ntworld.ink
Course Library · Digital Skills Stream

Agentic AI Web Dev 2026: From Design Security to Discoverable Deployment

How to control who can read your site, and how to make it readable and quotable by AI systems.

DURATION · Self-paced, two streams LEVEL · Intermediate, web fundamentals assumed FORMAT · Single-page course + 2 interactive explainers
// what this course covers

Two things that come after getting a site online

You can already publish a static site. This course covers what happens next.

Access control. Stopping people you have not chosen from reading a page. Most tutorials, and most AI coding assistants, produce a passcode box that does not do this. You build one, break it, then build one that works.

Machine readability. How AI systems read your site and decide whether to quote it. This half sorts the techniques with evidence behind them from the ones vendors are selling.

Both halves turn on one question: where is the decision made? A gate works when the decision to send or withhold happens on the server. A signal you publish works when the system reading it has decided to use it.

// what this course does not promise

No rankings, no citation counts, no traffic numbers. Much AI influence cannot currently be measured, and the techniques with evidence behind them come from research benchmarks rather than guaranteed field results. What the course teaches instead: how to build correctly, how to check a claim against its primary source, and how to report what you could not measure.

Before you start Audience and prerequisites

Who this is for, and what you need first

Written for someone who already publishes static sites and wants to know what the two new problems are and how to solve them.

// you need

No backend or framework experience is assumed. If you have never published a site, start with Putting a website online and come back.

The two streams are independent. Take Stream A alone if you only need access control. Take Stream B alone if you work in marketing or communications and the security half is not your problem.

// what you will be able to do
Foundation phase Concept, then a check in your browser

How a page gets delivered

What happens between a visitor's request and your page appearing on their screen. Both streams depend on this.

// covers

The point to take from this phase

Code you send to the browser runs on the visitor's machine, under their control. Code that runs on the server does not. Stream A is about that difference. Stream B is about which of the things you publish are actually read, and by what.

// do this

Watch a page arrive

Open developer tools on any site and reload with the network panel open. Read the response headers on the main document. Then open the sources panel and look at the JavaScript. Everything visible there is visible to any visitor.

Foundation phase Method, then one claim traced

How to check a claim before you act on it

A method for telling a web standard from a proposal. You will need it constantly in Stream B, where most of the published advice comes from vendors selling something.

// covers

The point to take from this phase

Two questions to ask about any technique in this course, and any technique someone sells you later. Who says it works, and has anyone adopted it?

// do this

Trace one claim to its source

Take a confident claim from a vendor blog about AI search. Find the primary source it rests on. Note what the source actually says, when it was published, and whether the claim survived the trip.

// core stream A

Access control

In one sentence: a passcode checked in the browser protects nothing, and understanding why tells you how access control works.

Stream A phase Build, then break

Build a passcode gate, then break it

You build the gate an AI assistant writes when you ask it to make a page private, then defeat it three ways using tools already in your browser.

// covers

Build the broken version yourself. It takes about ten minutes, and none of the rest of this stream lands without it.

Stream A phase Concept

Why a browser check cannot work

Three separate failures, and the general rule underneath them.

// covers

The rule, and what else it applies to

Anything the browser can check, the visitor can read and change. That covers hidden prices, disabled buttons, client-side validation and feature flags, not just passcodes. Real access control decides what to send before it sends it.

Stream A phase Compare, then build one

Three access-control options that work

For the common case: showing a site to people you choose, without running a subscriber system. All three are real. They differ in effort, cost and how finely you can target them.

OptionHow it worksEffort and costReach
Server function with a signed cookie A serverless function compares the submitted passcode against a secret in an environment variable. On success it returns a signed, HTTP-only, Secure cookie. Content is served only when a valid cookie arrives. Most effort. Usually free at personal-site scale on standard function allowances (medium, verify current) Per page or per section
Edge access with a one-time PIN An access layer in front of the site intercepts every request and emails a short-lived PIN to an allow-listed address. Nothing is served until the PIN is accepted. No code. A free tier covers a small allow-list, then per-user pricing (medium, verify current) Whole site or per path
Host-level site password One password for the whole site, set in the host's dashboard and enforced at the host's edge before anything is served. Least effort. Paid plan feature on the hosts that offer it (medium, verify current) Whole site only

What each protects against

The server function stops the passcode being read, the token being forged, and scripts stealing the cookie. It does not stop guessing, so choose a long passcode and consider limiting attempts. The other two stop everything in this stream, for the same reason: nothing is delivered until the check passes.

One option to know about and not use

Hosts have offered built-in account systems that give a static site real logins. At least one was announced as deprecated in early 2025, then partially walked back to "still supported", with no active development since (medium; the status is genuinely ambiguous). That is the worst state for a dependency: still recommended in old tutorials, but nothing will be fixed. Check whether a convenience feature is maintained before you build on it.

// on the prices

Pricing and plan names for all three options changed within the past year, and one host moved to a different pricing model entirely. Dated figures with confidence labels are in the access-gates resource written for this course. Re-verify against each vendor's current page before quoting a number to anyone. No price appears on this page or in the interactive explainer, deliberately.

Stream A phase Concept, then audit your own repository

Where to put secrets

The gate is only as good as where its signing secret lives.

// covers

Private repository and environment variables are two separate protections. Use both.

// companion explainer for stream A
// core stream B

Being read and cited by AI systems

In one sentence: the target has moved from ranking in a list of links to being a source an AI system quotes, and most published advice on how to do that has no evidence behind it.

Stream B phase Definitions

SEO, GEO and AEO: what the terms mean

Four labels, what each one means, and how settled it is. The terminology is contested, so this phase exists to stop you treating vendor jargon as fixed categories.

TermMeansHow settled
SEOSearch Engine Optimisation. Ranking in ordinary search results.Settled. Nobody argues about it (high)
GEOGenerative Engine Optimisation. Visibility inside a generative engine's answer.The safest label to use, because it comes from a research paper rather than a vendor (high)
AEOAnswer Engine Optimisation. Being the extracted answer in featured snippets, AI overviews and assistant replies."Answer" is the mainstream reading (high). "Agent Engine Optimisation" is a minority usage (medium; may be rising)
LLMO, AIO, "AI SEO"Overlapping descriptions of the same practice.Vendor labels. Not settled (medium)

Where GEO comes from

"GEO: Generative Engine Optimization" by Aggarwal, Murahari, Rajpurohit, Kalyan, Narasimhan and Deshpande, arXiv:2311.09735, posted November 2023 and published at ACM KDD 2024, with authors from Princeton, Georgia Tech, the Allen Institute for AI and IIT Delhi (high). Every tactic finding later in this stream comes from that paper. It is the thing to check vendor claims against.

Stream B phase Concept, then a sorting exercise

What machines read, ranked by how settled it is

Four layers, from ratified standard down to unproven proposal. Learn to place a new technique on this list before adopting it.

LayerStatus
robots.txt A genuine standard, IETF RFC 9309 (2022), respected in stated policy by the major search crawlers and most major AI crawlers. It controls what a bot may fetch, and nothing else (high)
Semantic HTML and an XML sitemap Foundational and universally respected. The base layer of being readable by any machine (high)
Schema.org data as JSON-LD Useful infrastructure, mixed evidence on citations. Helpful on some AI surfaces; a late-2025 study found no correlation between schema coverage and citation rates in several major assistants, and some engines missed data placed only in the JSON-LD. Treat it as amplification of an already-strong page, not a citation switch (medium; evidence genuinely mixed)
llms.txt A proposed convention with contested adoption. Proposed September 2024, no standards-body process, described by its own author as not an official standard, and largely unread by the systems it is aimed at on 2026 telemetry (high). It is not a replacement for robots.txt, which does a different job. Cheap to publish; not currently earning citations

What would change the llms.txt verdict is specific: a major AI company documenting that its production answer system fetches and uses the file. That has not happened.

Stream B phase Concept, then verify the current names

Which AI crawlers to allow, and which to block

The distinction that trips people up, and why blocking the wrong crawler removes you from AI answers.

// covers
// do this

Check the crawler names against the vendors

Crawler names change several times a year, so this is an exercise rather than a table to memorise. Take the list from the course, open each vendor's own bot documentation, and confirm or correct it. Record the date you checked.

Stream B phase Findings, then rewrite one of your pages

What earns a citation

The GEO paper tested nine tactics across ten thousand queries and validated against a live answer engine. Here is what worked and what did not.

TacticResult
Quoting sources directlyBest single tactic in the benchmark (medium; benchmark result)
Adding citationsAmong the strongest (medium; benchmark result)
Adding statistics from named sourcesAmong the strongest, and stronger again combined with clearer prose (medium; benchmark result)
Writing more fluently, with an authoritative voiceAmong the strongest, with no change to the facts on the page (medium; benchmark result)
Keyword stuffingScored below the untouched baseline. Worse than doing nothing (high, within the study)

What to do with that

Front-load the answer. Use headings that match the questions people actually ask. Attribute every number to a named source. Quote the sources you rely on. Write clearly. The winning tactics describe good, well-sourced writing rather than a technical trick.

One more finding: lower-ranked sites gained more from these tactics than sites already at the top (medium). Treat the paper's percentages as benchmark results, not predictions about your site.

Stream B phase Concept, then read your own logs

Why you cannot measure most of this

Ordinary analytics undercount AI influence systematically, not randomly. Knowing the size and shape of the gap is part of the job.

// covers

The defensible statement is not a multiplier. It is that a large share of the influence is unmeasured.

// companion explainer for stream B
Capstone Build, verify, report

Apply both streams to your own site

Four pieces of work on a site you actually run, and one piece of writing.

How it is marked

The writing carries the most weight. "I could not determine whether this made any difference, and here is why" is a stronger result than an unfounded number. Reporting uncertainty accurately is the habit this course is trying to build.

Optional adaptation For a marketing or communications audience

Adapting Stream B for a marketing audience

Stream B works for a marketing or communications group with a shared foundations layer added underneath and an applied layer added on top.

// shared foundations layer // marketing layer

This layer works best against the organisation's own performance data rather than generic examples. Say so when someone commissions it.

Before use Re-verification checklist

What to re-verify before delivering this

Two categories of fact here go stale faster than the course does. Both are flagged wherever they appear.

// about the two interactive explainers

Both are single self-contained files that run without a build step and work opened directly from disk. The security explainer is a closed simulation: no working passcodes, no signing code, nothing that functions against a live site. The GEO explainer keeps every status claim in line with the confidence labelling of the report behind it.

Reference Where the facts on this page come from

Sources used

Every factual claim above traces to one of these. Nothing on this page is invented, and no citation is fabricated.

The two companion documents written for this course hold the full detail with dates and confidence labels on each claim: a self-teaching resource on access gates and login options, and a report on the shift from SEO to GEO and how AI systems cite sources. Both name what their author could not verify.

Not verified, and flagged as such

The exact current pricing of all three access-control options; the exact current crawler names; which assistants each analytics platform captures today; and whether the "Agent" reading of AEO is still a minority usage. Check each before delivery.

Last updated 14 August 2026