IT Can Now See the AI You Plugged Into Your Ad Accounts
Cloudflare can now spot AI assistants reaching into company tools, and block the ones that skipped approval. Google, Microsoft, Meta and Pacvue all run the endpoints your team plugged into.
On August 14, Cloudflare turned on a way for companies to spot a specific kind of traffic crossing their networks: an AI assistant reaching into a live business tool.
The plumbing has a name. MCP, short for Model Context Protocol, is the standard way an AI assistant gets a working connection to a system that holds real data, so it can pull your campaign numbers rather than guess at them. It’s what turns a chatbot into something that can read your account.
Cloudflare’s Gateway product now flags that traffic when it passes through, shows a dashboard of which servers your staff are reaching and who is reaching them, and lets an administrator block any connection that skipped the approved route. The company has a name for that last category:
“Shadow MCP is a connection to a server the organization has not approved.”
The sentence that should interest a marketing leader is the one explaining how easy it is:
“An employee can point Claude Code, Codex, Cursor, OpenCode, VS Code, or any AI harness at an MCP server without checking whether it is approved.”
A harness, in that sentence, is the app wrapped around a model that lets it use tools and take steps rather than just answer. The point is that every one of those is a normal piece of software somebody on your team can install this afternoon.
Your ad platforms are the endpoints
This lands on marketing harder than on most functions, for a reason that has nothing to do with marketers being careless.
The ad platforms went first. Google, Microsoft, Meta, Pinterest, Pacvue, AdRoll, PubMatic and Prebid.js have all shipped MCP servers for campaign data. As PPC Land put it, “Every one of those endpoints is, from a network administrator’s position, an HTTPS destination that an employee can add to a client without approval.”
Microsoft doesn’t bury this. Its own product page invites you to query Microsoft Advertising data from the AI assistants you already use, and names them: Microsoft 365 Copilot, the Claude desktop app, the ChatGPT desktop app, or “any MCP-compatible AI agent.” The described capability is reading. Campaigns, ad groups, ads, keywords, performance.
Read the same page for what it doesn’t cover, which took us about a minute. There is nothing on authentication beyond the setup steps, nothing on permission scoping, and nothing on audit logging. The platform tells you how to connect an AI assistant to your campaign data. Who is allowed to, and what record exists afterward, is left to you.
The connectors nobody vetted
Alongside the official servers sits a second layer that most marketing leaders have never looked at.
One of the popular open-source Google Ads connectors, mcp-google-ads by Ernesto Cohnen, has 686 stars. Its README describes what it hands an assistant:
“Campaign information, performance metrics, keyword analytics, and ad management”
To run it, a person needs a Google Ads developer token plus either OAuth credentials or a service account granted access to the target accounts. That is a real key to a real account, held by an individual, configured on a laptop.
We read the README looking for a warning about access scope or credential handling and found none. That says nothing bad about the author, who published a useful tool and owes nobody a compliance program. It describes where the guardrails currently sit, which is nowhere in particular.
The record of what changed
The governance problem here is smaller and more specific than “AI is risky,” and it’s worth stating exactly.
The arguments an assistant sends to a campaign server carry account identifiers, audience definitions and budget figures. Where a connector has write access, they carry instructions that move live spend. And when an analyst connects a personal assistant straight to an ads endpoint rather than through a company-managed route, the record of what happened lives with the ad platform, not with the buyer.
That’s the part that bites later. Your agency changes a bid strategy through an assistant. Three weeks on, performance drops and somebody asks what changed and when. The change log is inside the platform, attributed to a token, and your own systems recorded nothing. We’ve watched a version of this before, when verification moved inside the platforms being verified and buyers lost the independent record.
Cloudflare’s changelog dated the underlying capability August 12 and describes the rule an administrator writes: block MCP traffic that does not arrive through an approved portal. Simple to write. The consequence is that a connection your team has been relying on stops working, possibly with no warning, because nobody told the network team it existed.
What to do this week
Three things, none of which require a policy document.
Inventory it before IT does. Ask your team, without consequences attached, which AI tools currently have a live connection to Google Ads, Meta, GA4, your CRM or your analytics. You want the honest list, which means asking in a way that doesn’t punish the answer. Somebody built something useful and never mentioned it, and that’s the normal case. Clay handled the written-policy version of this well when it published how its staff may use AI, and the useful part was that the policy described the work rather than forbidding the tool.
Find out who holds the audit trail. For every connection on that list, answer one question: if this changes something, where is the record, and can we get it? A connection where the answer is “the platform, and no” is the one to route differently first.
Say it out loud to whoever runs the network. The block is a single rule. If your connections aren’t on the approved path when somebody writes it, they break. Being on the list beforehand costs one conversation.
The useful way to read this is not as a crackdown. Marketing teams wired AI into their live systems faster than anyone governed it, which is roughly how every useful tool has ever entered a company. The tooling to see that traffic arrived on August 14. The people who go first now get to shape what “approved” means for their own stack, and the people who wait get handed somebody else’s definition.
Quoted in this story
- Kenny Johnson, Author, Cloudflare engineering blog, Cloudflare (source)
- Ernesto Cohnen, Author, mcp-google-ads, Independent (source)
Want your perspective in coverage like this? Get quoted.
Sources
- Cloudflare: How Cloudflare detects MCP traffic and helps secure it
- Cloudflare Developers: MCP protocol detection and AI Security dashboard
- Microsoft Advertising: Microsoft MCP Server
- PPC Land: Cloudflare Gateway blocks MCP calls that bypass approved portals
- GitHub: cohnen/mcp-google-ads
This story is part of our running coverage: the full picture →
Get Net Effect.
The net effect of AI on your marketing: the stories that matter, twice a week, in five minutes.


