
Let me tell you how this story got reported, because the process is the story, and the process was a masterclass in being handed a pamphlet.
For weeks, ADOTAT has been trying to get Mobian to answer questions about Agent Ads, the product it launched with TIME on July 30 that plants sponsored FAQ blocks inside the machine-readable versions of TIME's pages. The versions built for AI crawlers. The versions no human being will ever see unless they spoof a User-Agent header and go digging like it's 2011 and you're trying to find the real Yelp reviews. We sent ten questions. Real ones. About methodology, about billing, about conflicts. The kind of questions a measurement company founded by the guy who built Moat, the verification firm Oracle actually paid money for, should be able to answer before finishing his coffee.
What we got back, this week, was a link. Not from Goodhart. From a colleague, forwarding us a blog post the CEO had already published for literally everyone, as though we might not have noticed the internet. Go read the public statement, it said, in politer words than that. And we were not alone in the reading room. When The Register asked TIME to verify what its own reporters had already found in the markdown pages, TIME didn't answer either and pointed them at a Digiday story instead. Two publications, two brush-offs, one link, and a company that apparently believes the press release and the answer are the same document.
So we read the post. Slowly. Twice. And here is the honest verdict on Jonah Goodhart's "Agent Ads Initial Response," published August 11: it is a genuinely well-built piece of writing that answers the easy version of every hard question and skips the hard version entirely. It is the FAQ equivalent of a politician who "hears the concerns." It raises more questions than it settles. Which would be a survivable problem, except for what happened the same day it went up.
The word that isn't in the response
The post opens by declaring the reaction since launch has been "overwhelmingly positive." Brands reaching out. Publishers reaching out. The vibes, apparently, immaculate.
Here is what else happened. Digiday reported, also on August 11, that Perplexity has blocked all markdown advertising on Time.com from influencing its agents. Not flagged it. Not asked politely for a meeting. Blocked it, roughly since the moment the practice was first reported. Perplexity's chief communications officer Jesse Dwyer told Digiday that publishers who deploy "deceptive advertising like markdown ads" risk a reputational downgrade in Perplexity's search index, including a hit to their trust score. Sponsored label or not. Perplexity, notably, is not known for subtlety when it decides you're the problem.
Now go back to Mobian's launch post from July 30. It names exactly two AI systems that accessed the first Agent Ad in real time: ChatGPT and Perplexity. One of the two named launch guests has walked out of the party and told everyone at the door what they thought of the hors d'oeuvres.
The body of Goodhart's roughly 4,000-word response handles the matter in a section titled "Won't models block this, and what happens if they do?" Note the tense. Might. Hypothetically. Someday, perhaps, in a galaxy far away. The post treats as a thought experiment something that had already happened, to Mobian, on its only live publisher, from one of the two agents it name-dropped at launch like a wedding invite list. Goodhart's on-record reaction, when Digiday actually asked him, was that the block was "a bit perplexing." Cute. The invoice question is less cute, and we'll get to it.
A document titled Initial Response that does not respond to the actual response is not a FAQ. It is a press release wearing a lab coat.
The disclosure protects the wrong party
The post's central defense is transparency, and to be fair to Goodhart, he says the word "transparent" like a man who has genuinely convinced himself. Sponsor named in the first line of every ad. Citation on every fact. Fully inspectable, anyone can open the file and read exactly what an agent reads. All of this is true, and all of it is beside the point, because the file being open to inspection is not the same thing as anyone actually inspecting it.
Every disclosure Mobian built points at the machine. The model sees the sponsored label. The model sees the citations. The human at the end of the chain, the one who asked ChatGPT which bank to consider, sees an answer. No label. No citation. No idea. No label survives ingestion, which is either an oversight or the entire business model, and the response post never tells us which because it never mentions that person exists.
This is not a gap Mobian discovered by accident. It is the product. Goodhart said it himself to Digiday at launch, in the quote that will outlive the company: "When you influence ChatGPT, you're influencing potentially all of ChatGPT. If ChatGPT changes what it says about [a brand], it's massive and it's more than any one campaign could ever do."
Read that next to the response post's insistence that Agent Ads are just facts a model may weigh or ignore, take it or leave it, no big deal. Influence when he's selling. Information when he's defending.
Pick a lane, Jonah.
"Everyone tricks Googlebot" is not the defense you think it is
Some people, hearing all this, want to wave it off with the oldest line in the industry: everybody's been gaming crawlers since crawlers existed, cloaking is basically the founding sport of SEO, relax.
Sure. And? That's not an excuse. That's a confession with a shrug attached. The old game was already grubby, and the fact that an entire generation of publishers spent a decade quietly serving Googlebot a different page than they served you is not a defense of the practice, it's an indictment of the era. We built a whole vocabulary for it, gray hat, black hat, the SEO underworld, because everybody involved understood, even at the time, that it was a little dirty.
Here's the thing. Agent Ads is not that system. It is not a decade-old hack bolted onto a legacy CMS by an intern in 2009. It is a brand-new product, built from scratch in 2026, by a former CEO of a company whose entire reason for existing was independent measurement you could trust. Mobian had the rarest gift a company gets: a blank page. No legacy debt. No decade of bad habits to inherit. And on that blank page, the founding decision was to fork the response by User-Agent header and quietly hand the paying crawlers something the free ones don't get.
If you're building the thing from nothing in the age of AI, the excuse "well, this industry has always been a little gray" doesn't hold up, it just tells us which shade you picked on purpose. Maybe it's time to actually do it right. Not gray. Not dark. Not blackhat with better branding and a citation footer. The technology is new. The sins don't have to be inherited.
The cloaking rebuttal redefines cloaking
The post asks itself, is this cloaking? And answers no, because cloaking means deceiving, and nothing here is concealed.
That is a definition by intent, offered by the party being asked about its own intent, which is not usually how definitions work. The operational definition, the one search engines have enforced for twenty years, is a mechanism: serving a crawler a different document than a human gets at the same URL. Vincent Schmalbach, the German developer who found these ads in the wild before most of the trade press did, documented the mechanism precisely. ClaudeBot, OAI-SearchBot and PerplexityBot receive the sponsored markdown. Google's standard search crawler gets the same HTML a human gets. The Register replicated his results. The ads sit on evergreen content, the Best Inventions list, the TIME100 Creators pages, the stuff models cite for years, quietly, in the background, forever.
Sit with that routing table for a second. The crawler that could actually penalize you for cloaking gets the clean version. The crawlers that answer consumer questions get the paid one. Whatever you want to call that arrangement, "nothing is concealed from anyone" is doing a lot of cardio for one sentence.
Rob Derow of BCG X said in Digiday, before Perplexity acted, that the biggest risk with markdown ads was the absence of any rule governing how models treat them, and that models could come to read the practice as cloaking. He said it in July. Perplexity did it in August. When the consultant's caution note becomes the platform's enforcement action inside two weeks, the caution note was not cautious enough, and somebody at Mobian should be forwarding Derow a very awkward email.
The numbers grade their own homework
The response post leans hard on provenance. Facts with citations are trustworthy. Facts without them are the mud of the open web. Fine. Let's apply the standard to the man holding the ruler.
Models get brand facts wrong around 34% of the time. Source: Mobian's latest internal data. Roughly 17% of sources AI engines cite conflict with a brand's own positioning. Source: a Mobian study of 750-plus brands, unpublished. 98% of Newsweek's content graded brand-safe over six months, versus the 63% keyword blocklists flagged. Source: a Mobian trial, no published methodology, conducted on a publisher that appears on Newsweek's own advertising page as a paying Mobian partner, which is a sentence that should make everyone in the room go quiet for a second.
Every number that sizes the problem comes from the company selling the fix. No sample construction, no definitions, no third party, no audit. The company that built its founding mythology on making Moat the independent referee of ad measurement now serves the page, inserts the ad, counts the exposure, defines the impression, and scores the outcome, and asks to be taken at its word on all five, which is a lot of hats for one referee to be wearing simultaneously. Goodhart spent years arguing the incumbents should show their work. The standard you demand of Nielsen is the standard you owe the rest of us, and we are, in fact, the rest of us.
And the impression itself? The post says test requests via curl don't count, and that real impressions are verified by rDNS confirmation of the agent operator, "depending on the CDN and agent operator." Depending on. That is not a standard. That is a weather report. Meanwhile the served pages carry a Mobian header that mints a fresh impression ID on every single request. Somewhere between that header and the invoice, someone is doing subtraction, and nobody outside the building audits the math. Which brings us back to Perplexity: is blocked-agent traffic still being counted, and billed, on the Ally and PMI campaigns? We asked. See above regarding the link.
The science is pointed at the wrong process
The response post cites real research, and this is the part where the sophistication actually works against it. Kandpal. Allen-Zhu and Li. Chang. Legitimate papers, correctly summarized, about how many times a fact must appear in a pretraining corpus for a model to retain it. Roughly a thousand exposures for full storage. Facts fade without repetition. All true. All from a completely different room in the building.
Goodhart deploys this to answer whether more AI impressions matter. The papers are about training. Agent Ads are about retrieval. A page a model reads while answering a question never touches its weights. The model forgets the ad the moment the conversation ends, which is precisely why the post's other pillar, real-time updatable brand facts, works at all, a fact that quietly contradicts the training citations three paragraphs earlier. He half-concedes the distinction in a subordinate clause, then keeps the conclusion anyway, which is the intellectual equivalent of footnoting your own alibi. And notice which conclusion the sleight of hand supports: repetition builds retention, therefore buy more impressions. The citations aren't scholarship, they're load-bearing for the media plan.
The efficacy evidence has the same shape. Causal Ad Impact puts the brand's fact on the page and confirms the model reading the page repeats it. That is retrieval functioning as designed, a thing literally nobody disputed, ever. Goodhart's own proof-of-life demo, per Digiday, was prompting ChatGPT and Perplexity to fetch a specific TIME page and watching the ad come back, which is a bit like proving your smoke alarm works by holding a lighter to it yourself. Asking a model to read a page and observing that it read the page is not influence. It is literacy. The honest test, Model Impact, queries models cold with no page attached, and there the post reports statistically significant movement on exactly one question, described as the campaign question with the most room to move. When a company cites its Benjamini-Hochberg correction and then publishes the single best performer out of a pre-registered family, the correction is the confession.
What we're left with
Strip away the citations and the McNemar tests and the post makes one argument: brand facts are good for models, so models that block them will suffer for it. That is a vendor telling the platforms that refusing his product will be to their detriment, two sentences after insisting the model can always choose freely. One of those platforms already chose, and chose no.
Somewhere under all of this is a real question that deserves better than either the hype or the hand-waving: how does a publisher get paid when the majority of its visitors have no eyes? TIME sees more bots than humans most days. That traffic earned nothing. Wanting to monetize it is rational, and Goodhart is right that the business models have to evolve, we're not the ones arguing otherwise. But the first serious attempt at it has produced a product where the disclosure never reaches the human, the measurement never leaves the vendor, one launch platform calls it deception, and the company's answer to weeks of specific questions is a link to a blog post it already wrote for someone else.
We've told Mobian this is an ongoing story, because it is. Our questions are open, the offer to come on the show stands, and we will print their answers at length and in context whenever they arrive, gray areas and all. The post says anyone can open the file and read exactly what's inside. We did. The file was easy. The company is still locked.
How we reported this: This piece is based on Mobian's published launch and response posts, Digiday's July 30 and August 11 reporting, The Register's August 5 story, Vincent Schmalbach's technical documentation of TIME's user-agent routing, and public materials from Mobian, TIME and Newsweek. ADOTAT sent Mobian ten detailed questions and received a referral to the company's public blog post; our questions remain open and this story will be updated with any substantive response. Figures attributed to Mobian (34%, 17%, 98%) are the company's own internal, unpublished numbers and could not be independently verified. Jonah Goodhart has previously appeared on The ADOTAT Show. ADOTAT has no financial relationship with Mobian, TIME, Perplexity, or any company named in this piece, and has taken no money from any of them. No subject received advance review of this article.
You've read this far. Read the rest with us.
Members fund the reporting and read it first. No advertisers, no sponsored anything, just the people who want this work to exist.
Join ADOTAT+What members get:
- Every investigation, including the ones with a lawyer's fingerprints on them. Those are the good ones.
- The Field Kit. Because "do your own diligence" is useless advice without the actual checklist.
- Their side, unedited. You get the full statement before I take it apart. Judge for yourself which of us is being unfair.
- No paid editorial. Not one word, not ever. If it's in the copy, nobody paid to put it there.


