AI Bot Hits vs. AI-Referred Visitors: How to Tell Them Apart in Your Data

Published · 5 min read · AppWT Web & AI Solutions

Black and gold title card reading AI Bot Hits vs. AI-Referred Visitors: How to Tell Them Apart in Your Data, with the AppWT Analytics name in gold along the bottom edge

A bot that fetches your page for an AI assistant is not a customer visit, and your reports should not count it as one. Two different things get mixed together: machine requests from AI crawlers and fetchers, and human visits that arrive after someone clicks a link inside an AI answer. This guide shows how to tell them apart and what to do with each.

The fix needs no special software. It needs a clear rule for what counts as a person, plus a habit of checking one extra source of truth: your server logs.

Why the two get confused

Most reports start from a tracking script that runs in a visitor's browser. Many bots never run that script, so they stay out of those numbers. Others do run it, and they can inflate sessions and distort your conversion rate.

Meanwhile, server logs record every request, human or machine. When you compare the two, the gap tells you how much machine activity touches your site. That gap is useful information, not a problem to hide.

The three kinds of AI requests

OpenAI's documentation lists separate user agents for separate jobs. This is a good model for thinking about any AI company, because the same pattern shows up elsewhere.

  • Training crawlers. GPTBot is described as being used to make OpenAI's generative AI foundation models more useful and safe. Disallowing it signals that your content should not be used for training.
  • Search crawlers. OAI-SearchBot surfaces websites in ChatGPT's search features. It builds the index that answers can cite.
  • User-initiated fetchers. ChatGPT-User handles actions that a person starts inside ChatGPT or a Custom GPT. OpenAI notes that robots.txt rules may not apply to these requests, because a user triggered them.

Google documents a similar idea. Its user-triggered fetchers act on the request of an end user, and in March 2026 it added a Google-Agent user agent for agents that browse and act on a person's behalf. Each of these is a machine request. None of them is a human visit.

What a real AI-referred visit looks like

A human visit is different. A person reads an answer, sees your business cited, and clicks the link. Their browser then loads your page and runs your measurement script like any other visitor.

The referrer, the page the person came from, may show the assistant's domain. In some cases the link itself carries a tag in the address, and in other cases the referrer is blank. Because signals vary, treat AI referral numbers as a minimum count, not a full count.

This also explains why an AI company can fetch your pages thousands of times while sending you few visitors. Fetches build answers. Visits happen only when someone clicks.

A five-step method to separate them

  1. Pull a week of server logs. Ask your hosting provider or developer for raw access logs. Filter the user-agent field for names such as GPTBot, OAI-SearchBot, ChatGPT-User and Google-Agent.
  2. Verify the source. Anyone can type a famous name into a user-agent string. OpenAI publishes IP lists for its crawlers, and Google publishes IP lists plus a reverse DNS check for verifying its requests. Match the address, not just the label.
  3. Count the machine requests by purpose. Group them into training, search indexing and user-initiated. Each group means something different for your business.
  4. Count the human visits separately. Use your analytics report and filter by referrer or source for AI assistants. Keep this number in its own row, labeled as a minimum.
  5. Compare the rows. A big machine count with a small visit count is normal. The useful question is whether the visits that do arrive turn into inquiries, calls or sales.

Reading the results

Suppose your logs show many ChatGPT-User requests to one service page. That tells you people are asking an assistant about a topic your page covers. It is a demand signal, even though no visit shows in your report.

Now suppose a page gets heavy training-crawler activity but nothing else. That page is being read, but it may not be earning citations. Check whether it answers a clear question in its first few sentences, and whether the facts on it are current.

If a page gets human AI-referred visits that convert, protect it. Keep it accurate, keep it fast, and avoid blocking the crawlers that help it appear.

Decide what to allow

You control more than most owners realize. OpenAI states that its settings are independent, so a site can allow OAI-SearchBot to appear in search results while disallowing GPTBot to keep content out of training. Updates to search rules can take about 24 hours to take effect.

A simple starting policy for many small businesses looks like this:

  • Allow search crawlers, because they support citations and possible visits.
  • Decide on training crawlers based on your own comfort with how your content is used.
  • Accept that user-initiated fetchers may ignore robots.txt, and use your hosting provider's firewall tools if you truly need to restrict them.

Write the policy down with a date. When someone asks why a number changed, you will have an answer.

Keep measurement privacy-first

None of this requires tracking individual people. Server logs and aggregate analytics are enough to see which sources send visits and which pages draw machine attention. Avoid collecting more personal data than you need, and review the privacy rules that apply to your visitors in each country you serve.

If you use IP addresses to verify bots, use them only for that check. Do not tie them to named people, and follow your own retention schedule for logs.

Build a clean monthly report

Use four lines in one table, reviewed monthly:

  1. Human visits from search engines.
  2. Human visits from AI assistants (minimum count).
  3. Verified AI crawler and fetcher requests, split by purpose.
  4. Inquiries or sales that followed AI-referred visits.

Report the first two as audience, the third as exposure, and the fourth as results. Mixing them is how a bot surge gets mistaken for growth.

The takeaway

Machine requests tell you that AI systems are reading your pages. Human visits tell you that people are choosing to come. Count them separately, verify who is knocking, and judge every number by what it does for your business.

Frequently asked questions

Is a ChatGPT-User request in my logs a real visitor?

No. OpenAI documents ChatGPT-User as a fetcher that acts when a person asks ChatGPT or a Custom GPT something. It is a machine retrieving the page for the answer. The person who asked usually never lands on your site unless they click a link later.

Can I block AI training without hiding my site from AI answers?

Often yes. OpenAI states that each of its crawler settings is independent, so you can disallow GPTBot for training while allowing OAI-SearchBot for search features. Check each company's documentation, because rules differ and robots.txt may not apply to user-initiated fetches.

How do I confirm a request really comes from the company it claims?

Do not trust the user-agent text alone, because anyone can copy it. Compare the request's IP address with the published IP lists. OpenAI and Google both publish lists, and Google also documents a verification method using reverse DNS.

Sources

See which AI platforms already send you visitors. Start with AppWT Analytics or ask us a question.

All articles

Accessibility

by AppWT Web & AI Solutions
🛡️ Accessibility Profiles
📝 Content Adjustments
Content Scaling 100%
Font Size 100%
Line Height 1.4
Letter Spacing 0px
🎨 Color Adjustments
Color Saturation 100%
🎛️ Orientation & Controls
♿

Accessibility Statement

Our commitment to digital accessibility and inclusive design

Our Commitment to Accessibility

AppWT Web & AI Solutions is committed to ensuring digital accessibility for people with disabilities. We continually improve the user experience for everyone and apply the relevant accessibility standards to achieve these goals.

Conformance Status

The Web Content Accessibility Guidelines (WCAG) defines requirements for designers and developers to improve accessibility for people with disabilities. It defines three levels of conformance: Level A, Level AA, and Level AAA.

AppWT Web & AI Solutions is partially conformant with WCAG 2.1 level AA. Partially conformant means that some parts of the content do not fully conform to the accessibility standard.

Accessibility Features

  • Built-in accessibility toolbar with multiple customization options
  • Keyboard navigation support throughout the website
  • Screen reader compatibility and proper ARIA labels
  • High contrast mode and color customization options
  • Text size adjustment and font modification capabilities
  • Reading guide and focus indicators for improved navigation
  • Alternative text for all images and media
  • Semantic HTML structure for better screen reader interpretation

Technical Specifications

Accessibility of AppWT Web & AI Solutions relies on the following technologies to work with the particular combination of web browser and any assistive technologies or plugins installed on your computer:

  • HTML
  • WAI-ARIA
  • CSS
  • JavaScript

These technologies are relied upon for conformance with the accessibility standards used.

Feedback

We welcome your feedback on the accessibility of AppWT Web & AI Solutions. Please let us know if you encounter accessibility barriers:

Phone: (888) 565-0171

Email: sales@appwt.com

Address: 33300 Five Mile Rd, Livonia, MI 48154 (by Appointment Only)

Assessment Approach

AppWT Web & AI Solutions assessed the accessibility of our website by the following approaches:

  • Self-evaluation
  • External evaluation
  • Automated testing tools
  • Manual testing with assistive technologies

Date

This statement was created on January 15, 2025 using the W3C Accessibility Statement Generator Tool.

Last updated: