The accountability question in agentic advertising is not philosophical. It is contractual, and most current ad contracts have no answer to it. Insertion orders are designed for a world where a human approved the buy. DSP terms of service place liability on the human operator of the platform. When an agent makes the buy, those contracts still exist, but the party they were written to hold liable was not in the room when the decision was made.
TL;DR. Advertising's accountability framework was built for human-to-human transactions, and it assigns liability to the human who authorised the buy. When an agent acts within a buyer's explicit instructions, the buyer remains liable: the agent is the buyer's instrument. The harder questions arise when an agent acts outside its instructed bounds, when something goes wrong at machine speed before anyone noticed the bounds were exceeded, or when the buyer's agent and the seller's agent hold different records of what was agreed. None of those scenarios are covered by current standard contract terms. The practical answer is not to remove accountability but to make it explicit at each stage: what the agent may agree to, on whose authority, and who answers for the consequences.
Who holds the liability when an agent transacts?
Under current legal frameworks, an agent acting within explicit instructions is acting as its principal's instrument, and the principal remains liable. A buyer who instructs an AI agent to negotiate deals within defined parameters is legally in the same position as a buyer who instructs a human trader to do the same. The agent's action is the buyer's action, legally speaking, and the buyer carries the consequences.
This is the straightforward case, and it is the one most agentic deployments currently occupy. The agent operates within limits the buyer set: spend caps, brand-safety requirements, approval thresholds above which a human must sign off. An agent that stays inside those bounds is executing instructions, and the buyer who set those instructions is accountable for the result.
The harder question arises when something goes wrong at machine speed before the limits caught it, when the agent acts on a signal that turned out to be flawed, or when the deal it agreed to turns out to be different from what the buyer believed was authorised. At that point, the question shifts from "who set the instructions" to "did the platform's agent act within its contracted scope, and can anyone prove what that scope was."
What breaks in the standard contract structure?
Standard advertising contracts (insertion orders, platform terms of service, agency agreements) were written to answer one question: which human authorised this buy. An IO is signed by a person. A trading desk operates under an agency-client agreement with named responsible parties. A DSP's terms of service place operational liability on the account holder.
None of those documents currently contemplate an agent making deal-level decisions. An IO that is negotiated entirely by a buyer's agent and agreed by a seller's agent has no human signatory on either side. Whether that agreement is legally binding, and which party's version of its terms governs in a dispute, is not settled by any current standard contract form.
The indemnity chain becomes more complicated at each step. Client indemnifies agency. Agency indemnifies trading desk. Trading desk operates through a DSP with its own liability terms. When the action in question was taken by an agent running on a vendor's platform against another vendor's agent, and both vendors' contracts were written for human operators, the chain has a gap where the autonomous action sits.
Where does the agent's decision sit in the current accountability framework?
It sits in a gap, and that gap is currently papered over by the fact that agentic advertising is still operating at small enough scale that disputes have not yet surfaced in force. That will change as volumes grow.
The industry specifications that are being built try to address this in part. The IAB Tech Lab's agentic frameworks require human approval on any action that commits spend above a threshold value. That design choice is not just a safety mechanism; it is an accountability mechanism, because it ensures a human explicitly authorised the material decisions. An agent that operated below the threshold is executing an authorised mandate. An agent that committed spend above the threshold without human sign-off exceeded its authorised mandate, and the platform's liability terms become relevant.
Brian O'Kelley of the Ad Context Protocol has said that a binding, signed record of an agentic transaction is "active in production at scale - not yet," as quoted in an ADOTAT investigation published in August 2026. That absence is not just a standards gap. It is a liability gap: without a shared, cryptographically binding record of what the agents agreed, a dispute has no authoritative document to resolve against.
What happens when both sides hold different records of the deal?
This is the liability scenario that existing contracts are least equipped to handle. When a buyer's agent and a seller's agent each maintain their own record of a deal, and those records diverge, each party will default to its own record as authoritative. Published simulation research modelled across 90,202 agent-to-agent transactions found that two agents which had just agreed the same deal recorded its terms differently in 95.3% of cases under separate record-keeping, as detailed in research available from WPP. The simulation models the specification architecture rather than any live production system, but it illustrates the mechanism: separate books will drift apart.
When those books disagree and the campaign ends and the invoice arrives, who decides which record is right? Current contracts assume the parties negotiated in person and can identify what was agreed. They do not have a mechanism for adjudicating a dispute between two automated systems' competing records of the same negotiation.
What should buyers and vendors do now?
The immediate practical answer is to make the accountability structure explicit in the contract before the campaign runs, not after something goes wrong.
For buyers, that means several things. Define in writing what the agent is authorised to agree to, the spend threshold, the deal types, the counterparties, and what requires human sign-off. Ensure the platform's terms cover what happens when the agent acts outside that mandate and who bears the cost. Require that the deal record be stored in a form both parties can reference independently, so disputes have a fact to resolve against rather than two competing assertions.
For vendors, it means the same thing from the other direction. State clearly in the platform's terms what the agent will and will not do on the buyer's behalf, what the platform's liability is if the agent exceeds its mandate, and what the dispute resolution mechanism is when the buyer's record and the seller's record disagree.
The accountability infrastructure the industry needs is the same infrastructure both standards bodies say is technically missing: a shared, deterministic record of what the agents agreed, held in a place neither party controls unilaterally. The contractual and the technical problem are the same problem. Solving the technical one resolves the contractual one, because both sides can reference the same fact.
________________
This article references the IAB Tech Lab's published agentic advertising specifications on approval thresholds, statements by Brian O'Kelley of AdCP published in ADOTAT in August 2026, and published simulation research into agentic deal reconciliation conducted by Alkimi Exchange and available from WPP Research. The simulation models the current specification architecture and is not an assessment of any specific production platform.