Ad fraud has always been treated as a measurement problem: something verification vendors catch after the fact and advertisers write off as a cost of doing business online. A new UK regulatory proposal wants to make it a legal liability for the platforms that carry the fraudulent ads in the first place, and that shift in where accountability sits is the real story for anyone buying or selling media.
What Ofcom is proposing
Ofcom, the UK’s communications regulator, has published draft rules requiring large platforms to actively stop scam advertising rather than simply respond to complaints. The proposal builds on duties already created by the UK’s Online Safety Act and targets Category 1 and Category 2A services, the tier that includes Facebook, Instagram, TikTok, YouTube, Pinterest and Reddit.
The headline mechanism is what Ofcom is calling a “one strike and you’re out” approach. Today, several major platforms give scammers multiple warnings before removing them. Under the draft code, a confirmed scam advertiser would be banned immediately, with no grace period for a second attempt.
Nearly 40 measures, not a single switch
The consultation sets out close to 40 practical steps platforms would be expected to adopt. Among them: permanently banning accounts that post fraudulent ads and blocking those operators from simply opening a new account, intercepting profiles that impersonate legitimate businesses, confirming that anyone running ads for banking or investment products is actually authorized to offer them, and standing up dedicated channels so law enforcement can flag scam campaigns directly rather than routing through general abuse forms.
Notably, the draft also names AI-generated ad creative as a specific risk category, calling for platforms to test and safeguard against criminals using AI tools to mass-produce convincing fraudulent ads. That is a direct acknowledgment that the same generative tooling martech vendors are selling to legitimate advertisers for creative production is already being repurposed by scammers at scale.
Ofcom estimates that fraudulent advertising costs UK consumers roughly £200 million a year. Oliver Griffiths, an Ofcom director, framed the expectation bluntly: “We expect firms to take robust action to stamp out scam ads.”
Real money behind the rules
This is not a voluntary code. Platforms that fail to comply face fines of up to £18 million or 10% of global revenue, whichever is greater, once the rules take effect. For a company the size of Meta or Google, 10% of global revenue dwarfs the cost of building out the compliance infrastructure Ofcom is asking for, which is precisely the point: the proposal is designed to make under-investment in fraud prevention more expensive than the fix.
The consultation runs until October 2, 2026. Ofcom plans to publish its final statement by mid-2027, and the resulting rules will still need Parliamentary approval before they are enforceable, so this is a multi-year process rather than an immediate mandate. But the direction of travel is now explicit, and platforms operating in the UK are on notice well before enforcement begins.
What it means for the marketing leader
For legitimate advertisers, this proposal is a preview of the compliance environment that ad platforms will need to build around, and it has three practical implications.
First, expect more friction in ad account verification. If platforms must confirm that anyone advertising banking or investment products is properly authorized, similar identity and business-verification checks are likely to extend to other regulated or high-risk categories over time. Brands running programmatic or paid social campaigns should anticipate tighter onboarding and periodic re-verification, not just a one-time KYC check at account setup.
Second, brand safety and ad fraud stop being separate line items. Marketing teams have historically bought verification as a defensive layer sitting on top of the platforms, via ad verification tools racing to keep pace with the AI ad economy. If platforms themselves are legally required to police scam activity, the baseline of what a “clean” platform guarantees moves up, which should, in theory, reduce how much marketers need to spend on third-party verification for fraud specifically, even as verification demand grows elsewhere.
Third, this is a UK-specific rule with global implications. Regulatory regimes rarely stay contained to one market once a workable enforcement model exists; the EU’s Digital Services Act and ongoing US state-level privacy and consumer-protection activity suggest other jurisdictions will study how Ofcom’s one-strike model performs. Marketing leaders operating across regions should treat this as an early signal of where platform accountability for ad content is heading generally, not just a UK compliance footnote.
What to watch next
The consultation window closing October 2 is the next concrete checkpoint. Expect platforms named in the proposal, along with industry bodies representing programmatic and social advertising, to submit formal responses arguing over the specifics of the 40 measures, particularly the account-recreation ban and the AI-creative safeguards, both of which require real engineering investment to enforce at scale. How the ad platform leadership responds to this proposal, including any public statements from the platforms named, is worth tracking as an early indicator of how seriously they intend to treat the new accountability regime.
Marketers do not need to change anything today. But procurement and legal teams evaluating platform partners for 2027 planning should start asking media partners directly how they intend to meet Ofcom’s proposed measures, since the answer will separate platforms treating this as a genuine operational priority from those waiting for Parliament to force their hand. The leadership questions already surfacing at verification vendors over AI-era trust are a preview of the same scrutiny platforms themselves are about to face directly.
Source: Ofcom