I Checked 36 Named RSL Supporters for the License File. Three Have One.
Aug 15, 2026 · 6 min read · by Jordan Kwan
TL;DR: Three. On August 15, 2026 I fetched the RSL license file, robots.txt, homepage HTML, response headers and one content URL below the root for all 36 organizations named as supporters of the RSL Standard or the RSL Collective on the two official sites. Three serve a valid RSL license document: Medium, Stack Overflow and The Guardian. Thirty-one return a clean 404 with a fully-served robots.txt that contains no License: directive. Two, Akamai and MIT Press, block automated requests entirely and cannot be scored either way. The standard's own December 2025 press release claims "1500+ media organizations, brands, and technology companies worldwide now endorse RSL."
Really Simple Licensing launched on September 10, 2025 with the best founding roster a web standard has had in years: Reddit, Yahoo, Quora, Ziff Davis, People Inc., Internet Brands, O'Reilly Media and Medium, with Fastly, Cloudflare, Akamai and Creative Commons underneath as infrastructure. The pitch was clean. Robots.txt only says yes or no; RSL says yes, for this use, at this price. Eleven months later every implementation artifact the spec defines is a public file at a predictable URL, which means "did this ship" is a question you answer with curl instead of with opinion.
What counts as implementing RSL?
The RSL getting-started guide is two steps: put an XML license document in your web root, then point at it from robots.txt with a License: line. The robots.txt guide is unambiguous about the second half: "RSL-compliant robots.txt files must include one or more License directives that link to an RSL license file." The web pages guide adds a third surface, a <link rel="license" type="application/rsl+xml"> tag or an inline <script type="application/rsl+xml"> block in the page head. Every valid document carries the namespace https://rslstandard.org/rsl.
So I checked all of it, per domain: /rsl.xml, /license.xml, /.well-known/rsl.xml, robots.txt grepped for a License: line, the homepage HTML grepped for the namespace and the rsl+xml type, and the homepage response headers grepped for a Link: header with rel=license. Browser user agent, redirects followed, so a www-versus-apex mismatch could not fake a miss.
Who actually serves the file?
The population is every organization named on rslstandard.org or rslcollective.org, meaning both Featured Supporters logo walls plus every company named in the September 2025 launch release and the December 2025 RSL 1.0 release. That is 36: Reddit, Yahoo, People Inc., Internet Brands, Ziff Davis, O'Reilly Media, Medium, Vox Media, USA TODAY, Quora, wikiHow, The Daily Beast, Raptive, Ranker, Evolve Media, BuzzFeed, Fast Company, Inc., Man of Many, MIT Press, Note Inc., Quizlet, Slate, Stack Overflow, VerticalScope, Cloudflare, Fastly, Akamai, Creative Commons, ADWEEK, Miso.AI, The Guardian, the Associated Press, Boston Globe Media, Arena Group and IAB Tech Lab.
Three serve a real one. Medium permits ai-input ai-index search with attribution, prohibits ai-train, and embeds a note to its writers explaining that the file is an instruction to AI companies to come negotiate. Stack Overflow publishes four lines pointing at CC BY-SA 4.0. The Guardian prohibits everything and routes buyers to its licensing desk. All three also carry the License: line in robots.txt, which is the part that makes them findable rather than merely present.
Thirty-one are confirmed absent. Their robots.txt files load fine, at full size, with real directives, and contain no License: line at all, which the spec says is disqualifying on its own no matter where the XML lives. Reddit's robots.txt is a thoughtful 538-byte document that points at its Public Content Policy and says nothing about RSL. Three of the five named RSL Technical Steering Committee members sit at O'Reilly Media, Yahoo and Fastly. None of those three domains serves the file their committee governs.
Across all 36, zero homepages carried the namespace, zero carried the rsl+xml link tag, and zero returned a Link: header with rel=license.
Why isn't a 403 the same as a 404?
Because it is the difference between evidence and an artifact of my own tooling. A bot-blocked 403 tells you the site refused a robot; it tells you nothing about what is behind the door. An earlier bare-curl pass over a dozen of these domains came back half 403s, which would have supported a much louder and much worse article. Switching to a browser user agent and following redirects collapsed nearly all of those into readable 200s and clean 404s.
That leaves exactly two I cannot score. Akamai and MIT Press return an "Access Denied" page on every path I tried, robots.txt included. They are not in the absent column. They are unknown, and 2 of 36 unknown is the honest denominator. It is the same discipline that made the llms.txt count survive contact with its critics: separate what you observed from what you were merely unable to see.
Did I check anything besides the homepage?
Yes, because RSL declarations can be scoped to a path or a subdomain rather than the apex, and scoring a site only on its root would be a cheap way to manufacture a null result. For every domain I also fetched one content URL below the root, a section front or article such as Yahoo News, theguardian.com/technology, usatoday.com/tech, quora.com/What-is-machine-learning and buzzfeed.com/quizzes. Twenty-six of those returned real content. Not one carried the namespace, the link tag or a license response header. Reading a site's actual crawl instructions is where these questions usually get settled, and here they settle the same way twice.
Why would a standard with this much backing stall?
Because a competing mechanism shipped fourteen days later, from inside the tent. On September 24, 2025, Cloudflare, an RSL supporter whose VP of Product gave a warm quote for the RSL 1.0 launch, announced the Content Signals Policy: a Content-Signal: line in robots.txt expressing search, ai-input and ai-train preferences. Cloudflare did not ask anyone to adopt it. It pushed the policy into the managed robots.txt it already serves for "over 3.8 million domains."
That is the whole structural story. RSL asks a publisher to author an XML document, host it and edit robots.txt. Cloudflare asks a publisher to do nothing. Stack Overflow's robots.txt is the tell: it carries an RSL License: directive and a Cloudflare Content-signal: search=no, ai-train=no line, in the same 113-byte file. The infrastructure backer routed around the standard it endorsed, and cloudflare.com's own robots.txt has no License: line either. Endorsement was free. It usually is.
What would change my mind?
Several things, and I want to be straight about all of them. Eleven months is short for a licensing standard, and RSL 1.0 has only been final since December 10, 2025, so the shipping spec is eight months old. A collecting society is a legal instrument. Its leverage comes from the size of its repertoire and its willingness to litigate, not from a well-known file, and enrollment happens in a dashboard I cannot see. Publishers with signed AI deals have every reason to keep terms private. And RSL's Licensing Partners route adoption through Fastly, Supertab and MonetizationOS rather than hand-edited files, so real usage could be invisible to me.
But the partners page also lists WordPress support, and that link goes to a single-maintainer GitHub repository with 34 stars, no forks and its last commit on February 9, 2026. It is not in the WordPress.org plugin directory. For a standard claiming 1,500 endorsers "spanning billions of web pages," the easiest possible on-ramp is one person's side project.
The three who did implement did it in about ten lines, correctly, and I could verify them in under a minute. The spec works. The number that does not survive contact with curl is 1,500.
Written by Jordan Kwan, founder of Reachium.
I build Reachium, the LinkedIn outreach platform behind the tactics you just read. Same brain, live product.
See what Reachium does ↗