Refacto

Industry story

IAB Tech Lab Ships AAMP 2.3 for Autonomous Programmatic Buying

agent-framework ai-in-adtech brand-safety programmatic walled-gardens

The IAB Tech Lab released version 2.3 of its Agentic Advertising Management Protocols (AAMP), a standards framework enabling AI agents — software that acts autonomously on behalf of buyers — to execute programmatic ad transactions without human involvement. The update adds compatibility with Amazon Bedrock and Databricks (cloud AI infrastructure platforms), extends buying to Meta, integrates Google Ad Manager reporting, and embeds privacy and brand-safety tooling directly into the buyer agent layer. Notably, the spec explicitly states that inventory availability must be based on 'real, not derived' numbers — a clause the article frames as a tacit admission that the ad supply chain has historically had problems with fictitious inventory. The author argues the protocol's feature list reads like 'a list of things that have already gone wrong,' and that stacking autonomous negotiation on top of a supply chain with integrity problems is a significant open risk.

Analysis

Showing the shorter version.

IAB Tech Lab Ships AAMP 2.3 for Autonomous Programmatic Buying

The IAB Tech Lab published version 2.3 of AAMP, its protocol for letting AI agents buy programmatic advertising without a human in the loop. The update adds hooks into Amazon Bedrock (Amazon's cloud AI platform) and Databricks (the data and AI cloud), extends buying to Meta's inventory, and pulls Google Ad Manager reporting into the agent layer. It also bakes brand-safety and privacy rules into the protocol itself.

Buried in the spec is a clause requiring that inventory be "real, not derived." Somebody had to write that down, in 2026, after thirty years of RTB. A spec addendum does not fix a supply chain that still cannot reliably prove an impression exists. It just gives the old fraud a new place to hide, moving at machine speed.

The platform war hiding inside a standards release

The Bedrock and Databricks integrations are the part that actually matters for market structure. This is the header-bidding wrapper fight replayed at the agent layer: whoever owns the trusted agent runtime owns the toll booth. The question stops being "which DSP has the best UI" and becomes "which cloud runs the robot that spends the budget." Google wiring Ad Manager into the reporting layer is a defensive move, keeping measurement tied to its pipes while buying logic drifts toward the clouds. Amazon and Databricks sit on the winning side of that shift if AAMP gets real adoption.

Independent SSPs like Magnite and PubMatic are exposed. Their PMP and direct-deal relationships assume a human buyer who values those relationships. An autonomous agent has no loyalty to either.

Why this probably sits on a shelf

The IAB has shipped standards the industry then ignored. AAMP needs coordinated, honest implementation across buy-side platforms, sell-side platforms, two clouds, and two walled gardens simultaneously. Meta and Google have every incentive to adopt the parts that favor their own inventory and slow-walk the rest.

On the operator side, the tooling gap is real. DSP integrations, brand-safety checks, and reconciliation workflows all assume a human closes the loop. Autonomous buys generate discrepancy volumes no AdOps team can eyeball in real time, and nobody has yet answered who eats the loss when an agent buys at the wrong CPM or on junk inventory. That liability question will keep procurement and legal blocking production deployment until someone puts an answer in writing.

Our call: By the IAB's ALM in early 2027, no top-10 agency holding company will have moved a disclosed, material share of programmatic spend through fully autonomous AAMP agents without a human approval step in the loop. The supply chain integrity problem the spec itself confesses, combined with an unresolved liability gap and the IAB's own track record on adoption timelines, makes supervised pilots the base case. Real autonomous spend at scale would require the walled gardens to implement consistently and the liability question to close. Neither is close.

If you are evaluating a pilot: hard spend caps, mandatory reconciliation, and legal sign-off on liability before an agent touches real money.

Also covered this issue

Comments