Ofcom, the UK’s communications regulator, published a draft Fraudulent Advertising Code of Practice on July 10, 2026 as part of the third phase of implementing the country’s Online Safety Act. The draft code, open for public consultation until October 2, 2026, sets out nearly 40 specific practical measures the UK’s largest social media and search platforms would be required to follow to tackle paid-for scam advertising — a response to Ofcom’s own estimate that fraudulent ads cost UK consumers and businesses around £200 million a year.
The code applies to what the Online Safety Act calls Category 1 and Category 2A services — in practice, the platforms with the largest UK user bases and the greatest reach for paid advertising, named explicitly in coverage of the proposal as including Facebook, Instagram, TikTok, YouTube, Pinterest, and Reddit. The proposed obligations go well beyond simply asking platforms to take down reported scam ads faster. They include requirements to actually verify the identity of advertisers before running their ads, to stress-test the platforms’ own AI-based ad-review tools against realistic scam attempts rather than trusting they work as advertised, and to embed anti-fraud accountability at board level rather than treating scam-ad enforcement as a purely operational, lower-level function.
“One Strike and You’re Out” — and No Coming Back Under a New Name
One of the more aggressive measures in the draft is a proposed “one strike and you’re out” standard: an advertiser account caught running a genuinely fraudulent ad would face an outright ban, rather than a warning or temporary suspension. Just as importantly, the draft code also requires platforms to build real mechanisms to stop banned scammers from simply creating a new account and starting over — a well-documented workaround that has undermined softer enforcement approaches in the past. If the code is eventually approved by Parliament and takes effect, non-compliant platforms would face fines of up to £18 million or 10% of their global annual revenue, whichever is greater — a penalty structure clearly designed to be meaningful even against companies the size of Meta or Google. Ofcom has said it aims to publish final decisions on the code by mid-2027, after which it still needs parliamentary approval before the rules actually take legal effect — meaning this remains a proposal working through a genuine regulatory process, not yet an enforceable law. Ofcom has emphasized that the nearly 40 measures in the draft aren’t a menu platforms can pick and choose from selectively — the code is designed as a baseline package, with the regulator explicitly framing scam-ad prevention as a governance failure that boardrooms, not just trust-and-safety teams, need to own.
The Third Act in a Three-Phase Rollout
This fraudulent-advertising code is the latest step in a broader, multi-year rollout of the Online Safety Act, not a standalone rule. Phase 1 — duties requiring platforms to tackle illegal content such as child sexual abuse material, terrorism content, and fraud — came into force on March 17, 2025, following codes of practice Ofcom published that December. Phase 2 followed on July 25, 2025, when child-safety obligations took practical effect, requiring platforms to complete children’s risk assessments and roll out Ofcom’s Protection of Children Codes of Practice. This new fraudulent-advertising code sits within Phase 3, the set of additional duties Ofcom reserves specifically for the UK’s largest and most widely used services — meaning it’s arriving after two earlier phases have already forced major platforms to build real compliance infrastructure for the Online Safety Act, not as regulators’ first real test of whether these companies will actually cooperate.
What This Means for Philippine Founders
Scam advertising isn’t a uniquely British problem — it’s a well-documented, ongoing issue across the platforms Filipino consumers use every day, from fake investment schemes to fraudulent remittance and job-recruitment ads specifically targeting Overseas Filipino Workers and their families. Ofcom’s draft code matters to the Philippines for two concrete reasons. First, it’s a real, detailed regulatory template — advertiser verification, board-level accountability, permanent bans instead of temporary suspensions — that Philippine regulators, from the DTI to the National Telecommunications Commission, could plausibly look to as a model if the country ever moves toward its own binding scam-ad rules, rather than relying purely on platform self-policing. Second, and more immediate: if the UK’s rules do eventually take effect, global platforms like Meta and Google typically build compliance systems designed to satisfy their most demanding regulatory market and then extend meaningful pieces of that same infrastructure globally, since maintaining entirely separate ad-verification systems per country is more expensive than building one strong system and applying it broadly. Filipino consumers could plausibly see real benefits from UK-driven platform changes well before the Philippines writes any equivalent rule of its own — and Philippine fintech and consumer-protection startups building anti-scam or ad-verification tools now have a concrete, credible regulatory framework to point to when making the case that this is a real, fundable problem category, not a hypothetical one.
Share this article