← Back to blog

Is your store ready for AI shopping assistants? The agent-ready audit for Shopify, BigCommerce, Adobe Commerce and Magento

Is your store ready for AI shopping assistants? The agent-ready audit for Shopify, BigCommerce, Adobe Commerce and Magento

Shoppers now ask an assistant before they open a search engine. They ask ChatGPT for a skillet, ask Google's AI Mode which of three jackets is warmer, or let the assistant built into their browser fill a basket. The assistant reads your product pages, the structured data behind them and, on some platforms, a catalogue your platform publishes for it, then answers in a sentence. If the sentence says your product is out of stock when it is not, the shopper buys elsewhere and you never see the visit.

This is the audit we run when a merchant asks "are we ready for this?" It covers the three things that matter, readable, reachable and buyable. Every check below names the tool to open, what to look for, what good looks like and what the fix is, with the differences by platform. You can do the whole thing in about thirty minutes with a browser. Nothing here needs a chatbot, a new checkout or a replatform.

Run the free AI agent readiness check now: it reads five product pages live and shows the evidence in about a minute. If you would rather have the whole catalogue read for you, the full free Health Check returns a ranked result within one working day. No store access is needed.

What changed, with the dates

  • Every Shopify store is open to assistants by default. Shopify's Agentic Storefronts documentation (11 May 2026) states products are "automatically accessible to AI channels like ChatGPT, Shop, and Copilot". Since 8 September 2026, Meta's assistant is a default-on sales channel in the Shopify admin. The developer reference for all of it is at shopify.dev/docs/agents.
  • Assistants can check out, not only recommend. On 28 September 2026 Shopify added checkout tools for browser agents, running inside the checkout page with no merchant setup. Google's AI Mode shows and sells products. Chrome is shipping the browser standard, WebMCP, that lets a page offer tools to an assistant; it is behind a flag in stable releases as we write this. The shopping protocol behind much of it is the Universal Commerce Protocol.
  • The traffic is real and it buys. Adobe Analytics reports visits to US retail sites from AI sources up 393% year on year in the first quarter of 2026, converting 42% better than other traffic by March 2026 (Adobe's write-up).
  • The first thing merchants notice is a wrong answer. On the Shopify Community in September and October, merchants reported assistants quoting a product as out of stock when it was in stock, old prices from a comparison site, and orders from assistants showing up as "Direct" with no trace.

So the question is no longer whether to take part. It is whether assistants read the right price and stock, whether they can reach your store at all, and whether a shopper who sends an assistant can actually pay.

What agent-ready means

  1. Readable. The facts an assistant reads are correct and stated once: price, currency, stock, variants, and the facts that decide a purchase (size, materials, what is in the box, delivery and returns). The common failure is two sets of product facts on one page that disagree, usually because a review or SEO app prints its own block next to the theme's.
  2. Reachable. Assistants can find the store and query it: the AI crawlers are not blocked by accident, the sitemap works, and where the platform offers an agent endpoint (a standard way for an assistant to search the catalogue and build a basket), it is on and exposing the right products.
  3. Buyable. A shopper's assistant can get from a product to a purchase: the cart is reachable, the policy pages exist and are linked, and the checkout is the merchant's own, with the merchant's own payment provider.

A fourth thing sits with the merchant rather than the shopper: control. Read-only by default, approval before anything writes to the store, a view of which visits and orders came from assistants, and a switch to turn it off per store.

The audit, check by check

Do each check on two products: one you sell well and one you sell badly. Keep a note of what you find; the fix list at the end is built from it.

Readable

1. Count the product blocks.

Open the product page, press Ctrl+U on Windows or Cmd+Option+U on a Mac to view the source, and search for application/ld+json. Read each block that contains "@type": "Product" or "ProductGroup".

Good: one block, printed by your theme. A ProductGroup with variants nested inside it counts as one.

Bad: two or more separate blocks. One is usually from a review or SEO app. When they disagree, an assistant picks either.

Fix: find which app prints the second block (its name is normally in a comment just above it) and switch off that app's structured data, or remove the app. Re-check the page source, not the admin. Why the source and not the inspector: the inspector shows the page after JavaScript has run, and most assistants read the raw HTML.

2. Read the price and stock in that block.

In the same block, find availability, price and priceCurrency.

Good: InStock on a product you can buy, the price on the page, the currency on the page. Mixed availability across variants is normal.

Bad: OutOfStock on a product with a working buy button; no availability at all; a price in one currency and a page in another.

Fix: on Shopify, make sure the theme's product block reads availability from inventory, not from a theme setting; on BigCommerce and Magento, check the theme's structured data template or the extension that prints it. Then use the Rich Results Test on the page URL and read the actual values it extracts, not only whether the result is valid. The Schema Markup Validator shows the same values without Google's eligibility rules.

3. Compare with what your platform says.

On Shopify, add .json to the product URL (for example yourstore.com/products/your-handle.json) and compare each variant's available value with the availability in the structured data. On other platforms, compare the structured data with the admin's stock status for the same variant.

Good: they agree.

Bad: structured data says InStock while the platform says no variant is available. We saw this on three of three sampled products on two large Shopify stores in October 2026, both with a second product block on the page.

Fix: the same as check 1 or 2, whichever source is wrong. Record which one disagreed first; that is the fix, not the assistant.

4. Same variant, same market, same currency.

Open the page in a private window with the market an assistant would use. A US shopper and a UK shopper see different stores on many platforms.

Good: the price and stock the assistant quoted match that variant in that market.

Bad: you compared the default variant in your own market with an assistant answering for another. Half of "wrong price" reports are a regional price or another size.

5. The facts that decide a purchase.

Read the page as a stranger: what is it, who is it for and not for, what is in the box, size or fit, materials or ingredients, delivery and returns. Negations matter most: "not suitable for", "does not contain", "not certified".

Good: each fact stated plainly in the page text.

Bad: facts only in an image, a tab that loads on click, or a yes/no attribute table. Generated catalogue fields tend to keep the attribute and lose the "not".

Fix: state the fact in a sentence in the page text, and in the structured data where a property exists for it.

Reachable

6. robots.txt.

Open yourstore.com/robots.txt. Look for the AI user agents and what each is allowed: OAI-SearchBot and ChatGPT-User (OpenAI's list), Google-Extended (Google's list), ClaudeBot (Anthropic), PerplexityBot (Perplexity), Meta-ExternalAgent (Meta) and Amazonbot (Amazon).

Good: none of the shopping and search agents disallowed. Blocking GPTBot, the training crawler, is a separate decision and does not stop ChatGPT shopping.

Bad: Disallow: / under User-agent: * with no allow, or a copied block list that caught the search agents along with the training ones.

Fix: edit the rules (on Shopify, through the robots.txt.liquid template; on BigCommerce and Magento, in the control panel or the file). Check the result in Search Console's robots.txt report.

7. Bot protection.

From a browser you do not normally use, or a plain request with an unusual user agent, load the homepage.

Good: a page.

Bad: a 403, a challenge page or a timeout. Assistants with unverified user agents get the same, and they give up faster than people do.

Fix: allow the AI crawlers you want in your bot protection (Cloudflare, Akamai, Imperva), or support Web Bot Auth, which lets verified agents identify themselves.

8. Sitemap and llms.txt.

Open the sitemap named in your robots.txt, or yourstore.com/sitemap.xml (BigCommerce uses /xmlsitemap.php). Then open yourstore.com/llms.txt.

Good: a sitemap that answers and lists products; an llms.txt that describes the store and links the key pages (the format is at llmstxt.org). Shopify stores now serve one automatically.

Bad: a 404 sitemap. A missing llms.txt is a warn, not a fail: it helps an assistant orient and costs nothing, but it does not fix a wrong availability value.

9. The agent endpoint.

This is the platform-specific part; see the platform sections below for how to check and switch it on. The short version: Shopify provides one on every store; BigCommerce has one you switch on in the control panel; Adobe Commerce has one with the licence; Magento Open Source and most other platforms have none unless you add one.

Buyable

10. Cart and checkout.

Open the cart page in a private window with an item in it, then start checkout.

Good: both load without a login wall, in the currency and market you expect.

Bad: a cart that only works with a session cookie from the homepage, or a checkout that errors on a direct visit.

11. Policy pages.

From the footer, open refund or returns, privacy, terms, and shipping or delivery.

Good: all four published and linked.

Bad: missing or unlinked. Shopify's documentation for its agent channels lists missing policy pages among the reasons a store is excluded, and no warning appears in the admin.

12. Ask an assistant, logged out.

Ask ChatGPT and Google's AI Mode for your product by name and by category. Note the price and stock quoted and the page cited. Record the prompt, the platform, the time and a screenshot.

Good: current price, current stock, your page cited.

Bad: wrong price or stock. Work forward through what you control, page, structured data, feed, catalogue, and note the first place the wrong value appears. Only when everything you control agrees do you call it "cached", and then you log it as unconfirmed rather than diagnosing it. If you sell through Google, check the Merchant Center item too: automatic item updates can change price and availability from what the page shows (Merchant Center Help).

If you run Shopify

What you already have. The agent endpoint and the checkout tools, on by default. You are in the door whether you chose to be or not.

What is usually wrong. Two product blocks from a review or SEO app. Availability printed from a theme setting rather than from inventory. Policy pages missing on stores that never finished setup. AI referrals landing as Direct, so the channel looks like nothing.

How to check the endpoint. Your robots.txt now points assistants to it, and your store serves a /.well-known/ucp file. A developer can list its tools with one request to /api/ucp/mcp; the free check does this for you.

How to switch it on, or off. There is nothing to install. In the Shopify admin, open Sales channels and review the agent and AI channels listed there; each can be switched off individually. The browser tools in current Liquid and Hydrogen themes and in checkout are provided by Shopify; the agents documentation lists which checkouts have them.

What to fix first. One product block per page, printed by the theme. The four policy pages, linked in the footer. Then check 12 on your ten best sellers, and fix the facts assistants get wrong on the page itself: generated catalogue fields cannot be edited, so the page is your only lever.

What to watch. Orders by source. Until attribution settles, a short "how did you first hear about us" question after checkout catches assistant-influenced buyers the referrer misses.

If you run BigCommerce

What you already have. A storefront agent endpoint (Storefront MCP, in beta since 28 April 2026, now with authenticated shopping and B2B) that lets a connected assistant search the catalogue, build a basket and get a checkout link. It lives at a store-specific address, not on your domain, so nothing changes on the storefront and a browser inspector will not show it. Shoppers' browser agents do not see it either; that is the gap a browser-facing layer fills.

What is usually wrong. Products that are hidden or in no category, so they cannot be bought, never mind found. In one audit this year, 3,576 of 4,942 products were hidden, so only 1,366 could be bought. Two canonical tags on every page, one injected by an app script and pointing at the home page. Default title templates on most of the catalogue. Structured data as microdata inside the theme rather than a JSON-LD block, which crawlers read but fewer assistants parse first.

How to switch it on. Per BigCommerce's documentation:

  1. Sign in to the control panel as the store owner.
  2. Go to Settings, then MCP under API and MCP. Some accounts still show it as Settings, Early Access, MCP Integration.
  3. Enable Storefront MCP and accept the terms.
  4. Select the storefront and copy its MCP endpoint address. Activation can take up to ten minutes.
  5. Connect an assistant that supports remote MCP (Claude, Cursor and others) to that address and test three calls: search a product, add it to a cart, create a checkout link.

What to fix first. Catalogue visibility and category assignment before the endpoint goes on, otherwise you hand assistants a catalogue a shopper cannot buy from. Remove the injected canonical. Then switch on the endpoint knowing what is behind it, with an undo for every change you make on the way.

What to watch. The checkout handoff. The endpoint returns a checkout link; make sure it lands on your real checkout with your real payment provider, including hosted providers such as Viva Smart Checkout, and that an order created this way carries its source.

If you run Adobe Commerce or Magento

What you already have. Adobe Commerce ships a storefront agent endpoint with the licence (Adobe's overview). Magento Open Source and Mage-OS do not. Either way, your checkout runs on the payment modules you already trust, and 2026 has been a year of security patches (StyleSmuggler, CVE-2026-75650, exploited from 4 September) and version deadlines (2.4.6 standard support ended 11 August 2026).

What is usually wrong. Structured data from an old extension that disagrees with the theme. Robots rules written years ago that block everything that is not Googlebot. Staging that drifted from production months ago, so nobody dares add anything to the storefront. Microdata instead of JSON-LD, which passes check 1 but reaches fewer assistants.

How to switch it on. On Adobe Commerce, your developer enables and configures the endpoint through Adobe's Commerce MCP setup (developer.adobe.com/commerce) and gives the resulting address to the assistants you want to allow. On Magento Open Source and Mage-OS there is nothing to switch on yet: the endpoint has to be added as a module, tested on an isolated copy of the store first, with scoped credentials and no new payment integration. The shopper pays on the checkout you already run. Your agency keeps the merge.

What to fix first. The readable checks, on a copy of production, not on the live store. Then the robots rules. Then the endpoint, as a module behind the same security review as any other.

What to watch. The patch cadence. An agent endpoint is one more surface; it belongs on a patched, current version.

If you run WooCommerce or something else

The readable and buyable checks apply unchanged. For reachable, WooCommerce has its own agent work under way through WordPress tooling, and custom or headless builds have nothing until you add it. Add the endpoint the same way you would add any integration: read-only first, scoped keys, logged, and switched off per store in one click.

The audit sheet

CheckWhere to lookPass when
1. One product block per pageView source, search application/ld+jsonExactly one Product or ProductGroup block
2. Price, currency, availabilitySame block; the Rich Results TestValues match the page; InStock on buyable products
3. Platform agreesShopify: product URL plus .json; others: the adminSame availability per variant
4. Same variant, market, currencyPrivate window in the shopper's marketQuoted values match that variant
5. Purchase-deciding facts in textThe page, read as a strangerSize, materials, contents, delivery, returns, negations in plain sentences
6. AI crawlers allowed/robots.txt; the Search Console reportNo root disallow for the search and shopping agents
7. Bot protectionHomepage from an unusual clientA page, not a challenge or 403
8. Sitemap and llms.txtRobots.txt Sitemap line; /llms.txtSitemap answers and lists products; llms.txt optional
9. Agent endpointPlatform section aboveOn, and exposing the products you sell
10. Cart and checkoutPrivate windowBoth load directly
11. Policy pagesFooterRefund or returns, privacy, terms, shipping linked
12. What assistants answerChatGPT and AI Mode, logged outCurrent price and stock, your page cited

Score it as passes out of the checks that apply to your platform, and keep the sheet. Re-run it after every theme change, app install or app uninstall, and once a month regardless. An SEO app a merchant removed a year ago was still rewriting every title on their store last week; the admin preview showed their text, the live page showed the app's.

Three things not to do

  • Do not buy a chatbot to solve this. The assistants your customers use are not on your site. They are ChatGPT, Google, Copilot, Perplexity and the browser. A widget on your storefront does not change what they read.
  • Do not trust the admin preview. The "search engine listing" preview shows what you saved. The live page shows what the theme and your apps print. Only the live source tells the truth.
  • Do not treat llms.txt as the fix. It helps an assistant orient and it costs nothing, but a wrong availability value is not fixed by a text file.

What this looks like with the work done for you

Vortex IQ runs the twelve checks across the whole catalogue rather than two products, and puts the result in plain English: the facts assistants get wrong, the pages with conflicting blocks, the crawlers blocked by accident, the policy pages missing, and the five changes to make first. The fixes are prepared for approval. It proposes. Your team approves. Nothing goes live without your say-so.

Run the free AI agent readiness check: paste your store address and watch the result in about a minute. For the catalogue-scale version, request the full free Health Check and you get a ranked result within one working day. No store access is needed. If you have already fixed the basics and want the next layer, how to get cited by AI shopping answers covers eligibility, feeds and citations.

Questions merchants ask

Does this replace my checkout or payment provider? No. The shopper pays on your existing checkout page with the provider you already use.

Does the assistant see card details? No. Payment happens on your provider's page. The assistant receives an order confirmation, not a card.

Can I switch assistants off? Yes. On Shopify, per channel under Sales channels. On BigCommerce, the endpoint is a per-store setting. On a Vortex IQ-provided endpoint, per store, in one click, and it starts read-only.

Is any of this a ranking factor? No. It is a correctness factor. An assistant that reads the wrong stock does not recommend you, whatever your rank.

My structured data is microdata, not JSON-LD. Is that a fail? Not today. Crawlers read both. JSON-LD is what most assistants parse first, so when you next touch the theme, print a JSON-LD block from the same source of truth and retire the microdata rather than running both.

How often should I re-check? After every theme change, app install or uninstall, and once a month regardless.

Sources: Shopify developer changelog and agents documentation (11 May, 8 September and 28 September 2026 entries); Adobe Analytics, Q1 2026 and March 2026 releases; Shopify Community threads, September and October 2026; BigCommerce Storefront MCP announcement, 28 April 2026; Sansec research on CVE-2026-75650; Adobe Commerce support lifecycle. Audit figures are from Vortex IQ store audits in 2026, anonymised; the October 2026 structured-data findings are from public checks of large Shopify stores and are not attributed.

Connect directly to the commerce platforms you run