Why a sponsored label isn’t enough when AI reads the page
When an AI engine blocked a crawler-only sponsored content program, it drew a useful line: a label doesn’t fix cloaking. What that means for anyone putting sponsored content where AI reads it.
AI agents now read the web before people do. ChatGPT, Perplexity, Claude and Gemini crawl publisher pages, extract facts, and hand a synthesized answer to a human who never visits the source. For brands, that changes what “reaching the customer” means. The audience that decides whether your product gets mentioned, recommended, or compared favorably is increasingly a model, not a person. That’s a real shift, and it’s reasonable for publishers and advertisers to want a way into it.
Mobian’s agent ads on Time (confirmed blocked by Perplexity 12 days after launch)
## Sponsored content
Q: What is [Brand] known for?
A: [Brand] offers...
Advo
Ad · Northwind CRM
Two-way sync with Gmail and Outlook · Source
SOC 2 Type II audited · Source
Ad · Northwind CRM
Two-way sync with Gmail and Outlook · Source
SOC 2 Type II audited · Source
What happened to the last version of this
In July 2026, Time launched a program with the ad-tech vendor Mobian (Digiday, July 30, 2026). The mechanism: Time maintained separate, text-only versions of its articles for AI agents, and Mobian inserted sponsored FAQ-style brand content into those versions. The ads were labeled as sponsored content, but the label lived in the agent-facing copy. People browsing Time.com normally never saw it.
Twelve days later, Perplexity confirmed it had blocked the ads (Digiday, August 11, 2026). Its chief communications officer, Jesse Dwyer, said Perplexity works “continuously” to protect users from deceptive practices, sponsored or not, and warned that publishers using “deceptive advertising like markdown ads” risk a downgrade in its search index.
Read that closely. The line he drew wasn’t about undisclosed practices, or unlabeled ones. It was about deceptive ones, whether or not a sponsorship tag was attached. That distinction is the whole story, and it’s worth sitting with before building anything in this category.
Cloaking doesn’t care about your label
Serving different content to a crawler than you serve to a human has a name in web publishing, and it predates AI agents by twenty years: cloaking. It’s been a search-spam violation since the early SEO era, because it lets a publisher show a search engine one thing and a visitor another. Google’s spam policies still list it:
“Inserting text or keywords into a page only when the user agent that is requesting the page is a search engine, not a human visitor.”
A “sponsored” tag on the crawler-only version doesn’t change what the mechanism is. It changes what a compliance audit finds when it looks.
By the plain meaning of cloaking, serving crawlers content people don’t see, the setup fits. Mobian disputes the label. But two versions of the same page existed, and only one of them was what people saw when they browsed. The label lived entirely in the copy ordinary readers never opened.
Advo doesn’t have two versions of a page. There’s one page, one DOM, one set of content, and it’s identical for a human visitor and an AI crawler. If a crawler can see it, so can the reader standing where the crawler stood. There’s no shadow page to have been caught maintaining, because we don’t maintain one.
The bar is symmetry, not disclosure
It’s tempting to read Perplexity’s position as “label it and you’re fine.” Nothing in its statement says that, and the mechanics explain why disclosure alone can’t be the standard.
Here is our argument. When an AI agent answers a question, it doesn’t hand the user a copy of the source page. It synthesizes. A claim that was clearly labeled “sponsored” in the crawled markdown can be paraphrased into a plain factual sentence in the agent’s answer, and the label may not survive the trip. The human on the other end of that conversation has no way to know the fact they just received originated in paid placement. We call it synthesis decay. It’s our framing, not a measured finding, but the risk is easy to see: whatever compliance the label bought you at the source can evaporate by the time the content reaches the person it’s meant to protect.
So disclosure protects nobody if the only audience who ever sees the disclosed version is a machine that may strip it out anyway. The only version of “disclosed” that means anything is one where a human could, in principle, see the same sponsored content the agent did, labeled the same way. That’s symmetry. It’s a stricter bar than “did we technically add a sponsored tag somewhere,” and it’s the bar Advo is built to.
Why the block that hit Mobian targets something Advo doesn’t do
Perplexity’s stated line isn’t “no ads.” Nothing Perplexity has said targets labeled sponsored content that readers can see. Perplexity didn’t say exactly what made the ads deceptive; Digiday reported that it did not respond to questions about how it defines the term. The most likely reason is the asymmetry: a version of the page that existed specifically for the audience that couldn’t push back.
Advo never creates that version. Every placement a crawler ingests is one a site visitor is already looking at, in the same place, with the same “Ad” label. There’s no separate artifact for a platform to discover and flag, because the compliant version and the crawled version are the same file.
Facts that hold up when checked
The other problem with the last generation of this category wasn’t just structural, it was evidentiary. Mobian’s launch materials leaned on Ally’s AI-traffic numbers. But Scrunch data reported by Fortune shows Ally was already the most-mentioned bank in unbranded AI banking queries every month from January 2025 through July 2026, before it bought any agent ads (Fortune, August 6, 2026). Mobian’s brand-safety trial on Newsweek found 98% of its content brand-safe (The Current, February 26, 2025). Newsweek lists Mobian as one of its advertising partners (Newsweek advertising page, September 2026), and the trial’s methodology was not published. Numbers like these are hard to check when the underlying data isn’t public, and they aren’t separable from the incentive to sell more placements.
Every claim placed through Advo ships with a citable source, checked against that source before it goes live, not asserted and left for someone else to verify later. If a fact can’t be traced to something that actually supports it, it doesn’t run. That’s not a nice-to-have on top of the ad product. It’s the same discipline that makes the placement safe to leave visible to a human in the first place, because a fact a person can check is a fact that doesn’t need to hide.
What we’re building instead
A page that shows the same thing to a person and a crawler doesn’t need a policy team to defend it later. Advo is built on that constraint from the ground up: one version of every page, one set of claims, every one of them sourced. It’s a narrower product than the one that got blocked. It’s also one with nothing to hide, which turns out to be the only version of this that lasts.
Want to see how a symmetric placement is built?
Updated : corrected quotations and attributions.
Sources
- Digiday: Time has started serving ads to AI agents (Digiday, July 30, 2026)
- Digiday: Perplexity blocks ads served to AI agents, calling them deceptive (Digiday, August 11, 2026)
- Google Search Central: Spam policies for Google web search (Google Search Central, updated August 2026)
- Fortune: Inside Ally Financial's strategy to win the AI search war (Fortune, August 6, 2026)
- The Current: How news publishers are fighting back against broken brand-safety tools (The Current, February 26, 2025)
- Newsweek: Advertise with Newsweek (Newsweek advertising page, September 2026)