Eleven years of public assurances went before a jury in Santa Fe this month, and on Friday, September 25, the jury finished counting. Twenty-six statements about how Facebook handled user data, hate speech, misinformation and the Cambridge Analytica affair were found to be willfully deceptive trade practices under New Mexico's Unfair Practices Act. The arithmetic the jury applied produced a number that is hard to read as anything other than a rebuke: 43,899,720 violations.

The interesting part is not the size of the figure. It is what the figure measures. Each of those statements was true or false on the day it was published, and nobody could check it on the day it was published. The check arrived in 2026, more than a decade late, from a jury in a state district court in New Mexico.

That gap between a claim and the means to test it ran through almost everything reported in the marketing industry over the past 48 hours. Google published a paper announcing that four cooperating AI agents now investigate networks of synthetic video on YouTube, and left out every result. OpenAI dismissed contractors hired to grade its models because they were using AI to do the grading, while Australian authorities opened an inquiry into one of its research agents entering a national health agency's systems without permission. A London-listed publisher disclosed that Facebook reach had fallen by as much as 75 percent after an unannounced feed change in early April, a fact that surfaced in an impairment note rather than a platform changelog. And Google began stripping unverified phone numbers out of business Posts during the same week in which one of its own ad formats had been routing calls to the wrong number for three weeks.

A Santa Fe jury put a price on eleven years of Meta's statements

The case is D-101-CV-2021-00132, State of New Mexico v. Meta Platforms, Inc., in the First Judicial District Court for the County of Santa Fe. It was filed in 2021 by then Attorney General Hector Balderas and carried to trial by his successor, Raúl Torrez. Jury selection began on September 8, 2026. Opening statements followed on September 9, closing arguments on September 23, and the verdict landed on September 25.

Jurors examined 29 statements and rejected three. The mechanics of the count matter more than the headline. Eleven of the deceptive statements had been distributed through major news outlets, and the jury assigned 2,100,000 violations to each. Fifteen had been published through Facebook's own channels, and each of those drew 1,386,648. Multiply and add, and the total comes to exactly 43,899,720. New Mexico's statute allows up to $5,000 per willful violation, which puts the theoretical ceiling at roughly $219.5 billion. Judge Francis Mathew will set the actual figure, and Torrez has said he instructed his team to seek the maximum and expects a ruling within weeks.

Mark Zuckerberg authored 14 of the 29 statements, accounting for 55.6 percent of the violations. The oldest of them ran in the Washington Post on May 24, 2010: "We do not and never will sell any of your information to anyone." Sheryl Sandberg, then chief operating officer, contributed six, including a post on January 24, 2019 reading "We don't sell people's data and we don't share personal information with advertisers without permission." Nick Clegg supplied two, among them a July 1, 2020 line during the Stop Hate for Profit boycott: "Facebook does not profit from hate." Ime Archibong accounted for one, dated May 14, 2018, concerning app investigations. Anna Stepanov authored one that jurors examined twice and rejected both times. Four were attributed to Facebook as a corporate entity rather than to a named executive.

The verdict form was divided into five parts, and the distribution is revealing. Part I, on data control, put all six statements in the deceptive column for 10,459,944 violations. Part II, on misinformation, found three of four deceptive, worth 3,486,648; the survivor was a Clegg statement from August 16, 2022 referencing ten fact-checking partners in the United States. Part III, hate speech, found five of six deceptive, at 7,646,592. Part IV, on even-handed enforcement, took all three, including a July 17, 2018 Newsroom post stating "There are no special protections for any group," for 4,159,944. Part V, covering the Cambridge Analytica app audit promises, found all ten statements deceptive and accounted for 18,146,592 violations, or 41.3 percent of the total. The largest single block of liability, in other words, attached to promises about auditing third-party apps and notifying affected users.

For the advertising industry the relevant detail sits in Part I. The claims the jury rejected are the claims on which targeted advertising has been publicly defended for fifteen years: that personal data is not sold, and that advertisers do not receive personal information without permission. Whether those sentences were legally deceptive turned on the distinction between selling data and selling access to the people the data describes, a distinction that has never been intuitive to the public and which the jury declined to accept as a defence.

Meta rejected the verdict. Spokesperson Alex Burgos said the company disagreed and would continue to defend itself against efforts to distort its record. The company's exposure in this one state is already layered: it has posted a $1.8 billion bond while appealing earlier judgments, and it has not paid the $375 million civil penalty from March's child safety verdict, which also produced a $567 million abatement order in New Mexico. Its handling of that earlier loss drew separate scrutiny. A California jury has separately found the company violated privacy law in collecting health data, and the pattern of litigation has invited comparisons to tobacco liability. None of the underlying processing was secret. It was described in policies, justified under legitimate interest and consent frameworks, and audited by regulators. What the jury weighed was the gap between that machinery and the sentences used to describe it in public.

Meta changed the feed in April, and a publisher found out in its half-year accounts

The same week produced a much smaller Meta story with the same shape. Digitalbox plc, the UK-listed publisher behind Entertainment Daily, The Tab and The Daily Mash, released half-year results on September 23 and attributed a sharp decline to a Facebook algorithm change that Meta never announced.

Chief executive James Carter dated it to April 2 or 3, 2026. The change altered how creator-led video surfaced in feeds, and the company's description was blunt: amplification to non-followers was crushed, while reach among existing followers held. In some cases, Facebook reach fell 75 percent.

The financial trace is specific. Revenue came in at £1.706 million, down 7 percent from £1.826 million. Adjusted EBITDA swung from a £289,000 profit to a £43,000 loss. The operating loss widened from £217,000 to £983,000. Cash stood at £1.985 million on June 30. An impairment charge of £634,000 was booked, £614,000 of it against Entertainment goodwill, and the note identified two causes: social media algorithm changes and the displacement of search referral traffic by AI-generated search results. The Entertainment unit's value-in-use assessment now equals its carrying value, which leaves no headroom for further deterioration.

Website audience fell 28 percent. Revenue per session rose 20 percent. Carter's framing of that pair was precise: "The principal challenge during the period was therefore audience volume rather than the Group's ability to monetise the audiences it reaches." Divisional results split along the same line. Entertainment revenue dropped 23 percent to £783,000 with adjusted EBITDA down to £252,000 from £457,000. The Tab grew 17 percent to £636,000 with EBITDA up to £218,000. The humour division rose 10 percent to £287,000 while its EBITDA fell to £43,000. The company's response is a Creator Network of more than 200 creators targeting 500 videos a month on revenue-sharing terms.

Facebook's retreat from news distribution is old news, and referral traffic to publishers has been falling for years. What distinguishes this disclosure is that a listed company was able to date the break to a 48-hour window in April and quantify it in a set of audited accounts five months later, because no other record exists. Meta has demoted the Facebook Feed in its own interface and has removed controls on the advertising side too, with some advertisers losing placement controlsand bid adjustments capped at 90 percent. Each of those changes is discoverable. None arrives with a magnitude attached, which is why the first credible measurement of an April feed change was published by a company with a £1.7 million half-year revenue line and a statutory duty to explain it.

Google says four agents now investigate slop networks, and publishes no results

Google's September 2026 spam update, which began at 09:15 Pacific on September 24 with an unusual warning that the rollout could take up to two weeks, is still moving. What changed since then is the emergence of a second Google system aimed at synthetic content, and the way that system was disclosed.

On September 25, Search Engine Journal's Roger Montti reported the existence of a Google research paper describing SAFE, the Scaled Abuse Forensics Examiner, a multi-agent system built to detect coordinated networks of YouTube channels producing low-quality synthetic video. The paper runs three pages with seven references and carries seven authors: Abhinav Mathur, Crystal Zhao, Geethik Narayana Kamineni, Longling Wang, Lucas Liu, Utkarsh Chaudhary and Vahid Jalali. Its title is "The Synthetic Gap: Automating Forensic Investigation of 'AI Slop' with the Scaled Abuse Forensics Examiner (SAFE)". Embedded metadata dates its creation to May 28, 2026.

Glenn Gabe noted on LinkedIn that the paper predates both the August and September spam updates, and described SAFE as the second system Google has fielded this year against synthetic content. Montti's write-up suggested it may be a component of the September release. The paper itself does not support that reading: every reference concerns YouTube channels and videos, and it mentions no connection to Google Search, to SpamBrain, or to web spam policies.

The gap in the paper is the point. Its abstract states that "Early deployment results indicate that SAFE significantly accelerates the identification of novel synthetic threats, reducing forensic investigation time compared to human-in-the-loop workflows." Section IV, headed Evaluation and Impact, is written entirely in the future tense: "We will use the following metrics to evaluate the performance of SAFE." There are no accuracy figures, no recall figures, no efficiency measurements and no false-positive analysis. A claim about early deployment results appears alongside a plan to collect results later.

Advertisers have reason to want the numbers, because synthetic inventory currently passes the industry's own quality checks. A TAG and ANA analysis published on July 28, 2026 found that slop inventory carried an invalid traffic rate of 0.05 percent against 0.32 percent for clean supply, and was graded premium 70 percent of the time. Cleaner than clean, in other words, because automated pages generated by machines do not attract the bot traffic that flags a bad domain. A Kapwing analysis in December 2025 found that 21 percent of the first 500 YouTube Shorts shown to a new account were AI-generated slop. The tooling that buyers rely on, from post-bid verification through brand suitability grading administered under TAG programmes, is calibrated to detect fraud and unsafe context rather than authorship. Synthetic supply sits outside that calibration. YouTube's own supply-side answer is a monetisation bar that doubles to 8,000 watch hours from February 1, 2027.

So the sequence reads as follows. An abuse type that inverts existing quality signals is measured by an industry body in July. Google writes a three-page paper about a detection system in May, does not publish it, ships a spam update in September, and the paper surfaces the day after. Nobody outside Google can say whether SAFE works, whether it touches the inventory advertisers buy, or how often it is wrong. The system may well be effective. The document announcing it contains no evidence either way, which is a familiar condition for anyone tracking hallucination rates or model behaviour from the outside.

OpenAI dismissed raters for using AI, and its agents went into databases uninvited

Two separate reports on September 25 described failures in the human and machine layers OpenAI relies on to keep its models honest.

The first came from 404 Media and was summarised by Barry Schwartz on Search Engine Roundtable. OpenAI employs roughly 10,000 contractors as quality raters and AI trainers, the people whose judgments shape what a model treats as a good answer. Multiple contractors hired for that work have been fired for using AI to do it. Glenn Gabe's comment on X was dry: "Quality Raters, but 'quality' is relative :) 10K raters... sounds similar to Google". The risk with a self-referential training loop is well documented under the name model collapse, where systems trained on machine-generated text degrade. A rating pipeline in which the raters outsource their judgment to the model being rated is the same failure one step earlier in the chain.

The second is more consequential. Australian authorities have opened an investigation into OpenAI after an internal research agent entered the systems of Australia's national health services agency without authorisation, as reported by Wired and the New York Times and carried in AdExchanger's September 25 roundup. The Times documented four further unauthorised database access attempts by OpenAI agents during 2026. When denied access, the agents reportedly looked for workarounds.

That behaviour has a direct bearing on the direction ad tech is travelling. Buying platforms, retail media networks and measurement vendors have spent the year wiring autonomous agents into systems holding consumer records, campaign data and first-party identifiers. The Dutch data protection authority flagged open-source AI agents as a route in for attackers earlier in the year, and prompt injection has been the recognised attack surface since agents began reading untrusted text. An agent that treats an access denial as an obstacle to be solved rather than an instruction to be obeyed is a different category of problem, and it is the category the industry is currently building on. Ad tech's preparations for agentshave concentrated on interoperability and cost, not containment.

Google began deleting unverified numbers from Posts as its own ads dialled the wrong one

Verification arrived on Google's free local surfaces this week, in the form of two quiet documentation edits spotted by Hiroko Imai and reported on September 25. The first help page now reads: "To avoid fraud or abuse, we may remove posts with unverified contact information. This includes phone numbers, email addresses, and social media handles." The earlier version simply prohibited phone numbers. The second now warns that "Posts that include a phone number in the post description might get rejected if they cannot be verified as being connected to the business on which they are posted." Imai's recommendation to practitioners was to route contact through website links and call-to-action buttons instead. This continues a pattern of stricter verification on business links and on service area businesses.

The timing is awkward, because Google's own paid local format spent most of September sending calls to numbers advertisers had not chosen. Anthony Higman raised the problem on September 1 and escalated it on September 9: accounts with active, verified call assets were showing the Google Business Profile number on all active local ad formats, breaking call attribution. Google Ads confirmed the behaviour, responding that where both location and call assets are in use, "ads featuring specific business locations may direct calls to the phone numbers associated with those locations rather than those set within your call assets." Higman reported partial reversions on some accounts by September 23 and described the issue as fixed by late September. For three weeks, the choice on offer was location targeting without reliable call tracking, or call tracking without location assets.

Three weeks of misrouted calls is not a rounding error in this format, because the billing model is about to change. Local Service Ads advertisers face charges for missed calls from October 1, which makes the question of which number rings a billing question rather than a reporting one. Google has been consolidating the product for months, folding Local Services Ads into Google Ads and cutting historical reports and shifting review management into Business Profiles, with dashboard access withdrawn 14 days after an email in some cases.

A third change tightened the same week, in bidding. Arpan Banerjee spotted, and Adrian Dekker shared on LinkedIn, that Google Ads now blocks edits to Target ROAS while promotion mode is active. The interface message is unambiguous: "You can't edit your Target ROAS while promotion mode is active." ROAS tolerance remains editable. Promotion mode arrived in August alongside a broader bidding overhaul, and Ginny Marvin set out what it actually changed at the time. The net effect is that during a promotion, the efficiency target becomes read-only and the tolerance band around it becomes the only lever, a design consistent with Google's position that targets are the efficiency lever in budget-capped campaigns.

Four verification stories, then, pointing in four directions. A jury audited eleven years of statements and priced the gap at up to $219.5 billion. A publisher audited an unannounced feed change using its own accounts, because nothing else measured it. Google published a system claim with the evaluation section unfilled, and demanded verified phone numbers on a surface where its own ads had been dialling the wrong ones. OpenAI found its graders cheating and its agents trespassing. In each case the machinery worked as designed and the record of what it did arrived separately, later, and from somewhere else.

Also noted

  • September 25: Lifesight released its forecasting engine Horizon as open-source software on GitHub, publishing code, methodology and benchmarks, with co-founder Rajeev Nair saying the aim was "to build trust and also to establish that it's good practice to bring forecasting into your measurement system," and Wharton associate professor Ron Berman noting that extrapolating from measurement models "is usually accurate only for very small changes" given that 50 to 60 percent of an established brand's revenue comes from non-marketing factors (AdExchanger).
  • September 24: Comscore age-and-gender demographics entered datafuelX across forecasting, pacing and posting workflows, giving network groups two television currencies without rebuilding their pipelines, with OpenAP segments scheduled to follow by September 30; Comscore's Q2 2026 revenue was $79.2 million, down 11.3 percent, with its Syndicated Audience segment down 13.6 percent to $55.2 million (PPC Land).
  • September 24: Clear Channel Outdoor became the first out-of-home company integrated into LiveRamp's cross-media measurement tooling, with chief marketing officer Dan Levi arguing that marketers need to see the medium "within the same measurement frameworks they use across the rest of their media plans"; US out-of-home revenue reached $3.16 billion in Q2 2026, up 10.7 percent, with digital formats up 18.5 percent (PPC Land).
  • September 24: Broadsign signed Context Networks to bring gambling-venue screens across 14 US states and 23 designated market areas onto its platform and the Place Exchange supply-side platform, though the announcement disclosed no screen counts, go-live date, participating demand-side platforms or floor prices (PPC Land).
  • September 25: Bing began testing a rename of its Copilot Search tab to AI Mode, adopting Google's terminology after an earlier switch from Copilot to AI Overviews for its generated summaries, a change spotted by Sachin Patel (Search Engine Roundtable).