top of page

Agentic Trading: A New Stack or a New Set of Intermediaries?

  • 2 days ago
  • 33 min read

Agentic trading promises to automate how advertising is discovered, negotiated, executed and settled, but building it will require an entirely new transaction stack. The industry may believe it is choosing software, when in fact it may be choosing its next set of intermediaries.


Agentic Trading Has Arrived


Until recently, agentic trading was mostly a compelling idea on AdTech and agency roadmaps. Autonomous agents could theoretically represent media buyers and sellers, discover inventory, negotiate terms, execute campaigns, and eliminate much of the manual coordination that has accumulated across digital advertising. The question was whether any of this would actually work outside a demo.


We are beginning to get an answer. Agentic media transactions are now happening in the real world. pubX CEO Andrew Mole recently told Signal & Noise that his company is facilitating roughly $3,000 per day in media that is both agent-bought and agent-sold. Separately, Boostr and Vox Media completed an AdCP-based direct media transaction in which buyer and seller agents handled nearly the entire workflow—from interpreting the buyer’s requirements and developing the media plan through order creation, trafficking and activation—with humans retained at two critical approval points.


The Vox experiment was deliberately small, but the change in workflow was striking. A conventional direct buy can involve weeks of planning, negotiation, insertion-order creation, trafficking, system configuration and coordination across multiple teams. In the Vox pilot, agents handled almost all of that work, with people stepping in only to approve the media plan and perform a final check before activation. In a recent Signal & Noise podcast, Boostr CEO Patrick O’Leary told us that the agentic process took roughly two minutes. He estimated that a comparable transaction handled conventionally could take between three and six weeks.


None of this means agentic trading has reached scale. It certainly has not. But it does mean the industry has crossed an important threshold. The conversation no longer needs to revolve around whether buyer and seller agents can transact media. We know they can.


The harder question is what must exist around those agents before they can conduct a meaningful share of the market. Agents need structured information to discover opportunities, common protocols for negotiating, integrations for executing campaigns, trusted systems for verifying delivery, financial infrastructure for settling transactions, and governance for assigning responsibility when something goes wrong.


Those requirements create both an implementation challenge and a competitive one. Agentic trading is often described as a way to remove intermediaries and connect buyers and publishers more directly. Yet the infrastructure required to make it work could produce an entirely new group of gatekeepers—companies controlling agent discovery, transaction protocols, operational integrations, verification and settlement.


The industry may believe it is choosing software or building a new stack, but it may actually be choosing its next set of intermediaries. The question, then, is not simply how quickly agentic trading will grow, but who will control the stack on which it grows, how open that stack will be, and whether automation will create a more direct advertising market or merely reorganize the layers standing between buyers and publishers.

The threshold has been crossed: The question is no longer whether buyer and seller agents can transact media. We know they can. The question is what must exist around them before they can operate at scale.

Pro Tip: Begin With the Right Transaction


Now that agentic trading is really happening, the first question should not be where agents can transact. It should be where they can create enough value to justify changing how media is bought and sold. This distinction matters because not every part of digital advertising is equally broken.


Open-auction programmatic is enormously complex, but we need to accept it already automates much of what agents would otherwise need to do: evaluate individual impressions, apply targeting and bidding logic, pace budgets, clear auctions, serve ads, and reconcile transactions at enormous scale. Agentic systems may eventually reshape this market, but simply placing an AI agent on top of an existing DSP or SSP does not necessarily solve an issue that needs urgent solving.


The more immediate opportunity is likely to be reserved and negotiated media—direct IOs, programmatic guaranteed (PG) deals, private marketplaces (PMP), preferred deals, sponsorships, and other transactions where buyers and sellers agree on some combination of inventory, audience, price, volume, or commercial terms before the media runs.


Guaranteed buys, private marketplace deals, preferred deals, sponsorships and other negotiated inventory typically require buyers and sellers to move repeatedly between email, spreadsheets, planning systems, order management platforms and ad servers. Inventory has to be discovered, audiences and packages need to be evaluated, availability must be checked, and pricing and terms have to be negotiated. Once the deal parameters are in place, IOs are created and approved, creative gets trafficked, and campaigns are monitored. When something changes, a change order may need to issued.

Where agents create the most immediate value: Direct IOs, programmatic guaranteed deals, PMPs, preferred deals and sponsorships—transactions that combine structured media buying with extensive human coordination.

This is precisely the kind of coordination that agents are well suited to automate. Patrick O'Leary argues that direct IO and programmatic guaranteed transactions are effectively ready for agentic workflows today. In the Vox pilot, the buyer agent could describe what it wanted in natural language, the seller agent would then respond with appropriate inventory and pricing, and the two refined the media plan before passing a structured order directly into Boostr's order management system (OMS). The protocol also supports revisions after a campaign begins, allowing agents to manage changes that traditionally generate another round of emails, handoffs and manual work.


Andrew Mole sees a similar opportunity from the publisher side. One of the advantages of agents, he argues, is their ability to make publisher inventory and audiences discoverable without requiring a salesperson or media buyer to manually navigate every possible combination. A publisher might have thousands—or tens of thousands—of potential audience and inventory combinations. A human cannot realistically evaluate all of them for every brief. An agent can.


Big picture, this begins to point toward something more consequential than workflow automation. Agentic trading could make transactions economically viable that are simply too cumbersome to execute today. Buyers could potentially evaluate far more publishers, inventory packages and audience combinations without requiring corresponding increases in headcount. Publishers could ostensibly expose more of what makes their inventory valuable without depending on a salesperson to package every opportunity in advance.


For this reason, direct and negotiated media looks like the logical place for agentic trading to establish itself. But it may not be where it ends.


Agentic trading should begin where automation removes the most friction: complex, negotiated media transactions that still depend on manual coordination and handoffs.
Agentic trading should begin where automation removes the most friction: complex, negotiated media transactions that still depend on manual coordination and handoffs.

Don't Assume It Ends With Direct-Sold Media


Reserved and negotiated media may be the obvious starting point for agentic trading, but it would be a mistake to assume this is where the technology stops. Today, open-auction programmatic already solves a problem that agents are only beginning to address elsewhere—namely, it allows buyers and sellers to transact enormous volumes of media automatically and in real time.


The functionality itself isn't the problem—it's everything that has accumulated around the transaction. This includes DSPs, SSPs, exchanges, identity providers, verification companies, and other intermediaries who each perform functions that were (at least initially) developed for legitimate reasons. Collectively, however, they have created an extraordinarily complicated and convoluted supply chain between the advertiser spending the dollar and the publisher ultimately receiving it.


Agentic trading raises a provocative question: how much of this Rube-Goldberg machine is actually necessary if buyer and seller agents can communicate directly? Of course it depends on whom you ask. Andrew Mole believes the answer could eventually extend well beyond direct IOs. In our conversation, he described a potential architecture in which a buyer agent could interact with publisher inventory through existing standards such as OpenRTB and Prebid, using a relatively lightweight bidder to participate in the publisher's auction and ultimately pass the winning transaction to the ad server.


As we move forward, there is an important distinction between the functions performed by today's AdTech platforms and the companies that currently bundle those functions together. A buyer still needs decisioning, budgets still need to be paced, and inventory needs to be evaluated. Moreover, publishers still need yield management, and ads of course will still need to be served. Also, identity, measurement, verification, fraud prevention, and financial settlement do not magically disappear just because two agents can talk to one another.


While these functions may still be needed in an agentic future, this does not necessarily mean every one must remain packaged inside the same DSPs, SSPs and other platforms that perform them today.

During our discussion last month, Patrick O'Leary arrived at a similar conclusion from a slightly different direction. For now, he sees direct IOs, programmatic guaranteed (PG), and certain non-guaranteed deals as the clearest opportunities for AdCP. Open RTB already works at massive scale, he pointed out, so there is little reason to immediately rip it out simply to prove that agents can replace it. His expectation is that the two models will operate in parallel: traditional programmatic continuing to handle much of today's auction-based buying, while agentic trading absorbs more direct and negotiated transactions as the technology matures.


What Buyers Need to Participate


Suffice it to say, if agentic trading is going to become a meaningful buying channel, advertisers and agencies will need more than just a basic buyer agent. Consider that the agent will need to understand what it is trying to accomplish, what it is allowed to buy, how much it can spend, which audiences matter, what constitutes an acceptable outcome, and when a decision requires human approval. In other words, the intelligence of the agent matters, and so does the environment around it.


At a minimum, a buyer-side agent needs access to several types of information—campaign objectives and KPIs, budgets and pacing requirements, audience definitions, identity and first-party data, creative assets, brand suitability rules, measurement frameworks, and commercial constraints such as approved publishers or pricing thresholds. Sure, anyone who has worked in media knows most of this information already exists inside advertiser and agency organizations. The problem is that it rarely exists in one place—or in a form an autonomous agent can easily understand and act upon.


For example, campaign objectives may live in a brief, while audience definitions may sit inside a CDP or data platform. Historical performance data is scattered across DSPs, ad servers and measurement systems, while creative assets live in a DAM. Brand-suitability policies are typically administered by verification vendors, but contracts and approved-partner lists typically live in procurement systems, with budget approvals exist inside yet another workflow.


Humans have historically served as the connective tissue between these systems. By humans, I am referring to media planners, ad buyers, traders, ad operations, and account teams who gather information from different places, interpret it, make decisions and move the transaction forward.


An agentic model begins to transfer some of this connective role from humans to software. This makes context critically important. A buyer agent cannot simply receive an instruction to “reach sports fans in New York” and be expected to make good decisions. It needs to understand what the advertiser actually means by that audience, what business outcome it is optimizing toward, which data it can legally use, how much it should pay, what environments are acceptable, what has worked previously, and of course which decisions it is authorized to make on its own.


This is also why governance cannot be bolted on later as an afterthought. The Vox experiment provides a useful early example. Although agents handled nearly the entire transaction, humans remained at two deliberate checkpoints: one to approve the proposed media plan and confirm the publisher wanted to accept the business, and another to verify the campaign setup before activation. Boostr designed those intervention points to be configurable rather than assuming autonomy meant removing humans altogether.


That is probably a more realistic model for the early stages of agentic trading. Remember, the objective is not maximum autonomy. I would argue it is controlled autonomy, which I define as allowing agents to perform the repetitive discovery, negotiation, orchestration, and execution work while humans retain authority over decisions where financial, operational or reputational risk warrants it.

The objective is not maximum autonomy. It is controlled autonomy: Agents handle repetitive discovery, negotiation and execution while people retain authority over decisions carrying financial, operational or reputational risk.

Over time, sure, these boundaries will likely move—maybe even dramatically. As organizations gain confidence in agents, protocols mature, and transaction histories provide evidence the systems behave as intended, some approval gates can become automated or even disappear altogether. But before advertisers can hand over more authority to agents, they first have to make their objectives, data, rules and constraints legible to them. What's more, publishers need to do the same thing on the sell-side of the transaction.


A buyer agent needs more than intelligence. It needs access to the campaign’s objectives, budgets, audiences, creative, measurement, and commercial constraints—with human approval retained where the risk demands it.
A buyer agent needs more than intelligence. It needs access to the campaign’s objectives, budgets, audiences, creative, measurement, and commercial constraints—with human approval retained where the risk demands it.

What Publishers Need to Participate


If advertisers need to make their buying intentions legible to agents, publishers face the inverse challenge: they need to make what they have to sell legible to machines. In many ways, this is more complicated than simply exposing available impressions.


Ths reason for this is publishers sell combinations of inventory, audiences, context, formats, data, placement, timing, and commercial terms. Some of those products are standardized, but many are not. A premium publisher might, for example, offer homepage takeovers, custom sponsorships, high-impact formats, video packages, contextual segments, first-party audiences, or combinations of all of the above. Pricing can vary by buyer, volume, seasonality, audience, format, and availability.


Historically, the salesperson has acted as the interface by making sense of this complexity and translating it to customers. Give a good seller a campaign brief, and they should know how to interpret what the buyer is actually asking for. What's more, they understand which inventory is available, which audiences are relevant, which packages might work, what can be negotiated, and where the publisher has something differentiated to offer. They then translate all of this into a media plan the buyer can evaluate. It's a complex process with multiple inputs, numerous steps, and of course an element of judgement and taste.


By definition, a seller agent has to perform some version of the same functions. This means publishers need to make their inventory and commercial rules machine-readable so an agent can understand what products exist, which audiences can be reached, how much inventory is available, what it costs, what minimums apply, which creative formats are supported, how campaigns are measured, and which terms it has the authority to negotiate.


Andrew Mole's work at pubX provides an interesting example of how this can begin to work. Rather than requiring publishers to completely rebuild their technology stack or dump enormous volumes of log-level data into another platform, pubX connects to systems publishers already use and interprets existing audience taxonomies. Mole described reading the audiences a publisher has defined in systems such as its ad server or DMP and making those audiences discoverable to agents.


This is important because the problem for many publishers is not a lack of valuable inventory or data, but discoverability. A large publisher may have thousands—or even tens of thousands—of potential permutations of audience, context, and inventory. A salesperson cannot reasonably search through every possible combination each time a brief arrives. Nor can a media planner know everything a publisher might be capable of offering. An agent, however, can approach the problem differently.


Mole described a scenario in which an advertiser asks for a particular audience and the seller agent assesses the publisher's available taxonomy, inventory, and data to identify what best matches the request. Instead of requiring the publisher to pre-package every possible audience into a predefined media product, the agent assembles the appropriate opportunity dynamically and on the fly. This could become extremely important as publishers attempt to differentiate themselves from the commoditized inventory available on the open web. In this future, a publisher's value resides not simply in the number of impressions it has available, but in the combination of its content, first-party audience relationships, contextual signals, proprietary data and unique advertising experiences.


If agents are going to buy this perceived value, however, they first have to be able to discover it. Once they can, something interesting and potentially magical happens: the number of products a publisher can effectively bring to market is no longer constrained by how many packages its sales team can manually create and sell. This would be a game-changer that potentially changes the economics of publishing. Inventory or audience combinations that were previously too small, specialized, or cumbersome to package may suddenly become commercially viable because the incremental cost of discovering, assembling and negotiating them falls dramatically.


But making inventory discoverable is only part of the problem. Once buyer and seller agents find one another, they still need a common way to communicate, negotiate, authenticate themselves, execute transactions and establish the boundaries of what each agent is authorized to do.


The future agentic trading stack: - Discovery: What can the agents find? - Protocol: How do they communicate and negotiate? - Execution: How does an agreement become a campaign? - Verification: How do the parties prove what happened? - Settlement: How are obligations reconciled and paid? - Governance: Who is authorized, accountable and liable?

Publishers must make their inventory, audiences, formats, availability and commercial rules legible to machines—allowing seller agents to assemble opportunities that human teams could never package manually at scale.
Publishers must make their inventory, audiences, formats, availability and commercial rules legible to machines—allowing seller agents to assemble opportunities that human teams could never package manually at scale.

The Protocol Layer


Making buyer intent and publisher inventory machine-readable solves the discovery problem. It does not, however, solve the transaction problem. For agentic trading to work at scale, buyer and seller agents need a common language for exchanging it and a trusted framework for acting on it. An agent must be able to identify a potential counterparty, verify that it is legitimate, understand what it is authorized to do, negotiate within defined parameters, and create a record of the resulting agreement. This is where protocols become essential.


Today, much of digital advertising’s transactional infrastructure is standardized, but only within relatively narrow boundaries. OpenRTB provides a common format for real-time auction requests and responses, while ads.txt and sellers.json help buyers verify authorized inventory paths. VAST standardizes aspects of video advertising, while systems for identity, measurement and reporting provide additional—if fragmented—layers of interoperability.


The issue is these standards were largely designed for a world in which transactions followed predetermined workflows within programmatic. A publisher made an impression available, an exchange then sent a bid request, buyers submitted prices, and the auction selected a winner. The systems involved did not need to reason extensively about the campaign’s broader objectives or negotiate a bespoke commercial arrangement. They primarily needed to execute a transaction whose structure had already been (pre)defined.


Unless we restrict the types of deals they are allowed to negotiate, agents introduce a much wider range of possible interactions. Because they would be automating the entire publisher sales process for all their inventory, a buyer agent might ask whether a publisher can reach a particular audience across several formats, see if additional inventory will become available during a specific period, or determine whether the publisher will accept a lower price in exchange for a larger commitment. It might request a custom combination of video, display, newsletter, and sponsored content. It could even ask what measurement options are available, whether certain data can be used, or how a proposed package compares with alternatives elsewhere.


Importantly, the seller agent must be capable of responding to these requests without inventing products—we all know how LLMs like to get creative—exposing restricted information or agreeing to terms outside its authority. In other words, it needs to distinguish between what is available, what is possible with approval, and what is prohibited altogether. This means the communication between agents cannot consist of unrestricted natural-language conversation alone. Language models may provide the reasoning interface, but the commercial exchange underneath them will require structured messages and explicit rules. This is what I'm calling the "Protocol Layer."


A buyer agent should be able to communicate the campaign objective, target audience, budget, timing, geography, formats, measurement requirements and non-negotiable constraints in a form another system can reliably interpret. The seller agent should also be able to return eligible products, projected availability, pricing, minimum commitments, permitted uses of data, measurement options and the conditions under which the offer remains valid.


Just as importantly, both sides need to understand the status of the conversation. Is the agent gathering information, requesting a proposal, making a non-binding offer, or committing its principal to a contract? A human salesperson can often infer these distinctions from context. A machine, by contrast, needs them to be explicit. Identity and authorization therefore become as important as the commercial vocabulary itself.


Before a publisher shares pricing or audience information, it needs to know exactly who is asking. Is the agent acting for an advertiser, an agency or an intermediary? Has that organization authorized it to negotiate? Can it commit budget, or can it only recommend a plan for human approval? Is it permitted to accept particular data-use provisions, creative requirements, or cancellation terms? The same tough questions apply on the publisher side. A buyer needs confidence the seller agent represents the inventory it claims to represent, the products being offered actually exist, and the agent has authority to reserve or sell them.


For agentic trading to function at any scale, the industry will need a way to express limits on the authority agents are granted. An advertiser might, for example, allow its agent to shift spending between approved publishers, but require human approval before adding a new vendor. A publisher might permit its agent to discount inventory by five percent, but escalate anything beyond that threshold. Certain categories, audience segments, data uses or creative formats might always require review.


These permissions cannot live solely inside a prompt. They need to be encoded as enforceable policies around the agent in a governance layer that sits between buyer and seller. Furthermore, every material action must also produce an auditable record or ledger of transaction that records what the agent was asked to do, what information it considered, which offers it made, which concessions it accepted and who ultimately approved the transaction. Without this record, an agentic marketplace could make an already opaque industry even harder to inspect.


Interestingly, this creates a paradox of sorts. While on one hand agents promise to make digital advertising faster and simpler, achieving this simplicity may require the industry to define its products, permissions, and commercial processes with far greater precision than it does today. This work will not be glamorous. It will involve schemas, credentials, APIs, authorization models, transaction logs, and agreements about which system is responsible when something goes wrong. But it is the difference between agents that can merely discuss advertising and agents that can safely conduct business.


The companies that control these standards may also acquire considerable influence. A protocol determines which information is visible, which products are easy to describe, which forms of negotiation are supported, and which intermediaries can participate. In other words, what looks like boring plumbing will quietly become the market architecture. The next contest in agentic trading, then, may not be over who builds the most intelligent buyer or seller, but rather who defines the language those agents are required to speak and how they interact.


The Execution Layer


A protocol can help two agents describe, negotiate, and record an agreement, but it does not ensure the agreement will actually be carried out. Once the buyer and seller have settled on a package, the resulting terms still need to be translated into the systems that reserve inventory, accept creative, configure targeting, control pacing, deliver impressions, collect data, and even issue invoices.

This complex web of activities is what I'm deeming the "execution problem" of agentic trading.


In conventional programmatic, much of this machinery is already connected. A campaign configured in a DSP can generate bids, purchase impressions, and adjust delivery within the boundaries supported by the platform. The workflow may be complicated, but its major components and functionality have been refined and integrated over many years. The DSP is a very mature technology.


Assuming agentic trading encompasses all types of media currently bought and sold, it becomes much more difficult. Consider a buyer agent that negotiates a package combining CTV, display, newsletter sponsorship and branded content. Each component may live in a different system, follow a different production schedule and use a different method of measurement. Some inventory might be available through a DSP, while other placements require a direct order in the publisher’s ad server. The newsletter could be managed by an email platform, and the sponsored content might require an editorial workflow involving writers, designers, legal reviewers and the advertiser. The negotiation itself may produce one commercial agreement, but operationally it has created several distinct jobs.


For agents to execute these deals, the terms they negotiate must be translated into instructions each underlying system can understand. Budget allocations need to become line items, and audience definitions need to be translated into targeting rules. Delivery dates must become flight windows, and both buy and sell slides will need to consider with frequency limits, pacing requirements, creative specifications, brand-safety restrictions, and measurement provisions. What's more, all of these steps need to pass from a negotiated proposal into actual campaign execution.


This translation cannot depend on an agent reading the agreement and improvising the setup. Anyone who has worked in media can tell you even small differences in interpretation can produce large material consequences. “Reach IT technology decision-makers” is not an executable instruction unless the audience definition, eligible data sources and permitted inference methods are specified. “Prioritize premium video” means little unless the parties have agreed on which inventory qualifies, how it will be identified and what happens when it is unavailable.


The execution layer therefore needs a machine-readable order that functions as the authoritative version of the deal itself. It should identify the products purchased, systems responsible for delivering them, applicable pricing model, audience and contextual criteria, creative requirements, measurement plan, and conditions under which changes are permitted. To complicate matters, each operational platform can only receive the instructions relevant to its role, but all of them need to trace back to the same agreement.


These instructions become especially important (and more complicated) when agents are allowed to optimize a campaign after it begins. A buyer agent might want to move money from display into video, increase spending with a publisher that is outperforming, or reduce exposure to inventory that is failing a quality threshold. A seller agent might propose additional supply, recommend a different format or offer a discount to unlock incremental budget.


This cascade of decisions means the industry needs to come up with a way to distinguish optimization from renegotiation. If an agent changes pacing within an approved line item, it may simply be executing the original agreement. If it moves budget between products, changes the target audience, or accepts a different measurement methodology, it may be altering the substance of the deal. The first action could be permitted automatically, while second might require a change order, additional authorization via human approval. Without this distinction, agents could gradually transform a campaign into something neither party originally intended. A series of individually reasonable optimizations might change the media mix, audience, economics, or risk profile of the agreement.


The execution layer must therefore preserve the boundaries established during negotiation and make any movement beyond them explicit. Creative introduces another complication. Media cannot begin delivering merely because the commercial terms have been accepted. The appropriate assets must exist, meet the publisher’s specifications, and comply with legal, regulatory, and brand requirements. Sure, an agent might be able to resize an image, generate a variation, or adapt copy for a particular format on the fly, but it should never assume permission to buy media includes permission to create or materially alter the creative itself—unless of course the brand is okay with this.


To minimize risk with creative, the campaign order must specify which creative actions are authorized. Can the agent crop an image, rewrite a headline, generate a new background, translate copy, or substitute a product claim? Each step carries a different level of risk. The system also needs to know which assets have received final approval, where those assets may run, and for how long, and whether additional review is required for regulated categories or sensitive contexts.


Publishers face a parallel challenge with custom products. A seller agent might determine that a proposed package is commercially attractive, but execution could still depend on editorial capacity, production resources, talent availability or technical development. Inventory that appears theoretically possible is not necessarily operationally available. The agent must thus confirm the teams and systems responsible for fulfillment can deliver before converting an offer into a binding commitment.


This is why agentic trading will require more than simply connections between buyer and seller agents. It will also require deep connections into the operational systems on both sides. Campaign-management tools, ad servers, creative platforms, data systems, billing software, and approval workflows all need to expose enough structured information for agents to understand their capabilities and current state. An agent needs to be able to determine if a line item has been created, creative has been approved, tracking is functioning, and inventory has been reserved and whether the campaign is pacing correctly. When something goes wrong, it will need to know which system owns the problem and whether it has permission to correct it.


None of this eliminates people—quite the opposite. In fact, the execution layer may reveal just how many advertising workflows still depend heavily on human judgment and informal coordination. Salespeople know whom to call when an order needs to be expedited, and ad ops teams know which specifications are flexible. Buyers will typically know when an apparent performance problem is really a tracking issue, and producers can predict based on past experience if a program described in a proposal will require three rounds of revision and two weeks more than the official timeline suggests.


The challenge is not to pretend these exceptions do not exist, but rather to make them visible enough for agents to route work appropriately. A well-designed execution layer should automate predictable tasks, identify deviations early, and escalate decisions that require judgment. It should not allow an agent to conceal operational uncertainty behind a confident response.


Ultimately, a transaction is not complete when two agents agree. It is complete when the promised media has been delivered under the agreed conditions, the results have been measured according to the agreed methodology, and the financial obligations have been reconciled. This makes execution where the rubber meets the road in agentic trading encounter. Negotiation may be where agents appear insanely impressive, but fulfillment is where the industry will learn if they are actually useful.


The Verification Layer


Execution turns an agreement into a campaign, but it does not necessarily prove that the campaign delivered what was promised or confirm any of the agents involved made the right decisions. For that, agentic trading requires another layer dedicated to verification. This requirement exists in advertising today, of course. Buyers are able to verify whether impressions were served, ads were viewable, audiences were reached, inventory was brand-safe, and campaigns produced measurable outcomes. Publishers reconcile their own delivery records against those of ad servers, exchanges, DSPs, measurement providers and advertisers.


The difference is that agents will make these decisions faster, more frequently, and with far less human visibility. A buyer agent could evaluate thousands of opportunities, negotiate dozens of packages, redistribute spending throughout the day, and adjust its strategy as new performance data arrives. A seller agent could alter prices, recommend inventory, release capacity, and make counteroffers just as quickly. Someone still needs to determine whether those actions worked.


The optimization trap: Agentic trading could make advertising extraordinarily efficient at optimizing the wrong proxies. The faster agents learn, the more precisely advertisers must define what success actually means.

The first challenge is verifying delivery against the machine-readable order. If a buyer purchased a specific audience, format, context, geography, and level of exposure, the systems involved must be able to confirm that those conditions were met. I don't think it will usually be enough to report a total number of impressions. Each material requirement in the agreement should correspond to evidence showing whether the obligation was fulfilled.


The issue is the evidence will rarely come from one source, which is part of what makes measurement such a challenge today. The publisher may have one record of delivery, the buyer’s platform another, and an independent measurement company a third. Identity loss, latency, filtering rules, and differences in methodology can cause those records to disagree even when no party has acted improperly. Agents cannot simply pick whichever number is most favorable to their principal. They will need rules governing which source is authoritative for each provision, how discrepancies are calculated, and what happens when those discrepancies exceed an agreed threshold.


The same applies to commercial outcomes. A campaign may be judged on reach, attention, site visits, sales, subscriptions, brand lift, or some combination of these outcomes. Each metric answers a different question, operates on a different timeline and carries different limitations. An agent optimizing toward the metric that updates most quickly could inadvertently sacrifice the outcome the advertiser actually cares about. This creates a dangerous possibility that agentic trading could make advertising extraordinarily efficient at optimizing proxies based on vanity metrics.


Click-through rates, completion rates, and other readily available signals may give an agent rapid feedback, but they do not necessarily indicate actual business impact. Even conversion data can be misleading when the system generating the conversions also controls targeting, delivery or attribution. An agent instructed simply to maximize measured performance will naturally favor the environments and methodologies that give it the strongest measurable credit. This has been one of the main issues with Made For Advertising sites, which tend to perform well if your main measurement outcomes are low CPMs and lots of impressions (scale and reach).


To run a campaign, agents will need more than a list of KPIs. They will need a measurement hierarchy. The buyer will need to specify the primary outcome, supporting indicators the agent may use during optimization, attribution rules, acceptable data sources, and conditions under which the agent should stop or escalate. They will should also distinguish between metrics used to steer the campaign and those used to judge its ultimate success.


Seller agents require similar discipline. A publisher’s agent may learn that certain packaging choices, audience labels, or measurement approaches make its inventory appear more effective. Some of these discoveries will represent legitimate improvements, while others may merely exploit weaknesses in how the buyer agent evaluates opportunities.


If you ask me, this is an old advertising problem in a new form. Markets optimize around whatever they are rewarded for—"Show me the incentive and I'll show you the outcome," to quote the late great Charles Munger. The difference is that agents may identify and exploit these incentives much faster than humans, potentially without either principal realizing how the behavior emerged and after the damage is done.


This is why independent verification becomes more important, not less, in agentic trading. If the buyer agent, seller agent, or platform executing media also serves as the sole authority on performance, the marketplace will be vulnerable to self-scoring—what we call "grading your own homework." Third parties will still be very much needed to validate delivery, quality, audience composition and outcomes, though their role will shift from producing reports for humans to providing trusted signals that other machines can use.


To prevent abuse, those signals will need their own provenance. An agent will need to know who produced a metric, which methodology was used, when the data was collected, and whether the provider has a commercial interest in the result. “Verified” cannot become a generic label applied to any data entering the system. Verification also applies to the agents themselves. Brands and publishers will need to evaluate not only whether campaigns performed, but whether their agents behaved as intended. Did the buyer agent honor approved publisher lists and spending limits? Did it make unnecessary concessions? Did it consistently favor certain platforms or measurement providers? Did the seller agent protect pricing floors, disclose limitations, and escalate exceptions appropriately?


Answering these questions requires a comprehensive record that connects the original instruction, the available options, the agent’s action, and the eventual outcome. Without that chain, a company might know that a campaign underperformed but have no practical way to determine whether the problem came from the strategy, the inventory, the data, the execution or the agent itself. Over time, these records must allow principals to compare agent behavior. Two buyer agents given the same objective may construct very different plans. Two seller agents may generate different yields from the same inventory.


In a likely future, performance will no longer be evaluated solely at the campaign level, which mans companies will need ways to assess the quality, consistency and risk of the agents acting on their behalf. This creates another important boundary. An agent should be able to learn from outcomes, but it should not be free to redefine success based on what it can most easily achieve. The objective must remain controlled by the principal, even as the tactics evolve.


Agentic trading is often presented as a way to remove friction from advertising. Verification is friction by design because it inevitably slows certain actions, challenges convenient conclusions, and preserves evidence that someone may later need to inspect. This may make the marketplace less seamless, but it is also what prevents automation from becoming unaccountable.


If agents are going to negotiate and execute media on behalf of companies, “trust the system” will not be an acceptable measurement standard. The system will need to show its work.


The Settlement Layer


Once delivery has been verified, someone still needs to determine what is owed, who owes it, when payment is due, and what happens if the parties disagree. This is the settlement problem of agentic trading.


At first glance, settlement might appear relatively simple. The buyer and seller agreed on a price, the campaign delivered, and an invoice can now be issued. Anyone familiar with advertising finance knows the reality is considerably messier. The final amount may depend on verified impressions, completed views, audience delivery, performance thresholds, production expenses, data fees, platform charges, cancellation provisions, underdelivery, overdelivery, make-goods, or negotiated credits. Different portions of the same package may use CPM, flat-fee, sponsorship, cost-per-action, or outcome-based pricing. Taxes, currency conversions, and agency fees introduce still more variables.


Every change made during execution can affect the final obligation. If a buyer agent shifted budget between formats, a seller agent released additional inventory, or either side accepted a revised price, the billing system needs to know which version of the agreement applies. The original order, approved changes, delivery records, and verification results must all reconcile into one defensible calculation.

This is another reason agentic trading needs a common transaction record. The invoice cannot be an isolated document created after the campaign ends. It should be the financial expression of the machine-readable agreement and all the events recorded against it.


Each charge should trace back to an authorized product, pricing term, and verified unit of delivery. Each adjustment should indicate what triggered it, which policy governed it, and whether an agent or person approved it. If the amount changes, both parties should be able to understand why without reconstructing the campaign from emails, spreadsheets, and platform reports. Of course discrepancies will still occur. For example, a publisher may calculate 10 million billable impressions while the buyer recognizes only 9.5 million. A measurement provider may invalidate traffic that the publisher’s ad server counted, or a campaign could technically meet its delivery commitment but fail an audience-composition guarantee. Sponsored content might run as planned while the programmatic portion underdelivers.


Today, resolving these differences can require weeks of manual investigation. Teams compare reports, identify methodological differences, negotiate adjustments, issue revised invoices, and occasionally agree on makegoods that run months after the original campaign. Agents could certainly accelerate this process, but only if they are given explicit settlement rules. For example, the agreement might state discrepancies below a certain percentage are accepted automatically, while larger differences require reconciliation. It might also identify which measurement source will be used for billing, how invalid traffic is treated, when underdelivery creates a refund, or whether a make-good can be accepted instead of a credit.


As elsewhere, the agent’s authority matters. A seller agent may be permitted to issue a small credit, but not waive a substantial balance. A buyer agent might accept a routine discrepancy while escalating a failed guarantee. Neither should be free to resolve a financial dispute merely because doing so is the fastest way to close the transaction.


Payment also introduces counterparty risk. Before accepting a deal, a publisher needs confidence the advertiser, agency, or intermediary will pay in the first place. The buyer needs assurance the seller controls the inventory, can fulfill the agreement, and will return funds or provide compensation when necessary. This becomes complicated when agents assemble packages across multiple companies. A buyer may believe it has purchased one coordinated plan even though the transaction creates obligations with several publishers, data providers, technology platforms, and production partners. Who extends credit? Who invoices the buyer? Who pays each participant? And who absorbs the loss if one party fails?


The answers cannot be inferred after the campaign begins. The protocol will need to identify the legal counterparties, payment responsibilities, credit terms, and conditions under which funds can be released or withheld. In some cases, marketplaces may use prefunding, escrow, guarantees or other mechanisms to reduce risk. In others, established commercial relationships will continue to support invoicing on standard terms.


This may create a powerful role for the platforms that handle settlement. The system that maintains the transaction record, calculates obligations, manages disputes, and moves money between participants will see a detailed picture of the marketplace. It could become the connective tissue between buyer agents, seller agents and the companies they represent. Based on what I'm reading in the trade press, I believe this is one area Scope3 is currently exploring in an attempt to operate the payment rails and in effect become the clearinghouse or market-maker for a future agentic trading marketplace.


That position is powerful but also creates potential conflicts. A settlement provider should not be able to alter commercial terms, privilege certain participants or use transaction data in ways the principals did not authorize. Financial infrastructure must therefore be subject to the same scrutiny around neutrality, permissions and auditability as the agents themselves.


Let's face it, settlement is unlikely to be the part of agentic trading that generates the most impressive demos or gets VCs excited. And I doubt anyone will marvel at an agent reconciling an invoice or applying the correct credit. But unless the industry can reliably complete these tasks, agentic transactions will remain demonstrations rather than commerce.


A market does not function simply because two systems can agree. It functions when their agreement can be fulfilled, verified and settled—and when every participant knows it will get paid.


The Governance Layer


If agentic trading eventually operates across discovery, negotiation, execution, verification and settlement, the industry will still need to answer a deceptively simple question: Who is responsible when something goes wrong? This is important because in media, a lot can go wrong. An agent could purchase inventory the advertiser did not intend to buy, accept terms outside its authority, expose confidential information, misinterpret a measurement requirement, or optimize toward a result that violates the brand’s policies. A seller agent could offer inventory that is unavailable, apply an unauthorized discount, disclose protected pricing, or make a commitment the publisher cannot fulfill.


In most instances, the failure will not belong entirely to either agent. It could originate in the model itself, the data it received (garbage in / garbage out), the protocol connecting the parties, a failed integration, an outdated permission, or the system responsible for verification that drops the ball. In a transaction involving several agents and platforms, even identifying the cause may be difficult. This is the governance problem. Traditional advertising agreements assign responsibility through contracts, platform terms, insertion orders, sequential liability, and established business practices. These mechanisms can be frustratingly slow, but they give the parties a framework for resolving disputes. No, agentic trading will not eliminate this framework, but it will require the industry to translate much of it into rules machines can enforce.


The first task is establishing accountability. A company should not be able to avoid responsibility by claiming its agent acted independently—the "blame it on the agent" excuse. If an advertiser authorizes an agent to transact on its behalf, the advertiser—or the service provider (usually agency) operating the agent—must remain accountable for actions taken within that authority. The same principle should apply to publishers and their seller agents. The harder cases will involve an agent acting outside its authority, which is certainly possible when we see LLMs applying creativity to solve problems. Suppose a buyer agent commits more budget than it was allocated because it misinterpreted a spending limit. Is the resulting order binding, or does the publisher bear responsibility for failing to verify the agent’s authority? Is the agent provider liable because its system ignored a policy, or does the advertiser absorb the loss because it deployed the agent?


These questions cannot be answered consistently through technical design alone. The market will need agreements defining when an agent’s action becomes binding, which party is responsible for validating its credentials, and how unauthorized transactions can be challenged or reversed. Agent identity will be central to this framework. Every agent participating in the market should be associated with a verifiable organization, an authorized principal, a defined scope of activity, and a current set of permissions. Other participants need to know not only which company the agent represents, but which system operates it and who can be contacted when its behavior creates a problem.


This will probably lead to some form of industry registration, certification, or accreditation. An agent might need to demonstrate that it follows the relevant protocol, enforces permissions, maintains adequate records, protects confidential data, and supports an established dispute process before other systems agree to transact with it. The industry already has examples of standards that became more useful when compliance could be validated rather than merely claimed. Agentic trading will require a similar distinction between declaring that an agent is trustworthy and providing evidence that it satisfies specific requirements.


This is already beginning to take shape. IAB Tech Lab recently launched an Agent Registry as part of its Agentic Advertising Management Protocols initiative. Companies can register their agents, describe their purpose and capabilities, identify the protocols they support, and associate them with an established IAB vendor identity. Tech Lab describes the registry as a neutral framework for agent identity, verification and disclosure, and plans to add ratings and a mechanism for confirming that seller agents actually represent the properties they claim to sell—essentially an ads.txt-style authorization system for agents.


For now, this is closer to registration and transparency than formal certification. The registry does not yet appear to certify that an agent complies with every applicable protocol, protects confidential information, or participates in a defined dispute process. Some of those controls are being developed elsewhere within AAMP through approval gates, authenticated access, structured workflows and provenance records. Over time, these efforts could evolve into a broader accreditation regime in which an agent if forced to demonstrate that it follows the relevant standards, enforces permissions, maintains adequate records and satisfies minimum security and governance requirements before other systems agree to transact with it.


IAB Tech Lab recently launched an Agent Registry as part of its Agentic Advertising Management Protocols (AAMP) initiative.

Governance also means a way to handle complaints and appeals. Automated systems will make mistakes, and not every dispute can be resolved by comparing transaction logs. The underlying agreement may be ambiguous, two verification providers may disagree, or a technically authorized decision may still produce an unreasonable outcome. As such, companies will need a mechanism to pause activity, challenge a decision, preserve evidence, and escalate the matter to people with authority to resolve it. “The agent decided” cannot become the final answer to a commercial dispute.


This is particularly important because the agents themselves may operate at very different levels of sophistication. A global agency could deploy a highly customized buying system with extensive controls, while a local advertiser uses an off-the-shelf agent configured in minutes. A large publisher may operate its own sales agent, while a smaller publisher relies on one supplied by an AdTech partner like Optable.

A workable governance model cannot assume every participant has the same technical resources, and as such must protect smaller companies without preventing them from participating, while ensuring that convenience does not become an excuse for weak controls.


The protocols and policies governing the market will also change over time. New formats, emerging data regulations, improved measurement methods, or new commercial models will require updates. An agent operating under one version of a standard may encounter another using different definitions or permissions. Governance therefore includes version control, backward compatibility and a process for deciding when older practices are no longer acceptable.


Who controls that process will matter enormously. If a single platform defines the protocol, certifies the agents, maintains the transaction record, and settles the payments, it could gain extraordinary influence over the market. It would effectively decide who can participate, what products can be traded, which rules apply and how disputes are resolved—that's a lot of power.


This might produce efficiency, but it would also recreate the concentration of power (Walled Gardens, ahem) agentic trading is supposed to disrupt. The governance layer should therefore be designed to prevent any one participant from becoming legislator, market operator, auditor, and judge at the same time. Sure, industry bodies will need to play a role as could independent certification organizations, regulators and groups representing buyers and publishers. But whatever structure emerges, it will need legitimate participation from all sides of the market and a transparent process for changing the rules.


Governance is sometimes treated as something to address after a technology proves useful. With agentic trading, that would be a huge mistake. The more autonomy agents receive, the harder it will become to retrofit accountability after companies have built their businesses around them.

The question is not whether agents will occasionally make bad decisions—of course they will. The question is whether the market can identify those decisions, contain their impact, assign responsibility and provide a meaningful remedy. Without that governance, agentic trading may automate transactions, it will not create a market companies can trust, and will end up being limited in scale and adoption.


The central tension: Every layer required to make agentic trading safe and scalable is also a potential control point. Infrastructure that removes friction can also create dependency.

The New Control Points


If you ask me, agentic trading will not eliminate the advertising supply chain so much as rearrange it. Some intermediaries may lose relevance, while new ones emerge around the infrastructure agents need to transact. The most valuable positions may not belong to companies with the most intelligent agents, but instead belong to those controlling the discovery, protocols, integrations, verification, and settlement layers of the agentic stack.


In some ways, this creates a potentially uncomfortable possibility. Agentic trading is often presented as a way to reduce intermediaries and connect buyers and publishers more directly. In practice, it could produce a new group of even more deeply embedded gatekeepers. They may call themselves agent operating systems, orchestration layers, registries or protocol providers, but their power will come from controlling how agents find one another and conduct business.


Let's face it, incumbents begin with significant advantages. Large advertising platforms already possess the integrations, commercial relationships, data and transaction history agents require. A startup may build a better reasoning system, but without access to the platforms where media is purchased, delivered and measured, its intelligence remains locked outside the transaction.


Publishers and advertisers therefore face a familiar risk. A seller agent may represent a publisher while operating within rules and economics established by its technology provider. A buyer agent may claim to search the market objectively while favoring inventory, data or measurement services connected to its own commercial ecosystem.


Agentic trading may remove some intermediaries only to create new ones. The companies controlling discovery, protocols, execution, verification and settlement could become the market’s next gatekeepers.
Agentic trading may remove some intermediaries only to create new ones. The companies controlling discovery, protocols, execution, verification and settlement could become the market’s next gatekeepers.

Due to this dynamic, transparency about ownership and incentives will be as important as technical capability. Buyers should know whether their agents receive different economics from particular sellers or platforms, while publishers should know whether their agents benefit from routing transactions through certain demand sources. Open standards can reduce these risks, but they will not guarantee an open market. A protocol can be publicly available while the most valuable integrations, data and transaction volume remain concentrated inside a few companies.


The real test will be portability. Can a brand move its objectives, permissions and transaction history from one buyer agent to another? Can a publisher switch seller agents without rebuilding its product catalog and workflow? Can either side select an independent verification or settlement provider without losing market access? If not, agentic trading will reproduce the same lock-in under a new architecture.


The industry may believe it is building a new tech stack, but it may end up choosing its next set of intermediaries.


------------------------------------------------


Rio is an executive with 20+ years at the intersection of strategy consulting, AdTech, data, and media. He's a trusted advisor on customer experience, digital strategy, and marketing transformation. He's a partner at Credera, Omnicom's consulting arm. He's also a podcast host, writer, and public speaker focused on the future of advertising and AI-driven infrastructure.






Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page