OpenAI's always-on agents browse with no published user agent
Summary
A query asked once in AI Mode or ChatGPT now keeps re-running after the person leaves, and the OpenAI half of that traffic arrives from a cloud browser with no documented user agent.
Access rules and log reports keyed to OpenAI's four published bot names miss it. Segment by datacenter IP and headless-browser signals instead, and keep prices and hours current, because a later update reads the page as it stands.
Google opened AI Mode’s information monitoring to all users on September 28, after limiting it to Ultra and Pro subscribers, and OpenAI launched its always-on ChatGPT agents, called dots, on September 29. Search Engine Journal’s piece on the two rollouts lands on the part that matters for site owners: in both products the request stays active after the person who made it has closed the tab, so one query re-checks the web on a schedule.
On the OpenAI side, that re-checking happens in a browser nobody outside the company has a name for. OpenAI’s user agents documentation lists four: GPTBot for training crawls, OAI-SearchBot for ChatGPT’s search features, OAI-AdsBot for checking the safety of pages submitted as ads, and ChatGPT-User for actions a person starts. A dot is not on that list, and neither is the cloud browser it drives. Any access rule or log report built on those four names is already blind to the newest thing OpenAI shipped.
The traffic is not invisible, only unattributed. Search Engine Journal quotes OpenAI’s computers and apps page saying each dot works through a cloud computer and its own browser, and that “Some websites block cloud browsers or require further verification,” so something is detecting them already. OpenAI’s documentation does not say what user-agent string that browser sends, which makes a datacenter IP range or a browser fingerprint the likelier basis for those blocks. Robots.txt is the wrong lever here in any case: OpenAI’s own doc says that because ChatGPT-User actions are user-initiated, “robots.txt rules may not apply,” and a dot’s browsing is user-initiated in the same sense, so the same caveat presumably applies. An agent that works through a site’s own tools rather than ordinary page clicks, as in Cloudflare’s agent browser, is the same attribution problem from another angle.
Google’s half stays inside Search
Google’s monitoring gives less to instrument. A user creates one by adding “keep me updated” to a search, and Robby Stein, VP of Product for Google Search, wrote on September 28 that Search will “continuously check across changing info on the web.” What changed across the announcements is the links language. Google’s May I/O announcements and the June launch for Ultra subscribers both described updates arriving with links to the web, and Search Engine Journal notes that Stein’s September post drops that and talks about updates and suggested tasks instead. Whether a monitoring update sends anyone to the page it read is now an open question.
Search Console will not answer it either. Search Engine Journal’s review of Google’s documentation found AI Mode folded into reporting with no explanation of how monitoring updates are counted or identified separately, and none of the May, June, or September posts says how Search picks the sources for an update. The practical consequence is repeat reads with no traceable visit and no lever to pull. Search Engine Journal’s piece also makes the point that for local businesses and retailers, a later update can include information that appeared after the original search, so the facts on the page this week, not the ones that were live when someone searched, are what gets read back to the user.
What to do
- Stop treating OpenAI’s four published agents as the full list. In logs, segment by datacenter ASN and headless-browser signals rather than by user-agent string, and expect agent sessions to sit in the unattributed bucket.
- Decide the blocking question per path before a rule goes in. Blocking cloud browsers also blocks a logged-in customer’s delegated agent on checkout and support pages, which is why Cloudflare tests charging AI agents instead of blocking them.
- Enforce server side if you need to stop user-initiated fetches at all. A robots.txt line does not bind ChatGPT-User by OpenAI’s own account.
- Keep the facts that change accurate and dated: price, stock, opening hours. A monitoring update reads the current page, not a cached version of the one that was searched.
- Do not read movement in AI Mode reporting as monitoring activity. Nothing in Search Console separates the two.
Dots are rolling out to Pro users outside the European Economic Area, Switzerland, and the UK, and to Business Premium users in all supported regions, with the Enterprise beta off by default. Volume is likely small for now, which is the reason to build the log segmentation now rather than after it grows.