Since the release of AAMP 2.0 in April of this year, which added five new transaction types, including agentic PMPs and Programmatic Guaranteed, to the Agent’s vocabulary, the Agentic Task Force has been aggressively pushing forward. In less than three months, the AAMP GitHub repository has seen collaboration and use cases submitted from across the industry. This resulted in the addition of bug fixes and improvements based on real-world testing, the extension of capabilities to address those use cases, and, above all, the maturing of the AAMP framework.
AAMP 2.3 takes agentic media buying beyond demos and first live implementations to capabilities integrated into production media buying stacks and processes operating at scale with:
- Enterprise-Grade Deployment and Interoperability.
- Built in governance and trust.
- Making Audiences Transaction-ready.
Here we will explain why and some of the highlights of AAMP 2.3. For a full list of changes and additions, you should review the GitHub repository.
AAMP Interoperability and Deployment become Enterprise-Grade
Trust comes from running where enterprises already run. The AAMP Buyer and Seller Agents now have a full Amazon Bedrock AgentCore Runtime deployment surface, with REST and MCP modes, S3-backed inventory adapters, CloudFormation for provisioning, and nearly 5,000 successful unit tests running across the agents. AAMP now meets buyers and sellers on the infrastructure they already use for day-to-day operations and where organizations can govern, secure, and audit.
Interoperability between agents and systems received a similar upgrade. The MCP transport upgrade restored Streamable HTTP as the primary transport mechanism, kept legacy SSE alive for older clients, and made the client auto-negotiate between them. In addition, the Seller Agent replaced legacy credential flows with OAuth protocols for Streaming Hub and Buyer Cloud, replacing bespoke credential paths with modern, standards-based authentication for greater security. Agents can also now scale horizontally across multiple instances instead of being pinned to a single node as a result of the addition of pluggable storage backends, including SQLite, Redis, and Postgres+Redis.
AAMP 2.3 also brings a wider range of partners for the Buyer and Seller Agents to work with. Companies can now choose the model the agent uses, through support for the ability to work with OpenAI, Google Gemini, and other OpenAI-compatible services like NVIDIA NIM, Ollama, and Hugging Face. The framework also increased the execution tools that agents can use by adding integrations for Google Ad Manager Reporting and Meta Ads.
Together these commits mature the AAMP framework from “works on a laptop” to “runs in an enterprise stack.”
Trust and Safety Move from Optional to Enforceable
Answering the industry’s compliance, trust, and safety concerns is the second major theme running through AAMP 2.3.
The Buyer Agent now incorporates a vendor approval gate via the IAB Diligence Platform / SafeGuard Privacy. When this enforcement is enabled, unapproved vendors are filtered out before the agent ever sees them, and the same check is applied before a transaction is finalized. This important check is turned off by default and fully invisible when no key is present. This means the gate is there when a buyer needs governance and stays in the background when they don’t. This agentic autonomy that respects a hard approval boundary is a critical requirement for regulated advertisers in the Agentic Task Force.
Just as important, even though it is a very different form of ‘trust’, was a fix to the problem of CPM hallucination. Earlier versions of agent behavior allowed fabricated CPM values when pricing data was missing, which was a dangerous failure mode when an agent was negotiating real money. AAMP 2.3 removes those LLM fallbacks by adding a field showing the pricing provenance. With this field in place, organizations can trace where every price came from through the negotiation chain and can put guardrails in place so the agent cannot invent floor prices. An agent that says “I don’t know the price” instead of confidently making one up is an agent you can trust once it is deployed.
Audiences become a First-Class Citizen
One other key part of AAMP 2.3 is making Agentic Audiences ready to be used in the existing programmatic workflow. The Agentic Audience Extension in OpenRTB means that audience vector embeddings can be included in the bidstream, and the Prebid module supporting Agentic Audiences makes the field operational for all sellers.
AAMP 2.3 also integrates Mixpeek’s contextual enrichment technology, which Mixpeek donated to IAB Tech Lab earlier this year, to match context to the existing Taxonomy standards used throughout the programmatic supply chain. This makes it easier for buyer and seller agents to describe and match audience segments that are consistent with other programmatic transactions.
Why does this matter? Because audiences are where programmatic deals actually live or die. Giving agents a structured, auditable way to describe, discover, and match audiences, because the embedding is carried through the compliance context to provide round-trip auditability, turns “the agent found something close enough” into “the agent matched against a verifiable, taxonomy-backed audience plan.” That’s the difference between a party trick and a tool that a media buyer will actually trust with a budget.
Making AAMP Adoption Ready
There is a lot of debate in the industry about what an agentic advertising protocol should look like. IAB Tech Lab believes that it should not reinvent the wheel, but be built on top of the existing battle-hardened foundations that have been growing the ecosystem for over a decade. This includes:
- Meeting the enterprise where it lives. Bedrock AgentCore, pluggable storage, and standards-based MCP transport make AAMP deployable inside the cloud and security environments that large advertisers and publishers already run.
- Being honest about money. The CPM hallucination fix and pricing provenance directly address the failure mode that would otherwise disqualify any agent from touching real spend.
- Building in governance by default. The SafeGuard Privacy approval gate answers the “can I trust an autonomous agent with my brand and budget?” question with an enforceable mechanism, which is exactly the concern that slows enterprise adoption of any protocol, let alone an agentic one.
- Making Audiences a differentiator. The typed, taxonomy-backed audience layer with provenance and snapshot-honoring deal minting gives AAMP a rigorous, auditable audience negotiation story — the part of the workflow that matters most to buyers and is the hardest to fake.
By addressing these critical maturity use cases, the AAMP 2.3 release removes the obstacles in the way of agentic buying being adopted at scale: verifiable audiences, enforceable trust, real deployment targets, and pricing you can defend. Those are durable advantages, not feature-checklist parity.
There’s Still Work to Do
AAMP v2.3 is a maturity release based on foundational underpinnings including: typed audiences, enforceable trust, enterprise deployment, and pricing you can trace. That combination is what moves agentic advertising from an interesting experiment to something a buyer or publisher can actually stand behind.
But the work is not yet done. These features will continue to evolve, and there are more use cases to be accounted for that go beyond creating and executing orders and deals. Some of these may be even more valuable and are outcomes that agents are especially capable of creating. Join the Agentic Task Force today, pilot AAMP agents, and help innovate and build the industry’s agentic future. AAMP 3.0 is coming soon and you can be part of it.

Shailley Singh
COO/EVP of Product
IAB Tech Lab