8 September 2026 · Updated 9 September 2026

Brand Safety in Agentic Media Buying: What Agents Check and What Requires Human Sign-Off

Brand safety in programmatic advertising has always been a two-layer problem. Understanding the distinction between context safety and creative safety is the difference between deploying agents correctly and discovering the gap after an incident.


By Alkimi

Brand safety in programmatic advertising has always been a two-layer problem. The first layer is context: is this impression serving in an environment that matches the brand's category and quality requirements? The second layer is creative: does the ad creative itself, in the specific placement it is running in, meet the brand's standards for representation, tone, and adjacency? Human trading desks have historically managed both layers through a combination of blocklists, verification tools, and judgment calls. Agentic buying changes how each layer works, and not in the same direction. Understanding the distinction is the difference between deploying agents with appropriate brand safety controls and discovering the gap after a brand safety incident.

TL;DR: Context-level brand safety (inventory category, domain reputation, viewability, fraud signals) can be evaluated by an agent using codified signals and encoded policy. Creative-level brand safety (tone adjacency, representation quality, situational appropriateness) requires human review and cannot be reliably evaluated by an agent acting autonomously. The right architecture separates these two layers explicitly rather than treating brand safety as a single category that agents either handle or do not. Brands that have not made this distinction in their agentic configuration are exposed to creative-level failures that context controls will not catch.

Why brand safety is not a single problem The conflation of context safety and creative safety is the root cause of most agentic brand safety failures. Both are described as "brand safety", both appear in brand safety policies, and both are addressed (in different ways) by brand safety technology. But they are fundamentally different problems that require different tools and different oversight models.

Context safety is a property of the inventory slot: is this impression serving on a page, in an app, or in a video environment that matches the brand's content category requirements? The inputs to this question are codified: IAB content taxonomy categories, domain reputation scores, MFA (made-for-advertising) classifications, viewability thresholds, and fraud signals from IAS, DoubleVerify, or equivalent verification providers. These signals are machine-readable by design. An agent can evaluate them in real time and act on the results according to a configured policy.

Creative safety is a property of the specific combination of creative and context: does this ad unit, in this specific placement, meet the brand's standards for how it wants to appear? This question involves subjective elements that are not reducible to a signal. The tone of the surrounding editorial. The visual adjacency between the ad creative and the page content. Whether the brand's appearance in this specific combination communicates something unintended. These judgments are not impossible to approximate algorithmically, but no current system can reliably perform them at the level of quality a human reviewer would apply to a material placement.

The mistake most agentic configurations make is to treat "brand safety is handled" as a single state that applies to both layers. Context safety can be handled by an agent. Creative safety, in any scenario where it matters, cannot.

What agents can check: context-level brand safety An agent evaluating an inventory opportunity can check, in real time, against a set of encoded context signals. What this looks like in practice:

Content category compliance. The IAB Content Taxonomy provides a standardised classification for content categories across digital environments. A brand that excludes news content, adult content, or specific verticals can encode those exclusions as taxonomy codes. An agent evaluating an inventory opportunity checks the declared taxonomy classification against the exclusion list and acts accordingly. This is the most basic context check and, in compliant supply paths, the most reliable.

Domain reputation and quality signals. Third-party brand safety and verification providers score domains and app bundles against quality dimensions including MFA classification, viewability history, invalid traffic rates, and content quality signals. An agent can consume these scores and apply threshold-based decisions: if the domain scores below a defined threshold on any monitored dimension, do not buy. These scores are updated on a rolling basis and require the agent's configuration to stay aligned with the verification provider's current data.

Viewability and fraud signals. Pre-bid viewability prediction and pre-bid fraud signals are available through standard supply path integrations. An agent can incorporate these signals into its buying decision in real time. The configuration question is what threshold the agent should apply: a viewability requirement of 70% predicted measurability is different from a requirement of 90%, and the inventory available at each threshold is substantially different.

Contextual signals beyond category. Some verification providers offer contextual signals at a finer grain than IAB taxonomy: sentiment scores for the surrounding content, topic adjacency signals, or signals specific to video environments like content rating and genre. These can be incorporated into an agent's context safety evaluation where the supply path supports them.

The common thread across all of these: the signals are machine-readable, the policy can be encoded, and the evaluation can happen in real time. Context-level brand safety is well-suited to agent execution.

What agents cannot check: creative-level brand safety Creative safety is the layer that agents cannot evaluate reliably, and the layer that produces the brand safety incidents that attract the most attention.

Tone adjacency. A news site that is editorially appropriate for a brand's category requirements may publish individual articles with a tone that, in the moment, creates a problematic adjacency for a specific creative. A financial services brand that has appropriately excluded high-risk news categories may still find its creative appearing adjacent to an article about economic anxiety that changes the meaning of its message. The taxonomy classification is correct. The verification scores are acceptable. The specific combination is still a problem. An agent acting on context signals will not detect this. A human reviewing material placements will.

Representation and inclusion standards. Brand guidelines for representation (the diversity and inclusion standards that govern what content the brand appears adjacent to) are expressed in subjective terms that cannot be fully reduced to machine-readable signals. "Avoid content that stereotypes" is a policy statement that requires interpretation. The interpretation requires human judgment.

Situational appropriateness. Advertising that runs adjacent to content about a live crisis, a breaking news story with unexpected developments, or user-generated content that has changed in character since the brand safety audit last ran is a recurring creative safety problem that context signals will not catch in real time. Human monitoring of active campaigns, particularly on high-sensitivity topics, is the only effective check.

Creative performance quality. Whether a specific creative unit, at a specific size, in a specific context, is performing its intended function and not degrading brand perception is not something an agent evaluates. This is a human review function.

The architecture that handles both layers The appropriate architecture for brand safety in agentic media buying is not to add more context signals and hope they cover creative safety. It is to separate the two layers explicitly and apply different oversight models to each.

For context-level brand safety: encode the policy as completely and specifically as possible in the mandate. Run the agent against the encoded signals. Review the configuration regularly to ensure it stays aligned with current verification provider outputs and with any changes to brand policy. Treat context-level brand safety as something the agent handles, with human oversight concentrated on configuration quality and periodic audit of the outputs.

For creative-level brand safety: identify the categories of placement that require creative review and build a pre-approval step into the deal structure for those placements. An agent that has identified an opportunity in a context category where creative safety judgment is required should route to human approval before the deal is confirmed, not after. In environments where the creative-level risk is low (standard display in well-classified inventory with no adjacency complexity), continuous human review is not proportionate. In environments where the risk is material (video in news environments, contextually sensitive topics, brand-specific risk categories), pre-approval is the only reliable control.

IAB Tech Lab's AAMP framework provides the protocol infrastructure for encoding approval requirements into the deal flow: a deal type that requires pre-approval carries that requirement in the deal record, and a compliant system routes the decision to the appropriate approver before confirmation. The protocol makes the two-layer architecture technically implementable rather than aspirational.

The deal record as the brand safety audit A final point that connects brand safety to the broader agentic infrastructure question: the value of a complete deal record for brand safety auditing goes beyond regulatory compliance. When a brand safety incident occurs, the first question is "what did the agent buy, and why?" A deal record that captures the inventory signals the agent evaluated, the mandate conditions it checked, and the approval state of the transaction answers that question directly. A partial record does not.

Brands setting up agentic media buying programmes should treat deal record completeness as a brand safety requirement, not just an operational one. The deal record is the evidence that context-level brand safety was evaluated correctly. Without it, the brand cannot demonstrate that the policy was applied, only that the policy was written.

Alkimi's DealSheet infrastructure captures inventory signals, mandate conditions, and approval states as part of the standard deal record for agent-negotiated transactions. For brand safety teams, this means the post-incident audit has a usable evidence base rather than a gap where the evidence should be.

Entering Alkimi Marketplace...