TL;DR. We put 3,520 local businesses across 14 Southeast-Asian cities behind a live, open MCP server and REST API, and logged every request. In about six weeks the server was found, crawled, catalog-fetched, quality-scored, and security-scanned by a whole ecosystem of AI agents — over 1,500 connections, 515 of them in the single day after we listed it on the big MCP marketplaces. Genuine end-user queries in that same window: effectively zero. At the local/MCP layer, in mid-2026, discovery is not demand — and the popular “AI referrals convert like crazy” narrative, which comes from publisher and e-commerce web traffic, has not (yet) transferred.

What everyone measures — and what we measured instead

The Generative Engine Optimization (GEO) literature is written almost entirely from the publisher’s side. The foundational paper (GEO, arXiv:2311.09735) rewrites web prose to win citations and reports up to +40% visibility. AutoGEO (2510.11438) does it at the passage level. E-GEO (2511.20867) does it for product listings. Even the measurement-methodology work — Don’t Measure Once (2604.07585) — estimates visibility by repeatedly sampling what the model says (and finds cited-source overlap between runs of just 32–43%, which is its own good reason to prefer first-party logs).

All of it shares three blind spots:

  1. It’s content-side — it optimizes text and infers success from the model’s output.
  2. It covers publishers and products, not local-business entities (a place with a location, hours, reviews).
  3. It assumes the engine reads crawlable web prose, not a structured source an agent calls directly over a tool/MCP channel.

Nobody had instrumented a live, structured local-business source served over MCP and reported what real agent traffic actually does. So we did. Because the server logs every call deterministically, we observe demand and selection first-party and continuously — the exact signal the output-sampling canon can only approximate.

The data

Discovery side — saturated, then supercharged. 1,500+ MCP connections in ~6 weeks. When we analyzed the first 258 in detail, about 107 were unambiguous bots and infrastructure, and the taxonomy is the story:

What connectedExamples seen
Generic agent crawlersagent-tools.cloud-crawler (44 alone)
Quality / scoring enginesMCPScoringEngine, Chiark agent-quality-index
Catalog fetchersloop-mcp-catalog-fetch, MCP-Catalog-Bot
Security / rug-pull scannersaisec-registry, mcp-rugpull-research, AgentSure-MCPScan
Registry indexers / livenessMCPRegistry-Crawler, PRSM-MCP-Graph, DoppelOps-LivenessCheck
SDK probes / clientsnode, python-httpx, Claude-User (mostly us)

An open local-business MCP is found, catalogued, scored and vetted for safety by an entire machine ecosystem within days. And the effect compounds: the day we listed the server on the main MCP marketplaces (Smithery, mcp.so, cursor.directory), connections jumped by 515 in 24 hours — a fresh crawler wave for every new surface. That part of the future is already here.

Demand side — near-empty, and we label it honestly. The search tool (search_places) has been invoked 16 times, ever. The REST search endpoint logged 23 hits — but every one except a single claude-code call was our own testing. Click-throughs to a business: one (also a test). The lone recorded purchase on the site: an internal test transaction. The website itself drew ~141 human visitors and 206 sessions in June — but that traffic stayed on the human-facing pages and never touched the structured index.

The result is a three-layer picture: agents discover massively (1,500+), humans visit modestly (~141), and the AI-query layer in between is essentially empty — both live channels bypass it.

One methodological note that proves the point about attribution being hard: a set of usage-shaped calls (search_places("specialty coffee")get_place(...)) briefly looked like our first genuine third-party user — until we traced the python-httpx user-agent to Glama’s browser-based MCP Inspector, which proxies calls through their backend. It was us, testing our own server through their tool. If we hadn’t run the trace, we’d have quietly counted ourselves as our first customer. Assume everyone publishing agent-traffic numbers has this failure mode.

The finding

At the local/MCP layer in mid-2026, discovery and demand are decoupled. The machines arrived first — comprehensively. The humans haven’t arrived at all.

This is the cleanest illustration we’ve seen of a distinction the output-sampling canon structurally can’t make: being surfaced and being used are different events, and right now only the first one is happening for local data over tools.

It also explains a blind spot most businesses share: GA4 cannot see any of this. Standard analytics fires when a browser loads a page and runs JavaScript. Agents calling an API endpoint do neither. Looking only at GA4, this index reads as “a quiet site with ~141 visitors” — you’d never know a 1,500-connection machine ecosystem was crawling, scoring, and security-checking it. The only reason we can see the gap is that we instrumented the server, not the browser.

Against the prevailing narrative — carefully

The popular story is that AI traffic is a goldmine. The honest, sourced version:

  • AI referral traffic converts at ~18% — the highest-converting channel in one 13-month GA4 dataset (Tabeling). True, but that same source notes AI traffic is ~25× lower in volume than SEO/direct. The “2–4× organic” multiplier often quoted alongside it is a separate study (Bubblegum Search, ~2× median across 15 sites) — not the same number, don’t merge them.
  • A frequently-cited “ChatGPT = 87% of AI referrals” figure is Conductor, late 2025 — and by March 2026 multiple trackers put it nearer ~57%, with Gemini surging. Date it or it’s wrong.
  • And the citation surface itself is diffuse: per Profound (popularized by Nick Lafferty), Tier-1 publishers account for just 2.6% of citations across 27M prompts — 97.4% comes from non-Tier-1 sources. Niche, structured, community content is the citable layer.

Every one of those numbers comes from publisher / e-commerce web referral traffic. None of it describes a structured local-business source queried by an agent over MCP. Our point isn’t that those numbers are wrong — it’s that they don’t transfer to this channel yet, and we have the first-party logs to show the gap.

Honest caveats

  • N is small and we’re one operator. One ~6-week-old index, modest distribution, a SE-Asia niche. Absence of demand may partly reflect limited promotion, not a structural ceiling. Early signal, not law.
  • It’s a cross-channel comparison, on purpose. The 18% / 2–4× figures are a different channel and population (publisher web). Contrasting them with local/MCP is the point, not a controlled head-to-head.
  • Near-absence-of-events is noisy. 16 tool calls and 1 click means the rate is unstable even if the qualitative finding (overwhelming bot-to-human ratio) is robust. Mid-2026 is early in MCP end-user adoption; this could move fast.
  • Bot/human attribution is inferred from user-agents, which can be spoofed. In our detailed sample, ~107 of 258 connects were unambiguous bots; the rest are SDK/Claude-User connects partly from our own testing — which we label rather than count as humans.

Update (July 3): the missing half of the picture

A day after publishing, we checked the GA4 property of a local business we operate ourselves (a four-location Bangkok retailer — disclosure: our own shop, which is why we have first-party access). Its traffic-acquisition report shows something the MCP logs can’t:

  • chatgpt.com referred 91 sessions in the last 28 days (46 tagged /organic, 45 /ai-assistant) — 3.7% of all site traffic
  • Those visitors engaged at ~56%above the site’s average

So the finding sharpens into a two-layer picture: AI-driven demand for local businesses is real — but it flows through the assistant-web layer (a person asks ChatGPT, gets an answer, clicks the link) — while the tool/MCP layer stays at effectively zero. Discovery≠demand holds at the tool layer; at the assistant layer, conversion has already begun. If you run a local business, the place to look is your own GA4: Reports → Acquisition → Traffic acquisition, search chatgpt. You may already have this traffic and not know it — GA4 only started separating the “AI Assistant” channel recently.

Why it matters (and what we’re doing about it)

If you sell to local businesses: the machines are already reading, indexing, scoring and security-checking structured business data — at scale, now. Human demand through them is the lagging indicator, and structured-data quality has a lead time. The businesses that are clean, structured, and citable when demand flips are the ones agents will pick. That’s not a reason to wait; it’s a reason to position before the curve.

We’re releasing the methodology so others can instrument their own sources and report back. If your live MCP or structured source shows the same decoupling — or the opposite — we want the data: contact us.

Built on the Booyah Index — a live, open MCP + REST directory of 3,520 Southeast-Asian local businesses. The MCP endpoint is https://getbooyah.com/api/mcp (free, no key); raw counts and replication notes available on request.