Controlled beta for Google Ads advertisersRead the update
Guide · For DTC founders and operators

What is an AI marketing agent and what should you ask before giving one your ad account?

The term is doing a lot of work in a lot of marketing copy right now, and most of it means something different. This page sets out what the word should mean, how an agent differs from the two things people already use, and the five questions worth asking any vendor before you grant access to an account that spends real money.

Demo account · illustrative figures

Definition

The short version

An AI marketing agent is software that reads your marketing data on its own, forms a view about what is working, and either acts on that view or proposes an action for you to approve.

It decides what deserves your attention. This is the part that separates an agent from everything before it. A reporting tool presents everything it has and leaves the judgement to you. An agent does the judgement first and brings you the short list, which is only useful if it is right often enough to be worth reading.

It works from your account's own history. A useful agent compares this week to what is normal for you, because a 2.1 return on ad spend is excellent for one brand and a crisis for another. Any tool that tells you a number is good or bad without knowing your baseline is guessing, whatever it is built on.

It can show its working. A language model will produce a fluent explanation for anything, including a conclusion it invented. The only defence is evidence: the figures a claim came from, attached to the claim, so you can check rather than believe.

Everything else the category argues about, how autonomous it is, which model it runs on, how many integrations it claims, matters less than those three.

Three kinds

Three kinds of software get called an agent.

Dashboards and rules engines are good products and many people should buy one instead. They answer different questions, and the difference is easiest to see in who does the noticing.

Dashboards, rules engines and agents compared by what each asks of you
DashboardRules engineAI agent
Who notices something is wrongYou do, when you look.You did, in advance, when you wrote the rule.The software, on its own schedule.
What you configure firstWhich metrics to show.Conditions and thresholds for every case you can think of.An account to read.
Catches a problem nobody anticipatedOnly if you happen to be looking at the right chart.No. A rule fires on the condition it was given and no other.In principle yes. This is the whole reason to want one.
What you getNumbers, arranged.An action, already taken.A finding, a reason, and either an action or a proposal.
What it costs when it is wrongNothing. It reports what happened.A stale threshold keeps firing until you notice.Depends entirely on whether it needed your approval first.

The last row is the one to read twice. An agent's value and its risk come from the same property: it acts on a judgement rather than on a rule you checked. How much that should worry you depends on what it is allowed to do without asking, which is the first thing to establish about any vendor.

Before you connect

Five questions to ask before you connect an ad account.

These are worth asking of every vendor in this category, including us. A vendor who answers all five specifically is worth more of your time than one with a better demo.

  1. 01 What permissions is it asking for, and can I read them before I grant them?

    Consent screens are written by the ad platform and they are vague on purpose. Meta's ads management permission covers reading yesterday's numbers and pausing your best-performing campaign, in one line of text, with one button.

    What a good answer sounds like. The exact scope list, published before you sign up, with what each one is used for and which are read-only. A vendor who cannot show you that page is asking for trust they have not offered to earn.

  2. 02 Can it change anything without asking me?

    Autonomy is a spectrum, and every vendor in the category is somewhere different on it. The answer decides how much of your judgement you are handing over, and it is the question most likely to get a slogan back instead of an answer.

    What a good answer sounds like. A specific position. "You are always in control" is not one. Ask exactly which actions can execute unattended, whether that is configurable, and what the limit is on any single change.

  3. 03 Does it show the numbers behind a claim, or only the claim?

    A language model produces fluent, confident, well-structured explanations whether or not the underlying reasoning holds. Fluency is not evidence, and in this category it is the failure mode that costs money, because the output is a recommendation about where to move budget.

    What a good answer sounds like. Every claim traceable to a figure, and every figure traceable to the platform and the date range it came from. If a finding cannot be checked in under a minute, it cannot be trusted in under a minute either.

  4. 04 What happens when it is wrong?

    It will be wrong. The question is what that costs. An agent that can execute a budget change on a bad conclusion is a different product from one that can only propose it, even if the two demo identically.

    What a good answer sounds like. Hard limits that hold regardless of what the model decided, a person in the loop for anything that moves money, and a record of what was changed, when, and on whose approval.

  5. 05 Where does my data go, and does it train a model?

    Your ad account is competitive information: what you pay per customer, what converts, which creative works. It has value to somebody other than you.

    What a good answer sounds like. A named list of subprocessors, a written answer on model training rather than a reassuring adjective, and a data processing agreement you can actually read before you sign up.

Our own answers

How we answer our own five questions.

Written to be checked against the rest of this site rather than taken on faith. Every one of these links to the page that carries the detail.

  1. 01 Permissions

    Every scope we request for every platform is published on the integrations page, with what each one reads and what it can change. A new connection is read-only. Write access is a separate switch you arm yourself, and nothing arms it for you.

    See every scope

  2. 02 Autonomy

    Nothing changes in your account without you approving that specific change. There is no unattended mode and no setting that creates one. The agent can propose a fixed set of changes and no others, and each arrives as a card showing what would change, from what to what.

    See the approval flow

  3. 03 Evidence

    Findings carry the figures they came from, with the platform and the date range. The honest limit: a figure on screen does not print the minute it was fetched, so a number read this morning and a number read an hour ago look the same to you.

    See a worked finding

  4. 04 Being wrong

    Two limits sit outside the model and hold whatever it concludes. A budget increase above 300% is blocked before an approval card is ever created, and a change above 20% in either direction is flagged on the card as a learning reset. After a change executes, the platform is read again and the result is recorded.

    See the gates

  5. 05 Your data

    We do not train any model on your data. There is no fine-tuning pipeline and an accepted decision record in our repository rejects building one by name. Subprocessors are named individually, and the data processing agreement is on the site to read before you sign up rather than on request afterwards.

    Read the AI terms

What we do not do

What we do not do

The same disclosure the rest of this site runs on. If one of these is what you came for, the honest answer is that another product is a better buy.

  • No attribution modelling. We report what Meta, Google and Shopify each report, and we tell you which figure came from where. We do not model cross-channel credit and we are not building it.
  • No creative generation. We read how your existing creative is performing. We do not make ads.
  • No unattended action. Anything that changes your account waits for you, which is slower than a rules engine on purpose.
  • No certification. No SOC 2 and no ISO 27001. Our security page opens with that rather than burying it.
  • Meta and Google Ads write access is not described as live. Meta's app review sits outside this repository, and no Google Ads change has been evidenced end to end in production yet.

Questions

Questions people ask about the category.

Is an AI marketing agent the same as marketing automation?

No. Marketing automation executes a sequence you designed: if this, then that. An agent decides what matters without being told in advance what to look for. The difference shows up on the problem you did not anticipate, which is the only kind that actually costs you money.

Can an AI agent run my ads without me?

Some are built to, and some vendors sell that as the point. Ours is not, and will not be. A confidently wrong model with unattended access to a budget spends real money on a bad conclusion, and you find out days later from the invoice rather than at the moment it decides. There is no version of that we would want to explain to a customer afterwards.

Do I need one if I already have a dashboard?

Only if the dashboard is not being read. Most founders we talk to have one and open it when something already feels wrong, which is usually a week or two after it started. The gap an agent fills is the days nobody was looking, and if you genuinely check yours daily the case is much weaker.

What does it cost?

One initial Google Ads audit is included without a card. Repeat audits, scheduled monitoring, alerts and the agent require an active trial or plan. Solo and Studio are self-serve; Agency and Scale start with a conversation.

Controlled beta

Ask it about your own account

Connect Google Ads and run the included audit. Google’s consent scope can cover writes, but Sable Mako keeps writes off until you enable them, and every change still needs exact approval.