
A version of the same meeting has been happening in marketing teams everywhere over the past eighteen months. The GA4 acquisition report goes up on screen. Organic search is flat or sliding. Direct traffic is up 30, 40, sometimes 60 percent year over year. And someone at the table asks the obvious question: what is going on with Direct traffic?
The honest answer is always a bit weird…because the report being used to answer the question is unreliable. In the digital marketing world we know that a meaningful share of that “Direct” traffic never came from a URL typed into a browser. It came from ChatGPT, Perplexity, Gemini, Claude, and Copilot, or got stripped of its referral information from browsers like Safari or Brave. Either way, when it shows up without identifiable referral information, it gets sorted into Google’s unknown pile: “Direct traffic.”
For smaller marketing teams, this analytics shift matters more. The impact is greater. When you have one person, or a fraction of a person, responsible for reporting, there’s rarely time to interrogate a channel breakdown. There’s no time to actually come to firm determinations of where Direct traffic should be attributed to. Because of this, a rising Direct line gets explained as brand awareness. A soft organic line gets blamed on the algorithm, the market, or the content. The true beauty of this situation is that both explanations can be wrong at the same time, and the real story sits unexamined in the unknown bucket.
So, let’s examine it.
Where this problem came from, why it’s gotten dramatically worse, and what you can realistically do about it without hiring an analytics engineer.
Direct Traffic Was Never Really a Channel
First, some history, because like many issues with source attribution, this problem is older than ChatGPT.
Back in 2012, journalist Alexis Madrigal coined the term “dark social” to describe something most marketers already suspected: the majority of link sharing happens in places analytics can’t see. Someone pastes a link into an email, a text thread, a Slack channel. The click that follows carries no context, so GA4 files the visit under Direct (our unknown bucket). It’s the same label GA4 gives someone who types your URL from memory.
Groupon put a number on this in 2014 by conducting a Ludacris experiment to see if Direct traffic really should be in the number one spot. They deindexed their entire site from Google for part of a day just to see what would happen to their traffic classifications. Organic search collapsed, obviously. But here’s the interesting part: Direct traffic also fell by roughly 60 percent in the same window. Most of what Groupon had been calling “Direct” was organic search traffic showing up with broken attribution.
SparkToro and ReallyGoodData ran a cleaner version of the same test in 2023, driving over a thousand tracked visits from 11 social networks to purpose-built pages. Every single visit from Slack, Discord, WhatsApp, TikTok, and Mastodon registered as Direct. Facebook Messenger dropped attribution on three-quarters of its clicks. Even public LinkedIn posts lost referral data 14 percent of the time. If your buyers talk about vendors in private Slack communities and forwarded emails, then a chunk of your Direct traffic has always been in the nonsense pile that amounts to digital word of mouth.
The takeaway from a decade of this research: Direct was never a channel. Google just isn’t brave enough to call it “Other.” Marketers mostly made peace with it because the misattributed volume stayed manageable.
Then two things happened at once. The browsers got aggressive about privacy, and AI assistants became a discovery channel. The blind spot stopped being manageable.
The Browsers Started This Fire
Before anyone blames AI for the state of their Direct channel, credit where it’s due: Apple got there first. Turns out, humans started this problem.
Safari’s Intelligent Tracking Prevention launched in 2017 and has been tightening every year since. The relevant piece for attribution is that Safari downgrades referrer information to just the originating domain—and in plenty of scenarios, strips it entirely. Traffic from those users arrives at your site unattributed.You can guess which bucket it lands in.
The cookie side is arguably worse. Safari caps JavaScript-set first-party cookies at seven days; if the visitor arrived from a domain Safari classifies as a tracker, that window shrinks to 24 hours. Picture the actual buyer journey here: someone clicks your LinkedIn ad on their iPhone during their commute, reads a bit, then comes back four days later to fill out your contact form. Safari deleted the cookie connecting those two sessions days ago. Your analytics records a Direct conversion, LinkedIn never gets the conversion signal, and now the entire channel is being questioned as viable when CPAs are sky-high.
Two details make this bigger than a Safari problem.
- Every browser on iOS runs on WebKit, so Chrome on an iPhone follows the same rules as Safari on an iPhone. If your audience skews mobile, ITP applies to most of it regardless of what browser icon they tapped.
- Safari isn’t alone, just furthest ahead. Brave strips tracking parameters aggressively by design; Firefox has its own tracking protection; and the in-app browsers inside LinkedIn, X, and most email clients mangle referrer data in their own creative ways.
None of this is a bug. It’s deliberate, browser-level privacy engineering. It operates silently, and there is no setting on your end that turns it off. Which means some portion of your Direct traffic growth over the past several years was never mysterious at all. It was Tim Cook.
Let’s Be Real Though, AI Kind of Poured Gasoline On All of This
ChatGPT referral traffic started appearing in analytics for most sites in mid-2024, at volumes small enough to ignore. That lasted about a year. Adobe measured AI-driven referral traffic growing more than tenfold between July 2024 and February 2025, and Similarweb estimated AI platforms sent over 1.13 billion referral visits to the top 1,000 websites in June 2025—up 357% year over year, with the curve still climbing since.
That’s an absolutely insane number. Here’s the thing though, those numbers only count the visits that arrived with attribution intact. Those visible visits are the smaller portion. The invisible portion not included in this report is magnitudes larger. Think of it like an iceberg. We’re only seeing 10% above water; the other 90% is a frozen underwater mystery.
The most cited measurement of the gap comes from Loamly, which analyzed 446,000 confirmed AI-referred visits and found that 70.6 percent of them landed in Google Analytics as Direct. Other firms working from their own data put the range between 35 and 70 percent depending on platform mix. Take either end of that range and the conclusion is the same: whatever your dashboard says your AI traffic is, the real number is meaningfully higher, and the difference is sitting in the nonsense pile.
The mechanics are a grab bag. The ChatGPT and Perplexity mobile apps frequently drop the referrer entirely when opening links, and mobile is where most of this traffic lives. Some platforms open links in ways that deliberately remove the referral source. ChatGPT adds a “utm_source=chatgpt.com” tag to some outbound links but not others, and often without the companion parameters GA4 expects. This means thar some of those visits end up in “Unassigned,” which is somehow an even less useful label than Direct. Perplexity, Gemini, and Claude tag inconsistently or not at all.
Google’s AI Overviews run the same play in reverse. Clicks from AI-generated answer boxes pass google.com as the referrer, making them indistinguishable from regular organic clicks. So while assistant traffic inflates your Direct channel, AI Overview traffic quietly changes what your organic channel even means. Nothing about your report looks different, but it’s starting to get more and more inaccurate when trying to understand AI attribution separately from organic search.
Side note, I’ll be diving into the differences between getting mentioned and cited in AI Overviews and in LLMs in a future blog, and it is actually quite interesting how the strategy differs. Learn more about our GEO services here.
Why You Should Actually Care
If all this traffic behaved like average traffic, you could shrug and move on. Of course though, it doesn’t. It behaves wildly.
Multiple independent datasets show AI-referred visitors converting at unusually high rates. B2B analyses have measured conversion rates from AI platforms in the 10 to 16 percent range, against roughly 2 percent for standard organic search. The logic holds up when you think about it. Someone arriving from an AI answer already did their research inside the conversation.
They asked the assistant to compare options, weigh tradeoffs, and produce a shortlist. By the time they hit your site, they are in evaluation mode. For companies selling into government, security, or technical buying committees, this is exactly how procurement research happens now. Contracting officers and CISOs ask an assistant to summarize a vendor landscape before anyone visits a website.
People are using AI in ways you would never imagine. You might say, “well this company isn’t licensed to use the XYZ model.” You’re totally correct, but 48% of employees will still use their preferred models on their personal devices, usurping policies.
Now stack up what the misattribution actually does. Your highest-intent emerging channel is invisible, its conversions credited to a bucket nobody manages. Your Safari and mobile ad conversions are partially invisible, too—making paid channels look weaker than they are. The reported organic decline looks worse than reality, which invites the worst possible response: overhauling the content that’s earning AI citations in the first place.
And the rising Direct line keeps flattering a brand awareness story the data doesn’t support.
This is an exhausting and defeating place to be in. You know that nobody types a 70-character blog URL from memory. If your Direct sessions are landing deep on individual articles and capability pages rather than your homepage, those are not brand-recall visits.
Google’s Fix Helps—It Doesn’t Finish the Job
On May 13, 2026, Google added a native “AI Assistant” channel to GA4’s default channel grouping. Traffic from recognized AI assistants now gets its own row in acquisition reports, no configuration required. This is a genuine improvement, and an official admission that the problem is real. But I refuse to give Google too much credit because…it’s also incomplete.
The native channel only classifies sessions that arrive with recognizable referrer patterns, and early documentation shows gaps around platforms like Perplexity and Claude. But above all, and fundamentally, the problem remains: no channel definition can classify a session that shows up carrying no signal at all. The 35 to 70 percent of AI sessions arriving headerless still land in Direct, exactly as before. The update tidies up the visible portion of the problem. The invisible portion, which is larger, doesn’t move.
What a Lean Team Can Actually Do
The good news: most of this fits into an afternoon, and none of it requires an engineer.
Run the Diagnostic First
In GA4, open Traffic Acquisition, isolate Direct, and add Landing Page as a secondary dimension. Direct sessions landing on your homepage plausibly include real brand-driven visits. Direct sessions concentrated on specific blog posts and solution pages are almost certainly misattributed. Then, check the Tech report. If Safari and mobile contribute far more than their share of Direct traffic, browser stripping is a major culprit. If the Direct trend line tracks the AI assistant adoption curve from late 2023 forward, you’ve found the other one.
Build a Custom Channel Group
Define an AI channel using a filter against known AI domains: chatgpt.com, chat.openai.com, perplexity.ai, gemini.google.com, claude.ai, copilot.microsoft.com, and peers. It takes 30 minutes, but I promise Chat or Claude can walk you through it. It captures every AI session that does arrive with a referrer. I am seeing multiple reports that this alone recovers half or more of the visible misclassification. Put a quarterly reminder on the calendar to update the list, because the domains and behaviors keep changing.
Tag Everything You Control
Every email, social post, paid placement, and partner link gets UTM parameters. Parameters travel in the URL and survive most referrer stripping, so this shrinks the legacy portion of Direct and makes the AI-driven remainder easier to isolate. It won’t save you in Safari’s Private Browsing, but nothing will because it’s like that pit Batman had to crawl out of. This is still the highest-leverage hygiene fix available.
Ask the Question Directly
Don’t be shy, all this privacy stuff does have a point. Sometimes the easiest way to get accurate source information is to ask. Add a “How did you hear about us?” field to demo and contact forms. Self-reported attribution is imprecise, but it surfaces AI assistants in the buyer journey months before your analytics does. For long B2B sales cycles, it’s often the only attribution that survives the full research process.
Fix the Instrument Before You Judge the Performance
Here’s the larger point: measurement has quietly become a strategy question. Apple isn’t going to loosen privacy on Safari. AI platforms have little incentive to pass cleaner referral data. The companies that can see their real traffic sources are the ones that set up the detection themselves, because nobody upstream is going to do it for them.
That visibility is a prerequisite for everything else. You can’t make the case for investing in AI search presence if the returns get silently credited to a channel nobody manages. And you can’t diagnose an organic decline—real or imagined—with a report that files its own uncertainty under a misleading label.
So before the next analytics meeting turns into a referendum on SEO or content, it’s worth the 30 minutes to build a custom channel group and pull the landing-page view of your Direct traffic. There’s a good chance your content has been working better than GA4 admits. The visitors were arriving the whole time. Your analytics just didn’t know what to call them.



