Skip to content
AI Tools August 25, 2026

Five Social Platforms Now Let an AI Agent Buy Ads. X Joined This Week.

X shipped an Ads MCP with 10 write functions this week. Meta, TikTok, Pinterest and Snapchat got there first. Across all five, the whole safety model is one switch.

By The State of AI Marketing newsroom
Share
Editorial illustration for: Five Social Platforms Now Let an AI Agent Buy Ads. X Joined This Week.
Credit: JAC Growth Marketing

X shipped an Ads MCP server this week, first covered on August 23. It exposes 23 tools to any AI assistant an advertiser points at it. Ten of those tools write: create a campaign, update it, activate it, build line items, add and remove targeting, publish an ad post, promote it.

An MCP server is the standard plug that lets an AI assistant operate a piece of software the way a person would, reading the numbers and clicking the buttons. The letters stand for Model Context Protocol. X says its server works with any MCP-capable client, “including Grok, Claude Code ‘or a custom agent built on the MCP SDKs.’” The example prompt in X’s own announcement is a media plan typed as a sentence: “launch a campaign for the fall drop. $15k over two weeks, US only. goal is to drive sales…”

That’s a large change to how a media buyer’s day works. It’s also, at this point, unremarkable.

The count is now five

Meta got there first, opening its Ads AI Connectors in beta on April 29 with read and write access at launch. TikTok shipped its server in May and put a front door on it in July with the Agentic Hub, which we covered at the time. Pinterest and Snapchat followed. Amazon opened its ad stack the same way. Google is the conspicuous holdout, and only partly. Its server exposes three tools and can’t change a bid, pause a campaign, or create an asset.

Four months. Five major social platforms. The channel went from human-operated to agent-writable with no industry conversation about what that means. Each launch read as one company’s product news rather than as a category changing state.

The fifth launch is the story, not the launch itself.

The entire safety model is one switch

Here’s the part worth putting in front of whoever owns your paid budget.

Across these platforms, the protection against an agent spending money you didn’t approve is one mechanism: anything the agent creates lands paused. X’s campaigns and line items are, in PPC Land’s words, “always created in a paused state” and need explicit activation. Meta enforces the same default. A human flips the switch.

Everything before the switch is unsupervised. The agent picks the targeting. It sets the budget. It writes and uploads the creative. It builds the line items. Then it stops, one step short of spending, and waits for a person who is looking at a finished campaign and a green button.

Anyone who has approved a media plan they didn’t build knows what that approval is actually worth under deadline.

The other control is the credential. X’s server authenticates with the advertiser’s own OAuth token across three scopes, and the one that matters is ads.write. Access tokens expire in roughly two hours. That’s a security feature and also a tell: this was built for a session, not for a standing robot. Ask the governance question at the credential, then. Which person on your team holds a token that can write to the ad account, and has anybody written that down?

Operators didn’t wait for any of this

The platforms are late, not early.

Cody Schneider, co-founder of Draft Horse AI, posted a walkthrough months before most of these servers existed. His pitch was blunt:

“How to manage your Facebook Ads with Claude Code. Do this and you can never touch the Facebook Ads Dashboard again. Make a Facebook Ads Marketing API key and give it to Claude Code. You can now bulk upload new Facebook Ads, turn losers off, turn winners on, create new ad sets — anything you can imagine.”

No official connector, no server. An API key and an assistant. The post drew over 100 comments. Two of them reported ad accounts getting suspended after wiring Claude in, which is the sort of detail a vendor launch post will never carry.

The same pattern shows up on Google, where the official server is read-only. A solo founder we profile in a separate piece today had his agent build its own command-line tool against the Google Ads API. That gave it full create, update and delete authority over campaigns. Google’s MCP won’t let an agent pause a campaign. The Google Ads API always would.

So a read-only server buys less than it looks like. An afternoon of work removes it. The paused-by-default protection is exactly what you lose the moment someone routes around the official path.

What to do about it before the next platform ships one

  1. Find out who holds ads.write. On every platform, not just the one your agency mentioned. This is an access list, and most teams have never made one.
  2. Decide whether “paused” counts as approval. If a person is rubber-stamping finished campaigns they didn’t scope, that switch has stopped being a control and become a signature.
  3. Watch for the unofficial route. An agent with a raw API key has more authority than one on an official server, and leaves less trace. IT can see MCP traffic now; a script calling the ads API from a laptop looks like any other integration.

X building one is the small news. The large news is that a category-wide change to who can spend money finished in four months, quietly, while everyone read the announcements one at a time.

Quoted in this story

  • Cody Schneider, Co-founder, Draft Horse AI (source)

Want your perspective in coverage like this? Get quoted.

Sources

This story is part of our running coverage: the full picture →

Get Net Effect.

The net effect of AI on your marketing: the stories that matter, twice a week, in five minutes.

More from AI Tools