NVIDIA is one of the few large companies whose public surface an agent can actually navigate. Findings below, hardest evidence first: every one re-checkable in a single command. The strong baseline is credited in detail, because it earns it; the gap is precise and sits exactly where the world is looking.
curl header/file GETs of standard public paths, a soft-404 control, and WebSearch/WebFetch of NVIDIA's own report + primary sources for figures (labeled reported). No authentication, no scanning, no enumeration beyond standard well-knowns. Captured 2026-07-14. Not affiliated with or endorsed by NVIDIA.www.nvidia.com/llms.txt (200, text/markdown) is a real index that fans out to a maintained hierarchy: docs.nvidia.com/llms.txt (200, 7.7 KB, self-dated "Last updated 10 July 2026"), developer.nvidia.com/llms.txt (200, ~28 KB), plus locale and blog files. developer.nvidia.com/.well-known/agent-card.json is a real A2A (Agent2Agent: the protocol AI agents use to discover and call each other) agent card (200). And robots.txt enumerates 50+ named AI crawlers and explicitly Allows them the markdown lane. This is not a "you're behind" brief, it's "you built the reading room; the verification vault is missing."No jargon. NVIDIA already built the best agent-reading room we've audited, every fix below just extends that lead to the one story the whole world is now scrutinizing. Here is what each one is worth.
Your Scope-3 footprint doubled to 6.9M tonnes and lives only in a self-authored PDF; an on-chain retirement receipt per unit of compute turns that story into something an auditor, regulator, or agent can independently confirm.
developer.nvidia.com is agent-ready, but the marketing host where the sustainability story lives returns 403 to every agent probe; opening it means the reading room you already built finally has a door on the building where the hard questions land.
Your A2A card advertises a universal /{path}.md skill that only partly resolves, so an agent following it hits 404s on real topics; completing it protects the very legibility NVIDIA invested in.
Your production frame-ancestors list still carries UAT/QA hosts and one malformed token; a config sweep removes an unforced signal without touching anything a user ever sees.
The evidence for the credit, so it's not just praise:
curl -s https://www.nvidia.com/llms.txt · curl -s https://developer.nvidia.com/.well-known/agent-card.jsonThe developer host is agent-ready. The corporate/marketing host (where the sustainability and investor story lives) is not: the entire /.well-known/ tree is blocked at the edge, and ai.txt/sitemap.xml return the SPA 404 shell (byte-identical to a random control, so they're soft-404s, not real files).
curl -sI https://www.nvidia.com/.well-known/agent-card.jsonThe developer agent card advertises a page-markdown skill at https://developer.nvidia.com/{path}.md. Coverage is partial: one representative path works, two return 404 (HTML shell). Separately, developer.nvidia.com/llms.txt returned 0 bytes on a first cold GET then the full ~28 KB on immediate retry: an edge-cache cold-miss, reported honestly as a reliability note, not a broken file.
/{path}.md and hit 404s on real topics, eroding the very legibility NVIDIA invested in. Small, fixable, and worth naming precisely rather than glossing.curl -s -o /dev/null -w '%{http_code}\n' https://developer.nvidia.com/blog.mdNVIDIA's FY25 Sustainability Report is a downloadable PDF. It reports real progress: 100% renewable electricity for owned/operated offices and data centers (genuine, credited), but also that Scope 3 emissions jumped from 3.5M to 6.9M MT CO₂e (purchased goods & services +~2.8M). None of it is machine-verifiable, and there is no per-unit-of-compute retirement receipt an outside party can check. In an AI buildout the whole world is scrutinizing, the proof is a self-authored document.
www.nvidia.com's content-security-policy: frame-ancestors allowlists UAT/QA CMS hosts (cms.nvidia-docs-uat…brightspot.cloud, …qa3…, docs.nvidia-docs-uat…) alongside production origins, and ends on a truncated/malformed token (https://nvfile;). Low stakes: the kind of thing a CSP cleanup sweeps up.
curl -sI https://www.nvidia.com/en-us/ | grep -i content-security-policyRetire the compute footprint of a single AI session to a verified on-chain Regen Network certificate (pocket change at NVIDIA scale) and keep the certificate. It gives the Scope-3 story its missing verifiable object: a unit of compute, its ecological cost, addressed and independently checkable.
Or have any AI agent make one keyless call: x402 (a web-native way for AI agents to pay per use) POST vealth.net/.well-known/vealth/work-tco2e ($0.005) or /work-packet ($0.10), and fund one place-based restore packet near an NVIDIA data-center community. Deliverable: the on-chain proof receipt.