Beauty DTC AI Agent Readiness: 10 Brands Tested
I ran ten mid-market beauty DTC brands through our AI agent-readiness checker on August 26, 2026 - the names you know from Sephora end-caps and Instagram: Kosas, ILIA, Merit, Saie, Topicals and the rest. Not one cleared 3 of 9 protocols. And the part that matters: the handful of checks any of them passed, they all got for free from Shopify.
Ten beauty DTC brands, tested the same day. Top score: 3 of 9. Every passing signal (MCP, UCP, llms.txt) is inherited from the platform, not built by the brand. Agent protocols any brand self-hosted: zero. And half the sample blocks AI crawlers at the edge, so even the readiness the platform handed them is unreachable.

Stay in the loop
Get news and updates about GEO, AI search and new features. Unsubscribe anytime.
Is your brand a Ghost or a Guide on AI?
See if AI knows your brand. We ask Gemini and Claude live - in ~5 seconds, no signup.
What AI agent readiness measures
The checker probes nine public signals an AI shopping agent looks for on a storefront: model-side protocols (MCP, WebMCP, A2A), an identity layer (ANP), two commerce and payment protocols (UCP, AP2), a machine-readable API doc (OpenAPI), an llms.txt guide, and a Wikidata entity anchor. Each is a plain yes or no - does the file resolve and validate.
“Every commerce journey is moving towards having a second buyer — AI agents that evaluate what they can read and verify are augmenting digital discovery. When selecting technologies to support agentic commerce, choose openness over convenience.”
The score is how many of the nine are present, so it measures what an agent can actually find, not an opinion about the brand.
Beauty DTC agent readiness tops out at 3 of 9
Here is the full board, tested August 26, 2026.
| Brand | Platform | Agent readiness | AI crawlers reachable |
|---|---|---|---|
| Kosas | Shopify | 3 of 9 | 20 of 20 |
| ILIA | Shopify | 3 of 9 | 20 of 20 |
| Versed | Shopify | 3 of 9 | 20 of 20 |
| Saie | Shopify | 3 of 9 | 20 of 20 |
| Nécessaire | Shopify | 3 of 9 | 19 of 20 |
| MERIT | Shopify | 3 of 9 | 9 of 20 |
| Tower 28 | Shopify | 3 of 9 | 9 of 20 |
| Bubble | Shopify | 3 of 9 | 0 of 20 |
| Topicals | Shopify | 2 of 9 | 4 of 20 |
| Youth To The People | Custom | 0 of 9 | 0 of 20 |
Nine of the ten run on Shopify, and they cluster on the same 3 of 9: MCP, UCP and llms.txt. The checker flags all three as Shopify-inherited - a platform-managed storefront MCP exposed through shop.app, UCP from Shopify's platform rollout, and an auto-generated llms.txt. The brand-controlled signals (WebMCP, A2A, ANP, AP2, OpenAPI, Wikidata) came back empty for all ten.
“You need to be prepared for trust signals. Machines love trust signals.”
Not one brand had added an agent signal of its own.

Your agent-readiness score is the score your platform gave you
Topicals is the tell on the low side: same Shopify base, but 2 of 9, because its llms.txt is missing. Youth To The People is the tell on the other end - it runs a custom stack rather than Shopify and scores 0 of 9. Off-platform you inherit nothing, and nobody had backfilled it by hand. So the beauty DTC readiness number today is really a read on the platform, not the brand. That holds right up until an agent wants something Shopify does not hand you for free, and then the brand that added its own signals is the one an agent can act on. The platform-by-platform version of this is in the platform requirements piece.
Blocking AI crawlers cancels your agent readiness
The score flatters half this list. Bubble scores 3 of 9 on protocols but returns HTTP 403 to all twenty AI crawler user-agents we tested (GPTBot, ClaudeBot, PerplexityBot and the rest), so an agent cannot read the storefront those protocols were meant to open. Topicals blocks sixteen of twenty, Tower 28 and Merit eleven each. The block usually comes from an edge or WAF rule rather than a deliberate call - several of these sites sit behind Cloudflare, which can turn on AI-crawler blocking by default. Readiness an agent cannot reach does not count, which is the same failure the checkout mechanics piece covers on the transaction side.

How to raise your AI agent readiness
- Check crawler access before anything else. If you return 403 to GPTBot and ClaudeBot at the edge, no protocol on the site matters. Look at your Cloudflare Bots to AI Crawlers setting and your WAF rules first.
- Keep the llms.txt your platform gives you. Shopify generates one; do not strip it - Topicals did, and dropped to 2 of 9. It is the cheapest signal on the board.
- Add the signals nobody in your category has. A Wikidata entity for your brand, and an OpenAPI doc if you expose any public API, are brand-controlled and unclaimed across all ten here - easy ways to clear the category floor.
- If you run custom, you inherit nothing. Off Shopify (like Youth To The People) you self-host all of it - at minimum an llms.txt and a real MCP endpoint. Budget for it rather than assuming a platform default.
- Re-test after each change, because the score is simply which files resolve today.
Ten brands, one vertical, checked August 26, 2026. Small sample, and agent readiness moves - a brand can add a file tomorrow and jump. Read this as the state of one category on one day, not a permanent scorecard, and re-run any brand yourself for today's number.
The pattern under all of it is the one from the pillar guide: agents act on what they can read, and right now beauty DTC is coasting on whatever the platform exposes. The brands that add even one signal of their own will stand out, because the category floor is the platform default.
Want your own number? Run GEOlikeaPro's agent-readiness checker on your store and see which of the nine an agent can find.
FAQ
What is an AI agent-readiness score?
It measures how many of nine public signals an AI shopping agent looks for are present and valid on a storefront: MCP, WebMCP, A2A, ANP, UCP, AP2, OpenAPI, an llms.txt guide, and a Wikidata entity. Each is a plain yes or no (does the file resolve and validate), and the score is how many of the nine are found. It measures what an agent can actually discover, not a judgment about the company.
Why did the beauty DTC brands score so low?
In our test of ten mid-market beauty DTC brands on August 26, 2026, none cleared 3 of 9. The three that passed (MCP, UCP, llms.txt) are all inherited from Shopify at the platform level, not built by the brand. None of the brand-controlled signals (WebMCP, A2A, ANP, AP2, OpenAPI, Wikidata) were present for any of the ten, so the ceiling was whatever the platform hands over for free.
Does being on Shopify make you AI agent-ready?
Partly, and only to a floor. In our sample every Shopify beauty brand inherited the same three signals (MCP through shop.app, UCP from Shopify's rollout, and an auto-generated llms.txt) for 3 of 9. The brand-controlled protocols were still missing, and the one brand on a custom stack scored 0 of 9. So Shopify gives you a baseline, not a finished agent-readiness posture.
Can blocking AI crawlers hurt your agent readiness?
Yes, and it can cancel it outright. A storefront can pass protocol checks yet return HTTP 403 to AI crawler user-agents at the edge, so an agent cannot read the site at all. In our sample one brand scored 3 of 9 on protocols while blocking all twenty AI crawlers we tested. The block usually comes from an edge or WAF rule (Cloudflare can enable AI-crawler blocking by default), so check that before anything else.
How do you improve an AI agent-readiness score?
Start with crawler access: if you 403 GPTBot and ClaudeBot at the edge, no on-site protocol matters. Keep the llms.txt your platform generates. Then add brand-controlled signals almost no one has yet, like a Wikidata entity and an OpenAPI doc if you run a public API. If you are on a custom stack you inherit nothing and must self-host at least an llms.txt and an MCP endpoint. Re-test after each change.