A free, working cannabis & CBD SEO library, 500 guides. Browse the library ›
Home » Blog » On-Page & Technical SEO » How to Run an AEO Audit on a Cannabis Website
On-Page & Technical SEO

How to Run an AEO Audit on a Cannabis Website

In short

A cannabis AEO audit checks whether AI answer engines can reach your pages, read them and quote them. Start with crawler access in robots.txt and your firewall. Then check the age gate and whether your menu exists without JavaScript. After that, confirm your pages are indexed and allowed to show a snippet, and only then work on how answers are written. A free audit tool gets you started, but the checks that matter most on a cannabis site are the ones you confirm by hand.

What a cannabis AEO audit checks

A cannabis AEO audit asks one question of every important page: can ChatGPT search, Perplexity, Google's AI Overviews and AI Mode get to it, read it and pull an answer from it? Most of that overlaps with a normal cannabis SEO audit. Google says outright that a page needs to be indexed and eligible to show a snippet to appear in its AI features, and that there are no extra technical requirements beyond that. The AI-specific part of the audit is smaller than most people expect, and on a cannabis site it clusters around three things: bots being turned away, age gates and JavaScript menus.

We treat AI search as one more search surface inside the same SEO program, not a separate project. If you want the background first, our explainer on AEO for cannabis covers what the term means.

Start with crawler access

Crawler access is the first check because nothing else matters if the bots never get the page. Open your robots.txt and look for rules naming AI user agents. OpenAI runs separate crawlers for separate jobs, and its documentation says you can allow OAI-SearchBot, so you can appear in ChatGPT search results, while blocking GPTBot, which collects training data. Plenty of sites block both without meaning to, usually through a plugin setting or a template copied from somewhere else.

Robots.txt is only half of it. Firewalls and CDNs block bots before robots.txt is ever read. Cloudflare moved to blocking AI crawlers by default in July 2025, so a site behind it can be turning away AI bots that nobody on the team chose to block. Cannabis sites also tend to run aggressive security rules after dealing with scrapers and fake orders. If AI bots are getting 403 or 429 responses, your server logs will show it.

Check what your age gate shows a bot

The age gate is the check most specific to cannabis. A gate drawn as an overlay on top of a fully loaded page usually does no harm, because the product text is still in the HTML. A gate that redirects to a separate URL, or holds back the page content until someone clicks, is a different story. A crawler can't click "I am 21," so it indexes the gate and nothing behind it.

To test it, fetch a product page with a command-line tool or a crawler set to an AI user agent, then search the raw HTML for a product name and a price. If they aren't there, neither search engines nor AI engines can see them.

See whether your menu exists without JavaScript

Whether your menu exists without JavaScript is where many dispensary sites quietly lose. Vercel's December 2024 study of crawler traffic found that none of the major AI crawlers it measured render JavaScript, including OpenAI's, Anthropic's ClaudeBot and PerplexityBot. Menus from third-party ordering platforms are often loaded with JavaScript or placed inside an iframe, and content inside an iframe belongs to the platform's domain, not yours.

The result is a common pattern. AI engines know the store exists, its address and maybe its hours, but they can't see a single product. The fix is to server-render the pages you want quoted: location pages with hours and services in plain HTML, category pages with real text, and top products on pages your own domain serves.

Make answers easy to lift

Making answers easy to lift comes next, once access and rendering are clean: each page should give an engine something to quote. Put a direct answer under each question-style heading. Keep your name, address and phone number identical everywhere. Use structured data that matches what's on the page, such as store and product markup, and check that no page carries a nosnippet or max-snippet:0 tag you forgot about. Google's eligibility rule means a page that can't show a snippet can't be a supporting link in AI Overviews either.

llms.txt comes up in every AEO conversation. It's a proposed standard, so treat it as cheap and optional, not as a lever that moves results.

Pick AEO audit tools that fit the job

AEO audit tools split into two kinds: tools that check whether your site is ready for AI crawlers, and tools that track which prompts mention you. For an audit you want the first kind. EliteAEO keeps a comparison of AEO audit tools that lists 20 of them A to Z with what each one checks. 5 of the 20 let you run an audit for free, and the checks range from fetching a page as GPTBot to scanning robots.txt rules for 14 AI crawlers.

Run a free one first to get a baseline, then confirm its findings by hand. No tool knows how your age gate works or which menu provider you use, and those two settings decide more on a cannabis site than any score.

What to fix first

What to fix first follows the order the bots meet your site. Access comes first, then rendering, then indexing and snippet eligibility, and only then content structure. Rewriting answers on a page that GPTBot gets a 403 on is wasted work. After the technical layer is clean, the next gains come from being mentioned on other sites that AI engines already trust, which is ordinary link and PR work.

Next steps

Your next steps start with robots.txt and your firewall: check both for AI bot rules this week. Fetch three key pages as an AI user agent and look for your product text in the raw HTML. Fix access and rendering before touching copy, then run a free audit tool to catch what's left.

Frequently asked questions

Is a cannabis AEO audit different from a cannabis SEO audit?

A cannabis AEO audit is mostly a cannabis SEO audit with a few extra checks: AI user agents in robots.txt and the firewall, raw HTML without JavaScript, and snippet controls. If your SEO audit already covers those, you have most of an AEO audit.

Should a dispensary block GPTBot?

A dispensary that blocks GPTBot stops OpenAI from using its pages for training, and OpenAI says that is a separate setting from OAI-SearchBot, which powers ChatGPT search results. Many stores allow the search crawler and decide on the training crawler separately.

Does llms.txt help a cannabis site show up in AI answers?

llms.txt is a proposed standard, and none of the evidence so far shows it moving AI answers. It takes minutes to add, so add it if you like, but don't put it ahead of access and rendering fixes.

How often should a cannabis site run an AEO audit?

Run an AEO audit after any change to your theme, age gate, menu provider, CDN or security plugin, since those are the changes that break bot access. Otherwise a quarterly check is enough for most stores.

Do free AEO audit tools work on cannabis sites?

Free AEO audit tools work on cannabis sites for the general checks: crawler access, schema and page structure. They can miss problems caused by age gates and embedded menus, so test those by hand with a raw HTML fetch.

Key takeaways

  • Most of an AEO audit is an SEO audit: indexed, crawlable and snippet-eligible pages come first.
  • Check AI bot access in robots.txt and in your firewall or CDN, not just one of them.
  • Age gates and JavaScript menus are the two cannabis-specific reasons AI engines see a store but not its products.
  • Use a free audit tool for a baseline, then confirm the cannabis-specific checks by hand.

Sources

Want this done for your brand?

We build cannabis & CBD search visibility with full transparency, for dispensaries, brands, and MSOs.

Get a free cannabis SEO audit ›