Somewhere this week a business owner will open ChatGPT or Claude, click through a five-minute setup, and connect it to their Meta ad account. Then they will type something like "build me a campaign for the fall sale" and watch it happen. Campaign, ad set, ads, all of it, sitting in Ads Manager a minute later.
The videos selling this moment are not subtle. One of the most-watched walks through connecting an agent to Meta, generating images, drafting ads and scheduling fresh ones to launch every week, and ends on the line that you no longer really have to do anything. Another, a paid sponsorship for an autonomous tool, promises you will never need to log in to your Google Ads account again.
Here is what actually changed this year, stripped of the excitement. Meta now offers an official connector that lets an AI agent create and edit campaigns, ad sets, ads and custom audiences in your account. Google's official connector is still read-only, but third-party tools already make changes in Google Ads through its API, and more arrive every month. The technical name for these connectors is MCP, which is why "Google Ads MCP" and "Meta Ads MCP" are suddenly things people search for. You do not need to know what the letters stand for. You need to know that the software can now do things, not just say things.
So the question an owner faces has quietly changed. It used to be "what can AI write for me?" It is now "what have I allowed it to touch?" Most people connecting these tools have not answered the second one, because nobody asked them to.
Reading Your Account and Changing It Are Different Jobs
A few weeks ago I argued that the best use of AI in your advertising is reading, not writing: hand it the search terms report or two years of numbers and let it find what you would never have the patience to find. We made that case in Stop Asking AI to Write Your Ads. Ask It to Read Your Account., and I stand by all of it.
An agent with permission to change the account is a different animal, and the difference is the cost of a mistake.
When a tool that can only read gets something wrong, you get a bad idea. It sits in a chat window. You can ignore it, argue with it, or sleep on it. When a tool that can act gets something wrong, the mistake is already live. A budget doubled at 2 a.m. spends until somebody notices. An audience deleted is gone. A campaign launched on the wrong objective is buying the wrong thing by breakfast.
Nils Rooijmans, who has been automating Google Ads accounts since the days of hand-written scripts and now runs agents on client work, has the best description of these tools I have heard. They are "interns with terrifying confidence." The confidence is the problem. An agent reasons from general knowledge of how advertising works, scraped from everything ever written about it, and it applies that knowledge to your account without knowing your strategy, your margins or the reason you set something up the way you did. He sees them miss things as specific as bid limits inside a portfolio strategy, and then recommend a change in a tone that sounds entirely reasonable to anybody who is not a specialist.
The other failure is quieter. An agent guesses at what it cannot see. In one hands-on test of Meta's own connector, the agent was asked to duplicate a campaign, could not see the original targeting, had to ask for the pixel, and guessed at the settings it could not read. The result looked fine. It was built on assumptions nobody had checked.
Every Agent Works for Somebody
Before you decide what an agent may do, it is worth asking whose agent it is. The answer shapes every recommendation it makes.
One agency owner in the UK, who publishes his Google Ads testing on YouTube, spent a few weeks testing the AI advisor Google now builds into the Google Ads interface. He told it his goals were revenue and profit. Its first suggestion was to raise the budget on a campaign that was already spending right on target. He told it the budget was fixed. It suggested a smaller increase. He pushed back again, and it moved on to recommending a new Performance Max campaign, then a Demand Gen campaign, both of which need more budget, not less. It was only after he had refused all of it and asked outright for savings that it went through his search terms and found two genuinely useful negative keywords. Then it tried to add them and could not finish the job.
None of that requires anyone at Google to be acting in bad faith. It is simply a system built by a company that earns more when advertisers spend more, doing what it was shaped to do. An owner who took its first answer at face value would have raised the budget and felt well advised.
The same question applies to every third-party tool. Some charge a subscription, some charge a share of spend, and a good number of the enthusiastic videos about them are paid placements. That does not make the tools bad. It means the person telling you to hand over the keys may be paid when you do.
This is also not new. Google has been making changes to accounts on advertisers' behalf for years through auto-apply recommendations, and plenty of owners who have it switched on do not remember choosing to. We walked through which of those to leave on and which to turn off in A 100% Optimization Score Just Means You Agreed With Google. An AI agent is that same idea with far more reach.
Sort Every Task by What It Costs to Be Wrong
The useful way to decide what an agent may touch is not by how impressive the task is. It is by what happens if the agent gets it wrong, and whether you can take it back. That sorts everything an agent might do into three levels.
Read. Pulling reports, summarizing performance, going through the search terms, auditing the account against your notes, comparing this month to last. Nothing in the account changes. The worst case is a wrong conclusion, and you are standing right there to catch it. Let an agent do as much of this as you like. It is the work most small businesses never get around to, and it is where these tools genuinely earn their keep.
Draft. Building the list of negative keywords for you to approve. Writing ten new headlines. Setting up a new campaign and leaving it paused. The agent does the tedious construction and you make the decision. This is the level most owners should live at for a long time, because it captures most of the time saved with almost none of the risk. Meta seems to agree: ads created through its connector are paused by default until a person sets them live.
Do. Changing budgets. Changing bids or bid targets. Pausing and enabling campaigns. Creating or deleting audiences. Launching anything live. Every one of these either spends money the moment it happens or throws away something that took time to build. A budget change can push a campaign back into the platform's learning period, which we explained in Your Slow Season Is the Wrong Time to Stop Advertising., and you pay for that learning whether the change was a good idea or not. This level stays with a person until an agent has earned its way in, one task at a time.
When a new task comes up that does not fit neatly, use the single question underneath all three levels: if this is wrong, could I undo it tomorrow without losing money, data or learning? If the answer is yes, it can probably sit in Draft. If the answer is no, it is a Do, and a person decides.
Set the Limit in the Platform, Not in the Prompt
Most people who connect an agent set its limits by typing them. "Do not change any budgets." "Ask me before launching anything."
That is a request, not a control. The agent is being asked to remember a sentence, in a tool that forgets things between conversations and that, by its nature, is guessing what you meant. Rules that matter belong somewhere the agent cannot talk its way past.
On Meta, the lock exists, and almost nobody has found it. If you have full control of your business portfolio, go to Settings in Meta Business Suite, then Integrations, then Ads MCP server. For each ad account you can allow or block specific actions an agent is allowed to take. You can block it from creating campaigns. You can block it from editing budgets entirely, or allow budget changes but block anything above a set amount, and Meta's own example is a ceiling of $1,000. Meta enforces those rules on its side, so a request from the agent that breaks one is simply refused.
One detail matters if an agency runs your ads. When you share an ad account with a partner, they can set their own rules for it, and those rules apply only to their people. Your rules are yours to set. Do not assume theirs cover you.
On Google, the lock is the login. Every person with access to a Google Ads account has an access level, and one of them is Read-only: it can see campaigns and run reports, and it cannot edit campaigns. If you want an agent that reads, connect it through a login that only has Read-only access, and the question of what it might change answers itself. Google's own connector is read-only in its current release anyway. The tools that make changes need a higher level, and when one asks for Standard or Admin access, that is the moment to ask what exactly it intends to do with it.
And either way, give the agent its own login. Not yours. If the agent works through your personal account, everything it does looks like you did it, and switching it off means changing your own access. A separate login shows up separately in the history, and removing it takes one click. We made the broader version of this argument in Your Ad Account Is Not Yours., where the lesson was that nothing about your advertising should depend on one person's login. That applies to software as well.
Autonomy Is Earned One Task at a Time
None of this means an agent can never act on its own. It means autonomy should be earned the way you would let a new hire earn it: on one job, with a track record, before you hand over the next.
Rooijmans's own setup is the clearest model I have seen, and it translates directly to a small business. He gave his agent one narrow job, suggesting negative keywords, and nothing else. It was not allowed to audit the account or touch the ads. At the start it could act on nothing. Every suggestion went to a sheet where he or his team approved or rejected it and wrote down why when it was wrong. Over time the agent got better at predicting which suggestions would be accepted, and it scores each suggestion with a confidence number. These days, when that confidence is above 85%, it adds the negative keyword itself. Everything below the line still waits for a person. And whenever it acts, it logs what it did and emails him the list.
Here is the owner's version of that:
Pick one task. Negative keywords are a good first job because a wrong one is cheap to reverse and the saving is real.
Run it in Draft for a month. Approve or reject every suggestion yourself, and keep a simple count of how often you said no.
Look at the count honestly. If you were rejecting one in three, the agent is not ready to act, and the reasons you wrote down are what it needs to learn from. If you were rejecting almost nothing, it may be ready for the narrowest possible slice of Do, with every change logged.
Only then consider the next task. Not all of them at once because the first one went well.
Rooijmans is also candid that building this is harder than the demos suggest. Most of the work is writing down how you actually want the account run and giving the agent the context about your business that it cannot find on its own. That is not a reason to avoid it. It is a reason to be suspicious of anyone telling you it takes five minutes.
If You Cannot See What It Changed, You Do Not Control It
The last layer is the simplest and the one most often skipped. Look at what happened.
Both platforms keep a record. Google Ads has a change history that shows what was changed, when, and by which login. Meta keeps an activity history for each ad account, and its connector can pull the same log. If you gave the agent its own login, its changes are easy to pick out from everyone else's.
Once a week, open it and read it against what you actually asked for. You are looking for three things. Changes you did not ask for. Changes made at odd hours, when nobody in your business was working. And changes that touched money, meaning budgets, bids or anything launched live, that you do not remember approving. If you find one, find out why before you do anything else, and tighten the permission that let it happen.
The same question applies if an agency runs your account, and it is a fair one to ask directly. Are you running AI agents on my account? What access do they have? Does a person review what they change before it goes live, or after? A good agency will answer that without hesitation and will probably be glad you asked. How they answer tells you a great deal, which is the same test we laid out in How to Tell If the People Running Your Ads Are Any Good.
The Platform Still Holds You Responsible
There is a sentence in Meta's own help documentation worth knowing about. It says that connecting an agent through its connector is safe, and that an account is unlikely to be banned simply for using it. Bans come from breaking the advertising policies, running ads that do not comply, trying to get around enforcement.
Read that the other way round. The connector will not get you banned. What the agent publishes might. If an agent writes an ad that makes a claim you cannot support, or builds an image that breaks a policy, the account it lands on is yours. The platform does not care which of you typed it.
That is the real reason the Do level stays with a person. Not because the software is bad at advertising. Some of it is surprisingly good. It is because the budget, the offer and every claim your ads make carry your business's name, and the platforms hold you responsible for all three.
We use these tools on client accounts every week, and they save real time on the reading and the drafting. On every one of those accounts, a person decides what the software is allowed to touch. If you would like help setting that line on your own account, we are glad to look at it with you. If you would rather set it up yourself, start with the permission panel, not the prompt.




