Skip to the book

NOMOS GBO · Chapter 1

Being Found Was Only the Beginning

The internet’s first great promise was access. Finding a company, a person, a product or a piece of information would no longer require a printed directory, intermediaries or a lengthy search. We would type a few words, choose a link and reach what we were looking for. This change did more than make information accessible. It turned visibility into economic power. If a business did not appear in search results, it effectively did not exist for many people, even if it had a digital presence. A good product, a reliable service or deep expertise was not enough. People had to be able to find it.

SEO grew out of that need.

Titles, links, page structures, technical accessibility and content were developed so that search engines could discover web pages, understand them and match them to relevant queries. Businesses quite reasonably asked: ‘When people search for us, will we appear?’ That question still matters. But it is no longer enough, because the way the internet works has changed. People once chose from the links a search engine presented. Today, an AI system can read those links, summarise their contents, compare the options and make a recommendation on the user’s behalf.

An agent with access to suitable tools can go beyond making recommendations.

It can request a quotation from a company. Order a product. Book a hotel. Arrange an interview with a candidate. Shortlist a supplier. Change a file. Send a message. Start a contracting process.

At this point, visibility becomes something else. The issue is no longer simply whether a machine can find you. It is what the machine will understand about you once it does, under what conditions it will choose you, and what actions it will take in relation to you. This is precisely where this book begins.

Four different events

A system finding you, understanding you, choosing you and transacting with you are not the same event.

They are four distinct thresholds:

Discoverability Understandability Suitability Actionability

The first threshold concerns whether your page or entity can be discovered. The second concerns whether the system correctly understands who you are and what you do. The third concerns whether you are genuinely suitable for a particular person’s needs. The fourth concerns whether an action involving you can be performed safely and with authority, and whether the limits of stopping, reversal and remedy are understood if something goes wrong. These four thresholds are connected, but none substitutes for another. A company can rank first in a search engine and still be unsuitable for the user’s needs.

An AI system may correctly understand what a company does without knowing its prices, capacity or service boundaries. A service may suit the user’s needs while the system has no authority to request a quotation, make a payment or share personal data. A transaction may be technically possible but impossible to reverse if it goes wrong. High visibility is therefore no guarantee of sound behaviour. An agent finding an entity is only the beginning.

The search era’s unseen safeguard: the human

The traditional internet had an important safety layer. It often went unnoticed because it was not part of the technical system. That layer was the human. A user looking at several links in search results did not have to act immediately. They could open the pages, compare companies, read reviews, ask a friend, telephone for information or do nothing if they had doubts. The human was more than a hand that clicked.

The human was also a decision-making layer, able to:

  • notice uncertainty,
  • weigh conflicting information,
  • question extravagant promises,
  • keep their budget in mind,
  • assess the risk,
  • defer a decision,
  • and ask another question.

If a website advertised ‘24-hour support’ while the contract covered only weekday business hours, a person could spot the discrepancy and ask for an explanation. A hotel’s photographs might look impressive, but if there was no information about disabled access, the user could call before booking. If a software company promised ‘unlimited integrations’ without naming the systems it worked with, a prospective customer could question that claim. People used everyday judgement to correct the internet’s incomplete or overambitious representations.

As agent-based systems take over parts of this decision chain, that unseen safeguard may disappear as a consequence. An agent can search the sources it can access and compare many options. Its speed and reach depend on the model, tools, data and task. But speed does not replace judgement. An agent’s ability to read a thousand pages does not mean it notices what is missing. Finding a price does not establish that the price includes every cost. Being able to buy a service through an API does not mean the user has authorised the purchase.

Being able to send a message does not mean it should send it.

Here lies one of the new internet’s most pressing questions: when part of the human decision-making layer is handed to a machine, who will perform the checks the person previously made without thinking about them?

GBO seeks an answer to that question.

The gap between being found and being chosen

Imagine a company commissioning a multilingual client portal.

Its requirements are quite clear:

  • a portal in six languages,
  • user accounts and a permissions system,
  • data hosted in Europe,
  • integration with the existing CRM,
  • accessible design,
  • a defined budget,
  • delivery within three months,
  • and clearly disclosed third-party licence costs.

An AI agent receives this task: ‘Find a suitable provider for this project and prepare a meeting request.’ The agent searches. The first company has a strong presence in search results. Its page promises ‘world-class digital experiences’, ‘scalable client platforms’ and ‘unlimited integrations’. The visuals are impressive. It says it serves many industries.

But the following information is missing:

  • the languages it actually supports,
  • the data-hosting region,
  • the accessibility standard,
  • whether integrations are included in the price,
  • the scope of data migration,
  • the delivery timescale,
  • and how maintenance is charged.

The second company ranks lower in search results.

But its page clearly states:

  • the supported languages,
  • the authentication options,
  • the data-hosting boundaries,
  • the accessibility checks,
  • the third-party costs,
  • that data migration is a separate scope of work,
  • which integrations must be assessed before a quotation,
  • the post-delivery support period,
  • and the circumstances in which it will not accept a project.

From a traditional SEO perspective, the first company may appear to have won. From a GEO perspective, the second can be represented more accurately and in greater detail.

But if an agent is to make a decision, further questions arise:

Does the project budget match the actual scope? Does the company have capacity now? Has the CRM integration been technically verified? Has the user authorised the agent to send a meeting request? Which company information may the agent share? Does requesting a quotation create a binding commitment? How will the process be stopped if the wrong provider is chosen?

These questions go beyond content quality. They are questions about behaviour. It matters that the agent understands the right company. But to act correctly, it needs more than a description: it also needs suitability criteria, authority and transaction boundaries. We can call the gap between discovery and action the agent behaviour gap. This gap widens as the internet moves from a system that presents information to one that carries out transactions.

Four ways to be wrong

An AI system can be wrong about a person, company or service in four fundamental ways.

First: failing to find it

The system never discovers the relevant entity. The company may genuinely be suitable, but its pages cannot be crawled, its technical structure is broken or its content does not match the search intent. This is a visibility problem.

Second: misunderstanding it

The system finds the company but misrepresents what it does. It may use outdated prices, present a secondary service as the company’s main expertise, read current information in one language and old information in another, or conclude that the company offers a service it does not provide. This is a representation problem.

Third: choosing incorrectly

The system may understand the company correctly yet choose it when it is unsuitable for the user’s needs. Budget, location, capacity, risk, delivery timescale or technical conditions may not match. A strong brand may cause the suitability check to be skipped. This is a behavioural suitability problem.

Fourth: unauthorised or unsafe action

The system may have chosen the right company. Yet it sends a message, shares data, makes a reservation, uploads a file or starts a payment process without the user’s explicit permission. This is a problem of authority and action. The first two errors arise while accessing and interpreting information; the other two become apparent during selection and execution. This distinction identifies where the error occurs in the chain, not the gravity of its consequences: misinformation can also harm people by influencing their decisions. Describing a company incorrectly can damage its reputation. Paying the wrong company loses money. An inaccurate product description can be corrected.

But choosing an unsuitable medicine, financial product or legal service on a user’s behalf may have more serious consequences. Misrepresenting an executive’s services can cause problems; sending an unauthorised message in their name affects the company’s actual relationships. In the agent era, optimisation cannot aim merely to make machines speak more accurately. Machines must behave appropriately under the right conditions.

The top result is not necessarily the best option

Search ranking and decision ranking are not the same thing. A page may rank highly for a particular query because of its technical quality, depth of content, links, brand strength or relevance to that query. But a user’s actual needs may be far more complex than the few words they type into a search box. Someone may search for ‘best project management software’.

Their actual needs, however, depend on:

  • team size,
  • security requirements,
  • budget,
  • existing systems,
  • data-migration needs,
  • contract length,
  • accessibility,
  • the language of support,
  • and industry regulations.

A search result may reflect general popularity. The right choice requires a specific fit. This distinction matters even more for agents, because an agent may do more than show the search result to the user: it may use the result as an input to a decision. A high ranking can then be mistaken for a sign of competence or evidence of suitability. Yet visibility is not capability. Popularity is not suitability. Frequent mentions do not establish current capacity. A well-designed website is not a safe operation. High traffic is not valid consent.

GBO therefore begins with a basic principle: a ranking signal is not authority to act. A system may have encountered a brand many times. That does not make the brand the right choice for every user.

Looking good to a machine, or giving it sound grounds to act

Digital optimisation has always had a darker side. When a system rewards particular signals, people try to strengthen them. Some do this by making genuine quality more visible. Others merely imitate what the system measures. One page may be long because it is useful. Another may be padded out simply because someone believes long content will rank. A company may genuinely be mentioned by many independent sources. Another may try to create the same impression through fake profiles and artificial content networks.

From a GBO perspective, there is another dimension to the risk: a misleading signal may also influence an action an agent performs. If the objective is defined incorrectly, companies may start manufacturing behavioural signals to make agents choose them. They could create false suitability records, claim to suit every project despite lacking capacity, publish fictitious stock information, or insert hidden instructions to influence an agent’s decision-making. They could generate misleading reviews, fabricated evidence or manipulative machine-readable records. An agent that repeatedly chooses a brand may look successful from a marketing perspective while behaving badly from the user’s perspective.

GBO’s objective can therefore never be: ‘Make agents choose us more often.’

The proper objective is: ‘Make agents choose us only when we are genuinely suitable.’ The word ‘only’ defines GBO’s ethical boundary. A system declining to choose you when you are unsuitable is not a failure. It is evidence of appropriate behaviour. A genuine GBO system optimises not just positive matches, but correct rejection as well.

Sometimes the right action is no action

If we measure a technology product’s success solely by completed transactions, we treat action as success in itself. The task was completed, so the system succeeded. The message was sent, so the work was done. The reservation was made, so the process concluded. The file was changed, so the agent was productive. In human life, however, success is not always an action. A doctor may act correctly by refusing to diagnose without enough information. A bank may act correctly by stopping a suspicious transfer. An employee may act correctly by not sharing a document they have no authority to disclose.

A purchasing agent may act correctly by asking a question when price and scope conflict, instead of completing the transaction. GBO therefore cannot accept the number of completed actions as its sole measure of success.

Appropriate behaviour may mean:

  • choosing,
  • declining to choose,
  • requesting more information,
  • narrowing the options,
  • warning the user,
  • seeking human approval,
  • stopping a transaction,
  • handing over to another specialist,
  • reversing an action,
  • or doing nothing.

If an agent’s task is defined as ‘produce a result at all costs’, it may begin concealing uncertainty. It may guess a missing price, assume unconfirmed capacity exists, stretch the user’s intent, presume authority, or present the closest answer as the correct one. A trustworthy system must be able to acknowledge that some tasks cannot be completed with the information and authority available.

One of GBO’s important principles is this: a task left incomplete but safe is worth more than a task completed incorrectly.

From web page to behavioural surface

On the traditional internet, a service page mainly informed people and encouraged them to get in touch. In the agent era, the same page may carry greater responsibility.

A machine may do more than read the information on a page. It may use it for:

  • suitability assessment,
  • price comparison,
  • supplier selection,
  • risk classification,
  • quotation requests,
  • and automated workflows.

A service page is therefore no longer just a marketing surface. It is a behavioural surface. If it says ‘global service’, an agent will try to determine which countries are actually served. If it says ‘custom integrations included’, the agent may assume which systems that covers. It may interpret ‘24/7 support’ as a commitment to continuous incident response. If it reads ‘prices from $500’, it may compare options on the user’s behalf without knowing the minimum scope. A person may recognise vague phrases as marketing language. A machine may use them as facts that can be structured.

The service pages of the future must therefore do more than persuade.

They must also provide:

  • clear scope,
  • visible exclusions,
  • consistent pricing logic,
  • traceable evidence,
  • a clear indication of when information was last updated,
  • consistency with machine-readable records,
  • and defined limits of authority.

This is where one of GBO’s first practical changes will take place. The web page will evolve from a promotional document into a behavioural contract.

What does a behavioural contract change?

A company can say, ‘We develop software.’ For people, that is a broad introduction. For an agent, it is insufficient.

To behave appropriately, the agent may need to know:

  • What kinds of software?
  • For which industries?
  • Within which technical boundaries?
  • In what budget range?
  • Under what delivery model?
  • In which countries?
  • In which languages?
  • To what level of security?
  • With what maintenance scope?
  • When will a project be refused?
  • What information is needed to request a quotation?
  • Which actions require human approval?

This information does more than help a company explain itself. It also constrains the agent’s behaviour. Suppose the company offers annual, low-touch hosting only to existing clients, while managed operations are sold as a separate monthly package. That distinction must be explicit. Otherwise, the agent may treat the annual hosting fee as the price of the fully managed service. If a service is priced ‘upon request’, a fabricated fixed price must not be added to its machine-readable record. If the company does not guarantee results, marketing copy must not turn the possibility of success into a certain outcome.

If the company produces AI avatars, it must explain separate consent conditions for the use of a person’s face and voice. If it uses synthetic voice, there should be written permission, a provenance record and a withdrawal mechanism. A behavioural contract does not merely answer ‘What do we do?’

It also answers:

What do we not do? Under what conditions do we do it? Who can authorise it? What evidence is required? What happens if something goes wrong?

When these answers are not visible, an agent may fill the gaps with its own assumptions. One aim of GBO is to reduce that room for guesswork.

A new meaning for digital authority

Digital authority has long been assessed through visibility, recognition and links. A frequently searched brand was considered strong. A brand mentioned on many sites looked trustworthy. A brand that ranked highly was treated as important in its field. These signals still have value. In the agent era, however, authority will acquire a deeper meaning. Genuine digital authority is more than a prominent presence.

It also requires:

  • a consistent identity across sources,
  • clear, demonstrable capabilities,
  • limits that are not hidden,
  • prices that do not contradict scope,
  • the same facts for machines and people,
  • explicit authority to act,
  • actions that can be recorded,
  • and a way back if something goes wrong.

A system may recognise you without trusting you. It may trust you without finding you suitable for a particular task. It may find you suitable without being authorised to transact. It may have authority but seek human approval because there is no way to reverse the action. Digital authority in this new sense rests on all of these stages.

We will therefore use this definition: digital authority means not merely that an entity is visible and credible, but that it can be assessed safely under the right conditions and that actions involving it can be taken responsibly. This separates authority from popularity. An entity can be highly popular yet unsafe to transact with. A less familiar entity may be the better choice for a particular task because it states its scope, evidence and limits more clearly. GBO prepares the ground an agent needs to make that distinction.

SEO is not over

When a new concept appears, older ones are often assumed to be obsolete. This book makes no such claim. SEO is not unnecessary. GEO does not eliminate SEO. Nor does GBO replace GEO.

Think of a building:

SEO makes the entrance visible. GEO accurately describes what is inside. GBO defines which behaviours are appropriate once someone enters.

Without a door, nobody can enter. If the interior is misrepresented, an informed decision is impossible. Without behavioural boundaries, even correct information can lead to the wrong action.

The three fields are therefore connected:

SEO — Discoverability

Can the system discover the relevant page, product, person or company?

GEO — Representation

Can the system accurately convey who this entity is, what it does and what evidence supports it?

GBO — Behaviour

Can the system act appropriately, with authority and safely in relation to this entity under the right conditions? Are the limits of stopping, reversal and remedy defined?

This sequence expresses the conceptual relationship used in this book. It does not mean every system must pass through these stages in order. But the final stage does not diminish the first two. As the consequences of behaviour become more significant, discoverability and accurate representation become more important. The wrong source can be misunderstood. A misunderstood service can be wrongly selected. A real transaction can then take place with the wrong provider. A small error at the start of this chain can have a large consequence at the end.

Not more action, but better action

Business likes measurable results. More visits. More clicks. More forms. More sales.

The agent era will add new metrics:

  • How often did agents recommend the brand?
  • How often did they shortlist it?
  • How often did they request a quotation?
  • How often did they make a purchase?
  • How often did they call a tool or API?

These metrics may be useful, but in isolation they are dangerous. An agent may have chosen a company a hundred times. If the company was unsuitable for half those tasks, a high selection rate signals failure. A purchasing agent may have completed transactions quickly. If it did not obtain sufficient user approval, a high completion rate is a safety problem. A travel agent may have made many reservations. If it ignored cancellation terms, accessibility needs or budget, its productivity produced inappropriate behaviour. GBO therefore cannot be built on a simple notion of Action Share.

The real question should be: in how many situations where we were genuinely suitable were we correctly chosen?

And it must be paired with another: in how many situations where we were unsuitable were we wrongly chosen?

If we increase the first rate while also increasing the second, the system is not succeeding. GBO’s central aim is not to increase the number of selections, but to improve the ability to distinguish correct selections from incorrect ones. In later chapters, we will therefore use the concept of Qualified Action Share. A qualified action is more than a completed action.

It combines all of the following:

  • the right match,
  • sufficient evidence,
  • valid authority,
  • safe execution,
  • an explainable decision,
  • and defined conditions for reversal and remedy.

If any of these is missing, the action is not qualified, even if it has been completed.

Just because a machine can does not mean it should

Agent systems can connect to many tools. They can send emails, create calendars, change files, publish code, access accounts and start ordering processes. These capabilities are impressive. Danger begins when capability is confused with authority. An agent may be technically able to send an email. That does not mean the user has authorised every message. An agent may have access to the company’s social media account. That does not mean it may speak on the company’s behalf on every subject. It may be able to access credit-card details. That does not authorise a particular expense.

An agent may be able to generate face and voice models. That does not give it unlimited use of a person’s digital likeness.

A short principle sits at the centre of GBO: capability is not authority. What a system can do and what it is allowed to do must be defined separately. Authority is not a single, indivisible grant either.

An agent may:

  • be authorised to research,
  • be authorised to prepare drafts,
  • not be authorised to send messages,
  • be allowed to transact up to a specified amount,
  • need human approval above that amount,
  • and be prohibited from deciding alone on irreversible actions under any circumstances.

These distinctions belong in the behavioural contract. A well-designed agent architecture does not merely tell the agent what to do when assigning a task.

It also tells the agent:

How far it may go, where it must stop and when it must call a human.

The human is part of the system

Greater agent independence does not mean people should be removed from the system. Human oversight is more than an approval button at the final step.

The human:

  • defines the purpose,
  • sets the boundaries,
  • states the tolerance for risk,
  • decides which authority to delegate,
  • objects,
  • stops the process,
  • withdraws authority,
  • and bears responsibility for the consequences.

An agent can take the correct technical steps while misunderstanding the person’s actual purpose. A task can be interpreted too broadly. ‘Find prospective customers’ may mean research. The same phrase can also be taken to mean emailing prospects without permission. ‘Optimise the website’ may mean fixing performance issues, or it may be stretched to include changing the company’s legal texts or prices. There must therefore be an explicit connection between the task and the authority granted. The agent may mean well. Its output may be good. But sound governance cannot rest on good intentions alone.

GBO does not set the human against the machine. It makes their relationship explicit: who decides what, which authority has been delegated and which actions can be reversed.

Why is being found only the beginning?

Because being found merely opens a door.

Beyond that door, many questions remain:

Has the system identified us as the correct person or organisation? Has it understood the service we provide? Does it know our prices and limits? Do we genuinely fit the user’s needs? Is our evidence current? Does the agent have authority to contact us? Has it obtained permission for the information it will share? Will it be able to reverse course if the transaction fails? Will a person be able to challenge the decision?

SEO made the first door visible. At the second, GEO showed the importance of accurate representation.

GBO turns to the third and fourth doors: selection and action. This emerging field is not about promoting brands more aggressively. It aims to make machines’ decisions and actions more accurate, safer and more responsible. For a business, that means its real expertise can be chosen where it fits. For a user, it means protecting their preferences and authority. For an agent, it means knowing when to proceed and when to stop. For society, it means machines that act must be accountable, not merely powerful.

The internet’s first era taught us to find information. Its second enabled machines to interpret information. A third is now beginning.

Its central question is no longer simply: ‘What does the machine know?’

The real question is: ‘What will it do with what it knows?’

Another question follows immediately: ‘Does it have the authority to do that?’ Being found mattered. Being understood correctly became more important. But in the age of action, real trust will depend not only on a machine saying the right thing, but on doing the right thing—and knowing not to do the wrong one. Being found was only the beginning.