Meta opened its Ads MCP server to any developer with a Meta app on 21 July 2026, so tools like ChatGPT and Claude could create, edit and launch campaigns straight inside a live ad account. On 11 August, Meta shipped the missing piece for it: Meta Ads AI Connectors, a permissions panel that's supposed to control what those tools can touch. By default, the panel left every sensitive action switched on. Budget edits included. If an AI tool is connected to your Meta ad account right now, go check it before it touches anything else.
What Actually Changed With Meta Ads AI Connectors?#
Meta's Ads MCP server has been open since July, letting any developer wire an AI agent into ad account management through OAuth instead of custom integration code (Relevant Audience). It went from a controlled setup to something any Meta app developer could switch on, no approved-partner status required.
Then on 11 August, Meta added the piece that was missing: a permissions panel inside Business Settings, under Integrations, then Ads MCP Server. It governs around 100 tools an agent can call, each one set to "always allowed," "blocked," or "should request approval." Seven of the most consequential actions were switched to "always allowed" the moment you connected an agent, with no prompt to change that. Editing or setting any budget. Creating campaigns, ad sets and ads. Editing targeting, creative and status (Jon Loomer Digital).
Does This Affect Your Ad Account?#
If you haven't connected ChatGPT, Claude or another AI tool to your Meta Business account, nothing here changes for you today, and you can stop reading. If you have, even just to pull a report or draft ad copy, that same connection likely has standing permission to touch your budget too, whether you meant to grant it or not.
That second group is bigger than people assume. Most of the "connect your ad account to ChatGPT" setup guides that spread over the summer walk through authorization without mentioning the permissions panel at all, because it didn't exist yet when they were written.
The Honest Trade-Offs#
The upside is real. Wiring an agent into Meta's own MCP server instead of a third-party middleman cuts a genuine amount of integration work: no custom API wrapper, no token-refresh logic to maintain, Meta handles the auth. For a founder running their own ads, asking an AI tool to draft a campaign structure from a brief is a legitimate time-saver, and it's part of the same push toward agent-run ad workflows we saw when Gemini's agentic video mode started cutting competitor research time for creative teams.
The downside is that "always allowed" was never something most people opted into. It was the state the panel arrived in. An agent with write access to a live ad account can spend real budget on its own, and a badly worded prompt is enough to trigger it. Scoping the permission matters more than trusting the model behind it. We'd also flag that the panel only controls what the connector can do going forward. It doesn't audit what already ran before you checked it.
How We're Handling It At WebEpex#
We reviewed the Ads MCP Server's permission set the week the panel shipped and switched budget editing, campaign creation and targeting changes to "should request approval" on every client account we manage, before doing anything else with it. Ten minutes per account, no cost.
For the actual build work, reporting, WhatsApp lead response automation, creative-brief generation, we still run most of it through our own n8n workflows rather than Meta's native connector. Mostly so a client's ad account never sits behind a chat interface with standing write access by default. It's the same instinct that had us pushing n8n's own security patches out to every client instance within days of that advisory. Assume the default isn't the safe setting, verify it, then move on. For the GCC, European, USA and Canadian accounts we run Meta ads on, that verification step is now a standing item on our monthly account audit, not a one-time check.
I'll say plainly that the panel itself is a good addition. It just shipped with the wrong default, and we'd rather flag that than pretend it arrived locked down.
What Should You Do This Week?#
Open Business Settings, go to Integrations, click Ads MCP Server, and look at what's set to "always allowed" for every connected tool. Three things worth doing in the next ten minutes:
- Switch budget editing and campaign creation to "should request approval" unless you deliberately want an agent spending unsupervised
- Check this separately for every business portfolio you manage, since the setting isn't global
- If you're an agency managing client accounts, get sign-off on what's connected before you touch the panel on their behalf
If nothing's connected to your account, there's nothing to fix. Still good to know the option exists before someone on your team switches it on without reading the fine print.
Meta ad accounts get exposed to more AI tooling every quarter, not less. This is a permissions habit worth building now, not after something spends money it shouldn't have. If you want a second pair of eyes on what's connected to your account, send me what you're running and I'll tell you what I see, no pitch attached. [cal.com/webepex/growth-review]