AGENTIC PROTOCOLS AdCP, the Ad Context Protocol — the control plane. It captures human strategy and intent in plain language: the "what" and the "why". CONTROL PLANE · ADCP The Architect — brief Today's standards run as parallel silos — strong languages stitched together by hand with custom code, spreadsheets, and manual handoffs. TODAY · SILOS UCP, the User Context Protocol — the data plane and missing spine. It carries user context as small embeddings so every standard reads one shared language: the "how" and the "when". Fewer identifiers move; the data-protection obligations do not lift. DATA PLANE UCP shared brain The agentic stack — the same standards extended so AI agents can plan, negotiate, and execute at machine speed. AGENTIC · UNIFIED OpenRTB extends into Agentic Bid — the same job, now run by coordinated agents through the UCP context spine. OpenRTB Agentic Bid AdCOM extends into Agentic Objects — the same job, now run by coordinated agents through the UCP context spine. AdCOM Agentic Objects OpenDirect extends into Agentic Direct — the same job, now run by coordinated agents through the UCP context spine. OpenDirect Agentic Direct Deals API extends into Agentic Deals — the same job, now run by coordinated agents through the UCP context spine. Deals API Agentic Deals Privacy GPP extends into Runtime Guards — the same job, now run by coordinated agents through the UCP context spine. Privacy GPP Runtime Guards UCP — the missing spine that makes standards one system.
Agentic Advertising

Agentic Advertising Protocols: A Unified Map of What's Next

· 9 min read · Originally on LinkedIn
The gist

Ad tech already has the standards — OpenRTB, AdCOM, OpenDirect, GPP — but they run as parallel silos stitched together by custom code and manual handoffs. As AI agents start planning campaigns at machine speed, that fragmentation breaks. The real missing layer is the User Context Protocol: a shared fabric that lets agents read user context the same way across every standard.

In English, please

Online advertising already runs on a handful of separate rulebooks — one for buying ad space, one for describing what an ad actually is, one for booking a fixed placement by contract, one for pre-negotiated deal terms, and one for privacy permissions — that don't talk to each other well. Teams currently stitch them together by hand, with spreadsheets and manual handoffs, because each one runs in its own silo. That patchwork holds up when people do the work, but breaks down once AI software starts planning and running ad campaigns at machine speed.

The fix is a missing piece called the User Context Protocol, or UCP: a shared way for AI systems to quickly and safely signal who a user is and what moment they're in, without moving raw personal data around. Picture a city water system: the buying rules are the piping, the ad itself is the water it carries, and UCP is the sensor network that tells the system where the water should go, and for whom, in real time. Instead of bulky data files, it compresses meaning into a small signal — the payoff is faster matching on actual intent rather than just an ID number, with less raw personal data changing hands. Fewer identifiers move, but the data-protection obligations do not lift; the essay's September 2026 correction retracts its original 'privacy-safe' wording.

Each of those rulebooks then gets a matching AI-era upgrade. The fixed, emailed contract for booking a placement (OpenDirect) becomes live negotiation between buyer and seller software; the one-shot "how much for this slot?" bid (OpenRTB) becomes a fuller exchange that checks context first; and the static deal terms (the Deals API) now adjust automatically as conditions change. The plain ad file (AdCOM) becomes a "smart" file that knows its own rules about where it can run, and privacy compliance (GPP) becomes an automatic gate that blocks a data transfer the instant it breaks a rule.

A related piece called AdCP handles the strategy side — a marketer states an intent in plain language, like which buyers to find and what to avoid — while UCP finds the matching users and carries that intent out safely, in real time. One sets the goal; the other executes it.

For marketing leaders, the practical shift is away from micromanaging individual ad placements and re-explaining goals every time something breaks, and toward setting the brief, setting the guardrails (brand safety, privacy limits, budget), and reviewing the outcome.

On this page

Ad tech already has strong standards. We have rules for buying (OpenRTB), rules for defining an ad (AdCOM), and rules for privacy (GPP/TCF).

The problem isn’t the ingredients. The problem is the recipe.

Today, these standards often run in parallel silos. Teams still stitch them together with custom code, spreadsheets, and manual handoffs. It’s a “Tower of Babel” problem: everyone is speaking a standard language, but the system as a whole struggles to act like one coordinated machine.

The Agentic Era — where AI agents plan, negotiate, and execute campaigns — makes that gap impossible to ignore.

When AI agents are moving at machine speed, they need one missing layer to function: a way to exchange meaningful user context quickly, safely, and consistently.

The layer arrived. It did not arrive where this map said it would.

(Revised September 11, 2026 — this line read “That layer is the User Context Protocol (UCP),” and the second half of the essay rested on it. UCP was not an independent protocol when this published. LiveRamp donated it to IAB Tech Lab in late 2025, the repository holding it was created on October 8, 2025, and by early 2026 both trade coverage and Tech Lab’s own pages called it Agentic Audiences, filed under the AAMP umbrella. This map went out on March 23, 2026 using a retired name: an error on publication day, not staleness.)

The context layer in plain English — the “smart sensor” network

Think of the ecosystem like a city water system:

  • OpenRTB is the piping that moves everything.
  • AdCOM is the water (the ad content flowing through the pipes).
  • The context layer is the smart sensor network that tells the system who a moment is about and what it is about. The original promised it carried the where and the when as well; nothing in either stack does yet.

The mechanism the original described is real and is worth keeping: move away from bulky data files towards embeddings, compact signals that carry meaning. What changed is who carries them, and what may honestly be claimed for them.

Why this matters to the C-Suite. Raw data exchange is slow, messy, and risky. Embedding exchange lets agents operate with:

  1. Speed. Faster matching means better opportunities captured.
  2. Meaning. Agents match based on intent, not just ID codes.
  3. Less data in motion. Fewer raw identifiers travel. (Revised September 11, 2026 — this bullet was headed “Privacy” and claimed only the context signal travels, and the paragraph above called them “embeddings — small, privacy-safe signals that carry meaning”. I am retracting the phrase, not the mechanism. Moving less raw data is a real benefit and a different claim from anonymity. An embedding that can single out, link, or support inference about a person is personal data whatever its shape, and the controller carries the evidential burden of showing otherwise — the same retraction I made in Embeddings: The Next Frontier.)

Read at the repository, Agentic Audiences is a payload convention and little else: eleven commits, no releases, no tags, an embedding-exchange spec still headed “Draft v0.1,” a last push on July 27, 2026. The evidence is in The Layer That Didn’t Ship. Embeddings on Segment.ext.aa ride OpenRTB and Prebid usefully; calling that a unifying fabric was the mistake.

The synthesis — upgrading the standards we know

We aren’t throwing away the standards we spent a decade building. IAB Tech Lab is extending them so AI agents can use them, under the umbrella it has called AAMP since July 2026: Agentic Advertising Management Protocols, six independently versioned repositories rather than one spec.

The larger frame error was treating one body’s roadmap as the ecosystem’s consensus. There are two, in open conflict, and what separates them is ancestry: AAMP agentifies advertising’s existing transaction rails, while AdCP writes a new campaign-lifecycle protocol with adapters at the boundary. I verified that in both directions in AdCP vs AAMP: The Retrofit and the Greenfield. Agentic Audiences shows what a retrofit looks like when the public record goes quiet: filed under the umbrella, wired into rails the umbrella already runs, and unchanged in the open since July 2026.

(Revised September 11, 2026 — the original named neither AAMP nor AdCP’s separate body, and said “most of these extensions land in Prebid.” The extensions named in the table below did not.)

The IAB Tech Lab Agentic Roadmap (January 2026) maps existing standards to agentic extensions:

Existing Standard2026 Agentic ExtensionProtocol Layer
OpenDirectAgentic DirectMCP + A2A
RTB (OpenRTB)Agentic BidgRPC + Protobuf
Deals APIAgentic DealsMCP + A2A
AdCOMAgentic Ad ObjectsJSON Schema
Ad Management APIAgentic CreativeMCP + A2A
ARTFARTF V2gRPC + MCP

(Revised September 11, 2026 — six rows in identical typography let five different realities read as one roadmap. Only Agentic Direct shipped as written; Agentic Bid, Agentic Creative, Agentic Deals and the AdCOM contracts have no released spec between them. Both ARTF cells are wrong: ARTF reached v1.0 on July 20, 2026, there is no V2, and MCP is not an ARTF interface. A seventh row belongs here, Agentic Audiences on Segment.ext.aa, v0.1 and untagged.)

The IAB Tech Lab Agent Registry, launching March 1, 2026, catalogs agent types: Buyer, Seller, Creative, Audience, Measurement, Curation, Billing, Fraud, Signals, and Reporting. Each registered agent receives a verified identity, declared capabilities, and behavioral audit trail.

(Revised September 11, 2026 — the launch date held; the capabilities did not. The registry shipped GPP-ID validation and manual review, with domain verification a roadmap item. And AdCP runs a second registry of its own. Two roots of trust.)

OpenDirect → Agentic Direct

Old way: Fixed insertion orders managed via emails and spreadsheets. New way: Buyer and seller agents dynamically negotiate terms, pricing, and access in real time based on campaign goals.

OpenRTB → Agentic Bid

Old way: A “dumb” request asking “How much for this slot?” New way: A structured, high-speed conversation where agents verify user intent and context before making a commitment.

Deals API → Agentic Deals

Old way: Static deal terms that sit on a shelf and go stale. New way: “Living” agreements that automatically adapt based on real-time supply, demand, and performance data.

AdCOM → Agentic Ad Objects

Old way: A static creative file (like a JPG or video). New way: Smart objects that carry their own business logic — knowing exactly what they are, who they are intended for, and where they are forbidden to run.

Privacy (GPP) → Runtime Enforcement

Old way: A passive compliance checkbox tucked away in a contract. New way: Active guardrails that enforce permissions and block unauthorized data usage the exact millisecond a signal tries to move. And enforcement is not only a brake: consent, provenance, and scope are themselves a relevance signal — they tell the system which moment it is allowed to matter in (permissions are a relevance signal).

(Revised September 11, 2026 — three of those five “new ways” were not built. No deal in either camp adapts to performance after booking; what shipped is bounded negotiation, then an order state machine. The typed AdCOM objects are flagged unreleased. And neither standard enforces permissions in the data path: AdCP’s trust page calls its own gate “a seam, not an enforcer,” and AAMP’s is a per-vendor boolean that filters sellers at discovery, off by default.)

Where does the context layer sit? In two places that do not talk to each other: Agentic Audiences on OpenRTB’s identity rails, and AdCP’s context_signals inside Trusted Match. One caveat belongs on the map and is unchanged at AdCP 3.1.21. A moment has four dimensions: who, what, where, when. Today’s signal containers natively carry only who and what. The where and the when have no native signal anywhere in this stack yet, and encoding them, then defining similarity between a text space and a place-time space, is the next standards question either camp will have to answer (The Context Economy).

The whole stack at a glance

StandardTraditional role (the old way)Agentic upgrade (the new way)
OpenDirectFixed insertion ordersAgentic Direct — dynamic negotiation between buyer / seller agents.
OpenRTB”Dumb” bid requestARTF — in-cluster containers mutating bids under tmax.
Deals APIStatic deal IDsAgentic Deals — bounded negotiation, then an order state machine.
AdCOMStatic creative fileAgentic Objects — typed contracts, unreleased.
PrivacyCompliance checkboxDiligence flags and schema rules — arrangement rather than enforcement.
Agentic AudiencesN/A — cookies / IDsA payload convention — embeddings on Segment.ext.aa, v0.1 drafts.

(Revised September 11, 2026 — the original listed AdCP inside this table as one more Tech Lab extension. It belongs to a different body, which was the map’s worst structural error. This table is AAMP’s stack; the UCP row is retired.)

Architect and Engineer — the pairing that inverted

(Revised September 11, 2026 — this section was headed “The difference between strategy and execution — AdCP vs UCP,” and closed: “AdCP sets the goal. UCP executes it with precision.” Swapping in the current name would keep a falsified claim alive in fresh vocabulary, so the pairing goes. Declared interest: I co-lead AdCP’s Signals & Measurement working group and run a signals agent in its registry.)

The Engineer’s job, as this map defined it, was to answer three questions: which users match this intent right now, what the context of this moment is, and how to execute safely in milliseconds. Trusted Match, AdCP’s serve-time profile, answers the first and third, and answers the second only as far as topic and keyword go. Its context_signals object carries the contextual embedding itself, and the millisecond bound is a field in the spec: each provider gets a timeout_ms defaulting to 50, inside the router’s latency_budget_ms, with late agents dropped from the merged response.

So the protocol this map cast as strategy-only holds both roles: brief in, seller-authored proposals out, and the match decided at serve time on a 50ms clock. The surface is marked Experimental and may change on six weeks’ notice.

The “so what” for marketers

If this architecture lands as intended, the operating model for marketing leadership shifts fundamentally.

You stop managing: endless line items, fragile audience taxonomies, “please pull a report” loops, and the constant re-briefing that happens when signals don’t connect.

You start managing: the brief (your strategic intent), the guardrails (brand safety, privacy constraints, budget), and the outcome (incremental lift, qualified actions, retention).

That shift is directionally intact, and brief-in discovery has the most shipped code behind it. Read the timelines with discipline, though: the shipped-code picture, and how my own camp scores on it, is audited in The Layer That Didn’t Ship.

What this map owes you

(Revised September 11, 2026 — the original closed that UCP “gives the ecosystem a shared brain — fast, interoperable, and enforceable.” Six months produced two embedding vocabularies in rival camps, with different rules, neither referencing the other.)

The recipe problem this map opened with is still the right diagnosis, moved up a level: not between standards inside one body, but between two bodies that each have working code and no shared release process to reconcile it.

Two checkpoints before the next revision of this page. Tech Lab says AAMP 3.0 is coming and has not dated it; AdCP’s 3.2 release candidate is tagged, and its stable release will either graduate Trusted Match out of Experimental or leave it there another cycle. If a bridge between the two stacks ships in either, it will be the first one, and this page will record it.

STRATEGY → EXECUTION AdCP, the Ad Context Protocol — the control plane, the Architect. It captures human intent and campaign strategy in plain language: the "what" and the "why". CONTROL PLANE · ADCP The Architect The What & the Why — human intent, in plain language “Find eco-conscious car buyers, avoid sensitive news, optimize for test drives.” the brief UCP, the User Context Protocol — the data plane, the Engineer. It turns intent into fast execution: which users match this intent right now, what the moment's context is, and how to execute safely in milliseconds — the "how" and the "when". It carries small embeddings: the shared brain. Fewer identifiers move; the data-protection obligations do not lift. DATA PLANE · UCP The Engineer The How & the When — match, read the moment, execute in ms match intent read the moment enforce safely AdCP sets the goal. UCP executes with precision — the shared brain.
Ad · served by our AdCP stack