Monday AI & Growth Brief: The AI Stack Is Growing Up – Access, Decisions and Control
entry 003 · 22 September 2026 · covering 14–21 September
Cloudflare separated search crawling, AI training and AI agents. SEO is moving closer to task completion. AI referral benchmarks still disagree with each other, while enterprise AI is converging around reusable skills connected to governed business data.
This week produced fewer shiny “SEO is dead again” announcements and more infrastructure changes.
The strongest signal is that the web is beginning to distinguish between search crawlers, AI-training crawlers and agents acting on behalf of humans. At the same time, enterprise AI is settling around reusable skills connected to trusted data, permissions and business rules.
For my work, this makes the relationship between AEO, analytics, CRO and workflow design clearer rather than fuzzier. The common thread is access.
Can an AI system retrieve the right information? Can it understand what it has found? Can it verify it? And, if it is allowed to act, what exactly is it permitted to do?
Before creating more content, adding another visibility tool or building another agent, those are increasingly the questions I want to answer first.
1. Jev suggests AI workflows may need fewer writers and more decision-makers
One of the more interesting AI launches last week wasn’t another model designed to write longer answers.
It was designed to make decisions.
TypeSafe AI launched Jev on 15 September, describing it as a probabilistic decision model. Instead of receiving some context and generating paragraphs of text, Jev receives a state and a set of defined questions, then returns structured answers such as a choice, score or boolean together with probabilities.
That sounds like a fairly technical distinction, but I think it points toward something important about how useful AI workflows are going to be designed.
Most of the AI systems we use today ask a large language model to do everything, but many steps inside a real workflow don’t require an eloquent answer.
They require a decision.
Is this lead high priority?
Does this analysis have enough evidence?
Does this recording contain a likely usability problem?
Should this anomaly be investigated?
Does this article satisfy our quality criteria?
Should this task go to a human, another model or nowhere at all?
Those are classification, scoring and routing problems and Jev is designed specifically around that layer. Vercel describes it as taking shared state and returning typed decisions with probabilities, allowing software to automate high-confidence cases and send uncertain ones somewhere else for review.
Why I find this more interesting than another new LLM
We’ve spent most of the last few years trying to make one increasingly powerful model do everything. The emerging alternative is much more modular.
A workflow might eventually look like:
data comes in
↓
a decision model classifies what happened
↓
a rule determines whether action is warranted
↓
a larger reasoning model investigates when necessary
↓
a human approves consequential actions.
For something like CRO, imagine a weekly system reviewing hundreds of signals. It does not need GPT-6-level reasoning to decide that:
- conversion rate moved less than the investigation threshold;
- a session recording contains repeated dead clicks;
- an experiment has insufficient sample;
- a CRM order and GA4 purchase match;
- a funnel anomaly deserves deeper analysis.
Those small decisions could be handled cheaply and quickly, while a stronger model is reserved for the part we actually want it for: understanding why something happened and deciding what to do about it.
There is early evidence developers find this useful
Jev became the fastest-adopted model Vercel says it has launched through its AI Gateway. Within the first 24 hours, Vercel reported that nearly 13% of its paid AI Gateway teams had used it, more than twice the adoption of any previous model launch on the platform.
That’s an interesting adoption signal. I still don’t know how I am going to test it, but I’ll find a way.
TypeSafe’s own workflow evaluations reportedly found Jev up to 193.6× faster and 444.6× cheaper than the language models it compared against. Those are vendor benchmarks, so I wouldn’t treat them as general real-world performance claims.
The important idea survives without them. Not every AI task needs generative intelligence.
As I have mentioned before, many times, I’ve been working on moving away from the idea of building one giant “marketing agent.” This is not a new idea, just a personal learning curve.
Jev makes the alternative architecture easier to see. A good AI system might contain different kinds of intelligence for different jobs:
Generative models: Research, explanation, hypothesis generation, strategy.
Decision models: Classification, scoring, quality checks, routing and escalation.
Deterministic software: Permissions, calculations, business rules and actions.
Humans: Ambiguity, accountability and consequential decisions.
That distinction motivates me because it potentially makes AI systems cheaper and faster, but more importantly, easier to control and evaluate.
For marketing teams, the opportunity may therefore be less about finding one model smart enough to run the entire department.
It may be about designing the right decision architecture around the work, and that feels considerably closer to how reliable businesses already operate.
If you want to read a jev deep dive, this one is really interesting.
2. Cloudflare just separated “being discoverable by AI” from “letting AI do whatever it wants with your content”
On 15 September, Cloudflare launched new controls allowing websites to independently manage three categories of machine access: Search → AI training → AI agents.

Its new disallow AI Training setting is designed to let a website remain discoverable in traditional search while refusing the use of its content for model training.
Cloudflare is also replacing its broad “Block AI Bots” switch with separate controls for search, training and agents, while its new Bot Preference Sync feature is intended to apply a website’s preferences across supported crawlers.
According to Cloudflare, Apple, Google and Microsoft already meet, or have committed to meet, the criteria behind its new “Accountable” crawler designation. Those criteria include a training opt-out, a separate AI-summary opt-out, URL-level visibility and confirmation that refusing training will not affect traditional search rankings.
This corrects an increasingly dangerous simplification in AEO: “Don’t block AI crawlers or you’ll disappear from AI.” That isn’t a sufficiently precise recommendation anymore.
There are at least three fundamentally different activities:
- A machine indexes your content to help someone find it.
- A model provider uses your content for training.
- An agent accesses your website in real time to complete someone’s task.
A business may reasonably want the first and third while refusing the second.
Publishers may make a different choice from ecommerce businesses. An advertising-funded site may not want an AI agent consuming pages without generating human page views. A travel business, meanwhile, may want an agent to find current availability or pricing while keeping other parts of the site restricted.
The right configuration depends on the business model. However, a Crawler & Agent Access Check needs to be within any AI Visibility Audit:
- Which search, training and agent crawlers can access the site?
- Are CDN, firewall or bot-protection rules blocking them unintentionally?
- Is search access being confused with training access?
- Should agents be allowed to interact with the website?
- Do the website’s robots and infrastructure settings reflect the business’s actual objectives?
The goal is to be able to answer “Which machines do we want accessing which information, and for what purpose?” before we start thinking about the solution to our clients’ problems.
3. Your firewall may now determine your AI visibility
Cloudflare’s change matters for another reason. AI discoverability increasingly depends on infrastructure the SEO or marketing team may never have configured: CDN settings, bot protection, firewall rules, crawler classifications and robots directives.
Imagine this diagnosis:
Website content: excellent.
Schema: excellent.
Internal linking: excellent.
Google rankings: excellent.
AI visibility: poor.
The instinct will often be to create more content, but the actual problem could be that the relevant retrieval system cannot reliably access what is already there. That is an expensive category error.
A more useful AI visibility diagnostic
Before recommending new AEO content, I increasingly want to review the system in this order:
- Retrieval: Can the system access the information?
- Interpretation: Can it understand the entity, offer and relationships correctly?
- Evidence: Can it verify the claims through credible, consistent sources?
- Representation: How does it describe, cite or recommend the business?
- Business outcome: Does that visibility influence useful demand, qualified traffic or revenue?
This is the same principle I use in CRO: diagnose where the customer is getting stuck before prescribing another redesign.
In AEO, the blockage may happen before the content is ever considered.
4. SEO and CRO are converging around task completion, not rankings
One of the better SEO pieces published this week argued that ranking is only half the job: pages should also be evaluated by whether people can complete the task that caused the search.
The idea is not new to CRO at all. What is interesting is that SEO is moving toward it. AI search makes task completion more important because Google, ChatGPT and other systems can increasingly satisfy the informational part of a query themselves.
The click that remains may represent something the machine could not complete:
- check live availability
- compare a specific option
- obtain a quote
- configure a product
- book
- buy
- verify trust
- speak to somebody.
The commercial value of a page may therefore depend less on how comprehensively it repeats information and more on how effectively it helps someone finish the job.
For a travel business, an AI system may explain destinations, weather, hotels and visa requirements beautifully. Eventually, however, the person needs to pick dates, verify real availability and price, confirm flight schedules, and pick a room before they book with confidence.
That is where the website still has a considerable advantage.
CRO angle
What task is someone still trying to complete when they arrive here?
Then I want to test whether the page makes that task easier. This is a healthier way to think about AI search than desperately trying to reproduce every answer an LLM can already provide.
The website does not need to win every information exchange. It needs to become exceptionally good at the parts of the journey where current information, trust and action matter.
5. AI referral conversion benchmarks are still a mess, and that is useful information
This week brought another round of claims that AI traffic converts spectacularly well, but when datasets are compared, the picture becomes wonderfully inconvenient.
A recent synthesis of four retailer examples found materially different outcomes. Some datasets showed AI referrals converting far above other traffic sources, while others showed them performing below the site average.
Meanwhile, a Semrush manufacturing study found that visits attributed to AI assistants and AI search represented only 0.48% of sessions in that dataset, despite extensive exposure inside AI-generated search experiences.
The manufacturing result should not be generalized to travel, retail or B2B. The retailer examples should not be treated as a universal benchmark either.
That is precisely the point. I would actively reject a claim like “AI visitors convert four times better.” without asking:
Which industry?
Which AI platform?
Which conversion?
Which attribution method?
Which landing experience?
Which sample size?
The contradiction tells us that AI referral does not seem to be an intent category.
Someone asking ChatGPT to explain Portuguese history and somebody asking it to find a seven-night all-inclusive Dominican Republic package departing Lisbon next month may both appear as chatgpt.com in analytics.
Their commercial intent is galaxies apart.
I would not benchmark AI traffic primarily against one industry conversion rate. Where volume allows, I would segment it by platform, landing page, likely intent, action, new/returning user. I would also compare pages to conversion, time to conversion, internal-search use, return visits and assisted outcomes.
AI systems may influence a decision without sending a traceable referral at all. A person can discover a brand in an answer and return later through branded search or direct traffic. That does not mean we should credit every increase in brand demand to AI; it means referral analytics alone cannot describe the whole effect.
6. Salesforce just showed what mature AI workflows are starting to look like
At Dreamforce on 16 September, Salesforce launched AIforce, an architecture designed to expose its data, business logic, workflows and governed actions to multiple AI interfaces.
The particularly interesting part for me is Claudeforce.
Salesforce in Claude launches in beta with a prebuilt MCP server and 37 reusable sales skills. Salesforce also says its Claude Code development plugin includes more than 40 development skills, with analytics, marketing, service and commerce capabilities planned for the broader integration.
AI Workflow Design & Quality Systems
At this point, there is no doubt that the real work is to identify:
- the task
- the authoritative sources
- the reasoning procedure
- the tools and permitted actions
- the human checkpoints
- the evaluation criteria.
The automation is almost the boring bit.
7. AI workspaces are swallowing the tools around them
Anthropic moved in the same direction this week. On 16 September, it announced that Claude’s chat and work capabilities are being brought into one interface, alongside document and presentation creation tools.
The familiar “copy/paste” workflow is slowly evaporating (along with our credits but that’s a topic for another day). The AI workspace itself is becoming an orchestration layer.
If one system can research, analyze files, query connected tools, create documents and take actions, an error can propagate much farther too. The key asset becomes the information the system trusts, and the method it applies to it.
Which brings me right back to the same place as last week, the architecture I have been developing: Context → Skills → Tools → Permissions → Logs → Evaluation.
Better tools increase the value of the system around them. They do not remove the need for one.
8. Google Analytics quietly added a useful data-integrity control
On 21 September, Google Analytics added hostname Include filters, allowing a property to maintain an allowlist of domains authorized to send event data.
Previously, teams could exclude known unwanted hostnames. An allowlist reverses the logic: accept the approved domains and block the rest.
That can reduce spam and abnormal traffic without requiring a team to keep discovering and excluding new sources one by one.
There is an important implementation detail: Google says these hostname filters do not apply to events sent through Measurement Protocol, while empty hostnames are blocked automatically. This is not a switch I would activate without checking the property’s data flows first.
This is not the most glamorous Analytics update, but it reinforces the same lesson as Cloudflare’s crawler controls. Infrastructure settings shape what enters the dataset before an analyst ever sees a chart. Google’s recent measurement guidance offers a useful framework here.
Data foundation
Are the events trustworthy, and is the property receiving data only from intended sources?
Multiple signals
What do GA4, CRM, Search Console, PPC, recordings and project logs show?
Causal evidence
Can we reasonably establish that the redesign caused the difference?
The first step is not exciting, but everything after it depends on it.
I would borrow this framework shamelessly for CRO.
What I would actually do this week
Three things feel worth doing.
First, I am rethinking the methadoly behind the AI crawler and access check on my AI Visibility Audit. Cloudflare’s 15 September change makes crawler configuration part of the marketing stack. I need to know whether the relevant systems can retrieve what is already there properly across the board before making assumptions.
Second, I am going to resist universal AI-conversion benchmarks. For clients, I want to treat AI referral traffic as a collection of intents rather than a channel with one expected conversion rate. Where the sample is small, I will say that plainly rather than manufacturing certainty.
Third, I want to formalize one reusable skill inside my own workflow system. I am not going to build the whole machine at once. I have been testing and play with different ways to build my own CRO sidekick(s), this week I will test the first layer I build rather than building the second.
This week’s wider lesson feels simple:
Before optimizing the output, inspect the system that produces it.
In AI visibility, that means checking retrieval before creating more content.
In analytics, it means checking data integrity before explaining a metric.
In CRO, it means understanding the remaining task before redesigning the page.
And in AI workflows, it means defining context, permissions and evaluation before adding more automation.
The tools are getting more capable. The useful work is increasingly about making sure they can access the right things, for the right reasons, without creating more expensive guesses.
Sources
- Cloudflare, Cloudflare Helps End the Search-or-AI-Training Tradeoff
- Search Engine Land, Ranking is only half the job: SEO for task completion
- MaShop, AI Shopper Conversion: What Four Shops Really Measured
- Semrush, AI search & manufacturing SEO: What the data shows
- Salesforce, Salesforce Unveils AIforce
- Reuters, Anthropic to fold Claude AI features into one interface, launches document tools
- Google Analytics Help, What’s new in Google Analytics
- Google, New updates to measurement suite in Google Ads
