Agentic Advertising Infrastructure and What It Requires From Ad Tech Stacks
Agentic systems demand infrastructure legacy ad stacks cannot provide.

Agentic advertising has moved out of pilot programs sitting on some innovation team's roadmap. It is live in buying, ad ops, and monetization workflows right now, and that shift produces a mismatch: most organizations' infrastructure was built for a different operating model entirely. That gap between what agentic systems require and what the legacy stack can provide is the subject of this piece.
The ad tech stack's structural problem with agentic buying
Three forces arrived together to produce this moment. Conversational AI platforms built audiences large enough to support real ad monetization. Agentic systems can now execute media buys faster than any human trafficking team could review them. And the intent data flowing out of AI conversations carries a depth and specificity that keyword and page-level channels never produced. None of these three developments alone would force a rebuild of the stack. Together, they do.
The clearest marker of how fast this moved: OpenAI launched ads inside ChatGPT in February 2026 and opened a self-serve Ads Manager that May, making ChatGPT a third major buying surface alongside Meta and Google. Most agency stack documentation still doesn't reflect that fact. That gap is a sign of how far ahead deployment has run relative to the planning documents meant to govern it.
The pace kept accelerating from there. In a single week before Cannes Lions (June 22–26, 2026), at least eight major platforms, DoubleVerify, LiveRamp, Pixalate, Mediaocean, Magnite, Yahoo, Stagwell, and Fox, each shipped autonomous buying agents, coordination layers, or the verification and measurement infrastructure those agents need to operate: not a trend, a simultaneous structural move. They responded, separately and simultaneously, to the same underlying shift in what buyers and publishers now expect their systems to do.
Every one of those launches assumes that the stack beneath it can support machine-to-machine decision-making without a human checking each step. In most organizations, that assumption doesn't hold. A set of discrete, structural requirements, spanning signal ingestion, protocol design, governance, and publisher-side infrastructure, either exist in an organization's stack or don't. The rest of this piece maps those requirements layer by layer.
What agentic systems do differently from automated buying
Calling agentic buying "automation, but faster" understates what has actually changed. It operates on a different set of decisions, at a different speed, and it fails in a different way than a misconfigured campaign does.
Three structural drivers have converged: conversational AI platforms now have audiences large enough to monetize; agentic systems can execute media buying faster than human ops teams can review; and intent data from AI conversations is qualitatively richer than anything legacy channels produced. Platform-native automation, think Google AI Max or Meta Advantage+, sits inside buying surfaces advertisers already use, governed by that platform's own controls. Standalone cross-channel agents, such as Smartly or Albert, operate a buyer's accounts across multiple platforms at once, concentrating cross-channel power in a vendor the buyer doesn't own. And agent-to-agent buying goes a step further still: software negotiates directly with publisher and supply-side agents, with no human present at the moment the trade executes.
What separates these three is where human approval sits in the process, or whether it sits anywhere at all. Platform-native automation keeps spend inside one walled garden, subject to that garden's rules. Agent-to-agent buying removes the human from the negotiation itself, and the infrastructure requirement at each layer is different because the point of failure is different.
Adform's platform illustrates how far this has already gone in practice. Its infrastructure lets advertisers interact directly with its DSP, Ad Server, DMP, and ID Fusion through outside tools such as Claude, ChatGPT, or Microsoft Copilot. The agent a buyer chooses to work with is issuing commands to a live, integrated stack in real time. PubMatic's AgenticOS, launched January 5, 2026, defines a comparable model on the supply side: advertisers set goals, guardrails, brand-safety requirements, and creative parameters inside their preferred LLM interface, and a coordinated set of agents plans, executes, and optimizes within those boundaries.
The stakes of getting this wrong scale with the amount of autonomy granted. A misconfigured campaign wastes budget until someone notices and fixes it. An agent given the wrong instructions, or no ceiling on its authority, propagates that error on its own, at machine speed, across every placement it touches before a human has the chance to intervene. That's the operating reality the rest of this piece's infrastructure requirements are built to contain.
The signal layer: why conversational intent changes what targeting infrastructure must ingest
The targeting input that matters most in conversational AI environments is the live conversation itself. It's the live conversation itself, and reading that signal requires an ingestion layer that the legacy ad stack was never built to handle.
In LLM advertising environments, the working unit of targeting is what's called a context hint: a freeform, natural-language description, written at the ad group level, of the conversations where a given ad belongs, matched against the live exchange in real time. Matching against that hint requires more than reading the user's current message. The system has to track the entire arc of the conversation, what the user asked several exchanges back, how the AI responded, which follow-up questions surfaced, and where the exchange appears to be heading.
This changes what the signal actually contains. A conversation frequently states the person's budget, their real constraint, their shortlist, and what they already ruled out, information that keyword reconstruction from search queries never recovered and that a page-level content category cannot capture. Data from LLM interaction analysis bears this out: users typically go several prompts deep with an AI system before moving to the open internet to convert, and certain categories, flights and electronics among them, convert within hours of that AI session. A single session in sports and fitness can surface running shoe preferences, dietary requirements, training location needs, and a custom workout plan, a depth of signal that no individual search query comes close to matching.
That depth creates a real infrastructure demand. The buying system has to ingest and process multi-turn conversational context as it happens, not match incoming traffic against a static keyword list or a page-level content classification built for a different kind of web. Generalist DSPs built around keyword and page-level signals cannot read this kind of conversational context. Single-surface AI ad networks can read the context, but only within the one surface they were built for, without the reach to buy across multiple environments. The space between those two limitations is exactly where the infrastructure requirement now lives: a system that can both parse conversational signal and operate across more than one surface at once. Very little of the current stack does both today.
The API and protocol layer: what machine-readable infrastructure requires
Agentic buying only works if every piece of the stack an agent touches exposes an interface that machine can read and act on, and the industry has not settled on what that interface should look like.
Two open initiatives currently define this layer. The Ad Context Protocol (AdCP) governs agent-to-agent communication and transactions. IAB Tech Lab's Agentic Advertising Management Protocols (AAMP) coordinates agentic standards across the existing programmatic stack. IAB Tech Lab CEO Anthony Katsur has been direct about what this means for the pace of adoption: the industry should expect several false starts as agentic solutions get deployed, and practical, reliable use will take years of market experimentation, standardization work, and alignment across platforms, agencies, and publishers.
The uncertainty here isn't cosmetic. As of the most recent reporting available, it remained unclear whether AdCP and AAMP are even compatible with one another. An organization that commits its stack to one framework now risks having to re-platform that work later if the other protocol becomes the de facto standard. That's a genuine architectural risk for 2027: teams that build agentic workflows around the wrong protocol may face a forced rebuild once the market converges on one approach.
In practice, the Model Context Protocol (MCP) is emerging as the practical wiring for many current integrations. DoubleVerify's Insight Agent ships through MCP with Anthropic's Claude, with integrations for Google Gemini and Microsoft Copilot planned. LiveRamp exposes its agents through both APIs and MCP servers. Adform takes the same approach at the platform level, opening its full stack through an MCP server that it describes as a flexible integration gateway for AI systems, in contrast to more rigid, advertising-specific protocols. That choice says something important: interoperability in agentic advertising is forming around general-purpose protocols like MCP, not around any single advertising-specific standard built solely for this industry.
For teams evaluating their own stack, the requirement is concrete. The practical requirement for teams: every component of the stack that an agent will touch, the ad server, the DMP, the reporting layer, must expose a stable, documented API. A proprietary black-box component, or any step in the workflow that still requires a human clicking through a UI, breaks agent orchestration at that exact point. Fixing that doesn't require betting on which protocol wins the standards fight. It requires making sure nothing in the stack depends on a human hand where an API call should be.
Governed autonomy: the control layer that agentic stacks cannot operate without
The organizations getting measurable value out of agentic buying right now are the ones building explicit governance controls around systems that are capable but not yet fully trustworthy on their own. Governed autonomy is the actual differentiator between deployments that work and ones that don't, more so than the sophistication of the AI itself.
The reason this matters now, specifically, is that the surface area available for delegation has expanded faster than the controls built to contain it. Google and Meta have folded automation so deeply into their platforms that opting out of it is becoming difficult. Standalone agents are asking to run accounts across every channel a buyer touches. Agent-to-agent buying has moved out of pitch decks and into live media spend. Each point along that progression that removes a human from the loop creates a new place where a budget can run away unchecked if no ceiling was set in advance.
That makes the requirement organizational as much as technical. Someone has to own the definition of each guardrail, and someone has to be able to say where it's enforced. A functioning agentic stack needs spend caps set at the level of the individual agent as well as the campaign as a whole. It needs approval gates that trigger automatically before any irreversible action, a budget reallocation above a set threshold, expansion into a new audience, a swap of creative assets. And it needs a change log that a human reviewer can actually read and make sense of after the fact.
Skepticism toward vendor performance claims belongs inside this same governance framework, not outside it. Most of the headline performance lifts attributed to autonomous platforms, including figures cited by Google, Meta, and Smartly, come from the vendors themselves rather than from independently audited results. A serious governed-autonomy program means running an organization's own holdout tests at its own spend level rather than taking a vendor's benchmark as a given.
Verification has moved as well. It now sits inside the buying process itself rather than functioning as a separate audit performed after a campaign has already run. DoubleVerify's Insight Agent, LiveRamp's agent network, and Pixalate's OpenEPG are all structured as programmatic infrastructure for DSPs, SSPs, and buyers, operating at the pre-bid layer in real time, with post-bid analytics as an added capability rather than the primary function. Treating governance as a drag on the value of automation gets the relationship backward. An ungoverned agent that produces errors doesn't generate data anyone can learn from, and spend lost to an agent nobody was watching cannot be recovered just because the next feedback loop runs faster.
The supply side: what publisher infrastructure must expose for agentic monetization to work
None of the demand-side requirements above matter if the supply side can't meet them halfway. Publishers and SSPs still relying on page-level inventory classification cannot take part in agent-to-agent buying, because that model depends on interfaces built to expose conversational context, not page metadata.
Four specific functions have to sit alongside any LLM involved in a conversational ad placement, because a language model cannot reliably handle them on its own: confirming that a given product actually exists, tracking the link associated with it, crediting the correct publisher, and preventing the same user from seeing the identical offer repeatedly within one session. Meeting those four requirements takes a rule-based pipeline running alongside the language model.
PubMatic's AgenticOS, again, is the clearest existing example of what this looks like on the supply side. Advertisers define their goals and guardrails inside their preferred LLM interface, and a coordinated set of agents plans, executes, and optimizes within those defined boundaries, functioning as the supply-side counterpart to the demand-side agent stack described earlier in this piece. New ad formats are emerging to match this shift directly. Dappier's "Sponsored Conversations" format lets an advertiser insert a custom brand agent into an AI chat session running on a publisher's own site. Other entrants are skipping the retrofit entirely: one, having raised a reported Series A round, is building an AI-native ad network from the ground up, designed specifically to insert contextual, native ad units directly into generative AI conversations rather than adapting legacy display infrastructure to a new format.
The requirement that ties all of this together is straightforward to state, even if it's not straightforward to build. A publisher has to expose conversational context signals, not just a URL, a content vertical, or an audience segment, through an interface a buying agent can query directly and in real time. Inventory described only in those older, page-level terms simply isn't visible to the kind of agent this piece has spent its length describing, no matter how much of it exists or how well it performed under the previous model.
Sources
- Adform Opens Full-Stack Infrastructure for Agentic Advertising - ExchangeWire.com
- The 6 biggest ad tech stories of the year — and what they mean for 2026
- Agentic Advertising in 2026: The AI Ad-Ops Playbook
- The AI Ads Agency Tech Stack: The Tools You Actually Need in 2026
- Agentic Ad-Tech: The Buying Layer Goes Autonomous 2026


