An AI Agent Is Running Your Google Ads: Who’s Accountable?

In October 2025, Google open-sourced its own MCP server (Model Context Protocol, the common language that lets an AI agent talk directly to a piece of software) for Google Ads. Three tools, nothing more: list the accounts you can access, query the data in read-only mode, describe which fields are available. No mutation is possible: no bid changes, no pausing a campaign, no creating an ad. That deliberately narrow choice could have settled the governance debate around AI agents in advertising. Instead, it just moved the debate somewhere else.

Google’s official server isn’t what most campaign managers actually use day to day. What’s spreading instead are third-party connectors, this time with write access, that let a conversational agent (Claude, ChatGPT, Gemini) run a Google Ads account in plain language: no more clicking through a dashboard, just a conversation with an agent that acts on your behalf. If you’re already weighing which parts of your marketing process to hand to an agent and which to leave alone, ad management is one of the areas where that shift has gone furthest. And it raises a question that seemed settled: it’s no longer the agent’s competence that’s in doubt, but who answers for what it did, and how you check it.

Person working on a laptop in an office, managing advertising campaigns

What Google’s official MCP can do, and what it can’t

The technical detail matters, because it heads off a common mix-up. The MCP server Google published exposes exactly three read functions: list the accounts you can access, run a GAQL query (the Google Ads API’s query language), and describe a resource’s metadata so you can build that query. It cannot change a bid, pause a campaign, or create an ad. That restriction isn’t incidental: it’s a signal that Google itself chose not to open up write access on the first pass, even though the technical temptation existed. The risk this article describes doesn’t come from that product. It comes from the third-party connectors that do expose the mutation.

This push toward more agentic control also comes from Google itself, beyond third-party developers. In April 2026, Google announced three new agentic features for Ads Advisor, the assistant built into the Google Ads interface: proactive troubleshooting of ad policy violations, continuous account security monitoring, and instant certifications where the process used to take weeks of paperwork. The signal is clear: delegating to an agent is the direction the entire online advertising market is heading, Google’s own product included, not a fringe case.

The real gap: the interface’s guardrails don’t survive delegation

The Google Ads interface offers, by design, a form of governance that goes largely unnoticed because it costs nothing: a campaign structure that stays stable from one session to the next, a history you can consult, a screen several people can look at together to agree on what actually happened. That governance disappears the moment you step outside the interface. A precise example, documented in the Google Ads API’s technical documentation: the resource that lets you query the change history (the one a connected agent would check to verify what happened) only returns a rolling 30-day window, capped at 10,000 rows. Past that window, an agent trying to audit its own action, or another agent’s, simply has no access to the record anymore.

Frederick Vallaeys, in an analysis published on Search Engine Journal in early September 2026, lays out the structural risks of this kind of delegation: an agent that confuses a campaign with an ad group can, on its own initiative, build a dozen unnecessary campaigns where the interface would have forced it down a marked path. The state of a decision now lives only in a scrolling chat history that no one ever rereads. A scheduled automation can keep running quietly after a third-party connector has stopped working, with no alert to warn anyone. And whatever record survives, when it survives at all, captures the “what” of an action, never the “why” behind it.

The parallel Vallaeys draws with Google Ads Scripts in 2012 is both reassuring and unsettling. Reassuring, because this isn’t new territory: a powerful automation adopted before the ecosystem built the guardrails for it, scripts copied without being understood, creators who leave the company while their code keeps running unread. Unsettling, because a conversational agent is harder to audit than a broken script. A failing script makes the same mistake consistently, which makes it easy to spot. An agent that gets something wrong does so creatively, improvising a different structure each time it runs: there’s no reproducible bug to chase, only a decision, made once, that has to be pieced back together after the fact.

Two colleagues checking a campaign together on a laptop during a meeting

A governance checklist, not a case for caution

None of this argues against delegation: the speed gain is real, and Google itself is investing in this direction. The question for a leader who runs or has someone else run paid ad budgets isn’t whether to use an agent, but what you put back in place to cover what the interface used to do for free. Four habits are enough to start with, before widening the agent’s scope any further:

  • Start in read-only mode, following the pattern of Google’s own official MCP, and only open up write access once the account structure and the agent’s habits are well understood.
  • Require a preview before anything is applied: no irreversible action (pausing, changing a bid, creating something new) runs without explicit approval from a person who has seen what’s about to change.
  • Keep a decision log separate from the change history, noting the why behind an action and not just its outcome, since that reasoning is recorded nowhere else.
  • Check the Google Ads interface directly on a regular basis, even without an alert, since a silent automation will never tell you on its own that it has stopped working correctly.
Person taking notes in a notebook next to a laptop, keeping a decision log

None of these four points calls for extra tooling or a dedicated budget: they call for one person, inside the company, staying identifiable as accountable for what the agent did. That’s exactly what the Google Ads interface guaranteed without anyone having to think about it, and what natural-language delegation quietly removes if nobody puts it back. The legal side of this kind of oversight is a separate question. This one stays operational: handing an agent the execution of an action never hands away the responsibility of checking what it produced.

And if part of your team is already running campaigns through a conversational agent, the question isn’t whether an incident will happen. It’s whether you’ll have what you need to reconstruct it the day it does.

If this piece made you rethink how your team oversees its automated campaigns, write to us. We’re curious how you’ve handled it.


Photo credit: Pixabay.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top