The IAB wants to bring some structure to a market already selling its first "impressions" to AI agents without knowing precisely what those impressions measure. The organization will publish a framework on Nov. 12 designed to measure and credit AI's role in conversions, according to Digiday. It covers the cases where the traditional signals – clicks, referrers, UTM parameters – drop out of the path.
The document is still being drafted. Caroline Giegerich, the IAB's vice president of AI, is working with a group that includes tech platforms, publishers, agencies, advertisers and measurement specialists. The IAB has not disclosed who is in it. Asked which points the group finds hardest to agree on, Giegerich said: "everything."
The problem is not just the lack of a shared KPI. Advertising aimed at agents inserts a new intermediary between exposure and decision, one that can pull several sources, synthesize them and, in some cases, act on the user's behalf.
Proving an ad was delivered is no longer enough. Buyers have to establish whether the machine actually processed it, whether the information survived the generation of the answer, and whether that answer shaped a human decision or an automated action.
A bot impression proves almost nothing
The IAB published a first framework on brand and publisher visibility in AI interfaces in early August. It sets out a hierarchy of metrics, the "4 Ps," and separates directional measurement from measurement solid enough to inform an investment decision.
The next framework has to go one step further, from presence in an answer to credit for an advertising outcome.
Between the two sits a measurement chain that is still largely invisible. When a crawler loads a page carrying a sponsored message, the publisher's server can log the request. That contact proves neither that the model retained the information nor that it fed it into an answer.
A brand mention in that answer proves more, but it does not establish that the ad caused it. The agent can draw on dozens of other sources, on its training data, or on data the brand supplied directly. Conversion adds a fourth layer. If the user clicks a link, a promo code or an identifier can still rebuild a deterministic form of attribution.
If the agent simply recommends a product and the purchase happens elsewhere, or if the agent executes the transaction itself, the thread from sponsored message to outcome is likely to vanish.
A bot request, a retrieved piece of information, a displayed recommendation and a purchase are four different events. Rolling them up into a single "AI impression" would make reporting comfortable and close to useless.
The IAB is considering splitting influence into two layers: the moment AI exposes a user to information, an awareness or intent layer, and the moment it contributes to the decision. The split is necessary. It does not answer the central question of what evidence lets you move from one layer to the next.
Time opened a market Perplexity is already contesting
The debate accelerated with a test run by Time and AI visibility vendor Mobian. The magazine converts its pages into markdown versions, easier for AI systems to read, and inserts sponsored content in a FAQ format. Ally Bank and the Project Management Institute are among the first advertisers named. Time tracks crawler traffic to those pages. Mobian then queries answer engines to follow the visibility, tone and accuracy of the information tied to the brand.
The setup documents content delivery to bots and shifts in certain outputs. It cannot yet causally link an ad exposure to an answer served spontaneously to a user, and then to a purchase. Querying a chatbot yourself on the themes a campaign covers builds a presence test. It is neither a reach measure nor a conversion attribution.
Even the definition of the inventory is contested. AI search engine Perplexity blocked the ads inserted in Time's markdown pages and called them a form of "cloaking." The engine argued that the bot receives different content from the one shown to a human reader. The company also threatened to lower the trust it assigns to publishers that use the practice.
The clash is not a brand safety footnote. If each engine unilaterally decides which messages its agents can read, weigh or repeat, the product an advertiser buys depends on rules set by a platform outside the transaction.
A brand can pay a publisher to reach an agent that filters the message before it ever enters the decision process. Before measuring performance, the market has to define what counts as authorized, verifiable delivery.
Attribution turns into a fight over value
Publishers are not only after a new traffic volume to monetize. They want a share of the value created when their content feeds an AI answer that later steers a purchase. The IAB framework could give them the vocabulary and the evidence to press that claim with platforms and advertisers.
Three economic relationships need to stay separate: the license that pays for access to editorial content, the sale of an ad message to an agent, and credit for a conversion.
An article that helped build an answer can justify a conversation between publisher and platform. It does not prove the ad on that page produced the recommendation, still less that it deserves credit in the advertiser's attribution model.
The distinction matters more because the incentives diverge. The publisher wants every agent visit to its content to count. The AI platform wants to protect the quality of its answers and its control over the sources it uses. The advertiser is looking for incremental effect, not confirmation that its message was technically reachable. The measurement vendor, meanwhile, has to establish causality from signals the other three hold.
The risk of rebuilding walled garden measurement
Shared definitions will not help if platforms do not make the events observable. The traces that matter sit inside their systems: which sources were actually retrieved, what the model retained, how the answer was composed and what action was executed. A publisher sees the crawl. An advertiser may see the sale. Only the platform can connect the gap between them.
OpenAI shows the asymmetry. For its own ad formats shown to users, the company recently said it was extending measurement beyond the click through its pixel, its Conversions API and third-party integrations. Those tools can improve reporting on campaigns bought inside ChatGPT.
They do not automatically give publishers and independent measurement firms access to the signals that would explain how an agent read an ad it encountered elsewhere on the web.
The parallel with social platforms is direct. The platform produces the data, sets the integration rules, then lets a third party audit it without exposing the full system. Independence then covers the verification of a protocol the platform supplied, not measurement genuinely outside it.
An IAB standard could make those audits comparable. It could also normalize a new generation of black boxes if it sets no minimum level of access to the evidence.
The agent registry planned under AAMP, the IAB Tech Lab's agentic initiative, can help identify the systems interacting with ad players. Knowing which agent made a request still says nothing about what it understood or what it did with it. Identity is a condition of traceability, not proof of influence.
Media buyers should keep delivery, influence and outcome apart
Until a standard exists and platforms adopt it, campaigns aimed at agents should be treated as GEO or sponsored content tests, not as a performance channel already comparable to search or social.
Buyers should ask for three separate reports: delivery to identified crawlers, changes in the brand's presence in answers, and observed business results. None of the three should stand in as a shortcut for the next.
Methodologies built on synthetic prompts can document a shift in visibility, provided they spell out the queries tested, the models queried, the frequency, the location and the volatility of the answers. They only demonstrate an advertising effect when paired with controls: exposed and unexposed groups, holdout periods, incrementality tests, or identifiers that survive the path where the path allows it.
The framework will be useful if it sets not just metric names but standards of proof: which event is observable, by whom, with what stability, with what audit rights and at what level of causality. Without that, the industry will get better at naming the contribution it assumes agents make, without getting any better at verifying it.
The real standard will not be the one that invents a CPM for bots. It will be the one that forces every link in the chain – publisher, agent, platform and merchant – to document the part of the path only it can see.

