Ofcom opened a consultation on 10 July 2026 setting out nearly 40 draft measures that would require the UK's largest social media and search platforms to police the paid-for advertising they carry, marking the first time regulated services would face binding duties to tackle fraudulent adverts under the Online Safety Act 2023.

The draft Fraudulent Advertising Codes of Practice apply to services designated as Category 1 or Category 2A on Ofcom's 2026 register of categorised services. The proposals cover paid-for advertising content only, and explicitly exclude user-generated content and non-sponsored search results. Feedback is open until 2 October 2026, and Ofcom plans to publish its final statement by mid-2027 at the latest.

The regulator framed the intervention around the scale of the harm. More than £40 billion a year is spent on digital advertising across the UK, according to Ofcom, making up the majority of the revenue earned by the platforms selling the ads. Against that backdrop, an estimated total of more than £200 million is lost by victims to these kinds of scams in the UK on average each year, a figure drawn from Ofcom's economic analysis annex published alongside the consultation.

What the draft code would require

The consultation sets out a layered package of measures grouped across governance, fraud assessment, account integrity, moderation, and complaints. Rather than relying on a single control point, Ofcom placed significant weight on account-level interventions intended to stop fraudsters advertising from the outset, then added moderation and reporting duties to catch fraudulent adverts that get through.

At the centre of the account-integrity proposals is an advertising ban duty. Under measure H5, providers should ban advertising account holders that post fraudulent advertisements or fraudulent advertising proxy, and take reasonable steps to prevent them from returning to the service. The proposed remedy is specific: removal of the advert and a ban on the account holder advertising to UK users.

Providers would also need an account checks and actions policy under measure H1, applied consistently and reviewed at least every 12 months. That policy should verify that account holders work for, or on behalf of, the individual or organisation they claim to represent, carry out checks to stop banned advertisers returning under new identities, and identify accounts carrying a material risk of posting fraudulent adverts so restrictions can be applied. Providers would be required to publish a summary of the policy.

A separate strand targets financial promotions. Measure H2 would require a financial services verification policy setting out which financial services advertising is permitted, how the provider identifies financial adverts and those posting them, and how it verifies that individuals and firms hold the appropriate legal permissions before their adverts can be encountered by UK users. In the UK, financial services advertising targeting UK consumers can only be issued or approved by individuals or firms authorised by the Financial Conduct Authority, unless an exemption applies. That regulatory anchor connects the draft code to a verification model already operating in the commercial market. Google expanded its own mandatory financial services advertiser verification to 24 additional European Union and European Economic Area countries in June 2026, bringing the total under that program to 42, with the United Kingdom having run a dedicated verification framework tied to the FCA since 2021.

Account takeover and appeals

The draft code treats hijacked accounts as a distinct vector. Fraudsters take over legitimate advertising accounts and use them to post fraudulent adverts, so measure H3 would require an account security mechanism on all advertising accounts, and measure H4 would require an account takeover reporting mechanism that is easy to find, access and use.

The consultation's supporting materials map the process in detail. Where an account holder reports a compromise, the provider reviews the report and decides whether a takeover occurred. If confirmed, the provider assesses whether the account is likely to be used to post further fraudulent adverts or poses an ongoing risk. Where that risk is judged likely, restoration may not be appropriate and the advertising ban would remain in place unless the risks are mitigated. Where it is not likely, the provider should restore access to the authorised holder and remove the ban so the account can again post adverts to UK users.

Balancing the enforcement measures, the draft code builds in appeal routes. Account holders could appeal decisions arising from a failed account check, a failed financial services check, or the placement of an advertising ban. A distinct advertising appeal covers the narrower question of whether a specific advert was fraudulent. Providers would be required to determine appeals promptly and, where an appeal is upheld, reverse the action taken so far as possible to restore the account holder or the advert to the position it would have held had the decision not been made. Ofcom characterised the availability of appeals as an important safeguard for freedom of expression and privacy, providing a means to correct erroneous moderation judgements against legitimate adverts and account holders.

Moderation, testing and ad libraries

On the detection side, measures under section C would require providers to operate advertising moderation systems designed to review and assess adverts they have reason to suspect are fraudulent, and to take them down swiftly once aware. The draft distinguishes the two categories of service: for Category 1 user-to-user services, moderation means removing the advert; for Category 2A search services, it means ensuring individuals can no longer encounter the advert in or via search results. Providers would also have to set internal advertising policies, set performance targets, apply a prioritisation policy, resource the function, and train the staff who carry out moderation.

The consultation addresses the growing role of generative tools directly. Where a provider makes an advertisement generation tool available to account holders, capable of creating text, image, audio or video adverts, measure F1 would require the provider to test the tool to identify whether and how it could be used to create fraudulent adverts. Ofcom noted that fraudsters exploit new technology such as artificial intelligence, take advantage of social trends, and use the credibility of public figures and trusted brands to deceive users, listing the impersonation of public figures and brands, cloaked landing pages, unusual URLs, and the use of generative AI and deepfakes among the risky characteristics providers should learn to recognise.

A further transparency measure would require providers that display adverts capable of being encountered by UK users to set up a publicly available ad library containing all such adverts while live and for a year after they were last live. The proposed library would need to update at least daily, offer multi-criteria search including by keyword, exact phrase and specific advertising account, and expose an API. Required fields include the advertising account name, advertiser name, advert content, target audience by demographic, target or actual reach, and previous account names. The stated purpose is to help expert organisations detect and report suspected fraudulent adverts quickly. Transparency repositories of this kind are already established across parts of the market, with Google, Meta and Amazon operating public ad libraries that researchers and journalists use to scrutinise advertising practices.

Governance and the intermediaries question

The draft code also reaches into corporate structure. Governance measures would require the most senior governance body to carry out an annual review of compliance, name an individual accountable for the fraudulent advertising duties, hold written statements of responsibilities for relevant senior managers, and run an internal monitoring and assurance function. Providers would additionally carry out a fraud indicator assessment under measure B1, reviewed at least every 12 months or whenever the provider makes a significant change to its paid-for advertising, to identify the characteristics that signal a material risk of fraud.

One structural complication runs through the proposals. The pathway a provider uses to place adverts, whether an owned-and-operated supply chain often described as a walled garden, or the open-display market served by advertising intermediaries, affects how much control it has over placement. Ofcom acknowledged that providers using intermediaries in an open-display supply chain may in some circumstances have insufficient control to apply a given measure. Its proposed answer, an advertising intermediaries measure numbered K1, would require any provider that cannot fully implement a measure because of limited control to use all reasonable endeavours to implement a version as similar as possible. Ofcom was firm on the principle: the pathway a provider uses should not result in different safety outcomes for users.

Why this matters for the advertising market

For the platforms in scope, the proposals convert a reputational problem into a prospective legal obligation. Ofcom set out that once its codes are approved by Parliament and come into effect, companies that fall short could be subject to enforcement action, including fines of up to £18 million or 10% of global revenue, whichever is greater. Those figures are not new to the Online Safety Act regime, and the same maximum penalties feature in Ofcom's existing enforcement actions against services under the Act. The distinction the consultation introduces is subject matter: for the first time, paid-for advertising itself would fall within the enforceable duties, not only the organic content platforms host.

The commercial context helps explain the regulator's focus. Platform monetisation of fraudulent advertising has drawn sustained scrutiny, with internal Meta documents reviewed by Reuters indicating the company projected roughly 10% of its 2024 revenue would come from adverts for scams and banned goods, and estimating that its platforms showed users around 15 billion higher-risk scam adverts a day. Separate industry analysis has quantified the exposure inside specific verticals, with banking adverts identified as a high-value, high-trust category that attracts bad actors from several directions at once. Impersonation of well-known brands to target marketers has itself become a recurring pattern, including a phishing operation that used OpenAI's name to solicit fake advertising beta testers in early 2026.

For advertisers, the verification and account-check measures raise the compliance floor. A financial services firm advertising on a search or social platform in the UK would need to satisfy an FCA-linked permission check before its adverts can run, formalising at the platform level a requirement that already governs how such promotions may lawfully be approved. Legitimate advertisers taken down in error would gain a defined appeal route, and the requirement that providers adjust internal policies where there is a pattern of adverts being removed incorrectly points toward fewer blunt automated suspensions over time.

Ofcom's consultation also signals more to come. The regulator said it wants to see proactive technology used to filter out fraudulent adverts at source, and will bring forward a separate consultation on detailed proposals in autumn 2026 alongside a broader package of online safety measures. For an advertising ecosystem where the boundary between a legitimate promotion and a fraudulent one is policed by the same platforms that profit from the traffic, the draft code represents an attempt to move that judgement from a commercial discretion to a regulated duty. Whether the final measures preserve the current scope, and how the intermediaries carve-out is resolved, will shape how heavily the obligations land on the open programmatic market as against the walled gardens.

Timeline

  • 26 October 2023: The Online Safety Act 2023 receives Royal Assent, establishing Ofcom as the online safety regulator and introducing duties on categorised services.
  • 2025: Ofcom research finds 51% of adults who are online have seen a potentially fraudulent advert, with 36% seeing them frequently.
  • 10 July 2026: Ofcom publishes its draft Fraudulent Advertising Codes of Practice, the 2026 register of categorised services, and supporting materials, opening the consultation.
  • 2 October 2026: Consultation closes for stakeholder responses.
  • Autumn 2026: Ofcom plans a separate consultation on proactive technology to filter fraudulent adverts at source.
  • Mid-2027: Ofcom plans to publish its final statement at the latest, with codes taking effect once approved by Parliament.

Summary

Who: Ofcom, the UK online safety regulator, addressing providers of Category 1 and Category 2A services, including major social media and search platforms.

What: A consultation on draft Fraudulent Advertising Codes of Practice setting out nearly 40 proposed measures covering account bans, financial services verification, account takeover reporting, advertising moderation, testing of AI advert-generation tools, ad libraries, and governance duties, with maximum penalties of £18 million or 10% of global revenue once in force.

When: Published 10 July 2026, with the consultation open until 2 October 2026 and a final statement planned by mid-2027 at the latest.

Where: The United Kingdom, applying to paid-for advertising encountered by UK users on categorised services.

Why: Fraud is the UK's most common crime, advertising is the second most common way fraudsters reach victims online, and an estimated £200 million-plus is lost to these scams in the UK each year, yet paid-for advertising had not previously fallen within enforceable duties under the Online Safety Act.