The quick answer
An AI visibility audit is a one-time diagnostic that documents which sources ChatGPT, Perplexity, Claude, Gemini and Google AI Overviews cite for a defined query set and country, whether the brand appears in those sources, and which specific sources to win next. As of 2026, a defensible AI visibility audit covers 30 to 100 queries across 1 to 3 countries, and ships a written report with a citation map, a share-of-voice baseline, a hotspot list, a gap list and a prioritized action plan. Anything less (a handful of ChatGPT screenshots, a single-engine scrape, an "AI readiness score" with no cited sources behind it) is not an audit. This playbook defines the scope, the checklist, the report structure, and the red flags.
Note on scope: this piece covers the audit as a deliverable (what goes in scope and what the report contains). For the measurement math behind the baseline number, see how to measure AI share of voice. For what to charge, see the GEO agency retainer pricing playbook.
What an AI visibility audit is, and what it is not
An AI visibility audit answers one question with evidence: for the queries that matter to this brand, which sources do AI engines actually cite, and is the brand among them? An audit is a diagnostic artifact, not a monitoring subscription and not a content strategy. The output is a document a marketing lead can act on without re-running the research, and that a second analyst could reproduce from the recorded query set.
The distinction that matters most in 2026 is between an audit and a demo:
- An audit is reproducible. The query set, engine list and country are written down, so a re-run four weeks later produces a comparable number. A screenshot of one ChatGPT session is not reproducible, because the same prompt returns different sources on a different day.
- An audit names sources, not scores. A "brand visibility score of 62/100" with no underlying list of cited URLs cannot be acted on. A ranked list of the 14 domains Perplexity cited for "best CRM for B2B SaaS" in the US can be acted on tomorrow.
- An audit ends in a decision. The final section names which sources to pursue, in what order, and why. An audit that stops at "you have low AI visibility" has diagnosed nothing.
An AI visibility audit is also distinct from an SEO audit, which inspects crawlability, rankings and backlinks against Google's ten blue links. An AI visibility audit inspects which third-party sources an answer engine assembles its answer from, which is why a page ranking #1 on Google can be absent from every AI answer in the category, a divergence covered in Google rankings vs AI citations.
Who commissions an AI visibility audit, and when
Three buyers commission an AI visibility audit: an agency selling it as a paid entry point, an in-house marketing lead who needs a baseline before funding a GEO program, and a founder reacting to a specific loss (a prospect said "ChatGPT recommended your competitor"). As of 2026, the audit is the standard first engagement in generative engine optimization, because no other deliverable establishes a defensible starting point.
The three trigger moments, and what each buyer needs from the report:
| Buyer | Trigger | What the report must answer |
|---|---|---|
| Agency (selling GEO) | New business pitch or retainer entry point | Which sources the prospect is missing from, ranked, with contacts |
| In-house marketing lead | Budget request for a GEO program | A baseline number and a credible before/after plan |
| Founder / product marketing | A lost deal attributed to an AI recommendation | Why the competitor is cited on the specific query, and what to fix |
Commission an audit when a decision depends on it, not on a schedule. An audit is a snapshot, so a second audit three weeks after the first, with no intervening action, produces noise rather than insight.
In scope vs out of scope
An AI visibility audit inspects the citation surface: the queries, the engines, the countries, the cited sources and the brand's presence within them. Work that changes the brand's visibility (writing content, pitching editors, fixing crawler access) is remediation, not audit. Keeping the line clear protects both sides: the client knows what arrives, and the agency does not silently absorb a content project inside an audit fee.
| In scope (the audit inspects) | Out of scope (a separate engagement) |
|---|---|
| The frozen query set and how it was chosen | Rewriting the site's page copy |
| Cited sources per engine, per country | Pitching editors and placing the brand in sources |
| Brand vs competitor citation baseline | Ongoing weekly or monthly monitoring |
| Cross-engine hotspot sources | Building the citation dashboard |
| Gap list (where competitors appear, brand does not) | Link building and classic SEO remediation |
| AI crawler access check (robots.txt, blocked bots) | Fixing the robots.txt and server rules |
| Owned-property citability review | Producing the recommended new content |
| Prioritized action plan | Executing the action plan |
The audit stops at the action plan. The action plan is the bridge to the next engagement (monitoring or source outreach), which is exactly why the audit converts so well as an entry product, a dynamic detailed in the GEO agency retainer pricing playbook.
The AI visibility audit checklist (copy this)
A complete AI visibility audit inspects nine things, in order. Each item produces an artifact that lands in a named section of the report, so the checklist and the table of contents map one to one. Run the checklist top to bottom, because each step depends on the frozen inputs defined in step 1.
1. Query set definition (30 to 100 queries).
Record the exact list, plus the selection logic (category questions, problem questions, comparison questions). Tag each query with a commercial weight from 1 to 3. Freeze the list before the first run, and print it in the report appendix. An audit whose query set is not disclosed cannot be verified or reproduced.
2. Engine and country declaration.
Name every engine queried (ChatGPT, Perplexity, Claude, Gemini, Google AI Overviews) and every country, explicitly. AI engines cite different sources for the same query in the US versus Germany, so an audit that blends countries into one number is measuring the blend, not the market.
3. Competitor list lock (3 to 8 named rivals).
Declare the competitor domains before counting. A competitor list assembled after seeing the results is a list chosen to flatter the client. Print the domains in the report.
4. Citation map per query, per engine, per country.
For each query, record every source each engine cited: the domain, the URL and the engine. The citation map is the raw evidence layer of the audit, and every later section derives from it.
5. Share-of-voice baseline.
Compute the brand vs competitor citation percentage per engine using the weighted method in how to measure AI share of voice. The audit reports the baseline and the setup that produced it; the linked playbook owns the formula.
6. Hotspot source identification.
Isolate the sources multiple engines cite at once for the same query. A hotspot source is the highest-leverage outreach target in the audit, because one placement moves several engines at once. Rank hotspots by how many engines cite them and by query weight.
7. Gap list.
List every source where a tracked competitor appears and the brand does not, ranked by engine count and query weight. The gap list is the single most valuable page of the report, because it converts diagnosis into a to-do list of named domains.
8. AI crawler access check.
Verify that the brand's own properties are reachable by AI crawlers. Check robots.txt against the documented user agents (OpenAI publishes its GPTBot and OAI-SearchBot crawlers in the OpenAI bots documentation), plus any WAF or bot-management rule that blocks them at the edge. A brand blocking the crawlers that feed answer engines has a mechanical problem no content plan fixes, covered in robots.txt for AI crawlers.
9. Owned-property citability review.
Inspect whether the brand's key pages are structured for extraction: answer-first sections, self-contained claims, visible facts (not facts locked in images or JavaScript), and schema that mirrors the visible HTML. Being crawlable and being quotable are two different tests, and an audit should run both.
If a proposed audit skips items 6, 7 or 8, it is a reporting exercise, not a diagnostic.
The audit report: a table of contents you can reuse
An AI visibility audit report runs 12 to 25 pages and follows a fixed order: method first (so the reader can trust the numbers), findings second, decision last. As of 2026, the reason to lead with method is that the audience has seen unverifiable AI visibility claims, so the setup disclosure is what makes the findings credible.
The reusable table of contents:
- Executive summary (1 page). The baseline share-of-voice number per engine, the three biggest gaps, and the top three recommended actions. Written so a CMO who reads nothing else can decide.
- Method and setup (1 to 2 pages). Query set size, engine list, countries, competitor list, run dates, and the tool or API used. State the limits honestly: a snapshot on named dates, not a permanent state.
- Citation map (3 to 6 pages). Per query, per engine: the cited sources. Tables, not prose.
- Share-of-voice baseline (2 pages). Brand vs competitors, per engine, with the weighted percentage and the setup that produced it.
- Hotspot sources (1 to 2 pages). The pages multiple engines cite at once, ranked, with why each matters.
- Gap list (2 to 4 pages). Named domains where competitors are cited and the brand is not, ranked by leverage, with the editor contact where available.
- Technical access findings (1 to 2 pages). Crawler access, blocked user agents, and citability issues on owned properties.
- Prioritized action plan (2 pages). 5 to 10 actions, each with an owner, an effort estimate and the expected mechanism ("placement on this hotspot source should surface the brand on 3 of 5 engines for these 4 queries").
- Appendix. The full query set and the raw citation data, so the client can reproduce or re-run the audit independently.
Section 9 is the integrity test. An agency that will not hand over the query set and raw citation data is selling an opinion, not an audit.
Real audit vs superficial audit
A real AI visibility audit is reproducible, multi-engine, per-country and source-level. A superficial audit is a single-engine, single-session screenshot tour with a score attached. The difference is not effort or page count: it is whether a second analyst, given the report, could re-run the work and land within noise of the same numbers.
| Dimension | Real AI visibility audit | Superficial audit |
|---|---|---|
| Query set | 30 to 100 queries, frozen and disclosed in the appendix | A few ad-hoc prompts, never listed |
| Engines | ChatGPT, Perplexity, Claude, Gemini, Google AI Overviews, named individually | ChatGPT only, presented as "AI" |
| Country | Declared and held constant per run | Unstated, silently blended |
| Evidence | Cited URLs per query per engine, raw data in the appendix | Screenshots of chat sessions |
| Competitors | 3 to 8 domains locked before counting | Chosen after seeing results |
| Baseline metric | Weighted share of voice with the setup disclosed | A proprietary 0-100 score with no method |
| Crawler check | robots.txt and edge rules verified against documented AI user agents | Not covered |
| Output | Ranked gap list of named domains plus an action plan | "Improve your AI presence" |
| Reproducible | Yes, from the appendix | No |
Red flags that expose a fake AI visibility audit
Six red flags separate a real AI visibility audit from a repackaged screenshot deck. Each red flag is a question a buyer can ask before signing, and each has a correct answer a competent provider gives without hesitation.
- No query set in the deliverable. Ask: "will the full list of queries be in the appendix?" An audit that hides its inputs cannot be verified, and cannot be re-run to prove improvement later.
- One engine presented as "AI". Ask: "which engines, individually?" ChatGPT alone is not AI visibility. Sources diverge across engines, so a single-engine audit misstates the picture by construction.
- A score with no sources behind it. Ask: "show me the cited URLs behind this number." A 0-100 visibility score is a summary, not evidence. If the provider cannot produce the underlying citation list, there is nothing underneath.
- No country declared. Ask: "which country was this run in?" An audit without a fixed country is not comparable to anything, including its own re-run.
- Guaranteed citations. Ask: "what exactly is guaranteed?" No provider controls what an AI engine cites. Committing to outreach volume is honest; guaranteeing citations or a ranking inside AI answers is not.
- Recommendations that are just "write more content". Ask: "which named sources, in what order?" A generic content recommendation means the gap list was never built, which means step 7 of the checklist was skipped.
A seventh, subtler flag: an audit that recommends only the provider's own paid placements. An audit's job is diagnosis, so if every recommendation routes to one vendor's inventory, the deliverable is a media proposal wearing an audit's clothes. The related question of whether payment is required at all is covered in do you have to pay to get cited by AI.
How long an AI visibility audit takes
An automated AI visibility audit takes 3 to 10 working days end to end, where the data collection is minutes and the analysis is the real work. As of 2026, the timeline splits cleanly: querying 50 queries across 5 engines and 2 countries through an AI citation API returns 500 answer-source lists in one scheduled batch, while interpreting them into a ranked gap list and an action plan is human judgment.
A realistic breakdown for a 50-query, 2-country audit:
| Phase | Typical duration | What drives it |
|---|---|---|
| Scoping (query set, competitors, countries) | 1 to 2 days | Client input and alignment on what matters |
| Data collection | Minutes (API) to 3+ days (manual) | Automation, entirely |
| Analysis (hotspots, gaps, citability) | 2 to 4 days | Analyst judgment, not tooling |
| Report writing and review | 1 to 2 days | Depth of the action plan |
The collection phase is where manual audits collapse. Running 50 queries across 5 engines and 2 countries by hand means 500 chat sessions, copy-pasted, with prompts drifting as the analyst tires. Automating collection is what makes the appendix (and therefore the audit's integrity) possible.
Running an AI visibility audit with Getspotted
Getspotted is the AI citation API and MCP server behind steps 4 through 7 of the checklist: one /search call returns the sources Google, ChatGPT, AI Overviews, Perplexity, Claude and Gemini cite for a query, in a chosen country, plus the cross-engine hotspots and the contacts behind each cited source. The citation map, hotspot list and gap list are the direct output of that call, as structured JSON, which is what makes the appendix reproducible and the audit re-runnable four weeks later.
Agencies packaging the audit as a paid entry point start at Getspotted for agencies; teams running it in-house start with the API reference to model the per-audit cost.
FAQ
What should an AI visibility audit include?
An AI visibility audit should include a frozen query set (30 to 100 queries), a declared engine and country list, a locked competitor list, a citation map of the sources each engine cites per query, a share-of-voice baseline, a hotspot list, a gap list of named domains, an AI crawler access check, and a prioritized action plan. The raw citation data belongs in the appendix so the audit is reproducible.
How is an AI visibility audit different from an SEO audit?
An SEO audit inspects crawlability, rankings and backlinks against Google's ten blue links. An AI visibility audit inspects which third-party sources ChatGPT, Perplexity, Claude, Gemini and Google AI Overviews cite when assembling an answer, and whether the brand appears among them. The two diverge: a page ranking #1 on Google can be absent from every AI answer in its category.
How long does an AI visibility audit take?
An automated AI visibility audit takes 3 to 10 working days: 1 to 2 days scoping, minutes for API-based data collection, 2 to 4 days of analysis, and 1 to 2 days of report writing. Manual collection across 5 engines adds 3 or more days and makes the audit non-reproducible, because prompts drift between sessions.
How much does an AI visibility audit cost?
US AI visibility audits anchor between $1,500 and $4,000 as a one-time deliverable in 2026, priced on query count and country count rather than hours. A 30-query, single-country audit sits near the bottom of that band and a 100-query, 3-country audit near the top. The full pricing model is in the GEO agency retainer pricing playbook.
How do you know if an AI visibility audit is legitimate?
A legitimate AI visibility audit discloses its query set, names each engine individually, declares the country, and shows the cited URLs behind every number. Red flags: a single-engine "AI" audit, a proprietary 0-100 score with no source list, no country declared, guaranteed citations, or recommendations that route only to the provider's own paid placements.
Should an AI visibility audit cover more than ChatGPT?
Yes. AI engines cite different sources for the same query, so an audit limited to ChatGPT misstates the picture by construction. Cover ChatGPT, Perplexity, Claude, Gemini and Google AI Overviews individually, and report per engine, because a brand can be well cited on one engine and absent from another.
How often should you re-run an AI visibility audit?
Re-run a full AI visibility audit only when a decision depends on it, typically every 6 to 12 months or after a major GEO program. An audit is a snapshot, so re-running it weeks later with no intervening action produces noise. Once a baseline exists, recurring monitoring on the same frozen query set is the right instrument, not a repeated audit.
Can you run an AI visibility audit yourself?
Yes, if you can freeze a query set, query each engine per country, and record the cited sources reproducibly. The bottleneck is collection: 50 queries across 5 engines and 2 countries is 500 sessions by hand. Teams that run audits in-house automate collection through an AI citation API and spend their hours on the gap list and action plan instead.
Written by
Alexis Maresca
Cofounder, Getspotted · GEO & AI visibility expert
Alexis Maresca is a cofounder of Getspotted and a specialist in Generative Engine Optimization (GEO). He helps brands and agencies understand which sources AI engines like ChatGPT, Perplexity, Claude and Google AI Overviews cite, and how to get featured in AI-generated answers.
See what AI recommends to your buyers
Scan 6 AI engines in one click. Find the sources they cite. Get your brand featured.
Try Getspotted free