# What an AI Search Audit Should Include: A Guide for UAE Businesses By Tamara Karmiczewska An AI search audit has two halves: one tests what the assistants actually answer when someone asks about your category, recorded so the test can be run again, and the other inspects what your own site publishes and whether a machine can reach it, read it and quote it correctly. A complete audit does both and hands over the evidence from each. Lunasol, the agency that owns AI Visibility, opens its GEO service with an audit of its own, so the checklist below is one to hold any provider to, ourselves included. The short version: a real audit gives you a written prompt set, a raw run log with the environment recorded, a fixed competitor list and a dated baseline. It also gives you an inventory of the sources the answers cited, a list of wrong facts, a fix list with owners, and a re-test date. Nobody can promise you a mention. Why an audit has two halves An AI search audit is a two-part, repeatable exercise: a recorded test of the answers, and a documented inspection of the pages behind them. It has two halves because one of those jobs is done by measuring and the other by inspecting, and neither method answers the other's question. The answer half asks what comes back when your customers ask, who gets named, on what evidence, and from which pages. It means nothing unless it can be run again. The site half asks what your pages publish and whether a machine can read it. It rests on documentation rather than opinion. Sold on its own, each half is a fragment. An audit that produces only screenshots cannot tell you what to change. An audit that produces only a technical checklist cannot tell you whether changing it moved anything. The two halves of an AI search audit, side by side: What you are comparing Answer half Site half Question it answers What do the assistants say about my category and my company? Can a machine reach, read and quote my pages? What it produces A log of runs, with dates, platforms and environment An inventory of files, controls and page facts Evidence it rests on Repeated measurement Your server, your CMS, your published pages Who does the work Someone who can run and record tests Someone with access to the site What it cannot tell you Why an answer came out that way Whether anything changed in the answers In practice the two halves run in sequence rather than side by side: the answers are measured first, then the pages behind them are worked on, then the same questions are asked again. Lunasol's published process runs in that order too. It opens with the audit, putting the questions a buyer's customers actually ask to the AI tools those customers use, and then works on the signals and the pages those tools read (Lunasol (https://lunasol.ae/geo-aeo)). What we found when we ran both halves We ran both halves in September 2026 on two questions a Dubai buyer would actually ask, and the halves did not explain each other. We asked who the best interior design companies in Dubai are, and which company to use for an office fit-out, twice each in ChatGPT and once each in Google's AI Mode. The ChatGPT runs were temporary chats with personalisation off and thinking effort set to high, and the Google runs were made while signed in. One further ChatGPT run failed with an error message and returned nothing. We logged that as a failure and re-ran the same prompt unchanged in a fresh chat rather than quietly dropping it, which left six answers to work from. We then took the domains those six answers cited, set aside a video platform and a social network as platforms rather than business sites, and fetched robots.txt on the twenty-nine business domains that remained. That file sits at the root of a site and tells crawlers which paths they may fetch. One day, one set of accounts, one connection. Far too small to be a study. We logged what the assistants said and verified none of it, and we name no company. The answers ran on published credentials. Every company named arrived with the same kind of evidence attached: a founding year or a number of years in the market, project counts, named client projects, certifications, award names with years, in-house capability lists, and a district or a street. One ChatGPT answer closed its first recommendation with the firm's ISO credentials. Another named four client projects, three of them with the year. One ChatGPT answer carried a map card with star ratings. Google's answers gave the district or the street for each firm they listed. For a buyer, that list is the specification. Those are the facts an audit should check your own pages state in text, because they are the ones the answers were built from. The two tools did not return the same list. On the first question the three answers named eight, seven and thirteen companies, with four names appearing in more than one answer. On the second, one ChatGPT run shortlisted four firms and the next shortlisted three, two of them shared, and none of those appeared in Google's answer at all. The same published record came back in two versions. One run described a firm by its founding year and a count of certified projects. The next run described the same firm by the number of years it has been in the market, with a count one higher. Both are readings of the same public record. An audit line that says only that the assistants mention your certifications has recorded nothing useful. It has to capture the claim as stated, run by run, so that a wrong version can be challenged. On the site side, almost nobody had made a decision. Twenty-seven of the twenty-nine domains returned a readable robots.txt. Twenty-three of those named no AI crawler anywhere in the file: no GPTBot, no OAI-SearchBot, no Google-Extended, no PerplexityBot, no ClaudeBot, nothing. In practice their position on AI crawlers is whatever their "User-agent: *" block happens to say. Four named at least one crawler explicitly, and all four allowed it. None of the twenty-seven blocked an AI crawler, and none carried a blanket disallow. Two domains did not return a file to us at all. One failed certificate verification and one timed out on connection. We fetched each file once over HTTPS, from one connection, on one day, so we cannot conclude from this alone that either site is broken for everybody. What we can say is that both were cited in answers we logged, and that nothing in those answers hinted at it. That is the argument for inspecting a site from its own side instead of inferring its state from an answer that quotes it. The honest reading of our own data is that on this sample the crawler layer explained nothing about who got named. Almost none of these sites had made any decision about AI crawlers, so there was no permission pattern to separate them by. We surveyed no uncited sites, so we cannot say whether the picture differs there. For a buyer this cuts both ways. On a site like these, an audit that checks only robots.txt will have very little to report. One that reads only answers will never notice that a certificate did not verify. What the answer half should contain The answer half should contain a written, repeatable test rather than an impression. Seven things make it one. A prompt set, handed over as a file. How many questions, in which categories, and why those. Category questions, brand questions, comparison questions, and the buying questions your customers actually ask. A named list of platforms. ChatGPT, Google's AI Mode and AI Overviews, Perplexity, Gemini, Copilot, Claude. Which are in scope, and which are not. Run every question more than once. Our own two runs of the same question, minutes apart in the same mode, returned eight names and then seven, with four in both. The environment recorded, every time. Fresh or temporary chat, personalisation off, the location the tool used, the account tier, free or paid, and the date. Without it, the next round is not comparable with this one. Fix the competitor set in advance. The second measurement then scores against the same list as the first. A per-run record. Whether you appeared, in what position, what was said about you, which other companies were named, which domains were cited, and any fact that was wrong. Date the baseline. This is the number everything later is measured against, and it is worth very little if it was assembled after the work started. The measurement has to be framed honestly, because the platforms frame it honestly themselves. OpenAI writes of ChatGPT search that it "ranks search results using multiple factors intended to help users find relevant, reliable information" and that "Placement is not guaranteed", adding that "Search results and citations can be incomplete, outdated, or incorrect" (OpenAI Help Center (https://help.openai.com/en/articles/9237897-chatgpt-search)). What the site half should contain The site half should contain an inspection of things that exist on your own server, each with a file name or a URL against it. Expect the person who can log into your CMS, your hosting and your Search Console to be in the room for this part, because the items that touch those systems cannot be done from the outside. If that person is an outside developer, they may also be the one implementing the fix list, so budget their hours separately from the audit fee. Crawler access, read for what each name actually does. The tokens are not interchangeable and an audit should say which is which. OpenAI's documentation states that "OAI-SearchBot is used to surface websites in search results in ChatGPT's search features", while GPTBot "is used to crawl content that may be used in training our generative AI foundation models" (OpenAI (https://developers.openai.com/api/docs/bots)). Perplexity documents PerplexityBot, which it says is "designed to surface and link websites in search results on Perplexity". Perplexity-User is a separate fetcher, triggered when a reader asks for a page. Of that one Perplexity writes: "Since a user requested the fetch, this fetcher generally ignores robots.txt rules" (Perplexity (https://docs.perplexity.ai/guides/bots)). The audit's job here is to report which of these names your file mentions, whether each is allowed or blocked, and whether the file says what you assumed it said. List the snippet and indexing controls page by page. Google's guidance is that there are "no additional requirements to appear in AI Overviews or AI Mode, nor other special optimizations necessary", and that to limit what is shown you "use nosnippet, data-nosnippet, max-snippet, or noindex controls" (Google Search Central (https://developers.google.com/search/docs/appearance/ai-features)). These were often set years ago by somebody who has since left, so the audit should name every page where one is live. Whether the page can be fetched at all. Certificate, redirect chain, response codes, and whether the content survives without JavaScript. Two sites in our own sample failed this for us and were being quoted regardless. The facts your pages state, in text. What you do, for whom, where, what it costs, what is included, who to contact, and which of these appear only in an image, a PDF or a contact form. An assistant can quote a fact that exists as readable text. Bury the same fact in an image, a PDF or a contact form and it becomes harder for the machine to reach and harder for you to correct. If you publish in Arabic as well, the inspection covers those pages separately, because the Arabic pages can carry a shorter or older set of facts than the English ones. Check the structured data instead of assuming it. Whether your pages carry schema.org markup for the organisation, its services, its location and its FAQs. This is machine-readable code, usually in JSON-LD, that restates the page's facts in a fixed format. Check that it validates and that what it declares matches the visible page, because markup that contradicts the page is worse than none. Consistency across the places that describe you. The same legal name, address, category and service list on the site, the business profile and the directories, because a contradiction between your own sources is where a wrong answer later can come from. Our own runs showed the same published record restated two different ways. Report the llms.txt check as a fact, not a promise. Say whether the file exists and what it claims. It is a proposal rather than a published requirement, and none of the crawler documentation quoted in this guide mentions it. We looked for one on two of the cited domains and neither had one, and we did not look on the other twenty-five, so we can say nothing about those. Reporting set-up. Google folds AI features into ordinary Search reporting, stating that sites appearing in AI features such as AI Overviews and AI Mode are "included in the overall search traffic in Search Console" and that "they're reported on in the Performance report, within the 'Web' search type" (Google Search Central (https://developers.google.com/search/docs/appearance/ai-features)). An audit should leave you able to open that report yourself. How Lunasol approaches an AI visibility audit Lunasol treats the audit as the first step of a cycle rather than as a document delivered once. Its published process runs in four steps, and the first is the audit: the step is described as putting a buyer's questions to the AI tools their customers use, and the question research on the same page starts from "what your customers actually ask". The three steps after it are Signals, "Entities, brand mentions, consistent facts and structured data across the sources models actually read"; Content, "Direct answers, quotable lines, FAQ blocks and schema on every page"; and Track, described as re-asking the models "your customers' questions" every quarter (Lunasol (https://lunasol.ae/geo-aeo)). For a buyer, the shape of that matters more than the labels. The audit produces the question list and the baseline. The middle two steps act on what the audit found. The fourth step puts the questions back through the models on a schedule, which is what turns a first measurement into a trend. It is also the structure this guide argues for: a dated baseline first, the work in the middle, and the same questions asked again on a fixed schedule. The files you should be handed at the end You should be handed eight files, not a presentation. Each of these is something you keep: The prompt set, in a format you can re-use. The raw run log, with every run in it, including the empty ones and the ones that failed. A baseline table carrying the date, the platforms and the competitor set. An inventory of every source the answers cited, marked as yours or not yours. A list of wrong facts. Each one carries a note on where it probably came from. A fix list in priority order, with an owner and an effort estimate on each line. A re-test date, plus a written commitment that the same questions will be asked the same way. A written list of what is excluded, so the boundary of the engagement is on paper rather than assumed. Two things about that list belong in the contract. The first is ownership: the prompt set, the log and the fix list should be yours to keep and to hand to a different provider next year without asking permission. If any of it lives in the provider's own dashboard, ask what happens to your access when the contract ends, and ask for the underlying data as a file you hold regardless, because a dashboard you lose is not a deliverable you own. The second is the raw log. If a report arrives without one, you cannot audit the auditor, and every number in the summary has to be taken on trust. What you supply to the audit You supply eight things, and it is better to know that before the kick-off call. Expect to provide your service list in plain language, the questions you believe customers actually ask, and the competitors you want to be measured against. You will also need the facts you want stated correctly about you, CMS or developer access for the site half, access to Google Search Console, which the site half needs and which somebody may have to set up first, access to your Google Business Profile and any directory listings, and a named person who can sign off on published wording within a working day. Budget a few hours of that person's time in the first week, because published wording cannot go out until somebody approves it. Then do the sums before you compare quotes. A set of thirty questions, run twice each across three platforms, is a hundred and eighty recorded answers. Someone has to read each one, log it, check it for wrong facts and note its sources. That is the number to hold a price against, along with two others: how many working days pass between kick-off and the report, and what a repeat cycle costs, because the second measurement is where the value sits. Scale the prompt set to what you sell, with one set of buying questions per service line and one per emirate if you sell in more than one. A proposal offering a handful of questions, asked once, on one platform, has not produced a baseline. After the report arrives Somebody has to implement the fix list and somebody has to run the re-test, and both belong in writing before the audit starts. Ask who implements each line, whether implementation sits inside the fee or is quoted separately, when the re-test happens, and what the report looks like the second time. Get the interval in writing. A re-test with no date is how a baseline quietly becomes a one-off. If you already have an SEO agency, settle the overlap before signing. The site half is where the two services meet: crawl access, response codes, structured data and page facts may be work your SEO agency is already doing, and you should not buy the same technical crawl twice. Ask the audit provider to mark every line on the fix list as new work or as something your incumbent already covers, then give each page a single owner. The measurement, the prompt set and the log should stay with whoever runs the audit, because comparability across rounds is what you are paying for. And if a meaningful share of your customers search in Arabic, say so at the briefing stage, before the quote is written. Arabic is a second measurement rather than a translation. It needs its own prompt set, its own baseline and its own competitor list, with the prompts written by someone who speaks the language those customers search in, because there is no basis for assuming the Arabic answers name the same firms. Our own runs were in English only and tested nothing in Arabic. Adding Arabic roughly doubles the number of recorded answers, so it should be priced that way rather than added for free. Machine-translated prompts are a tell in themselves. The tells of a repackaged SEO report A repackaged SEO report gives itself away on eight points, and any one of them is reason enough to ask for the raw material behind the report. It is possible to sell one half of this work and call it the job: a technical site report with a new cover on it, or a folder of screenshots from one afternoon in ChatGPT. Keyword rankings and backlink counts lead the document, and the AI section is a short appendix. There is no prompt set, because no fixed set of questions was ever written down. Screenshots appear without dates, without the mode they were taken in, and without any sign of how many times the question was asked. An AI visibility score is quoted with no method behind it and no way to reproduce it. No competitor list was fixed in advance, so the comparison changes every time. The fix list is the generic technical checklist you would get for any site, with nothing on it about the facts your pages state. There is no re-test date. Somewhere in the proposal, a placement is promised. What an audit cannot promise An audit cannot promise a mention, a position or a citation, and a provider who promises one is contradicting the documentation they are quoting from. Placement is not guaranteed. OpenAI says exactly that in its own help pages. Google states that no additional requirements or special optimisations are necessary to appear in its AI features, and the wording on both pages can change without notice. What an audit can promise is a measurement you can repeat, a list of things that are wrong, a list of things that are missing, and a date when somebody looks again. Questions worth asking any provider Fourteen questions separate a provider who has run audits before from one who has not, because each asks for something that exists only if the work was actually done. How many questions are in the prompt set, and may we see the list before we start? How many of them are buying questions a customer would type without knowing our brand name? How many times will each question be run? On which platforms, and which are out of scope? What environment will the runs happen in? Will it be recorded per run? Which competitors are we being measured against, and who chose them? Do we get the raw log, or only the summary? Who does each item on the fix list, and when is the re-test? Do we own the prompt set and the log afterwards? If the results live in your dashboard, what happens to our access when we stop paying? What do you need from us, and how many hours of our time? If we already have an SEO agency, which lines on the fix list are yours and which are theirs? Will anything be tested in Arabic? What is excluded from the engagement altogether? A provider who can answer all fourteen has done this before. Ask to see an anonymised example of each deliverable rather than a description of it. How to have an audit run Lunasol's GEO service opens with an audit, and you can reach the team by WhatsApp or email (Lunasol (https://lunasol.ae/geo-aeo)). Lunasol also offers a free AI visibility check as a starting point. This article is general information about buying and scoping a service, current at September 2026, and it is not legal, contractual or purchasing advice. The publisher of this article is owned by an agency that provides the service described here. The live check reported above was run on one day, on one set of accounts, over one connection, on two questions in a single sector. It illustrates a method and is not a study, and nothing in it is a finding about any particular company. No audit, by anyone, can secure a mention, a citation, a ranking or a position in any AI product. AI products and their documentation change without notice and differ by country, so check the current version of any page quoted here before relying on it. Product names are used here for identification only, and neither AI Visibility nor Lunasol is affiliated with, endorsed by or sponsored by any of the companies named. ChatGPT, GPTBot and OAI-SearchBot are products of OpenAI. Google Search, Search Console, Google Business Profile, AI Mode, AI Overviews, Gemini and Google-Extended are products of Google. Perplexity, PerplexityBot and Perplexity-User are products of Perplexity AI. Copilot is a product of Microsoft. Claude and ClaudeBot are products of Anthropic. WhatsApp is a product of Meta. All are trademarks of their respective owners. AI Visibility is owned by Lunasol.