← All insights
ArticleSeptember 5, 2026· 8 min read· Dan Feldstein

What AI Actually Automates in Advertising - and What It Can't

Everyone in digital advertising is talking about agentic. But there's a lot more to what's possible - and what isn't - than celebrating every adCP transaction. We get into the reality of what's automatable and what should still be done by humans.

What AI Actually Automates in Advertising - and What It Can't

Every ad tech vendor is now selling the same slide. Autonomous agents handle bidding, pacing, and creative rotation. Humans "focus on strategy." The pitch has been so thoroughly standardized across the category that it has stopped carrying information.

We want to state a position clearly, because we think most of the market is describing the wrong boundary.

AI agents are genuinely good at setup, quality assurance, pacing, and reporting, but they aren't good at deciding what a campaign is actually for. This isn't just a temporary limitation that a better model will eventually fix. It’s a structural one. The tradeoff is real: teams that adopt this split might give up some speed on strategic shifts, but they gain the certainty of knowing exactly why their money moved. In 2026, we think that’s the right trade to make. Here’s why.

The case is strong for where agents are winning

It would be dishonest to frame this as skepticism. The mechanical case for agentic systems in media buying is overwhelming, and any agency claiming otherwise is protecting billable hours.

A human buyer might adjust bids a few times a day. An agentic system, on the other hand, evaluates auction signals continuously. It rebids across thousands of placements without getting tired, taking weekends off, or suffering the quiet drop in quality that happens when a good buyer is stretched across nine accounts instead of three. These are mechanical optimization problems, which is exactly what machines are built for.

The four domains where we have seen agents deliver reliably:

Campaign setup. Trafficking is repetitive work with a high error rate when people are under pressure. Naming conventions, geo-targeting, audience assignment, and mapping creative across dozens of ad groups: an agent building this from a brief makes fewer mistakes than a human doing it at 6 p.m. on a Friday. The task is clear and the results are easy to verify.

Quality assurance. This is the most undersold application in the category. Agents are excellent at continuously checking a live campaign against a specification: pixel firing correctly, creative rendering at every size, spend distribution matching the plan, no placements appearing on excluded domains, frequency caps holding. QA is pattern-matching against a known standard, run constantly. Humans do this well once and poorly on the fortieth repetition.

Pacing. Delivery management is a closed-loop control problem with a clear objective function and observable feedback. Agents handle it better than people do, particularly across flighted budgets with uneven inventory availability.

Reporting. Pulling, reconciling, and narrating performance data across platforms consumes an enormous share of junior media hours and produces almost no differentiated value. Automating it is pure gain.

Notice what these four tasks have in common: each has a clear set of rules that exists before the work starts, and each has an outcome that can be checked against those rules. That is the real boundary, it’s not about how hard the task is or how fast decisions need to be made.

Where it breaks: judgment requires context the agent cannot access

The real problem we see isn't agents making "bad" optimizations. It’s agents making locally correct optimizations that are strategically wrong, and doing it faster than anyone can catch.

An agent reallocating toward the lowest CPA will find the lowest CPA. If your lowest-CPA pocket is branded search cannibalizing organic demand you already own, the agent will scale it enthusiastically. It is not malfunctioning. It is optimizing precisely what you asked it to optimize, in a business context it has no access to.

Four categories of decision that keep failing this way:

Defining the objective itself. Almost every important strategic question in media is about what to measure. That question can’t be delegated to a system whose only job is to hit whatever metric you give it. Are you buying incremental customers or just harvesting intent you already have? Should you optimize for the first purchase or a sixty-day margin? These choices drive outcomes far more than bid optimization ever will, and they happen before an agent even enters the picture.

Distinguishing a brand-safety problem from a cultural opportunity. Agents cannot reliably tell the difference between a moment a brand should lean into and one it should exit immediately. Both look like an unusual traffic spike in an adjacent context. The judgment required is about brand meaning, and it is not available in the bid stream.

Novel situations without precedent in the data. Agents optimize against learned patterns. A category entering a genuinely new competitive dynamic, a first-time channel test, a pricing change that alters the entire conversion economics — these are exactly the moments where historical patterns mislead, and exactly the moments they are trusted most, because the machine reports confidence in every regime.

Anything with an asymmetric downside. A wrong bid costs a small amount of money and self-corrects. A wrong brand-adjacency decision or a wrong reallocation into an untested channel does not self-correct on the same timescale. Speed is an asset when errors are cheap and reversible; it is a liability when they are neither.

The industry’s own behavior reflects this, even if the marketing says otherwise. The realistic near-term path is manual oversight today, moving toward consistent auditing later. Humans are shifting from pressing every button to checking whether the machine pressed the right ones. Agentic buying doesn't remove the need for judgment; it just moves where that judgment happens.

There’s also a governance side that most vendors ignore: regulators don't care if a model is "opaque." If an autonomous system harms consumers, saying "the model decided" won't work as a defense. An inability to explain a decision looks like a lack of oversight. Whatever autonomy you grant needs a clear audit trail to go with it.

The operating model we run

The way we explain this to clients is simple: agents own the execution of a specification, while humans own the specification itself.

Concretely, that means a documented brief that exists before any agent touches the account, defining the objective metric and why it was chosen, the guardrails (spend ceilings, velocity limits, excluded inventory, non-negotiable brand contexts), the conditions that require a human decision, and the review cadence.

We give agents unsupervised authority over bid adjustment within approved parameters, pacing, QA monitoring and alerting, reporting assembly, and campaign construction from an approved brief. We reserve for humans any change to the objective metric, budget movement across channels, new inventory sources or audience segments, brand-adjacency calls, and any reallocation exceeding a defined threshold.

Two implementation details matter more than the framework.

Widen authority in stages, not at once. New agents should run in shadow mode against human decisions, then in recommendation-only mode, then with human-approved execution, then with limited autonomy under monitoring. Each stage produces the evidence for the next. And when you change the model, the prompt, the tool access, or the data scope, the prior track record no longer applies to the new configuration — re-evaluate before re-authorizing.

Layer your caps and test the kill switch. Daily spend limits aren't enough because a fast agent can do a lot of damage in a single day. You need hourly velocity limits and anomaly thresholds to catch failures. Also, if you’ve never tested your kill switch, it’s not actually a kill switch: it’s just an assumption.

The tradeoff

Unfortunately, this isn't free.

Running human specification over agent execution means you will be slower than a fully autonomous competitor on genuine reallocation opportunities. When a channel opens up mid-flight, a fully autonomous system moves in hours; our model moves in a day or two because a person has to agree that the move fits the strategy. Sometimes that costs real money, and we would rather say so than pretend the approach is strictly dominant.

We take that trade because of the difference in what these errors cost. An autonomous system’s mistakes are fast and often invisible until the end of the month. The same speed that makes agents efficient also makes their errors scale. A supervised system’s mistakes are slower and easier to read. In a field where the most expensive failures are strategic, we’d rather be slightly late than efficiently wrong.

There is a second reason, less philosophical. Full autonomy is being sold considerably ahead of the standards required to operate it safely. Agent-to-agent buying protocols are competing and none has won. Interoperability is uneven. When the infrastructure settles, the boundary will move, and it should. Right now, buying the pitch means accepting a governance gap that the vendor will not be holding when it matters.

What to ask a vendor

Four questions that separate real capability from repositioned automation:

Which specific decisions does the agent make on its own, and which ones go to a human? If a vendor can't give you a straight answer, they’re just selling old-school automation with new buzzwords.

How do I audit a decision after it happens? If you can't reconstruct why the agent did what it did, you can't defend it to your CFO or a regulator.

What happens when the model changes? Ask whether prior performance validation carries over. It shouldn't.

How fast does the kill switch execute, and across how many channels simultaneously? Single-channel stops leave everything else spending.

The honest version of the AI media buying story is less dramatic than the pitch and more useful. Agents have already made execution cheaper and better, and any team not using them for setup, QA, pacing, and reporting is burning money on work that no longer requires people.

But the real value of media buying wasn't about button-pressing. It was about knowing which buttons were worth pressing and why. That’s a question data alone can't answer. The agencies that thrive will be the ones that get faster at execution while getting more rigorous about their judgment, not the ones that automate judgment away and call it progress.

Sources

  • Beet.TV, Beet Retreat Berkshires 2026 (Dentsu X on manual oversight moving toward consistent auditing)
  • FTC 2026 Section 5 guidance as applied to autonomous ad decisioning (opacity not recognized as a defense)
  • Industry reporting on agentic ad tech deployment and standards fragmentation, mid-2026