In April 2026, Meta launched Ads AI Connectors, an official MCP server and command line interface that, in Meta's own words, let advertisers and agencies "create, manage, and analyze campaigns."
Create. Manage. That is write access. An operator.
In August, Meta shipped new Meta AI features for small businesses. Meta AI can now work with Facebook and Instagram analytics, review advertising performance, and compare results.
Read. Review. Compare. That is an analyst.
Same company, same underlying capability, four months apart, opposite permission models.
That looks like inconsistency. I think it is the most coherent decision either platform has made this year.
The permission question keeps getting asked wrong
The industry has been arguing about whether AI agents should be allowed to change ad accounts as though there is a single correct answer waiting to be discovered.
Look at what has actually shipped in 2026:
| Product | Permission |
|---|---|
| Google Ads MCP server | Read-only |
| Google Analytics MCP server | Read-only |
| Google Merchant API MCP (alpha) | Read-only plus low-risk write |
| Meta Ads AI Connectors | Create and manage |
| Meta AI for small businesses | Read and analyze |
Five products. Four distinct permission models. Two companies with more behavioral data on advertiser competence than anyone reading this will ever have.
If there were one right answer, they would have converged on it. They have not, and the reason is that the question is underspecified. Should an agent have write access is not answerable without asking whose account, and what happens when it is wrong.


The variable is the review layer
An agency running forty accounts has infrastructure around a change: a QA step, a naming convention, a second person who reviews before it goes live, a weekly performance review that surfaces anomalies within days. Write access removes tedium, and the failure mode is contained by process that already exists for human error.
A small business owner has none of that. They have a phone, a business to run, and no second pair of eyes. For them, an agent that restructured a campaign at 11pm would be indistinguishable from the platform malfunctioning, and they would have no way to diagnose which it was.
So Meta gave the party with a review layer more capability, and the party without one more guardrails.
That is not a compromise between two positions. It is the recognition that permission should scale with the capacity to catch mistakes, and that capacity varies enormously between customers of the same platform.
Google made the same move on a different axis
Google did not segment by customer. It segmented by consequence.
Read-only for Ads and Analytics, where a wrong action spends real money in real time and the state you return to after an undo is not the state you left, the learning phase is gone, the auction position is gone, the budget is spent.
Read-only plus low-risk write for Merchant Center, where creating a data source is recoverable and Google explicitly limits the write surface to actions of that kind: "strictly limited to read-only operations and low-risk write tools... as a safety guardrail."
Two different segmentation strategies, same underlying logic: match the permission to the blast radius.
What this means for your team
The useful question is not "do I trust the model." It is "would I catch this, and how quickly?"
That reframes it into something you can actually assess:
Do you review account changes on a schedule, or when something looks wrong? Scheduled review is a genuine safety layer. Reactive review means your detection time is however long it takes for damage to become visible in a report.
Would a bad change be obvious or subtle? A paused campaign is obvious. A slightly wrong target CPA is not, and will quietly underperform for a week while looking approximately normal.
How many accounts, and how often do you look at each? Blast radius scales with count and inversely with attention. Forty accounts reviewed monthly is a very different risk posture from one account you know intimately.
Who explains it to the client? "The agent did it" is not an answer. If you would not be comfortable describing the change after the fact, you should not have delegated it in advance.
The resolution
The industry has not failed to decide. It has decided something more useful than a single answer: that the right permission level is a property of the relationship, not the technology.
Two companies looked at the same capability and segmented it, one by customer sophistication, one by consequence severity. Both are right, because they are answering different versions of the question for different populations.
Which means the decision is yours to make deliberately rather than to inherit from a default. Work out where your team sits on review capability and blast radius, and pick accordingly.
Then write it down, because the defaults will keep moving.
Working out where AI actually fits in your marketing?
I write these while building the systems behind them: measurement, creative pipelines, and agents that do real work. Connect on LinkedIn and tell me what you are working on. That is where these conversations start.
Connect on LinkedIn