No Hacks with Slobodan Manic

Slobodan "Sani" Manić

AI is changing the internet, and nobody asked us if we wanted it changed. So every week I go and look at one thing it did: a website that started charging robots to read it, an assistant that got turned away at the door and answered anyway, a company that promised something a year ago and can't show a receipt. Then I tell you whether it's good, bad, or pointless, and what to do about it, whether you use the web or build it.  Around fifteen minutes per episode, usually me on my own, with occasional guests. Hosted by Slobodan Manic, a CXL-certified conversion specialist, WordPress Core Contributor, and the creator of Machine-First Architecture, the framework for building websites for the agentic web.

  1. 1d ago

    234: OpenAI's Dots Are Cute. What They Do With Your Data Is Not.

    OpenAI's new agents, dots, are fuzzy balls with eyes that you name and dress. They also sign into websites with your saved passwords and read the email you connect. I went through OpenAI's pages to see what the face is covering. What a dot reads can train the model unless you find the switch, and websites are told nothing. I would not give one my logins or my card. Chapters 00:00 Sam Altman's pitch, and what a dot is01:42 Do you need one?02:36 Where the face came from04:33 Launch day, and why now07:05 Under the costume: your data08:37 A model that looks for another way10:06 What the cute is for11:09 What websites are told12:39 Through the web, or over it14:01 The verdictKey Takeaways The face is how it gets sold. OpenAI had characters on the side in April. Meta made the character the product, and three weeks later OpenAI did too.What a dot reads can train the model by default. The setting is "Improve the model for everyone", and it covers the apps you connect, email included.OpenAI publishes no way for a website to recognise a dot. Its instructions tell the user to try their computer when a website blocks one.What to Do In ChatGPT, open Settings, then Data controls, and uncheck "Improve the model for everyone".Before you give any agent your logins or a card, ask what it does that you needed.If you run a website, send it to me at nohacks.co/ai-accuracy. I'll put one question your customers ask to the AI assistants and send you what they said. It's free.The newsletter is at nohacks.co/subscribe.Sources & Links From OpenAI Introducing dotsDots privacy FAQDots, computers and appsOpenAI's crawlersGPT-6 Astra test resultsMentioned in the episode Thomas Germain, BBC, on Meta's MuseThe Tech Report, with Ed ZitronBetter OfflineFTC on Joe Camel, 1997No Hacks runs no sponsorships and is funded by advisory and audit work.  If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

  2. Sep 26

    233: Muse Is Why Meta Has No Business Building The Agentic Web

    Mark Zuckerberg says Meta's AI agent, Muse, needs to be discreet. The same month, some of the calls it made to businesses were placed by people in a call center. I went through what he told Joanna Stern and Alex Heath about Muse's privacy and security and sorted every claim by tense. What exists today, only Meta has checked. The protection from Meta itself is promised for later this year. My verdict: stay away from this. After the sign-off, the show moves to Saturday mornings. Chapters 00:00 - Discreet AI, and calls made by people00:59 - What Muse is, and the agentic web02:33 - Joanna Stern's question03:57 - Present tense: the virtual machine and the ads05:45 - Passwords, Sentinel, Amazon and the Mac app07:05 - Future tense: the locked version and discretion10:10 - Who is asking: an ad company with a privacy record11:40 - From the browser wars to the agent wars14:42 - Two documents, 1993 and 202616:00 - After the episode: moving to SaturdaysKey Numbers 500,000+ people tried Muse in its first week, as reported by The Information97.6% of Meta's 2025 revenue came from ads$5 billion: the FTC's 2019 privacy penalty on Facebook87 million people's data reached Cambridge Analytica1993: CERN put the web's code in the public domain"Later this year": when Meta says the version it cannot see inside arrives Key Takeaways Listen for the tense. What Muse does today is described only by Meta, and nobody outside Meta has published a check of it. The version Meta itself cannot see inside is promised for later.Meta's plan for Muse is a small cut of every transaction. Zuckerberg said the cut will come from the businesses. If you run a store, that is you.The early web worked because it was given away and ran on your own computer. This time the companies want to be in the middle from day one. It is the browser wars again, fought over the agent.What to Do Before you connect your email, passwords or card to any agent, ask how it works today, in the present tense.If you run a store on Shopify, check Sales channels, then Agentic. Meta's agent and Google's AI may be on by default.Watch the full Joanna Stern interview.The No Hacks newsletter is at nohacks.co/subscribe.Sources & Links The interviews Joanna Stern, New Things with Joanna SternAlex Heath, Sources podcastMeta's own words Introducing MuseMeta's 2025 annual reportThe record FTC, $5 billion penaltyCERN, 30 years of a free and open webNo Hacks runs no sponsorships and is funded by advisory and audit work.  If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

  3. Sep 16

    232: The Agentic Web Is Still A Single-Player Game

    A hundred and seventy-two companies have put their name to A2A, the standard for AI agents at different companies to find each other and talk. I took the web address the project lists next to each name and asked 135 of them the question the standard is built around. Four answered. The reason is not technical: MCP needs one person to say yes, A2A needs two organisations. Chapters 00:00 - AWS, Microsoft, Salesforce, SAP, and four answers00:54 - What I was actually sold, and what I went looking for01:31 - What counts as another party, and what does not03:08 - Single-player, and why the reason is not technical04:07 - MCP, November 2024: one person has to agree06:56 - A2A, April 2025: two organisations have to agree11:04 - What the agent card is, and why not having one is fine12:56 - Who is actually at your server15:35 - Forget the logos, watch your own logs16:24 - After the episode: the race to the bottomKey Numbers 172 companies listed on the A2A partners page135 of them checked, both well-known paths, 270 requests4 served an agent card. 131 served nothing1 served it at the path the specification registers14 returned HTTP 200 at that path. 12 were the homepageMCP: 1 person has to agree. A2A: 2 organisationsKey Takeaways The visitor at your server is one person's assistant, not another company's agent. It fetches one thing, cannot ask a follow-up, and has no patience for a slow page. That is a smaller job than the one being described to you, and a different one.A protocol that pays off alone spreads. One that needs a counterparty waits. MCP works the afternoon you wire it up. You can implement A2A perfectly and get nothing until somebody you do not control has done the same work.Not having an agent card is not a failure. It is not a test, nothing scores you on it, and if no agent runs on your server there is nothing to publish.What to Do Watch your own logs rather than the partner lists. The day something arrives that was clearly sent by another company's system, not a person, is the day this changed.Treat a 200 as nothing. Twelve of the fourteen I found were a homepage answering to any address.Answer clearly and quickly, and be honest about what you do not have. Most websites say yes to everything.The No Hacks newsletter is at nohacks.co/subscribe.Sources & Links The standard A2A specification, section 8.2 discoveryA2A partners listIANA well-known URI registryThe other protocol Model Context Protocol specificationAnnouncing A2A, Google, April 2025No Hacks runs no sponsorships and is funded by advisory and audit work.  If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

  4. Sep 10

    231: A Paywall Stopped ChatGPT From Reading The Article. It Confidently Summarised It For Me Anyway.

    A magazine put a paywall in front of its journalism to stop AI reading it. I tested what that paywall actually checks. It reads one line of your request, the name you type in yourself, and compares it against a list. Say who you are and you get a bill. Make something up and you walk straight in. Then I asked two assistants to read the article anyway. Both got charged, both answered, and neither had read a word of it. It keeps going after the sign-off, about where this podcast is headed. Chapters 00:00 - A story, and a bill instead of a page02:19 - What a 402 is, and who sells it04:02 - What the wall checks, and the name I made up06:46 - robots.txt says one thing, the server does another08:08 - Googlebot walks in free while Penske sues Google10:08 - Is anybody actually paying12:13 - I asked Claude and ChatGPT to read it15:22 - Being read or being cited17:42 - Ask your chatbot where it got the facts19:17 - After the episode: where this is headed Key Numbers 402 Payment Required has been in the web standards since 1992 and almost nothing ever used itrobots.txt has been a convention since 1994, and nothing makes a robot obey it6,000 or 8,000 or 9,500 websites, depending which of TollBit's own pages you read25 robots named in Variety's robots.txt, 24 of them blocked3 crawlers get charged that the file never names at all0 AI companies named on TollBit's page aimed at AI companies1 paying customer ever named publicly, a news reader app Key Takeaways The paywall checks a name, not a robot. Every crawler that identified itself honestly got a bill. A name I invented, belonging to no company on earth, got the whole page one second later.Your server sets your policy and your robots.txt only describes it. Variety's two disagree right now, and three crawlers the file permits are charged anyway.Blocking the machine does not block the answer. It decides who gets credited when the machine repeats you. Two assistants credited a search engine and a podcast directory. What to Do Request a page from your own website with a crawler name in the user agent, then with a name you invent, and compareRead your robots.txt beside what your server actually returns, line by lineCheck what Google-Extended covers before you rely on it, because it has never covered AI OverviewsAsk your assistant whether it read the page or searched around itEvery link and every check I ran is in the newsletter, nohacks.co/subscribe Sources & Links No Hacks websiteVariety's robots.txtThe articleNo Hacks runs no sponsorships and is funded by advisory and audit work.  If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

  5. Aug 12

    230: A Shoe Company And A Cookie Company Now Say The Exact Same Thing To AI Agents

    On August 5 Shopify switched on a second way into every store on its platform, built for AI agents instead of people. Nothing to install, no merchant asked. I opened three unrelated stores, Allbirds, Brooklinen and Partake Foods, and asked each what it could do for a machine. All three answered with the same roughly 800 words, identical character for character, and no merchant wrote a syllable of it. What those words say, and what it costs a brand when the visitor has no eyes. Chapters 00:40 Thirty years of every shop trying to sound different02:13 What Shopify switched on, overnight, on every store03:19 Three stores, one identical answer05:06 The tools are stage direction for a machine08:13 Nobody is using any of it yet13:45 Your voice does not transmit, your data doesKey Numbers Three unrelated stores returned the same ~800 words of tool text, identical character for characterThe adapter file is version 0.1.0Etsy put AI agent platform traffic under 1% of its total in Q2 earningsShopify reports AI-referred orders tripled, which is referred traffic, not agents buyingShopify reports over a million merchants on the platformThree Takeaways Shopify wrote what your store says to machines, and every other store says it too. These are instructions, not descriptions. The checkout tool tells the agent to "follow it." Another tells it not to ask the shopper about missing options when it decides they only want to look. Someone chose when the customer gets consulted, and it was not the customer or the merchant.This is the right way to build it, which is separate from whether anyone noticed. The tools read the same database as the storefront people see, so the two cannot drift apart. One good default beats a million bad ones. It is still worth knowing a default was set for you.If the machine is the visitor, your voice does not transmit and your data is what is left. The photography, the badges, the reviews, the copy someone agonised over: none of it survives the call. Back comes a title, a price, a size run, availability. What is left to compete on is whether your prices are right and your stock is accurate. That work pays off whether or not the agents arrive.Mentioned My WebMCP reference guide: https://nohacks.co/blog/what-is-webmcpWhat I found on day one: https://nohacks.co/blog/shopify-gave-every-store-an-agent-apiShopify's docs for building the buyers: https://shopify.dev/docs/agentsTalia Wolf and the Emotional Targeting FrameworkEpisode 229, llms.txt against 137,000 domainsNewsletter, one a week: https://nohacks.co/subscribe Say hello: hi@nohacks.co No Hacks runs no sponsorships and is funded by advisory and audit work.  If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

  6. Aug 5

    229: Does llms.txt Work? What 137,000 Domains' Server Logs Show

    Most of what's sold as AI search optimization has never been tested by the people selling it, and this episode is me checking the biggest one against server logs. Ahrefs looked at 137,000 domains in June: 97% of llms.txt files got zero requests in May, and the biggest readers of the rest were SEO audit tools. I also lay out the line I use to sort every pitch: a hack tries to influence what the machine says about you, architecture changes what a machine can read and do on your website. Chapters 00:00 The AI optimization economy and its zero evidence 02:50 llms.txt checked against 137,000 domains 06:00 The main readers of llms.txt are SEO audit tools 08:53 Why this market keeps producing hacks 10:23 Visibility scores and the prompt problem 12:43 Every generation of hacks dies the same way 15:08 What survives model updates 18:39 The mirror: fix what the internet thinks you are Key Numbers 137,000 domains in Ahrefs' June 2026 server-log study28% had a valid llms.txt file, and that number is the ceiling, their customers skew technical97% of those files got zero requests in May, not low traffic, zeroOf the 3% that got fetched, around 22% of the readers were SEO audit tools, the tools that flag you for not having the fileMy own Cloudflare logs at nohacks.co show the same thing, nobody fetches itThree Takeaways The pitch is a screenshot, the truth is in the logs. Before you pay for any AI visibility work, ask for evidence at the level of server logs, and watch what happens.A hack tries to influence what the machine says about you. Architecture changes what a machine can read and do on your website. The first is rented and dies at the next model update, the second is owned.LLMs are a mirror of everything happening online. If ChatGPT doesn't call you the best X for Y, the honest question is whether the internet agrees you are, and that's the problem worth fixing.What to Do Sort anything you bought or got pitched this quarter with one question: does it change what a machine can read and do on the website, or what the machine says about it?Ask any vendor for their evidence before money leaves your account. Logs, tests, a mechanism, the same bar you'd use for anyone touching revenue.Check your own server logs for who actually fetches your llms.txt, it takes five minutesTry this: open free ChatGPT logged out of search, type "what is [your name] known for," and send me the screenshot at hi@nohacks.co. I want to see what you get.Sources Ahrefs llms.txt server-log study (June 2026): https://ahrefs.com/blog/llmstxt-study/My identity-vs-capability piece: https://nohacks.co/blog/agentic-web-identity-vs-capabilityWeekly newsletter: https://nohacks.co/subscribeNo Hacks runs no sponsorships and is funded by advisory and audit work.  If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

  7. Jul 24

    228: OpenAI Killed Its AI Browser

    I came back from a month off the grid to find OpenAI had killed Atlas, its most glamorously launched product, nine months after the keynote. It barely matters, though. The automated, non-human visitor Atlas was sending to your website is still coming, through whatever shell comes next. Build for the visitor, not the browser. Timestamps 00:00 - Back from break, and the bad news01:17 - Atlas: the most hyped browser ever launched02:27 - Watching it work is a demo, not a workflow03:29 - Killed with no keynote: the browser was never the product04:35 - The visitor isn't dead, so build for it05:24 - The real agentic web: background agents you don't watch07:52 - Silent failure: a human recovers, an agent doesn't09:41 - OpenAI's side quests, and the name that gave it away12:48 - My Cloudflare data: AI traffic is 5-10x human14:24 - What No Hacks is nowKey Numbers AI assistant traffic (ChatGPT and Claude users) is running 5-10x my human traffic on nohacks.co (my own Cloudflare AI analytics)Atlas: launched October 2025, shuts down August 9, 2026, nine months oldEight months in, Atlas never shipped beyond macOS, no Windows, iOS, or AndroidKey Takeaways The visitor outlives the shell. Browser, app, extension, cloud: the wrapper keeps changing, but the automated visitor arriving at your website is the same one every time. Build for the visitor, not the browser.Watch-it-work AI browsers were always a demo. If you have to sit and watch it, it is not a workflow. The real agentic web runs in the background, which means its failures are silent, and you never see the lost signup or sale.Being cited is not the whole game. The agent does not only mention you, it comes to your website and tries to act. Optimizing to appear in a prompt misses the harder work: a website a machine can actually use.What to Do Simplify the paths a human muscles through but an agent will not: coupon-box bugs, cookie banners, console errors. The agent hits the wall and leaves, silently.Check your own logs and bot analytics for AI-assistant traffic. You are probably getting more than you think.Stop optimizing only to be discovered. Make the website something an agent can finish a task on.More on this every week in the No Hacks newsletter: nohacks.co/subscribeSources & Links The story OpenAI is shutting down Atlas (TechCrunch)My companion take and data AI Browsers Are Backward Because Agents Never Needed the Visual LayerCloudflare Radar: bot and AI trafficNo Hacks runs no sponsorships and is funded by advisory and audit work.  If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

  8. Jun 17

    227: ChatGPT Shopping Is Scraped Google Shopping with Malte Landwehr, CMO/CPO at Peec AI

    I sat down with Malte Landwehr, who left VP of SEO at Idealo to become CPO and CMO at Peec AI, the platform that tracks what ChatGPT, Claude, Gemini, and Google AI Overviews actually cite. We open on the strangest finding of the year. GummySearch, a Reddit analytics tool that shut down last November, now sits behind about 0.1% of all ChatGPT citations. From there we get into why clicks are the wrong way to measure AI search, why your local brand keeps losing to US ones, why scaled AI content rockets then crashes, and why Malte says SEO is dead as a default growth channel. Guest Profile Malte Landwehr is CPO and CMO at Peec AI, an AI search visibility platform that runs daily prompts across ChatGPT, Perplexity, Gemini, Google AI Overviews, Claude, and Grok. He spent more than twenty years in search and product, including five years as VP of SEO at Idealo and five years as VP of Product at Searchmetrics. In his first six months at Peec AI, the company grew from roughly $500K to $5M in ARR. Chapters [0:00] Intro[1:15] Leaving one of Europe's best SEO jobs for AI search[5:07] Why clicks are the wrong way to measure ChatGPT[8:22] Which answer engines actually matter[12:34] GummySearch: a dead product winning ChatGPT citations[18:33] Listicles and the English-language fan-out bias[23:48] Advertorials, local results, and Mount AI content[33:50] Digital PR over technical SEO[36:27] ChatGPT Shopping is scraped Google Shopping, and the MCP contest[42:16] SEO is dead as a default channel, and the chunking moveKey Takeaways Stop measuring AI search by clicks. In an LLM, clicking is optional, so ChatGPT can look like 1% of your traffic while shaping most of your buying journeys. Measure the influence on the decision, not the visit.What gets written about you offsite now matters more than your own technical SEO. Grounding pulls from Reddit, G2, Wikipedia, YouTube, and news, so digital PR is the bigger lever for how AI describes and recommends you.One citable paragraph beats a chunked article. Put your main claim near the top in two or three declarative, self-contained sentences that name the entities. Do not shred a whole article into one-line bullets.Notable Quotes "In a web search, clicking is part of the intended user journey. In an LLM, clicking is completely optional." Malte Landwehr "They didn't gain visibility as a brand. They now have power over what brands are recommended by LLMs." Malte Landwehr, on GummySearch Resources Peec AI: https://peec.aiPeec AI research blog: https://peec.ai/blogMalte Landwehr's website: https://www.maltelandwehr.deFuture of AI Shopping webinar with Malte Landwehr (Peec AI): https://peec.ai/webinars/future-of-ai-shoppingConnect Malte Landwehr on LinkedIn: https://www.linkedin.com/in/landwehr/Peec AI: https://peec.aiNo Hacks runs no sponsorships and is funded by advisory and audit work.  If your website needs to work for machines as well as people, start with a fixed-scope Machine-First Architecture audit: https://nohacks.co/audit

5
out of 5
7 Ratings

About

AI is changing the internet, and nobody asked us if we wanted it changed. So every week I go and look at one thing it did: a website that started charging robots to read it, an assistant that got turned away at the door and answered anyway, a company that promised something a year ago and can't show a receipt. Then I tell you whether it's good, bad, or pointless, and what to do about it, whether you use the web or build it.  Around fifteen minutes per episode, usually me on my own, with occasional guests. Hosted by Slobodan Manic, a CXL-certified conversion specialist, WordPress Core Contributor, and the creator of Machine-First Architecture, the framework for building websites for the agentic web.

You Might Also Like