Plans
Learn Library

AI Is Buying Your Traffic Now. Have You Ever Audited What It Trusts?

A learn article on agentic media buying: it examines AI agents that execute ad campaigns autonomously, cites PropellerAds Q2 2026 ad-safety data and IAB surveys on malware and cloaking, and argues that risk signals and human review should sit inside the agent's decision loop.

ai-marketingadsevidence
2026-10-08SupaMarketers9 min read

A few days ago, an old friend who works in media buying invited me to dinner.

At the table he was thrilled. He'd just pulled off something big: he handed a large chunk of his day-to-day campaign management to an AI agent. Set the goal, set the budget, and from then on — adjusting bids, swapping placements, killing underperformers — it did it all by itself, no human sign-off required.

How did it go?

He pulled out his phone and showed me the dashboard: customer acquisition cost, down almost 30%.

He said that from now on, his team just needs to "watch the results."

I said, congratulations. But don't celebrate yet — let me ask you a question: this agent that spends money on your behalf, have you ever audited what it trusts?

He froze.

That frozen look was worth a lot. Because just a couple of days earlier, I had come across PropellerAds — an ad platform that processes more than 15 billion ad impressions every day — publishing its ad-safety data for Q2 2026. That dataset is the best possible footnote to this exact question.

Let's start from the beginning.

What Is Agentic Media Buying?

What is agentic media buying?

Put simply: AI goes from advisor to operator.

In the past, AI assisted: it generated reports, guessed audiences, wrote copy — but a human always made the final call. Today's AI executes: it looks at the data itself, makes its own judgment, adjusts budgets on its own. For the vast majority of the steps, nobody needs to sit next to it nodding.

How fast is this change happening?

In its 2026 Outlook Report, IAB (the Interactive Advertising Bureau) surveyed the buy side: 96% of ad buyers have heard of using AI agents to buy ads; 66% are already increasing their investment in it.

Wow. This is no longer a "trend forecast" — it's reality, happening right now.

Agents are moving from the seat that watches the dashboard to the seat that holds the steering wheel. And human approval, which used to cover every press of the gas pedal, is shrinking down to a few key intersections.

The Old Guardrails Only Guarded Half

Once people let go, everyone's first reaction is the same: add guardrails.

IAB put out another report in July 2026 that captured this mindset very precisely: 96% of digital video buyers accept the agent's role in programmatic buying; at the same time, 40% require a human in the loop, 36% require audit trails, and 31% require drawing clear boundaries between what agents can and cannot do.

Budget caps, human approval, traceable logs.

Every one of these guardrails is correct. But reading them, I had only one reaction: all of these guardrails govern "how much money gets spent."

Nobody has answered the more lethal question: is what the agent trusts actually right?

Cheap Conversions May Be a Clocked Car

Back to my friend. In theory, this is exactly how his agent could crash.

Suppose a media-buying agent's task is to drive acquisition cost down. It scans the field and finds a traffic source whose conversions are especially cheap. The numbers look beautiful, so it moves money there. The more it spends, the better the "results" look, and the harder it pushes.

The dashboard: all green.

Where's the problem? The problem is that AI can rarely get the full context. Look one step upstream, and the same set of numbers might be a different picture entirely: the behavior on the landing page is off; one of the redirects switches to a suspicious domain midway; the traffic-quality system has been flashing yellow for a while.

It's like buying a secondhand car at an absurdly cheap price. Clean dashboard, lovely mileage, irresistible price.

Until one day the engine has a problem, you open the hood, and discover: the odometer had been rolled back.

There are two kinds of cheap conversions: genuinely cheap, and "cheap for now." An agent cannot tell them apart — unless you hand the safety signals to it directly.

This is not scaremongering; the data speaks.

In PropellerAds' Q2 data, the total number of rejected ads fell 42% quarter over quarter, from 36,085 to 20,790. The overall volume was ebbing. But within it, rejections related to viruses and malware rose from 23.3% of the total in Q1 to 45.9% in Q2, and grew another 14% in absolute terms.

On one side, the total is receding; on the other, malware is crowding deeper into the rejection list.

One thing to note: this is PropellerAds' own platform review data, reflecting what it sees on its platform; it cannot be taken directly as a measure of how far malware has spread across the whole market. But precisely because it is "first-party data," the signal is all the more striking: even a platform that swims in traffic every single day can visibly see malware squeezing into its rejection list.

And there's an even more stubborn opponent: cloaking.

What is cloaking? Showing different content to different "viewers." When the review system comes to inspect, it sees a well-behaved online store; when real users come in, the door they push open is a different one.

It's exactly like dealing with hygiene inspections as a kid: on the day the teacher came, the classroom was so clean you could see your reflection in it.

How stubborn is it? In Q2, cloaking accounted for 67.3% of advertiser bans; in Q1, it was 68.1%. Almost no movement.

External data tells the same story. In GeoEdge's published malicious-ad data, auto-redirects account for 45% of all attacks, up 25% year over year.

So you see, that CPA number on the dashboard may be just one gauge among several — and not necessarily the most critical one at this moment.

The Brakes Can't Sit in the Trunk

So what do we do?

Two roads ahead.

The first: optimization does optimization, safety does safety. The optimization system chases the data; the safety system watches from outside the loop and steps in after something goes wrong. In the era when humans managed budgets, this was barely enough, because the human standing in the middle was a natural buffer.

But now, agents can spend money by themselves. On the strength of "the numbers got better," they can raise bids, shift budgets, scale up. So why should safety signals be relegated to watching from outside the loop?

The second road: wire the risk signals into the same decision loop.

Optimization is the gas pedal, safety is the brake. The brake cannot be installed in the trunk; it has to sit at the driver's foot.

Numbers improve: press the gas, scale up. Something looks off: ease off the gas, slow down, gather evidence a little longer. Alarm sounds: pull over, call a human to take over.

Let risk and opportunity sit in the same meeting room.

Otherwise, the safety system will always be correcting errors — and always several intersections after the car has blown past its exit.

Humans Belong in the Gray Zone

"Human in the loop" — those four words sound extremely correct.

But think about it: if every single step needs a human nod, what happens?

Every bid adjustment needs approval, every source swap needs approval, every budget shift needs approval. Then this thing is not an agent anymore — it's a machine that needs a human chaperone the whole way. The human regresses from operator to an assistant cleaning up after the AI. Busy, truly busy; valuable, truly not.

The smart split is to put the human in the gray zone.

What does the machine do? Scan massive volumes of signals, recognize repeating patterns, handle routine decisions where the evidence is clear and the risk is low. At these, it's a hundred times faster than a human.

What does the human do? Handle the moments that "can't be pinned down": results are great but the safety signals look strange; a brand-new pattern that no rule fits; amounts big enough to deserve another pair of eyes.

PropellerAds' own AI agent, NIKO, divides the work exactly this way. Pulling quotes, checking targeting, querying account data — it does those itself at full speed; but the moment something would actually touch campaigns or budget, it stops immediately, lays the full parameter set in front of a human, and executes only after confirmation.

Low-risk zone: runs flat out. High-risk zone: brakes firmly. That's how "human in the loop" is supposed to work.

Oh, and one more thing: leave a trail.

In that same July IAB report, 36% of buyers wanted audit trails — all for the sake of "explainability." What should the audit record? Breadcrumbs: what the agent saw at the time, which signals influenced it, on what basis it decided to scale up, slow down, or escalate.

When real money is flying out automatically, one sentence — "the model decided" — explains nothing.

Two Loops, Neither Optional

Think back: for years, media-buying optimization has been practicing one move: chase opportunity.

Where are conversion odds highest? Where is the next dollar best spent? Which source deserves more budget? AI answers these faster than any human.

But once an agent takes over execution, it needs a second loop: watching for risk.

Is this traffic normal? Do the signals line up with one another? In the second half of the user journey, is anything going wrong? In this scenario, is it still the agent's call to make?

My judgment: these two loops must live in the same operating system. Not one chasing opportunity in the office while the other counts risk on the rooftop.

An agent that buys traffic on your behalf must be able to press the gas — and to brake.

At that dinner, this is how I left it with my friend: acquisition cost down 30% is worth being happy about. But before you celebrate, go ask your agent where that 30% came from.

If it can answer — congratulations, you have hired a good driver.

If it can't… then inside that 30% may be hiding a few clocked cars. The dashboard is still glowing green all the way, while the engine, somewhere you can't see, has already started to smoke.

Here's wishing you: may every cheap car you buy be cheap for real.

Continue reading