AI agents for marketing are software that works through a task on its own: they open pages, run scripts, read what comes back and choose the next step, instead of answering a single prompt. In my measurement work I hand them the jobs that only read or draft (tag audits of public pages, keyword and results-page research, writing and fact-checking manuals, render checks), and every push waits for my approval. Anything that writes to an ad account or a client system, and any finding that depends on location or consent, should stay with a person too.
What is an AI agent in marketing?
A chatbot answers; an agent acts. The agents I use run in Claude Code, which reads a codebase, edits files and runs commands (Claude Code overview). A session can hand parts of a job to subagents, and each one runs in its own context window with its own system prompt, tool access and permissions (subagents). That separation is what lets one run have a writer and an independent checker. The marketing part is only the task: the same agent that edits a file can load a landing page and list which tags fire.
Which marketing work do I hand to agents?
| Job | What the agent does | What limits the damage |
|---|---|---|
| Tag audit of a public page | Loads the page in headless Chrome and captures the requests: gtm.js from googletagmanager.com (container snippet), the Google tag's config call (gtag.js), conversion requests | Read-only; it never submits a form |
| Keyword and results-page research | Runs third-party SEO skills that pull search volumes and read the current results for a query | My rules sit on top: no paid API call without my approval, no indexing submissions |
| Drafting manuals | One writer agent per article | An independent fact-checker reads it next |
| Fact-checking | Re-reads the vendor's help pages and fixes or cuts claims they do not support | Editor passes, then me |
| Render checks | Opens every page in a real browser at desktop and phone width | Nothing goes live until I approve the push |
Every row either only reads, or produces a draft that another agent and then I check before anything goes live.
What does a real run look like?
On October 2, 2026, one run used 32 agents to write 13 manuals, tighten 5 drafts and render-check 20 pages. Each article had its own writer and its own fact-checker, editor passes followed, and one agent rendered every page in a browser at both widths. I read the result, then approved the commit and the push myself. No agent in that run published anything.
What did the fact-checkers catch?
Real errors, each stated as fact. A draft explained which calls Google Ads counts in "Calls from ads" and missed that, with call recording on, AI now analyzes the recording to judge lead quality, and your set call duration is the fallback (Measure calls from ads). Another sentence invented a frequency nobody had measured, "the case I see most", and was cut. Lauren Tan, an engineer at Cursor, describes the coding version of this in a recorded talk: an agent confidently named the cause of a bug, and its tool calls showed it had not read the code she thought should be affected. A checker that re-reads the source is how I catch that before a reader does.
What should stay with a human?
Three things. Anything that writes to an ad account or a client system: a conversion upload, a change to a conversion action, a client's tag setup. Every commit and push. And every finding that depends on where the check ran or on the visitor's consent. What these share is that no automated check of mine catches every wrong one before it lands, so the check has to be a person, before it happens. Before any write to Google Ads, test it the way testing a conversion upload safely describes.
How do I keep pushes behind my approval?
I approve every commit and push, and agents never push on their own. If you want that gate in the tool and not only in your habits, Claude Code permission rules can do it: an ask rule prompts for confirmation every time Claude Code tries a matching command, and rules are evaluated deny, then ask, then allow (permissions).
{
"permissions": {
"ask": ["Bash(git push *)"]
}
}The same page warns that a push written another way, such as git -C . push, is not matched, so treat the rule as a seatbelt rather than a lock.
Why do consent findings need a human?
Because an agent sees one visitor's version of a site. While I researched practices for outreach, an agent reported a site that sent its Google hits with consent denied and showed no banner. That was true only because the check ran from my machine in Bulgaria: the site, built on Wix, set consent to denied for EU visitors only, so a visitor in the US never saw that state. That fits Wix's own help, which says that a site with no cookie banner sends no data to Google Analytics for visitors from a country that requires consent, such as those covered by GDPR (Wix help). Google lets a site set different consent defaults per region (consent mode), so a finding like this holds only for the place the check ran from. The finding was withdrawn. For what consent changes in the numbers, see measuring conversions under consent.
Where does the trust curve fit?
In the same recorded talk, Lauren Tan draws her own use of coding agents as a trust curve. At the start she watched every output of a handful of agents and could not run more, because she did not yet trust the output of one. The skill she calls most important is verification: agents that run the real app and test their change. She warns against jumping to large numbers of agents before that trust exists, and says there is "no shortcut". My split follows the same logic: a job moves to agents once something real checks it, and it stays with me while the only check would be me noticing afterwards.
How should a small business start with AI agents?
Start with one job that only reads public data, such as loading your own landing page in a headless browser and listing the tags and requests it sends. Give the agent only the tools that job needs: a Claude Code subagent takes a tools allowlist, and the docs' example code reviewer gets only Read, Glob and Grep (subagents). Add a second agent, or a script, whose only job is to check the first against the source. Keep every write, send and push with you until a check exists that would catch a wrong one first.
Where does this leave the measurement itself?
Agents make the reading half of measurement faster: audits, research, drafts and checks. Deciding what counts as a conversion, and changing the account that bids on it, stays with a person. If your ad platforms, GA4 and CRM disagree and you want them reconciled by someone who signs off every change, see marketing analytics.
Tags
Frequently asked questions
What marketing tasks can AI agents do on their own?
The ones that read or draft and have a check behind them. I hand agents read-only tag audits of public pages with a headless browser, keyword and results-page research, writing and fact-checking manuals, and render checks of every page at desktop and phone width. Keep anything that changes an ad account, a client system or the live site with a person.
Should an AI agent have write access to my Google Ads account?
I would not let them. Conversion uploads, changes to a conversion action and anything else that writes to an ad account or a client system should stay with a person, because a wrong write changes live data before anyone has reviewed it. Let agents read, research and draft; a person makes the change.
Can an AI agent check its own work?
It can check against something real, such as the vendor's help page, a rendered page or a captured network request. In my runs the errors were caught by separate checker agents, not by the writers: a wrong account of how Google Ads counts calls from ads, a consent finding that only held from Europe, and a sentence that invented how often something happens.
How should a small business start using AI agents?
With one job that only reads public data, such as loading your own landing page in a headless browser and listing the tags and requests it sends. Give the agent only the tools that job needs, add a second agent or a script that checks the first against the source, and keep every write, send and push with you.