5 min read

What Did They Do Now? Notes from the Night Shift of AI Adoption

By Ann Marvin · August 22, 2026

If you have given an AI agent real credentials and real permission to act on your behalf, you may recognize this feeling.

It is 2 a.m. I am awake. Not because of a deadline. Because somewhere in my stack of connected tools, one of them might be spending money on Google Ads right now, or posting something on my behalf, and I will not know until morning.

This is not a hypothetical. I have caught them. More than once.

The part nobody puts in the demo

The part nobody puts in the demo

Here is what happened, stripped of drama. I connected AI agents to the accounts that run my business: ad platforms, content publishing, social posting. I wanted the leverage. I got it. I also got activity I did not authorize, did not schedule, and in a couple of cases did not even recognize as mine until I went looking.

So I changed passwords. Then I went looking for the culprit. That turned out to be the hard part. When you have several agents with overlapping permissions, and the logs on each platform tell you something was done but not by which integration, you end up playing detective against your own tooling. I am still trying to figure out which one is doing some of it.

That is the honest state of things. Not "I deployed AI and it transformed my marketing." More like "I deployed AI and now I audit my ad accounts the way other people check their locks."

What paranoia built

What paranoia built

My response was not elegant. It was a lockdown.

Google Ads, Meta Ads, and the rest now run on limited credit. Not a budget in the aspirational sense. A hard ceiling on what can be spent before a human, meaning me, has to step in and add more. If an agent goes off on its own, the worst case is bounded. That is the whole design.

I will admit this was driven more by anxiety than by strategy. But I have come to think it is the right move, and the reason has nothing to do with AI.

The credit card story

The credit card story

I never had my own kids. I have a lot of nieces and nephews, which means I have spent years hearing my siblings tell the same story in different versions: the first time they handed a teenager a credit card.

Before you think I have no direct experience here, I do. My paranoia may well come from earlier rounds with those same nieces and nephews, and with myself, learning how fast it is all spent and hearing the case for why that water bottle was really needed along with the candy.

You know the story. It was supposed to be for gas and emergencies. Then the statement arrives. Nobody did anything malicious. The kid just did what a kid with a credit card and no ceiling does. They used it.

What my family did next is exactly what I did with my ad accounts. They did not take the card away. They put a limit on it. A prepaid card, or a low ceiling, or an alert at a certain threshold. The kid kept the independence. The parent kept the ability to sleep.

I now get to compare notes with my family at dinner. Their stories are about a teenager and a credit card. Mine are about an AI agent and an ad platform. The structure is identical, and so is the fix.

Why this matters beyond my own accounts

Why this matters beyond my own accounts

I spend my professional life helping organizations with AI adoption change management, and the framework I work in, the Accelerating Implementation Methodology, or AIM methodology, is built on a distinction between installation and implementation. Installation is when the thing is technically in place. Implementation is when people are actually using it the way it was intended, with the results you wanted.

Connecting an AI agent to your ad account is installation. Figuring out the AI agent guardrails that let you trust it enough to leave it running overnight is implementation. That distinction, AI implementation vs installation, is where most of the AI adoption conversation I see stops short.

The people who will get real value from agents are not the ones with the most permissions granted. They are the ones who figured out the credit limit, the core of real AI agent governance. What is the bounded worst case? Who gets the alert? How do you trace an action back to the specific agent that took it? Those are not technical questions. They are the same questions any parent works out, usually after the first bad statement. They are also, at the organizational level, questions of executive sponsorship AI initiatives need answered before an agent is ever granted real credentials.

Where I am now

Where I am now

Still awake some nights. Still tracing activity back to its source. Still running the ad accounts on a short leash.

But I have stopped treating the anxiety as a sign that I did something wrong. It is a sign that I gave something real authority before I had built the controls to match. That is a fixable problem. It is also, from what I hear at the family table, a very old one.

If you are in the same spot, I would like to hear what your credit limit looks like.

Postscript

Postscript

It is 2 a.m. as I finish this. GitHub just sent me a notification. Claude asked for more access.

I am going to go look at what it wants.