Ofcom’s scam advertising rules: What tech platforms need to know

Ofcom scam advertising rules

According to Ofcom, annual revenues from digital advertising now total c. £40 billion in the UK alone.  Online ads are a vast commercial ecosystem relied on by companies worldwide to reach their target customers, and by Big Tech to generate fees.  But it’s also being increasingly exploited by fraudsters.  Given that the internet gives criminals unprecedented and often anonymous access to consumers, it is unsurprising that so much fraud now begins online, with Ofcom estimating losses to victims of £200 million every year from one particularly troublesome source: scam ads.

What is a scam advert?

Some are easy to spot: fake retailers and travel companies offering impossible deals that are clearly too good to be true.  Others are much more sinister, particularly with the emergence of deep fakes and voice cloning where software is being weaponised to trick consumers into believing that consumer specialists and wealthy entrepreneurs are endorsing products.  Despite the efforts of consumer champions like Martin Lewis, anyone can be scammed and increasingly sophisticated tactics can catch out even the most savvy individuals, as well as vulnerable users.

Why is the law changing?

Ofcom (as the regulator armed with the power to enforce the Online Safety Act) is now seeking to intervene by forcing certain tech platforms to prevent scams before they happen.  For too long, scammers have exploited the reach, user data and sophisticated advertising infrastructure of major technology platforms to target victims at scale.  Ofcom’s view is that these platforms are uniquely placed to identify, disrupt and preventscams before they cause harm.

What will platforms be required to do?

To that end, Ofcom’s draft Fraudulent Advertising Code of Practice sets out almost 40 measures that it expects certain platforms to adopt.  At a high level, platforms that sell advertising space will be expected to:

    1. Implement effective governance to address fraudulent advertising, including allocating responsibility for compliance, providing staff with appropriate training, identifying and assessing fraud risks, and implementing measures designed to tackle those risks.
    2. Implement systems and processes to identify and take action against fraudulent advertising, including moderation and monitoring capable of detecting scam ads and advertisers and responding promptly when risks are identified.
    3. Verify advertisers properly by applying additional scrutiny where fraud risks are elevated, protecting advertising accounts from hacking, and preventing previously sanctioned advertisers from setting up new accounts.
    4. Strengthen reporting mechanisms and transparency measures, including facilitating the reporting of suspected scam ads by users and relevant authorities and maintaining accessible records of advertising displayed on the platform.
    5. Evaluate and mitigate risks arising from advertising technologies, including assessing how ad creation tools (including those using AI) could be exploited and safeguarding against those risks.
    6. Ensure fraud prevention measures operate throughout the advertising journey, including through clear platform rules, appropriate review and appeal mechanisms, and cooperation with third parties involved in the delivery of ads where responsibility is shared.

Together, these measures are intended to improve the interception and prevention of scam ads at multiple points in the advertising lifecycle, thereby protecting consumers.

A significant implementation challenge

Aside from the obvious “does this go far enough?” there is also a significant practical question: can platforms implement these proposals effectively in the real world?  Having worked both in private practice as a fraud specialist and in-house for a major social media platform, I have seen first-hand the difficulty of balancing user safety with innovation, commercial objectives and freedom of expression.  For global platforms in particular, meaningful change often requires coordination across multiple jurisdictions and teams with very different areas of expertise.

These proposals will have left many in-house regulatory teams wondering where on earth to begin.  Although some measures may appear straightforward enough on paper, the big challenge lies in implementing changes as part of a coherent system without disrupting the user experience, or unfairly penalising legitimate sellers.  A report of a suspected scam, for example, will likely inform content moderation decisions, advertiser risk assessments and account enforcement measures.  Likewise, preventing banned advertisers from returning to a platform may require coordination between advertising, product, engineering, trust and safety, fraud, legal and compliance teams, as well as engagement with advertisers, intermediaries, regulators and law enforcement.

Well-organised and robust platforms will ultimately find solutions to these challenges, but that does not mean implementation will be without significant delay and challenges.

What if platforms do not comply?

Once the relevant duties and Code are in force, the regime will be enforced by Ofcom which will have authority to require platforms to provide information and documents, conduct audits and investigations, and require specific steps to remedy non-compliance.  Failure to comply could result in financial penalties of up to £18 million or 10% of qualifying worldwide revenue, whichever is greater.  In egregious cases involving very large volumes of scam ads, or repeat offenders, Ofcom may also seek business disruption measures through the courts, potentially involving third parties such as payment providers, advertising services or internet service providers.

Increased risk for platforms

As well as the regulatory risks discussed above, platforms will also need to consider litigation risks.

From a litigation perspective, claimants will not automatically succeed in bringing a claim simply because a platform has breached the Online Safety Act.  Where a user suffers loss as a result of a scam, however, they may be entitled to rely on failures to comply with the regime as part of a wider attempt to establish liability for loss.  This is particularly true where platforms fail, for example, to implement required measures or to follow processes like responding appropriately to a known scam.

You can imagine, for example, a situation where a platform becomes aware that a scam advertiser has been identified by its systems as a repeat offender but fails to take action.  In that case, a claimant may point to that failure as evidence that the platform did not take reasonable steps to protect them from foreseeable harm.  The Online Safety Act does not turn every scam victim into a valid claimant, but it does open the door to argument.

This makes governance and record-keeping especially important.  Platforms will need to be able to demonstrate not only that appropriate measures are in place, but also that those measures are being implemented effectively in practice.  Success will not be measured (at least by Ofcom) by whether a platform eliminates all scam ads.  Instead, the focus will be on whether it can demonstrate robust, proportionate and effective systems designed to reduce the risk of users encountering fraudulent content.

The cross-border challenge

Tech platforms face uniquely difficult cross-border regulatory challenges with jurisdiction-specific legal obligations creating a patchwork of requirements.  The UK’s Online Safety Act is just one example.  The EU has taken a broader approach through the Digital Services Act (DSA), which platforms have been fighting to implement over the past few years with varied success.  The DSA includes transparency requirements for ads, requires very large platforms to maintain publicly accessible ad repositories and requires the largest platforms to identify and mitigate systemic risks arising from their services, including risks associated with illegal content.

Mercifully, this does mean most if not all platforms are likely to have a headstart in implementing the new Online Safety Act proposals, having already established robust, joined-up processes across their global operations for the implementation of new regulations.

These are still proposals

It is important to emphasise that the measures described above are proposals rather than final requirements.  Ofcom published its draft Fraudulent Advertising Codes on 10 July 2026 and is consulting on the proposed measures until 2 October 2026.  Ofcom then intends to consider these responses before publishing its final statement and Code around mid-2027.

This consultation will provide platforms with an opportunity to disclose where the proposed measures may be technically, operationally or commercially unrealistic to implement.  Given the breadth of the proposals, responses are likely to provide the regulator with a picture of the practical challenges involved, including the extent to which existing advertising systems can be adapted and where significant new investment or cooperation across the advertising ecosystem will be required.

Polly Fletcher, Senior Associate at Cooke, Young & Keidan.jpg

Polly Fletcher

Polly Fletcher is Senior Associate at Cooke, Young & Keidan. With extensive experience in civil fraud, regularly handling high-value claims valued between £500,000 and £1 billion, Polly has acted for both claimants and defendants. She is skilled in securing urgent interim relief such as freezing orders and orders for specific disclosure, helping clients protect their interests swiftly and effectively. Polly has a particular specialism in tech, having supported major technology clients including Microsoft and TikTok Technologies.

Author

Scroll to Top

SUBSCRIBE

SUBSCRIBE