The pitch for agentic media buying is intoxicating in its simplicity. Hand an AI agent your goals and your budget, and let it plan, buy, and optimize across channels while your team sleeps. It is the logical endpoint of two decades of programmatic advertising, and it is genuinely arriving. But the closer agencies get to putting it into practice, the clearer it becomes that this is not a shrink wrapped product you switch on. It is a setup job, and the setup has to be redone for every single client.
That distinction sounds small and it is actually the whole story. A standardized software tool works the same way for everyone, which is what lets it scale cheaply. An agentic buying system does not, because the thing that makes it safe and useful is a thick layer of rules tuned to one specific client's world. Change the client and you change the rules, the risk limits, the definition of an acceptable error, and the channels it is even allowed to touch. The intelligence may be general, but the guardrails are bespoke.
Why one configuration cannot fit all
Consider the range of businesses a single agency serves. A pharmaceutical brand and a medical device maker operate under strict regulation where an error is not an inconvenience but a compliance failure. A financial services client carries its own legal constraints. An agriculture or alcohol advertiser lives with entirely different rules about where and to whom it can appear. Each of these demands work that is effectively error free, and each defines error differently. You cannot govern them all with the same settings.
This is why the leaders testing these systems describe control as something that has to be handled client by client rather than baked once into a platform. The guardrails shift not only with the client but with the AI model doing the work and the channel it is buying, so a setup that is safe for one combination may be reckless for another. Expanding from a single format like connected TV into online video, display, and streaming audio multiplies those combinations, and every new one is another environment that has to be configured and watched.
The spending tells the real story
For all the excitement, the money moving through these systems is still deliberately small, a low single digit share of total budgets. That restraint is not a sign the technology is failing. It is a sign that clients are sensible, unwilling to hand major spend to an autonomous agent until they have watched it behave inside their specific guardrails for a while. Trust in this context is not given. It is earned one controlled test at a time, and the budget grows only as the configuration proves itself.
That cautious ramp is worth respecting rather than rushing. The teams doing this well are treating early agentic buying as a supervised apprenticeship, giving the agent narrow, well defined jobs and expanding its authority only as it demonstrates it can be trusted in that client's environment. Anyone promising to route large budgets through an autonomous agent overnight is selling a story the practitioners are pointedly not buying.
What this does to the agency job
Here is the counterintuitive part. Automation was supposed to remove human labor from media buying, and in one sense it does, taking over the routine execution. But it replaces that labor with a different and arguably higher kind. The valuable work becomes building the guardrails, encoding each client's risk tolerance and compliance needs into rules an agent can follow, and governing the system as it runs. Configuration and oversight are not the leftovers of automation. They are the new core of the job.
That reframes what an agency is selling. Less the mechanical act of placing buys, which the machine now handles, and more the judgment to set the boundaries correctly and the vigilance to catch the agent when it drifts. It is specialized, expert work that does not scale the way software does, because it cannot be copied from one client to the next. The irony is that the more autonomous the buying gets, the more it depends on skilled humans to define the box it operates inside.
A note on working in the open
One more idea from the practitioners deserves attention, which is the case for transparency between competitors. Because everyone is learning how to configure and govern these agents at the same time, there is an argument that sharing what works, rather than hoarding it, could lift the whole industry's standards and create a small wave of improvement for everyone. That is an unusual instinct in a competitive business, and it reflects how genuinely new and unsettled this territory still is.
It also acknowledges a shared risk. If early agentic buying goes badly in a visible way, through a compliance disaster or a runaway spend, the damage to trust would fall on the whole category, not just the agency that stumbled. Working in the open is partly enlightened self interest, a recognition that in an unproven field everyone is safer if the collective bar for doing it responsibly is high.
The takeaway
Agentic media buying is real, and it is going to reshape how advertising gets executed. But the fantasy of a universal buy anything button is colliding with the messy truth that safety lives in the details, and the details are different for every client. The work is moving upstream, from placing the buys to designing the rules and watching the machine. Agencies that understand this will invest in the unglamorous craft of configuration and governance, because that is where the value and the trust now sit. The ones waiting for a one size fits all product to switch on will be waiting a long time, because the whole point is that one size never fit anyone.




