This week

Run of 2026-09-26, GitHub-hosted runner, US data center, 92 storefronts. Change against 2026-09-20 in brackets.

30%
withhold robots.txt from an agent
28 of 92 (-1)
25%
of readable files name any AI agent
16 of 64
53%
serve a readable homepage to a non-browser agent
49 of 92 (-1)
3
publish a Universal Commerce Protocol profile
of 92
16
publish an llms.txt
of 92

The full picture

robots.txt withheld (refused or no answer)28 / 9230%
robots.txt readable64 / 9270%
of readable: names any AI crawler or agent16 / 6425%
of readable: blocks a training crawler outright5 / 648%
of readable: blocks an AI search crawler outright3 / 645%
of readable: blocks a user-triggered agent outright2 / 643%
of readable: carries Content-Signal lines1 / 642%
homepage served, readable by a non-browser client49 / 9253%
homepage refused or challenged30 / 9233%
homepage an empty shell (script challenge or JavaScript-only)7 / 928%
homepage no answer4 / 924%
homepage other2 / 922%
of served homepages: JSON-LD structured data30 / 4961%
llms.txt published16 / 9217%
Universal Commerce Protocol profile at /.well-known/ucp3 / 923%
A2A agent card0 / 920%

Week on week

Runrobots.txt withheldnames AI agenthomepage servedllms.txtUCP
2026-09-26281649163
2026-09-20291650163

Method

Sample: NRF Top 100 Retailers 2026, one consumer storefront each; 92 of 100 have one. Where a company runs several banners, its own storefront is used if it has one, otherwise its largest US brand. Six plain requests per site, 1.5 seconds apart, under a user agent that names the research project and links to it: robots.txt, /llms.txt, /.well-known/ucp, two A2A agent-card paths, and the homepage. No login, no forms, no cart, no browser impersonation, no impersonating another company's bot, no retry after a refusal. A homepage counts as served only if it returns a title and at least ten links; a 200 response carrying a script challenge or an empty JavaScript shell is not a page an agent can read. Timeouts are reported as no answer, not as refusals, because a slow site and a deliberate stall look the same from outside.

The scan runs every Saturday from a GitHub-hosted runner in a US data center. Bot-management decisions are not fully deterministic, so a handful of sites answer differently between runs; read the trend, not a single week. Only aggregates are published here. Per-merchant results stay private; nothing on this page rates or ranks any retailer.

The launch piece: Amazon Blocked Meta's Shopping Agent in Public. A Third of Big Retailers Do It Quietly. For the identity layer that would change these numbers, see the Major Labs Agent Identity Tracker.

Machine-readable: /trackers/merchant-readiness/feed. Every figure is reproducible from the method above. Spot an error? Reply to any edition. See also all trackers.