No Hacks with Slobodan Manic

No Hacks with Slobodan Manic

Download on the App Store

No Hacks with Slobodan Manic episodes

  • 234: OpenAI's Dots Are Cute. What They Do With Your Data Is Not.

    OpenAI's new agents, dots, are fuzzy balls with eyes that you name and dress. They also sign into websites with your saved passwords and read the email you connect. I went through OpenAI's pages to see what the face is covering. What a dot reads can train the model unless you find the switch, and websites are told nothing. I would not give one my logins or my card.

    Chapters

    • 00:00 Sam Altman's pitch, and what a dot is
    • 01:42 Do you need one?
    • 02:36 Where the face came from
    • 04:33 Launch day, and why now
    • 07:05 Under the costume: your data
    • 08:37 A model that looks for another way
    • 10:06 What the cute is for
    • 11:09 What websites are told
    • 12:39 Through the web, or over it
    • 14:01 The verdict

    Key Takeaways

    1. The face is how it gets sold. OpenAI had characters on the side in April. Meta made the character the product, and three weeks later OpenAI did too.
    2. What a dot reads can train the model by default. The setting is "Improve the model for everyone", and it covers the apps you connect, email included.
    3. OpenAI publishes no way for a website to recognise a dot. Its instructions tell the user to try their computer when a website blocks one.

    What to Do

    • In ChatGPT, open Settings, then Data controls, and uncheck "Improve the model for everyone".
    • Before you give any agent your logins or a card, ask what it does that you needed.
    • If you run a website, send it to me at nohacks.co/ai-accuracy. I'll put one question your customers ask to the AI assistants and send you what they said. It's free.
    • The newsletter is at nohacks.co/subscribe.

    Sources & Links

    From OpenAI

    • Introducing dots
    • Dots privacy FAQ
    • Dots, computers and apps
    • OpenAI's crawlers
    • GPT-6 Astra test results

    Mentioned in the episode

    • Thomas Germain, BBC, on Meta's Muse
    • The Tech Report, with Ed Zitron
    • Better Offline
    • FTC on Joe Camel, 1997

    No Hacks runs no sponsorships and is funded by advisory and audit work. 

    If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

    15 min
  • 233: Muse Is Why Meta Has No Business Building The Agentic Web

    Mark Zuckerberg says Meta's AI agent, Muse, needs to be discreet. The same month, some of the calls it made to businesses were placed by people in a call center. I went through what he told Joanna Stern and Alex Heath about Muse's privacy and security and sorted every claim by tense. What exists today, only Meta has checked. The protection from Meta itself is promised for later this year. My verdict: stay away from this. After the sign-off, the show moves to Saturday mornings.

    Chapters

    • 00:00 - Discreet AI, and calls made by people
    • 00:59 - What Muse is, and the agentic web
    • 02:33 - Joanna Stern's question
    • 03:57 - Present tense: the virtual machine and the ads
    • 05:45 - Passwords, Sentinel, Amazon and the Mac app
    • 07:05 - Future tense: the locked version and discretion
    • 10:10 - Who is asking: an ad company with a privacy record
    • 11:40 - From the browser wars to the agent wars
    • 14:42 - Two documents, 1993 and 2026
    • 16:00 - After the episode: moving to Saturdays

    Key Numbers

    • 500,000+ people tried Muse in its first week, as reported by The Information
    • 97.6% of Meta's 2025 revenue came from ads
    • $5 billion: the FTC's 2019 privacy penalty on Facebook
    • 87 million people's data reached Cambridge Analytica
    • 1993: CERN put the web's code in the public domain
    • "Later this year": when Meta says the version it cannot see inside arrives


    Key Takeaways

    1. Listen for the tense. What Muse does today is described only by Meta, and nobody outside Meta has published a check of it. The version Meta itself cannot see inside is promised for later.
    2. Meta's plan for Muse is a small cut of every transaction. Zuckerberg said the cut will come from the businesses. If you run a store, that is you.
    3. The early web worked because it was given away and ran on your own computer. This time the companies want to be in the middle from day one. It is the browser wars again, fought over the agent.

    What to Do

    • Before you connect your email, passwords or card to any agent, ask how it works today, in the present tense.
    • If you run a store on Shopify, check Sales channels, then Agentic. Meta's agent and Google's AI may be on by default.
    • Watch the full Joanna Stern interview.
    • The No Hacks newsletter is at nohacks.co/subscribe.

    Sources & Links

    The interviews

    • Joanna Stern, New Things with Joanna Stern
    • Alex Heath, Sources podcast

    Meta's own words

    • Introducing Muse
    • Meta's 2025 annual report

    The record

    • FTC, $5 billion penalty
    • CERN, 30 years of a free and open web

    No Hacks runs no sponsorships and is funded by advisory and audit work. 

    If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

    19 min
  • 232: The Agentic Web Is Still A Single-Player Game

    A hundred and seventy-two companies have put their name to A2A, the standard for AI agents at different companies to find each other and talk. I took the web address the project lists next to each name and asked 135 of them the question the standard is built around. Four answered. The reason is not technical: MCP needs one person to say yes, A2A needs two organisations.

    Chapters

    • 00:00 - AWS, Microsoft, Salesforce, SAP, and four answers
    • 00:54 - What I was actually sold, and what I went looking for
    • 01:31 - What counts as another party, and what does not
    • 03:08 - Single-player, and why the reason is not technical
    • 04:07 - MCP, November 2024: one person has to agree
    • 06:56 - A2A, April 2025: two organisations have to agree
    • 11:04 - What the agent card is, and why not having one is fine
    • 12:56 - Who is actually at your server
    • 15:35 - Forget the logos, watch your own logs
    • 16:24 - After the episode: the race to the bottom

    Key Numbers

    • 172 companies listed on the A2A partners page
    • 135 of them checked, both well-known paths, 270 requests
    • 4 served an agent card. 131 served nothing
    • 1 served it at the path the specification registers
    • 14 returned HTTP 200 at that path. 12 were the homepage
    • MCP: 1 person has to agree. A2A: 2 organisations

    Key Takeaways

    1. The visitor at your server is one person's assistant, not another company's agent. It fetches one thing, cannot ask a follow-up, and has no patience for a slow page. That is a smaller job than the one being described to you, and a different one.
    2. A protocol that pays off alone spreads. One that needs a counterparty waits. MCP works the afternoon you wire it up. You can implement A2A perfectly and get nothing until somebody you do not control has done the same work.
    3. Not having an agent card is not a failure. It is not a test, nothing scores you on it, and if no agent runs on your server there is nothing to publish.

    What to Do

    • Watch your own logs rather than the partner lists. The day something arrives that was clearly sent by another company's system, not a person, is the day this changed.
    • Treat a 200 as nothing. Twelve of the fourteen I found were a homepage answering to any address.
    • Answer clearly and quickly, and be honest about what you do not have. Most websites say yes to everything.
    • The No Hacks newsletter is at nohacks.co/subscribe.

    Sources & Links

    The standard

    • A2A specification, section 8.2 discovery
    • A2A partners list
    • IANA well-known URI registry

    The other protocol

    • Model Context Protocol specification
    • Announcing A2A, Google, April 2025

    No Hacks runs no sponsorships and is funded by advisory and audit work. 

    If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

    19 min
  • 231: A Paywall Stopped ChatGPT From Reading The Article. It Confidently Summarised It For Me Anyway.

    A magazine put a paywall in front of its journalism to stop AI reading it. I tested what that paywall actually checks. It reads one line of your request, the name you type in yourself, and compares it against a list. Say who you are and you get a bill. Make something up and you walk straight in. Then I asked two assistants to read the article anyway. Both got charged, both answered, and neither had read a word of it. It keeps going after the sign-off, about where this podcast is headed.


    Chapters

    • 00:00 - A story, and a bill instead of a page
    • 02:19 - What a 402 is, and who sells it
    • 04:02 - What the wall checks, and the name I made up
    • 06:46 - robots.txt says one thing, the server does another
    • 08:08 - Googlebot walks in free while Penske sues Google
    • 10:08 - Is anybody actually paying
    • 12:13 - I asked Claude and ChatGPT to read it
    • 15:22 - Being read or being cited
    • 17:42 - Ask your chatbot where it got the facts
    • 19:17 - After the episode: where this is headed


    Key Numbers

    • 402 Payment Required has been in the web standards since 1992 and almost nothing ever used it
    • robots.txt has been a convention since 1994, and nothing makes a robot obey it
    • 6,000 or 8,000 or 9,500 websites, depending which of TollBit's own pages you read
    • 25 robots named in Variety's robots.txt, 24 of them blocked
    • 3 crawlers get charged that the file never names at all
    • 0 AI companies named on TollBit's page aimed at AI companies
    • 1 paying customer ever named publicly, a news reader app


    Key Takeaways

    1. The paywall checks a name, not a robot. Every crawler that identified itself honestly got a bill. A name I invented, belonging to no company on earth, got the whole page one second later.
    2. Your server sets your policy and your robots.txt only describes it. Variety's two disagree right now, and three crawlers the file permits are charged anyway.
    3. Blocking the machine does not block the answer. It decides who gets credited when the machine repeats you. Two assistants credited a search engine and a podcast directory.


    What to Do

    • Request a page from your own website with a crawler name in the user agent, then with a name you invent, and compare
    • Read your robots.txt beside what your server actually returns, line by line
    • Check what Google-Extended covers before you rely on it, because it has never covered AI Overviews
    • Ask your assistant whether it read the page or searched around it
    • Every link and every check I ran is in the newsletter, nohacks.co/subscribe


    Sources & Links

    • No Hacks website
    • Variety's robots.txt
    • The article

    No Hacks runs no sponsorships and is funded by advisory and audit work. 

    If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

    24 min
  • 230: A Shoe Company And A Cookie Company Now Say The Exact Same Thing To AI Agents

    On August 5 Shopify switched on a second way into every store on its platform, built for AI agents instead of people. Nothing to install, no merchant asked. I opened three unrelated stores, Allbirds, Brooklinen and Partake Foods, and asked each what it could do for a machine. All three answered with the same roughly 800 words, identical character for character, and no merchant wrote a syllable of it. What those words say, and what it costs a brand when the visitor has no eyes.

    Chapters

    • 00:40 Thirty years of every shop trying to sound different
    • 02:13 What Shopify switched on, overnight, on every store
    • 03:19 Three stores, one identical answer
    • 05:06 The tools are stage direction for a machine
    • 08:13 Nobody is using any of it yet
    • 13:45 Your voice does not transmit, your data does

    Key Numbers

    • Three unrelated stores returned the same ~800 words of tool text, identical character for character
    • The adapter file is version 0.1.0
    • Etsy put AI agent platform traffic under 1% of its total in Q2 earnings
    • Shopify reports AI-referred orders tripled, which is referred traffic, not agents buying
    • Shopify reports over a million merchants on the platform

    Three Takeaways

    1. Shopify wrote what your store says to machines, and every other store says it too. These are instructions, not descriptions. The checkout tool tells the agent to "follow it." Another tells it not to ask the shopper about missing options when it decides they only want to look. Someone chose when the customer gets consulted, and it was not the customer or the merchant.
    2. This is the right way to build it, which is separate from whether anyone noticed. The tools read the same database as the storefront people see, so the two cannot drift apart. One good default beats a million bad ones. It is still worth knowing a default was set for you.
    3. If the machine is the visitor, your voice does not transmit and your data is what is left. The photography, the badges, the reviews, the copy someone agonised over: none of it survives the call. Back comes a title, a price, a size run, availability. What is left to compete on is whether your prices are right and your stock is accurate. That work pays off whether or not the agents arrive.

    Mentioned

    • My WebMCP reference guide: https://nohacks.co/blog/what-is-webmcp
    • What I found on day one: https://nohacks.co/blog/shopify-gave-every-store-an-agent-api
    • Shopify's docs for building the buyers: https://shopify.dev/docs/agents
    • Talia Wolf and the Emotional Targeting Framework
    • Episode 229, llms.txt against 137,000 domains

    Newsletter, one a week: https://nohacks.co/subscribe
    Say hello: [email protected]

    No Hacks runs no sponsorships and is funded by advisory and audit work. 

    If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

    18 min
  • 229: Does llms.txt Work? What 137,000 Domains' Server Logs Show

    Most of what's sold as AI search optimization has never been tested by the people selling it, and this episode is me checking the biggest one against server logs. Ahrefs looked at 137,000 domains in June: 97% of llms.txt files got zero requests in May, and the biggest readers of the rest were SEO audit tools. I also lay out the line I use to sort every pitch: a hack tries to influence what the machine says about you, architecture changes what a machine can read and do on your website.

    Chapters

    00:00 The AI optimization economy and its zero evidence
    02:50 llms.txt checked against 137,000 domains
    06:00 The main readers of llms.txt are SEO audit tools
    08:53 Why this market keeps producing hacks
    10:23 Visibility scores and the prompt problem
    12:43 Every generation of hacks dies the same way
    15:08 What survives model updates
    18:39 The mirror: fix what the internet thinks you are

    Key Numbers

    • 137,000 domains in Ahrefs' June 2026 server-log study
    • 28% had a valid llms.txt file, and that number is the ceiling, their customers skew technical
    • 97% of those files got zero requests in May, not low traffic, zero
    • Of the 3% that got fetched, around 22% of the readers were SEO audit tools, the tools that flag you for not having the file
    • My own Cloudflare logs at nohacks.co show the same thing, nobody fetches it

    Three Takeaways

    1. The pitch is a screenshot, the truth is in the logs. Before you pay for any AI visibility work, ask for evidence at the level of server logs, and watch what happens.
    2. A hack tries to influence what the machine says about you. Architecture changes what a machine can read and do on your website. The first is rented and dies at the next model update, the second is owned.
    3. LLMs are a mirror of everything happening online. If ChatGPT doesn't call you the best X for Y, the honest question is whether the internet agrees you are, and that's the problem worth fixing.

    What to Do

    • Sort anything you bought or got pitched this quarter with one question: does it change what a machine can read and do on the website, or what the machine says about it?
    • Ask any vendor for their evidence before money leaves your account. Logs, tests, a mechanism, the same bar you'd use for anyone touching revenue.
    • Check your own server logs for who actually fetches your llms.txt, it takes five minutes
    • Try this: open free ChatGPT logged out of search, type "what is [your name] known for," and send me the screenshot at [email protected]. I want to see what you get.

    Sources

    • Ahrefs llms.txt server-log study (June 2026): https://ahrefs.com/blog/llmstxt-study/
    • My identity-vs-capability piece: https://nohacks.co/blog/agentic-web-identity-vs-capability
    • Weekly newsletter: https://nohacks.co/subscribe

    No Hacks runs no sponsorships and is funded by advisory and audit work. 

    If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

    20 min
  • 228: OpenAI Killed Its AI Browser

    I came back from a month off the grid to find OpenAI had killed Atlas, its most glamorously launched product, nine months after the keynote. It barely matters, though. The automated, non-human visitor Atlas was sending to your website is still coming, through whatever shell comes next. Build for the visitor, not the browser.

    Timestamps

    • 00:00 - Back from break, and the bad news
    • 01:17 - Atlas: the most hyped browser ever launched
    • 02:27 - Watching it work is a demo, not a workflow
    • 03:29 - Killed with no keynote: the browser was never the product
    • 04:35 - The visitor isn't dead, so build for it
    • 05:24 - The real agentic web: background agents you don't watch
    • 07:52 - Silent failure: a human recovers, an agent doesn't
    • 09:41 - OpenAI's side quests, and the name that gave it away
    • 12:48 - My Cloudflare data: AI traffic is 5-10x human
    • 14:24 - What No Hacks is now

    Key Numbers

    • AI assistant traffic (ChatGPT and Claude users) is running 5-10x my human traffic on nohacks.co (my own Cloudflare AI analytics)
    • Atlas: launched October 2025, shuts down August 9, 2026, nine months old
    • Eight months in, Atlas never shipped beyond macOS, no Windows, iOS, or Android

    Key Takeaways

    1. The visitor outlives the shell. Browser, app, extension, cloud: the wrapper keeps changing, but the automated visitor arriving at your website is the same one every time. Build for the visitor, not the browser.
    2. Watch-it-work AI browsers were always a demo. If you have to sit and watch it, it is not a workflow. The real agentic web runs in the background, which means its failures are silent, and you never see the lost signup or sale.
    3. Being cited is not the whole game. The agent does not only mention you, it comes to your website and tries to act. Optimizing to appear in a prompt misses the harder work: a website a machine can actually use.

    What to Do

    • Simplify the paths a human muscles through but an agent will not: coupon-box bugs, cookie banners, console errors. The agent hits the wall and leaves, silently.
    • Check your own logs and bot analytics for AI-assistant traffic. You are probably getting more than you think.
    • Stop optimizing only to be discovered. Make the website something an agent can finish a task on.
    • More on this every week in the No Hacks newsletter: nohacks.co/subscribe

    Sources & Links

    The story

    • OpenAI is shutting down Atlas (TechCrunch)

    My companion take and data

    • AI Browsers Are Backward Because Agents Never Needed the Visual Layer
    • Cloudflare Radar: bot and AI traffic

    No Hacks runs no sponsorships and is funded by advisory and audit work. 

    If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

    18 min
  • 227: ChatGPT Shopping Is Scraped Google Shopping with Malte Landwehr, CMO/CPO at Peec AI

    I sat down with Malte Landwehr, who left VP of SEO at Idealo to become CPO and CMO at Peec AI, the platform that tracks what ChatGPT, Claude, Gemini, and Google AI Overviews actually cite. We open on the strangest finding of the year. GummySearch, a Reddit analytics tool that shut down last November, now sits behind about 0.1% of all ChatGPT citations. From there we get into why clicks are the wrong way to measure AI search, why your local brand keeps losing to US ones, why scaled AI content rockets then crashes, and why Malte says SEO is dead as a default growth channel.

    Guest Profile

    Malte Landwehr is CPO and CMO at Peec AI, an AI search visibility platform that runs daily prompts across ChatGPT, Perplexity, Gemini, Google AI Overviews, Claude, and Grok. He spent more than twenty years in search and product, including five years as VP of SEO at Idealo and five years as VP of Product at Searchmetrics. In his first six months at Peec AI, the company grew from roughly $500K to $5M in ARR.

    Chapters

    • [0:00] Intro
    • [1:15] Leaving one of Europe's best SEO jobs for AI search
    • [5:07] Why clicks are the wrong way to measure ChatGPT
    • [8:22] Which answer engines actually matter
    • [12:34] GummySearch: a dead product winning ChatGPT citations
    • [18:33] Listicles and the English-language fan-out bias
    • [23:48] Advertorials, local results, and Mount AI content
    • [33:50] Digital PR over technical SEO
    • [36:27] ChatGPT Shopping is scraped Google Shopping, and the MCP contest
    • [42:16] SEO is dead as a default channel, and the chunking move

    Key Takeaways

    1. Stop measuring AI search by clicks. In an LLM, clicking is optional, so ChatGPT can look like 1% of your traffic while shaping most of your buying journeys. Measure the influence on the decision, not the visit.
    2. What gets written about you offsite now matters more than your own technical SEO. Grounding pulls from Reddit, G2, Wikipedia, YouTube, and news, so digital PR is the bigger lever for how AI describes and recommends you.
    3. One citable paragraph beats a chunked article. Put your main claim near the top in two or three declarative, self-contained sentences that name the entities. Do not shred a whole article into one-line bullets.

    Notable Quotes

    "In a web search, clicking is part of the intended user journey. In an LLM, clicking is completely optional." Malte Landwehr

    "They didn't gain visibility as a brand. They now have power over what brands are recommended by LLMs." Malte Landwehr, on GummySearch

    Resources

    • Peec AI: https://peec.ai
    • Peec AI research blog: https://peec.ai/blog
    • Malte Landwehr's website: https://www.maltelandwehr.de
    • Future of AI Shopping webinar with Malte Landwehr (Peec AI): https://peec.ai/webinars/future-of-ai-shopping

    Connect

    • Malte Landwehr on LinkedIn: https://www.linkedin.com/in/landwehr/
    • Peec AI: https://peec.ai

    No Hacks runs no sponsorships and is funded by advisory and audit work. 

    If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

    51 min
  • 226: Most Brands Are Chasing AI Visibility Backwards with Alisa Scharf, Chief AI Officer at Seer Interactive

    This week I welcome Alisa Scharf, Chief AI Officer at Seer Interactive, to the podcast, to ask the question she fires back at every client who walks in wanting to "win at AI visibility." Her answer flips the whole project: fix what the models get wrong about you before you chase the category terms. We got into her research on why lower-authority websites earn more citations, why LLMs recommend a brand only 2.3% of the time, and the gap nobody is tooling for: getting an agent to actually use your website, not find it.

    About the Guest

    Alisa Scharf is Chief AI Officer at Seer Interactive, where she runs the AI practice across the agency's client accounts. Her team's research spans hundreds of thousands of pages and tens of thousands of prompts, and she argues that citations are a leading indicator, not a business outcome.

    Chapters

    • 00:00 - The first question Alisa asks a new client
    • 04:08 - Brand accuracy: what models get wrong about you
    • 06:57 - Defense wins championships
    • 09:54 - The brand accuracy audit
    • 13:12 - Why lower-authority websites get cited more
    • 15:57 - Citations are page two of Google
    • 19:37 - LLMs recommend a brand 2.3% of the time
    • 21:49 - The agentic browsing tooling gap
    • 28:13 - Losing 30-80% of organic traffic
    • 37:31 - How a 15-year-old brand catches up
    • 40:24 - What we will get wrong in 12 months
    • 43:18 - Where to find Alisa

    Key Takeaways

    1. Defense before offense. Pick five factual prompts about your own company, founding, location, what you sell, who you compete with, and run them across ChatGPT, Claude, and Gemini. Fix what the models get wrong before you spend a dollar chasing category terms.
    2. Citations are a leading indicator, not a result. They swing by month and by model. Real success shows up in direct traffic, branded search, and brand recognition, none of which sit neatly on a dashboard.
    3. Visibility is not readiness. Getting cited and getting an agent to actually buy, book, or provision on a customer's behalf are two different problems. Most providers sell the first and call it the second.

    Notable Quotes

    "You can flip an old house and turn it into a really impressive place to live. You can't flip an old house and turn it into a skyscraper."

    "Everything we just spent the last 10, 15, 20 years learning is now doing you a disservice, because you really have to turn to a fresh page and say, where is my audience?"


    Resources

    • Seer Interactive: https://www.seerinteractive.com
    • Seer insights and research: https://www.seerinteractive.com/insights
    • No Hacks EP 222, Wil Reynolds, AI visibility is a vanity metric: https://nohacks.co/episode/222-ai-visibility-is-a-vanity-metric-with-wil-reynolds
    • No Hacks EP 225, Matt Biilmann on agent experience: https://nohacks.co/episode/225-every-website-already-has-an-agent-experience-and-most-are-bad-with-netlify-ceo-matt-biilmann
    • SparkToro: https://sparktoro.com

    Connect with Alisa Scharf

    • LinkedIn: https://www.linkedin.com/in/alisascharf/
    • X: https://x.com/alisa_scharf
    • Bio: https://www.seerinteractive.com/people/team/alisa-scharf

    No Hacks runs no sponsorships and is funded by advisory and audit work. 

    If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

    48 min
  • 225: Every Website Already Has An Agent Experience And Most Are Bad With Netlify CEO Matt Biilmann

    The user-agent string in the HTTP header has been there since the 1990s. The web was built with software navigating it on someone's behalf. For thirty years that someone was a human. That changes now. Matt Biilmann, CEO and co-founder of Netlify, was one of the first to take seriously what it means when the "user" navigating the web is an AI agent. 

    He published the foundational essay on Agent Experience in January 2025, pivoted his entire company around it, and recently shipped netlify.ai as a separate entry point built for agents. We cover the four pillars of Agent Experience, why every product already has an agent experience whether you designed one or not, content negotiation as a way to tell agents to go to a different URL than humans, why SaaS is in real trouble (with a story from inside Netlify about ripping out vendor contracts), how the data-structure assumption that has defined software for fifty years is breaking, and the one thing every website owner should start doing this week.

    About the Guest

    Matt Biilmann is the CEO and co-founder of Netlify, the platform that started the Jamstack movement and is leading the shift from developer experience to agent experience. His January 2025 essay on Agent Experience is the foundational text for the discipline. 

    Chapters

    • 00:00 Every product has an agent experience (cold open)
    • 00:35 The architectural question
    • 01:46 Welcome Matt to No Hacks
    • 02:15 When AX became a design constraint, not a concept
    • 06:44 The January 28 2025 essay and who got it first
    • 10:22 Why netlify.ai was built as a separate website
    • 12:44 Content negotiation: telling agents to go to a different URL
    • 13:54 Qualitative data and the Axis eval framework
    • 17:12 Does AX apply to e-commerce and content websites?
    • 20:59 The cumulative media argument (TV did not kill radio)
    • 25:00 User-agent in HTTP and Al Gore-era agent commerce laws
    • 26:33 SaaS business model is dead: build-vs-buy is shifting
    • 30:44 The end of structured content as a hard constraint
    • 40:25 One thing every website owner should do now
    • 43:08 Where to find Matt online

    Key Takeaways

    1. Every website already has an agent experience. Agent Experience is how AI agents currently interact with your product, whether through computer use, fetching, or working around the barriers you put up. It is not a feature you add. The only question is whether the experience is good or bad.
    2. The four pillars: Access, Context, Tools, Orchestration. Matt's framework for thinking about AX systematically. Access answers whether agents can reach your product at all. Context is the prompt-engineering equivalent for agents. Tools are the concrete capabilities you expose. Orchestration covers how agents string those tools together inside your product.
    3. Build a separate entry point for agents. netlify.ai is purpose-built for agents while netlify.com remains the human entry point. Content negotiation tells agents to go to one URL, humans see the other. The blessed-path approach beats trying to make one URL serve both.
    4. SaaS economics are shifting structurally. The build-vs-buy floor is dropping fast as AI lowers the cost of software. Traditional 90%-margin seat-based SaaS is in real trouble. Dev tool companies have upside because companies need more tools. Everyone else is going to be ripping out vendor contracts and building internally.
    5. The data-structure paradigm is breaking. Software engineering has operated on the Linus Torvalds principle that data structures matter more than code. LLMs are not built around data structures. Building software around LLMs means rethinking the assumption that drove fifty years of computer science.

    Notable Quotes

    "Every product has an agent experience because all of these agents, whether through computer use or through fetching your website or through working around the barriers you put up from them, have some agent experience right now. It is just a question of is it good or bad."

    "There is a reason it is called a user agent in the header. It was forward-looking."

    "We have been ripping out SaaS contracts. Sometimes it is heartbreaking. The rep calls to right-size the contract and the customer reacts with 'let me see if I can build it with an agent.' Then they call back and cancel instead."

    "The context and the flows and your creativity are probably more important than both the data structures and the code."


    What To Do Next

    • Open your website in Claude Code or ChatGPT and ask the agent to complete a real task. Watch where it stalls. That is your AX baseline.
    • Check your traffic logs for AI assistant visitors (ChatGPT-User, Claude-Web, PerplexityBot, GPTBot). The number is rising whether you measure it or not. Cloudflare reports AI assistants are now 5.5% of all internet traffic, up from 3.9% six months ago.
    • Read Matt's January 28 2025 essay on Agent Experience at biilmann.blog as the starting point. Then read the one-year retrospective for the four pillars framework.
    • If you operate a developer tool or any product with a clear automation surface, start a simple eval scenario: take a fresh agent, give it a task, score whether it succeeds. Axis from Netlify will give a proper framework when it ships open source.

    Resources Mentioned

    • netlify.ai (the agent-built entry point Matt and team shipped recently)
    • netlify.com (the human entry point)
    • Matt's original Agent Experience essay, January 28 2025: biilmann.blog
    • Matt's "AI in the CLI: The Humanoid Robot of the Web" (August 2025)

    • Claude Code (the agent that flipped broad accessibility for CLI coding agents)

    Connect with Matt Biilmann

    • Blog: biilmann.blog
    • LinkedIn: linkedin.com/in/mathias-biilmann-christensen-a5a3805
    • Twitter/X: @biilmann (x.com/biilmann)
    • Bluesky: bsky.app/profile/did:plc:grjr4il5dredrsuj7nosb4pq
    • Mastodon: mastodon.social/@biilmann
    • Netlify: netlify.com and netlify.ai

    Connect with No Hacks

    • Website: nohacks.co
    • Subscribe to the newsletter: nohacks.co/subscribe
    • Machine-First Architecture: machinefirstarchitecture.com

    No Hacks runs no sponsorships and is funded by advisory and audit work. 

    If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

    46 min

About No Hacks with Slobodan Manic

From the publisher's feed

AI is changing the internet, and nobody asked us if we wanted it changed. So every week I go and look at one thing it did: a website that started charging robots to read it, an assistant that got…

More shows like No Hacks with Slobodan Manic

The Totally Football Show with James Richardson by The Athletic

The Totally Football Show with James Richardson

1,014 Listeners