# What Is Agentic Buying — full text corpus > A single, definitive, citable answer to one question. Generated 2026-08-13. 5 documents. --- # What Is Agentic Buying? Source: https://whatisagenticbuying.com/ Agentic buying is software buying advertising from software: an agent representing the advertiser and an agent representing the publisher agree terms over a machine-readable protocol and book the campaign, with no human rekeying a brief or an insertion order. Agentic buying is software buying advertising from software. One program works for the advertiser and holds the campaign: the budget, the flight dates, the audience, what counts as success. Another works for the publisher and holds what is available and what it costs. The two exchange structured messages, settle the terms and book the buy, with nobody retyping a brief into a second system. An agent here is a program with a mandate: allowed to ask for things and, inside limits somebody set in advance, allowed to commit to them. The commitment is the whole difference from the automation already sitting on the desk. A dashboard that recommends is not an agent. A script that books is. Advertisers do have automation, and it stops in a specific place. Programmatic automated the auction and only the auction: one impression, one bid, decided in milliseconds, against a plan a person built in a spreadsheet weeks earlier. Everything on either side of that auction is still people. The brief that goes out by email. The availability deck that comes back. The call about the rate, the insertion order, the trafficking sheet, the argument at the end of the month about whose numbers are right. Those are what agentic buying is aimed at, so the unit of the trade changes with it: programmatic settles one impression at a time, and an agentic buy settles a whole campaign. Whether that counts as a real change or a relabelling is an argument the two standards bodies have already had in public. Campaigns have already run this way. Butler/Till and PubMatic bought connected TV for a beverage brand across two flights in December 2025 and January 2026. NBCUniversal, the agency RPA and FreeWheel put a single premium video investment across linear and streaming through agents in the first quarter of 2026, live NFL playoff inventory included. Both were announced by the companies that ran them. What the first campaigns saved came out of a fee, not out of a plan The beverage brand in that first campaign was Geloso Beverage Group, and it is still the only advertiser anywhere to have put its name on an agentic buy. Agents did the planning and the execution off a written brief. A person at the agency signed off the curated inventory before anything ran. The saving came from the plumbing rather than from the agents. The buyer's agent talks to the publisher's agent directly, so the demand-side platform that used to sit between them, and charge for sitting there, is not in the path at all. That is what the headline number measures. PubMatic's case study calls it roughly an 80% cut in buy-side costs and Digiday puts it at 82% of DSP tech fees, with the deployment ledger setting the two side by side. Both figures are a percentage of what the intermediary charged, not of the media budget, so neither converts into money on its own. On your own account the conversion is simple enough: whatever your DSP charges you as a share of spend is the ceiling on what removing it can save. Both of those figures came from the company that removed the fee, which is the norm rather than the exception. Nearly every number attached to agentic buying so far was published by a firm with something to sell. One measurement on that campaign came from outside it, and it was about quality rather than cost. Digiday reported that the verification firm Jounce audited the inventory and put made-for-advertising junk, the sites that exist only to carry ads, below 1% of what ran. It is the only independently produced number in the story so far. Nobody outside the two companies has isolated how much of the cost saving the agents themselves earned. The budget was never disclosed, nobody ran the same money the old way alongside it, and those two things are what an honest test would have to supply. Omnicom told investors in April 2026 that shrinking the intermediary take is the objective, so the buy side is chasing the same fee the sell side just removed. Publishers have their own version of the trade. In June 2026 a seller agent built by Boostr received, negotiated and closed a campaign-level buy for Vox Media covering budget, audience and delivery schedule, and Vox's ad operations team accepted it and checked it in the ad server. No performance figure was published, and the claim that hours of manual setup went away comes from Boostr's own announcement. If the take rate is the target, the next question lands on the agency: what happens to a retainer priced on the labour of executing buys, once the executing gets cheap? The plan itself changes in one concrete way well before it changes in any grand one. The brief stops being a document a colleague reads and becomes an input a machine parses. "Premium environments, ideally CTV, sensible frequency" gets interpreted generously by a human planner and literally, or not at all, by a parser, so whoever writes the brief inherits more of the outcome than they used to. Now the timing. The forecasts Magnite's chief executive gathered from the industry at Cannes topped out at 600 to 700 million dollars of agentic ad spend in the whole of 2027. Magnite alone puts through more than 9 billion dollars of ad spend a year, so the optimistic industry-wide figure for 2027 amounts to four weeks of one company's pipe. There is no case for re-planning a 2027 budget around that. There is a case for one small test, and the reason is not efficiency: it is finding out where your own approval thresholds sit before a counterparty's defaults decide for you. Does agentic buying need a language model? The obvious guess is that this means typing a campaign into a chatbot. It does not. "Agentic" is a claim about autonomy: who decides, who commits, inside what limits. Whether a language model is anywhere in the picture is a separate question. By that test a rules engine holding an API key qualifies, and a chat window that waits for a person to press send does not. The protocol most live deployments run on says so in its own request format. AdCP, the Ad Context Protocol, asks a publisher what it can sell with a request that takes either a written brief or a structured filter: countries, channels, budget range, start and end date, creative format IDs, delivery type. One field is required whichever of those two you send: a mode flag with three values, brief, wholesale and refine. It declares what kind of buying you are doing rather than what you want. In the two modes that are not brief, prose is not merely optional. The brief is forbidden outright. So a buyer that never sends a sentence of English is an agent by every definition the protocol itself uses, and the protocol has deliberately built the path that lets it be one. That distinction has a commercial edge. A vendor demonstrating a conversational interface has shown you an interface, and whether anything behind it can transact is a different question, answerable against the published operation list. Where the human sign-off actually sits The call that books a campaign carries a key that stops the same order being placed twice, plus the account, the brand, a start time and an end time. Every machine-to-machine API worth using has that key. The account, the brand and the two dates rule out anonymous buying and open-ended commitments in one go. Before that call, a pre-flight check asks about a media plan that already exists, and the caller has to identify itself. So an agent cannot conjure a campaign out of nothing: something authenticated has to point at a plan somebody already made. The wire format stops there. It never asks whether the somebody was a person, and by the definition above an agent has an identity too. Every specification here leaves the amount of delegation to you, which makes the human gate a matter of your own policy rather than the protocol's. The call sequence shows where the decision points fall. One side of the argument coined the term For a phrase this heavily used, the paper trail is one sentence, and it sits in AdCP's own FAQ: Put simply: AAMP is agentic bidding; AdCP is agentic buying. AAMP, the Agentic Advertising Management Protocols, is IAB Tech Lab's competing programme. Agentic bidding, in that sentence, means agents working inside the real-time auction, one impression at a time, on a clock measured in milliseconds. Agentic buying means agents working at campaign level, over minutes and days. That split is real. One camp named both halves, and IAB Tech Lab has never used either label about itself, in either direction. AdCP is stewarded by AgenticAdvertising.org, which discloses that two of its four interim board seats are held by Scope3 people and that Scope3 donated both the foundational IP and the seed property registry. Scope3 sells agentic advertising products built on AdCP. The disclosure is more thorough than most standards bodies manage, and it still leaves the category's only written definition authored by a commercial participant about a competitor. So "agentic buying" in a pitch points at no ratified document. Treat the adjective as marketing until the vendor names a protocol and a version. Agentic commerce is a different business The two get mixed up constantly. Search the phrase and much of what comes back is Stripe, IBM, Shopify and PwC writing about an assistant completing a consumer checkout. That is agentic commerce: checkout, payment and fulfilment, on behalf of a shopper. Agentic buying is an advertiser buying media from a publisher. The adjective is the only thing the two have in common, and they run on separate protocols. They do meet, and the seam is written down. AdCP describes the Agentic Commerce Protocol (OpenAI and Stripe) and the Universal Commerce Protocol (Google, with Shopify, Walmart and Target) as the commerce layer that complements its own advertising layer. Its FAQ spells out the handoff: a Sponsored Intelligence conversation runs the brand experience inside an assistant, and when the user decides to buy, the host passes the session identifier to one of the commerce protocols, which owns the purchase from there. Three questions for a vendor who says "agentic" The layer underneath the word is checkable, and three dull questions get you most of the way. Which protocol, and which version? A good answer is a name and a number, such as AdCP 3.1.13. A weak one is "we support the agentic standards". An AAMP compliance claim needs a follow-up, because the repository carrying AAMP's shared wire schemas sits at v0.5.0 and unreleased, so in 2026 the claim is about membership rather than about a shipped contract. Both stacks move, and where each has got to is tracked at maturity. Which operations have you implemented? AdCP publishes a versioned schema registry with the request and response shape of every operation in it, so a good answer is a list of names whose payloads you can validate today. A demonstration is not a list. What can your agent do with no human in the loop? Press on what it may spend unattended, whether it can approve inventory, and who can cancel. If the demonstration was conversational, ask which values of buyingmode it sends in production, because the two that are not brief carry no English at all. One check needs no vendor at all. AdCP publishes a public registry of agents, and on 12 August 2026 it listed 23. Three of them handed an actual list of products to a caller with no credentials: Cora AI, Equativ and No Fluff Advisory. Two of the three send back the same catalogue whatever you ask for, including a brief one character long. Being listed is not the same as having implemented anything, and the agent-by-agent results are worth ten minutes before a vendor call. --- # How Agentic Buying Works, Step by Step Source: https://whatisagenticbuying.com/how-it-works/ How agentic buying works, step by step: a buyer's agent finds the publisher's agent through a file on the publisher's own domain, asks what it can sell, clears the spend against a budget policy, books the campaign, then reads delivery back. A brand wants connected-TV inventory from a publisher it has never bought from. Nobody sends an email, nobody fills in a booking form, and no salesperson picks up the phone. Software on the brand's side holds a budget, a set of dates and a description of who the campaign is for. Software on the publisher's side knows what inventory exists, what it costs, and what is already committed. Getting from there to a booked, serving campaign takes eight steps. Each of those steps is a message with a name, a defined request and a defined answer, agreed by both sides in advance. That is the point of a standard here: no person sits in the middle translating, so the translation has to be written down first. The sequence below follows AdCP, the Ad Context Protocol, which is the only one of the two competing stacks publishing versioned schemas and the one named in the Boostr and Vox Media buy further down. Its current release is 3.1.13. IAB Tech Lab's rival programme, AAMP, covers the same ground across eight separately versioned repositories of reference code, and the places where the two disagree are marked, because those are the places a client breaks. The eight steps | Step | What happens | Who answers | Can a first version skip it? | | ---- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------- | --------------------------------------- | | 1 | The buyer's agent reads a public file on the publisher's domain listing which agents may sell for it | the publisher's own web server | only if someone handed you the endpoint | | 2 | It asks that agent what it supports | the publisher's selling agent | no | | 3 | It describes the campaign and reads back what is on offer | the selling agent | no | | 4 | It finds out which ad formats are accepted, builds the ad, uploads it | a creative agent, then the selling agent | not if the buy has to serve | | 5 | It registers the budget and the policy the campaign runs under | the buyer's own policy agent | yes, unless the account has one | | 6 | It asks whether this campaign, this caller and this spend are allowed | the buyer's own policy agent | same | | 7 | It books the buy | the selling agent | no | | 8 | It reads delivery, and sends performance back | the selling agent | the performance half, yes | Running that in order is straightforward. Knowing which agent answers each call is not, and one call name carries two different contracts depending on which agent you point it at. Step 4 also puts a third party in the transaction: a creative agent is software that holds the full specifications for an ad format and can build the ad to them, and it is not the same software as the agent selling you the inventory. It may belong to your creative shop, to a specialist vendor or to the publisher. Twenty-three agents were publicly listed on the AdCP registry on 12 August 2026, and three of them will show a catalogue to a caller with no credentials. Everything past that point needs a relationship, so most of the sequence below is what the other twenty are building towards rather than something you can try this morning. The measured detail is at the end. What a first version can skip Steps 5 and 6 are conditional. An account with no policy agent attached never needs a plan, so a first client can leave both out and nothing on the wire will complain, which is also the problem with them. Step 1 goes only if somebody handed you the endpoint directly, which is how every pilot starts. Skipping it means you have taken the seller's word for it that it may sell what it is selling. Creative is skippable at buy time and not at serve time. A buy created with no creatives sits in a pending state where "the buyer must attach creatives via synccreatives before the buy can serve", which is a buyer obligation rather than a seller-side approval queue. Performance feedback is the one call nothing else depends on: the campaign runs whether or not you ever send an outcome back. That leaves the spine. Ask the agent what it supports, ask what it can sell, book it, read delivery back. All of that is what the schemas allow, and the endpoint on the other end is free to be stricter than the schema; the only way to find out which is to call it. Where Performance Max stops and this starts Most marketers meet this idea and reach for the nearest thing they already run: Google's Performance Max, or Meta's Advantage+. Those optimisers belong to the seller and reach the seller's own inventory, so there is no second party in the conversation and nothing to negotiate. Steps 1, 3 and 7 have no equivalent inside one, because each assumes a counterparty: find out who may sell, ask a named seller what it has, book terms both sides can read back afterwards. Step 6 is the difference that matters at budget-approval time, because the policy sits on the buyer's side and the seller cannot overrule it, where inside a walled platform the rules belong to the platform. Programmatic still spends the money. Agentic buying is a pilot line, which is the argument in agentic buying versus programmatic. One campaign that ran this way Butler/Till and PubMatic ran connected TV for Geloso Beverage Group's Clubtails brand across two flights, December 2025 into January 2026, on Samsung, Paramount, Vizio and Tubi. Agents did the planning and the execution from a written brief, and a person at the agency signed off the curated inventory before anything served. The savings everyone quotes came from the vendor that sold the campaign: PubMatic's own case study puts the result at roughly an 80% cut in buy-side costs. One thing was checked from outside, and it was not the money: the verification firm Jounce audited inventory quality. The full set of figures, and who produced each one, is worth more than the headline. Two more have transacted and published no numbers at all. NBCUniversal, RPA, FreeWheel and Newton Research announced an agent-led buy across linear and streaming in January 2026, including NFL playoff inventory. Boostr and Vox Media closed a campaign-level buy through a seller-side agent in June 2026, and a Vox staffer accepted it in the ad server before it launched. The dated list of everyone else who has transacted is the deployment ledger. In both campaigns described as fully agentic, a person approved something before it ran. Step 1: who may sell this publisher's inventory The publisher puts a file at a fixed address on its own domain, /.well-known/adagents.json, naming the agents allowed to sell its inventory. It is the same idea as ads.txt and sellers.json, which do this for seller IDs, moved up a level to agent endpoints. A publisher can list the authorisations in that file or point at one central file elsewhere, which is how a network of a thousand sites manages it without editing a thousand files. The central-file option is the one with a threat model attached, and the schema writes the attack and the defence into a single field description. One deploy can change authorisation across every publisher in a network, so anything reading the file has to cap its size, refuse redirects, time out fast, and keep serving the last good copy when a fetch fails. An empty list is legal. A reader "MUST NOT read it as deny-all, authorize-all, or a revocation", because a catalog-only mirror publishes formats for a platform that never adopted the protocol. Fail closed on an empty list and you drop inventory nobody was selling. AdCP's own walkthrough skips this step and opens at discovery. What belongs in the file is covered in agent discovery files, with the field list alongside it. Step 2: the handshake The buyer's agent opens the conversation with an empty request. The call whose job is finding out what the other side speaks requires no fields at all, and the answer carries everything: which protocols the seller supports, out of a closed list of seven, and which releases it speaks. The call is getadcpcapabilities. Two things in that answer decide work you do before the first real call. The first is versioning. Send a release number like "3.1" and treat the endpoint's answer as the version you are talking to, rather than pinning the major version on its own, which the protocol is retiring. The second is authentication, and there is no single field for it. The floor is a bearer token per counterparty. Signed requests are an upgrade both sides negotiate, optional in 3.0 and required for spend-committing operations in 4.0, and sellers turn them on "selectively during per-counterparty pilots". Holding tokens for a hundred publisher agents, and knowing which one just expired, is an operations problem the protocol hands straight to you before you have made a single call. Step 3: describing the campaign The call that asks a publisher what it can sell has exactly one required field. It is buyingmode, and which of its three values you send decides the conversation that follows. brief is curated discovery: the buyer describes the campaign in plain English and the seller proposes against it. wholesale skips the conversation and hands over raw feed access against structured filters. refine is another pass over products and proposals you already hold. The brief text itself is conditionally required: mandatory when the mode is brief, forbidden when the mode is wholesale or refine. That rule lives in the field descriptions and in nothing a validator enforces. So brief mode does not actually require a brief, and a request saying "curate for me" with nothing to curate against passes validation and goes on the wire. Deciding what belongs in the brief text and what belongs in the structured filters is a real job with money attached, and Brief Gateway works through it. Everything else on the request is context the seller may use: the brand, the account, delivery preferences, a list of properties, and performance thresholds, which sit lower down than most people look. The call is getproducts. Step 4: the creative call that exists twice The buyer's agent now needs creative formats, so it calls listcreativeformats. There are two calls by that name, registered once under media buy and once under creative, pointing at two request schemas that are not the same object. | | The media-buy one | The creative one | | --------------- | --------------------------------------------------- | ------------------------------ | | Who answers | the selling agent | the creative agent | | What comes back | format IDs, plus which creative agents provide them | the full format specifications | | What it is for | finding out what this publisher accepts | finding out how to build it | The registry says it plainly once you are on the right entry: "Buyers query creative agents for full format specifications." Learn the call from the creative documentation, point it at the publisher's selling agent, and you send fields that schema has never heard of. The split is documented nowhere. That is how the trap works. Steps 5 and 6: the spend check The gate is checkgovernance, and it needs a plan to check against. A plan does not exist until the buyer has pushed one to a policy agent, so the two come as a pair and the first is easy to miss. A plan "defines the authorized parameters for a campaign", which it lists as budget limits, channels, flight dates and authorised markets. The gate takes that plan and the caller's identity and decides whether this agent, on this plan, may do this thing. The endpoint belongs to the buyer. AdCP describes the governance agent as an external service the advertiser configures on its own account. The seller receives the endpoint and credentials at account sync, calls it the way the buy-side orchestrator does, and cannot override the verdict. Policy sits with the party spending the money. Enforced is a stronger word than the protocol has earned. A buy with no plan behind it is still a legal buy, because the plan reference is required only "when the account has governanceagents". No policy agent on the account, no plan, no gate. AdCP's own trust documentation calls it "a seam, not an enforcer". Steps 5 and 6 are policy you impose on your own agent, not a lock the wire holds shut. Neither approval in the two campaigns above went through this call. They were people in a user interface, which is what most governance is today. Permission is still where this protocol spent its surface area. The permission machinery is about twice the size of the machinery that books the buy, which tells you what the people writing it were worried about. Programmatic has no equivalent, because there is nothing to validate a plan against when the unit of trade is one impression. Step 7: booking the buy Booking requires five things, and each one is an argument about how media should work. It wants a retry key, because retries are assumed and double-spending is not the buyer's problem to solve by hand. It wants an account, because a billing relationship exists before the buy does. Then it wants the brand and the start and end dates, which rule out anonymous buying and open-ended commitments. A sixth requirement is written in prose rather than in the schema, and a validator will not catch it: the buy needs either explicit line items or a reference to a proposal the seller already made, and a referenced proposal has to have been finalised first. That is the sort of rule that passes validation and fails at the counterparty. The wire-level trace has the field names and the three shapes the response can take. The rest of the request is the media plan plus paperwork: the budget, the plan reference, a purchase order number, an agency estimate number, an invoice recipient, an insertion-order acceptance record, the advertiser's industry. Nobody invents a purchase-order-number field from first principles. The call is createmediabuy. Some answers arrive days later Seven operations can accept a request, say "submitted", and finish hours or days afterwards: discovery, signals, creative build, creative sync, catalog sync, the buy and its updates. Everything else answers inline, so the slow set is short and known, and the buyer's agent either polls or registers a webhook. One of those slow answers will bite you. Alongside "still working" there is a state meaning a human or an upstream system has to supply something before the buy can proceed. A client that treats it as an error hangs on its first real campaign, and the human it is waiting for is usually on your own side. Step 8: reading delivery back Reading delivery is easy. One call returns impressions, spend and pacing, and requires nothing at all. Sending outcomes the other way is where the protocol makes a choice. The feedback call carries a single normalised performance index rather than raw conversions, and that index is the entire outcome channel from buyer to seller at 3.1.13. I think that is deliberate. The buyer normalises its own measurement and hands over one comparable number instead of a conversion definition the seller has to interpret. What travels the other way is richer: a performance standard attached to the buy names a metric, a threshold and a measurement vendor, so the vendor goes into the contract rather than the protocol trying to define measurement itself. The call is provideperformancefeedback. The vendor's diagram will use different words The two stacks do not agree on what to call the software on the sell side, and not in the harmless way where two words point at one thing. AdCP's noun is "sales agent", and it is the noun that governs who may sell; AAMP's repositories never use it. AAMP says "seller agent", which AdCP uses in prose and never defines. AdCP has a governance agent holding the buyer's policy and AAMP has nothing in that role at all. So a slide reading "buyer agent talks to seller agent" is compatible with both stacks and commits to neither, and when the diagram is the only artefact in the room, ask which of the two words is in their code. The same buy on the AAMP side runs differently in one respect that ends up in a contract. The buyer's agent finds the seller through an agent card listing skills, asks for availability against a media kit, and gets a quote the documentation is blunt about: "Quotes are non-binding price offers from the seller. They have a 24-hour TTL." Then the two bargain, with accept, counter, final offer and reject as the moves and with round limits and concession caps keyed off the buyer's access tier, and agreement turns the quote into a deal. AdCP has none of that on the wire at 3.1.13, where the nearest thing is a proposal moving from draft to committed. Every AAMP term here comes from reference-implementation code rather than a ratified specification, which is the weaker claim, and the published state diagram for an order no longer matches the code that implements it, so do not build against the diagram. Agentic Ad Lab puts the two side by side, payload by payload. How much of this is running today? Twenty-three agents were publicly listed on the AdCP registry on 12 August 2026. Three of them returned an actual product list to a caller with no credentials: Cora AI, Equativ and No Fluff Advisory. Two of those three send back the same catalogue no matter what the brief says. So the sequence above is what the specification defines, and the part a stranger can exercise this morning is step 3, on three endpoints. Everything after it needs credentials, which is right for a protocol that moves money and also why nobody outside a deal can verify the interesting half. The agent-by-agent results are on AdCP Explorer, and they make a better opening question for a vendor call than anything in a deck: which of these eight steps does your agent implement, and against which version. --- # Agentic Buying vs Programmatic Buying Source: https://whatisagenticbuying.com/agentic-buying-vs-programmatic/ Agentic buying negotiates a whole media buy over an agent protocol while programmatic clears one impression per auction in milliseconds, and whether that counts as a real difference depends on which specification you point at. Is agentic buying just programmatic with a chat box on top? Two standards bodies have already answered that question in writing, and they contradict each other. Before the answer, the difference the argument turns on. Programmatic buys one impression at a time. A page loads, an auction runs, a winner is picked, an ad renders, and the whole thing finishes in about a tenth of a second. Repeat a few billion times a day. Nothing in that loop knows what campaign it belongs to or what the campaign was for. Agentic buying moves the unit of trade up a level, to the thing a human buyer would recognise as a deal: a budget, a flight, a set of placements, terms both sides agreed. Software on the buyer's side describes what it wants, software on the seller's side proposes what it has, and the two settle it between them without a person retyping a media plan into a booking form. The impressions still clear through the old machinery afterwards. So the honest version of the sceptic's question is not "is there a chat box" but "did the unit of trade actually change". One of the two standards says yes and the other says no, in their own repositories, on the record. IAB Tech Lab's Agentic RTB Framework says no, it did not change. Line 6 of its protocol definition imports the OpenRTB 2.6 bid request, before ARTF defines anything of its own. What an ARTF agent emits is a change applied to that bid request or its response, on the exchange's millisecond clock. That is programmatic with an agent holding the knob, and the sceptic is right about this half. The Ad Context Protocol says yes, it changed, and it says so by refusal. AdCP is governed by AgenticAdvertising.org rather than IAB Tech Lab, which trips up almost everyone who meets it second: a pending 501(c)(6) trade association whose interim board of four directors holds two seats affiliated with Scope3, an ad-tech company and founding contributor to the protocol. Half the interim board of the body writing the rules works for one company building on them, and that is a governance risk to price into a build decision rather than a scandal. Someone proposed a price-quote step to that working group, sitting between discovery and commitment: submit targeting, get a firm rate back, then buy. It was turned down twice over, in the published design principles and again at the top of the product-discovery reference. A protocol that was really programmatic with a chat box on the front would have taken that proposal without blinking. Neither corpus acknowledges the other: not one file across the eight repositories under IAB Tech Lab's AAMP umbrella (Agentic Advertising Management Protocols, the initiative ARTF ships under) names AdCP at all. They sit at different layers all the same. ARTF lives inside your bidder, mutating a request you were already handling. AdCP lives in front of your inventory, as an agent a buyer's agent calls before any auction exists. A seller running both a direct business and an exchange plausibly ships both, and neither corpus publishes a word on how the two reconcile. Then there is the size of the thing. Magnite, which processes about 9 billion dollars of ad spend a year, told its August 2026 earnings call it had transacted "a handful of millions of dollars" agentically to date. The public AdCP agent registry listed 23 agents on 12 August 2026, and three of them would hand a product catalogue to a caller with no credentials. Which one should you be running today? Programmatic, at scale, still. Agentic buying is a pilot line everywhere it exists, and what it asks of you differs by which side of the wire you sit on. AdCP's required-tasks page is direct about the floor, and the floor is different on each side. - Publisher or SSP selling direct, you ship a sales agent: seven required Media Buy tasks (getproducts, getadcpcapabilities, createmediabuy, updatemediabuy, getmediabuys, getmediabuydelivery, provideperformancefeedback), served over at least one transport, with mediabuy declared in the protocols it says it supports. That is a real server, not a route on an existing one. - DSP or buying desk: you are the orchestrator, and orchestrators "are not MCP/A2A servers — they call sales agent tasks." Conformance is five behaviours. The one that costs engineering is handling the three long-running states plus webhook delivery of completion artifacts, because everything you own already assumes a synchronous auction. - Exchange or bidder, there is nothing to conform to yet. ARTF is your surface, and its proto file defines messages and enums with no service and no remote calls in it, so how a mutation actually reaches you is still the exchange's problem to define. - Brand with an agency in between: nothing this quarter. What changes it is your agency's orchestrator shipping, not either spec moving. The difference, row by row | | Programmatic (OpenRTB / RTB) | Agentic buying (AdCP 3.1.13) | | ---------------------- | -------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------- | | Unit of exchange | One impression, one auction | A media buy containing packages | | Wire format | OpenRTB 2.6 bid request / bid response | A JSON Schema registry, 64 registered operations at 3.1.13 | | Transport | HTTP POST to a bidder endpoint | MCP tools/call or A2A message/send | | The clock, declared | tmax, "maximum time in milliseconds" | status: submitted is "queued for long-running execution (hours to days)"; working is "expect completion within 120 seconds" | | The clock, buyer-side | The exchange sets tmax | The buyer sets timebudget and the seller "does not start processes... that cannot complete in time" | | How intent is stated | Targeting parameters attached to a seat | buyingmode of brief, wholesale or refine, plus a conditionally required free-text brief | | Iteration | Rebid | buyingmode: "refine" with a typed array of change requests | | Finding counterparties | ads.txt, sellers.json | /.well-known/adagents.json | | Negotiation | The auction is the negotiation | Proposals move draft to committed; AAMP's seller-agent defines accept, counter, finaloffer, reject | | Idempotency | Fire and forget | idempotencykey required on createmediabuy, minimum 16 characters | | Governance | Post-hoc blocklists and verification vendors | checkgovernance before any spend-commit request, with a required caller URL | tmax and timebudget are the same idea about six orders of magnitude apart: whoever is waiting declares how long they will wait. The agentic one spells out the consequence, too. The seller "does not start processes (human approvals, expensive external queries) that cannot complete in time." An exchange with a 120ms tmax never had to write that sentence, because no human was ever going to be in that loop. Transport moves a build estimate more than anything else here. Adopting AdCP means standing up an agent server. Its transport page binds it to MCP tools/call or A2A message/send and says the two are interchangeable: "If a call works on one, the equivalent call works on the other." That page also says AdCP MCP servers no longer publish per-tool parameter schemas when a client lists the available tools, where "every tool shows {type: 'object', properties: {}}". Runtime introspection will not tell you the shape of anything, so you validate against the registry version you pinned at build time and ask the agent on the other end what it supports. The free-text brief is conditionally required rather than optional: required when buyingmode is brief, forbidden when the mode is wholesale or refine. That mutual exclusion is written into the field descriptions and into no validated conditional, so a validator will pass a request that breaks it either way. The only unconditionally required field in the whole getproducts request is buyingmode itself. A buyer in wholesale mode still never writes a sentence, which is the interesting half. Performance Max is a different kind of automation Most marketers reach past programmatic for a closer comparison: Google's Performance Max, or Meta's Advantage+. Set a budget and an objective, and the platform's optimiser picks the placement, the audience and often the creative. If software already decides where the money goes, what does an agent add? Nothing you would call intelligence. The optimiser belongs to the seller and it reaches the seller's own inventory. It has no counterparty, so there is nobody to describe a campaign to, nobody to send terms back, and no record of what was agreed, because nothing was agreed. And it does not travel. Take Performance Max off Google and nothing is left to run. An agentic buy inverts the ownership. The deciding software is yours or your agency's, it talks to any publisher's agent that publishes an endpoint, and the terms are fields on a wire you can log: budget, dates, brand, placements, the price accepted. TensorOps' 2026 field guide draws the same line, black-box optimisers confined to a single platform against a layer that can reason across several. An agent decides inside limits you set, and if you set none you have swapped one black box for another with your own logo on it. What you gain is the record: Performance Max tells you what the campaign spent, while an agentic buy leaves you what was asked, what was offered and what was accepted. Where that record stops is what neither protocol standardises. AdCP turned down the price-quote step and published its reasoning The proposal was a firm price quote sitting between discovery and commitment. AdCP's design principles say no on the grounds that rate cards, firm prices and an iteration mode already exist, so "the 'new task' framing assumes targeting and pricing are missing from discovery; they aren't." The product-discovery reference restates it in one line: the split "splits one expert decision into two underspecified ones and breaks the brief→curation contract." That is an argument about who knows what. It never mentions latency, or whether a language model belongs in the loop. How convincing it is depends on what you sell. On premium supply it holds: the seller knows things about its own inventory the buyer cannot infer, so making the buyer specify targeting first and receive a price second forces both parties to guess at the half they cannot see. On commodity supply it does not, because the price is knowable up front and the refusal costs a round trip to learn what the rate card already knew. The same section then concedes three real gaps: pricing that depends on flight dates and a total budget the buyer has not committed yet, a time-bound firm rate issued before commitment, and an auditable account of what drove the price. The refusal and the concession sit in the same file, which is the opposite of the position ARTF took. IAB Tech Lab's answer is in the protobuf ARTF's agentic unit is a mutation: an intent, an operation, a path and a payload. The operations are add, remove and replace, and the paths are JSON pointers into the bid object — a user's segment list, one impression, a deal inside a private marketplace, a bid from a seat. This is JSON Patch against OpenRTB with a taxonomy of reasons attached. What those mutations are for is the interesting part. Eight named intents ship in v1.0, and in English they are: turn segments on, turn deals on, turn deals off, move a floor, move a margin, shade a bid, attach metrics, attach campaign IDs. That is the whole vocabulary, and all but two of them adjust the terms of trade on inventory that already exists. No brief anywhere in it, no product, no proposal, no counterparty to negotiate with. The lifecycle has exactly two stages, publisher bid request and DSP bid response, with the comment "More to be added" sitting under them. There is a file-by-file breakdown of that repository and a full AdCP-versus-AAMP side-by-side on the other sites. If the definition of agentic buying is "software decides instead of a human," ARTF qualifies and always did. If the definition is "the unit of exchange changed," it does not come close. Vendor decks routinely use the first definition while showing diagrams of the second, and that is where most of the confusion in this category comes from. Where the clean two-layer story breaks down The tidy version, where programmatic owns the impression and agentic owns the campaign, is repeated everywhere including here. It survives until you reach Trusted Match, which is AdCP's decisioning surface at ad-call time. A publisher's router fans a request out to buyer agents and asks two uncorrelated questions: which of the packages already bought against this property fit this page, carrying no user identity, and which fit this user, carrying no page context. The spec "targets sub-50ms end-to-end latency (publisher → router → agents → router → publisher)," with agent-side p95 under 30ms and a per-provider timeout defaulting to 50ms. AdCP's own FAQ prints a timing row calling agentic "Asynchronous (seconds to days)" — true of most of the surface, false of the part built to sit next to the auction. The asynchrony on the other side of the line is thinner than advertised too. The documentation says every mutating task ships a long-running path; seven operations actually publish one, and the mutating calls that publish none of them include the plan, account, property-list, signal-activation and rights calls you need before you can spend anything. The generic envelope carries asynchrony everywhere instead: every response requires a top-level status, and the description is blunt that agents shipping without one are non-conformant. The envelope is the real mechanism and the documentation describes an intention, which stops being an academic distinction the moment somebody picks a stack on the strength of what the documentation promised. Does agentic buying replace real-time bidding? No. Both specs say so on their own pages, from opposite directions. AdCP's FAQ describes a publisher's agent accepting a createmediabuy from a buyer agent and then using OpenRTB internally: "AdCP handles the workflow; OpenRTB handles the auction." The same page notes that one createmediabuy can spawn thousands of impression-layer events. ARTF mutates a bid request, and there is no version of that proto in which the bid request goes away. If someone tells you agentic buying kills RTB, ask which schema field they are pointing at. There is not one. Measurement, fraud and reconciliation are left to you Measurement gets delegated and then contracted. A performance standard requires a metric, a threshold and a vendor, with an optional named standard because MRC and GroupM define materially different viewability thresholds. Buyers screen on those standards inside the filters on the discovery call, and once a package is confirmed the creative has to carry that vendor's tracker script or pixel. Programmatic runs the measurement itself. AdCP writes the measurement vendor into the purchase order and leaves the running to them. The feedback call centres on a normalised performance index where 1.0 is expected. Everything else in the request is metadata about what that number means. One number is the entire quantitative signal a buyer sends a seller about whether the buy worked. Invalid traffic sits outside both stacks, but not equally. AdCP names IVT across its documentation, invalid traffic is one of five values in its performance-metric list, and its known-limitations page is explicit that "GIVT/SIVT filtration (per MRC), viewability measurement (per the MRC Viewable Ad Impression standard), and brand-safety verification execute in the delivery stack or the chosen vendor layer." Across all eight IAB Tech Lab agentic repositories, invalid traffic is not mentioned once, and neither is AdCP. Reconciliation is the largest of the gaps, and the running list of the others lives on the hub. The delivery call returns the seller's own numbers against a reporting period and a currency, and that is where the registry stops. No operation compares them to what the buyer's ad server counted, none raises a discrepancy, and neither corpus says whose number wins when the two disagree. So the discrepancy lands where it lands today, in a spreadsheet and a thread between two ops teams, and whoever builds against AdCP writes that matching layer themselves before the first invoice. The money that has actually moved IAB's 2026 digital video release, dated 5 May 2026, puts 21% of digital video buyers live with agentic AI, 20% testing and 25% planning. Read that 21% against the definitional problem the ARTF proto exposes: roughly 400 decision-makers self-reporting against a term the two standards bodies cannot agree on, so a chat interface driving an existing DSP counts as live and so does a bid shader. The survey also closed in March. What has been transacted is smaller than the survey sounds, and named. Butler/Till and PubMatic ran connected TV for Geloso Beverage Group across two flights from December 2025, and the results everyone quotes came from PubMatic: roughly an 80% cut in buy-side costs in its own case study, 82% of demand-side platform tech fees as Digiday reported it, plus 40% more impressions than planned and about 30% lower effective CPM. The verification firm Jounce audited inventory quality, and that is the only part an outside party checked. One comparison exists that no party to the campaigns produced. The analytics firm DataBeat, using May 2026 data from one ad network, put average CPMs at $6.95 for conventional demand against $6.13 for agentic demand, a 13.4% premium paid by conventional buyers, alongside 86% fewer auctions entered. Which way that cuts is unclear: agents clearing cheaper is consistent with avoiding overpayment and equally consistent with winning inventory conventional demand had already declined, and entering far fewer auctions says they were bidding on a much narrower slice of the same supply either way. It is one network and one month, and DataBeat sells analytics into this market. Everything else in circulation came from the vendor that sold the campaign, and the deployment ledger marks each figure with who produced it. The step-by-step trace walks one buy from discovery through to the performance report, and the running tally of what has shipped is kept separately. The strongest objection is about trust. At Digiday's Programmatic Marketing Summit in New Orleans in December 2025, the buyers Digiday quoted named hallucination as the reason they were not handing activation to language-model agents: an agent that slips a decimal place spends money that is not coming back, and as one of them put it, that is "a fireable offense." AdCP does have a pre-commit gate and it does not close this. A buyer agent MUST call checkgovernance before sending any spend-commit request, but that call establishes whether this caller is allowed to spend against this plan, which is authorisation rather than arithmetic. Nothing in either registry checks whether the number the model just produced is sane, and neither specification pretends otherwise. --- # About This Site and Who Pays for It Source: https://whatisagenticbuying.com/about/ This site answers one question in plain English for people who buy or sell advertising: what agentic buying is, how it works, and how much of it is real. It is written by an operator who sells work in the field he writes about. What this site answers What agentic buying is, how a buy actually runs, how it differs from programmatic, and how much of it is real yet. It is written for someone who buys or sells advertising and heard the phrase at a conference. Two figures get quoted everywhere with Dynatrace's name on them: 59% for security, 55% for accuracy. Neither is in Dynatrace's own release, and neither traces to any primary source. The maturity page prints the real numbers next to the phantom ones. Where a primary source and the press coverage of it disagree here, the primary source wins, and no page on this site predicts a date. Where a specification says nothing on a point, the page says so and stops. Guessing produces a plausible sentence with nothing behind it. I sell work in this field Constantine Mirin, chief executive of Postindustria, where I build agentic systems that have to survive production. That is how I ended up reading two advertising standards line by line. I also sell work in this field, and that is the disclosure worth leading with. Agentic Ad Lab, the sister site to this one and the technical half of it, publishes what that work is: integration and readiness reviews for companies deciding whether to expose a buying or a selling agent. That includes an audit of which of the 64 operations in AdCP — the protocol most live deployments run on — a given role actually needs. A sales agent selling media is required to implement seven of them, and a buy-side orchestrator implements none and calls them instead. Non-affiliation costs me nothing. An invoice could bend a page. Neither standards body has any say over this Two organisations are writing the rules. AgenticAdvertising.org maintains AdCP under Apache 2.0 and claims 123+ members on its homepage, Yahoo, PubMatic and Scope3 among them. IAB Tech Lab publishes AAMP and the reference implementations under it. Neither is a client. I am a member of neither, and nobody at either has read a word of this, let alone approved it. Trademarks belong to their owners. There is no AdCP-versus-AAMP table on this site. That comparison lives at Agentic Ad Lab with the payloads attached, and a thinner copy of it here would make both worse. How to report an error Send the page, the sentence, and what it should say instead, to hello@agenticadlab.com. If the defect is upstream and the specification itself is wrong, an issue on that repository fixes more than a correction here does. --- # Is Agentic Buying Real Yet? What Has Actually Shipped Source: https://whatisagenticbuying.com/maturity/ Agentic buying is real in parts. Eight named deployments have transacted since December 2025, most of them on the same protocol, and the most optimistic industry forecast for 2027 agentic ad spend is under a billion dollars. Nothing yet runs end to end unattended. Partly, and the real part is smaller and more specific than either the vendors or the sceptics say. Eight named deployments have actually transacted since December 2025. Exactly one advertiser has put its name to any of them: Geloso Beverage Group, whose Clubtails brand ran a connected-TV campaign across Samsung, Paramount, Vizio and Tubi over two flights from December into January. Software planned and executed it from a brief written in ordinary English. A person at the agency, Butler/Till, signed off the inventory list before it ran. The money is the part that rarely makes the coverage. Michael Barrett, chief executive of the exchange Magnite, said the most optimistic 2027 forecasts he could collect at Cannes put total industry spend bought this way at 600 to 700 million dollars. Magnite alone processes about 9 billion dollars of ad spend a year. The whole category next year, at its most hopeful, is four weeks of one exchange's pipe. A software team can build against a published standard today. Nowhere does the chain run brief to booking to invoice with nobody watching, and nothing is close to it. Eight deployments have transacted since December 1. Butler/Till and PubMatic, for Geloso's Clubtails brand, over two flights from December 2025 into January 2026. The only campaign in the set with a published performance figure, taken apart below. 2. Magnite, which built a selling agent into its SpringServe ad server in December and ran its first test buys through it. No number published. 3. NBCUniversal, the agency RPA, FreeWheel and Newton Research, who transacted a single premium video investment across linear and streaming in the first quarter of 2026, including live NFL playoff inventory. Buy-side and sell-side software negotiated it. No number published. 4. Yahoo, which opened its demand-side platform to outside agents in January. A trafficking agent built by Newton and RPA has executed programmatic guaranteed buys through it, the kind where the impressions and the price are fixed in advance. No number published. 5. PubMatic, which reports more than 4,000 agentic deals transacted by the second quarter. That is an unaudited operating metric in an earnings release rather than a spend figure. 6. Omnicom, which told investors in April that it had run live client buys on agent-to-agent infrastructure, with the stated aim of shrinking what the intermediaries in the middle take. No number published. 7. Boostr and Vox Media, in June: Vox's selling agent received, negotiated and closed a campaign-level buy covering budget, audience and delivery schedule. A person at Vox accepted the buy and checked it in the ad server before it launched. No number published. 8. Magnite again, with a neutral layer connecting third-party buyer agents to its supply, launched in June. On the August earnings call it put the total transacted that way at a handful of millions of dollars. Every performance number came from a company selling the software Five of the eight published nothing at all. The one number in circulation is from the Clubtails campaign: a 5.5x improvement in buy-side supply-chain cost efficiency, which comes out at roughly an 82% cut in the fees the buying platform charged. It is a supply-chain figure rather than a smarter-buying figure. PubMatic removed the fee, and PubMatic published the multiple. Both of those can be entirely honest and the number still says nothing about what the software was worth, because the budget was never disclosed and nobody ran the same money the old way alongside it. One measurement in the whole set came from outside the trade. The verification firm Jounce audited the inventory on that campaign and found made-for-advertising sites — the low-quality pages that exist only to carry ads — below 1% of it. That is the only occasion a third party has looked at an agentic campaign and published what it saw, and it measured quality rather than performance. The deployments ledger keeps the dated list, with a column separating what a vendor claimed from what somebody independent measured. What to build on today Two standards are competing to be how this works. AdCP, the Ad Context Protocol, is what most of those deployments ran on; AAMP is IAB Tech Lab's set of reference implementations for the same job. Neither is one thing you adopt or refuse. Each is a stack of layers at different stages, and the stage is what decides whether you can build on it. Two counts decide it. An operation is one call the software can make: ask what is for sale, book the buy, report what ran. A conformance scenario is a published storyboard of an end-to-end flow, with the requests and responses it should produce, so two implementations can find out whether they agree before a customer does. | Layer | Status | What that supports | | --------------------------- | --------------------------------------- | ------------------------------------------------------------------------------------------------------------------ | | AdCP media-buy | Shipping | Build against it. Seven required tasks, 52 conformance scenarios, one corrective event in fourteen patch releases. | | AdCP creative and signals | Shipping, lightly tested | Build, and expect to write the flows the eight scenarios between them do not cover. | | AdCP governance and account | Specified, untested | Pin a version and watch. Twenty-seven operations and one scenario means the integrator is the test suite. | | AdCP Trusted Match | Pre-production, per its own maintainers | Wait. Twelve experimental files, no scenarios, and a shape that has already broken twice. | | AAMP reference agents | Running, tested, unratified | Runnable today if the commit is pinned, and the contract under them can move without notice. | | agentic-direct | Mock | Nothing to integrate. Every handler returns a fixture. | | agentic-audiences | Empty where the schema goes | Nothing to integrate. The agent interface file is zero bytes. | If you operate a sales agent or an orchestrator, the media-buy row is actionable now and the rest is planning. If you buy through a demand-side platform or sell through a supply-side platform — the buying software and the selling software either side of an ad — none of it lands until your platform ships an endpoint, and nothing here tells you when that is. None of those statuses is fixed. Four changes would move them: - Fill the zero-byte files in agentic-audiences, and the claim that AAMP's audience data plane has no agent interface inverts. - Give the shared library both AAMP reference agents depend on a release, or simply list it in AAMP's own README, and the unlisted-dependency problem goes away. - Publish a ratified IAB Tech Lab specification separate from the reference implementations, and the code-is-the-specification reading ends outright. This is the least likely of the four. - Write conformance scenarios for AdCP governance or Trusted Match, and two more rows turn over. Only three registered sales agents will talk to a stranger There is a public directory of AdCP agents, maintained by AgenticAdvertising.org, and it is the cheapest reality check anybody can run. On 12 August 2026 it listed 23 agents. Thirteen completed an anonymous connection. Six sales agents exposed the product-discovery call to a caller with no credentials, and three of those returned an actual catalogue of things to buy. The protocol's own public test agent would not answer without credentials. Two of the three returned the same catalogue for every brief submitted, including one a single character long, which means two of the three are not reading the brief at all. The agent-by-agent results list each endpoint and what it answered. Three is a small number and it is not zero, and that is the useful part. A buy-side integration can be tested against something that answers before anyone signs anything. The survey number everyone quotes counts something else The best-sourced adoption figure is IAB's own, from the 2026 Digital Video Ad Spend and Strategy Report published 5 May 2026, fielded 20 February to 13 March with Advertiser Perceptions and Guideline: Two in three buyers are live (21%), testing (20%), or planning to use (25%) agentic AI for digital video campaigns in 2026. Live is 21%. The other 45% is intent, and intent converts unevenly. A further 28% are investigating and 6% say it is not on the roadmap. IAB supplies the caveat itself, and it is the important half. The use cases behind that 21% are media planning and buying recommendations, inventory discovery and evaluation, and creative testing, each cited by roughly half of the live-testing-planning group. The report notes that use declines as processes become external-facing. Those are decision-support workloads. A planner accepting a recommendation from software is not a machine placing an order, and nothing in the report says those buyers are sending the call that actually books the media. One standard is a contract you can pin, the other is running code AdCP is a version number you can write into an agreement: pin it, and both sides know what they agreed to. AAMP is eight independently versioned repositories in IAB Tech Lab's GitHub organisation, and what the two sides have agreed to is whatever the code does that week. Who stands behind each one runs the same way. AdCP is published by AgenticAdvertising.org, a pending 501(c)(6) trade association incorporated in Delaware, whose charter names four interim directors, two of them from Scope3, with an elected board due after the first annual meeting. Across AAMP's eight repositories there is no charter, no bylaws and no intellectual-property policy, and the only written statement of governance is a single sentence saying that alignment across the repositories happens through coordination. AdCP ships a stable release every three or four days The published stable release is 3.1.13. It registers 64 operations across ten areas and stamps itself stable. The 3.0.0 release is dated 22 April 2026 and 3.1.13 is dated 11 August 2026. Across the 111 days between them, AdCP published 32 stable releases. That cadence has a cost, and the changelog is unusually honest about paying it. Release 3.1.3 was withdrawn, and 3.1.4 restored the previous contract by removing a field that should never have shipped in a patch. The withdrawn release stays published as a record of what happened. Two more releases on the same line changed a shape that implementers had already built against. Fourteen patch releases, and three of them broke or corrected something. That is a project shipping faster than it can review. It is also a project that writes every one of those events down and argues each against a published policy, which is more discipline than most standards bodies manage. Budget for movement, then, but budget it against a surface much smaller than 64. Seven tasks are marked required for a sales agent selling media: list what is for sale (getproducts), declare what the agent supports (getadcpcapabilities), book a buy (createmediabuy), change one (updatemediabuy), list them (getmediabuys), report delivery against one (getmediabuydelivery) and take performance feedback (provideperformancefeedback). Everything else is conditional on a capability the agent declares for itself. Buy-side orchestrators implement none of them; they call them. Of the three corrective events, one touched that required set. The other two were both inside Trusted Match, which the release itself flags as experimental. The repository trips people up in one specific way. Its working branch still declares version 3.1.1, and a 65th operation for syncing an agent's notification settings (syncagentnotificationconfigs) sits on that branch and appears in no published release. If a deck shows you 65 operations, or a version of 3.1.1, it is quoting the development branch rather than the shipped one. AdCP's own documentation has the same problem: a comparison table in the repository still gives the protocol a maturity of 3.0 GA, more than thirty stable releases behind the registry sitting a few directories away. The governance layer has never been tested against another implementation Fifty-two of AdCP's 69 conformance scenarios test a single area, media-buy, which holds 11 of the 64 operations. | Area | Operations | Conformance scenarios | Files flagged experimental | | ---------------------- | ---------- | --------------------- | -------------------------- | | media-buy | 11 | 52 | 2 | | governance | 22 | 1 (+3 specialisms) | 8 | | creative | 8 | 7 (+1 specialism) | 0 | | brand-protocol | 6 | 2 (+1 specialism) | 10 | | account | 5 | 0 | 0 | | sponsored-intelligence | 4 | 1 | 14 | | protocol | 3 | 0 | 1 | | signals | 2 | 1 (+1 specialism) | 0 | | trusted-match | 2 | 0 | 12 | | compliance | 1 | 0 | 0 | Sixty-four of the 69 track a protocol area. The other five track a capability a seller declares for itself rather than an area of the protocol, and are bracketed separately above. Governance is the largest area in the registry, 22 of the 64 operations, and it has one scenario. Trusted Match has two operations, twelve schema files carrying an experimental flag, and no scenario at all. Its full surface is on AdCP Explorer. For anyone integrating, that cashes out plainly. Build against the 22 governance operations and you can check your payloads against the schema. That is the end of what you can check. There is no published flow to run your endpoint through, and no artifact anywhere showing that two implementations have ever completed a governance exchange between them. You write that suite yourself and find out whose reading was wrong on the first call with a counterparty. AdCP's maintainers wrote the interpretation of that themselves, in a changelog entry dated 3 August 2026 explaining why a breaking reshape was allowed inside a patch release: Why 3.1.x, not 3.2 — bounded pre-production correction. TMP has no production use yet, and this corrected shape will be in place before any 3.1 TMP production deployment ships. A maintainer writing that down is worth more than any survey. The published release also ships 53 schema files marked experimental inside a tree labelled stable, six of them in shared files no single area owns, and nothing on the outside of the release says which parts are which. In AAMP, the code is the specification AAMP documents 143 operations across its eight repositories. The seller and buyer reference agents account for 101 of them, and those 101 are documented from the code that implements them. No specification sits behind them. | Origin | Operations | | ------------------------ | ---------- | | seller-agent | 87 | | agentic-direct | 33 | | buyer-agent | 14 | | iab-agentic-primitives | 8 | | agentic-rtb-framework | 1 | The table understates one row badly. All 33 tools in agentic-direct route through one function that returns a canned answer, under a comment telling whoever picks it up to replace it with a real implementation in production. The two repositories that behave like wire specifications, iab-agentic-primitives and agentic-rtb-framework, account for nine of the 143 between them. | Repository | Tag | Last commit | What it contains | | ------------------------ | -------- | ----------- | ---------------------------------------------------------------------------------------------- | | AAMP | none | 2026-04-16 | A README and a licence. That is the whole repository. | | agentic-direct | none | 2026-01-27 | A machine-readable list of calls wrapping IAB OpenDirect 2.1. Every handler returns mock data. | | registry-agent-example | none | 2026-02-24 | One commit, and it consumes a registry it does not specify. | | agentic-audiences | none | 2026-07-27 | A draft embedding-exchange spec, a taxonomy, a scoring service. | | agentic-rtb-framework | v1.0 | 2026-07-21 | A written specification with working code under it. The most spec-shaped repository here. | | iab-agentic-primitives | v0.5.0 | 2026-07-28 | The shared wire contract both agents depend on. | | buyer-agent | v2.3.0 | 2026-08-05 | Demand-side reference implementation, and the most documented thing in AAMP. | | seller-agent | v2.4.1 | 2026-08-05 | Supply-side reference implementation, and the biggest codebase in AAMP. | The engineering is real. Both reference agents carry test suites that run on every change, and a team could pull them today and build them. Three of the eight repositories have taken no commit since 9 May 2026. The hub is where it comes apart. AAMP's own README lists six repositories and says releases are published as tags, while half of what it points at has never been tagged, three of those six included. iab-agentic-primitives, the shared library both reference agents depend on, is not listed there at all, and both of them pin it at v0.5.0 — a version its own authors describe as unreleased, with interfaces that may change without notice. Version numbers declared inside these repositories disagree with the tags on them in both directions, so asking what version this is gets two defensible answers. Then agentic-audiences, where four files under specs/ are zero bytes. One of them is specs/v1.0/schema/agentinterface.schema.json, the buyer-to-seller interface that would connect the audience data plane to the rest of AAMP, and the specification document beside it is headed "Draft v0.1" inside a directory named v1.0. IAB Tech Lab announced a release on 30 July 2026 that included the line that Agentic Audiences v1.0 is ready for transactions; that repository has no tags at all. Both statements can be true, since the release may point at something living somewhere else, but the version anyone can check out is the empty one. The repository-by-repository read has the file list. The seller agent's own documentation completes the picture, in a note saying its registry integration is stubbed pending the public API specification and will be updated once the AAMP spec is finalized. So if you are weighing whether to support AAMP now, that is what you are weighing: running code and a pre-release library, not a document anyone can be held to. Which of those two problems hurts more, an unwritten specification or a thinly tested one, is what the AdCP-versus-AAMP choice actually turns on. Security and staffing stop it, not the protocols The broadest measurement available is Dynatrace's The Pulse of Agentic AI 2026, released 22 January 2026. It surveyed 919 senior leaders at enterprises above $100M revenue, fielded by Y2 Analytics in November and December 2025. | Barrier to moving agentic AI into production | Share | | ------------------------------------------------------------ | ----- | | Security, privacy or compliance concerns | 52% | | Technical challenges managing and monitoring agents at scale | 51% | | Shortage of skilled staff or training | 44% | The same study reports roughly half of agentic AI projects still at proof-of-concept or pilot stage, 69% of agentic decisions still verified by a human, and 13% of organisations running fully autonomous agents. Two other figures get credited to that report and are not in it: 59% for security and data privacy, 55% for accuracy and reliability. Neither appears in the release and neither traces to any primary source. A 59/55 pair carrying Dynatrace's name came from somewhere else, and if a deck shows it to you, that is the deck to stop trusting. That study covers enterprise IT generally. The advertising-specific blockers are narrower and worse. You can check your payloads against a schema for most areas, but there is no published flow to run them through. The library both AAMP reference agents depend on tells you in its own README not to depend on it. Thirty-three of AAMP's operations return a canned answer whatever you send them. None of that stops a pilot. All of it stops a finance director signing off unattended spend. Two named practitioners put the buy-side version of it on the record. Digiday's CES 2026 podcast of 13 January quotes executive editor of news Seb Joseph on buyers finding agentic AI "more interesting than urgent", because "everyone wants to do things faster, cheaper, better. But ultimately, that is about everything up until an ad is bought." Greg Langer, VP of programmatic supply at Havas Media Network, was blunter at Digiday's Programmatic Marketing Summit in May: "Agentic AI still hallucinates. There's still that issue that if it doesn't know the answer, it just makes one up." That is a buy side that is interested and funded and still not handing over the card. ---