Expert Mode - Insights from marketing, AI, and CX pros

Expert Mode: Your Media Agent Can’t Pick Up the Phone with Richy Glassberg from SafeGuard Privacy

This article is based on written responses from SafeGuard Privacy Co-Founder and CEO Richy Glassberg to questions from Greg Kihlström for The Agile Brand Guide’s Expert Mode series.

Most marketing organizations have made peace with how privacy approval works. Legal reviews the vendor, somebody files the paperwork, and the approved-partner list lives in a spreadsheet that gets updated when a person remembers to update it. Slow has been acceptable because slow was survivable. A buyer who isn’t sure whether a data provider is cleared for a particular market sends an email and waits a day for the answer.

Agents don’t wait a day. IAB Tech Lab’s AAMP 2.3 release on July 30 put the IAB Diligence Platform and SafeGuard Privacy directly inside the Buyer Agent, which means the vendor check now happens in the same sliver of a second as the bid. Richy Glassberg, Co-Founder and CEO of SafeGuard Privacy, argues that the real change here isn’t speed. It’s that a judgment a human buyer used to make by asking someone now has to exist in advance, written in a form a machine can read and act on. He has an obvious stake in that argument — he helped co-found the IAB in 1996, and the Diligence Platform now embedded in the agentic advertising standards runs on his company’s technology. It’s also why his read on the problem is worth having.

The Approval Nobody Can Chase Down

From a CMO’s chair, “approved vendor” sounds binary. Ask a privacy lead and you get a different answer, full of conditions and carve-outs and dates. Glassberg’s point is that those conditions are exactly where agentic buying breaks, because they’re the part that has always lived in somebody’s head or inbox.

“Vendor diligence is complicated, and it takes time. Even when a vendor has been approved, there can still be important questions before a transaction happens: Is the vendor approved to handle sensitive data? In which regions? Under what conditions? A human buyer can pick up the phone or send an email to get an answer. An agent making a decision in milliseconds can’t.”

We, as marketing leaders, tend to treat the approved-vendor list as settled infrastructure, the way we treat the office badge system. It isn’t. A DSP cleared for US state-law compliance may never have been assessed against GDPR, and the agent running a German retargeting push won’t know that unless somebody encoded it. So the question to put to your agency isn’t whether partners are approved. It’s whether the approval is machine-readable, current, and connected to the system placing the buy — and if the honest answer is “it’s in a shared drive,” you have a real gap and roughly one quarter to close it. Glassberg’s prescription isn’t to speed the lawyers up. It’s to “remove the manual handoff” so the diligence stays with the people qualified to do it while the agent reads the result directly.

Rules Set Before the Buy, Not During It

What AAMP 2.3 actually changes in practice is who decides, and when. Glassberg describes a setup where the privacy and buying teams agree on handling ahead of time, campaign by campaign, and the agent then works inside those parameters.

“If the vendor passes the compliance check, the buy can proceed. If the vendor hasn’t been vetted through the IAB Diligence Platform, the buyer can determine whether the agent should allow the transaction to proceed or block it. That means the decision isn’t being made in the moment by someone trying to interpret a policy or track down an answer. The rules have already been established.”

Read that closely, because there’s a live question buried in it. Somebody has to choose the default for unvetted partners, and that choice has a price tag either way. Block everything unvetted and the agent will pass on inventory your media team wanted, probably during the week it mattered most. Allow it and you’ve built a hole into the system on purpose. The setting can reasonably differ between an always-on prospecting campaign and a regulated-category launch, which is the argument for making it a campaign-level decision rather than a global one. What almost nobody has sorted out yet is who adjudicates when the agent blocks a buy and the trading desk wants it back. That’s a decision rights conversation, and it should happen before the first refusal, not after.

The Part That Isn’t Plumbing

Asked whether any of this genuinely belongs to a CMO, Glassberg gave up ground before making his case, which is the sort of answer worth quoting at length.

“The plumbing can absolutely sit with the agency, ad ops or technology teams. The decisions being made through that plumbing are a different matter. A CMO doesn’t need to know how an agent checks a diligence record or how the underlying protocol works. They do need to know what the agent is allowed to do on the brand’s behalf, where the boundaries are, and what happens when it reaches a situation it can’t resolve on its own.”

“The technical implementation isn’t a CMO problem,” he says, and that concession does more for the argument than another paragraph of urgency would. The division is clean enough to put on a slide. Implementation belongs to ad ops. Trust, risk, and autonomy belong to the person whose budget is moving. Practically, that means three things a marketing leader should be able to state without calling anyone: what the agent may transact without a human, what it must escalate, and who owns the escalation. If your human-in-the-loop design is a diagram your agency drew, it isn’t your design yet. Glassberg also makes a point that tends to get lost in the technology framing: adopting an industry platform pulls legal into the buying workflow as a participant rather than a reviewer after the fact.

What You Hand a Regulator Six Months Later

Regulators have been consistent that pointing at a vendor isn’t much of a defense. Automation doesn’t improve that position, and Glassberg is direct about the fact that an autonomous system doesn’t inherit the liability. The brand keeps it.

“If a regulator asks six months later whether a vendor was properly vetted, the brand should be able to show the diligence that was conducted, the assessments that were requested, the vendor’s answers, supporting documentation and other relevant records, along with timestamps showing when that diligence took place.”

Here’s a cheap test you can run this week. Pick a partner your team added last quarter and ask for the diligence file — assessments, responses, documents, dates. If producing it takes more than a day, the process isn’t defensible yet, and programmatic volume was already straining it before agents arrived. Glassberg’s framing is that a brand should be able to demonstrate what was reviewed and when, rather than asserting that a vendor was approved. The distinction is the difference between a claim and evidence, and it’s the one that holds up under questioning.

Start where he suggests: map where agents are already operating across your media, data, and partner relationships, then ask the privacy team whether the diligence behind those relationships was actually done. For agents already live, the follow-up is whether the agent can tell an approved vendor from an unvetted one before it spends, and who keeps those rules current. Then there’s the signal he’d watch for.

“This can’t be a ‘set it and forget it’ exercise. An agent is only as safe as the direction it’s given. If you haven’t given clear instructions around compliance and safety, you don’t really know what it’s buying, and that can come back to bite you. The warning sign is simple: if you can’t explain what would stop an agent from making an unsafe or non-compliant purchase, your governance hasn’t caught up with your technology.”

That’s a good test because you can run it on yourself, today, without a vendor demo or a workshop. If you can’t answer it in a sentence, the next call belongs to your privacy lead and your agency, together, on the same line.

The Agile Brand Guide®
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.