1 September 2026 · Updated 8 September 2026

Can AI Agents Be Trusted to Manage Advertising Budgets?

Who is accountable when an AI agent makes a bad media buy? The governance gap, earned autonomy, and deal-level audit trails.


By Alkimi

The question of whether AI agents can be trusted to manage advertising budgets has a partial answer and a harder one. On the technical side, agents can reliably execute media buys against defined parameters, respond to inventory signals in milliseconds, and in many categories outperform manual trading desk decisions on cost efficiency. On the accountability side, the answer is less comfortable: most organisations deploying agents in media buying cannot demonstrate, to an independent auditor, exactly what the agent decided, what it was authorised to decide, and who carries responsibility for outcomes.

That gap between capability and accountability is not a minor operational detail. It is where brand safety incidents, billing disputes, and regulatory exposure concentrate.

What makes AI agent accountability different from algorithmic accountability?

Programmatic advertising has operated on automation for over a decade. Bidding algorithms make real-time decisions at the impression level without human approval on each transaction. What shifts with AI agents is not the speed of decision-making but the nature of it.

A bidding algorithm executes a fixed policy defined at setup. An AI agent infers appropriate action from context, adapts as conditions change, and, in more advanced configurations, negotiates deal terms with counterpart agents on the sell side. That inference step introduces a qualitative change in accountability. When an algorithm produces an unintended outcome, the cause is typically traceable to a misconfigured parameter or a corrupted data feed. When an agent infers its way to a problematic outcome, the decision path may be opaque to both the operator and the buyer.

The ANA's ongoing research into programmatic supply chain transparency has documented that brand safety tooling routinely permits made-for-advertising exposure because individual impression-level decisions appear acceptable while the aggregate pattern does not. Agentic buying raises an equivalent problem at the deal level: each negotiated term may look within tolerance, while the combination produces outcomes no human would have approved.

Who is responsible when an AI agent makes a bad media buy?

Legal accountability for AI-driven media decisions currently defaults, in most markets, to the party that authorised the agent to act. If a brand grants its buy-side platform permission to run an autonomous agent, the brand retains liability for outcomes regardless of whether any human reviewed the specific buy. This is the framework that applies in the UK under existing agency law, and the UK Government's AI Opportunities Action Plan (January 2025) acknowledged that existing liability frameworks were not designed for multi-agent commercial interactions.

The accountability problem becomes structurally harder in agent-to-agent transactions. Where a buy-side agent negotiates directly with a sell-side agent, neither party's human principals may have seen or approved the final terms. Both may later assert that the counterpart agent modified the terms without authorisation. In the absence of a shared, independently maintained record of what was agreed, disputes resolve by assertion rather than by evidence.

Marc Pritchard, Chief Brand Officer at Procter & Gamble, described the programmatic supply chain at the IAB's Annual Leadership Meeting in 2017 as "murky at best, and fraudulent at worst". That characterisation applied to impression-level bidding under standard programmatic. Agent-to-agent deal negotiation raises the transparency requirement further, because the decisions involved are higher-stakes and less standardised than impression bidding.

What does earned autonomy mean in practice?

The most operationally useful framework for governing agent deployment is one that treats autonomy as a permission earned through demonstrated reliability, not a default state that can be switched off if something goes wrong. This framework is sometimes called the earned autonomy model.

The earned autonomy model structures agent behaviour across five stages: Observe, Recommend, Draft, Human-approved action, and Bounded automatic action. Each stage requires demonstrated performance before the next is accessible. An agent in the Observe stage surfaces information without acting on it. In the Recommend stage it proposes buys but cannot execute them. In the Draft stage it prepares order confirmations for human review. Human-approved action permits execution only where a human has explicitly approved the specific decision. Bounded automatic action, the highest stage, allows the agent to act within pre-specified limits without requiring per-decision approval, and is available only where a documented track record exists within those bounds.

Specifying which stage an agent is operating at, and what evidence justified that stage assignment, is itself an audit artefact. It becomes the reference point for any subsequent investigation, because it defines what the agent was authorised to do at the time of the decision in question. Autonomy, under this model, is not a default state. It is a permission granted action by action.

What controls exist at the deal level for brand safety?

Brand safety in agentic advertising cannot be handled entirely through pre-flight exclusion lists and bidding parameters. By the time an agent has negotiated deal terms with a supply-side counterpart, the relevant brand safety questions extend beyond whether a domain appears on a blocklist.

The MRC Brand Safety Floor and Suitability Framework defines minimum standards for content adjacency at the impression level. Those standards are necessary but not sufficient for agentic deal-making, because they apply to inventory at the point of serving, not to the deal-level governance process that preceded it. An agent that agrees a deal within acceptable parameters but produces no accessible record of those parameters creates a gap between what the brand safety tool reports and what the agent actually committed to.

Deal-level controls require three things: a contemporaneous record of what parameters the agent was operating under when the deal was made, a record of the terms the agent agreed to, and a record of whether a human approved the agreement before execution. Where all three records exist and are accessible to both buyer and seller, investigation of disputed outcomes is straightforward. Where they do not exist, investigation depends on internal logs that may be incomplete, inconsistent, or unavailable to the counterparty.

How do you audit AI-driven media buying decisions?

Auditing an AI agent's media buying activity requires the same foundation as auditing any other financial decision: a contemporaneous record, accessible to an independent reviewer, that documents what decision was made, what information it was based on, and who authorised it.

The structural difficulty in programmatic advertising is that buy-side and sell-side systems maintain separate records. ISBA's 2020 programmatic supply chain study, conducted with PwC across 15 major UK advertisers, found that 15% of spend was entirely unattributable across the supply chain: neither buy-side nor sell-side logs could account for where it went. That study covered standard programmatic transactions. Agent-to-agent deal negotiation, where the deal terms themselves are determined by inference rather than by a pre-set price, introduces additional complexity into both the log and the reconciliation process.

A workable audit trail for agentic buying should be bilaterally held: both the buy-side and sell-side agents should reference the same version of the deal record, and neither party should be able to alter it unilaterally after the fact. The record should capture the parameters in force at the time of the deal, any modifications made during negotiation, and the authorisation status of each material change. The question of which party holds the authoritative copy is precisely where most current architectures fail.

What does deal-level accountability infrastructure look like in practice?

Several infrastructure models are being developed to address the audit gap created by agent-to-agent negotiation. Alkimi Exchange, which operates as a neutral marketplace for agent-to-agent media trading, uses a shared deal record called a DealSheet. The DealSheet is bilaterally owned by the buy-side and sell-side agents in a transaction. It records negotiation history, agreed terms, modification events, and the authorisation status of each material change. Neither party can alter the record unilaterally, which gives both a consistent reference document for dispute resolution.

The DealSheet model addresses the accountability question at the infrastructure level, rather than relying on each party's separate internal logs to agree retrospectively. Planning, inventory, activation and measurement remain in each party's own systems. The shared record covers only what was agreed between agents at the deal level: the parameters, the terms, and who approved what. That is precisely the information that currently goes missing when agent-to-agent deals are disputed.

Deal-level governance infrastructure of this kind is not yet an industry standard. It represents, however, the direction accountability frameworks must take as agent-to-agent negotiation becomes more common. The operative question for organisations deploying media-buying agents is not whether the agents are capable but whether the infrastructure they operate on can produce, for an auditor, a verifiable account of what was bought, what was agreed, and who authorised it.

Without that infrastructure, trust in agentic advertising is asserted, not demonstrated.

Entering Alkimi Marketplace...