UK Regulator Targets Scam Ads on Major Tech Platforms—But Rules Won't Take Effect Until 2027

Ofcom, the UK's media regulator, opened a consultation on Friday proposing that major platforms — Facebook, Instagram, Snapchat, X, YouTube, Google and ChatGPT among them — be legally required to ban scammers from advertising on their services. The draft rules would also require platforms to block bad actors from creating new accounts after they've been caught, give law enforcement a direct way to flag fraudulent ads, and make it harder for legitimate accounts to be stolen and used for scams The Guardian.
Financial services ads would also need proper legal clearance before running. Oliver Griffiths, who oversees online safety at Ofcom, said the tech companies "had not done enough" to combat fraudsters operating on their platforms The Guardian.
These proposals are made under the Online Safety Act, a law that sets standards for how platforms handle illegal content and user safety. The consultation runs until October 2026. Once the rules are finalized and become legally binding, platforms that don't comply could face fines of up to 10% of their global revenue — a substantial penalty. However, Ofcom won't issue final decisions until 2027, meaning compliance would be required at least a year from now.
That delay has already drawn criticism. Which?, a consumer organization, welcomed the proposals but flagged the wait as a genuine problem. Rocio Concha, the group's head of policy and advocacy, pointed out that artificial intelligence is making scams more sophisticated every month, and a year-plus wait leaves consumers vulnerable to fast-evolving fraud techniques while regulation catches up The Guardian.
The underlying problem is substantial. The Online Safety Act's own impact assessment estimates the annual economic and social cost of online fraud in the UK at £18.9 billion Ofcom. Since March 2025, platforms covered by the law have been required to tackle illegal content — but scam ads still appear regularly on major platforms. Meta, for example, promised to stop illegal financial ads on its UK services, yet a Reuters investigation in March 2026 found such ads running roughly 1,000 times a week Reuters. At the time, Ofcom acknowledged it lacked power over paid scam ads because the relevant legal authority hadn't been activated — a gap Friday's consultation is meant to close.
The broader context here is one of mounting friction between the regulator and major platforms. Meta filed a legal challenge against Ofcom in May 2026 over online safety fees and fines Reuters, a separate dispute running parallel to the scam-ad issue. Ofcom has also called out TikTok and YouTube for lagging on child-safety measures relative to competitors, reporting in May 2026 that both platforms had failed to outline meaningful steps to protect British children from harmful content Reuters. The pattern shows a regulator finding platform behaviour inadequate repeatedly, even before its own enforcement powers are fully switched on.
The artificial intelligence dimension makes Concha's concern worth taking seriously. The Bank of England cautioned the public in June 2026 against AI-generated scams after deepfake videos (videos created with AI to impersonate real people) depicting Nigel Farage in a physical altercation circulated online The Guardian. Financial commentator Martin Lewis has spent years pressing the government to act against ads that misuse his image to lend credibility to fraudulent schemes — a grievance that predates this consultation but that the new proposals directly address.
The scam-ad rules arrive alongside separate draft measures covering journalistic content and harmful material more broadly. Ofcom is proposing protections against arbitrary removal or downranking of news content, requiring platforms to let publishers respond before action is taken. It also wants major platforms to limit user exposure to content involving suicide, self-harm, eating disorders and hate or abuse, and to give users tools — including the ability to block or mute accounts and filter interactions with unverified accounts — to manage their own exposure The Guardian.
The fact that scam-ad, journalism and harmful-content rules are bundled into a single consultation reflects how the Online Safety Act is being built piece by piece rather than switched on all at once. Each strand has its own timeline for enforcement and its own industry objections, which is partly why some observers see the phased approach as slow relative to the speed at which fraud techniques — especially AI-assisted ones — are changing. Whether the eventual fining power actually deters bad behaviour will depend largely on how Ofcom uses it after 2027 decisions are made, and on whether platforms with resources to litigate (as Meta has shown willingness to do) treat compliance as cheaper than contesting it.


