Free checklist
The 36-Point SEO, GEO and AIO Checklist
Thirty-six checks for getting found in Google and in AI answers. Each one has a plain-English line, a free way to run it, and a link to its source. Plus the eight things sold as AI SEO that do nothing. Free PDF.
PDF · Free
What is inside
The full contents, so nobody hands over an email to find out.
I went looking for a good SEO checklist for AI search and found the same advice on most of them: add an llms.txt file to your site so the AI models can read it.
Google's own documentation says, in these words, that Search ignores that file and it will neither harm nor help you. Nobody at OpenAI, Anthropic or Perplexity has ever said on the record that their systems read it either.
That is the state of this topic in 2026. The loudest advice has the thinnest sourcing, and the honest version is boring: get the technical basics right, be a real brand, make sure your CDN is not blocking the crawlers that actually produce citations, and measure the small amount you can measure.
So every check in this PDF carries its source. Where a vendor documents something, I quote the vendor. Where a study measured something, I name the sample size. Where nobody has measured anything, I say so instead of filling the gap with a number.
What's inside
Eight parts, thirty-six checks, and 71 links to the pages the claims came from.
- Measurement first. The two reports that actually show you AI answers (Google's Generative AI performance report and Bing's AI Performance report), GA4's built-in AI Assistant channel, and a written list of what you cannot measure at all
- Crawler access. OpenAI runs four crawlers and only one of them decides your citations. Same question for Perplexity and Claude, plus the two live fetchers that ignore robots.txt entirely
- The setting nobody opens. Google's Search generative AI control in Search Console, what it actually costs, and why Google-Extended is not the AI Overviews opt-out that half the internet thinks it is
- Your CDN. From 15 September 2026, on some plans, blocking AI crawlers becomes the default. The evidence is in your access log, not your config screen
- Findable at all. One canonical host, a sitemap that matches what is indexable, content that exists without JavaScript, and the Core Web Vitals numbers Google publishes today rather than the ones a 2026 blog told you
- Keywords and content. Starting from your own Search Console queries instead of a keyword tool, the commodity versus non-commodity test, and what structured data still does now that FAQ rich results are gone
- Off-site. What the 75,000-brand correlation study actually found, and why the same company measured the same variable five months earlier and got a wildly different number
- The eight things to stop doing. llms.txt, content chunking, rewriting for AI, schema as an AI requirement, blocking the wrong OpenAI crawler, Google-Extended as an opt-out, the AI conversion multipliers, and the single top-10 overlap figure that four measurements disagree about
- A printable run sheet. Every check as one line with a checkbox, cross-referenced back to the section that explains it
- A link directory. Google's own docs, the AI vendors' crawler pages, every free tool with its current limit, and the studies with their sample sizes attached
Two tracks, so you can skip half of it
Every check opens with one plain-English line, then the detail underneath for whoever is doing the work. If you own the decision and not the implementation, read the plain lines and ignore the rest. If you are the one running it, there are commands.
What it is not
It is not a tool list. Every check has a free way to run it, using Search Console, Bing Webmaster Tools, curl, the Rich Results Test, or your own logs. Paid tools get named twice, in the two places where free genuinely cannot do the job.
It is also not neutral about advice that has no evidence behind it. Part 7 exists because the peer-reviewed work on this, including a NeurIPS 2025 benchmark built to test these tactics, found most of them ineffective and several of them harmful. That is worth knowing before you pay someone for them.
Who it's for
Anyone responsible for whether a site gets found: developers, agencies, in-house marketers, and founders. No SEO background needed for the plain-English track.
Frequently asked questions
Is GEO or AEO a real discipline, separate from SEO?
Not according to Google. Its May 2026 guide says that from Google Search's perspective, optimising for generative AI search is optimising for the search experience, and is therefore still SEO. The checklist is built on that position, which is why it is one list rather than three.
Do I need an llms.txt file to show up in AI answers?
No. Google states that Search ignores the file and that publishing one will neither help nor harm your rankings. No other major AI vendor has said on the record that its systems read it. Publishing one is cheap and harmless. Paying for one is not defensible.
Does blocking GPTBot remove my site from ChatGPT?
No, and this is the most common mistake in the robots.txt files I read. Per OpenAI's own documentation, GPTBot is the training crawler. OAI-SearchBot is the one that decides whether you appear in ChatGPT search answers. Block GPTBot and you opt out of training while keeping your citations.
Can I stay in normal Google results but leave AI Overviews?
Yes. The Search generative AI control in Search Console excludes you from AI Overviews, AI Mode and generative AI in Discover, and Google states it is not used as a ranking or inclusion signal for the rest of Search. It is all or nothing across those three AI surfaces, and it costs you every impression from them.
Is structured data required for AI citations?
No. Google's guide says structured data is not required for generative AI search and there is no special schema you need to add. Keep adding it for rich results, where it does still work, and stop selling it as an AI lever.
How much of my AI visibility can I actually measure?
Less than you would like. Google reports impressions only, with no clicks. Clicks from an AI Overview arrive in analytics as ordinary Google organic traffic with nothing to distinguish them. OpenAI, Anthropic and Perplexity give site owners no console at all. The checklist covers what to do about that, including a manual prompt panel that costs nothing.
Get the PDF
Drop your name and email above and it's yours. Twenty-eight pages, clean and printable, with every link clickable.
Where should I send it?
One field. Every extra field costs you downloads.
The other checklists
The 17-Point Self-Hosted Security Checklist
The exact checklist I run on every server before it touches the internet. Firewall, SSH, containers, secrets, and backups, with the commands. Free PDF.
16 Moves That Make Claude Code Work in a Large Codebase
The setup order behind Claude Code deployments that stick, from CLAUDE.md files through hooks, skills, plugins and LSP to subagents, with a 19-step start-here list. Free PDF.
The Pre-Launch Site Audit Checklist
The 16 checks I run before any site goes live. The things that break silently between "the site is built" and "the site is found", each with the command that proves it. Free PDF.