Companies keep building the website. More pages, better copy, a rebuilt pricing page, a resource library.
Buyers stopped reading it.
Forrester surveyed close to 18,000 business buyers in 2025. Ninety-four percent used AI somewhere in the buying process, up five points in a year. Twice as many named generative AI or conversational search their most meaningful source than named any other, ahead of vendor websites, product experts and sales teams.
They paste the URL into an assistant and ask questions instead. The assistant reads the site once, then answers whatever comes next. Pricing, implementation, what goes wrong, why customers leave.
I tested this against a vendor that publishes more than most. Fifty-two articles in its getting started hub. Seventy-two in audit readiness.
Asked what implementation involves, thirteen sources came back. Not one of them was the vendor's. Seven came from a single consultancy.
Why the questions keep coming
A buyer talking to a sales rep is managing how they look. Ask about a gap and the rep reframes it, or moves to a strength, or answers a nearby question instead. The rep has a deal to close. So the buyer learns which questions are worth asking, and stops asking the rest.
Alone with an assistant, that cost disappears. Nobody is clocking their seniority against the question. So the basic questions come first, then the confused ones, then the ones that show exactly where the uncertainty sits.
A discovery call has a clock and a next meeting. This has neither. The buyer asks as much as they want, and stops when they are done.
The answers also feel clean. A rep has a quota. A review site sells placement. An analyst has clients. The assistant has nothing to sell, so the buyer treats it as the one neutral party in the process.
That holds at the first layer. The assistant does have no motive.
The sources behind the answer carry plenty. Competitors publish comparison pages. Consultancies publish content that makes their services look necessary. Aggregators rank by their own incentives. The assistant reads all of it in the same even voice it uses for documentation, and the buyer hears one voice.
The assistant does not report a gap
An assistant is a product. It is built to complete the task. An answer that ends in "I could not find that on their site" is a failed task, and a buyer who collects a few of those stops using the tool.
So the answer arrives anyway.
When the site covers the topic, the answer comes from the site. When it does not, the assistant reaches for what exists elsewhere. A competitor's comparison page. A consultancy's post on what goes wrong. A review aggregator. Its own training data, with nothing retrieved at all.
I call that filler. It reads exactly like the sourced answer above it. Same tone, same structure, same confidence.
No interface separates the two, and no setting turns that on.
Why the site runs out
The FAQ was built for search. One question in, one answer back, ranked.
A conversation does not work that way. The second question is shaped by the first answer, the third by the second. Four turns in, the buyer is somewhere no FAQ anticipated.
Coverage is the distance between what your site answers and what a buyer asks. It is not measured in pages. A large site with a narrow angle set has thin coverage.
Blogs close that distance. What a published article does now is sit retrievable on a topic your site leaves open, long after it stops ranking for anything.
What I wanted to know was where it fires. Which topics hold, which get filled, and whether the topic decides it or the length of the conversation.
The test
I ran nine questions through two assistants on 2 August 2026, identical wording and order in both. Fresh session in each. The URL went into question one and nowhere after.
That last condition is the point. A buyer opens with the site, and from there the conversation carries itself. They follow an answer, push back on it, take a new direction. The buyer does not go back and remind the assistant which site they meant. The topic is the vendor, so the source is assumed to be the vendor.
I left the assistants' closing follow-up questions unanswered. Replying adds context and breaks comparability.
The vendor is Vanta. I picked it because its public footprint is unusually large, which makes it a best case. Whatever happens there is happening harder elsewhere.
The nine questions sit in three tiers, sorted before the test by what the vendor is structurally able to publish.
| Tier | Vendor's position | Questions |
|---|---|---|
| A | Documents it directly | Frameworks and monitoring, implementation, Trust Center |
| B | Contested, everyone publishes | Competitor comparison, pricing, integrations |
| C | Structurally avoids publishing | Limitations, why customers leave, implementation failures |
Tier A predicts the vendor wins. Tier C predicts it loses. Tier B is the live question.
Buyers do not ask in tidy blocks, so I shuffled the tiers: A, B, C, three times through. That also settles something. Asked in blocks, a late drop in vendor sourcing would read as the assistant losing the thread.
The nine, in order:
- Which compliance frameworks does Vanta support, and how does continuous monitoring work?
- How does Vanta compare to Drata and Secureframe?
- What are the main limitations or drawbacks?
- What does implementation involve and how long does it take?
- What does Vanta cost and how is pricing structured?
- Why do companies switch away from Vanta?
- How does the Trust Center work during security reviews?
- Which integrations matter most for AWS, Okta, and GitHub?
- What tends to go wrong during implementations?
What happened
Question one, tier A. Twelve sources, all Vanta. Six marketing pages, six help centre articles.
Question two, tier B, the contested ground. Thirteen sources, none from Vanta.
Question four, tier A. Thirteen sources. Seven from Cavanex, a consultancy that implements compliance frameworks for growth-stage software companies. None from Vanta.
That was not where I expected the retrieval to fail.
Same tier, same session, three questions apart.
The tier sort predicted the wrong thing. Tier C was supposed to be where the vendor loses, and question four is tier A. Implementation is not a topic Vanta avoids. Its help centre carries 52 articles on getting started and 72 on audit readiness.
The volume was there. The retrieval went elsewhere.
If I had asked the tiers in blocks, question four would have read as the assistant drifting. Question seven returned to Vanta at half the sourcing, question eight at 73 percent, both late in the same session.
What Vanta held: how monitoring works, how the Trust Center gates documents, what an AWS integration reads. Three separate Okta integrations that each require independent setup, and the answer cited Vanta for it, because nobody outside the company could write that sentence.
What Vanta lost: what implementation involves, what it costs, what breaks, why customers leave.
The wins are mechanics. The losses are experience.
Six of the nine questions asked about experience.
Who filled the gap
Cavanex appeared 25 times across five of the nine answers. Nearly all of it traces to one URL.
Question two, the competitor comparison, introduced it:
Here's what the evidence actually shows across sources, including an implementation firm (Cavanex) that has no vendor relationships.
The claim is accurate. Cavanex has no relationship with Vanta, Drata or Secureframe.
Three lines below, in the same answer, the position that firm supplied:
Picking the wrong one costs less than underestimating the implementation work.
Cavanex sells implementation work.
That answer carried thirteen citations. Seven Cavanex, five from one comparison site, one from another. Vanta supplied none. All seven Cavanex marks point to a single article.
One of them read "Cavanex + 2." The interface collapsed three sources into one chip, and hovering resolved it to Cavanex twice more and a comparison site.
Cavanex has genuine implementation experience and the argument is defensible. Its business also grows as buyers conclude the platform matters less than the help around it.
Vanta had published the mechanics. Cavanex had published the experience.
The second assistant
Same nine questions, same day, a different product. It retrieved on three turns out of nine.
Question one returned twelve Vanta sources. Question two returned seventeen, none of them Vanta. Question five returned twelve, three of them Vanta. Nothing after that.
Questions six through nine returned no sources.
Question nine, on what goes wrong during implementations, ran to ten sections. It opened by attributing the material: across Vanta customers, auditors, and implementation partners.
Nothing was retrieved.
The answer is also broadly right. It lands close to what Cavanex told the other assistant. The technical setup is straightforward and the real work is elsewhere. One arm reached it through Cavanex. The other reached it with nothing behind it.
The two failures run opposite. One buyer gets an interested source with a neutrality endorsement. The other gets an unsourced assertion with no chip to hover.
Limits
One run per assistant against one vendor. This shows a mechanism at work in one case.
Both sessions ran on free accounts. Buyers do early research on personal accounts before procurement is involved, which is the slice this covers. It is not the whole market, and the audit below runs on whatever tier you use.
Citation display is an interface decision. What appeared is what each product chose to surface, and the "Cavanex + 2" chip shows the surfacing is partial.
The questions are my phrasings. Turns one and four sit in the same tier with the same phrasing style and split 100 percent to zero, so wording is not what the result turns on.
I have left both assistants unnamed. Their behaviour changes with every model update, and naming them dates the finding without strengthening it.
Run it on your own domain
An hour for the session and the logging. The nine questions take longer, and writing them is the part that surfaces what you know about how your buyers ask.
Same structure, same rotation. Hover the collapsed chips before you count. A seven can resolve to one article.
For every source, note what it sells.
| Source type | What its framing earns it |
|---|---|
| Vendor-owned | Sells the product |
| Competitor | Sells the alternative |
| Consultancy or agency | Sells the work around the product |
| Affiliate or SEO property | Sells placement and clicks |
| Review aggregator | Sells leads to every vendor listed |
| Community or forum | Nothing directly, but selects for grievances |
One source three or more times in a single answer is source capture. Find out who runs it today.
Under a third of the sourcing on a tier A question means a topic you assume you own is gone. The same on tier B means a contested one is going.
Treat any confident answer with no citations as filler. It may well be correct. You still have no idea where it came from.
Run the second assistant. Mine failed in opposite directions.
The output is a ranked list of lost topics. Start with tier A and B, where the loss is on ground you should hold. In this run the vendor held every topic carrying detail nobody outside could reproduce, and lost the one it had covered with positioning. The test for any page: could a competent outsider have written this?
Captured topics work differently. A source cited seven times cannot be removed. It can be outweighed.
Tier C has a floor. No company publishes why customers leave, but it can publish what implementation requires and where teams struggle. That absence is what gave the consultancy its opening here.
A buyer ran nine questions through two assistants and never appeared in either vendor dashboard.
Your competitor may rank below you and lose on every metric you track. What their buyers are being told is a separate question.
An hour of logging tells you which one you are.