Google Bans Third-Party MCPs, Tightens AI Policies Ahead of 2026 Update
September 5, 2026
Google is tightening its stance on agentic AI and MCP-wide architectures, explicitly banning third-party MCPs that serve multiple advertisers via shared infrastructure unless they are strictly for internal use.
The Developer Secondary Interface Review process allows legitimate wrappers to seek approval if they satisfy RMF adherence, measurement transparency, and auditing with immutable logs and external security assessments.
Leading up to the August 31, 2026 policy update, the timeline highlights mid-2025 to 2026 developments such as API cadence changes, data retention adjustments, and security enhancements.
For compliant developers, those using separate Cloud projects and user-driven authentication align with best practices, while hosted multi-tenant proxies now face risk under the new policy.
New disclosure and security obligations require agencies and vendors to inform clients of reporting delays, obtain client consent before data disclosure, and enforce encryption and secure handling across devices and networks.
Enforcement is active: existing integrations are being reviewed with outreach to affected developers; non-response can downgrade or terminate API access, and non-compliance may incur fees.
Two exceptions exist: direct use of the Google Ads API for one’s own use, and open-source tools where end-users run software locally with their own credentials.
Contextually, Google has been tightening API access over 2025–2026, consolidating data pathways through the Data Manager API, enforcing dedicated Cloud projects, and integrating MCP tooling with agentic AI developments.
RMF categories apply by tool type: Full-Service tools require RMF across creation, management, and reporting; reporting-only tools require RMF for reporting; internal-use tools are exempt.
The rollout emphasizes security and risk mitigation, citing risks from unaudited proxies, cross-tenant data leaks, and potential high-volume DoS impacts.
On August 31, 2026, Google updated the Google Ads Developer Policies to ban programmatic proxies and require each integration to connect directly to Google Ads services via its own dedicated Google Cloud project.
A programmatic proxy is defined as any third-party hosted interface or MCP server that replicates or re-exposes Google Ads capabilities as an intermediate layer, including MCP servers.
Summary based on 1 source
Get a daily email with more Tech stories
Source

PPC Land • Sep 5, 2026
Google bans programmatic proxies from Ads API access