Agentic media buying needs malware guardrails: A PropellerAds view
As AI takes on more campaign decisions, traffic-quality and security signals need to become part of the optimization logic.

Spy on Any Website
Agentic media buying is moving quickly from a conference-stage idea to something teams are actually using in production. IAB’s 2026 Outlook found that 96% of buyers are aware of agentic AI for ad buying, while 66% are already increasing their focus on it for ad buying and campaign execution.
That shift is hugely important because these systems are starting to move closer to the controls. They can analyze what is happening, decide what to do next and, increasingly, act on those decisions without waiting for a person at every turn. Human approval is moving from every decision to selected checkpoints.
Once that happens, the usual guardrails around spend and approvals only cover part of the picture. There is another question sitting underneath all of them: what is the agent allowed to trust?
A media-buying system can stay perfectly within budget and still make a very expensive mistake if the signals feeding it are incomplete. Give an autonomous system questionable inputs and it will not politely slow down to reconsider. It may simply become extremely efficient at following the wrong trail.
Spend limits only protect one side of the decision
Buyers already seem well aware that autonomy needs boundaries. In a separate IAB study, its July 2026 Digital Video Ad Spend & Strategy Report, 96% of digital video buyers saw a role for agentic AI in programmatic. At the same time, 40% wanted humans in the loop, 36% wanted an audit trail for explainability and 31% wanted explicit limits on what agents can do.
Those are sensible controls. They help define the size of the playground.
Media teams also need to think about the ground the agent is standing on.
Imagine a buying agent tasked with lowering acquisition cost while keeping spending within a fixed budget. And then it spots a source producing cheap conversions. The numbers look promising, and without a deeper check, the system starts sending more money in that direction.
From the dashboard, everything may look great.
But the problem with AI is that it’s extremely hard to give it a full context. Just a little upstream, the same numbers can be a total mess. A traffic-quality system may be seeing unusual behavior. A landing page may behave differently after launch. A redirect may introduce a questionable domain. The source may still look efficient on CPA while collecting warning lights further down the road.
Once AI can scale decisions automatically, those warning lights need to reach the driver before the system puts its foot down.
Performance and security can tell two different stories about the same traffic
Campaign moderation data already shows why this matters.
In PropellerAds’ Q2 2026 Ads Safety data, the total number of rejected campaigns fell 42% quarter over quarter, from 36,085 to 20,790. At the same time, antivirus and malware-related rejections moved in the opposite direction. Their share of all rejected campaigns rose from 23.3% in Q1 to 45.9% in Q2, while the absolute number increased by roughly 14%.
These figures come from PropellerAds’ own moderation data, so they should be read as a view into activity seen on the platform, not as a market-wide measure of malware activity.
That does not mean a high-performing traffic source is necessarily unsafe. What it does show is that performance signals alone cannot tell the whole story. Technical security signals need to remain visible throughout the campaign lifecycle, especially when an autonomous system is making decisions continuously. If the agent can react to performance in real time, it also needs to be able to react when the security picture changes.
Cloaking offers another example. It accounted for 67.3% of advertiser suspensions in Q2, compared with 68.1% in Q1. The number barely moved.
That persistence is important for autonomous buying because cloaking thrives on differences in what different systems see. Content may vary by location, device, visitor profile or moment of inspection. One observer sees a perfectly ordinary storefront. Another opens the side door and finds a very different room.
External research shows a similar visibility problem. In GeoEdge’s most recent public malvertising data, auto-redirects accounted for 45% of all attacks – up 25% year over year.
For a buying agent, this means the number sitting on the dashboard may only be one gauge among several, and not necessarily the one that matters most right now.
This is close to how PropellerAds runs its own moderation stack: traffic-quality and security checks operate continuously alongside performance data, rather than as a separate audit that happens after a campaign has already scaled. As agentic buying takes on more of the decision-making, that kind of always-on evidence layer is exactly what lets a system tell a genuinely cheap conversion apart from one that only looks cheap until the traffic behind it gets flagged.
Security signals need to play a more prominent role in optimization processes
For years, optimization and security have often lived in neighboring rooms yet didn’t really cross paths.
The optimization system watches performance and hunts for better outcomes. Security and moderation systems scan for risk, investigate anomalies and step in when something crosses a line.
That setup becomes harder to sustain when an AI agent can spend real money on its own.
If a system can raise a bid, shift spend or scale a traffic source because the numbers improve, then traffic-quality signals need enough authority to influence that same decision loop.
A useful way to think about it is as a second set of traffic lights.
A strong performance signal may give the agent a green light to scale. A mild anomaly could turn that green into amber and slow the pace while the system gathers more evidence. A high-confidence security alert may require a full stop and human review.
The point is to let risk travel through the same plumbing as optimization.
Otherwise, security ends up flagging the wrong turn several exits after the car has already taken it.
Human review works best at the messy edges
“Keep a human in the loop” sounds reassuring, and in many cases it is the right principle. The problem comes when every loop leads back to a person.
If every bid change, source adjustment or budget move needs human approval, the agent stops being autonomous or even useful. Cleaning its messes and checking things up after it becomes a task that takes up more time than doing it manually, the old-fashioned human way.
A more practical approach is to send humans the situations where context really matters.
Machines are good at scanning huge volumes of signals, spotting recurring patterns and flagging behavior that has drifted away from normal. They can also handle routine decisions when the evidence is clear and the risk is low.
Humans become especially valuable in the gray zones: when performance is strong but a security signal looks strange, when a new pattern does not fit existing rules, or when the financial impact is large enough to justify a second pair of eyes.
That approach also makes accountability easier to manage. Teams can define thresholds and escalation rules ahead of time, then preserve enough context to understand how a decision was made later.
PropellerAds runs a version of that same split inside its own AI agent, NIKO. It looks up rates, targeting options and account stats on its own, but anything that would actually touch a campaign or spend budget stops for an explicit confirmation, shown with the full set of parameters attached, before it executes. The AI moves at full speed on the parts that carry lower-risk, non-executing tasks, and pauses exactly where the stakes start.
That last part matters because buyers are already asking for auditability. In IAB’s July 2026 report, 36% said they wanted an AI-agent audit trail for explainability.
For media buying, an audit trail should capture the breadcrumbs. What did the agent see? Which signals mattered? What changed its confidence? Why did it keep scaling, slow down or escalate?
When real money moves automatically, “the model decided” doesn’t tell anyone which gauge it was watching.
Autonomous buying needs two feedback loops
Media optimization has become very good at chasing opportunity.
Where is the conversion probability higher? Where can the next dollar work harder? Which source deserves more budget?
Agentic systems can run through those questions at a speed no human team can match.
As those systems take on more execution, they also need a parallel view of risk.
Is this traffic behaving normally? Are the signals lining up? Has something changed further along the user journey? Is this still a situation the agent is cleared to handle on its own?
Experience across campaign optimization and moderation suggests these questions belong inside the same operating model.
A buying agent should know where the accelerator is. It should also know what the warning lights mean.
That may end up being one of the defining guardrails for agentic media buying: giving autonomous systems enough context to know when a promising opportunity is worth scaling, and when it deserves a closer look first.
Written by:
Julia Larionova
Head of Marketing at PropellerAds
Opinions expressed in this article are those of the sponsor. MarTech neither confirms nor disputes any of the conclusions presented above.
Add us as a preferred source on Google
Google's "preferred sources" feature allows users to customize their search results by selecting news outlets they want to see more often in the "Top Stories" section.
Add Martech Now