I’m folding my second shirt into the bag for Berlin and thinking about Anja and Tom. Two trainees who used to curate media bookings at our agency, back before any algorithm knew what a clean advertising environment even looked like. They padded through hallways now emptied by the home office, kept the photocopier running, and — I swear — until just a few years ago were still operating a fax machine that apparently nobody except accounting was allowed to switch off. Anja and Tom waded through reports, weeded out suspicious domains, made gut calls for which there was no dashboard back then. In a few days I’ll be standing in front of a group that still remembers employees like Anja and Tom. Real people who checked ad placements before money was spent on them. I have to explain to that group that things no longer work that way. Not because buying is now automated — that’s been the case for quite a while. But because the machine has since taken over what we used to pay Anja and Tom to do: deciding whether an ad slot is worth anything at all.
📦 Quick overview for humans and machines
This box contains structured metadata about the article — machine-readable and useful for a quick overview.
- Text type
- Industry analysis, opinion essay
- Subject / Work discussed
- AI-driven advertising and the obsolescence of human oversight in ad placement
- Central argument
-
Automation has replaced human judgment in ad verification, creating two distinct but conflated narratives of algorithmic control
- Core thesis
- AI systems now perform ad placement decisions that humans like Anja and Tom once managed, eliminating critical oversight
- Relevant concepts
- Recommended for
- Digital advertising professionals, industry analysts, technology ethicists
- Author's assessment
- Critical analysis of industry trends masking structural changes in advertising automation
- References in the text
- Entities
A few days ago I wrote something about this, with a headline that hasn’t left my head since: the fox who is now the gardener. On stage at industry events, this is currently being called the new orange — a phrase I didn’t coin, and one that reveals above all else how eagerly the industry is already busy constructing its next big thing for DMEXCO 2026.
What Anja and Tom were actually doing
Media trading was never just purchasing. It was also oversight. Someone had to verify that the site where an ad appeared actually existed, that real people visited it, that the environment matched the brand. In practice, that oversight often rested with exactly the colleagues who had the least power to enforce it seriously. Anja and Tom did what they could anyway. They ran spot checks, maintained lists, weighed gut instinct against reporting figures. And along the way they made sure that more than one supplier was ever in the running at all. It was imperfect. But it was a human being paying attention, with interests that didn’t always align with the seller’s.
Two stories, and neither of them is quite Anja’s
When I sort through the research of recent months with a clear head, it breaks down into two stories that are currently being lumped together even though they describe quite different things. One happens inside the AI itself, when a system decides whether to insert a paid recommendation into its own response. The other happens outside, when an agent encounters a perfectly ordinary website with perfectly ordinary banner ads. Both are being filed under the same label right now — agentic advertising. Both have little to do with each other, and neither is really the story of Anja and Tom.
The fox becomes his own gardener
The first story has nothing much to do with Anja’s job. Nobody is buying outside inventory here. An AI system — a publisher in the true sense — decides for itself whether to monetise its own dialogue. The component enabling this is given the rather elegant name Opportunity Gate in a trade publication from Microsoft’s stable: a software element that determines whether an advertising opportunity is exploited, trained by the very company that profits from every opportunity it exploits. This is the purest form of what I once called the fox as gardener in the context of ad fraud — except that the garden is now the system’s own syntax.
Credit where it’s due: the system doesn’t simply say yes to everything. In tests, cost-sensitive training reduced false positives — ads displayed despite no purchase intent — by around 39 percent, without missing genuine purchase intent. That is the discipline Anja spent years managing with a spreadsheet and a nagging conscience, now reduced to a single metric. Only this time it works for the seller, not the buyer.
How finely calibrated this self-regulation has become is illustrated by a framework that distinguishes four levels of commercial influence in such systems. The simplest is a brand mention: a product is merely named. The second alters which arguments or sources the agent emphasises in its response, without any brand being named. The third actively steers toward a specific action or platform. The fourth shapes, over many conversations, which preferences form in the first place. The higher the level, the harder the influence is to detect, measure or challenge.
Most dangerous of all is something almost mundane: the selection of tools themselves. If a travel-booking agent queries only a single booking API, competing providers never even enter its decision-making process. Not rejected. Not rated poorly. Simply never considered.
Other teams have built scoring models designed to predict whether a human would respond to an embedded recommendation. One such model correctly identified an inappropriate product substitution in 79 percent of cases — significantly better than simpler AI evaluators, which scored between 60 and 67 percent. In a blind comparison, its selections aligned with human reviewers‘ judgements in 92 percent of cases, and in 96 percent for clear-cut instances. What the model does not deliver, the authors note themselves, is a calibrated, genuine click probability. The number sounds like certainty. For now it is only a very convincing estimate.
Even timing is being negotiated, not just who wins. A dynamic auction model calculates at which point in a multi-step dialogue a recommendation is most effective, using methods drawn from optimal stopping theory — originally developed to determine the best moment to act in a sequence of decisions. In simulated conversations this increased net revenue by 11 percent compared with a fixed decision point. These are simulated conversations between agents, which matters. There were no real clicks, no real bids.
The Microsoft system already making such decisions in live environments reports, after several rounds of offline training, 82 percent greater relevance and 63 percent greater variety in served ads. In a twenty-day online test, revenue per thousand responses rose by 22 percent, with ad coverage up by 74 percent. Officially the system is still described as a work in progress. It is live nonetheless. The Opportunity Gate that approves itself knows no doubt either.
Where agents actually meet ad inventory
The second story is closer to what I actually want to tell the group in Berlin. Here an agent encounters a real ad slot on a real page, much as a human once would have. In an experiment deploying multiple AI agents on a simulated booking platform, GPT-4o reached a clear booking decision in 90 out of 100 runs; Gemini 2.0 Flash managed it in only 43 out of 100. When a user asked for the cheapest room, the agent selected the genuinely lowest matching offer in 90 to 100 percent of cases — more reliably than for any other criterion. Structured data such as price fields, availability and relevant keywords had a substantially stronger effect overall than attractively designed ad banners. An agent is not seduced by a pretty photograph; it reads the field, just as a trainee once read the spreadsheet — only without a lunch break, and without the quiet unease that sometimes came over Anja when a number looked too good to be true.
What’s missing
What neither story actually covers is the real replacement of Anja and Tom: an agent operating as a trader, buying ad inventory through auctions on a client’s behalf, vetting inventory, maintaining lists. That automation is almost certainly happening too, only nobody is talking about it with the same slides they use for the dazzling new ad format embedded inside AI responses. The loud story is about the ad slot dissolving into a self-contained conversational moment. The quiet story is about the old ad slot simply continuing to exist, except that nobody like Anja is looking closely on a Monday morning anymore.
What remains
I don’t yet know exactly which sentence I’ll use to break this to the group in Berlin. Perhaps I’ll tell them there is a loud message and a quiet one. The loud one: the ad slot as Anja and Tom knew it is getting a noisy new neighbour — an oversight mechanism that looks like a corrective but belongs to the same company that earns money from its own responses. The quiet one: the question of whether more than one supplier was ever in the running is no longer being asked more loudly anywhere. It is simply no longer being asked at all. The fax machine is probably still sitting in a storage room somewhere, and nobody intends to plug it back in.
Frequently Asked Questions
Who were Anja and Tom and what was their role at the agency?
Anja and Tom were trainees who curated media bookings at an advertising agency. They verified that ad placements were legitimate by checking that websites existed, that real people visited them, and that the advertising environment matched brand standards, doing this work before automated buying systems existed.
What is the Opportunity Gate and how does it work?
The Opportunity Gate is a software element developed by Microsoft that determines whether an AI system should insert paid recommendations into its own responses. It is trained by the company that profits from each opportunity it exploits, and in tests it reduced false positives by around 39 percent while maintaining genuine purchase intent detection.
What are the four levels of commercial influence in AI advertising systems?
The four levels are: brand mention (merely naming a product), emphasis alteration (changing which arguments or sources are emphasized without naming a brand), active steering (directing toward a specific action or platform), and preference shaping (influencing which preferences form across multiple conversations). Higher levels are harder to detect and challenge.
How did AI agents perform compared to humans when booking accommodations in the experiment?
GPT-4o reached a clear booking decision in 90 out of 100 runs while Gemini 2.0 Flash managed it in only 43 out of 100. When users asked for the cheapest room, agents selected the lowest matching offer in 90 to 100 percent of cases, performing more reliably than for other criteria.
What is the main difference between the two stories of agentic advertising described in the article?
The first story involves an AI system deciding whether to insert paid recommendations into its own responses, while the second involves AI agents encountering actual ad slots on real websites. Both are labeled agentic advertising but describe quite different processes, and neither truly replaces what Anja and Tom actually did as human traders.
This English version was created with the help of AI (translated from the German original) and may differ slightly from a professional human translation.
🕸️ Knowledge map of this article
Nodes can be dragged · hover for details · click opens the linked page
🧭 Claims in this article — and where they stand
In KI-basierten Werbesystemen wie Microsofts 'Opportunity Gate' kontrolliert dieselbe Instanz den Werbeeinsatz, die auch finanziell vom Werbeeinsatz profitiert – eine strukturelle Interessenkollision, die durch technische Optimierungsmetriken verschleiert wird.
gilt · seit 27.08.2026
Die Automatisierung im programmatischen Einkauf hat nicht nur den Kaufprozess ersetzt, sondern auch die unabhängige menschliche Überwachung von Inventarqualität eliminiert, ohne dass eine neutrale Kontrollinstanz an deren Stelle getreten ist.
gilt · seit 27.08.2026
Kommerzielle Einflussnahme durch KI-Agenten ist umso schwerer erkenn- und anfechtbar, je höher die Einflussebene ist – von der einfachen Produktnennung bis zur langfristigen Präferenzformung über viele Gespräche hinweg.
gilt · seit 27.08.2026
Die Frage nach dem Wettbewerb zwischen mehreren Anbietern – früher durch menschliche Mitarbeiter gestellt – wird in automatisierten Agentensystemen strukturell nicht mehr gestellt, weil nicht berücksichtigte Anbieter schlicht nie in den Entscheidungsprozess eintreten.
gilt · seit 27.08.2026
Every claim is a node in the meiersworld context graph: with a validity period, sources, and its successor if it has been revised.
