Meta's ads AI connectors: letting AI agents run ad accounts safely

Meta now lets AI assistants read and change ad accounts through its ads MCP server and command line tool. It is useful, and it needs rules. Here is what the connectors do and how an agency should set them up.

24 September 20264 min readBy the Wiro team, Dubai
A laptop on a desk showing lines of code in a dark editor

In April 2026 Meta opened its ad system to outside AI assistants. Through what it calls ads AI connectors, an AI agent can read an ad account's performance, create and edit campaigns, fix catalogue feeds and run tests, in plain language. The connectors are in open beta, and Meta added controls for business admins in July. For agencies managing many accounts, it is a genuinely useful tool, and one that needs deliberate rules before anyone switches it on.

What the connectors are

There are two. The ads MCP server uses the Model Context Protocol, a standard way for AI assistants to use external tools; Meta's developer documentation shows setup for Claude Code and ChatGPT, and says it works with any assistant that supports the protocol. The Ads CLI is a command line tool for developers and automated scripts, which runs on Python and authenticates with a system user token.

Signing in to the MCP server uses Facebook Login for Business and needs no developer setup, so the agent acts with the permissions of the person who connected it. Since July 2026, any AI app can also connect through a business's own developer app. Meta's documentation lists what the connection can be allowed to do, from reading ads and managing them to managing catalogues and business assets.

What an agent can do

  • Reporting and insights: pull performance for any campaign, ad set or ad, and explain it.
  • Ad creation and management: create and edit campaigns, ad sets and ads, manage custom audiences, including deleting them, and boost Instagram posts.
  • Catalogues: build catalogues and fix product feed problems.
  • Signals: check the health of the pixel and Conversions API data.
  • Tests: set up A/B and lift tests.
  • Help and activity logs: troubleshoot problems and see what has changed.

Meta says partnership ads are also coming to the MCP connector through the rest of 2026, so an agent will be able to create them and manage creators' permissions.

The safety defaults

Meta has built in one important default: anything an agent creates is created paused, and the assistant asks for confirmation before switching anything on. That means an agent can draft a whole campaign, but a person has to approve it going live. In July 2026, Meta added ads MCP server rules, which let anyone with full control of a business portfolio govern what AI agents may do in its ad accounts, from changing budgets to updating catalogues.

The risks worth taking seriously

  • Learning resets. Frequent edits to budgets, audiences or creative can send ad sets back into the learning phase. An agent that tweaks constantly can make a campaign worse, not better.
  • Permissions. The agent can do whatever the connecting person can do. Connect with an account that has only the access the task needs.
  • Deletions. Custom audiences can be deleted through the connector. Losing a carefully built audience is easy to do and slow to undo.
  • Account health. Digiday reported anecdotal claims of accounts being restricted after heavy automated use. There is no confirmed pattern, but it is a reason to start slowly.
  • Client data. Reports and customer lists pass through whichever AI service the agency uses. Check what each client's contract allows before connecting their account.

A sensible setup for an agency

  • Start with reporting only. Let the agent read and summarise performance before it is allowed to change anything.
  • Use MCP server rules to limit what agents may do in each account, starting with budget changes.
  • Keep the paused-by-default workflow, and make approving an agent's draft part of the account manager's routine.
  • Record which accounts have an agent connected, who connected it and what it is allowed to do.
  • Tell the client, and get their agreement in writing, before an AI agent works in their account.

Used this way, an agent is a fast analyst and a patient drafter: good at pulling the numbers every morning, spotting a broken feed or setting up a test, and never allowed to spend the client's money on its own. That is where the value is for most agencies, and where the risk stays small.

However campaigns are built, links still need consistent UTM tags so results can be traced in the client's analytics. The free UTM builder on this site creates them in one step, and flags the mistakes that split the numbers.