Blog Image
Security

Big Tech Scam Ads: Should They Do More? UK

August 22, 2026 12:00 AM
5 min read
0 views
Key Statistics: Ofcom draft Fraudulent Advertising Code published 10 July 2026: nearly 40 measures proposed. Consultation period: closes 2 October 2026. Final rules: expected mid-2027 at the latest. More than half of UK adults have encountered potentially fraudulent ads online; over a third see them ‘often’ (Ofcom, July 2026). Potential fines: up to £18 million or 10% of global annual revenue, whichever is greater. Category 1 platforms affected: Instagram, X, Google, YouTube, ChatGPT and others with 34m+ UK users or 7m+ with content recommender systems. Fraud is the UK’s most commonly experienced crime (National Crime Agency). Martin Lewis sued Facebook in 2018 over scam ads — the first high-profile campaign action. Which? successfully campaigned to have paid-for scam ads included in the Online Safety Act (2022–2023). Fake AI-generated images of Nigel Farage on X used in fraudulent ads (June 2026). Criminals exploit AI to generate convincing scam ads at scale.

Table of Contents

  • A Wild West That Has Lasted Too Long
  • The Scale of the Problem: How Bad Is It?
  • What Ofcom Has Actually Proposed
  • Which Platforms Are in Scope?
  • The Timeline: Why Has It Taken This Long?
  • Martin Lewis: ‘Far Too Late — And the Jury Is Out on Whether It’s Too Little’
  • The Case FOR Forcing Big Tech to Do More
  • The Case for Caution: What Critics of Heavy Regulation Argue
  • What Should They Actually Be Required to Do? A Practical Analysis
  • The AI Dimension: How Artificial Intelligence Is Making Scam Ads Worse
  • What the Platforms Say
  • What Victims Have Lost
  • What YOU Can Do Right Now: How to Spot and Report Scam Ads
  • Should They Do More? Our Analysis
  • Conclusion: Good First Step. Not the Last.
  • Frequently Asked Questions

A Wild West That Has Lasted Too Long

For years, Britain’s online advertising landscape has operated without adequate consumer protection. Criminals have paid to advertise fake investment schemes, bogus cryptocurrency platforms, cloned bank websites, and fraudulent celebrity endorsements across the UK’s most-used digital platforms — Facebook, Instagram, Google, YouTube, X and others — while those platforms collected the advertising revenue with minimal scrutiny of who was placing the ads or what they were selling.

The result has been devastating for thousands of ordinary people who clicked on what appeared to be a legitimate advert from a trusted company, handed over their savings, and discovered too late that the advert was fraudulent and the money was gone. Fraud is the UK’s most commonly experienced crime. A significant proportion of it begins online, with a paid advertisement.

On 10 July 2026, Ofcom — the UK’s communications regulator — published its draft Fraudulent Advertising Code, proposing nearly 40 measures that would, for the first time, legally require big tech platforms to tackle the scam ads that appear on their services. The response from consumer advocates was immediate: about time — but is it enough?

Breaking: Ofcom published its draft Fraudulent Advertising Code on 10 July 2026 — proposing nearly 40 measures requiring big tech platforms to tackle scam ads for the first time. Public consultation closes 2 October 2026. Final rules expected mid-2027. This article is current to August 2026.

The Scale of the Problem: How Bad Is It?

The scale of scam advertising in the UK is not marginal. It is pervasive. Ofcom’s own research published alongside the July 2026 consultation found that more than half of UK adults have encountered potentially fraudulent ads online, with over a third saying they see them often. This is not a problem affecting a small, vulnerable minority. It is affecting the majority of the British population on a near-daily basis.

The types of scam ads that circulate on major platforms include:

• Investment fraud: fake advertisements promoting guaranteed-return investment schemes, often using AI-generated images of celebrity endorsers such as Martin Lewis, Elon Musk, or Deborah Meaden, presenting them as having personally endorsed a particular scheme. The advertisements typically link to convincing fake websites that collect personal and banking details.
  • Brand cloning: criminals impersonate legitimate, well-known businesses. Fake adverts appearing to be from Lloyds Bank, Aviva, Hargreaves Lansdown, and HSBC have been documented, directing victims to cloned websites that steal login credentials or payment details. The legitimate firms whose names are abused have no relationship with the ad and no way to stop it.
  • Fake product adverts: advertisements for products that either do not exist, do not match their description, or are shipped in a degraded or counterfeit form. Portable air conditioning units, dietary supplements, and electronics have been among the most commonly flagged categories.
  • AI-generated deepfake political endorsements: in June 2026, the UK advertising watchdog raised concerns about adverts on X using fake AI-generated images of Reform leader Nigel Farage appearing to fight Bank of England governor Andrew Bailey. While this specific example was politically rather than financially motivated, it illustrates the new dimension AI is adding to scam content.
Ofcom Director Oliver Griffiths, July 10, 2026: For too long, victims have been exposed to scam ads online with tech giants simply not doing enough to combat the fraudsters using their platforms. Today we’ve set out nearly 40 practical, protective measures for companies to adopt. We expect firms to take robust action to stamp out scam ads and boot out the bad actors behind them to safeguard their users.

What Ofcom Has Actually Proposed

Ofcom’s draft Fraudulent Advertising Code is built on nearly 40 specific measures. The headline proposals are:
  • Ban and block repeat offenders: platforms must ban accounts that post scam ads and actively prevent those same individuals from creating new accounts under different identities. This directly addresses the current reality in which banned fraudsters simply open a new account and resume advertising.
  • Intercept impersonators: platforms must implement systems to identify and prevent accounts that are impersonating legitimate businesses. Brand cloning — the fraudulent use of a real company’s name, logo, and visual identity — should be caught before the ad is approved and published.
  • Pre-publication verification for financial advertisers: advertisers offering financial products or services (investments, loans, insurance, pensions) must be verified as authorised by the Financial Conduct Authority (FCA) before their ads can be published. This closes the gap that currently allows criminals to advertise financial products without any check on their regulatory status.
  • Step up security safeguards against AI exploitation: platforms must develop and implement specific measures to detect and prevent AI-generated fraudulent content in advertising. As the technology for creating convincing synthetic videos, images, and audio of celebrities and public figures becomes cheaper and more accessible, the risks of AI-powered scam ads are increasing rapidly.
  • Real-time monitoring and rapid removal: once a scam ad is identified — whether by automated detection, user reports, or regulator notification — it must be removed rapidly. The current gap between identification and removal allows scam ads to run for days or weeks after they have been reported.
image_png_1787414218.png
image_png_1787414310.png

Which Platforms Are in Scope?

The Online Safety Act creates three categories of regulated services, with different duties applying to each. The scam ad proposals in Ofcom’s July 2026 code primarily target what the Act calls ‘Category 1’ services — the largest and most widely used platforms.

Category 1 services are defined as user-to-user platforms that either have 34 million or more UK users and a content recommender system, or have 7 million or more UK users, a content recommender system, and the ability to facilitate direct messaging. In practice, this captures:
  • Instagram (Meta)
  • Facebook (Meta)
  • X (formerly Twitter)
  • YouTube (Google / Alphabet)
  • Google Search
  • ChatGPT (OpenAI) — newly added to the scope
  • TikTok
  • Snapchat
Smaller platforms face less comprehensive but still meaningful duties. The inclusion of ChatGPT in the Category 1 scope is notable: it reflects Ofcom’s recognition that AI-powered conversational tools are increasingly being used as a vector for presenting fraudulent financial advice and product recommendations.

The Timeline: Why Has It Taken This Long?

The frustration of consumer advocates with the pace of this regulation is well-founded and documented. The timeline illustrates how long this specific problem has been known and how slowly the regulatory response has developed:
image_png_1787414354.png

The gap between the Online Safety Act passing in 2023 and the rules becoming legally binding in mid-2027 is nearly four years. Four years in which scam ads have continued to run legally and without any specific mandatory compliance requirement for the platforms hosting them.

Martin Lewis: ‘Far Too Late — And the Jury Is Out on Whether It’s Too Little’

MoneySavingExpert’s Martin Lewis is the UK’s most prominent individual voice on financial scam advertising. His response to the July 2026 consultation was characteristically direct:

Martin Lewis, MoneySavingExpert (July 2026): It is definitely far too late, and the jury is out on whether it’s too little. For too long advertising online has been a Wild West. The only way for people to be safe right now is to assume every ad is a scam unless you can manifestly prove otherwise. It’s a terrible state of affairs. The criminals behind scams can act with impunity. Big tech turns a blind eye as it seemingly makes billions from those scammers, carefree about the financial lives they destroy and the serious consequences for people’s mental health.

Lewis’s view is not that the proposals are wrong. His position is that they are overdue by years and that the consultation-and-final-rules process, which will not conclude until mid-2027, allows the status quo to continue for another year while the harms continue to mount. His core argument — shared by Which?, Citizens Advice, and the financial services industry — is that platforms have had both the ability and the financial incentive to do more for years, and have chosen not to.

The Case FOR Forcing Big Tech to Do More

The arguments for compelling big tech platforms to take stronger action on scam ads are numerous and well-supported by evidence:

Revenue Without Responsibility

Online platforms earn substantial advertising revenue from UK users. They have sophisticated technology for targeting advertisements to specific audiences based on browsing behaviour, search history, location, and demographic profile. The same algorithmic sophistication that allows them to target a 65-year-old retirement saver with a pension investment advertisement could, if applied to advertiser verification, be used to identify and block fraudulent financial advertisers before their ads are published. The technical capability exists. The commercial incentive to apply it — absent regulation — does not.

The Profit Motive Problem

Fraudulent advertisers pay the same cost-per-click rates as legitimate advertisers. There is no direct revenue cost to a platform for accepting a fraudulent ad — until the regulatory consequences arrive. Without mandatory requirements and genuine financial penalties, the commercial logic favours accepting advertising revenue and applying minimal verification. The £18 million or 10 percent of global revenue fine structure proposed by Ofcom is specifically designed to create a financial incentive to comply that outweighs the revenue from fraudulent advertisers.

Unique Visibility and Capability

Platforms have unique visibility into advertiser behaviour: account histories, payment methods, IP addresses, behavioural patterns, and the text and imagery of the advertisements themselves. No external party has access to this data. Regulators, banks, and law enforcement cannot monitor platform advertising in real time. Only the platforms themselves can apply the first layer of defence. This unique capability creates a unique responsibility.

The Victim Cost Is Asymmetric

The cost of a scam ad to a victim can be catastrophic — life savings lost, retirement funds depleted, mental health damaged. The cost to the platform of verifying an advertiser is marginal: a regulatory compliance process that is a tiny fraction of the advertising revenue generated. The asymmetry between these costs — catastrophic for victims, marginal for platforms — is the ethical core of the case for mandatory action.

The Case for Caution: What Critics of Heavy Regulation Argue

The opposing view — that the proposed regulation goes too far, is technically difficult to implement, or risks unintended consequences — is also represented in the consultation responses, and deserves honest engagement:

Scale and False Positives

Millions of advertisements are published on major platforms every day. An imperfect verification system that incorrectly flags legitimate advertisers — a small business, a regulated financial firm, or a charity — would create significant harm of its own kind. Legitimate advertisers wrongly blocked face real commercial damage. The argument is not that scam ads should be tolerated, but that any mandatory verification system must be designed carefully to avoid creating a costly false-positive rate at scale.

Regulatory Overreach and Innovation Risk

Some technology industry advocates argue that mandatory pre-publication verification requirements for financial adverts could create barriers to entry for legitimate new financial services firms trying to reach consumers. Over-broad regulation may entrench incumbents and prevent legitimate innovation.

Global Enforcement Challenges

Many fraudulent advertisers are based outside the UK’s jurisdiction. Domestic regulation can require UK-accessible platforms to improve their verification systems, but it cannot prevent criminals in jurisdictions with weaker enforcement from continuing to attempt to place ads. The argument is not that domestic regulation is pointless — it is that it must be part of an international enforcement framework to be fully effective.

What Should They Actually Be Required to Do? A Practical Analysis

Beyond the broad debate, there are specific requirements that consumer advocates, financial industry bodies, and the Ofcom code itself point to as highest priority:
  • Mandatory FCA authorisation check before publishing financial services advertisements: this single measure, applied consistently, would eliminate the largest category of harmful scam ads — investment fraud, pension scams, and loan fraud. Any advertiser promoting a financial product or service must be verified as FCA-authorised before the ad is published, not after it has been reported. This is not technically complex. It requires checking a publicly available FCA register. The resistance to implementing it has been commercial, not technical.
  • Meaningful advertiser identity verification for all paid advertising: at a minimum, every paying advertiser should be able to be identified. The current system allows effectively anonymous advertisers to place ads. Requiring payment from a verified source, with a documented legal identity behind the ad account, is the floor of basic accountability.
  • Public advertiser transparency libraries: the EU’s Digital Services Act requires platforms to maintain public, searchable libraries of all advertisements they have run, including who paid for them. The UK should implement an equivalent requirement. This allows journalists, regulators, and members of the public to scrutinise advertising at scale.
  • Cross-platform sharing of known scammer identities: a scammer banned by Facebook should not be able to immediately open an ad account on Google or YouTube. Platforms should be required to share verified fraud information with each other and with law enforcement, not just maintain individual blacklists.

The AI Dimension: How Artificial Intelligence Is Making Scam Ads Worse

The June 2026 example of AI-generated images of Nigel Farage on X is a preview of what the consumer protection landscape faces over the next few years. AI tools can now generate convincing video of any public figure appearing to endorse any product, in any language, at minimal cost, and at industrial scale. The same tools that Martin Lewis’s image has been abused in for years can now generate a video of him speaking convincingly about an investment scheme, in his own apparent voice, with his own apparent face.

Ofcom’s proposals specifically address AI-generated scam content. But the technology is moving faster than regulatory timelines. By the time the Fraudulent Advertising Code is finalised in mid-2027, the AI tools available to fraudulent advertisers will be significantly more capable than those available today. Platforms need to invest in detection technology continuously rather than treating regulatory compliance as a one-time certification exercise.

The National Economic Crime Centre’s Nick Sharp put the challenge precisely: fraud continues to cause significant harm to individuals and businesses across the UK, with criminals increasingly exploiting online platforms and their advertising infrastructure to reach victims.

What the Platforms Say

Major platforms have not publicly opposed the Ofcom proposals, though their formal responses to the consultation will be published after the 2 October 2026 closing date. The public posture of platforms in these situations is typically to express support for the principle of consumer protection while raising questions about the specific implementation requirements during consultation.

Meta has previously pointed to its investment in AI-powered ad review systems and its enforcement statistics (millions of ads removed for policy violations each quarter). Google has similarly pointed to its Financial Products and Services policies, which require advertisers of certain financial products to be certified. The consumer advocates’ counterargument — supported by the continued prevalence of scam ads on these platforms despite existing policies — is that voluntary measures are insufficient and that self-reported enforcement statistics do not capture the full volume of fraudulent content that continues to run.

What Victims Have Lost

Behind the regulatory debate are real people who have suffered real financial harm. The stories documented by Citizens Advice, Which?, and the Financial Ombudsman Service are consistent: a retired teacher who transferred her pension pot to a fake investment scheme she found through a Facebook ad; a 50-year-old who lost his redundancy payment to a cryptocurrency scheme promoted by what appeared to be a celebrity-endorsed Google advertisement; a small business owner who paid an upfront fee to a loan broker advertised on Instagram and received nothing in return.

The financial losses are significant. But the documented harm extends beyond money. Research cited in Parliamentary debates on the Online Safety Act consistently found that investment fraud victims describe long-term mental health impacts — depression, anxiety, shame, and relationship breakdown — that persist long after the financial loss itself. Martin Lewis’s observation that the consequences extend to ‘the serious consequences for people’s mental health’ reflects documented evidence, not rhetorical flourish.

What YOU Can Do Right Now: How to Spot and Report Scam Ads

While regulation catches up, here is practical guidance for protecting yourself:
  • Assume all unsolicited financial advertisements are suspect: as Martin Lewis put it, the only way for people to be safe right now is to assume every ad is a scam unless you can manifestly prove otherwise. If you see an investment or financial product advertised online, do not click the ad. Go directly to the company’s official website or the FCA Register.
  • Check the FCA Register before any financial commitment: the FCA Register at register.fca.org.uk lists all firms and individuals authorised to offer financial products in the UK. If a company advertising a financial product is not on the FCA Register, do not engage.
  • Never use contact details from an advertisement: if you want to contact a company you saw advertised, find their contact details independently — through their official website, a phone directory, or a trusted source. Contact details in advertisements may be controlled by fraudsters.
  • Report scam ads to the platform: all major platforms have ad reporting mechanisms. Use them. While the current system is imperfect, reported ads are more likely to be reviewed and removed, and aggregated reports help platforms identify fraud networks.
  • Report to Action Fraud: the UK’s national reporting centre for fraud and cybercrime is Action Fraud (actionfraud.police.uk). Reports contribute to the National Fraud Intelligence Bureau’s intelligence picture and can trigger enforcement action.
  • Report to the ASA: the Advertising Standards Authority (asa.org.uk) investigates misleading advertising and can require ads to be removed. The ASA also flags issues to Ofcom and other regulators.

Should They Do More? Our Analysis

The headline question of this article deserves a direct answer: yes, big tech firms should be required to do more than they are currently doing voluntarily, and yes, the Ofcom proposals are a meaningful step in the right direction even if they do not go as far or as fast as consumer advocates would want.

The case for the platforms doing more is strongest in three specific areas. First, mandatory pre-publication verification of financial advertisers against the FCA Register — a technically trivial but commercially significant requirement that platforms have resisted implementing voluntarily despite years of documented harm. Second, meaningful advertiser identity verification so that there is a documented, traceable human or legal entity behind every paid advertisement. Third, cross-platform information sharing on confirmed fraudulent advertisers, so that a criminal banned from one platform cannot immediately resume operations on another.

The case for caution is strongest around the pace and specificity of implementation, and around the recognition that regulation alone cannot fully solve a problem that has its roots in international criminal networks operating outside UK jurisdiction. The Fraudulent Advertising Code is a necessary but not sufficient condition for protecting UK consumers from scam ads.

What does this mean for the consultation? Respondents who want to see stronger protection should specifically advocate for the FCA authorisation check before publication, mandatory advertiser identity verification, public ad transparency libraries, and a faster implementation timeline — not mid-2027, but now.

Conclusion

Ofcom’s July 2026 Fraudulent Advertising Code is the most significant regulatory step toward protecting UK consumers from online scam advertising since the Online Safety Act was passed in 2023. Nearly 40 proposed measures, applied to the UK’s largest and most-used platforms, with fines of up to 10 percent of global revenue for non-compliance, represent a substantive change from the current voluntary, self-regulated status quo.

But the process is not finished. The consultation does not close until October 2026. The final rules will not be in force until mid-2027 at the earliest. More than half of UK adults are encountering potentially fraudulent ads right now, today, while the consultation proceeds. Martin Lewis is right that this is too late. The question of whether it is too little depends on what the final code requires and how rigorously Ofcom enforces it.

The platforms that are in scope of these proposals have had the technical capability to implement most of the proposed measures for years. The draft Fraudulent Advertising Code is not asking them to do something impossible. It is asking them to do something commercially inconvenient: to apply to advertiser verification the same resources and sophistication they apply to advertiser targeting. They can do it. The law will now require them to. The question is how much stronger the final code will be, and whether it will be enough.

Frequently Asked Questions

What has Ofcom proposed about scam ads?

On 10 July 2026, Ofcom published its draft Fraudulent Advertising Code proposing nearly 40 measures requiring big tech platforms to tackle fraudulent advertisements. Key proposals include: banning and blocking scammers who attempt to re-register; intercepting impersonators who clone legitimate brands; requiring FCA authorisation checks before financial services ads are published; implementing AI deepfake detection; and ensuring rapid removal of identified scam ads. The consultation closes 2 October 2026 and final rules are expected mid-2027.

Which platforms are affected by the new rules?

The most stringent requirements apply to Category 1 platforms under the Online Safety Act: those with 34 million or more UK users with a content recommender system, or 7 million or more UK users with recommender systems and direct messaging. In practice, this includes Instagram, Facebook, X (Twitter), YouTube, Google Search, ChatGPT (OpenAI), TikTok, and Snapchat. Smaller platforms face less comprehensive but still meaningful duties.

What fines can platforms face for non-compliance?

Once the Fraudulent Advertising Code becomes legally binding (expected mid-2027), platforms that fail to comply face fines of up to £18 million or 10 percent of their global annual revenue, whichever is greater. For major platforms, 10 percent of global revenue represents a very large potential penalty — for Meta, with 2025 global revenue of approximately $165 billion, 10 percent would be approximately $16.5 billion.

Why has it taken so long for these rules to come in?

The Online Safety Act passed in October 2023, but the specific provisions relating to paid-for scam ads require Ofcom to develop and consult on a Fraudulent Advertising Code before they become enforceable. This process has taken from 2023 to 2026 for the consultation to be published, with final rules not expected until mid-2027 — nearly four years after the Act passed. Which? and Martin Lewis have both criticised this pace as too slow given the scale of harm occurring in the meantime.

What should I do if I see a scam ad online?

Report it to the platform immediately using the ad’s reporting mechanism (usually accessible via the three dots or options icon on an advertisement). Report financial scams to Action Fraud at actionfraud.police.uk. Report misleading advertising to the Advertising Standards Authority at asa.org.uk. Check any financial firm you see advertised against the FCA Register at register.fca.org.uk before engaging. Never click an ad to access a company’s contact details — find them independently through official channels.

Should big tech be doing more than the current proposals require?

Consumer advocates, including Martin Lewis and Which?, argue yes. The most widely supported additional measures include: mandatory FCA authorisation verification before any financial services advertisement is published (closing the gap that allows unregulated firms to advertise freely); mandatory advertiser identity verification (so every paid ad has a documented legal identity behind it); public advertiser transparency libraries (searchable databases of all platform advertising); and cross-platform data sharing on confirmed fraudulent advertisers. These measures are technically feasible and have been implemented in some form voluntarily by some platforms. Making them mandatory and universal is the next step.

How are AI tools making scam ads worse?

Artificial intelligence tools can now generate convincing synthetic video and audio of any public figure appearing to endorse any product — at minimal cost and at scale. Fake celebrity endorsement videos of Martin Lewis, Elon Musk, and others have been used in investment fraud ads. In June 2026, AI-generated images of public figures were used in fraudulent ads on X. As AI tools become cheaper and more capable, the volume and sophistication of AI-powered scam content will increase. Ofcom’s proposals specifically require platforms to detect and prevent AI-generated fraudulent advertising, but regulation will need to keep pace with rapidly advancing technology.
Topics Security
user's profile

Ernest Robinson

Expert Author

Some text here...

2490 Articles
3K Readers
3.7 Rating

0 Comments Comments

Leave a Reply

;