Autopilot: how an AI ad manager should be constrained and held to account
An AI manager that can move money needs limits it cannot talk its way around. This guide explains the constraints on Autopilot: what it optimises, what it may never touch, how much autonomy it gets per action, how every change is recorded, and how you stop it.
- The manager optimises one goal per account: cost per order, return on ad spend, cost per lead, or a spend budget.
- Guardrails are hard: maximum bid, daily ceiling, protected campaigns, and a list of things that may never be touched.
- Per-action policy: suggest only, auto above a confidence threshold, or full auto, set separately per action type.
- Account-level spend limit windows on the OpenAI platform, up to 60 non-overlapping, are ceilings the software cannot raise.
- Every change is logged with its source (person, rule or AI), before and after values, and the reason.
- A kill switch pauses everything the AI created. Shadow mode records intended changes for 48 hours before anything goes live.
What is an AI manager for ads?
Software that does the job of a campaign manager: it watches performance, stock, margin and conversions, decides what to promote, writes the hints and the copy, sets bids and budgets, pauses what fails, runs experiments and explains itself. Autopilot is that manager for ads inside ChatGPT, running on the same rules, log and rollback as a human click.
The OpenAI Ads platform supplies the levers: fixed bids, daily or lifetime budgets, context hints, pause and activate, product sets. It supplies no judgement and no safety rails; there is no target CPA, no pacing, no test mode and no notification when something changes, as the Ads Manager versus API guide sets out. A manager that works those levers has to bring its own constraints.
What goal does the manager optimise?
One goal per account, chosen by you: a cost per order, a return on ad spend, a cost per lead, or a fixed spend budget to be used well. The goal is measured on your data, joined to margin from your shop or deal value from your CRM, not on the platform's ROAS figure alone.
A single clear goal matters because the manager will trade everything else for it. If the goal is cost per order, it will cut a profitable but expensive product; if the goal is return on ad spend measured on margin, it will keep that product and cut a cheap one with thin margin. Every daily brief shows how far the account is from the goal.
Which guardrails should be hard?
Four, and they are limits the manager cannot cross rather than preferences it weighs. A maximum bid per ad group. A daily spend ceiling per account. A list of protected campaigns the manager may read but not change. And a list of things it may never do at all, such as archive, which the platform cannot undo, or touch creative that is in review.
Two of these are enforced on the platform itself, outside Adsonomy's reach. Campaign budgets are daily or lifetime limits the platform respects. Account-level spend limit windows, up to 60 non-overlapping date ranges each with its own ceiling, are a capability OpenAI enables on the account, and Adsonomy's manager has no action that raises them. That is deliberate: the software that optimises spend should not decide how much spend is allowed. Postpaid invoice accounts can carry a daily account limit in the same way.
The rest are enforced in Adsonomy before any call leaves for the API. A bid above the cap is clipped and logged as clipped. A change to a protected campaign is refused and appears in the brief as a suggestion. Everything on the platform is created paused, so nothing the manager builds is live until an activation step that is itself subject to the policy below.
How should per-action policy work?
Autonomy is set per type of action, not for the manager as a whole. For each of bids, budgets, hints, pausing and creative, you choose one of three levels: suggest only, act automatically when the manager's confidence is above a threshold you set, or full auto. Most accounts start with everything on suggest, move bids and pausing to a confidence threshold after a week, and keep creative on suggest.
Confidence is the manager's estimate that a change improves the goal, based on the evidence behind it: a bid change backed by fourteen days of conversions scores higher than one backed by two. Below the threshold the proposal goes into the brief with its reasoning, and you approve or decline with one click. Anything approved passes the same guardrails as an automatic change.
Some actions are never full auto. Archiving is irreversible on the platform and is always a human decision. Raising a campaign budget above its previous maximum needs an approval the first time. Adding hints is safe to automate because a hint that does not match simply does not serve; hints are versioned so a batch can be rolled back.
What must the change log contain?
Every change to the account, with its source, its target, the value before and after, the reason, and the moment it was applied. The source is a named person, a named rule, or the AI with the confidence it acted on. A change made in the Ads Manager outside Adsonomy is picked up on the next sync and logged as external.
Because the platform has no webhooks, Adsonomy reads the account on a schedule and reconciles what it finds with what it expected; a difference is either an external change or a failed call, and both are logged. Every logged change can be reversed from the log itself, except archiving. A rule that fires becomes a line naming the rule and the condition that triggered it.
What are the kill switch and shadow mode?
The kill switch pauses everything the AI created or changed, in one action, and leaves what you built untouched. Shadow mode runs the manager for 48 hours with the account read-only: it records every change it would have made, with its reasoning, so you can judge its decisions before it makes any.
The kill switch uses the platform's pause action, so it takes effect as fast as the API accepts the calls and can be undone by activating again. It never archives. Shadow mode stands in for the sandbox the platform lacks: a new account, a new goal or a changed guardrail starts in shadow mode, and the brief for those days reads like a dry run. After two or three of them, you set the per-action policy on evidence rather than a guess.
What is in the daily brief?
What moved, why, and what the manager wants to try next. Spend, conversions and the distance to the goal, joined to margin or deal value. Every action it took, with the guardrail it stayed within, every proposal waiting for approval, and the experiments it suggests for the week, each with a stopping rule.
The brief respects the platform's data timing: conversions need at least a day to settle, so it judges yesterday's decisions on settled data and flags what it is not yet sure about. Read the platform guide for reporting details, or the shop guide and service guide for the signals the manager reads.
Frequently asked questions
Can the AI raise my spend limit?
No. Campaign budgets and account-level spend limit windows are ceilings set by you. The manager can move budget between campaigns within your daily ceiling, subject to the policy you set, but it has no action that raises the ceiling itself.
What happens if I disagree with a change?
Open the change log, find the line, and reverse it. Every change carries its before and after values and can be undone from the log, apart from archiving, which the manager never does on its own. Declining a proposal teaches the manager to score similar proposals lower.
Is Autopilot a different product from Control?
No. Autopilot is a switch on top of Control. The rules, the log, the rollback and the guardrails are the same; the difference is that the manager proposes and, where you allow it, acts.
Adsonomy runs ads inside ChatGPT for shops and service businesses. Control edition: you run it with rules. Autopilot: the AI manager runs it inside your guardrails. Launching 1 October 2026.
Join the waitlist