
Through 2026, AI in ad accounts stopped being an advisor and became an operator. Two major platforms opened their interfaces so an external AI agent, not just a human logged in through a browser, can write to your account.
On Meta it has a name: the ads MCP server. Meta launched it on 29 April 2026 and on 16 July 2026 opened it to any developer, with no approved-partner status required. Through it, an assistant like ChatGPT, Claude or Perplexity connects to your ad account and, with the right permission, can create and pause campaigns, change targeting, edit the catalog and adjust budgets.
An agent with write access to a live ad account can spend real budget, so scoping access tokens and OAuth permissions belongs in the setup, not after it.
Google is moving the same way from the other side. Its Ads Advisor, an agent built on Gemini models, was announced on 12 November 2025 and can “apply approved changes directly to your account in just minutes.” It starts with English-language accounts, but the direction is clear: in-account AI that acts, not only advises.
The technology is not the danger; the setup is. Turning a connector on takes a minute. Giving it sensible permissions and checkpoints takes someone who knows what each access level actually allows.
That gap showed up clearly at Meta. When the platform updated its permission panel on 11 August 2026, Jon Loomer — one of the most respected authorities on Facebook advertising — reported that across all his accounts it opened with every agent action enabled, budget changes included.
On all of his accounts the panel opened with all seven agent actions allowed, including budget changes.
Meta did add fine-grained control over nearly a hundred tools. But the starting position was “allowed,” not “off.” Anyone who connects an agent and does not review the scopes by hand may be handing it actions they never meant to grant.
A foreign brand launching in the Czech market rarely runs the account alone. You hand access to a local agency, a Czech-speaking freelancer, a market-entry partner, maybe an AI tool on top — often remotely, in a language you do not read, under time pressure. That is exactly the situation where access sprawl builds up unnoticed.
An agent with write and financial access can spend real money and switch off a profitable campaign, and it can do so without a human approving the step. Picture three scenarios, none hypothetical: a tool with broad access “optimises” the budget upward overnight and you wake to double the spend; an agent judges a campaign weak and pauses it, when that was the one bringing in leads; or access lingers with someone you never meant to keep. In all three, the cause is a permission setting, not malicious AI.
The most expensive access to an account is the one you do not know about. It need not be abused by an attacker; a well-meaning automation making a big change faster than you notice is enough.
This is about order, not complexity. The same checklist secures the account whether or not you use AI.
Yes, if you grant the permission. Meta’s 2026 ads MCP server lets assistants like ChatGPT, Claude or Perplexity connect to the account; with write access an agent can create and pause campaigns, change targeting and adjust budgets. Google’s Ads Advisor can apply approved changes directly. The agent only does what the configured access scope allows — the catch is that defaults are often broader than owners expect.
It is a standardised interface through which an AI tool reads from and writes to your ad account. Meta launched it on 29 April 2026 and opened it to any developer on 16 July 2026. It offers three access levels: read only, read and write, and read, write and financial, the last including billing and spend limits. How safe it is depends entirely on the scopes you set and who holds the token.
In Google Ads open Tools and settings, then Access and security. In Meta Business Manager check People, Partners and Integrations, where AI connections via the MCP server are managed. Review every entry and confirm its permission level, paying special attention to anything with write or financial access you did not deliberately grant. Remove what you do not recognise or use.
Start at the lowest level that makes sense. Read-only is enough for analysis and recommendations. Grant write only to a tool under human control, ideally where the agent proposes and a person approves. Do not give financial access — billing and spend limits — to an automated agent in practice. Add permissions as needed, not in bulk up front.
Ads Advisor, built on Gemini models, analyses the account, proposes optimisations and, once approved, can apply them directly — for example adding sitelinks or generating keywords and creatives. Google announced it on 12 November 2025, starting with English-language accounts. Analytics Advisor only advises and explains. Remember Ads Advisor comes from a platform whose revenue grows with your spend, so treat its suggestions as input, not instruction.
We audit access and integrations on your Google and Meta accounts, remove what should not be there, and set AI tools sensible permissions with human approval on the big changes. From Prague, in native Czech.
Talk to our Prague team