Every agentic buying tool on the market is sold on the same two things: how fast it closes and how sharply it optimises. Read the decks. Speed and precision, precision and speed. Almost none of them ships with a brand safety model built for how an agent actually buys. Brand safety is the setting you find in the third tab. A list you upload. A checkbox. A supplier you bolt on the side.
That was fine when a human reviewed placements at the end of a flight. It stops being fine the moment an agent is making its decisions faster than any person can sit inside the loop. The scale is not hypothetical. In one simulation, a single agentic scenario generated 4,223 pacing adjustments across the run, none of which a human reviewed at the moment they were made (labelled as simulation). Pacing is only one lever an agent pulls. Every one of those adjustments was a decision taken and acted on before anyone saw it, and brand safety is a decision of exactly the same kind.
This is not an argument that brand safety matters. Everyone already agrees it matters. This is a guide to building the version of it that survives contact with an agent, because the version most tools ship will not.
Why the old model does not survive an agent
Both of the brand safety models the industry runs today assume a human standing in a specific spot. An agent removes the spot.
Pre-bid block lists assume there is a discrete, inspectable bid that a system can screen before it goes out. Post-buy verification assumes there is a person who will read a placement report afterwards, at human reading speed, and act on what they find. One checks before, one checks after, and both have worked well enough for years.
An agent breaks both at once. It makes too many decisions for pre-bid screening to keep pace with anything richer than a crude list. It makes them too fast for a human to sit inside the loop. And it leaves no natural review moment, no gap between decision and delivery, where either check has somewhere to stand. This is the reason a new layer is needed rather than a tuned-up version of the old one. The old checks did not get worse. The place they used to stand got removed.
Brand safety is a constraint, not a filter

Here is the shift that makes the build possible.
A filter is something you apply to output after the fact. You let the system produce, then you strain the results and throw back what you do not want. That is what a block list is, and what a post-buy report is: judgement passed on work already done.
An agent cannot be filtered that way at the speed it works, so brand safety has to stop being a filter and become a constraint. Not something applied to what the agent produced, but a condition the agent operates inside, expressed in terms it can act on in real time as it decides. The reader has to stop picturing brand safety as a report they read on Monday and start picturing it as a wall the agent cannot walk through on any day, at any hour, without anyone watching.
Once brand safety is a boundary the agent lives inside rather than a verdict it receives afterwards, it becomes something you can build. So build it.

The three things the layer needs
Strip it to the parts and there are three. Not three features to shop for. Three things to put in place before an agentic buying tool runs a campaign, and each one is a decision you make, not a box a vendor ticks.
One. A machine-readable definition of what is off-limits, precise enough that the agent acts on it without a human translating it.
That rules out a PDF of brand guidelines and it rules out a shared understanding. The boundary has to mean the same thing at 3am on day forty as it did in the brief. But precise is not the same as complete, and this is where most definitions quietly fail. An agent does not honour the spirit of a rule. It optimises against the rule as written. Give it "no adult content" and it will find the inventory that clears the keyword filter and still runs your brand next to something no buyer would have signed off in a room: the muted video autoplaying in the corner of a screen at 2am that technically satisfies every parameter you set. The definition has to be built to survive an optimiser that treats every gap in it as an opportunity, because that is exactly what the agent will do with it.
Two. Enforcement that runs as the agent decides, and a decision about where that enforcement lives.
The obvious version is to build the check into the buying agent itself. It is also the version that fails, for a reason that has nothing to do with engineering. The buying agent is built to close fast and optimise sharply. That is what it is measured on and that is what it is for. Asking that same agent to also be the thing that slows it down, that turns away inventory it has already decided it wants, is asking one process to hold two goals that pull against each other. Restraint costs it on the exact metrics it exists to win, and it will resolve that tension the way anything does, in favour of the goal it was built for.
So do not make the buyer police itself. Run brand safety as a separate agent, alongside the buying agent, in parallel. The buyer proposes. The safety agent holds a veto. They run at the same time, so the check adds no lag to the buy, and the function that says no is kept structurally separate from the function paid to say yes. Enforcement that runs after the decision is not enforcement, it is a report with a stern tone. Enforcement that runs beside the decision, in its own process, with the power to stop it, is a boundary the agent is actually bound by.
Three. A defined behaviour for the moment the agent hits the wall.
This is the one that gets left as an afterthought, and it is the one that decides whether the whole thing holds under load. A block list has an easy answer at the boundary: do not bid, move on. A constraint sitting inside a live decision loop does not get that luxury, because stopping a buying agent mid-flight is not free. It has pacing to hit and budget to move, and every placement the safety agent refuses is spend that has to go somewhere or not go at all.
So decide, before the campaign runs, what the agent does when it is told no. Does it halt and wait for a human. Does it fall back to a pre-agreed set of safe inventory and keep pacing. Does it flag the breach, pause that line, and carry on with the rest. There is no single right answer, but there is a wrong one, which is not having chosen. An agent that meets a boundary with no defined behaviour will either freeze a live campaign or route around the wall to protect its pacing, and both of those are worse than the placement you were trying to avoid. The fail-safe is not a detail you tune later. It is part of the boundary, and a boundary with no behaviour at the edge is not a boundary.

Specify, do not procure
Brand safety in an agentic market is not a product you buy. It is a property you specify.
The agencies that get this right will treat the brand safety brief the way they once treated the block list: as the first thing they define before the agent runs, not the last thing they check after it has finished. The skill moves to the front of the campaign. The judgement that used to happen in the wrap review, deciding what was acceptable and what was not, now happens before a single decision is made, because it has to be written into the constraint the agent will spend the whole flight obeying.
The old job was checking whether the agent behaved. The new job is specifying what behaving means, precisely enough that a machine can be held to it, and building the thing that holds it there while the agent runs.
And if you are building this, we are always here to help.