The part of AI visibility an institution controls outright is the part it already scores best on. The part decided by everyone else is where the gap sits, and no amount of CMS work closes it.
Most of the marketing teams we talk with have already done the obvious work. Schema markup, clean headings, faster page loads, an FAQ block that answers the questions members actually ask. That work matters, and our data confirms it pays off: technical health is the highest-scoring category in our benchmark. But a well-built website is table stakes, not the finish line, and treating it as the finish line is where the AI visibility plan usually stalls.
What a website cannot do by itself
An AI system answering “which credit union has the best auto loan rates in Ohio” is not only reading your homepage. It is synthesizing your site alongside review platforms, comparison content, forum threads, local press coverage, and other institutions' pages that happen to mention you. None of that lives on your domain, and none of it responds to a CMS update. Our audit's reputation category is the piece of the methodology built to capture the residue of that outside conversation, wherever the crawl can find a trace of it, and it averages 58 across the full dataset. That is a full six points behind technical health, and it is the category most marketing teams have the least direct lever over.
The speed problem is real, and it is not about your website either
The Notified finding is worth sitting with. Average time to first AI citation across 8,000 press releases: 8 hours, with most landing within 24. A press release is about as off-site as content gets, syndicated the moment it is filed, structured by the newswire rather than your web team. That speed is exactly why our own quarterly audit cadence recommendation exists: a static site update might take a content sprint to plan and a crawl cycle to register, while a wire-distributed announcement about a new rate or product can enter an AI answer same-day. If a competitor is faster to file, they can be faster to get cited, regardless of whose site has better structure.
There is a second study worth naming here for framing, not for adoption. Semrush's expanded 2026 AI Visibility Index, drawn from 126 million U.S. AI search prompts (Semrush, June 26, 2026), found 81% of organizations that fully integrate SEO and AI visibility work saw increased AI-driven traffic or leads, against 36% managing the two separately. Semrush is owned by Adobe and sells exactly the kind of integrated tooling that stat favors, so read the number with that in mind. It still lines up with what we see: institutions that treat on-site structure and off-site reputation as one coordinated project outscore the ones fixing either in isolation.
Your attribution report is probably missing this entirely
Here is the part that should worry a board more than the scores themselves. According to Previsible's July 6, 2026 AI traffic report, based on 6.77 million LLM-driven sessions across 166 GA4 properties over 19 months, ChatGPT alone now accounts for 92.4% of standalone AI referral traffic, up from 84% in December 2025. Most analytics setups still file that traffic under direct, because the referring assistant does not pass a standard referrer string. So a member who found you through an AI answer, built partly from off-site reputation signals your marketing team does not own, shows up in the dashboard looking like someone who typed your URL from memory. If your reporting cannot see the channel, you cannot tell your board whether the off-site work is working.
What to actually check this quarter
A useful audit does not stop at the homepage. It should tell you, category by category, where you stand against a real benchmark rather than against your own history, and it should be honest about which of those categories your marketing team can fix alone and which need outside distribution, press relationships, or review-platform presence to move. In our benchmark, technical health (64) and SEO (53) are levers your web team can pull directly. Reputation (58) and, to a lesser extent, GEO-specific structure (58) usually require work that happens off your domain, in newsrooms, review platforms, and the broader conversation about your institution.
If your team's current plan is “update the website and check back next quarter,” that plan addresses roughly half the problem this data describes. Kevin Farley wrote the practitioner-side version of this same discipline this week, on how to stress-test any AI search stat before it goes in a deck, including his own dataset's confidence breakdown.
Get your snapshot
If you want to see where your institution lands across all five categories, including the off-site half most audits skip, start a conversation with our team. We will show you the benchmark comparison and rank the fixes by which ones you can make alone versus which ones need a broader push.
