TL;DR: Deal record divergence is the foundational risk in agentic media buying: a WPP Research simulation found that buy-side and sell-side records disagreed in 95.3% of 90,202 modelled transactions under separate record-keeping. Data consent is a structural risk that agents cannot resolve on behalf of the controller; lawful basis under GDPR must be established before the agent uses a data asset, not by the agent in the act of accessing it. Budget overcommitment through aggregated sub-threshold spend is a mandate design risk that is almost entirely preventable. Liability allocation when an agent commits to a deal the principal did not intend requires pre-written principal-agent contracts with clear accountability assignment. Most mitigations are decisions made at mandate configuration, not responses to incidents after they occur.
Risk registers are planning tools. They are useful when the risks are specific, the evidence is available to assess likelihood and consequence, and the mitigations are actionable. Agentic media buying now meets all three conditions. The infrastructure is being deployed, the simulation data is published, and the governance specifications are available. What follows is a structured assessment of the six most material risks in agentic buying programmes.
What is the deal record divergence risk and how is it mitigated?
Deal record divergence is the risk that buy-side and sell-side agents complete a transaction but hold different versions of what was agreed. In an environment where agents are negotiating deal terms without a human on each side reviewing and confirming, the canonical version of the agreement exists only in the records each party maintains. If those records are kept separately, they can diverge.
The evidence for this risk is quantified. WPP Research modelled 90,202 agent-to-agent transactions to test divergence rates under two conditions: separate record-keeping by each party, and a shared record that both agents referenced at the point of agreement. Under separate books, the two parties' records diverged in 95.3% of transactions. Under a shared record, divergence fell to 0.19%.
The mitigation is direct: require shared record infrastructure as a condition of deployment, not as an optional feature. The deal record that both agents write to at the point of agreement becomes the authoritative source for both parties' measurement and reconciliation systems. Buyers evaluating agentic platforms should treat shared record access as a selection criterion with the same weight as audience data or brand-safety tooling.
What is the data consent risk in agentic buying?
Data consent risk is the risk that a buy-side agent uses a personal data asset in audience targeting without the data controller having established the lawful basis required under UK GDPR and GDPR. The agent's access to the data asset does not constitute consent or a legitimate interests assessment. Both of those determinations must be made by the data controller before the agent is authorised to use the asset.
This risk is structural rather than technical. No design improvement to the agent itself resolves it, because the legal obligation rests with the controller, not with the agent. A mandate that authorises an agent to use an audience segment without specifying which data assets are pre-authorised and under what lawful basis produces an agent whose data use may be non-compliant, regardless of the agent's technical behaviour.
The mitigation is to build a data authorisation inventory into every mandate. Each data asset the agent may access must be listed explicitly, with the lawful basis documented and the consent records or legitimate interests assessment available for audit. An agent mandate without this inventory is not ready for deployment in the UK or EU market.
What is the creative-placement mismatch risk?
Creative-placement mismatch is the risk that an agent negotiates or bids for a placement without visibility into the creative asset that will be served into that placement. The agent may win a placement that is contextually brand-safe, within audience parameters, and within budget, but for which the creative format is wrong, the message is contextually inappropriate, or the creative has not been approved for the channel.
This risk is operational rather than infrastructure-based. The agent does not have access to the creative at the point of placement decision. The mandate is the agent's only source of constraints on placement suitability.
The mitigation is to encode creative constraints as deal-level parameters in the mandate. Approved creative formats, excluded editorial categories, contextual adjacency restrictions, and any placement-level brand-safety requirements that go beyond categorical lists must be written into the mandate as conditions the agent applies at the point of bid submission or deal negotiation. A mandate that specifies "brand safe" as a single parameter without the supporting detail will produce placements that are categorically compliant and operationally mismatched.
How does budget overcommitment through sub-threshold aggregation happen?
Budget overcommitment through sub-threshold aggregation is the risk that an agent operating with per-deal approval thresholds makes multiple commitments each below the threshold but aggregating to a total above the brand's intended spend authority.
The mechanism is specific. A mandate specifies that any single deal above 10,000 pounds requires human approval. The agent negotiates fifteen deals in a single day, each valued at 9,000 pounds. Each deal is within the per-deal threshold and requires no approval. The day's total commitment is 135,000 pounds. The mandate's per-deal governance produced no approval trigger, but the aggregate outcome was not within the intent of the brand's instruction.
The mitigation requires two threshold types in every mandate: a per-deal approval threshold and a cumulative spend limit over a defined period (daily, weekly, or by campaign period). When the cumulative total approaches the period limit, the agent routes further deal requests to human approval regardless of individual deal size. Both thresholds must be present. A mandate with only a per-deal threshold has a design gap that sub-threshold aggregation will find.
How should liability be allocated when an agent makes a bad deal?
Liability allocation risk is the risk that an agent commits a brand or agency to a deal that was not intended, and there is no clearly designated legal accountability for that commitment. Agents are not legal entities. They cannot be party to a contract. The principal who deployed the agent bears the legal accountability for its actions within the mandate.
The complication arises when the action was within the mandate's literal terms but outside its intent, and when the agent acted without the mandate gap being foreseeable by either party at the time of configuration. Who is accountable for the outcome: the brand that provided the brief, the agency that designed the mandate, or the technology provider that operated the agent?
The mitigation is documentation and contract, not technology. Principal-agent contracts between brands, agencies, and technology providers must specify which party bears accountability for which categories of agent action, what the evidence standard is for demonstrating a mandate gap as distinct from a mandate violation, and what the dispute resolution process is for commitments the brand disputes. These contracts need to be in place before deployment. An agentic buying programme without pre-agreed liability allocation is operating on an assumption that disputes will not arise.
What is the measurement reconciliation failure risk?
Measurement reconciliation failure is the risk that a brand's verification tooling attempts to confirm delivery against a deal record that disagrees with the publisher's version of the same transaction. Third-party measurement providers verify delivery by comparing observed impression data against the deal record that specifies what was contracted. When the buy-side and sell-side deal records diverge, verification has no authoritative record to reconcile against.
The consequence is measurement that cannot be used for billing disputes, audience verification, or brand-safety confirmation, because the record of what was supposed to happen is contested between the two parties.
This risk is downstream of deal record divergence: if the primary mitigation of shared record infrastructure is in place, measurement reconciliation failure does not arise from the same source. For buyers transacting through infrastructure that does not yet provide shared record access, the mitigation is to require that verification providers confirm their reconciliation methodology and their process for handling record divergence before the campaign goes live.
*This article references a WPP Research simulation of 90,202 agent-to-agent transactions with findings on deal record divergence rates; the UK GDPR and EU GDPR data controller obligations as published by the UK Information Commissioner's Office and the European Data Protection Board; and the IAB Tech Lab's published agentic advertising working group specifications.*