Kondevs Made Its Site Usable by AI Agents. Here's What That Actually Requires.

Daily requests from AI agents on Cloudflare's network grew more than 1,700% over the prior year, according to a Cloudflare blog post from September 2026. That number sounds dramatic, and it is. But a network request is not a qualified lead, not a completed task, not a purchase. The gap between "an agent visited your site" and "an agent did something useful on your site" is where most enterprise websites quietly fail.

Kondevs published a detailed account of how it restructured its own site to be usable by AI agents. The piece is worth reading on its own terms, but it also raises a harder question that most agent-readiness guides skip: what does "usable" actually mean when the visitor has no eyes, no patience, and no ability to guess what you meant?

The Measurement Problem Comes First

"AI traffic" is not one thing. Training crawlers, retrieval crawlers that fetch pages to support AI-generated answers, and agentic browsers that navigate and act on a site are three fundamentally different categories. Mixing them in a dashboard produces numbers that look exciting and mean very little. A crawler request is not a human visit and does not prove a page was cited or influenced a decision. HUMAN Security's analysis found that 5.7% of traffic claiming to be from known AI crawlers was fake or spoofed; the ChatGPT user-agent was spoofed 16.7% of the time. Relying on user-agent strings alone is insufficient for trustworthy reporting.

This matters for anyone building a business case around agent readiness. If the executive sponsor sees inflated "AI traffic" numbers and expects proportional revenue, the project is already borrowing against trust it hasn't earned. Separating bot activity (server and CDN logs) from human referral sessions (analytics) is the baseline. Without it, you're optimizing for a signal you can't verify.

Some conversion data does look promising. A Semrush analysis found AI-referred visitors converted at 4.4 times the rate of traditional organic visitors. A single-client GA4 case study (October 2024 to April 2025) reported conversion rates of 15.9% from ChatGPT and 10.5% from Perplexity, compared to 1.76% from Google organic. But these are not universal benchmarks. The single-client study is exactly that: one client. And HUMAN Security's page-distribution data shows 77% of agentic AI activity concentrated on product and search pages, with only 2.3% reaching checkout. Agents are browsing. They are not yet reliably buying.

What "Agent-Usable" Actually Demands

Google's developer guidance, as reported by Search Engine Journal, emphasizes building for AI agents by focusing on fundamentals: semantic, accessible markup and predictable interactions. The advice is deliberately unglamorous. Don't create "AI-only" experiences. Make the site robust and interpretable.

Kondevs' own approach aligns with this. The emphasis falls on explicit, consistent key facts (pricing, policies, requirements), scannable structure (headings, lists, tables), semantic HTML (real links, real buttons, real labels), and task-completable journeys where an agent can search, compare, and inquire without hitting a dead end. Contentful's guidance reinforces the same point: structured, reusable content reduces wrong answers and misinterpretation by AI systems. Consistency across pages and channels becomes a competitive advantage, not a nice-to-have.

The harder part is what Ed Whicher framed in the Web Usability podcast as treating the AI agent as "a new user." That reframing shifts the optimization question. It's no longer only "can AI find and summarize this page?" It becomes "can an agent reliably complete the task using the site's interface?" Those are different problems. The first is content. The second is architecture.

WebMCP, and When Not to Rush

WebMCP is an emerging approach for exposing website actions as structured tools for agents. Sources treat it as early-stage, complementary to usability and secure application logic. Search Engine Land's coverage and the webmcp.com documentation both caution against treating it as a substitute for the fundamentals. If your semantic HTML is broken, your pricing is inconsistent across three pages, and your demo-request form requires JavaScript gymnastics that an agent can't parse, adding a protocol layer on top solves nothing. Worse, it creates new attack surface.

NIST's activity around agent identity and authorization signals that governance attention for agentic systems is increasing. AWS's security principles for agentic AI systems emphasize input validation, permissions, confirmations, and auditability. For enterprises in regulated environments (and with EU AI Act transparency obligations applying from 2 August 2026, that category is expanding), enabling agent actions on forms, bookings, or account changes without proper authorization flows is a compliance risk, not a feature.

The Control Plane Question

This is where the Kondevs article connects to a broader architecture problem. Making a website agent-usable is not a frontend project. It touches content governance (are facts consistent?), integration architecture (can the journey complete end-to-end?), observability (do you know what the agent did, what path it took, what failed?), and security (who authorized this action?). For enterprises running mixed estates with webMethods, SEEBURGER, Camunda, or similar platforms, the agent-readiness question lands squarely on the integration layer.

If an agent can route, it can misroute. If a provider can silently fall back, your architecture needs to notice before your customer does. The same principles that govern AI operationalization inside enterprise workflows apply to the external surface: explicit handoffs, auditable decisions, defined failure paths.

Adobe's retail data illustrates the trajectory. AI-referred traffic went from converting 43% less often than other traffic in July 2024 to only 9% less often by February 2025. AI-referred visitors viewed 12% more pages, bounced 23% less, and spent 41% longer on site. The gap is closing. But closing it depends on whether the site can actually serve those visitors, human or otherwise, with reliable, consistent, governable experiences.

The demo is not the system. A site that looks agent-ready in a test but breaks under real agentic traffic, or reports vanity metrics from spoofed crawlers, or exposes ungoverned actions to automated callers, has the same problem as an AI pilot that impresses in a workshop and fails in production. Before you celebrate accessibility, design control. That's the part Kondevs got right, and the part most agent-readiness checklists still leave out.

Related concepts & services

Key terms: AI Agent, IBM webMethods, Camunda

Explore our service: Data Science & AI Consulting

Related articles

AI & Machine Learning

How AI Is Transforming Business Process Management

Traditional BPM automates the rules you can write down. AI-enhanced BPM learns the patterns you can't: predicting escalations, routing intelligently, and reading the documents that used to need a human. Here's how, and where to start.

4 min read

Building an enterprise AI strategy?

From choosing the right use cases to ML and agents in production, let's talk it through.

Talk to an integration architect