Insights · News

AI Can Now Change Your Ad Budget. Who Holds the Keys in Your Czech Account?

By RKP Agency, Prague8 min read
The short version
  • In 2026, AI tools gained direct write access to ad accounts on both Meta and Google. An agent can now change budgets, pause campaigns and rewrite targeting, not just advise.
  • Meta launched its ads MCP server on 29 April 2026 and opened it to any developer in July. Google’s Ads Advisor can apply approved changes straight into the account.
  • Defaults are not on your side. Jon Loomer found Meta’s permission panel opened with every agent action switched on, budget changes included.
  • Entering Czechia, access governance matters more, not less — you are handing a local agency, freelancer or AI tool the keys to the account that spends your money, often from a distance.
A robotic hand holds a glowing key over an open vault that reveals a floating dashboard with budget dials and charts

What actually happened

Through 2026, AI in ad accounts stopped being an advisor and became an operator. Two major platforms opened their interfaces so an external AI agent, not just a human logged in through a browser, can write to your account.

On Meta it has a name: the ads MCP server. Meta launched it on 29 April 2026 and on 16 July 2026 opened it to any developer, with no approved-partner status required. Through it, an assistant like ChatGPT, Claude or Perplexity connects to your ad account and, with the right permission, can create and pause campaigns, change targeting, edit the catalog and adjust budgets.

An agent with write access to a live ad account can spend real budget, so scoping access tokens and OAuth permissions belongs in the setup, not after it.
— Relevant Audience, on Meta opening the ads MCP server to all developers (2026)

Google is moving the same way from the other side. Its Ads Advisor, an agent built on Gemini models, was announced on 12 November 2025 and can “apply approved changes directly to your account in just minutes.” It starts with English-language accounts, but the direction is clear: in-account AI that acts, not only advises.

Why the defaults are the real risk

The technology is not the danger; the setup is. Turning a connector on takes a minute. Giving it sensible permissions and checkpoints takes someone who knows what each access level actually allows.

That gap showed up clearly at Meta. When the platform updated its permission panel on 11 August 2026, Jon Loomer — one of the most respected authorities on Facebook advertising — reported that across all his accounts it opened with every agent action enabled, budget changes included.

On all of his accounts the panel opened with all seven agent actions allowed, including budget changes.
— Jon Loomer Digital, “Meta Ads AI Connectors Get More Security Controls” (11 August 2026)

Meta did add fine-grained control over nearly a hundred tools. But the starting position was “allowed,” not “off.” Anyone who connects an agent and does not review the scopes by hand may be handing it actions they never meant to grant.

Why this matters more when you enter Czechia

A foreign brand launching in the Czech market rarely runs the account alone. You hand access to a local agency, a Czech-speaking freelancer, a market-entry partner, maybe an AI tool on top — often remotely, in a language you do not read, under time pressure. That is exactly the situation where access sprawl builds up unnoticed.

  • Handovers leave residue. A trial tool, a former agency, an ex-contractor — each can keep write or admin access long after the relationship ends, because no one removed it.
  • Financial scope is easy to over-grant. Meta’s top tier includes billing and spend limits. Handed to an automated agent, that is budget control without a human in the loop.
  • Distance hides the change. A budget that doubles overnight or a winning campaign paused by an agent is harder to catch when you are a time zone away and not watching the Czech account daily.
The market-entry version of the mistake: you focus on who writes the Czech copy and forget who can move the Czech money. The second question is the one with a direct cost.

What it costs, in real terms

An agent with write and financial access can spend real money and switch off a profitable campaign, and it can do so without a human approving the step. Picture three scenarios, none hypothetical: a tool with broad access “optimises” the budget upward overnight and you wake to double the spend; an agent judges a campaign weak and pauses it, when that was the one bringing in leads; or access lingers with someone you never meant to keep. In all three, the cause is a permission setting, not malicious AI.

The most expensive access to an account is the one you do not know about. It need not be abused by an attacker; a well-meaning automation making a big change faster than you notice is enough.
— RKP Agency

How we would approach it

This is about order, not complexity. The same checklist secures the account whether or not you use AI.

  • Inventory access — in Google Ads under Access and security, in Meta Business Manager under People, Partners and Integrations. Remove anything you do not recognise or use.
  • Lowest useful level — read-only is enough for analysis and suggestions. Grant write only to a tool under human control.
  • Keep finance out of automation — billing and spend limits belong to named people, essentially never to an automated agent.
  • Human approves the big moves — budget increases and campaign pauses wait for a person to confirm. Add two-factor on admin accounts and a quarterly access review.
One caveat worth stating plainly: an AI agent in the account is an excellent servant and a poor master. Used with read access and approval gates, it finds wasted budget in minutes. The difference between help and damage is the permission level, not whether you let it in.

FAQ

Can AI really change my ad budget on its own?

Yes, if you grant the permission. Meta’s 2026 ads MCP server lets assistants like ChatGPT, Claude or Perplexity connect to the account; with write access an agent can create and pause campaigns, change targeting and adjust budgets. Google’s Ads Advisor can apply approved changes directly. The agent only does what the configured access scope allows — the catch is that defaults are often broader than owners expect.

What is the Meta ads MCP server?

It is a standardised interface through which an AI tool reads from and writes to your ad account. Meta launched it on 29 April 2026 and opened it to any developer on 16 July 2026. It offers three access levels: read only, read and write, and read, write and financial, the last including billing and spend limits. How safe it is depends entirely on the scopes you set and who holds the token.

As a foreign brand, how do I check who can access my Czech account?

In Google Ads open Tools and settings, then Access and security. In Meta Business Manager check People, Partners and Integrations, where AI connections via the MCP server are managed. Review every entry and confirm its permission level, paying special attention to anything with write or financial access you did not deliberately grant. Remove what you do not recognise or use.

What permissions should I give an AI tool managing ads?

Start at the lowest level that makes sense. Read-only is enough for analysis and recommendations. Grant write only to a tool under human control, ideally where the agent proposes and a person approves. Do not give financial access — billing and spend limits — to an automated agent in practice. Add permissions as needed, not in bulk up front.

What can Google Ads Advisor do by itself?

Ads Advisor, built on Gemini models, analyses the account, proposes optimisations and, once approved, can apply them directly — for example adding sitelinks or generating keywords and creatives. Google announced it on 12 November 2025, starting with English-language accounts. Analytics Advisor only advises and explains. Remember Ads Advisor comes from a platform whose revenue grows with your spend, so treat its suggestions as input, not instruction.

Sources

  1. Meta — ads MCP server (mcp.facebook.com/ads), launched 29 April 2026; opened to all developers 16 July 2026. Reported via relevantaudience.com
  2. Jon Loomer Digital — Meta Ads AI Connectors Get More Security Controls (default permissions finding, 11 August 2026). jonloomer.com
  3. Google — Ads Advisor and Analytics Advisor (executes approved changes; 12 November 2025). blog.google

Know who can move your Czech money

We audit access and integrations on your Google and Meta accounts, remove what should not be there, and set AI tools sensible permissions with human approval on the big changes. From Prague, in native Czech.

Talk to our Prague team
CallWe’re online