The strongest agentic advertising systems do not maximise autonomy; they ration it, widening what an agent may do without asking only as the agent's record earns that trust. This is the principle of earned autonomy, and it is the opposite of the hype narrative in which agents are set loose to run campaigns end to end. The case for it is not sentimental attachment to human control. It rests on a specific failure mode of autonomous systems, the economics of accountability, and the accumulating evidence that the enterprises succeeding with agentic AI are the ones that kept humans firmly in the decisions that matter.
TL;DR. Earned autonomy means an agent's freedom to act unsupervised expands gradually, as a function of its demonstrated reliability, rather than being granted wholesale on day one. It is the answer to the hype narrative of fully autonomous buying. The case rests on three things: a failure mode unique to autonomous systems, in which an agent repeats a wrong decision at speed because it cannot doubt its own signal; the fact that accountability for outcomes stays with the human and cannot be delegated to something that bears no consequences; and evidence that the enterprises running agentic AI safely are the minority who kept human sign-off on material decisions. The model, in practice: observe, recommend, draft, human-approved action, and only then bounded automatic action.
What is earned autonomy?
Earned autonomy is a design principle in which an agent starts with little freedom to act on its own and gains more only as it demonstrates that its decisions can be trusted. Rather than an on-off switch between supervised and autonomous, it is a graded scale, and where an agent sits on that scale is a function of its track record, not a setting flipped at launch. This is why the IAB Tech Lab specifications build human approval and operational boundaries into the protocol itself rather than leaving autonomy to the agent's discretion.
The progression has a natural shape. The agent begins by observing and recommending: it proposes actions and a human approves each one. As its recommendations prove sound, it moves to drafting and taking human-approved actions, where it prepares a decision that a human signs off before it executes. Only once it has a real record of reliability does it reach bounded automatic action, where it can act on its own within tightly defined limits, and even then the highest-stakes decisions stay behind a human gate. Autonomy is the reward for a demonstrated record, granted in stages, and revocable if the record deteriorates.
This is a deliberate rejection of the alternative, in which an agent is granted broad autonomy immediately because it is capable of acting autonomously. Capability is not the same as trustworthiness. An agent can be technically able to run a campaign and still not have earned the right to do so unsupervised, and earned autonomy is the discipline of keeping those two things separate. It is worth remembering that the people building these protocols concede the underlying capability is not yet running at scale, which makes an all-at-once grant of autonomy even harder to justify.
Why not just let a capable agent run autonomously?
Because of a failure mode that capability does not fix and that gets worse, not better, as the agent gets faster. An agent does exactly what it is told against the data it is given. When the signal is flawed, or the objective is subtly wrong, the agent does not hesitate or sense that something is off; it executes the flawed decision, and then executes it again, and again, at machine speed, because doing exactly what it was told is its nature. Analysts call this silent failure at scale, and the faster and more capable the agent, the more damage it does before anyone notices.
A human running the same flawed process makes one bad decision and catches it at the next review, because humans hesitate, doubt, and notice when results look wrong. An agent has none of those instincts. It cannot doubt its own signal, which means it cannot be the thing that stops its own compounding error. Something outside the agent has to be the interrupt, and that something is human sign-off on the decisions large enough to matter. The approval gate is not friction slowing down a good system. It is the circuit-breaker for a specific way that fast autonomous systems fail.
This is why more capability is an argument for earned autonomy, not against it. A more capable agent acts faster and more consequentially, so an unsupervised error is larger and arrives sooner. The case for keeping a human in the material decisions strengthens as agents improve, because the cost of being wrong without an interrupt rises with the agent's power.
Who is accountable when an agent decides?
The human, always, and this is the part that cannot be engineered away. When an autonomous decision goes wrong and costs money or damages a brand, someone answers for it to a client, to leadership, to a board. That someone is not the agent, which has no career, no relationship, and no stake in the outcome. The consequences land on a person, which means the person has an irreducible reason to retain control over the decisions that generate those consequences.
This creates a simple logic that the hype narrative ignores. You cannot delegate accountability to something that bears no consequences, so you cannot fully delegate the decisions that carry accountability either. An agent can be trusted with decisions whose downside is small and reversible, because if it errs, the cost is containable and the human can absorb it. It cannot be handed decisions whose downside is large and hard to reverse, because the human who will answer for those has every reason to keep them, and no sane reason to let an unaccountable system make them unsupervised.
Earned autonomy encodes exactly this. It automates the low-consequence decisions first, where the human can afford to be wrong through the agent, and keeps the high-consequence ones behind sign-off longest, where the human cannot. The scale of autonomy tracks the scale of consequence, which is another way of saying it tracks who has to answer for what.
What does the evidence say about human oversight?
It says the enterprises succeeding with agentic AI are disproportionately the ones that kept humans in control of the decisions that matter. Research into enterprise agentic adoption finds that while most organisations report deploying it, only a minority have it running safely in meaningful production, and the difference between the pilots that scale and the ones that stall comes down to governance infrastructure that maintains human accountability while the agent operates at speed. The safe deployments are not the most autonomous. They are the best governed.
The recommended operating models converge on the same shape. They call for a named human authority responsible for each agentic process, pre-set risk thresholds and intervention triggers, and the ability to roll back and audit what the agent did. They run bounded pilots under oversight in parallel with production, scaling only what has demonstrated reliability. Gartner's projection of a sharp rise in AI-related risk tied to insufficient guardrails points the same direction: the systems that skip human oversight are accumulating exactly the failures earned autonomy is designed to prevent. The evidence is not that autonomy is bad, but that unearned autonomy is where the trouble concentrates.
There is a further, structural reason human sign-off matters in advertising specifically. When agents on both sides of a deal transact, their records of the deal can diverge, and IAB Tech Lab's standards leads are explicit that an agentic transaction cannot simply rely on a model saying that a transaction occurred and instead needs a record both sides can reference and audit. Published simulation research into agentic reconciliation found that two agents which had just agreed a deal recorded its terms differently in the large majority of cases. That research models the specification architecture rather than any live platform, but it underlines why a human approving material actions is not redundant even when the agent seems reliable: the agent may be acting confidently on a record that its counterparty does not share, and a human sign-off on the deal is a point at which that divergence can be caught before it compounds.
How should a buyer apply earned autonomy?
Apply it as the default posture, not the cautious exception, and make the scale explicit. A buyer deploying an agent should decide, deliberately, what the agent may do at each stage and what it has to earn, rather than accepting whatever autonomy level the platform defaults to.
In practice this means starting the agent in observe-and-recommend mode, where it proposes and a human disposes, and treating that as the baseline rather than a temporary inconvenience. It means widening autonomy in stages tied to demonstrated reliability, automating low-stakes reversible actions first and keeping high-stakes irreversible ones, large budget shifts, new deal terms, brand-sensitive placements, behind human sign-off longest. It means defining, up front, what reliability looks like and what would cause autonomy to be narrowed again, so the scale runs both ways. And it means insisting on the audit trail that makes earned autonomy possible at all, because an agent can only earn trust if its decisions and their outcomes are recorded well enough to be judged.
The hype narrative sells autonomy as the destination and human involvement as a transitional stage to be minimised. Earned autonomy inverts that: human sign-off on the decisions that matter is not a phase to be outgrown but a permanent feature of a system that takes accountability seriously, and autonomy is something granted carefully, in proportion to trust, and never more than the agent has earned. The buyers who adopt this posture will get the speed of agents on the decisions where speed is safe, and keep human judgement on the decisions where being wrong is expensive. That is not a compromise between autonomy and control. It is what using autonomous systems responsibly actually looks like.
This article references enterprise research on agentic AI production-readiness and governance, recommended agentic operating models with human oversight, reporting on the state of agentic buying, Gartner's projections on AI-related risk, the IAB Tech Lab's specifications on human approval gates, and published simulation research into agentic deal reconciliation conducted by Alkimi Marketplace. The simulation models the current specification architecture and is not an assessment of any specific production platform.