15 Sep 2026 · 4 min read
How Publishers Verify a Deal Negotiated by an AI Buying Agent
TL;DR: Publishers verify agent-negotiated deals in three ways: identity verification of the buying agent at connection time, mandate verification against the deal terms proposed, and deal record verification after execution. The shared DealSheet is the primary verification instrument: it captures what was agreed before any impression is served, giving the publisher a signed reference point for every delivery claim the buyer makes.
When a human media buyer negotiates a deal directly with a publisher, verification is relatively straightforward. The buyer is a known entity. The terms are documented in an IO. The publisher's ad operations team sets up the deal in their ad server and can trace every decision back to a named contact on the buy side.
When an AI buying agent negotiates a deal, the publisher faces a different verification question. The agent is not a person. It may be operating on behalf of a buyer the publisher recognises, or it may be a new contact. The terms it proposes are machine-generated. And the deal may be executed before any human on either side has reviewed the exchange.
Publishers that are building sell-side agent infrastructure are addressing this through three verification layers.
Agent identity verification
Before any negotiation begins, the buy-side agent must identify itself to the publisher's systems. AdCP (Agent Communication Protocol), published by AgenticAdvertising.org specifies a credential format for this: the buying agent carries a signed identity claim that names the buyer it represents, the mandate authority under which it operates, and the scope of deals it is authorised to execute without human approval.
The publisher's sell-side agent checks this identity claim against a registry or directly against the marketplace's identity infrastructure. If the identity cannot be verified, the proposal is rejected before negotiation begins. This prevents a rogue or misconfigured agent from submitting proposals that appear to come from legitimate buyers.
In practice, identity verification for agent-to-agent deals works similarly to how supply-chain verification works in conventional programmatic. The Sellers.json and Buyers.json infrastructure that the industry uses to verify programmatic supply chains provides a model that A2A identity verification extends into the bilateral negotiation layer.
Mandate verification
Once a buying agent's identity is confirmed, the publisher's sell-side agent evaluates the deal proposal against the publisher's own mandate parameters. The sell-side agent knows what inventory it is authorised to offer, at what CPM floors, to what categories of buyer, and under what data conditions.
The buying agent's proposal carries the buyer's requirements: the CPM range, the inventory scope, the audience data permissions, the campaign period. The sell-side agent checks each element of the proposal against the publisher's parameters. If the proposal falls within the publisher's mandate, negotiation proceeds. If not, the sell-side agent counter-proposes with terms that do fall within its mandate, or it declines.
Mandate verification is the mechanism that ensures the publisher's sell-side agent does not accept deals that the publisher has not authorised. The sell-side agent is not permitted to accept a deal outside its mandate parameters without triggering a human approval request. This is the same earned-autonomy model that governs buy-side agents: the agent can act within defined parameters without human involvement, but anything outside those parameters requires explicit approval.
Deal record verification
After a deal is agreed, the terms are written to a bilateral deal record, the DealSheet, that both parties hold in shared state. For the publisher, this record is the authoritative statement of what was agreed: the CPM, the inventory, the audience conditions, the delivery commitment.
When the campaign runs, the publisher's ad server delivers impressions against the agreed DealSheet terms. Post-campaign reconciliation involves comparing the delivery log against the DealSheet. If delivery fell short, or if any impression was served outside the agreed inventory scope, the discrepancy is visible against a shared reference document, not discovered by comparing two separate logs that may not match.
This is a material improvement over conventional programmatic reconciliation, where the buyer's impression log and the publisher's delivery log are produced by different systems and often diverge. The DealSheet does not eliminate delivery discrepancies; it makes them unambiguous when they occur, because both parties are looking at the same agreed terms.
What publishers need to have in place
A publisher that wants to verify agent-negotiated deals properly needs three things.
A sell-side agent with mandate governance: a set of parameters that defines what the agent can and cannot accept, with a clear human approval path for anything outside those parameters.
AdCP-compliant infrastructure: the publisher's systems need to be able to receive and parse structured proposals in the AdCP format, respond with counter-proposals in the same format, and write the agreed terms to a deal record that the marketplace holds in shared state.
Deal record access: the publisher needs to be able to retrieve the DealSheet for any agreed deal and compare it against their delivery data post-campaign.
Publishers that have these three elements can verify agent-negotiated deals with the same confidence that they verify manually negotiated ones, and in some respects with greater confidence, because the verification chain is automated rather than dependent on human email chains and spreadsheets.