Well, here we are :) time magazine has started selling ads that only ai agents see. People get the usual html, while bots get a parallel markdown version of the same article with an ad block of «brand facts». The human version has no such block at all. The first advertisers are ally bank and project management institute, and the pages and the ads are made by the platform mobian. digiday reported the scheme first, and developer Vincent Schmalbach spotted it on the site.

The swap shows up in a single request

time decides who sees what by user-agent, so you can check this with one command:

curl -sS -D - -A "Mozilla/5.0 (compatible; ClaudeBot/1.0; +claudebot@anthropic.com)" "https://time.com/article/2026/08/07/the-last-house-ending/"

curl output: markdown version of a time page with an ally ad block

The ad-carrying markdown version goes to chatbot crawlers: claudebot, oai-searchbot, perplexitybot. gptbot and chatgpt-user got a 406 in the check by the register, while google’s regular search bot got the same html as people. So the fork is built precisely for those who put the article text straight into a model’s context.

What is actually being sold

The ad looks like a faq: a question and an answer with brand facts, marked as sponsored. mobian assembles the block from a brief, and after launch it asks ai search engines the same questions and tracks brand visibility, tone and accuracy of wording in their answers. Ads are attached to evergreen content — lists, roundups and photo galleries.

time sells one block per page at a premium, but does not disclose prices. The advertiser buys not a click, but influence over what the model will say about the brand. mobian’s head Jonah Goodhart puts it this way: you persuade a human one at a time, but change a chatbot’s answer and you get everyone who asks.

There are already more bots than people

The scale is real: on most days time sees more bot visits than human ones. That matches cloudflare’s data: bots account for more than half of all web traffic, and by the june figures cited by futurism, agents and bots overtook people for the first time.

What could go wrong

There are two risks here. google has long punished cloaking, and the rule may extend to markdown pages that differ from the human ones. And there are no rules for this kind of advertising yet: nobody has decided how language models should treat it and whether it has to be disclosed.

On the security side this is the same class of problem as indirect prompt injection, only legal and paid for. Text from an interested party lands in the model’s context dressed up as a reference fact. Architectural defenses like separating a trusted planner from a quarantined model for external data do not help here: the ad breaks nothing, it is simply persuasive. I wonder what compromise will eventually emerge between the interests of users, agent owners and ad platforms.