Skip to content

Regulatory Pulse

FTC examines platform ad optimisation in impersonation scams

The FTC is seeking evidence on whether platform ad-optimisation tools amplify impersonation scams and what safeguards or future rules may be appropriate.

United States
Platform governance, online scams, digital advertising and trust and safety
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Advance notice of proposed rulemaking · Reviewed 26 September 2026 · 6 min read

The 60-second summary

On 24 September 2026, the US Federal Trade Commission announced an advance notice of proposed rulemaking (ANPRM) examining whether online platforms' ad-optimisation tools help spread ads that impersonate businesses or government agencies. It requests evidence on platform incentives, tool design, advertiser vetting, monitoring and possible regulatory or non-regulatory measures. This is an initial request for comment, not a proposed final text, new obligation or finding that any platform violated the law. The FTC says comments will be due 60 days after the Federal Register notice is published; a calendar deadline should not be inferred until that publication is confirmed.

Timeline that matters

  1. 24 September 2026

    ANPRM announced

    FTC announced the inquiry and linked the proposed Federal Register text.

  2. Federal Register publication pending confirmation

    Formal notice

    Verify the published notice and docket before calculating the comment deadline.

  3. 60 days after publication

    Comment period

    FTC says comments will be due 60 days after the notice appears in the Federal Register.

  4. 26 September 2026

    Editorial review

    PrivacyBuilt verified the official announcement and ANPRM page.

  5. 26 October 2026

    Next review

    Check the Federal Register publication, closing date and any FTC clarification.

What changed

The FTC began gathering evidence on whether search, social-media and marketplace platforms' ad-optimisation services contribute to impersonation scams and whether the existing Impersonation Rule should be amended, a separate rule proposed, or other measures taken. The agency has not selected a regulatory approach.

Who should pay attention?

Ad platforms and marketplaces

Review advertiser screening, ad delivery, detection and response evidence.

Trust and safety teams

Test impersonation detection, takedown decisions and repeat-offender controls.

Brands and public-facing organisations

Track impersonating ads and escalation routes with platforms.

Privacy and security teams

Coordinate scam response where identity misuse or personal-data exposure is involved.

Policy and legal teams

Assess whether to submit evidence once the formal comment window opens.

What the guidance clarifies

Procedural status
This is an advance notice seeking information. It does not itself amend the Impersonation Rule.
Affected audience
The inquiry focuses on online platforms offering ad placement or optimisation and on the advertisers, trust-and-safety teams and service providers involved in screening and monitoring.
Scope of concern
The FTC asks how tools optimise ad content and delivery, what economic incentives exist, and what current controls prevent deceptive impersonation ads.
Possible measures
The notice asks about advertiser vetting, monitoring, investigation, removal and action against offending advertisers; these are topics for comment, not adopted duties.
Comment timing
The announced period is 60 days after Federal Register publication. The FTC announcement does not provide a fixed closing date.

Ad delivery and advertiser assurance need observable controls

Why this matters for global organisations

Platforms and brands can reduce impersonation risk by joining advertiser verification, scam detection, user reporting, investigation and takedown into a measurable process. Teams should preserve evidence of how ads were approved, distributed and removed.

  • Record who verifies advertisers and what evidence is accepted.
  • Monitor impersonating ads and repeat offenders across channels.
  • Preserve ad, targeting, complaint and takedown records.
  • Review whether optimisation rewards unsafe reach or delays intervention.

13 actions to start now

  1. Identify teams responsible for advertiser verification, ad optimisation, abuse detection and escalation.
  2. Map how ad content, targeting and delivery settings are reviewed before and after launch.
  3. Document identity checks for advertisers claiming to represent a brand or public body.
  4. Test detection of lookalike domains, brand misuse, cloned creative and deceptive landing pages.
  5. Provide accessible reporting routes for affected users and impersonated organisations.
  6. Set triage targets for suspected impersonation ads and track time to removal.
  7. Review whether automated optimisation continues distribution while a credible complaint is pending.
  8. Track linked advertiser accounts and repeated attempts to evade restrictions.
  9. Retain ad creative, targeting criteria, account history, review decisions and takedown timestamps.
  10. Coordinate fraud, security, privacy and legal response where personal information or credentials are exposed.
  11. Assess third-party ad-tech and verification vendor responsibilities.
  12. Verify the Federal Register notice and calculate the comment deadline only from its publication.
  13. Consider a documented comment submission based on operational evidence, if relevant.

Suggested next steps

  • Run a sample impersonation-ad incident from first report through ad pause, investigation, removal, evidence preservation and affected-party communication.

Evidence worth retaining

  • Advertiser verification policy and audit samples.
  • Ad approval and optimisation configuration records.
  • Brand impersonation detection rules and test results.
  • User and brand reports with triage outcomes.
  • Ad creative, landing-page captures and campaign delivery logs.
  • Takedown, appeal and repeat-offender decisions.
  • Fraud and privacy incident assessments.
  • Vendor contracts, service metrics and escalation contacts.
  • Federal Register notice and any comment-submission record.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Can an impersonating advertiser pass the current checks using a lookalike brand or domain?
  • What signals cause an ad campaign to pause automatically?
  • Can investigators reconstruct how an impersonation ad was targeted and amplified?
  • How are legitimate advertisers distinguished from impersonators?
  • Which vendor operates each verification or ad-optimisation control?
  • Could scam reporting reveal credentials or personal data that requires a separate response?
  • What evidence would help the FTC assess a possible rule without overstating current obligations?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.