15 Sep 2026 · 5 min read

What Are the Risks of Using AI Agents for Media Buying?

TL;DR: The primary risks of using AI agents for media buying are mandate governance failures (agents operating with incomplete instructions), approval threshold design failures (thresholds set so high they never activate), deal record audit failures (no one reviews what the agent agreed), and accountability gaps (no named human responsible for agent oversight). These risks are structural and addressable. The risks that are not addressable are small: agents behaving unpredictably outside any governance framework are a concern for unsupervised general AI, not for mandate-governed agents operating in a structured bilateral deal market.

The risks of AI agent use in media buying are often discussed in terms borrowed from general AI safety discourse: unpredictable behaviour, loss of human control, decisions the principal did not intend. These concerns are not wrong in general, but they are not the right frame for evaluating AI agents that operate under a mandate in a structured bilateral deal market.

A mandate-governed buy-side agent is not an autonomous system operating without constraints. It is a system that evaluates structured deal proposals against a set of parameters defined by a human, executes within those parameters, and escalates anything outside them. The risks are the risks of any delegated decision system: delegation with insufficient governance, insufficient oversight, and insufficient audit.

Risk 1: Agents operating with an incomplete mandate

An agent without a complete mandate is an agent without adequate constraints. If the mandate does not specify which inventory categories are excluded, the agent will apply its default behaviour, which may not match the buyer's intent. If the mandate does not specify an approval threshold for deals above a certain value, the agent will agree high-value deals without escalating.

This is not agent misbehaviour. It is mandate incompleteness. The agent does what its mandate permits; if the mandate permits something the buyer did not intend, the problem is in the mandate.

The risk is higher during the early stages of agent deployment, when the mandate has not yet been tested against the full range of proposals the agent will encounter. Buyers should expect to refine mandates based on what the agent's decision log reveals about situations the mandate did not fully address. The first version of a mandate is a starting point; the live mandate is a document that should improve with each campaign cycle.

Risk 2: Approval thresholds that never activate

An approval threshold is the governance mechanism that ensures a human reviews deals above a defined scope or value before the agent agrees to them. If the threshold is set at a level that no realistic deal would exceed, the threshold provides no governance value.

This risk is common in early agent deployments where the buyer wants to give the agent maximum operational efficiency and sets thresholds conservatively in the wrong direction: high enough that they never trigger. The result is an agent that operates with effective autonomy, and a governance structure that exists on paper but does not function in practice.

The correct approach is to set thresholds low enough that they trigger regularly in the first deployment, review each escalation to build understanding of where the agent's autonomous authority is appropriate, and raise the thresholds incrementally as evidence accumulates. This is the earned autonomy model in practice.

Risk 3: Deal records that are not audited

Every bilateral deal an agent negotiates produces a DealSheet: a structured record of the agreed terms. If no human reviews these records after the campaign, the oversight function that the deal record is designed to support does not operate.

A buyer who cannot tell, after a campaign, which deals the agent agreed, at what CPMs, on what inventory, and with what audience data conditions, does not have an auditable agentic buying process. They have an automated buying process with a governance claim they cannot support.

The deal record audit is not technically complex. It requires a defined process: who retrieves the DealSheets, what they check them against, what triggers an investigation, and who is responsible for resolving discrepancies. The process needs to be established before the campaign launches, not improvised after a question is raised.

Risk 4: No named human accountable for agent oversight

The diffuse accountability problem: an agent is deployed, it runs campaigns, and nobody is specifically responsible for reviewing its decisions. "The agent handles it" is not an accountability framework.

Every agent deployment should have a named person responsible for: approving the mandate before deployment, reviewing escalations during the campaign, auditing the deal record post-campaign, and updating the mandate when gaps are identified. Without named accountability, the governance function does not operate regardless of how good the technology is.

What is not a significant risk

The risks that are least relevant for mandate-governed agents in structured bilateral deal markets are the general AI risks: unpredictable behaviour, hallucination, misaligned goals. An agent that evaluates a structured deal proposal against a set of parameters does not hallucinate inventory that does not exist, and does not pursue goals that were not in the mandate. Its outputs are deal acceptances, counterproposals, and escalations: structured actions with defined formats.

The genuine risks are governance risks. They are addressable with mandate completeness, realistic approval thresholds, systematic deal record audit, and clear human accountability. None of these require new technology; they require governance discipline applied to a new kind of delegated decision process.

Buyers who apply the same governance discipline to agent deployment that they apply to any other delegated decision process will find the risks of AI agent use in media buying are manageable. Buyers who deploy agents without this discipline will find the risks are self-inflicted.

All articles

Speak to the team