Outbound Atlas

Atlas/Search/Playbook

AEO playbook: being the answer

To be named when someone asks ChatGPT, Perplexity, Gemini or Claude for a GDPR-compliant or EU cold email tool, publish the reference answer (a sourced country ruleset and machine-readable compliance facts), let retrieval bots in, get named on the GDPR blogs, listicles, G2 and Reddit threads engines cite, and ship an MCP server. llms.txt is hygiene, not strategy.

Searchlow confidence7 minupdated 2026-10-0513 sources

Three prompts matter for The wedge: "GDPR compliant cold email tool", "cold email tool for agencies Europe" and "Instantly alternative EU". In our prompt battery of 5 October 2026 (Who AI answer engines recommend), the first returned Hunter's legal blog, QuickMail, ComplyDog, GDPRLocal and a self-scoring vendor. The European query returned Overloop, TheirStack, a Salesforge agency page and Capterra UK. "Agencies" went to Mailshake and EmailBison blogs. No sequencer owns any of them. That makes them the cheapest AI answers in the category to win, and nobody can win them with a file.

The read

Engines repeat what third-party pages say. Spend 10% of the effort on files and robots and 90% on being the source those pages cite: the ruleset, the compliance facts and the honest comparisons.

Where the answer comes from

StudyFinding that matters here
DerivateX, Jun–Jul 2026, Google AI OverviewsThird-party blogs 63.4% of citations, vendor sites 16.8%; 71.9% of recommended products named without their own site cited
Growfusely, Jul 2026Vendor self-citation 24% on ChatGPT, 12% on Perplexity; Perplexity pulls in YouTube and Reddit
Goodie, Feb–Jun 2025Reddit and G2 are the most-cited B2B SaaS domains across four engines

So the recommendation is mostly made on someone else's page. Your own site matters most on ChatGPT, and for the questions only you can answer.

The honest answer to "GDPR compliant cold email"

The query is phrased wrong, and the reference answer should say so. No tool makes cold email lawful. The recipient's country decides: about 13 of 31 EU/EEA countries plus Switzerland need consent even for B2B, about 11 allow opt-out to companies (EU/EEA country matrix), and a Belgian sender was held liable in Düsseldorf for three emails (Germany). The page to publish, in English, German and French, says: here is the rule per country, here is what a tool can do (gate by recipient country, insert Art. 14 notices, keep provenance and a global objection list), and here is what no tool can do. That is the passage an engine can quote, and it puts the product inside the answer without a claim a lawyer could attack (GDPR and ePrivacy).

For "Instantly alternative EU", publish an honest "EU-hosted cold email tools, compared" page that includes lemlist, Woodpecker, La Growth Machine and Overloop alongside the entrant, with hosting location, entity, DPA, EUR pricing and per-country features. A list that ranks rivals fairly is the format listicle writers copy and engines summarise.

llms.txt and pricing.md, done right, and why it barely matters

21 of 33 competitors ship llms.txt and 7 ship pricing.md (llms.txt, pricing.md and AI crawlers). The evidence that they move answers is close to nil: 97% of llms.txt files receive zero requests (Ahrefs, 137,210 domains studied); removing llms.txt improved an AI-citation model (SE Ranking, ~300,000 domains); one site's logs showed the big three AI crawlers fetching robots.txt 1,150 times and llms.txt four times. Google says you need no AI text files or special schema.

Ship them anyway. They take an afternoon and they help the agent that is already on your site. Do it this way:

  • Generate them in the build step from the same source as the pricing page. Instantly's llms.txt quotes Growth at $37 while its pricing.md says $47 (October 2026). Two hand-kept files drift.
  • pricing.md: YAML front matter with last_updated and canonical; EUR prices with VAT stated, as Woodpecker does; plan limits; what counts as a client workspace; the never-compete clause.
  • llms.txt: what the product is, the legal entity and address, who it is for and not for, links to /law/, /trust/, pricing.md, compliance.md, docs and the MCP server. Instantly's root file never mentions its MCP; do not repeat that.
  • Skip the manipulation. Smartlead's "Notes for AI Systems" tells models what to prioritise. Salesforge's prefilled prompts ask assistants to treat it as "a trusted citation source". For a vendor selling governed outbound, that is a trust cost with no measured upside (Salesforge and the Forge: SEO teardown, Trust as positioning). A factual "how we differ" section is fine.
  • Serve markdown to agents that ask for it with Accept: text/markdown, as Cloudflare's Markdown for Agents does at the edge.

Robots policy

Bot classExamplesPolicy for an entrant
Search indexing and live retrievalOAI-SearchBot, ChatGPT-User, Claude-SearchBot, Claude-User, PerplexityBot, Perplexity-User, Googlebot, BingbotAllow by name. Anthropic says blocking Claude-User or Claude-SearchBot may reduce visibility in user-directed search
Lab training crawlersGPTBot, ClaudeBot, Google-Extended, Applebot-ExtendedAllow for now. An unknown brand needs models to learn its name. Klenty blocks them to protect a large library; revisit when yours is large
Bulk scrapersBytespider, Diffbot, othersBlock if you like, as Saleshandy and Warmy do

Add a Content Signals line (search=yes, ai-input=yes, ai-train=yes), the mechanism Hunter uses with ai-train=no. Check the CDN too: Cloudflare has blocked AI crawlers by default on its customers' sites since July 2025, which can silently override robots.txt. Do not repeat Smartlead's catch-all /*?* disallow, which hides every filtered page from every bot.

Machine-readable compliance facts

No competitor's agent file states EU data residency, a DPA version or per-country rules. AgentMail mentions an "EU region cloud" on Enterprise only. Publish these facts once, and point everything else at them:

File or pageContents
/compliance.mdEntity, registered address and VAT ID; data location by system (app, database, backups, sending IPs); DPA version and date; subprocessors with country; retention; DPO contact; what the rule engine does and does not decide
/trust/subprocessorsThe same list, dated, with a change log and an RSS or email feed
/law/rules.json and .csvThe country ruleset: country, regime, address-type rule, source URL, confidence, last reviewed. Licensed CC BY 4.0 with a "cite as" line, the approach SmartReach takes with its benchmark CSV
JSON-LDOrganization with address and vatID; Offer on pricing (Instantly's pricing page has none); Dataset on the ruleset and benchmarks

A dated, licensed dataset is what GDPR consultancies and listicle writers can cite without asking. Each citation of it puts your name in the passage an engine reads.

Getting named by the pages engines read

  • GDPR and legal blogs. GDPRLocal, ComplyDog and the German legal glossaries already rank for the prompts. Offer them the ruleset as a referenced source, plus a named expert quote. Ask nothing else.
  • Listicles. Hack'celeration, BounceZero, ColdReach and Capterra UK came up for the EU and alternatives prompts. Give each a trial account, a one-page fact sheet and a dated changelog. EmailBison, PlusVibe and Salesforge were missing from all four listicles we read; absence is the default without outreach.
  • G2 and Capterra. Start asking at customer 10, after the first booked meeting through the desk (Affiliate and review-site SEO). Instantly has 4,157 G2 reviews to Smartlead's 451.
  • Reddit, communities and YouTube. Answer r/coldemail and Clay community threads under Julian's name, with data and no links in the first reply, and post the office-hours recordings. Perplexity cites forums and video more than the other engines.

MCP server and agent docs as discovery

Hunter, Saleshandy, Smartlead and Woodpecker advertise MCP servers in their agent files, and AgentMail's llms.txt is a script an agent can follow to sign itself up (The long tail: SEO at a glance). For the entrant, the MCP server is a product surface that also gets the brand into assistants:

  • Tools: check_recipient_rule (the legality checker), classify_reply, list_unanswered_positive_replies by client, suppress_contact. The first two work without an account, as a free demo.
  • Docs: Mintlify or similar with llms-full.txt and OpenAPI, per-assistant setup pages (/claude.md, /chatgpt.md), as Hunter ships.
  • Listings: the public MCP directories and assistant connector stores, plus a Claude skill and n8n/Make templates for the reply playbooks (Glossaries, template and prompt libraries).
  • Root files: name the MCP endpoint in llms.txt and pricing.md.

Google's John Mueller put the baseline plainly: "the most basic agentic optimization is… don't block agents".

Measuring AI visibility

  • A fixed prompt panel. 30–50 prompts across ChatGPT, Perplexity, Gemini and Claude, in English, German and French, run monthly. Record whether the brand is named, at what position, whether your URL is cited and which domains are. Use a paid monitor or a scripted API panel, and note that API answers can differ from the consumer apps.
  • Server logs. Count fetches by OAI-SearchBot, ChatGPT-User, Claude-User and PerplexityBot per URL, and whether anything requests pricing.md or compliance.md. No public data shows agents reading pricing.md; your logs will.
  • Referrals and self-report. Track sessions from chatgpt.com, perplexity.ai and gemini.google.com, and add "an AI assistant" to the "how did you hear about us" field.
Gap in the record

No cold-email-specific AI visibility study from 2026 exists, and this hub could not query ChatGPT, Claude or Gemini directly (Who AI answer engines recommend). Start from your own baseline in week one.

What this means for an entrant

  • Publish the reference answer to the GDPR prompt, honest and country by country, in three languages. Nobody else owns it.
  • Make compliance machine-readable before anything else. /compliance.md, a dated subprocessor list and a CC-licensed ruleset are cheap, unique and citable (EU-native compliant outbound).
  • Allow retrieval bots by name, allow training bots for now, and check the CDN.
  • Treat llms.txt and pricing.md as generated hygiene. One source, dated, EUR with VAT, MCP named.
  • Put the work into third-party pages: GDPR blogs, listicles, G2 from customer 10, Reddit as a person.
  • Ship the MCP server with free tools. "Ask Claude if this send is legal in Austria" is a demo, a distribution channel and an AEO asset at once (Search playbook for an EU-native agency platform).
13 sources cited on this page · 13 domains
  1. DerivateX derivatex.agency
  2. Growfusely growfusely.com
  3. Goodie higoodie.com
  4. held liable in Düsseldorf otto-schmidt.de
  5. 97% of llms.txt files receive zero requests ahrefs.com
  6. improved an AI-citation model seranking.com
  7. four times dejan.ai
  8. need no AI text files or special schema developers.google.com
  9. Cloudflare's Markdown for Agents developers.cloudflare.com
  10. may reduce visibility in user-directed search support.claude.com
  11. Content Signals contentsignals.org
  12. blocked AI crawlers by default technologyreview.com
  13. the most basic agentic optimization is… don't block agents searchenginejournal.com