What an AI agent can and cannot do inside a live ad account
An agent connected to a live ad account reads everything and changes nothing: a person makes every edit. Here is why the read side is where the money sits.
The short answer: it reads everything, and it changes nothing. That split is deliberate.
An agent connected to a live account over MCP (Claude, ChatGPT, Codex and Cursor all speak the protocol now) gets a catalog of read tools: metrics, audit findings, account signals, competitor creatives. On the write side there is nothing. No pausing campaigns. No budget changes. No new campaigns. No bid rewrites. No creative edits. No audience surgery. If that sounds thin for something the market keeps calling an agent, good. Thin is the design.
Reading is where the value sits
Most account damage stays invisible until somebody lines the numbers up side by side.
One live client account we reviewed (anonymised) scored 79.82 out of 100 on a fixed checklist. A respectable number on paper. Underneath it, 92% of the spend was going to search queries that had never produced a single request. And 27 of 27 active ads were running without a second headline. Twenty-seven out of twenty-seven. Nobody had to be careless for that: someone built the account once and moved on.
An agent surfaces that in a minute. A person needs an afternoon, on a good day, with nothing interrupting.
The conversion numbers make the point harder. Direct sweeps every Metrica goal into the conversions column by default, technical ones included. In one account the report showed 697 conversions. 652 of them were an anti-spam goal firing. Real requests: 45. Cost per request moved from roughly 2 BYN to roughly 8 BYN the moment you counted honestly. The account had not changed. The story told about the account had.
Why there is no write list at all
Every write action inside an ad account is money moving without a person in the loop. So the agent gets none. It finds the problem, does the arithmetic and explains it; a person decides and makes the change in the ad account. Even pausing a campaign, the most reversible action there is, stays with the account owner.
There is a second reason, one I learned on Yandex Direct. The platform has no native if→then automation rules. Meta ships them free inside Ads Manager; Direct simply does not have them. Everything the market advertises as auto-rules for Direct is a third-party service polling the API and pressing buttons on your behalf. An agent with broad write access there is not automating a platform feature, it is inventing one on top of somebody else's live budget. That is where I stop.
The API will mislead the agent, so check its arithmetic
An agent believes what the API hands it. Direct's API hands over some genuinely awkward things, and we found every one of them the hard way while working with it:
- Request campaigns with an empty filter and archived ones come back too. In one account that was 32 of 52. An agent that skips the filter counts all 52 and calls that the live portfolio.
- The
Statefield outranksStatus. ReadStatusalone and you will call a stopped campaign active. - Money arrives in micro-units. Off by a factor of a million if you take it raw.
- Daily budget mostly is not where you would look for it: 2 campaigns out of 52 had an explicit daily budget, the other 50 ran under a weekly strategy limit.
Campaigns.getreturns the Units header,Reportsdoes not. Same API, different manners.- Direct's
Reportsservice takes at most 10 goals per report (theGoalsparameter). Metrica expects anOAuthauthorisation header rather thanBearer, and the token that opens Direct also opens Metrica. It will not open Webmaster.
None of that is exotic. All of it produces a confident, well-formatted, wrong answer when nobody checks. The real failure mode of agents in ad accounts is rarely a rogue robot burning budget. It is a fluent summary built on a misread field.
What happens when the agent is wrong
Two protections, both boring.
First, fixed checks instead of free improvisation. The catalog runs 131 checks across Meta and Google Ads. The agent walks the list. Same list next month, same list the month after, which is the only reason a score is comparable over time. An agent inventing fresh opinions every run gives you astrology with an API key.
Second, no write access means the blast radius of a bad call is a wrong paragraph in a report. A person reads it before anything in the account changes. Compare that with an agent holding full write access that decided overnight to optimise bids against the 697-conversion report.
And be straight about what is missing. Google Ads has not worked in Russia since 2022, so for a Russian account that whole leg of the catalog is decoration. Creative intelligence runs only against Meta's Ad Library; there is no equivalent for Direct or TikTok, and any vendor implying otherwise is selling you a Meta feature with a Direct label on the box.
If you want to test this yourself, start free. Raw MCP access to ad APIs costs nothing: for the Direct API alone there are more than twenty servers on GitHub, and you can wire one into Claude this evening. You will get the tools, and you will also get the archived campaigns, the micro-units and the State field to untangle on your own time. Read the account first, keep write access off until the read side stops surprising you, then decide whether you want a fixed checklist behind it.