How to make your website readable for AI assistants without exposing customer data

4 October 2026

These days it's quite normal to ask ChatGPT or Gemini, "What time does the clinic on the corner open?" Sometimes the assistant gets it right… and sometimes it makes things up. The difference lies in whether your website knows how to talk to these programs. Here it is in plain English: how to get AI assistants to understand your business (opening hours, services, menu) without putting your customers' data at risk.

What it means for a website to be "AI-readable" (and why you should care)

Until now, your website only spoke to people: someone would arrive, read, and then call or book. Today it receives another kind of visitor: AI assistants, which come to ask questions on a person's behalf. If your website is designed only for human eyes, the assistant has to interpret it as best it can, and the result is patchy.

A website being AI-readable means it can answer those assistants with clear, structured information, instead of leaving them to work it out from the HTML. The shift is already under way: Schroders' analysis of how conversational AI is changing search (2025) describes a gradual movement of questions from the search box to the conversation. Google is still the giant – around 90% of search market share, according to ADN for 2026 – but assistants have already earned their place.

What the agent.json manifest is, in plain English

Imagine your website leaving a business card at the door for agents: a public file at /.well-known/agent.json that says who you are, what you offer, when you open and how to book with you. That is the manifest.

It's the first thing an assistant can look at, much as Google looks at the sitemap to see which pages you have. And it's worth being clear about what it is not: it is not an access key. It is public information – the same you would put on the door of your premises or on your Google Maps listing – only organised so that a program understands it at first glance.

What an MCP server is for on your business's website

If the manifest is the business card, the MCP server is the question-and-answer channel. MCP (Model Context Protocol) is an open protocol that connects AI applications with external data sources and tools: it has a public specification, and Anthropic describes it as an open standard with rapid adoption. According to an Anthropic update from December 2025, as reported by Digital Applied, it already had more than 10,000 active public servers, in use across ChatGPT, Cursor and other platforms.

And what does that mean day to day? That the assistant can ask, "Do you have a table for four on Friday at 21:00?" and your website can answer with real data: the time slot, the capacity, the places free. In a clinic or a beauty salon, the same goes for services and the duration of each treatment. For a teacher or a coach, for courses and bookings. Your website stops merely "being read" and starts answering with precision.

What information is worth publishing, and what should stay protected

The rule is simple: publish everything that is already public and helps you sell, structured and up to date; everything that belongs to your customers stays where it is, and you decide on access.

Yes, publish it, well structured and kept up to date:

  • Opening and closing times, split by sittings if you serve lunch and dinner.
  • Menu with prices and allergens.
  • Services with duration and price.
  • Address and how to get there.
  • How to book, and how far in advance.

No, protect it, never in the manifest or the question channel:

  • Customers' personal data.
  • Specific bookings: who, when, phone number.
  • Payments and card details.
  • Internal notes and documents.

No assistant needs that second list to bring you customers. And if one asks for it anyway, that is where the firewall comes in.

The agentic firewall: how what you don't want to expose is protected

Think of the worst case: an agent asking odd questions, with a prompt injection (malicious instructions hidden inside the request) or a clear intention to pull out data. Who tells it no?

That is how the WordNext Guardian agentic firewall works. Every request from an agent first goes through a deterministic fast lane, with no AI, which decides on the spot whether it is allowed, blocked or quarantined. What is suspicious in its content is reviewed afterwards by a team of agents; if no verdict is reached, it is blocked (fail-closed). And whatever is judged to be an attack is learned as a rule for every website for 30 days: an attack on one website ends up protecting the rest. On top of that, the visitor's IP is never stored in plain text, only a daily hash: protection does not cost you privacy.

Can an AI book or buy on behalf of a customer? Only if you switch it on

The fear opposite to exposing data: an AI acting in your name without permission. Short answer: it cannot. An AI can make a booking or prepare a purchase only if the business enables it, and always with the person's confirmation or a mandate signed by them. And the price is always calculated by the server: nobody can manipulate it from outside.

In a restaurant it would look like this: the business sets how many diners fit per slot and the maximum per booking; the AI prepares the request ("table for four, Friday at 21:00"); the person confirms; and only times with real availability are offered. The AI prepares the ground, the customer has the final word, and the rules are yours.

How to get started on your website today, without knowing how to code

Three steps you can take this very week:

  1. Review which public information you want assistants to get right (opening hours, menu, services) and check that it is up to date: the seasonal menu? the summer timetable?
  2. Decide what is never published: the "no, protect it" list from above, in writing.
  3. Weigh up your platform: if you use WordPress or another CMS, this does not usually come out of the box; generating the manifest and the MCP server calls for bespoke development or a platform that includes it.

On that third point: every website built with WordNext is readable by AI assistants (agent.json manifest and MCP server) thanks to WordNext Guardian, and only with what is already public. No need to touch code.

Frequently asked questions

Does putting an agent.json or an MCP server online expose my customers' data?

No. Only what is already public is published: opening hours, services, menu. Customers' data does not leave, and agent requests pass through a firewall that blocks anything suspicious.

Do I need to know how to code for ChatGPT to understand my website?

No. There are platforms that generate the manifest and the MCP server automatically. On WordPress, as a rule, none of this exists without bespoke development.

Can an AI book or buy on my website without my permission?

No. Only if the business enables it, and always with the person's confirmation or a mandate signed by them. The price is always calculated by the server.

Does this replace Google SEO?

No, it complements it. Google still concentrates most searches, but day-to-day questions are gradually moving over to assistants. Having an AI-readable website prepares you for that change while you keep looking after your rankings.

If you want to see all of this working together – manifest, MCP server and agentic firewall – take a look at WordNext Guardian. And to carry on piece by piece: how to prepare your content for AI assistants and how to set up menus and online bookings without plugins.

How to make your website readable for AI assistants · Blog de WordNext