What MCP actually is
MCP (Model Context Protocol) is an open standard that lets an AI assistant talk directly to an application: it queries data and presses buttons itself through a structured set of commands, called tools. Previously, every such integration had to be custom-built and maintained by developers; MCP is a shared language that Claude, ChatGPT, Gemini and other agents all understand out of the box.
For advertising, that means: instead of “export a CSV and paste it into ChatGPT,” it becomes “ask Claude why yesterday’s campaign’s CTR (the share of people who clicked out of everyone who saw the ad) dropped,” and the assistant walks into your account itself, runs the numbers, and — if permitted — even fixes the bid.
Who has shipped one, and what it’s actually allowed to do
Google Ads. An official, open-source server from the Google Ads API team, free, self-hosted on your own computer or in Google’s cloud, usually requiring a developer token (a key Google issues for working with its API) with Explorer-level access (which allows working with real, not test, accounts). Deliberately read-only: three tools — list accessible accounts, run a GAQL query (Google Ads’ query language), and look up field metadata. It cannot change a bid, pause a campaign, or create an ad 2,7.
Meta Ads. The opposite approach: open beta (public testing ahead of official launch) since April 29, 2026, hosted on Meta’s own servers (mcp.facebook.com/ads), with both read and write permissions. An agent can create and edit campaigns, ad sets and ads, including changing budgets 3,4. The safeguard: every action the agent takes requires your authorisation in the AI assistant itself 4. On July 16, 2026, Meta opened the connection to any developer with their own app and added “ads MCP server rules” — a panel where anyone with full control of the business portfolio in Meta Business decides exactly which actions an agent may take: change budgets, create campaigns, edit the catalog 3.
Amazon Ads. Open beta since February 2, 2026, with the broadest permissions of any platform: creating, editing and deleting campaigns, access to reporting, account settings, and even billing data. Available globally, but only to Amazon Ads partners with active API credentials (keys for programmatic access to the account) 5.
TikTok. Announced its own MCP server on May 13, 2026, at TikTok World 7, then launched Agentic Hub on June 30 — a marketplace of ready-made AI skills (Skills) from TikTok itself and its partners, through which an agent creates campaigns, generates creatives and analyzes results 11; the server supports both read and write access 7. The Symphony Agent creative generator, according to Mintec, was presented separately, at the Q3 Product Preview 6.
Microsoft Advertising. The most cautious rollout: an open pilot since June 17, 2026, read-only, waitlist access 7.
Perpetua. Connects Claude and ChatGPT to retail media data, and the agent doesn’t just read the data: it prepares recommendations that you review and implement in Perpetua, with Perpetua itself handling the ongoing optimization. Perpetua doesn’t publish pricing or a list of countries; the server works only with a Perpetua account 1.
Google Ads MCP is open-source and free. Meta, Amazon, TikTok and Microsoft don’t mention a separate MCP fee in their announcements; as of September 23, none of them has published pricing. You pay separately for the AI assistant itself (a Claude or ChatGPT subscription) or for a third-party hosting service that takes the self-hosting hassle off your hands.
Where this is already going wrong
The main problem isn’t the protocol itself, but the habit of granting an agent more permission than it needs. When Meta updated the permissions panel on its MCP server on August 11, 2026 9, consultant Jon Loomer found that on all of his accounts the panel opened with all seven agent actions allowed, budget changes included: he wrote about it on his blog 12, and the industry blog AdMake AI recounts his check 8. In other words, at least on those accounts the business-portfolio panel restricted nothing by default until the owner narrowed permissions in Business Settings → Integrations → Ads MCP Server. Loomer himself notes that an action may still be blocked by the connector settings in the AI assistant.
The second risk is, in our view, more serious: AI agents that read web pages don’t always distinguish ordinary text from a hidden command. In March 2026, Palo Alto Networks’ research unit, Unit 42, published the first real-world case (first reported by Unit 42 in December 2025) of fraudsters trying to fool an AI-based ad-review system: the page of a “military glasses” discount ad hid 24 attempts to slip the system an “approve” command. Whether the attack worked, Unit 42 doesn’t know: the researchers are not aware of any confirmed successful attacks against deployed ad-review systems 10. The case concerns ad moderation, but the mechanics are the same as in budget management: an agent that reads external content while also holding the power to act risks trusting whatever text it’s handed.
The practical takeaway for anyone connecting an AI assistant to an ad account: check exactly which actions it’s allowed to take, and grant only what’s actually needed — keep reading reports separate from the right to change a budget.
We at Wideworks currently keep our own policy simple: agents are allowed to read reports and suggest changes, but no budget change reaches the account without a media buyer’s sign-off. For now, it’s cheaper to double-check than to explain to a client why the budget ended up somewhere unexpected.
Sources
- ↑Perpetua, company blog, September 22, 2026 — Introducing Perpetua’s MCP: Retail Media Meets Your AI
- ↑Google Ads API team, GitHub repository — googleads/google-ads-mcp (official server, documentation as of September 2026)
- ↑Meta for Business, official blog — Introducing Meta Ads AI Connectors (updated July 16, 2026)
- ↑Meta Business Help Center — Manage ads from an AI agent with Meta Ads AI connectors
- ↑Amazon Ads, official announcement, February 2, 2026 — Introducing the Amazon Ads MCP Server
- ↑Mintec Blog, September 9, 2026 — TikTok Agentic Hub: AI Agents Now Run Campaigns Through MCP and Skills (secondary source)
- ↑Markifact, July 15, 2026 — The State of Advertising MCPs in 2026 (status overview across platforms, including Microsoft Advertising)
- ↑AdMake AI, blog, August 31, 2026 — Meta Ads Updates: September 2026 Changelog for Media Buyers (independent industry observation, not an official Meta statement)
- ↑Advertising Is Hard, September 3, 2026 — Meta AI Can Now Read Your Ad Account: What It Actually Catches (independent industry observation)
- ↑Unit 42 (Palo Alto Networks), research, March 3, 2026 — Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild
- ↑TikTok for Business, official blog, June 30, 2026 — Introducing TikTok Agentic Hub: AI Skills to streamline your ad workflows
- ↑Jon Loomer Digital, Jon Loomer’s blog, August 11, 2026 — Meta Ads AI Connectors Get More Security Controls (primary source for the observation recounted by AdMake AI [8])