Instagram automation is not banned. Automation that bypasses Meta's API is. The distinction decides whether your account is safe.
Official automation works through the Instagram Graph API. You connect a Professional account to an approved app, grant specific permissions, and the app receives webhooks and sends messages through documented endpoints. Meta knows the app exists, has reviewed its permissions, and enforces rate limits. Nothing about this is against policy, because it is the interface Meta built for it.
Unofficial automation logs in as you. It stores your username and password, or drives a headless browser that pretends to be a phone. Anything advertising unlimited follows, mass DMs to people who never contacted you, or automated liking at scale falls in this category. Meta detects the pattern through device fingerprints and behavioural signals, and the penalty lands on your account, not the vendor's.
The behaviours that reliably cause problems are cold outreach to people who never interacted with you, sending faster than the documented limits, running several tools on one account at once, and messaging that generates a high report rate. That last one matters more than most people expect. Meta weighs user reports heavily, so a message people find unwelcome is a policy risk regardless of how it was sent.
Staying safe is mostly common sense. Only message people who took an action first, such as commenting or messaging you. Keep sending pace under the published ceiling. Give people an obvious way to stop hearing from you and honour it immediately. Keep your promises consistent with your captions, because mismatched expectations produce reports.
Before paying for any tool, ask one question. Do you use the official Instagram Graph API and are you a registered Meta tech provider. A vendor that cannot answer clearly is asking you to gamble your account to save a few hundred rupees a month.