Is Agentic Buying Real Yet? What Has Actually Shipped
Agentic buying is real in parts. Eight named deployments have transacted since December 2025, most of them on the same protocol, and the most optimistic industry forecast for 2027 agentic ad spend is under a billion dollars. Nothing yet runs end to end unattended.
Partly, and the real part is smaller and more specific than either the vendors or the sceptics say.
Eight named deployments have actually transacted since December 2025. Exactly one advertiser has put its name to any of them: Geloso Beverage Group, whose Clubtails brand ran a connected-TV campaign across Samsung, Paramount, Vizio and Tubi over two flights from December into January. Software planned and executed it from a brief written in ordinary English. A person at the agency, Butler/Till, signed off the inventory list before it ran.
The money is the part that rarely makes the coverage. Michael Barrett, chief executive of the exchange Magnite, said the most optimistic 2027 forecasts he could collect at Cannes put total industry spend bought this way at 600 to 700 million dollars. Magnite alone processes about 9 billion dollars of ad spend a year. The whole category next year, at its most hopeful, is four weeks of one exchange’s pipe.
A software team can build against a published standard today. Nowhere does the chain run brief to booking to invoice with nobody watching, and nothing is close to it.
Eight deployments have transacted since December
- Butler/Till and PubMatic, for Geloso’s Clubtails brand, over two flights from December 2025 into January 2026. The only campaign in the set with a published performance figure, taken apart below.
- Magnite, which built a selling agent into its SpringServe ad server in December and ran its first test buys through it. No number published.
- NBCUniversal, the agency RPA, FreeWheel and Newton Research, who transacted a single premium video investment across linear and streaming in the first quarter of 2026, including live NFL playoff inventory. Buy-side and sell-side software negotiated it. No number published.
- Yahoo, which opened its demand-side platform to outside agents in January. A trafficking agent built by Newton and RPA has executed programmatic guaranteed buys through it, the kind where the impressions and the price are fixed in advance. No number published.
- PubMatic, which reports more than 4,000 agentic deals transacted by the second quarter. That is an unaudited operating metric in an earnings release rather than a spend figure.
- Omnicom, which told investors in April that it had run live client buys on agent-to-agent infrastructure, with the stated aim of shrinking what the intermediaries in the middle take. No number published.
- Boostr and Vox Media, in June: Vox’s selling agent received, negotiated and closed a campaign-level buy covering budget, audience and delivery schedule. A person at Vox accepted the buy and checked it in the ad server before it launched. No number published.
- Magnite again, with a neutral layer connecting third-party buyer agents to its supply, launched in June. On the August earnings call it put the total transacted that way at a handful of millions of dollars.
Every performance number came from a company selling the software
Five of the eight published nothing at all. The one number in circulation is from the Clubtails campaign: a 5.5x improvement in buy-side supply-chain cost efficiency, which comes out at roughly an 82% cut in the fees the buying platform charged. It is a supply-chain figure rather than a smarter-buying figure. PubMatic removed the fee, and PubMatic published the multiple. Both of those can be entirely honest and the number still says nothing about what the software was worth, because the budget was never disclosed and nobody ran the same money the old way alongside it.
One measurement in the whole set came from outside the trade. The verification firm Jounce audited the inventory on that campaign and found made-for-advertising sites — the low-quality pages that exist only to carry ads — below 1% of it. That is the only occasion a third party has looked at an agentic campaign and published what it saw, and it measured quality rather than performance. The deployments ledger keeps the dated list, with a column separating what a vendor claimed from what somebody independent measured.
What to build on today
Two standards are competing to be how this works. AdCP, the Ad Context Protocol, is what most of those deployments ran on; AAMP is IAB Tech Lab’s set of reference implementations for the same job. Neither is one thing you adopt or refuse. Each is a stack of layers at different stages, and the stage is what decides whether you can build on it.
Two counts decide it. An operation is one call the software can make: ask what is for sale, book the buy, report what ran. A conformance scenario is a published storyboard of an end-to-end flow, with the requests and responses it should produce, so two implementations can find out whether they agree before a customer does.
| Layer | Status | What that supports |
|---|---|---|
| AdCP media-buy | Shipping | Build against it. Seven required tasks, 52 conformance scenarios, one corrective event in fourteen patch releases. |
| AdCP creative and signals | Shipping, lightly tested | Build, and expect to write the flows the eight scenarios between them do not cover. |
| AdCP governance and account | Specified, untested | Pin a version and watch. Twenty-seven operations and one scenario means the integrator is the test suite. |
| AdCP Trusted Match | Pre-production, per its own maintainers | Wait. Twelve experimental files, no scenarios, and a shape that has already broken twice. |
| AAMP reference agents | Running, tested, unratified | Runnable today if the commit is pinned, and the contract under them can move without notice. |
agentic-direct | Mock | Nothing to integrate. Every handler returns a fixture. |
agentic-audiences | Empty where the schema goes | Nothing to integrate. The agent interface file is zero bytes. |
If you operate a sales agent or an orchestrator, the media-buy row is actionable now and the rest is planning. If you buy through a demand-side platform or sell through a supply-side platform — the buying software and the selling software either side of an ad — none of it lands until your platform ships an endpoint, and nothing here tells you when that is.
None of those statuses is fixed. Four changes would move them:
- Fill the zero-byte files in
agentic-audiences, and the claim that AAMP’s audience data plane has no agent interface inverts. - Give the shared library both AAMP reference agents depend on a release, or simply list it in AAMP’s own README, and the unlisted-dependency problem goes away.
- Publish a ratified IAB Tech Lab specification separate from the reference implementations, and the code-is-the-specification reading ends outright. This is the least likely of the four.
- Write conformance scenarios for AdCP governance or Trusted Match, and two more rows turn over.
Only three registered sales agents will talk to a stranger
There is a public directory of AdCP agents, maintained by AgenticAdvertising.org, and it is the cheapest reality check anybody can run. On 12 August 2026 it listed 23 agents. Thirteen completed an anonymous connection. Six sales agents exposed the product-discovery call to a caller with no credentials, and three of those returned an actual catalogue of things to buy. The protocol’s own public test agent would not answer without credentials.
Two of the three returned the same catalogue for every brief submitted, including one a single character long, which means two of the three are not reading the brief at all. The agent-by-agent results list each endpoint and what it answered.
Three is a small number and it is not zero, and that is the useful part. A buy-side integration can be tested against something that answers before anyone signs anything.
The survey number everyone quotes counts something else
The best-sourced adoption figure is IAB’s own, from the 2026 Digital Video Ad Spend and Strategy Report published 5 May 2026, fielded 20 February to 13 March with Advertiser Perceptions and Guideline:
Two in three buyers are live (21%), testing (20%), or planning to use (25%) agentic AI for digital video campaigns in 2026.
Live is 21%. The other 45% is intent, and intent converts unevenly. A further 28% are investigating and 6% say it is not on the roadmap.
IAB supplies the caveat itself, and it is the important half. The use cases behind that 21% are media planning and buying recommendations, inventory discovery and evaluation, and creative testing, each cited by roughly half of the live-testing-planning group. The report notes that use declines as processes become external-facing. Those are decision-support workloads. A planner accepting a recommendation from software is not a machine placing an order, and nothing in the report says those buyers are sending the call that actually books the media.
One standard is a contract you can pin, the other is running code
AdCP is a version number you can write into an agreement: pin it, and both sides know what they agreed to. AAMP is eight independently versioned repositories in IAB Tech Lab’s GitHub organisation, and what the two sides have agreed to is whatever the code does that week.
Who stands behind each one runs the same way. AdCP is published by AgenticAdvertising.org, a pending 501(c)(6) trade association incorporated in Delaware, whose charter names four interim directors, two of them from Scope3, with an elected board due after the first annual meeting. Across AAMP’s eight repositories there is no charter, no bylaws and no intellectual-property policy, and the only written statement of governance is a single sentence saying that alignment across the repositories happens through coordination.
AdCP ships a stable release every three or four days
The published stable release is 3.1.13. It registers 64 operations across ten areas and stamps itself stable.
The 3.0.0 release is dated 22 April 2026 and 3.1.13 is dated 11 August 2026. Across the 111 days between them, AdCP published 32 stable releases.
That cadence has a cost, and the changelog is unusually honest about paying it. Release 3.1.3 was withdrawn, and 3.1.4 restored the previous contract by removing a field that should never have shipped in a patch. The withdrawn release stays published as a record of what happened. Two more releases on the same line changed a shape that implementers had already built against. Fourteen patch releases, and three of them broke or corrected something.
That is a project shipping faster than it can review.
It is also a project that writes every one of those events down and argues each against a published policy, which is more discipline than most standards bodies manage.
Budget for movement, then, but budget it against a surface much smaller than 64. Seven tasks are marked required for a sales agent selling media: list what is for sale (get_products), declare what the agent supports (get_adcp_capabilities), book a buy (create_media_buy), change one (update_media_buy), list them (get_media_buys), report delivery against one (get_media_buy_delivery) and take performance feedback (provide_performance_feedback). Everything else is conditional on a capability the agent declares for itself. Buy-side orchestrators implement none of them; they call them.
Of the three corrective events, one touched that required set. The other two were both inside Trusted Match, which the release itself flags as experimental.
The repository trips people up in one specific way. Its working branch still declares version 3.1.1, and a 65th operation for syncing an agent’s notification settings (sync_agent_notification_configs) sits on that branch and appears in no published release. If a deck shows you 65 operations, or a version of 3.1.1, it is quoting the development branch rather than the shipped one. AdCP’s own documentation has the same problem: a comparison table in the repository still gives the protocol a maturity of 3.0 GA, more than thirty stable releases behind the registry sitting a few directories away.
The governance layer has never been tested against another implementation
Fifty-two of AdCP’s 69 conformance scenarios test a single area, media-buy, which holds 11 of the 64 operations.
| Area | Operations | Conformance scenarios | Files flagged experimental |
|---|---|---|---|
| media-buy | 11 | 52 | 2 |
| governance | 22 | 1 (+3 specialisms) | 8 |
| creative | 8 | 7 (+1 specialism) | 0 |
| brand-protocol | 6 | 2 (+1 specialism) | 10 |
| account | 5 | 0 | 0 |
| sponsored-intelligence | 4 | 1 | 14 |
| protocol | 3 | 0 | 1 |
| signals | 2 | 1 (+1 specialism) | 0 |
| trusted-match | 2 | 0 | 12 |
| compliance | 1 | 0 | 0 |
Sixty-four of the 69 track a protocol area. The other five track a capability a seller declares for itself rather than an area of the protocol, and are bracketed separately above.
Governance is the largest area in the registry, 22 of the 64 operations, and it has one scenario. Trusted Match has two operations, twelve schema files carrying an experimental flag, and no scenario at all. Its full surface is on AdCP Explorer.
For anyone integrating, that cashes out plainly. Build against the 22 governance operations and you can check your payloads against the schema. That is the end of what you can check. There is no published flow to run your endpoint through, and no artifact anywhere showing that two implementations have ever completed a governance exchange between them. You write that suite yourself and find out whose reading was wrong on the first call with a counterparty.
AdCP’s maintainers wrote the interpretation of that themselves, in a changelog entry dated 3 August 2026 explaining why a breaking reshape was allowed inside a patch release:
Why 3.1.x, not 3.2 — bounded pre-production correction. TMP has no production use yet, and this corrected shape will be in place before any 3.1 TMP production deployment ships.
A maintainer writing that down is worth more than any survey.
The published release also ships 53 schema files marked experimental inside a tree labelled stable, six of them in shared files no single area owns, and nothing on the outside of the release says which parts are which.
In AAMP, the code is the specification
AAMP documents 143 operations across its eight repositories. The seller and buyer reference agents account for 101 of them, and those 101 are documented from the code that implements them. No specification sits behind them.
| Origin | Operations |
|---|---|
seller-agent | 87 |
agentic-direct | 33 |
buyer-agent | 14 |
iab-agentic-primitives | 8 |
agentic-rtb-framework | 1 |
The table understates one row badly. All 33 tools in agentic-direct route through one function that returns a canned answer, under a comment telling whoever picks it up to replace it with a real implementation in production. The two repositories that behave like wire specifications, iab-agentic-primitives and agentic-rtb-framework, account for nine of the 143 between them.
| Repository | Tag | Last commit | What it contains |
|---|---|---|---|
AAMP | none | 2026-04-16 | A README and a licence. That is the whole repository. |
agentic-direct | none | 2026-01-27 | A machine-readable list of calls wrapping IAB OpenDirect 2.1. Every handler returns mock data. |
registry-agent-example | none | 2026-02-24 | One commit, and it consumes a registry it does not specify. |
agentic-audiences | none | 2026-07-27 | A draft embedding-exchange spec, a taxonomy, a scoring service. |
agentic-rtb-framework | v1.0 | 2026-07-21 | A written specification with working code under it. The most spec-shaped repository here. |
iab-agentic-primitives | v0.5.0 | 2026-07-28 | The shared wire contract both agents depend on. |
buyer-agent | v2.3.0 | 2026-08-05 | Demand-side reference implementation, and the most documented thing in AAMP. |
seller-agent | v2.4.1 | 2026-08-05 | Supply-side reference implementation, and the biggest codebase in AAMP. |
The engineering is real. Both reference agents carry test suites that run on every change, and a team could pull them today and build them. Three of the eight repositories have taken no commit since 9 May 2026.
The hub is where it comes apart. AAMP’s own README lists six repositories and says releases are published as tags, while half of what it points at has never been tagged, three of those six included. iab-agentic-primitives, the shared library both reference agents depend on, is not listed there at all, and both of them pin it at v0.5.0 — a version its own authors describe as unreleased, with interfaces that may change without notice. Version numbers declared inside these repositories disagree with the tags on them in both directions, so asking what version this is gets two defensible answers.
Then agentic-audiences, where four files under specs/ are zero bytes. One of them is specs/v1.0/schema/agent_interface.schema.json, the buyer-to-seller interface that would connect the audience data plane to the rest of AAMP, and the specification document beside it is headed “Draft v0.1” inside a directory named v1.0. IAB Tech Lab announced a release on 30 July 2026 that included the line that Agentic Audiences v1.0 is ready for transactions; that repository has no tags at all. Both statements can be true, since the release may point at something living somewhere else, but the version anyone can check out is the empty one. The repository-by-repository read has the file list.
The seller agent’s own documentation completes the picture, in a note saying its registry integration is stubbed pending the public API specification and will be updated once the AAMP spec is finalized. So if you are weighing whether to support AAMP now, that is what you are weighing: running code and a pre-release library, not a document anyone can be held to.
Which of those two problems hurts more, an unwritten specification or a thinly tested one, is what the AdCP-versus-AAMP choice actually turns on.
Security and staffing stop it, not the protocols
The broadest measurement available is Dynatrace’s The Pulse of Agentic AI 2026, released 22 January 2026. It surveyed 919 senior leaders at enterprises above $100M revenue, fielded by Y2 Analytics in November and December 2025.
| Barrier to moving agentic AI into production | Share |
|---|---|
| Security, privacy or compliance concerns | 52% |
| Technical challenges managing and monitoring agents at scale | 51% |
| Shortage of skilled staff or training | 44% |
The same study reports roughly half of agentic AI projects still at proof-of-concept or pilot stage, 69% of agentic decisions still verified by a human, and 13% of organisations running fully autonomous agents.
Two other figures get credited to that report and are not in it: 59% for security and data privacy, 55% for accuracy and reliability. Neither appears in the release and neither traces to any primary source. A 59/55 pair carrying Dynatrace’s name came from somewhere else, and if a deck shows it to you, that is the deck to stop trusting.
That study covers enterprise IT generally. The advertising-specific blockers are narrower and worse. You can check your payloads against a schema for most areas, but there is no published flow to run them through. The library both AAMP reference agents depend on tells you in its own README not to depend on it. Thirty-three of AAMP’s operations return a canned answer whatever you send them. None of that stops a pilot. All of it stops a finance director signing off unattended spend.
Two named practitioners put the buy-side version of it on the record. Digiday’s CES 2026 podcast of 13 January quotes executive editor of news Seb Joseph on buyers finding agentic AI “more interesting than urgent”, because “everyone wants to do things faster, cheaper, better. But ultimately, that is about everything up until an ad is bought.” Greg Langer, VP of programmatic supply at Havas Media Network, was blunter at Digiday’s Programmatic Marketing Summit in May: “Agentic AI still hallucinates. There’s still that issue that if it doesn’t know the answer, it just makes one up.” That is a buy side that is interested and funded and still not handing over the card.