Time Sold Ads to AI Agents. Perplexity Blocked Them in Two Weeks.
Can publishers serve ads to AI agents? Time started placing sponsored FAQ blocks inside the markdown pages AI crawlers read, and Perplexity blocked all of them in under two weeks. The fight defines what an agent is allowed to see.

Time Sold Ads to AI Agents. Perplexity Blocked Them in Two Weeks.
Publishers can serve ads to AI agents, and at least one AI engine has already decided it will not read them. Time began placing sponsored FAQ blocks inside the markdown versions of its articles, the stripped-down text files AI crawlers prefer. Less than two weeks later, Perplexity blocked every markdown ad on Time.com from influencing its index and called the practice deceptive.
Key takeaways
- Time is selling ad units that no human will see. Sponsored FAQ blocks are placed inside markdown page versions built for AI crawlers, per Digiday. Ally Bank and the Project Management Institute bought first.
- Perplexity blocked them inside two weeks. Its chief communications officer warned that publishers running "deceptive advertising like markdown ads" risk a reputation downgrade and lower trust scores in Perplexity's index, Digiday reported.
- The economics are real. Time says it sees more bot traffic than human traffic on most days. Cloudflare Radar measured automated traffic at 57.5% of HTTP requests for web content in June 2026, against 42.5% human, the first crossover it has recorded and one it had forecast for the end of 2027.
- No rulebook covers this. Google's spam policies define cloaking as showing different content to users and search engines, with no clause addressing AI crawlers or generative systems.
- About 15% of brands already run their own markdown pages, according to Mobian, the ad tech firm building the units. Those brands face the same question without a publisher in the middle.
What is a markdown ad?
A markdown ad is sponsored content placed in the plain-text version of a webpage that AI crawlers read, rather than in the HTML version a person sees. Mobian generates the unit as an FAQ from a brand brief, exports it to PDF for client approval, and inserts it into the markdown file. It carries a sponsored label. Time can target it by article franchise or date range, and Mobian then puts the same FAQ questions to AI engines and tracks visibility, favorability, and accuracy over time.
The format choice is not incidental. An FAQ is the shape an engine most readily lifts into an answer, which is why it is also the shape most AEO guidance recommends. Being quoted is the whole product.
Takeaway: The unit is built to be retrieved rather than viewed, which is why the usual disclosure conventions do not fit it.
Why did Perplexity call it deceptive?
Because the reader of the ad is a machine that is expected to relay what it reads as fact. Perplexity's position is that a sponsored block sitting inside a source document risks being paraphrased into an answer without the sponsorship traveling with it. The label protects a human who sees the page. It does not reliably protect a user who only ever sees a synthesized paragraph three steps downstream.
Perplexity's response also went further than blocking a single unit. Its stated consequence is a trust penalty at the domain level, which means the cost of the experiment is not the lost ad revenue but the standing of every other article on the site. That is a meaningful escalation, and it is the first time an AI engine has publicly priced editorial behavior into source selection.
The moment a page has two versions, somebody has to decide which one is true.
Takeaway: The penalty lands on the domain rather than the ad unit, so the downside is carried by every page on the site.
Is this cloaking?
Under the existing definition, not quite, and that gap is the whole story. Google defines cloaking as "presenting different content to users and search engines with the intent to manipulate search rankings and mislead users." A markdown page is a legitimate alternate representation, published deliberately, of the same article. Serving it to a crawler is closer to serving AMP or a print stylesheet than to keyword stuffing a user agent.
The trouble starts when the two versions stop matching. A markdown file that carries a paid FAQ the HTML page does not carry is no longer an alternate representation. It is a different document with a commercial insert, addressed to the reader least equipped to notice. Google's spam policies do not mention AI crawlers, Google-Extended, or generative systems anywhere. There is no published rule to break, which is exactly why the first enforcement action came from an engine's trust score rather than from a policy.
Anyone who worked in display through the 2010s has seen this sequence. A new inventory type appears, it works because nobody has defined it, the definitions arrive later, and the definitions are written by whoever got hurt. We documented an earlier version of this pattern in black hat AI search, where the manipulation was cruder and the response slower.
Takeaway: The rules that would govern this do not exist yet, which is why enforcement is arriving as trust scoring instead.
Why publishers are doing it anyway
Mark Howard, Time's COO, framed agent traffic as inventory: a growing traffic source and therefore a growing source of inventory. He is not wrong about the volume. Time sees more bots than humans on most days, and in June 2026 Cloudflare Radar measured automated traffic at 57.5% of HTTP requests for web content against 42.5% human, a crossover it had expected to take until the end of 2027. That figure covers crawlable web content and excludes video streaming, email and gaming.
Jonah Goodhart, Mobian's CEO, put the strategic case more bluntly: it may be more important to influence the agent than the human, because influencing a human reaches one person while influencing an agent reaches everyone that agent answers. That is the correct read of the leverage, and it is also precisely why engines will fight it. Leverage that concentrated is the thing a retrieval system exists to protect.
Takeaway: If your audience is now mostly machines, selling only to the humans is selling into a shrinking half of the room.
What brands should do with this
Three things, in order of how quickly they matter.
First, check whether you already publish a markdown or llms.txt version of your own site. Roughly 15% of brands do, per Mobian, and many of those files were generated once and never audited. A machine-readable version of your site that has drifted from the human one is a liability whether or not anyone sold an ad in it.
Second, decide your own rule before a platform decides it for you. The workable standard is parity: the agent-readable version may be restructured, but it should not contain a commercial claim the human version does not. That is a governance decision, not a marketing one, and it belongs in the same place as your crawler policy. Our AI crawler cheat sheet covers which bots to allow before you decide what to feed them.
Third, treat paid agent placement as unproven rather than unavailable. One engine has already blocked it and applied a domain penalty. Buying the unit means accepting a trust risk on a publisher you do not control, priced by a platform that has not published its criteria.
Takeaway: Parity between your human and machine-readable pages is the rule to adopt now, before one gets written for you.
FAQ
Q: Can publishers serve ads to AI agents? A: Technically yes. Time places sponsored FAQ blocks in the markdown versions of its articles, sold through Mobian, with Ally Bank and the Project Management Institute as launch advertisers. Whether the ads reach an answer is a separate question, because Perplexity has blocked Time's markdown ads from influencing its index, so the inventory exists but delivery is not guaranteed.
Q: What is a markdown page and why do AI crawlers use it? A: A markdown page is a plain-text version of a webpage without navigation, scripts, or styling. AI crawlers favor it because it parses cleanly into the chunks a model retrieves from, with no layout to interpret. Publishing one is a normal technical practice and not manipulation in itself.
Q: Is serving different content to AI agents against the rules? A: There is no rule that names it. Google's spam policies define cloaking around users and search engines and say nothing about AI crawlers or generative systems. Enforcement so far has come from engines directly, through trust scoring and blocking, rather than from published policy.
Q: What happens to a site that gets flagged by Perplexity? A: Perplexity's stated consequence is a reputation downgrade and reduced trust score within its index, applied at the publisher level. That means the penalty affects a domain's ability to be cited generally, not only the pages carrying the ads.
Q: Should brands buy agent ads right now? A: Not as a standalone line item. One engine has already blocked the inventory and applied a penalty at the domain level, and none has published criteria for what it will accept. That is an unpriced risk sitting on a publisher you do not control. Revisit once at least two major engines state a policy.
Where this lands
The interesting part is not that a publisher sold an ad to a robot. It is that an AI engine responded by threatening a publisher's standing rather than by filtering a unit. That is a platform behaving like a gatekeeper, deciding not just what to show but whom to believe, with no policy document and no appeal.
Publishers are about to spend a year discovering how that gate works by hitting it. Brands get to watch. The useful position is the boring one: keep the machine-readable version of your site honest, know what every engine currently says about you, and let somebody else fund the enforcement precedent.
Book a meeting if you want to see what the engines currently say about your brand, or start with our research reports.


