For example, an individual user may check only a few products. An AI agent, however, may call multiple APIs within a short period to compare dozens of products, options, and inventory statuses.

    AI Agents Can Affect Actual Business Processes, Not Just Retrieve Information

    The level of risk changes when AI agents go beyond simply reading content and access the following areas:

    • Login and account registration

    • Product searches and inventory checks

    • Adding products to shopping carts

    • Holding seats or hotel rooms

    • Reservations and payments

    • Order and reservation modifications

    These functions are also provided to legitimate customers. Therefore, it is difficult to determine that a request is safe simply because its format appears legitimate.


    How Should AI Agents Be Classified?

    1. Can the Identity of the Entity Accessing the Service Be Verified?

    The first criterion is whether the entity responsible for an automated request can be identified.

    • Is the service or organization operating the agent publicly disclosed?

    • Does it use a consistent User-Agent?

    • Does it provide an official IP address list or authentication method?

    • Does it comply with robots.txt and crawling instructions?

    • Can its contact information and purpose of use be verified?

    Cloudflare defines verified bots and agents as those that honestly identify themselves, comply with robots.txt, maintain reasonable request rates, and do not attempt to bypass website operators’ policies.

    However, verifying a bot’s identity does not mean that it should be granted the same access permissions across every URL and API.

    2. What Is the Purpose of the Access?

    Policies may differ depending on the purpose of an AI system, even when the same company operates it.

    • Is it accessing the service to generate search results and answers?

    • Is it collecting data for model training?

    • Is it comparing products on behalf of users?

    • Is it attempting to complete an actual reservation or purchase?

    • Is it repeatedly collecting price and inventory information?

    A search crawler reading content pages and an AI agent calling payment APIs cannot reasonably be managed according to the same criteria.

    3. How Many System Resources Does It Consume?

    The legitimacy of automated requests should be evaluated not only by their purpose, but also by how they are made.

    • Number of requests per second

    • Number of concurrent requests

    • Number of repeated calls to the same URL or API

    • Session duration

    • Range of pages and functions accessed

    • Request patterns by time of day

    • Browsing speed compared with normal users

    Even a legitimate search crawler may need to be rate-limited if it accesses the service beyond the level the system can handle.

    4. How Does It Affect Business Outcomes?

    Finally, businesses need to determine how the requests affect actual service operations.

    • Do they contribute to brand visibility and content discovery?

    • Do they support legitimate product comparisons and purchase conversions?

    • Do they hold actual seats or inventory?

    • Do they distort analytics data and demand signals?

    • Do they interfere with legitimate customers’ login, reservation, or payment processes?

    • Do they increase infrastructure and external API costs?

    Technically identifying a bot is not enough. Policies must be determined according to the bot’s impact on the service and the business.


    How Should Allow, Restrict, Verify, and Block Policies Be Defined?

    Rather than applying a single action after detecting automated traffic, businesses can respond in stages according to the purpose and risk level of each request.

    Policy

    Applicable traffic

    Operational approach

    Allow

    Verified search crawlers and legitimate monitoring bots

    Allow access to content areas

    Rate limit

    Crawlers and agents with legitimate purposes but high request volumes

    Limit requests per second and concurrent requests

    Restrict access scope

    AI services that require only specific information

    Define the permitted range of URLs and APIs

    Additional verification

    Agents accessing login, reservation, and purchasing functions

    Apply authentication, token, and session verification

    Queue and process sequentially

    Legitimate traffic that exceeds system processing capacity

    Admit requests sequentially at a rate the system can process

    Block

    Unidentified entities, policy circumvention, and business logic abuse

    Detect and block access in real time

    The important point is to separate content access permissions from transaction permissions.

    Allowing a search crawler to read blog articles and product descriptions does not mean that the same crawler should also have access to login, shopping cart, reservation, or payment APIs.

    Bot management in the AI agent era is not simply about deciding whether to block automated traffic.

    It is about determining what level of access and processing speed should be provided to each type of automated traffic.


    How Should AI Agent Traffic Be Managed?

    In actual service operations, businesses can take the following step-by-step approach.

    Step 1. Identify the Automated Traffic Currently Accessing the Service

    The first step is to identify which bots and agents are accessing which pages and APIs.

    Rather than examining only the overall percentage of bot traffic, businesses should also review the following information:

    • URLs and APIs accessed

    • Number and frequency of requests

    • Browsing flows for individual sessions

    • Whether the traffic accesses login, shopping cart, or reservation functions

    • Response times and server resource usage

    • Impact on legitimate users’ conversion journeys

    Step 2. Classify Automated Traffic by Purpose

    Divide automated traffic into categories such as search, training, comparison, transactions, and attacks. Then define the appropriate level of access required for each category.

    Step 3. Set Policies for Individual Pages and APIs

    For example, policies can be differentiated as follows:

    • Blogs and guides: Allow search crawler access

    • Product and pricing pages: Provide limited access and manage request volume

    • Inventory and seat APIs: Apply authentication and rate limiting

    • Login and account registration: Apply behavioral analysis and additional verification

    • Shopping cart, reservation, and payment: Apply session-level analysis and control concurrent processing volume

    Step 4. Separate Detection Policies from Traffic Control

    Deciding which requests should be allowed and determining how quickly the allowed requests should be processed are two different issues.

    Even legitimate AI agents can cause service disruptions if they generate more requests than the system can process. Businesses therefore need both admission eligibility decisions and admission-rate control.

    Step 5. Continuously Adjust Policies

    As new AI search services and agents emerge, existing classifications and policies may no longer remain appropriate.

    • Identify new User-Agents and AI agents

    • Measure the actual referral and conversion contributions of allowed traffic

    • Monitor excessive API requests and resource consumption

    • Analyze false positives and policy-circumvention patterns

    • Readjust policies for individual URLs and APIs

    Responding to zero-click and AI agents is not a one-time configuration task. It is an ongoing area of service operation.


    After Zero-Click, Businesses Must Design for Both Discoverability and Access Control

    In the zero-click era, businesses must prepare their brands and content to be included in AI-generated answers.

    However, neither allowing all automated access for the sake of AI discoverability nor blocking every AI bot for security reasons is a sustainable approach.

    Websites and APIs will increasingly be accessed by various automated entities:

    • Crawlers that generate search results and AI answers

    • Data-collection bots used for model training

    • AI agents that compare information on behalf of customers

    • Transactional agents that support reservations and purchases

    • Scrapers and malicious bots disguised as legitimate agents

    Businesses must therefore answer the following two questions at the same time:

    Can AI systems discover our brand and content?

    Once they discover it, what should they be allowed to do within our service, and to what extent?

    Competitiveness in the AI search era cannot be achieved simply by publishing more content.

    Businesses need an operational framework that provides AI systems with accurate and necessary information while controlling the access permissions and processing speeds of automated traffic according to the purpose of the service.


    FAQ

    Q1. Could Blocking AI Search Crawlers Negatively Affect GEO Visibility?

    If crawlers used for search and answer generation cannot access content, the relevant pages may be less likely to appear in AI search summaries or be used as cited sources.

    However, search crawlers and model-training crawlers serve different purposes, so separate policies can be configured for each through robots.txt. In OpenAI’s case, OAI-SearchBot is associated with search visibility, while GPTBot is classified as a crawler potentially used for model training.

    Q2. Are All AI Agents Legitimate Bots?

    No. The fact that a system uses AI technology does not determine whether it is legitimate.

    Businesses must analyze the agent’s identity, purpose of access, request frequency, URLs and APIs accessed, and its impact on transactions and system operations.

    Q3. Can Legitimate AI Agents Also Cause Server Outages?

    Yes. Even without malicious intent, AI agents may place a burden on servers and databases if they call a large number of product, pricing, inventory, or reservation APIs within a short period.

    Reasonable request limits and traffic control policies are therefore necessary even for legitimate agents.

    Q4. Can robots.txt Manage All AI Agent Traffic?

    robots.txt is a method for communicating a website operator’s access policies to crawlers. However, not every automated tool complies with it.

    Automated activity involving actual service functions such as login, shopping carts, reservations, and payments also requires behavioral detection and API protection.

    Q5. What Is the Difference Between BotManager and NetFUNNEL?

    BotManager analyzes the behavior and risk level of automated traffic to detect and respond to malicious bots and macros.

    NetFUNNEL controls admission rates and concurrent processing volume so that legitimately allowed requests do not exceed the system’s processing capacity.

    In other words, BotManager determines who should be admitted, while NetFUNNEL controls how quickly they should be admitted.

    Share article
    Contents
    SummaryDoes Zero-Click Mean Website Visitors Are Disappearing?What Is the Difference Between AI Search Crawlers and AI Agents?What Problems Can Arise from Allowing All AI Agents?Content and Data May Be Collected ExcessivelyEven Legitimate AI Agents Can Create System LoadAI Agents Can Affect Actual Business Processes, Not Just Retrieve InformationHow Should AI Agents Be Classified?1. Can the Identity of the Entity Accessing the Service Be Verified?2. What Is the Purpose of the Access?3. How Many System Resources Does It Consume?4. How Does It Affect Business Outcomes?How Should Allow, Restrict, Verify, and Block Policies Be Defined?How Should AI Agent Traffic Be Managed?Step 1. Identify the Automated Traffic Currently Accessing the ServiceStep 2. Classify Automated Traffic by PurposeStep 3. Set Policies for Individual Pages and APIsStep 4. Separate Detection Policies from Traffic ControlStep 5. Continuously Adjust PoliciesAfter Zero-Click, Businesses Must Design for Both Discoverability and Access ControlFAQQ1. Could Blocking AI Search Crawlers Negatively Affect GEO Visibility?Q2. Are All AI Agents Legitimate Bots?Q3. Can Legitimate AI Agents Also Cause Server Outages?Q4. Can robots.txt Manage All AI Agent Traffic?Q5. What Is the Difference Between BotManager and NetFUNNEL?

    STCLab Inc.

    RSS·Powered by Inblog