If you've been doing this long enough, you remember the exact month "(not provided)" showed up in your Google Analytics keyword report and never left. It started as a small line, then it was the biggest line, then it was basically the whole report. Duane Forrester's July 19, 2026 piece on his Substack, Duane Forrester Decodes, makes an argument I've been circling for a while without quite landing it myself: AI search traffic is doing the same thing to attribution right now, just under a different name and at a speed 2011 never had to match.
The 'not provided' line item every analyst remembers
Quick refresher, since it's genuinely useful history and not just nostalgia. Starting in 2011, Google began encrypting search queries for signed-in users and, over the following couple of years, extended that encryption by default across the board. The practical effect: referrer strings that used to carry the actual search query stopped carrying it. Analytics platforms had no choice but to bucket that traffic under a single label, "(not provided)," and for a lot of sites that label became the single largest row in the entire keyword report. Not a top-ten row. The top row.
What made that moment matter wasn't the label itself. It was what analysts lost the ability to do. Before 2011, you could look at a landing page, see the exact queries sending it traffic, and reason directly from query to intent to content decision. After, you were inferring. You'd triangulate from Search Console's sampled, delayed data, from rankings tools, from conversion patterns on a page and a guess about what probably drove them there. The industry didn't stop measuring SEO. It stopped measuring it the way it always had, and it took years for new habits, new tools, and new expectations to fill the gap that opened up.
What actually changed, and what didn't
Forrester's framing in "Google Went 'Not Provided' in 2011... ChatGPT Just Shipped Its Version" is that AI engines are producing a strikingly similar blind spot, and it's worth sitting with why the comparison holds instead of waving it off as a clever headline. When a visitor clicks through from an AI chat interface, the referrer data your analytics platform receives is often thin to nonexistent: little to nothing about which specific question was asked, and often nothing that reliably tells you which citation or which answer actually produced the click. You see the session. You often don't see the why. Here's that comparison laid out plainly, framed against well-documented search history rather than any new dataset.
| WHAT ANALYSTS COULD SEE | BEFORE 2011 (SEARCH) | AFTER 2011 (SEARCH) | AI REFERRAL TRAFFIC TODAY |
|---|---|---|---|
| Exact query behind the click | Yes, in keyword reports | No, bucketed as (not provided) | Rarely surfaced by the referring engine |
| Which page/answer drove the visit | Directly attributable | Inferred from landing page + rankings | Inferred from timing, UTM guesswork, or self-report |
| Primary workaround analysts adopted | Not needed yet | Search Console query data, rank tracking, page-level inference | Branded-search lift, direct-traffic modeling, self-reported attribution |
Here's where the comparison isn't perfect, and it's worth naming the gap honestly rather than forcing a clean parallel. Google's 2011 move was a deliberate privacy decision, encrypting a specific data path on purpose. What AI engines are doing looks less like a decision and more like an omission, referrer data that was never built out with SEO-style attribution in mind because the product wasn't designed around it. The outcome, though, rhymes hard: a growing share of the traffic reaching your site arrives with the connective tissue between question and click stripped out, whether or not anyone stripped it out on purpose.
“The point isn't that AI companies are hiding something. It's that nobody built the wiring to show you, and by the time somebody does, most of the traffic will already have happened without it.”
Why this round of 'not provided' is worse
It would be tidy to say this is just history repeating and leave it there. I don't think that's quite right, and I don't think it undersells the problem to say so, because two things about this round make the blind spot bigger than the one analysts adapted to last time.
Illustrative sense of how much of the attribution picture survives each transition (directional, not measured data)
None of that is an argument for panic. It's an argument for taking the comparison seriously enough to build the equivalent of a Search Console workaround now, deliberately, instead of waiting three years for the industry to converge on one the way it eventually did last time. We've written before about attributing pipeline to organic and AI-cited traffic and the model we use to wire rankings, mention rate, and citation signals into the same dashboard as revenue. That model exists precisely because the referrer data alone was never going to close this gap on its own.
What you can still measure, and how
The honest version of this piece isn't "attribution is dead, give up." It's that direct, query-level attribution is gone for a growing share of traffic, the same way it went away for organic in 2011, and the response is the same kind of response: stop waiting for the platform to hand you the answer and start triangulating from the signals that are still available.
It's also worth reading the underlying traffic data itself the way an analyst, not a dashboard, would. A lot of the same discipline that used to go into parsing Search Console query reports around a ranking-volatility event, like the kind we cover in Google ranking volatility strikes again, applies directly here: look for correlated shifts across pages and time windows instead of trusting any single number in isolation. We break down the habits that carry over in reading Google Search Console like an analyst, and most of that muscle memory transfers to reading AI referral gaps the same way. The tool changed. The skill of triangulating around a missing data field didn't.
This is also, not incidentally, where reporting and analytics work earns its keep right now. Building a dashboard that survives a missing-data era isn't a nice-to-have layer on top of the SEO and GEO work, it's what keeps a program defensible when someone in finance asks where the AI traffic bump actually came from and "we can't tell" isn't an acceptable answer. It's the same discipline that held up the reporting behind our work with a healthcare tech client, where the attribution model had to survive scrutiny well beyond a single clean referrer string.
Do this next
Pull your analytics for the last 90 days and look honestly at how much traffic is sitting in an undifferentiated direct bucket that's grown alongside your AI citation activity. If you haven't segmented that traffic yet, that's today's task, not next quarter's. Stand up branded-search tracking next to it if you don't already have it running, because that lift is one of the few signals AI engines can't strip out of the picture the way they strip out the query. Then take the reporting model you're already running for organic and extend it to cover AI-cited traffic on the same cadence, instead of treating AI visibility as a separate, occasionally-checked metric. The keyword report never came back after 2011. Analysts adapted anyway, and the ones who adapted first spent less time arguing about the missing data and more time building around it. For the full argument, read Forrester's piece on Duane Forrester Decodes.
See where you are cited today
A free snapshot audit of your rankings and AI citations before we ever talk.
Josh leads work at the intersection of SEO and generative engines at Something Inc., helping B2B brands get ranked and cited across every major AI engine.