What AI should never do on a client's ad account
Guide · 2 min read · Updated 2026-10-06 · By the Cofoundr team
Never let AI invent results, change budgets or launch live campaigns without a person approving, act outside the accounts it is scoped to, publish claims you cannot prove, or message clients unreviewed. A person stays accountable for every change.
AI is genuinely useful with ad accounts: it reads fast, compares periods and drafts well. The agency stays responsible for the client's money and trust, so the limits matter as much as the uses. These are the lines worth drawing before anything goes wrong.
Never invent or estimate results
Numbers in reports and updates should come from your data. If an AI tool cannot find a figure, it should say so, not guess. A made-up number in front of a client is hard to recover from.
Never change spend without approval
- No budget increases, new live campaigns or audience changes without a person approving.
- Where automation is allowed, cap how large a change can be and keep a log.
- New campaigns should be created paused for review.
Never act outside its scope
Each AI connection should see only the accounts it needs, with only the permissions it needs. If a tool can reach every client, one mistake can affect every client.
Never publish claims you cannot prove
AI will happily write a persuasive claim about results, health outcomes or savings. You carry the responsibility, and Meta's advertising standards apply to every ad. Review claims against evidence and policy.
Never message clients unreviewed
AI can draft the update. A person should read it, especially when the news is bad, and send it.
Never treat credentials and client data casually
Do not paste passwords or tokens into prompts, and think before sharing client data with any tool. Check what your agreement and the tool's terms allow.
Keep a person accountable
Whoever approves a change owns it. Write down who approves what, so there is no doubt when something needs explaining.
How to enforce it
Use tools that enforce limits technically, not just by habit. Cofoundr's MCP server scopes access per ad account, can be read-only, logs every action and can be revoked at once, and Hadya asks for approval before sensitive actions. See the safe automation checklist.
Frequently asked questions
Is it risky to let AI manage ad accounts?
It is manageable if access is scoped, changes need approval, actions are logged and you start read-only.
What is AI best used for with ad accounts?
Reading and summarising data, spotting changes, drafting reports and suggesting options for a person to decide.
Who is responsible if AI makes a mistake?
The agency. That is why a person should approve anything that spends money or reaches a client.
