Ofcom mandates AI stress-testing and advertiser verification for UK platforms
Ofcom has released a draft code under the UK Online Safety Act 2023 that mandates major platforms to implement advertiser verification, anti-fraud governance, and rigorous testing of generative AI ad-generation tools. The proposed regulations aim to mitigate the proliferation of AI-driven scam advertisements by holding platforms accountable at the board level.
Key Takeaways
- Category 1 and 2A platforms must implement advertiser verification to confirm legal authorization for financial services promotions.
- Platforms providing AI ad-generation tools are required to conduct product testing to identify and patch fraud-prone vulnerabilities.
- Non-compliance with the final code carries potential fines of up to £18 million or 10% of global annual revenue.
- Proposed governance measures require senior bodies to hold direct oversight of anti-fraud compliance and risk assessments.
Why It Matters
The draft code shifts the regulatory burden from individual consumers to platform operators, effectively treating ad-tech vulnerabilities as systemic risks. By mandating AI stress-testing and advertiser verification, Ofcom is establishing a rigorous compliance framework that will likely force a re-engineering of automated ad pipelines. This moves the industry toward a 'safety-by-design' model where platforms are legally liable for the downstream output of their generative tools. In the broader ecosystem, these rules align with the EU's Digital Services Act, signaling a coordinated European crackdown on programmatic fraud. Watch for the final statement by mid-2027 and the results of a separate autumn consultation on proactive filtering technology.
Additional Context
The draft Fraudulent Advertising Code serves as a primary pillar of Phase 3 in the implementation of the UK Online Safety Act (OSA). According to Ofcom research cited by TechUK in July 2026, roughly 51% of UK adults have encountered potentially fraudulent advertisements, resulting in estimated annual losses of over £200 million. While small-scale illegal content duties affected all platforms starting in early 2025, these new ‘categorized service’ duties specifically target high-reach entities. Category 1 status applies to platforms with either 34 million UK users or 7 million users combined with specific content recommendation and sharing functionalities, according to Ofcom's June 2026 register. Regulators have emphasized that platforms should not wait for the formal 2027 enforcement window to begin improvements. Per the Brussels Signal in July 2026, Ofcom’s online safety group director Oliver Griffiths urged tech giants to act immediately to prevent account hijacking and enhance advertiser verification. The Financial Conduct Authority (FCA) has concurrently expressed support for the measures, noting that tech firms must proactively prevent unlicensed financial promotions rather than relying on reactive takedowns. This regulatory pressure follows a broader trend of holding intermediaries accountable for automated harms. Beyond fraud, the July 2026 proposals include expanded protections for journalistic content and democratic debate. As reported by The Guardian, these rules aim to ensure major social media platforms do not arbitrarily restrict news access and provide publishers with an opportunity to appeal content moderation decisions before they are finalized. This multifaceted approach reflects the UK’s strategy to balance fraud prevention with the protection of high-value speech, creating a complex compliance landscape for any platform with more than 3 million active UK users.
Read full article at mondaq.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source