Argued Agentic Ad Lab

Who Is Actually Running Agentic Buys: A Sourced Ledger

A dated ledger of named agentic media deployments since December 2025, and an audit of the headline figures against the vendors that published them.

18 min read 7 chapters

A judgement, signed. The evidence is checkable; the conclusion is mine to defend.

Agentic buying is real, it is eight months old, and it is smaller than one large publisher’s monthly revenue. Eight named deployments have transacted since December 2025, and only five of them are campaigns rather than platform aggregates. Exactly one advertiser has put its name to any of them. Three produced a number anybody could quote, all three of those numbers came from a company that sells agentic software, and that last fact decides how you read every case study you will be shown this year. Push on those numbers and they stop agreeing with each other, and each split traces back to whoever published it.

The buys that have actually run

Two threads on r/programmatic have been asking for that list. One put it bluntly: “Literally give me one example of an advertiser actually using either.” The January thread filed the category under “blockchain sandbox NFT IOT flying cars” pending tangible examples, and the closest it got to an answer was one publisher saying they had started integrating on the sell side with Magnite.

Three names carry the protocol column. AdCP, the Ad Context Protocol, is the buying-and-selling spec most of these deployments run on. AAMP, IAB Tech Lab’s Agentic Advertising Management Protocols, is the competing framework, and the two are compared here. A row marked MCP means the agents had a way to talk to each other and no published buy-side spec governed the commercial content of what they said.

A row qualifies when a named company is on the record, with a date, that something transacted. The window opens in December 2025, and the ledger is current as of 12 August 2026.

WhoWhenWhat ranProtocolReported resultWhere the number comes from
Butler/Till + PubMatic, for Geloso Beverage GroupTwo flights, December 2025 into January 2026CTV for the Clubtails brand across Samsung, Paramount, Vizio and Tubi, planned and executed by agents from a natural-language brief, with agency sign-off on the curated inventoryAdCP, per PubMatic5.5x buy-side supply-chain cost efficiency; 40% more impressions than planned; about 30% lower effective CPM; 98% video completion. Quality checked by the verification firm Jounce. Budget not disclosedVendor press materials, reported by Marketing Dive and Digiday
Magnite + Scope3December 2025, announced 6 January 2026Seller agent inside SpringServe; first AdCP test buys with LG Ad Solutions, MiQ and Warner Bros. DiscoveryAdCPNone publishedMagnite, via ppc.land
NBCUniversal + RPA + FreeWheel + Newton ResearchAnnounced 6 January 2026, Q1 2026 flightBuy-side and sell-side agents transacting a single premium video investment across linear and streaming, including live NFL playoff inventoryMCPNone publishedVendor announcement, reported by AdExchanger
Yahoo DSP + Newton, RPA6 January 2026External agents connect to Yahoo DSP over MCP; a Newton and RPA trafficking agent has executed programmatic guaranteed buysMCPNone publishedYahoo
PubMatic AgenticOSAnnounced January 2026, after running the Butler/Till flight in December 2025; 250+ deals reported in March, 1,000+ cumulative through Q1, 4,000+ through Q2Agentic deal transaction at platform scale; 80+ fully autonomous end-to-end campaigns by Q2, spanning all five holding companiesAdCP plus proprietary agentsLevel Agency, 2x reach per dollar against its incumbent DSP; a Spain CTV campaign 18% below target CPM and 23% over impression goalPubMatic Q2 2026 results, an unaudited operating metric in an earnings release
OmnicomDisclosed on the Q1 2026 earnings call, late April 2026Live media buys for selected clients on an agent-to-agent framework, aimed at shrinking the intermediary takeAdCPNone publishedCompany statement, reported by Digiday and AdExchanger
Boostr + Vox MediaJune 2026, announced 9 June 2026Seller agent received, negotiated and closed a campaign-level buy covering budget, audience and delivery schedule; Vox staff accepted the buy and verified it in the ad serverAdCPNone published; the claim is that hours of manual setup were removedVendor press release
Magnite Orchestration, with dentsu and DIRECTV Advertising11 June 2026A neutral layer connecting third-party buyer agents to Magnite supplyAdCP“A handful of millions of dollars” transacted agentically to date, against the roughly 9 billion dollars of ad spend Magnite processesQ2 2026 earnings call, 5 August 2026

One buy clears the on-the-record half of that rule and is still not in the table, on two grounds. On 16 October 2025 a Scope3 buyer agent transacted with a Swivel sell-side agent against LG Ad Solutions inventory over AdCP, two humans approved it, and MediaPost reported it as “a real, transactional buy. Money got exchanged in the end.” It falls outside the window by about six weeks, and the advertiser, a non-alcoholic drink brand called Ematini, was invented for the demonstration, which is the one thing the rule does not test for.

Eight rows, three different units. Two are platforms reporting aggregate volume: PubMatic AgenticOS and Magnite Orchestration. One is a seller-agent integration with named test buys behind it, Magnite and Scope3 inside SpringServe. The other five are discrete campaigns or buy programmes, where a brief went in and media came out. Eight is the number a vendor will quote at you. Five is the number that means something ran.

That standard undercounts, and in one place the size of the undercount is knowable. PubMatic said in March that nearly 100 brands, agencies and streamers had applied to its Agentic AI Acceleration Program. PubMatic’s Harry Tong told Digiday the company is running tests with “upwards of 10” agency partners and declined to name any of them. The table above carries one PubMatic campaign. The public ledger is a floor, not a census.

The ledger also has a hole where the biggest buyers should be. Yahoo’s DSP is in it. The Trade Desk got as far as an alpha, which is the next table’s business. Google’s DV360, Amazon DSP and Meta appear in neither table, and none of the three has named an agent-to-agent buy on the public record. The platforms that spend most of the world’s programmatic money have published nothing that would fill a row, and on a proof-of-deployment list that absence is worth more than most of the rows.

Ari Paparo, founder and chief executive of Marketecture Media, gave a reason to expect exactly that in November 2025: buyers do not want to be “price takers” and sellers do not want their rate cards inside an MCP server. He calls AdCP’s creative protocol brilliant in the same piece, so the objection lands on the media-buy half, which is the half every row above uses.

Shipped the infrastructure, no campaign to point at

Real products. No advertiser has been named on any of them.

WhoWhenWhat shippedProtocol
Kochava StationOne, with IAB Tech Lab24 March 2026Open-source workspace over IAB Tech Lab’s AAMP buyer agent reference implementation, 19 skills across 8 functional areas, for experimenting with agentic workflows without executing real transactionsAAMP, on OpenDirect 2.1
CNNReported 6 April 2026In-house agent-to-agent buying and selling for CNN’s article and short-form video inventory; testing during 2026, full-scale transactions targeted for early 2027Not stated
PMG7 April 2026Alli, the agency’s operating system, integrated with the AAMP buyer agent architecture and the AAMP agent registryAAMP
Zefr21 April 2026Zain, an agentic hub for YouTube, TikTok and Meta that turns a natural-language request into a live campaign inside Google’s buying stackAdCP over MCP
The Trade Desk21 April 2026Koa Agents in alpha, with Stagwell as the first agency partner building on The Trade Desk’s MCP; beta to select clients was expected later in the summerMCP
FOX Advertising17 June 2026End-to-end agentic platform on FOX AdStudio, with WPP, Horizon Media, Universal Ads by Comcast and Simulmedia named; Horizon runs agent-led planning from its Blu platform, Simulmedia covers automated linear spot buyingNot named; the release says “a security and governance-first protocol”

Fox sits here rather than one table up because the release reports no executed transaction and MediaPost’s account of the Cannes demonstrations does not confirm one. Kochava’s StationOne is here for a stranger reason: it was built not to transact.

Every headline number was published by a seller, and the numbers disagree

PubMatic’s AgenticOS ran the Butler/Till buy and PubMatic’s supply chain carried it. The 5.5x compares that path against what the two companies call the standard economics of traditional DSPs, and it gets much more useful when you take it apart. PubMatic’s own case study puts the same result at about an 80% reduction in buy-side costs. Digiday reports 82%, specifically in DSP tech fees. 5.5x is one divided by 0.18: the identical number restated as a multiple, by the company that removed the fee.

That covers three of the four supply-chain figures in circulation, and they do not share a publisher: 5.5x and the 80% are PubMatic’s own, the 82% is Digiday’s reporting. The fourth is PubMatic’s again, and it breaks the arithmetic: its 25 March 2026 release with the Untapped Growth Collective puts early agentic campaigns at a 40 to 50% reduction in supply chain costs, eight days after Digiday’s 82%, with no method attached to either.

That is the disintermediation thesis, proved and priced, and it settles one half of the argument the trade press has been having with itself. Paul Bannister of Raptive has been the clearest voice for the optimistic case, arguing that agentic trading “puts the buyer directly in touch with the publisher’s ad server and removes other middlemen”. On fees, the Butler/Till result is his evidence and it is good evidence. Craig Tuck of Ozone says the “biggest risk we see with an innovation like AdCP is decreasing transparency and control”, and this ledger is his evidence too. The fee came out of a supply chain only PubMatic can see, the saving was published by the party that charged the fee, and nobody outside PubMatic can reconstruct why those particular impressions were bought. Bannister wins the fee argument. Tuck wins the one that decides whether you can audit next year’s spend, and he wins it on Bannister’s own case study.

Buyers in a separate r/programmatic thread have reverse-engineered a supply-cost saving of that size and landed on two different mechanisms. One:

This stat is misleading. If you assume 15% dsp fee and 15% ssp fee the all in “supply costs” are 30%. If you move the buy to Activate and they only charge you a 6% tech fee on the bidder, you’ve reduced your “supply cost” by 80%.

The other, from u/Jaeger999, gets the same 80% out of a change in inventory source type, moving from PMP to programmatic guaranteed and “~15% fees to ~4% fees”, and asks whether the vendors running the test simply waived their fees for it. Two mechanisms, one published number, nothing in the release that picks between them, and a CPM premium hiding inside the second. AdCP 3.1.13 does carry a fee field, and it is not the one that would settle this: price_breakdown is an optional object on package (/schemas/3.1.13/pricing-options/price-breakdown.json), populated by the seller, describing the effective price of a single package. Nothing in it states the buy-side DSP fee the 80% and the 82% turn on, and nothing obliges a seller to send it at all, so a saving of this shape stays unreconstructible on the wire; what the two stacks leave unstandardised covers that hole.

It is also the limit of what the number says. Removing a DSP fee is a supply-chain result, not an agent result, and nobody has isolated the agentic layer inside it. The budget was never disclosed either, so from outside you cannot tell whether 40% more impressions than planned is agent optimisation or simply what a 30% lower effective CPM buys you on the same money. Gina Whelehan, group director of strategic partnerships at Butler/Till, declined to give Digiday the figure, which is a firmer fact than silence. That 30% is in PubMatic’s own case study and it travelled the least of any figure in the set, which is odd, because it is the one a planner would care about most.

One figure gets closer to the agent layer than any fee number does, and it is published twice. Digiday has campaign setup time down 98%, which is a workflow measure and not the 98% video completion in the Butler/Till row above, a delivery measure that happens to carry the same digits. PubMatic’s 25 March release with the Untapped Growth Collective, eight days later, has setup time at 87%. Neither figure appears in the ledger above, because the table records what the campaigns delivered and setup time is a claim about the workflow that produced them. Neither gives a baseline, a campaign count or a definition of setup, and faster setup is as easily a workflow-tooling result as an agent one.

The quality numbers are the exception in this ledger, and the two outlets that reported them disagree. Marketing Dive, working from press materials, published under 1% DoubleVerify failure and 0% made-for-advertising. Digiday reported that an independent audit by the verification firm Jounce found an MFA rate below 1%, with 80% of the inventory rated higher than DoubleVerify’s typical benchmark. Two outlets, two different numbers, one campaign, and no way from outside to tell which figure Jounce actually produced. Digiday’s version is the stronger claim precisely because it is the one place in this entire ledger where a third party looked at an agentic campaign and measured something.

The deal counts have the same shape and a weaker defence. 4,000 AI-powered deals transacted to date is a count of deals; the spend behind them has never been published, and the figure is an unaudited operating metric in an earnings release. What is useful in it is the curve, 250 to 1,000 to 4,000 across two quarters, which is real acceleration in something. The absolute number still tells you almost nothing about money.

Five rows in the first table publish no result at all. Four of them, NBCUniversal, Yahoo, Omnicom and Vox Media, confirmed a live transaction and then published no performance delta. The fifth, Magnite and Scope3 inside SpringServe, is an integration with test buys behind it rather than a client campaign, so it never had a delta to publish. The reasons could be commercial as easily as unflattering, since agencies and holding companies almost never publish client-level results for any tactic. But a delta is the thing that would settle the argument, and eight months in, nobody has produced one.

Nothing has gone wrong either, on the public record. No pulled campaign, no rerun, no agent that mispriced a buy, no integration that stalled with a name attached to it. Every row here is a success or a silence, which is exactly what a ledger assembled from press releases would look like whether or not the failures exist. The sharpest objection to the Butler/Till buy sits in its own announcement thread, from the ad-fraud researcher Augustine Fou: “ALL of the content inside the context protocol can be falsified and will be falsified by the bad guys to game the system. The AI wont know what’s fake or not fake.” Right or wrong, no row above is shaped to show it.

The one comparison that came from outside the campaigns

DataBeat, a programmatic analytics provider working with the revenue-operations firm MediaMint, published its US Programmatic Trends report on 22 June 2026 using May 2026 marketplace data: more than 55 million dollars of monthly revenue, 35 billion monthly impressions, over 200 bidders. It is the only agentic-versus-conventional comparison in circulation that was not written by a party to the campaigns it describes.

Independent of the campaigns is not the same as disinterested. DataBeat had no stake in the buys it measured and it has a direct stake in you reading the report: it sells analytics into this market, the report is monthly marketing, and its own conclusion is that agentic buying has moved past the experimental stage and stands to become a larger contributor to publisher monetisation. The numbers are still worth having, because they are the only ones of their kind.

MetricConventional demandAgentic demand
Average CPM (USD)6.956.13
Fill rate0.183%0.204%
Auction participationBaseline86% fewer auctions

Conventional buyers paid a 13.4% CPM premium, which reads either as agents avoiding overpayment or as agents winning inventory conventional demand had already declined. The fill rate would settle it if it were sound: an 11.5% relative edge between two fractions of one percent is not load-bearing, DataBeat never defines how either rate was derived, and ppc.land points out that a conventional fill rate measured the usual way runs far above 1%, so whatever these two numbers are, they are not that. Take them at face value anyway, pair them with 86% fewer auctions, and the unflattering reading fits better than the flattering one: curated, pre-negotiated supply does not clear at a fifth of one percent, and bidding rarely into thin competition does. DataBeat itself hedges that it is worth assessing whether the edge comes from inventory quality or from win-rate optimisation.

The scale figures at the top of the report and the CPM row do not describe the same base. 55 million dollars over 35 billion impressions is an effective CPM of about 1.57 dollars; clearing 6.95 dollars on 35 billion impressions would take roughly 243 million dollars a month. So either the revenue and impression totals cover a wider footprint than the CPM sample, or one of the three is counted a way DataBeat has not published. The report does not say which.

The table is also sold two ways. ppc.land ran it as a 13.4% CPM edge for conventional buyers. DataBeat’s own author posted the same figures to r/programmatic as a win for the machines: “The AI driven side is entering 86% fewer auctions but still hitting comparable CPMs and actually a higher fill rate. Bidding far less, converting better.” That post also records a revision, made because “the Agentic DSP section in our previous post sparked some confusion”, with no copy of the earlier version public. It is one network for one month, and still the only outside look anyone has published.

Where is AAMP in this ledger?

AAMP appears twice in these tables, both times in the second one, and neither appearance belongs to an advertiser: Kochava’s StationOne workspace on 24 March 2026, and PMG connecting Alli to the AAMP buyer agent architecture on 7 April 2026. The AAMP agent registry opened on 1 March 2026 and held ten entries by 11 March, every one of them declaring an MCP deployment and none A2A, the agent-to-agent transport that competes with MCP. Amazon Ads donated a bidstream component. Google, The Trade Desk, Amazon and Meta are named as members. Kochava built the flagship workspace, and its purpose is running AAMP workflows without executing real transactions.

So if a vendor is selling you AAMP compliance in 2026, they are selling you a roster. Every buy in the first table above ran on AdCP or on raw MCP.

The entire market is still a rounding error

Michael Barrett, Magnite’s chief executive, told an interviewer in July 2026 that the most optimistic forecasts he collected at Cannes put total 2027 agentic ad spend at 600 to 700 million dollars, and on the August earnings call he widened the range of answers he gets from customers to “0 to 1 billion dollars for the whole industry”. Magnite alone processes about 9 billion dollars of ad spend a year, which is roughly 170 million dollars a week. The top of Barrett’s own industry-wide forecast for 2027 is four weeks of Magnite’s pipe.

There is no urgency argument in those numbers, and I would not let a vendor build one for you out of a deal count. The case for running something this year is optionality: you learn what your own supply chain costs when a machine assembles it, at a budget you can afford to lose. What a defensible first pilot looks like is a separate question from whether the market is real yet.

What to carry into the next vendor call

So the number to carry into a business case is zero. Model your pilot at no media saving at all. If a fee really comes out, it shows up in your own reconciliation and costs you nothing to have not forecast; forecast it from somebody else’s press release and you have committed to a saving whose mechanism you cannot inspect. AdCP will not do the reconciling for you either: the one fee field in 3.1.13 is optional, seller-populated and scoped to a single package, so nothing on the wire obliges a counterparty to state what it took.

Who is on both sides of the trade? Run that on the next vendor who shows you a number. When one company supplies the buying agent and carries the supply, the saving it reports is the saving from removing a fee it was already positioned to remove, and that can be entirely honest while saying nothing about what the agent is worth to you. The practitioner version of it got 20 upvotes under the Butler/Till announcement: “So Pubmatic, an SSP, found inventory cheaper by not buying through a DSP? No shit.”

What was the budget, and did anything run against it? One order of magnitude is public, in the same Digiday piece that carries Tuck: John Goulding, chief strategy officer at MiQ, put its AdCP tests “in the five-figure territory”, run through an agent built inside MiQ’s own Sigma platform. That prices the experiment, not the prize. Every published figure so far is measured against a counterfactual, never a control. Ask for the control instead: same budget, same weeks, same market, bought the old way. Nobody has published one, so a vendor who offers to run one alongside your pilot is telling you more than the 5.5x does.

Then ask to speak to the advertiser. There is one. Geloso Beverage Group is the only brand that has let its name go on a transacting deployment since December; Level Agency is an agency and Vox Media is a publisher, and all three were put into a press release by the vendor that served them, so a reference call costs that vendor nothing if the campaign happened the way the release says it did.

One thing worth raising on that call, because both campaigns get described as fully agentic: in the Butler/Till buy a person signed off the curated inventory, and at Vox a person accepted the buy in the ad server before it launched. A third vendor ships that gate as its default. TeqBlaze describes its AdCP sales agent flow as buyer agents sending deal requests, the sales agent structuring the offer, and then “you review and approve the deal before anything goes live”.

Questions to ask an agentic advertising vendor carries the mechanism checks underneath all of this. One of them is a version check, and it has to be put precisely or every agent you probe looks stale. The published release is 3.1.13, read at commit a0fd0b5. What travels on the wire is a separate string: adcp_version is defined as release-precision, and the spec’s own request examples carry "3.1". How fast it moves is a question about the release process rather than about deployments.