Brand safety is the practice of keeping advertisements away from content that no mainstream advertiser wants to fund, such as terrorist propaganda, child exploitation, graphic violence and illegal drug sales. The practice exists because programmatic buying places ads on pages the buyer never sees. Without controls, a brand can pay for a placement beside material that harms its reputation and, in the same transaction, finance the publisher that produced it. The concept describes a floor: content unfit for every advertiser. Lawful but sensitive material above that floor belongs to brand suitability, a separate and more contested decision.
How it works
A programme runs in three stages: classification, enforcement and verification.
Classification comes first. Vendors and platforms crawl pages, apps and videos in advance, assign each a category and, in most systems, a risk level. Auctions close in milliseconds, so scoring cannot wait for a bid request. A page that was never crawled carries no score, which is why Display & Video 360 (DV360) offers an option to block unrated URLs in its Integral Ad Science (IAS) settings. The shared vocabulary came from the Global Alliance for Responsible Media (GARM). According to its September 2020 framework, the floor covers 11 categories, from adult content to terrorism, with three graded risk tiers above it.
Enforcement takes three forms. Pre-bid filtering lets a demand-side platform (DSP) check the URL or app bundle in each bid request against a cache of vendor scores and decline to bid. Post-bid verification wraps the creative in a vendor tag that runs where the ad renders, then either reports the surrounding content or blocks the ad before it displays. Platform-native controls sit alongside: Google's digital content labels and sensitive topic classifiers, Meta's inventory filter, and Amazon DSP's content exclusion categories, added on December 18, 2025.
The protocol layer says little. OpenRTB 2.5, published by IAB Tech Lab in 2016, carries the bcat and badv fields, lists of blocked advertiser categories and domains that a seller sets. These protect publishers from unwanted advertisers rather than advertisers from unwanted pages. OpenRTB 2.6, published in April 2022, added a cattax field declaring which taxonomy a request uses, yet no standard field carries a safety or suitability score. The verdict therefore travels as a vendor segment inside the DSP.
Verification closes the loop by reporting violation rates after delivery. On the buy side, the advertiser writes the policy, an agency trading desk configures it, the DSP applies it and vendors such as DoubleVerify, IAS and Zefr supply the classification. On the sell side, publishers and platforms moderate content, apply monetisation policies and pass category signals. The Trustworthy Accountability Group (TAG) launched its Brand Safety Certified Program on September 10, 2020, with more than 110 companies certified at launch, according to TAG. The Media Rating Council (MRC) accredits vendors' measurement separately.
Origin and evolution
Verification came first, safety later. The 2012 IAB and MRC ad verification guidelines covered site context, geography and fraud, and never used the word safety.
The term took hold in 2017. The Times of London reported ads from large brands running beside extremist videos on YouTube and, according to the paper's count cited by Marketing Week, more than 250 advertisers suspended spending. Matt Brittin, Google's president for Europe, the Middle East and Africa, apologised publicly on March 20, 2017. The next day Google announced stricter content policies and account-level exclusion controls.
Agencies then wrote the rules down. The American Association of Advertising Agencies (4A's) formed the Advertiser Protection Bureau on April 10, 2018, and released a Brand Safety Floor and a suitability framework covering 13 categories on September 21, 2018. That month the MRC finalised a supplement on content-level context and brand safety, setting requirements for analysing images, video and audio. The World Federation of Advertisers (WFA) founded GARM in June 2019 and published its floor in September 2020. GARM began work on a misinformation category in June 2021, and added it to the floor in June 2022. DoubleVerify, meanwhile, had brought Authentic Brand Safety to DV360 on November 2, 2020, citing more than 75 avoidance categories.
Why it matters for marketers
Brand safety turns a written policy into rules applied billions of times a day. Each exclusion removes supply. Google's own guidance warns that campaigns overusing controls can see limited reach and higher CPMs. News absorbs much of the loss. Vodafone reported in July 2025 that revised settings cut its block rates by 41% and opened 10% more news inventory, partly because a blocked entry for die had been catching pages about diet. Vodafone and DoubleVerify supplied the figures. String matching persists: Microsoft Advertising began rolling out exclusions for up to 1,000 page title terms in August 2026.
The settings also allocate revenue. A blocked page is an unfunded publisher, and that is where the practice turned political.
Limitations and disputes
Definition. On October 18, 2025, the MRC restricted the phrase brand safety to vendors that analyse images, video and audio. Property-level services built on text, keywords or language classification may not use the label, though they may describe suitability if they disclose five limitations, among them excluded media types and crawl rates. The grace period ended on April 18, 2026. The 2018 supplement had set the content-level standard seven years earlier; the council acknowledged that confusion persisted despite its clarifications. YouTube Shorts became the first short-form product accredited under the stricter definition on June 3, 2026.
Accuracy. A vendor tag proves measurement, not protection. After Adalytics reported on February 7, 2025 that DoubleVerify-measured ads had run on an image host beside explicit material, DoubleVerify replied that its tag might indicate only post-bid measurement rather than avoidance, and put the site at 0.000047% of transactions it measured.
Politics. The floor includes judgements about misinformation, and critics read them as viewpoint exclusion. A July 10, 2024 House Judiciary Committee staff report concluded that GARM coordination was likely illegal under antitrust law. X sued GARM, the WFA and several advertisers on August 6, 2024, and the WFA discontinued GARM within days, dating the closure to August 9. The WFA maintained that GARM standards were voluntary. Judge Jane Boyle dismissed the case in Dallas on March 26, 2026; according to The Drum, she cited a lack of jurisdiction and a failure to state an antitrust claim, while Reuters reported a failure to show antitrust harm. X appealed. The parties settled on July 29, 2026, with the WFA agreeing not to form or restart GARM or a similar initiative.
Regulators acted in parallel. The Federal Trade Commission (FTC) finalised a consent order on September 26, 2025barring Omnicom from directing spend on political or ideological grounds except at an individual client's instruction. On April 15, 2026 it sued WPP, Publicis and Dentsu, alleging that since 2018 they had imposed a common floor, through the 4A's bureau and GARM, that demonetised some conservative publishers. WPP said it agreed a consent order on a no admit, no deny basis, according to MediaPost. Chairman Andrew Ferguson said the arrangement had inverted competition in ad buying.
Independence. Novacap agreed to take IAS private for about $1.9 billion in September 2025. Nielsen agreed on August 6, 2026 to buy DoubleVerify for about $2.15 billion, with closing targeted for the first quarter of 2027.
Metrics. TAG, the Association of National Advertisers (ANA) and Fiducia found on July 28, 2026 that AI-generated junk inventory graded as premium more than 70% of the time, with invalid traffic of 0.05% against 0.32% for clean supply. Passing the filters is not the same as being worth buying.
Not the same as
Brand suitability is relative: an advertiser's own tolerance for lawful but sensitive content, set in graded tiers above the floor. Since the MRC's 2025 policy the two labels also carry different accreditation requirements.
Ad fraud, measured as invalid traffic, asks whether a human saw the ad at all. Vendors sell it in the same contract, but it addresses bots rather than adjacency.
Made-for-advertising (MFA) sites are sites built to harvest ad revenue. They are low-value rather than harmful, and DoubleVerify split MFA into three tiers in early 2024, separately from its safety categories.
Contextual targeting uses the same page classification to seek placements. Excluding tragedy coverage is brand safety; buying recipe pages is targeting.
Recent developments
As of October 6, 2026, the controls are narrowing in one place and multiplying in others. Google announced on August 27 that digital content label exclusions and most sensitive category exclusions would leave the DV360 API and Structured Data Files on October 1, 2026, in favour of inventory modes and content themes that do not map one to one. The coverage reviewed here confirms the schedule but not the cutover itself. Meta has withdrawn manual placement controls from some accounts, steering concerns towards inventory filters and block lists.
Platforms are also grading themselves. X told advertisers that Grok scores content, and cited brand safety rates above 99% and suitability above 97% drawn from X, IAS and DoubleVerify data, figures that have a commercial interest behind them. On October 5, 2026, IAS said it had started reporting on ChatGPT Ads for a select group of advertisers; neither the pilot size nor the method was disclosed.
Synthetic content is the newest test. DoubleVerify's AutoBait investigation of March 4, 2026 found more than 200 MFA domains producing clickbait with language models at roughly $2.25 an article.
Timeline
- February 14, 2012: IAB and the MRC release their guidelines for the conduct of ad verification
- February to March 2017: The Times of London reports ads beside extremist YouTube videos and advertisers suspend spending
- March 20, 2017: Google's Matt Brittin apologises publicly at Advertising Week Europe
- March 21, 2017: Google announces stricter policies and account-level exclusion controls
- April 10, 2018: The 4A's forms the Advertiser Protection Bureau
- September 2018: The MRC finalises its content-level context and brand safety supplement
- September 21, 2018: The bureau releases a Brand Safety Floor and suitability framework covering 13 categories
- June 2019: The WFA founds GARM
- September 2020: GARM publishes its floor and suitability framework with 11 categories
- September 10, 2020: TAG launches its Brand Safety Certified Program
- November 2, 2020: DoubleVerify launches Authentic Brand Safety on DV360
- June 2022: GARM adds misinformation to its floor
- August 6, 2024: X sues GARM, the WFA and several advertisers
- August 9, 2024: The WFA discontinues GARM
- September 26, 2025: The FTC finalises its Omnicom-IPG consent order
- October 18, 2025: The MRC restricts brand safety terminology to content-level analysis
- December 18, 2025: Amazon DSP adds content exclusion categories
- March 4, 2026: DoubleVerify publishes its AutoBait investigation
- March 26, 2026: A federal judge dismisses X's lawsuit
- April 15, 2026: The FTC and eight states sue WPP, Publicis and Dentsu
- April 18, 2026: The MRC grace period on brand safety terminology ends
- June 3, 2026: YouTube Shorts earns MRC brand safety accreditation
- July 28, 2026: TAG, the ANA and Fiducia find AI-generated inventory graded premium more than 70% of the time
- July 29, 2026: The WFA and X settle
- August 6, 2026: Nielsen agrees to acquire DoubleVerify for about $2.15 billion
- August 2026: Microsoft Advertising adds page title exclusions of up to 1,000 terms
- August 27, 2026: Google announces removal of two DV360 exclusion controls
- October 1, 2026: Scheduled removal of digital content label and most sensitive category exclusions from the DV360 API and Structured Data Files
- October 5, 2026: IAS announces brand safety reporting for ChatGPT Ads in a closed pilot
Related PPC Land coverage
- Explaining brand suitability - The tiered, advertiser-specific layer above the safety floor, with the history of the 2018 frameworks.
- Explaining pre-bid filtering - How impressions are screened against scored caches before a bid is placed.
- Explaining post-bid verification - How vendor tags measure or block delivered impressions, and where that coverage has gaps.
- How Google Brand Safety works - Digital content labels and sensitive topic classifiers across Google's buying products.
- Amazon DSP adds content exclusion categories for brand suitability control - Binary topic exclusions added in December 2025 across Twitch and third-party supply.
- MRC restricts property-level ad verification from brand safety claims - The October 2025 policy, its five disclosures and the April 2026 deadline.
- YouTube Shorts gets its first MRC brand safety accreditation - a short-form first - The June 2026 accreditation covering Shorts and in-stream inventory tiers.
- Vodafone increases news ad inventory 10% with AI brand suitability strategy - Company-reported effects of narrowing over-broad keyword blocking on news reach.
- Microsoft lets advertisers block ads next to 1,000 page titles - A string-matching control and the overblocking problem it inherits.
- X files Antitrust lawsuit against GARM and advertisers over alleged boycott - The August 2024 complaint naming the WFA, GARM and several advertisers.
- WFA disband GARM following Antitrust Lawsuit from Elon Musk's X - The suspension of the body whose framework standardised risk categories.
- FTC finalizes restrictions on Omnicom's acquisition of IPG - The consent order limiting viewpoint-based exclusion lists to individual client direction.
- FTC sues WPP, Publicis, and Dentsu over brand safety collusion - The April 2026 complaint, the House Judiciary report and the GARM timeline.
- Nielsen acquires DoubleVerify for $2.15 billion in all-cash deal - Terms and timing of the deal taking a leading verification vendor private.
- AI slop wins premium grades 70% of the time, TAG and ANA analysis finds - Evidence that synthetic inventory can outscore clean supply on standard quality metrics.
- Explaining made-for-advertising - The low-value site category that verification vendors tier separately from safety.
- Google cuts two DV360 brand safety exclusion controls on October 1 - The withdrawal of label and category exclusions in favour of inventory modes and content themes.
- Some Meta advertisers lose placement controls, with bid cuts capped at 90% - Meta's shift from placement exclusions towards inventory filters and block lists.
- Grok is now a brand safety tool - X's March 2026 playbook and its self-reported safety and suitability scores.
- ChatGPT Ads gains IAS brand safety measurement in closed pilot - The October 2026 pilot and the questions about method and accreditation it leaves open.
- DoubleVerify exposes AutoBait, an AI slop network costing advertisers millions - Per-article costs and domain counts for an automated clickbait network.
Summary
Who. Advertisers and agencies set policy. Verification vendors such as DoubleVerify, IAS and Zefr classify content and enforce settings inside DSPs, while Google, Meta, TikTok, Amazon and Microsoft run native controls. The MRC accredits measurement, TAG certifies companies and the FTC now polices how agencies coordinate.
What. The practice of keeping ads away from content unfit for any advertiser, applied through pre-bid filtering, post-bid verification, platform controls and exclusion lists, and measured by third-party reports.
When. The term spread after the YouTube advertiser boycott of March 2017, was formalised by the 4A's on September 21, 2018 and by GARM in September 2020, and was redefined by the MRC on October 18, 2025.
Where. Inside DSP settings, vendor dashboards and walled-garden account controls, across the open web, apps, social feeds, streaming video and, as of October 2026, a closed pilot in ChatGPT Ads.
Why. Programmatic buying separates the advertiser from the page. Controls exist to limit reputational harm, yet classification accuracy, vendor independence and the politics of exclusion all remain contested.
Discussion