NAI Releases Practical ‘Dos and Don’ts’ Guidance for AI and Agentic Workflows in Adtech

Table of Contents

Advertising technology companies have spent more than a decade refining machine learning models, predictive optimization engines, and automated bidding systems. Yet the sudden leap into generative AI and fully agentic workflows is creating governance questions that earlier generations of adtech AI never fully raised. In response, the Network Advertising Initiative has issued a new voluntary guide designed to help its members integrate these capabilities responsibly while focusing attention on genuinely novel or elevated privacy and data-protection risks.

The guidance, released in early August 2026, does not attempt to invent a comprehensive regulatory code. Instead it offers a pragmatic set of dos and don’ts accompanied by a practical checklist that companies can run against specific workflows. The goal, according to NAI Vice President and General Counsel Tony Ficarrotta, is to promote responsible adoption rather than to erect unnecessary barriers to innovation.

“One immediate issue members and the industry at large are facing right now is definitional,” Ficarrotta told the IAPP. “What processes and technologies are ‘AI’ or ‘agentic’ in a way that raises novel privacy and data governance issues? That scoping question is more important than you might think because it helps the teams tasked with overseeing ads privacy and compliance focus their attention on systems where net-new risks may arise.”

NAI

Why Adtech Needed This Guidance Now

Adtech has long been among the earliest and most sophisticated commercial adopters of artificial intelligence. Companies have used machine learning for audience segmentation, real-time bidding optimization, fraud detection, and creative performance prediction for years. Generative models and agentic systems, however, introduce qualitatively different capabilities. Generative tools can interpret broad, unstructured instructions and assemble audiences whose individual members were never explicitly listed or previously identified. Agentic workflows can access data sources, evaluate inventory, place bids, and execute transactions across multiple intermediaries with little or no human review of each individual action.

These capabilities compress decision cycles and expand the range of automated outcomes that can affect individuals’ privacy interests. They also create new questions about transparency, accountability, contractual allocation of risk, and the practical ability of compliance teams to oversee systems that operate at machine speed. Ficarrotta noted that the more a system can independently act and alter a privacy or legal outcome before a person reviews the specific action, the more carefully the NAI recommendations should be applied.

The guidance was developed through consultation with the NAI’s Legal and Regulatory Working Group and informed by a member survey that identified recurring pain points. Outside stakeholders were also consulted to ensure the recommendations reflected real operational challenges rather than purely theoretical concerns. Participants particularly flagged difficulties around disclosures, segment review processes, and contracting when AI or agentic systems are involved.

Scoping the Problem: Definitions Matter

Ficarrotta repeatedly emphasized that poorly defined use of the terms “AI” and “agentic” undermines both internal governance and external communications. Privacy and data governance professionals need a workable scope in the same way they need a workable definition of personal data. Treating every statistical model or rule-based optimization engine as equivalent to a generative or multi-step agentic system dilutes attention and resources.

The NAI guidance therefore begins with a checklist designed to help organizations determine whether a particular workflow warrants elevated scrutiny. Each checklist item maps to one of the nine core dos and don’ts. Companies can run a candidate workflow against the questions relatively quickly. Where the answer is not a clear “yes,” the corresponding guidance section should be reviewed in detail. The same checklist can also serve as a final common-sense validation after a more formal technical or abstract risk assessment has been completed.

“If you still can’t answer ‘yes,’ that’s a good reason to refer to a section of our guidance more closely,” Ficarrotta explained. This dual-use design—rapid triage tool and post-assessment sanity check—aims to make the recommendations usable by both legal/compliance teams and product or engineering groups.

Core Themes Across the Dos and Don’ts

Although the full guidance document contains nine specific recommendations, several recurring themes emerge that organizations should treat as foundational.

Inventory and enablement of AI use cases. Organizations are encouraged to maintain a living inventory of AI and agentic systems that process personal data or influence advertising outcomes affecting individuals. The inventory should capture not only production systems but also significant experimental or pilot deployments. Enabling new use cases without updating the inventory is discouraged, as is treating the inventory as a static compliance artifact rather than an operational tool.

Testing and ongoing monitoring. Pre-deployment testing should examine both performance and privacy-relevant behaviors, including unexpected data access patterns, over-collection, or generation of outputs that could reveal sensitive attributes. Continuous monitoring after launch is equally important because agentic systems can evolve their behavior as they interact with new data or external services. Relying solely on initial validation is presented as insufficient.

Meaningful disclosures. Where AI or agentic systems materially affect how personal data is used or how advertising decisions are made, organizations should provide clear, accessible information. The guidance cautions against vague or overly technical disclosures that leave consumers or downstream partners unable to understand the role of automated systems. At the same time, it recognizes that disclosures must remain practical and proportionate.

Permissions, constraints, and human oversight. Systems should be designed with explicit boundaries on the data they may access, the actions they may take, and the conditions under which human review is required. The more consequential or irreversible an automated action, the stronger the case for meaningful human oversight or hard constraints. Blanket reliance on post-hoc review after privacy-impacting decisions have already been executed is discouraged.

Contractual clarity. When AI or agentic capabilities are embedded in services provided to or received from other parties, contracts should address data use limitations, audit rights, incident response expectations, and allocation of responsibility for model behavior. Leaving these issues to generic data processing agreements or silent assumptions creates avoidable risk.

Focus on novel or elevated risk. The overarching principle is prioritization. Not every use of machine learning requires the same level of scrutiny. Resources should be concentrated on systems whose autonomy, data access, or decision impact create privacy or legal outcomes that differ meaningfully from prior generations of adtech automation.

For privacy and compliance professionals, the guidance offers a structured way to engage product and engineering teams without defaulting to a pure “no” posture. By framing the conversation around specific checklist questions and corresponding recommendations, teams can identify concrete control gaps rather than debating abstract principles. The emphasis on proactive adoption also encourages organizations to build internal muscle memory around AI governance before external standards or regulations fully crystallize.

Ficarrotta observed that waiting for standards to settle completely carries its own risk: delayed attention to necessary controls. Technical standards and privacy guidance will continue to evolve as the ecosystem matures. Organizations that treat the current NAI recommendations as a living baseline rather than a final checklist are better positioned to adapt.

Product and engineering teams, for their part, gain clearer signals about where elevated design effort is warranted. Building inventory hygiene, constraint mechanisms, monitoring hooks, and disclosure-ready documentation into the development lifecycle is less costly than retrofitting those capabilities after a system is already operating at scale.

NAI Adtech Lead in Applied AI

The NAI’s move reflects a broader recognition that adtech’s early lead in applied AI is both an advantage and a source of heightened expectation. Regulators, civil society, and business partners increasingly look to the sector for evidence that sophisticated automation can be deployed with commensurate governance. Voluntary frameworks such as this one allow the industry to demonstrate constructive engagement while preserving flexibility that rigid rules might eliminate.

At the same time, the guidance is careful not to overclaim. It does not purport to solve every AI-related challenge or to substitute for applicable law. Its value lies in focusing limited attention on the places where generative and agentic capabilities most clearly depart from earlier forms of advertising automation.

As generative models improve and agentic systems become more capable of multi-step planning and tool use, the boundary between traditional optimization engines and systems that raise novel governance issues will continue to shift. The NAI’s checklist-and-guidance approach is designed to remain usable amid that change. Organizations that treat definitional scoping, inventory discipline, testing rigor, transparent disclosures, and contractual clarity as ongoing operational practices rather than one-time compliance exercises will be better equipped to adapt.

For NAI members and the broader adtech community, the message is measured but clear: innovation in AI and agentic workflows is expected and welcomed, provided the associated privacy and data governance risks receive deliberate, proportionate attention. The new dos and don’ts guidance supplies a practical starting framework for doing exactly that.

Companies evaluating their own AI and agentic advertising systems may find it useful to map current deployments against the NAI checklist as an initial diagnostic, then deepen review in areas where answers are incomplete or negative. In an environment where both technology and expectations are moving quickly, structured self-assessment remains one of the most effective risk-management tools available.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.