Claude Updates: Web Search, Crawlers and Anthropic News

Claude as a search surface: what its crawlers do and what traffic it sends. And every Anthropic change that matters to site owners.

Last updated: Last checked: Web search global on all plans; Claude for Chrome on all paid plans; the $1.5B authors settlement approved
+386%Claude referral growth, Jan to Apr 2026SE Ranking panel of 101,574 sites
86.7%Citation overlap with Brave SearchProfound, a March 2025 measurement
$1.5BAuthors settlement, approved Jul 2026About $3,000 per work across ~500,000 works
3Documented Anthropic crawlersAll three honor robots.txt, per Anthropic

This page tracks Claude, Anthropic's assistant, as a search surface. It covers its web search and citations, the Claude for Chrome agent and the three documented crawlers.

It also covers what independent measurement says about the traffic they cost and send.

Anthropic announces less than any company on this beat. So much of what is known comes from measurement: referral panels, crawl-ratio studies and bot telemetry.

Where a figure appears here, we say what it counts and when it was measured. Claude numbers age fast and often measure opposite directions of traffic.

We update within a day or two of significant changes. Every claim links to a source we have read.

Claude search timeline: March 2025 to today

Every significant Claude search-surface change since web search launched, newest first. A thinner timeline than its neighbors fits this beat.

Anthropic ships and announces less, and measurement fills the gaps.

One dot per milestone since Claude web search launched in March 2025, one lane per event type. Hover a dot to identify it; most dots click through to the entry below.
20252026Product3Availability3Data9Legal1
DateEventTypeWhy it matters
2026
Claude in Chrome goes GA and acts autonomously; a built-in browser ships in CoworkProductAgent traffic on ordinary sites through a signed-in session; the crawler documentation still names three bots and never mentions browsers
IAB publishes an AI visibility measurement standardDataA shared vocabulary and a directional-versus-decision-grade quality test for the 20-plus tools selling AI visibility numbers; it ranks no provider
Replaying a prompt without its conversation changes 44.7% of answersDataPaired experiment on 180 multi-turn conversations; 26.7% of cases changed the recommendation or conclusion, and a 160-word prefix summary still left 30.8% materially different
$1.5B authors settlement approvedLegalBelieved the largest US copyright settlement; no appellate precedent set
DataDome Q2: Claude referrals +111%, Meta crawlers take the majority of AI trafficData876,000 Claude referral visits; Meta's two bots make 9.1B requests and send almost nothing back
Assistants recommending brands mostly cite other companies' pagesData102,025 responses, five assistants: 75.2% of citations to third-party corporate pages against 2.9% to the brand's own; the listicle is 21.0% of all citations
SE Ranking measures Claude referrals: +386% off a tiny baseData1.40% of AI-referred traffic in a 101,574-site panel
SIGIR: 252,000 trials on what wins the first citationDataFour gatekeepers hold across all six models tested: on topic, a stated price, a recent date, list position; formatting moved nothing
Wharton and Rutgers: blocking AI crawlers cost large publishers about 7% of weekly trafficDataStaggered DiD across SimilarWeb, Semrush and Comscore; window stops before AI Overviews, and the human-panel estimate is imprecise
2025
Claude for Chrome reaches all paid plansAvailabilityPro, Team and Enterprise join after months of testing
Claude for Chrome opens to all Max subscribersAvailabilityScheduled tasks and multi-tab workflows added since the pilot
Cloudflare publishes the crawl-to-refer seriesDataAnthropic measured at the highest crawl cost per referral of any AI operator
Claude for Chrome pilot beginsProduct1,000 Max users; published adversarial safety numbers
Web search goes global on all plansAvailabilityFree tier included, via an update note rather than an announcement
Search backend identified as BraveDataSubprocessor listing plus two independent measurements
Claude web search launchesProductPaid US preview on Claude 3.7 Sonnet, with direct citations

Latest updates

Product

Claude in Chrome goes generally available and starts acting without asking, and Claude gets a second browser of its own

Anthropic published two posts on 26th Aug that together change what Claude does on other people's websites.

The first says Claude in Chrome is generally available. Plan coverage reached every paid plan in December 2025, so that is not the change that matters.

It is that "Claude can now also take actions autonomously in the browser, instead of needing approval for every one", using the same automatic-approval mechanism as Claude Code.

A classifier reviews each action Claude is about to take. That includes opening a site or typing into a page.

It blocks any action that does not match what the user asked for. The setting can be switched off.

What Claude does through the extension is unchanged in kind. It reads the page, clicks links, types text, navigates and fills forms, on the user's existing logins.

The second post is the new one. Claude now has its own browser inside the Claude Cowork desktop app.

It opens in a side panel. It does the same navigating, reading, clicking and typing without touching the user's own browser at all.

Anthropic's framing of why both exist: "a lot of web tasks don't need your browser, just a browser, and now Claude has one".

Logins are carried over site by site from Chrome, Edge or Firefox. Banking, email and single sign-on sites are excluded unless the user opts them in.

It is rolling out over the week to Pro, Max and Team on macOS, Windows and Linux. It is on by default once it arrives.

Enterprise has it now, managed by admins in organization settings. Those admins can also restrict Claude in Chrome to approved domains.

The extension does not run on other Chromium browsers or on mobile.

For a site owner, what matters is what none of this appears in.

Anthropic's site-owner help page describes three bots and states that they honour robots.txt. They are ClaudeBot for training, Claude-User for fetches triggered by a user's question and Claude-SearchBot for search quality.

Read on 27th Aug, that page does not contain the words browser, Chrome, extension or agent anywhere. Neither of the two announcements names a user agent.

So there is no published way for a site owner to recognise this traffic. There is also no stated answer to whether robots.txt bears on it at all.

That is a different situation from a crawler you can allow or refuse. Requests arrive inside a signed-in session that the user authorised.

That is the same shape as Grok Bot. It is the reason this hub keeps returning to the gap between crawler controls and agent traffic.

The prompt-injection numbers are published, and they are the most detailed on this beat.

Anthropic's current test set is built from attacks written by professional red-teamers. Attacks that reached the model succeeded 17.6% of the time against Opus 4.5 before extra safeguards.

Against Opus 5 the rate was 3.8%. Anthropic also reports results with the content probes and the approval classifier running.

There were no successful attacks against Sonnet 5, Opus 5 or Mythos 5. Fable 5 saw a 0.3% success rate.

Two caveats come from Anthropic itself. The older test set was retired because it had been saturated at a 0% success rate.

Not every attack reaches the model in the first place. So these rates describe the attacks that got through rather than all attempts.

Anthropic's own conclusion is the one to carry into any decision about letting agents onto a site. The measures "meaningfully reduce the risk but can't eliminate it", and it recommends starting on sites the user trusts.

Data

The IAB publishes a measurement standard for AI visibility, and refuses to rank the tools selling it

The Interactive Advertising Bureau published Measuring Visibility in the AI Era on 3rd Aug. It is a set of guidelines for measuring how brands and publishers appear inside AI-generated answers.

It starts from a problem this page runs into constantly. More than 20 companies now sell AI visibility measurement tools.

Per the IAB, each uses different methods that "can produce different answers for the same brand or publisher".

The framework's answer is limited on purpose. It supplies a shared vocabulary, quality criteria and disclosure requirements.

In the IAB's own words it does so "without prescribing specific tools or ranking individual providers".

That limit is the most useful thing in it for a buyer. A trade body ranking vendors produces a winner list.

Defining what a mention is, and what a provider must disclose about counting one, does something better. It lets buyers compare quotes themselves.

The metrics sit in a four-level hierarchy the IAB calls the 4 P's of AI Visibility. The levels are ordered by how visibility turns into business value.

Presence asks whether you appear at all, through mention rate, citation rate, share of voice and visibility momentum.

Prominence asks where and how prominently. That includes how substantively a publisher's content is drawn on rather than merely listed as a source.

Portrayal asks in what context and with what accuracy. It covers sentiment and framing plus a hallucination rate and a factual inaccuracy rate.

Keeping those last two apart is the point of the level. A hallucinated mention is one the model invented.

A factual inaccuracy is one where the model reported a real source faithfully and the source was wrong. The two have different remedies.

Persuasion asks whether any of it drives action, through recommendation strength and post-citation click-through rate. How to attribute is left to a separate IAB framework still to come.

The second contribution is a quality test that sorts data by what it can safely be used for.

Directional measurement identifies patterns and signals trends, and the IAB states plainly that it "is not sufficient for budget allocation or executive strategy decisions".

Decision-grade measurement meets a higher standard across query volume, sample size, prompt type coverage, testing cadence, reproducibility and platform coverage. The IAB says that standard is required before any budget or strategy decision.

The named failure is not using directional data. It is treating directional data as decision-grade without noticing the difference.

Caroline Giegerich, the IAB's VP for AI, framed the gap the document is meant to close: "Consumers are increasingly discovering and considering brands and products in AI platforms, but measurement frameworks haven't kept pace."

Two things to know before reading it. Its scope is organic, non-paid visibility only.

So it does not cover paid placement inside AI answers, generative engine optimization tactics or commerce attribution.

And the adoption figures it cites for context are borrowed from third parties. The IAB did not measure them.

Those figures cover how many people use which AI surface. We have not adopted them here.

Some sit awkwardly beside the figures on our own hubs.

This framework also gets no row in the measurement table above, by design. Every row there counts something real that happened.

A vocabulary counts nothing, however useful it is for judging the people who do the counting.

Study

Testing a prompt on its own changes the answer in 44.7% of cases

Read this one with its authorship in view. It is a single-author arXiv preprint by Benjamin Tannenbaum of Aiso, a company selling AI-visibility tracking.

It has not been peer reviewed. The self-interest runs one way and belongs next to the result.

Aiso sells session-level conversation tracking, which is the product this finding argues buyers need.

We are carrying it because it measures a mechanism rather than ranking who is winning. It also repeatedly declines claims it could have made.

The question is narrow. Holding the last thing a user typed constant, how much do the earlier turns change the answer?

The experiment is paired at the conversation level across 180 English multi-turn conversations. Half come from Aiso's own governed corpus and half from the public PRISM dataset.

The final user message, the answering model and the output format stay fixed. Only the representation of the preceding turns changes.

Three answers are generated per case. One comes from the full role-labelled conversation and one from the final message alone.

The third comes from the final message plus a reconstruction of the earlier turns capped at 160 words.

One design detail carries a lot of weight. The reconstruction model never sees the final message.

So it cannot write a convenient summary backwards from the endpoint.

A separate judge model then scores all three under randomized labels. A difference counts only if it could change what the user does.

Four kinds of change qualify. Two are a different recommendation or factual bottom line, and different compliance with an explicit constraint.

The other two are a different requested deliverable, and different clarification or refusal behaviour. Wording, tone, organisation and amount of detail are excluded by rule.

Removing the conversation changed the answer materially in 44.7% of cases, weighted to the eligible cohorts. The 95% confidence interval runs from 33.8% to 56.1%, and the unweighted paired rate is 53.3%.

Full-conversation answers also scored better. The weighted mean was 3.80 against 3.31 on a 0 to 4 request-satisfaction scale.

The direction is not universal, and the paper says so. Full context scored higher in 36.2% of weighted cases and lower in 6.0%, with the rest tied.

The category breakdown is the part to read closely, with one caution about how it is reported.

The results table lists a changed recommendation or conclusion at 26.7% (17.0% to 36.9%). Changed clarification or refusal behaviour is at 14.4%, and changed constraint compliance at 10.6%.

The table presents those in the same column as the 44.7%, as rates over all cases. The body text describes them as shares of the differing pairs.

Read them as the paper's own category breakdown rather than as three independent rates. Note the paper's own line that the categories can co-occur.

The compressed-prefix condition produced the most useful result here. A 160-word summary of the earlier turns closed almost the whole satisfaction gap, to 0.01 points.

It still left 30.8% of answers materially different from the full-conversation answer.

So a state summary can support an equally good answer while changing which reasonable answer the model picks. Average quality and answer identity are not the same measurement.

The paper draws the consequence for this industry itself: "For a visibility tracker, that can mean a different cited brand."

There is also no safe subset of self-contained prompts. Cases were sorted by how context-dependent the final message looked.

Isolation still changed 31.0% of the least dependent answers. The middle band saw 56.1% and the highest 48.4%.

The companion paper from ten days earlier established the other half of this. It covered 670 commercial and 7,463 public conversations.

In 50.3% and 44.8% of conversations, an explicit constraint, alternative, correction or evidence requirement appeared before the final message. It did not appear in the final message itself.

The final prompt reproduced the full set of detected request dimensions in only about 26%.

The limits are large enough that this is direction about a measurement error. It is not a rate to quote as a population figure.

One answer model was requested, gpt-5.4-mini, with gpt-5.5 as judge. Both ran through a research command-line runner rather than a native chat product.

There was one generation per condition.

The judge is automated rather than human. The paper names that as its own most important replication target.

Medical, legal, financial and other high-stakes conversations were excluded from the sample entirely.

Half the sample is Aiso's own corpus, which cannot be redistributed. The weighting leans the pooled estimate towards the public half.

The commercial half showed a far larger effect, 68.5% against PRISM's 35.4%.

The scope is preceding turns inside one conversation. It does not test persistent memory across separate sessions.

The paper is explicit that its data cannot observe such a system.

Here is the practical reading for anyone buying this kind of data. A tool reporting whether assistants mention you is measuring endpoint strings unless it tells you otherwise.

The paper asks that such prompt sets be labeled as endpoint-message evaluations. Its conclusion puts it plainly: "Replaying endpoint strings alone measures a different task."

Read it beside the IAB framework published the same day. Its decision-grade test asks about query volume and prompt-type coverage.

This paper is about what a query is in the first place.

None of it belongs in the measurement table above, whose rows count real crawling and real referrals.

Legal

Anthropic's $1.5 billion authors settlement gets final approval

Judge Araceli Martinez-Olguin approved the $1.5 billion class settlement on 20th Jul, per TechCrunch: "The payout will deliver $3,000 per work across an estimated 500,000 works, shared among the authors and publishers who hold rights to them."

The legal shape matters as much as the number. Judge William Alsup had ruled that TRAINING on the books was fair use.

Downloading and storing millions of pirated copies was not. He granted preliminary approval on that basis in 2025.

Because Anthropic settled rather than appealed, no binding appellate precedent was set in either direction. Every other AI copyright docket, including Perplexity's eleven cases, proceeds without a controlling answer.

For site owners the practical reading is economic. Pirated training corpora now carry a price tag believed to be the largest in US copyright history.

That strengthens the hand of anyone licensing content, and the case for controlling the training crawler.

Study

DataDome: Claude referrals more than double, while Meta's crawlers take over the AI web

DataDome, a bot-management vendor, publishes a quarterly count of AI agent traffic across its network. The Q2 2026 edition is by VP of Threat Research Jerome Segura.

It draws on April to June data from "5 trillion signals analyzed daily across 400+ enterprises".

The Claude figure is the reason this sits here. Claude referral visits grew 111% quarter on quarter, from 415,000 to 876,000.

DataDome calls that the fastest growth among the tools sending real visitors to websites.

Perplexity grew 37% over the same period.

That is the second independent panel in two months to measure Claude referrals climbing fast from a small base. The first was SE Ranking's 386% over four months.

The two count different things on different networks. So they confirm the direction rather than the size.

The wider finding is that crawling and referring have come apart. ChatGPT-User fetched 6% fewer pages than in Q1 while ChatGPT referrals rose 17%.

ChatGPT still accounts for 80% to 88% of all AI referrals every month.

Meta runs the opposite way. Its two crawlers generated 9.1 billion requests in the quarter.

That is more than half of all AI agent traffic on the network.

DataDome's summary of what publishers got for it is blunt: "those billions of visits sent almost no real visitors back to those sites in return".

The two Meta bots do different jobs, and the split is the part site owners should read.

Meta-ExternalAgent, up 74% to 5.3 billion requests, collects training data. Meta-WebIndexer, up 163% to 3.75 billion, indexes pages so Meta AI can answer current questions.

In June it passed the training crawler in monthly volume for the first time.

Meta's own crawler docs say the same thing in Meta's words. Meta-WebIndexer "navigates the web to improve Meta AI search result quality", and allowing it in robots.txt "helps us cite and link to your content in Meta AI's responses".

So blocking it is a citation decision as well as a bandwidth one.

Read the denominator carefully. These are request counts on DataDome's customer network, not the web, and they are not crawl-to-refer ratios.

So none of them is comparable with the Cloudflare series above. That series divides crawls by referrals for a named platform.

Anthropic's own crawlers are not broken out in this report at all.

StudyWhen an assistant recommends brands, it mostly cites other companies' pages

Read this one with its authorship in view. It is a single-author paper by the operator of Ranqo, a commercial AI-visibility tracking platform.

It was posted to arXiv and not peer reviewed. The data is that platform's own production telemetry.

We are carrying it because its useful findings are about mechanism rather than about which brands are winning. The paper is also careful about the difference.

It covers 102,025 prompt responses and roughly 15,815 brand mentions across 102 brands on five assistants. The window ran between March and May 2026.

The finding to act on is where the citations go. Take an assistant citing sources while it recommends brands in a category.

75.2% of those citations point at corporate pages belonging to other companies in the same space. Just 2.9% point at the tracked brand's own domain.

So the pages an assistant reads to decide whether to recommend you are mostly your competitors' and peers' sites. The author reads this as the citation Matthew effect at brand level: already-cited domains attract more citation.

The non-corporate ranking also reorders a common assumption. Once corporate pages are set aside, video leads at 4.2% of all citations.

Tech and business media come next at 3.8%, then Reddit and other community forums at 3.3%.

Wikipedia follows at 2.6% and the software review sites G2 and Capterra at 1.1%.

On page type, roughly 59% of cited URLs are content pages. The rest are homepages, product pages and other landing pages.

Within the content, the ranked "best-X" listicle is 35.7% of content citations and 21.0% of all citations. The generic article follows at 31.0% and the how-to guide at 9.7%.

The author's argument for why the listicle earns that share is the practical part.

Once a ranked list includes a brand, that one page becomes a source. The engines reuse it across many different prompts.

The headline the paper leads with is a brand-stature ladder.

On unbranded category prompts, first-run visibility is 72.9% for the 11 largest brands tracked. It is 43.6% for the 36 mid-market ones and 11.4% for the 55 smallest.

Treat that ladder as an effect size rather than as a cause. The tiers are hand-coded from Wikipedia presence, press and funding, which are themselves proxies for web prominence.

The paper says so. It measures the size of an expected effect rather than proving that prominence drives citation.

One measurement caution applies well beyond this dataset. Sentiment is far less stable than mention.

Whether a brand is framed positively or negatively flips in 45.5% of repeat observations. Whether it is mentioned at all flips in only 6.8%, which makes sentiment roughly 6.7 times noisier.

No cell in the data was consistently negative.

What we are not carrying from it is anything about the vendor's own recommendation engine. The paper itself says its data cannot support a causal claim for it.

The cohort is convenience-sampled and skews towards SaaS, retail execution, fintech and Indian direct-to-consumer brands.

So none of these shares is a population rate. None of them appears in a statistics table here.

StudySE Ranking: Claude referrals grew 386% in four months, from a tiny base

SE Ranking's study measured Claude referrals across 101,574 websites with Google Analytics in 250 countries. The window ran from January 2025 to April 2026.

The growth is the headline. Claude's share of the panel's referral traffic went from 0.0029% in January 2026 to 0.0141% in April.

That is a 386% rise in four months. The base is the caveat.

All AI platforms combined drove 0.33% of the panel's traffic. Within that Claude held 1.40%, against ChatGPT's 78.23%, Perplexity's 9.33%, Gemini's 6.85% and Copilot's 3.57%.

Those figures are from Search Engine Journal's write-up of the study.

Two disclosures belong with the numbers. The study counts only direct clicks from AI platforms, not AI-influenced visits arriving through other channels.

And SE Ranking sells AI visibility tooling, a point SEJ's coverage makes. SEJ also observes that Claude is used mainly for writing, coding and analysis rather than search.

StudyA 252,000-trial experiment on what wins the first citation

Read this one with its authorship in view, as with every vendor-adjacent study on these pages.

All three authors work at Sprinklr, which sells software in this space. They piloted the resulting workflow inside the company.

It is also the most solid evidence anyone has published on the question. It was peer reviewed and presented at SIGIR 2026 in July 2026.

SIGIR is the main academic conference in information retrieval.

We are carrying it because it measures a mechanism rather than ranking which brands are currently winning. It is also very careful about what it does and does not measure.

The setup is a controlled retrieval test, not an observation of live search. On each trial the model is handed exactly two candidate sources and told to answer with citations.

The recorded outcome is which of the two the first citation marker points at.

The pairs are built from 100 product-review articles across 50 consumer categories. Every brand, product model and publisher name is replaced by a fictional alias.

So familiarity cannot decide the result.

Each pair differs in exactly one of 18 content factors. Facts, prices, specifications and length are held equal.

Order is counterbalanced and every combination runs five times.

The total is 42,000 trials on each of six models. Those are Gemini 2.5 Flash, Claude 3.5 Sonnet, Kimi K2 Thinking, GPT-5 Nano, GPT-5 Mini and GPT-5.2.

Four factors behaved as gatekeepers, significant in all six models with odds ratios above 100.

They are the content being on topic and a price being stated. The third is a recent date rather than an old one.

The fourth is being listed first rather than second. The paper's reading is that failing any one of them can eliminate citation odds.

That holds however strong the rest of the page is.

Seven more factors mattered in at least four of the six models. Their odds ratios ran from 2.1 to 243.

They are ordinary editorial fixes: carrying the query's terms, giving specifications, comparing against alternatives and writing confidently instead of hedging.

The others are backing claims with evidence, avoiding internal contradictions, and covering a subject deeply rather than shallowly.

The negative result is the most useful part for anyone budgeting the work. Formatting did nothing.

Dense paragraphs against organized sections, and scattered against grouped information, moved no model at all. The authors read that as models parsing content regardless of how it looks.

Five other plausible factors reached significance in only two or three of the six. So they carry no consensus.

They are a promotional tone, a weaker value proposition and weaker social proof. The other two are the timestamp comparisons that do not pit a recent date against an old one.

How much content moves a model varies sharply by model. Kimi K2 responded to 83% of the factors and the GPT family came next.

Claude 3.5 Sonnet at 50% and Gemini 2.5 Flash at 33% were the most selective.

Those two were also the most categorical. Between 67% and 78% of the factors that did move them produced odds ratios above 10,000.

The authors read that as something close to a binary decision boundary. All six still agreed on the four gatekeepers.

One figure explains why the first citation is the thing being counted. Across successful runs, answers named exactly one distinct URL 86.4% of the time.

Two or more URLs appeared 10.5% of the time, and none at all 3.1% of the time.

The limits are large enough that this is direction about a mechanism. It is not a measurement of any product.

No search engine was ever called. The two candidates are injected straight into the model's context.

So the paper says nothing about Claude's own web search, or about AI Overviews, AI Mode or ChatGPT search. The model versions tested are not the ones those surfaces run.

Production retrieval returns five to ten pages or more. The authors are explicit that their estimates are pairwise preferences over a controlled slate rather than full competition.

Anonymizing the brands is a design choice. It strips out the domain trust and brand recognition a live system may still weigh.

The corpus is synthetic. GPT-4o wrote the seed articles, performed the anonymization and produced the paired rewrites.

And the price gatekeeper comes from consumer product reviews.

So it is a finding about commercial pages. It is not a rule for a page with nothing to price.

None of it belongs in the measurement table above, whose rows all count real crawling and real referrals.

DataA Wharton and Rutgers study measures what blocking AI crawlers cost publishers: about 7% of weekly traffic

Hangcheng Zhao of Rutgers Business School and Ron Berman of The Wharton School asked a question. What did publishers get for blocking AI crawlers?

They measured a cost rather than a benefit. Their paper is Strategic Response of News Publishers to Generative AI.

It is a working paper rather than a peer-reviewed one. The version read here is the fourth, posted 15th Apr 2026.

It also circulates as a Wharton School research paper on SSRN. That copy was posted 14th Jan 2026 and last revised on 21st Apr.

The design is what makes it useful. Each publisher's first blocking event is identified from historical robots.txt snapshots in the HTTP Archive.

Blockers are then compared against publishers not yet blocking and publishers that never blocked.

The comparison uses the staggered difference-in-differences estimator of Callaway and Sant'Anna. It covers the 12 weeks before and 6 weeks after.

The outcome is log weekly visits, measured three separate ways. Those are SimilarWeb's daily domain estimates, Semrush's channel-level data, and Comscore's US household browsing panel.

All three point estimates land in the same place. The average treatment effect on the treated is -0.074 in SimilarWeb (significant at 1%).

In Semrush it is -0.069 (significant at 10%). In Comscore it is -0.065, which the paper reports with a confidence interval from -0.150 to 0.021.

Converted out of logs, that is about a 7% decline in weekly traffic within six weeks of blocking.

The Comscore column is the one to read carefully. It is the one that measures humans rather than server-side estimates.

Its estimate is the same size as the others and its confidence interval crosses zero. The paper's own summary line says so plainly: blocking "reduces total traffic; there is a negative, but imprecise effect on human traffic".

Size decides who this applies to. The authors extended the test to the 500 largest news publishers.

The effect is negative and significant for the top 50 by Semrush rank. It is negative but not significant for ranks 51 to 100, and no longer negative below that.

That is why the paper's abstract says large publishers. The same gradient appears in the Comscore data when it is split by daily visits.

The effect also fades: point estimates stay negative but lose significance after roughly 20 weeks.

The mechanism the authors propose is brand exposure rather than lost clicks. When a publisher blocks, the assistant names it less often as a source.

Readers then recall the brand less, and direct visits fall. They call that the likely primary channel and lost citation referrals the possible secondary one.

The grounds are that AI referral traffic was small in the period measured. The pattern fits.

Before May 2024 the decline sits in direct visits while organic search referrals stay broadly stable.

The checks against coincidence are very thorough for a working paper. Pre-blocking coefficients are indistinguishable from zero.

Synthetic DiD and two-way fixed effects both return negative estimates. Three separate placebo designs centre near zero.

Of 24 blocking publishers, 19 made no other robots.txt change at the same time.

Now the two limits that decide how far this figure travels.

The window runs from November 2022 to May 2024, and stops there on purpose. Google launched AI Overviews that month.

The authors treat it as a separate event that would otherwise contaminate the estimate.

So this measures the 2023 blocking wave against pre-AI-Overviews traffic. It is not a measurement of AI Overviews, and it is not a measurement of 2026 conditions.

And it is a finding about blocking in aggregate, not about any one token. The blocks it counts cover GPTBot and ChatGPT-User, ClaudeBot and Claude-User, PerplexityBot, Google-Extended and ByteSpider among others.

So the study cannot say what disallowing ClaudeBot alone costs a site.

One more thing belongs on the number itself. An earlier version of this paper, published on 31st Dec 2025, reported a 23% decline in monthly visits.

PPC Land's coverage of the revision attributes the change to the shift from monthly to weekly measurement. It also credits updated methods, and Semrush was added as a third dataset.

The 23% figure circulated for four months. The 7% figure is the one the current version supports.

Two other findings sit alongside the blocking result, and both cut against the expected story. Publishers did not scale up text output.

Measured against the top 100 retail domains, article and section tags fell 31.2%. Interactive elements rose 68.1%.

Layout components rose 70.2% and advertising technologies about 50%.

The paper is careful to add that it does not find publishers' multimedia elements growing faster than retail's. So the shift it documents is toward interaction and monetization rather than video.

And newsroom hiring did not contract. The share of new editorial and content-production job postings held or rose after November 2022.

That is the opposite of what a cost-cutting response to generative AI would look like.

ProductClaude for Chrome reaches every paid plan

Anthropic's Claude for Chrome page carries the arc in its own update notes.

A pilot limited to 1,000 Max plan users began on 25th Aug 2025. All Max subscribers joined from 24th Nov.

Then came "Update: Now available to Pro, Team, and Enterprise plans (Dec 18, 2025)", alongside "After months of real-world testing, we're ready to expand to all paid plans".

The extension lets Claude act in the browser: navigating, filling and completing tasks across tabs. Scheduled tasks and multi-tab workflows were added during the beta.

The safety disclosure is unusually concrete. Anthropic published adversarial results: "Browser use without our safety mitigations showed a 23.6% attack success rate when deliberately targeted by malicious actors."

With autonomous-mode mitigations that fell to 11.2%. A browser-specific set of four attack types went from 35.7% to zero.

Claude for Chrome outlived the standalone AI browsers. OpenAI's Atlas shut down in August 2026 and Microsoft retired Edge's Copilot Mode in May.

Both refocused on exactly this extension-plus-app shape.

Archive: 4 older entries
Study

Cloudflare's crawl-to-refer series: Anthropic crawls tens of thousands of pages per referral

Cloudflare's method comes from its first report. It counts HTML requests from a platform's crawlers.

It divides them by HTML requests arriving with that platform's hostname as the referrer. The result is normalized to one referral.

Anthropic's ratios were the series' extreme. Late June 2025 measured roughly 71,000:1.

July read 38,065.7:1, down 86.7% from January's 286,930:1. The first week of August read roughly 50,000:1.

The July comparison set: OpenAI 1,091.4:1, Perplexity 194.8:1, Google 5.4:1, Microsoft 40.7:1.

For publishers, the August report's sector cut is the relevant row. In news and publications, Anthropic crawled about 2,500 pages per referral, OpenAI 152 and Perplexity 32.7.

Cloudflare also split crawling by purpose in the July data. About 80% was training, 17% search and 3.2% user actions.

One stated limitation keeps the Anthropic figure in proportion. Traffic referred by Claude's native app carries no referrer header.

So its ratio is overstated by an unknown amount.

A dating note: newer 2026 ratios circulate on SEO sites without any Cloudflare publication behind them. So this page carries the 2025 series until Cloudflare publishes again.

Availability

Claude web search goes global on every plan

The gate fell without an announcement, in an update note on the launch post: "Update: Web search is now available globally on all Claude plans. (May 27, 2025)".

That completed a two-month rollout that had started US-only for paid users in March. Web answers with citations became a default Claude capability rather than a feature-preview extra.

For site owners the date marks when Claude traffic became possible at global scale. The measured volumes stayed tiny well into 2026.

Data

Claude's search backend identified as Brave, by three independent signals

Anthropic never announced what powers Claude's web search. The answer came from three directions within days of launch.

Anthropic added Brave Search to its subprocessor list on 19th Mar 2025. Simon Willison then observed that Claude's ten citations for a test query "were an exact match for that search on Brave".

He also found that Claude's search function exposes a parameter named BraveSearchParams.

Profound quantified it: "Claude leverages Brave Search as its primary search backend, confirmed by a statistically significant overlap of 86.7% (13 out of 15 total results) between Claude's cited results and Brave Browser's top non-sponsored results."

Their contrast figure: ChatGPT-to-Bing alignment of only 26.7%.

Handle the number with its method. The overlap is 13 of 15 results across three test queries, on one day in March 2025.

It is directional evidence about the then-current integration. Anthropic never confirmed it beyond the subprocessor listing, and we know of no newer measurement.

If it still holds, the SEO consequence is unusual and testable. Ranking in Brave's organic results would be the upstream lever for Claude citations.

Product

Claude gets web search, with direct citations

The launch post set the scope plainly: "Web search is available now in feature preview for all paid Claude users in the United States. Support for users on our free plan and more countries is coming soon."

The citation promise is the part site owners care about: "When Claude incorporates information from the web into its responses, it provides direct citations so you can easily fact check sources."

The launch model was Claude 3.7 Sonnet. Within a week the backend had been identified as Brave Search.

By late May the feature was global on every plan.

Anthropic's three crawlers, and what blocking each one does

Anthropic is the only AI search operator claiming robots.txt compliance for its user-triggered fetcher.

Anthropic documents three bots. Its compliance claim is the strongest of any operator on this beat: "Anthropic's Bots respect "do not crawl" signals by honoring industry standard directives in robots.txt."

That claim covers all three, including the user-triggered fetcher. OpenAI and Perplexity both document that robots.txt may not or does not apply to theirs.

CrawlerWhat it does, per AnthropicWhat blocking it means
ClaudeBotCollects web content "that could potentially contribute to their training" of generative modelsExcludes future materials from training datasets; the training opt-out
Claude-UserFetches a site when an individual asks Claude about itBlocks retrieval for user queries; Anthropic warns it "may reduce your site's visibility for user-directed web search"
Claude-SearchBot"Navigates the web to improve search result quality for users"Prevents indexing that feeds Claude's search relevance

The same help page gives operational details. Anthropic says its bots respect anti-circumvention technologies rather than bypassing CAPTCHAs.

It supports the non-standard Crawl-delay robots extension. It also warns that IP-based blocking "may not work correctly" because the bots run from cloud IPs.

Anthropic does not publish full user-agent strings on that page. The tokens above are the robots.txt names.

These are the operator's claims about itself. The independent counterweight lives in the measurement section.

TollBit's network found 30% of AI bot scrapes in Q4 2025 bypassed explicit robots.txt permissions. That is an industry-wide figure, and it is why serious enforcement pairs robots.txt with firewall rules.

Anthropic's help page carries no revision date. So this table is dated to our fetch of it on 13th Aug 2026.

The measurement layer: what AI surfaces cost and send

The cross-surface studies that quantify AI crawling and referrals, each labeled with what it counts and when.

Nobody announces this data. Infrastructure companies, analytics vendors and academics measure it.

It is the closest thing the AI-search beat has to a shared reality. Every row names what it counts, because these figures are routinely misquoted with the wrong object.

FindingWhat it countsSource and date
Blocking GenAI crawlers cost about 7% of weekly visits within six weeks (SimilarWeb -0.074, Semrush -0.069, Comscore -0.065 and imprecise); concentrated in the top 50 publishersTotal weekly visits TO publisher domains after a robots.txt block, staggered DiD against non-blockers; November 2022 to May 2024, so before AI OverviewsZhao and Berman, working paper, 15th Apr 2026
+386% Claude referral growth Jan to Apr 2026 (0.0029% to 0.0141% of panel traffic); all AI platforms combined 0.33%Referral visits arriving FROM AI platforms, 101,574-site Google Analytics panelSE Ranking, 3rd Jun 2026
Claude ~9% of generative-AI web traffic (from ~2%); ChatGPT ~53% (from ~76%); category 9.5B monthly visits, +70% YoYVisits TO the AI platforms themselves, worldwide panelSimilarweb, updated 29th Jul 2026
Anthropic crawl-to-refer 38,065.7:1 (Jul 2025); OpenAI 1,091.4:1; Perplexity 194.8:1; Google 5.4:1; news-sector cut 2,500:1 / 152:1 / 32.7:1Crawler HTML requests per one referred HTML visit, Cloudflare network; Claude app referrals carry no referrer, overstating AnthropicCloudflare, Jul and Aug 2025 reports
AI crawling by purpose: ~80% training, ~17% search, 3.2% user actionsShare of AI bot requests by operator-declared purposeCloudflare, 29th Aug 2025
1 AI bot visit per 31 human visits (Q4 2025, from 1 in 50 in Q2); robots.txt bypass 3.3% (Q4 2024) to ~13% (Q1 2025) to 30% (Q4 2025), worst agent ChatGPT-User at 42%; citation CTR 0.8% to 0.27%Bot visits, bypass share and citation click-through across TollBit's publisher networkTollBit State of the Bots via Digiday, 11th Feb 2026
17.7B AI agent requests in Q2 2026, +45% QoQ; Meta's agents now the majority of AI agent traffic; ChatGPT commands roughly 80 to 88% of AI referralsAI agent HTTP requests across DataDome's customer network; referral share is a separate measure in the same reportDataDome via the wire release, 16th Jul 2026
Only 12% of links cited by ChatGPT, Gemini and Copilot rank in Google's top 10 for the same prompt; Perplexity highest at 28.6%Cited URLs checked against Google's top 10, 15,000 long-tail queries, Ahrefs indexAhrefs, 11th Aug 2025
ChatGPT cites ~15 sources per response vs Gemini's ~3; 126M+ US prompts analyzedAverage cited sources per response, four platforms, Jan to Apr 2026 windowSemrush AI Visibility Index press release, 26th Jun 2026

A note on vintages: newer versions of several series here sit behind walls we could not read.

TollBit's 2026 edition is demo-gated, and Cloudflare's live Radar page renders client-side only.

The 2026 crawl-ratio numbers circulating on SEO blogs have no verifiable publication behind them. This table advances only when a primary does.

What Claude means for your site today

Tiny referrals, real crawl cost, clean controls, and one testable lever nobody else has.

In short: Claude sends very little traffic, 1.40% of an already-small AI referral pie. It costs real crawl budget, with the worst measured crawl-to-refer ratio of any operator.

And it offers cleaner controls than its rivals: three robots-honoring crawlers with separable purposes.

The control decisions map cleanly. Allow Claude-SearchBot and Claude-User if you want a place in Claude's answers.

Their opt-outs cost you retrieval and search presence. Decide ClaudeBot separately, because it is the training crawler.

The settlement just priced what training data is worth.

The distinctive lever is the Brave backend. If the March 2025 finding still holds, Claude citations follow Brave's organic rankings.

That makes Brave Search Webmaster-style hygiene a testable input, in a way no other AI surface offers.

The nearest thing to a controlled test of what earns a citation is the SIGIR paper below. It found four gatekeepers holding across all six models it tested, Claude among them.

It also found formatting changes doing nothing at all. Take it as direction rather than as a measurement of Claude.

It never called a search engine. And it anonymized exactly the brand and domain reputation a live system may still weigh.

Beyond that, our guidance matches the rest of this section. Citable, specific pages earn AI mentions everywhere, and expect referral volume to stay low.

Any tool promising "Claude optimization" is selling ahead of the evidence.

Frequently asked questions

Does Claude search the web?

Yes. Web search launched in March 2025 as a US paid preview.

It has run globally on every Claude plan, free included, since 27th May 2025. When Claude uses the web it shows direct citations, which Anthropic promised at launch.

What search engine does Claude use?

Brave Search, per three independent signals from March 2025. Anthropic listed Brave as a subprocessor, and Simon Willison found Claude's citations exactly matching Brave results.

Profound measured 86.7% overlap with Brave's top organic results.

Anthropic has never confirmed it publicly, and the measurements date to launch. So we treat it as the identified backend as of those probes.

How do I block, or allow, Claude's crawlers?

Anthropic runs three robots.txt tokens with separable jobs. ClaudeBot handles model training and Claude-SearchBot handles search indexing.

Claude-User fetches a page when a user asks about your site.

Anthropic says all three honor robots.txt, uniquely including the user-triggered one. It supports Crawl-delay, and warns IP blocking may misfire because the bots use cloud IPs.

How much traffic does Claude actually send?

Very little, growing very fast. In SE Ranking's 101,574-site panel, Claude referrals grew 386% between January and April 2026.

They still reached only 0.0141% of total traffic, 1.40% of AI-referred visits. ChatGPT accounts for around four-fifths of AI referrals in every panel we track.

What was the Anthropic authors settlement?

A $1.5 billion class settlement over pirated books used in training, approved 20th Jul 2026. It pays about $3,000 per work across an estimated 500,000 works.

The court had ruled training itself fair use while the pirated copies were not. Because Anthropic settled, no appellate precedent was set.

What is Claude for Chrome?

Anthropic's browser agent: a Chrome extension where Claude navigates and completes tasks across tabs. It ran as a 1,000-user pilot from August 2025.

It has been on every paid plan since 18th Dec 2025. Anthropic published its adversarial safety numbers, 23.6% attack success without mitigations falling to 11.2% with them.

Is Claude big enough to matter for SEO?

As a referrer, not yet: its measured share is tiny. As a crawler, yes today.

Cloudflare measured Anthropic at the highest crawl-to-refer ratio of any AI operator. That is thousands of pages crawled per referral in the news sector.

The control decision therefore matters now. The traffic case is a bet on the growth curve.

Spotted a change we have not covered? Ranking volatility, a new SERP test, a platform change: email us a tip and we will credit you if we cover it.
Cite this page: Keywords Everywhere, "Claude Updates: Web Search, Crawlers and Anthropic News", last updated 31st Aug 2026, https://keywordseverywhere.com/news/claude-updates/