The most consequential change to US retail advertising over the next eighteen months is unlikely to arrive as a federal rule. Signals point instead to advertiser identity verification becoming a practical precondition for buying paid reach, imposed by the platforms themselves and hardened by a British regulator, well before the Federal Trade Commission finishes the rulemaking it opened on October 1, 2026. Our central expectation is that by June 30, 2027 the FTC proceeding has advanced no further than a notice of proposed rulemaking, with no final rule in force, while verified advertiser status has become a routine gate on the main Meta and Google formats that retail brands and marketplace sellers depend on.
That combination matters because it inverts the usual compliance sequence. Retail advertising teams are accustomed to waiting for a rule, then budgeting for it. The pattern here suggests the operational cost lands first and the rule, if it ever arrives, ratifies a market structure that has already settled.
In short
- The prediction: advertiser identity verification likely becomes a de facto requirement for US retail and marketplace advertisers before any FTC rule takes effect, with the binding deadline set by platform policy and UK regulation rather than by Washington.
- The timeframe: by June 30, 2027 the FTC proceeding likely sits at or before the proposed-rule stage, while verified status is likely a hard gate across higher-risk retail categories on the two largest ad platforms.
- Signal 1: the FTC voted on September 24, 2026 to reopen platform liability for impersonation ads, a theory it formally abandoned in December 2024, publishing an advance notice on October 1 with comments due November 30, 2026.
- Signal 2: Ofcom closed its consultation on draft Fraudulent Advertising Codes of Practice on October 2, 2026, proposing nearly 40 measures including advertiser verification, with penalties reaching 10% of global revenue.
- Signal 3: Meta is targeting 90% of its advertising revenue from verified advertisers by the end of 2026, up from roughly 70%, and Google has said that verification will eventually reach every advertiser.
Why this matters now
Paid discovery is where most online retail demand is manufactured. The FTC’s own notice records that e-commerce accounted for 16.8% of total US retail sales in the first quarter of 2026, worth more than $300bn, and that platforms have become the primary gateway through which consumers find products. Anything that changes who is allowed to buy that reach, and on what terms, is a structural change to retail distribution rather than a compliance footnote.
The fraud numbers behind the current regulatory attention are large enough to sustain political pressure for several years. US consumers reported losing approximately $16bn to fraud in 2025, a 25% increase on 2024, according to the Commission’s data. Imposter fraud remains the single largest reported category, with more than one million reports and nearly $3.5bn in reported losses last year. Nearly 30% of consumers who reported losing money in 2025 said the contact began on a social media platform, accounting for $2.1bn in reported losses.
What makes this cycle different from earlier brand-safety panics is the specific target. Regulators on both sides of the Atlantic have stopped asking platforms to remove bad ads faster and started asking whether the tools that build and target ads are themselves the problem. That shift moves the remedy upstream, from content moderation to account admission, and account admission is a gate that every legitimate retail advertiser also has to pass through.
The commercial consequence is asymmetric. A large retailer with a registered entity, a consistent billing history and a dedicated agency clears verification as a formality. A new marketplace seller, a cross-border drop-shipper or an agency running dozens of client accounts under pooled billing faces a materially different cost, and that is where the competitive effect of this prediction concentrates.
Signal 1: the FTC reopened a theory it had already abandoned
On October 1, 2026 the Commission published an advance notice of proposed rulemaking under 16 CFR Part 461, the existing Rule on Impersonation of Government and Businesses. The notice proposes to examine unfair or deceptive practices by “search engine, social media, and other digital marketplace platforms that further government and business impersonation scams.” Comments are due by November 30, 2026, under Matter No. R207000.
The definition of a covered platform is deliberately broad. The notice describes platforms as public-facing websites or apps on which third parties offer goods, services or opportunities through paid advertisements or other listings, and names Google.com, Facebook.com, Amazon.com, the Apple App Store and LinkedIn.com as examples. That framing reaches retail marketplaces and app stores, not only social feeds and search engines.
The economic argument is the notable part. The Commission frames scam advertising as a negative externality created by ad-optimization tools, writing that platforms “internalize the revenue but externalize the risk.” It cites the suite of automated creative generation, audience targeting and delivery optimization products sold by the major platforms, and argues that the same machinery that makes legitimate advertising effective makes fraudulent advertising effective at the same time.
Crucially, this is a revival. The Commission proposed a means-and-instrumentalities provision in its 2022 notice, modified it in a March 2024 supplemental notice, and then stated in December 2024 that it had decided not to proceed with it, after commenters argued the language was overbroad and procedurally premature. The new notice concedes the point and narrows the theory to ad-optimization practices specifically, which is a tacit admission that the earlier attempt failed on scope.
The remedy menu the Commission is testing reads like an operations specification rather than a legal standard. It asks whether platforms should be required to verify advertiser identity before providing optimization tools, whether they should screen and monitor for impersonation ads, and whether complaints should trigger a duty to investigate and a clock to take confirmed ads down. It also asks who should be able to trigger that duty, explicitly including complaints “from those being impersonated,” which would hand impersonated brands a standing right they do not currently have.
One further detail signals how the Commission expects compliance to be built. It asks to what extent platforms could comply by scaling the processes they already run for the Digital Millennium Copyright Act, the TAKE IT DOWN Act and the INFORM Act. That is the Commission telling the market which existing machinery it expects to be repurposed, and it is a strong hint that any eventual rule would look like notice-and-takedown rather than prior restraint.
The Commission also addresses the obvious objection in advance, arguing that Section 230 of the Communications Decency Act does not deprive it of authority over platform conduct, and resting on long-standing case law that one who places into the hands of another a means of consummating a fraud may itself violate the FTC Act. That is a contested position and a likely locus of litigation, which is part of why we expect the timeline to be long. The full notice is published on the Federal Register for readers who want the primary text.
Enforcement has been running ahead of rulemaking in the meantime, which tells you the Commission can already reach the advertisers even without reaching the platforms. Recent actions include matters against a lead generator for placing deceptive government-impersonating search text ads, against a bill-payment service for impersonating consumers’ billers in search ads, and against operators who used search advertising to impersonate insurers and government programs. A separate settlement with a payment processor established that intermediaries can be held to a knowledge standard, a logic our earlier analysis of the processor knowledge test examined in detail, and the same logic is now being pointed at ad platforms.
Signal 2: Ofcom closed its fraudulent advertising consultation on October 2
The United Kingdom is roughly eighteen months ahead of the United States on this exact question, and its consultation window closed two days before this piece was written. Ofcom published draft Fraudulent Advertising Codes of Practice on July 10, 2026 under the Online Safety Act, and the consultation closed on October 2, 2026. Final codes are expected to be laid and brought into force during 2027.
Scope is narrower than the FTC’s framing but sharper in effect. The codes apply to services designated Category 1 or Category 2A on Ofcom’s 2026 register of categorised services, which captures the largest social platforms and search engines. They cover paid-for advertising content only, explicitly excluding user-generated content and non-sponsored search results, which keeps the obligation squarely on the commercial ad stack.
The package runs to nearly 40 draft measures, and the overlap with the FTC’s question list is the analytically interesting part. Ofcom proposes banning accounts that post fraudulent advertisements and preventing those actors from re-registering, verifying that advertisers genuinely represent the business they claim to represent, requiring authorisation checks for financial and investment advertisers, strengthening account security against hijacking, testing AI ad-creation tools for misuse, and establishing fast-track reporting channels for law enforcement.
Penalties are set at a level that compels board attention: up to £18m or 10% of qualifying worldwide revenue, whichever is greater. Ofcom has also scheduled a further consultation on proactive technology to filter fraudulent ads at source, with decisions expected in 2027, which suggests the first codes are a floor rather than a ceiling.
The reason this functions as a leading indicator for US retail is that the large platforms do not maintain separate advertiser onboarding stacks per jurisdiction where they can avoid it. Building identity verification, business-representation checks and repeat-offender prevention for the UK and then declining to run them in the United States would be an expensive way to preserve a liability exposure. The prior precedent of privacy and consent tooling points the same direction, where EU-built infrastructure was generally applied more broadly once the engineering cost was sunk.
The brand-side harm is already well documented in the United Kingdom, which is partly what drove the consultation. Trade coverage of the consultation put UK consumer losses to fraudulent advertising at roughly £200m a year. Our reporting on the case where a major grocer referred fake branded ads to police illustrates the dynamic precisely: the impersonated retailer absorbs the reputational damage, the platform keeps the ad revenue, and the brand has no efficient remedy. That asymmetry is exactly what both regulators are now trying to price.
Signal 3: the platforms are verifying advertisers ahead of any mandate
The third signal is the one that makes the prediction operational rather than theoretical, because it is already shipping. Meta has said it expects verified advertisers to account for 90% of its advertising revenue by the end of 2026, up from roughly 70%. The rollout began in March 2026 on a risk-based basis, with advertisers selected according to where their ads are delivered, their compliance history, and whether their category is prone to abuse.
Google has been less specific on timing but clearer on direction, stating that every advertiser will eventually be required to verify, with accounts pulled forward for suspicious behaviour, financial services advertising, or brand-related advertising. The inclusion of brand-related advertising matters for retail, because resellers, affiliates and authorised dealers routinely bid on brand terms they do not own.
Volume disclosures give a sense of the scale being managed. Meta reported removing more than 159 million scam ads globally in 2025, with 92% taken down before any user report, and reported 65 million removals as of late September 2026 with 94% proactive. Those figures are offered as evidence of effort, but they also quantify how much fraudulent demand the ad auction attracts in the first place.
The counter-evidence is what keeps regulators engaged. A late-2025 investigative report, widely cited in the FTC’s own notice, estimated that Meta earned roughly 10% of its 2024 revenue, about $16bn, from scam advertising, and described internal assessments that users were shown approximately 15 billion higher-risk scam ads per day. The same reporting described a policy under which advertisers were typically banned only once automated review reached 95% certainty of fraud, with lesser suspicion triggering higher ad pricing instead of removal.
Whether or not those specific characterisations survive litigation, they establish the commercial logic that both regulators are responding to. Verification is the cheapest available answer to that criticism, because it shifts cost onto advertisers rather than onto platform revenue, and it is measurable in a way that content moderation is not.
What the pattern suggests
Read together, the three signals describe a sequence in which the compliance requirement arrives through commercial policy and the rule arrives much later, if at all. The FTC is at the earliest procedural stage available to it. Ofcom is roughly at the end of its drafting stage. The platforms are already deploying the remedy both regulators are contemplating.
| Signal | Date | Source type | What it implies | Lead time to effect |
|---|---|---|---|---|
| FTC advance notice on platform impersonation liability | Voted September 24, 2026; published October 1, 2026 | Federal Register, 16 CFR Part 461, Matter No. R207000 | US rulemaking has started from the earliest stage, on a theory abandoned once already | 24–36 months to any final rule |
| Ofcom draft Fraudulent Advertising Codes | Published July 10, 2026; consultation closed October 2, 2026 | UK regulator consultation under the Online Safety Act | Nearly 40 measures including advertiser verification, enforceable at up to 10% of global revenue | 6–15 months to codes in force |
| Platform advertiser verification programmes | Rollout from March 2026; target set for end of 2026 | Company disclosures and product documentation | Verification is being deployed commercially regardless of rule status | Already live; 0–6 months to broad coverage |
The lead times are the argument. The slowest-moving signal is the one with US legal force, and the fastest-moving signal is the one with no legal force at all. When an industry adopts a remedy faster than its regulator can mandate it, the regulator’s eventual rule tends to codify prevailing practice rather than change it.
There is a second-order effect worth naming. Once verification is near-universal, the marginal cost of adding further obligations on top of it falls sharply, because the identity layer is the expensive part. That is why we expect the sequence to be verification first, then complaint-driven takedown duties, then possibly proactive filtering, rather than all three arriving together.
The rulemaking clock: what the FTC’s own precedent implies
The strongest basis for the timing half of this prediction is the Commission’s track record on this exact rule. The impersonation rulemaking is unusually well documented because it has already run a full cycle, and the elapsed times are a matter of record.
| Stage | Date | Elapsed from prior stage | Outcome |
|---|---|---|---|
| Advance notice of proposed rulemaking | December 23, 2021 | Start | Record opened on impersonation fraud generally |
| Notice of proposed rulemaking | October 17, 2022 | About 10 months | Rule formally proposed, including a means-and-instrumentalities provision |
| Final rule promulgated | March 1, 2024 | About 16 months | Core rule adopted; means-and-instrumentalities provision not adopted |
| Supplemental notice on expansion | March 1, 2024 | Concurrent | Proposed covering individuals and means and instrumentalities |
| Means-and-instrumentalities provision withdrawn | December 26, 2024 | About 10 months | Commission declined to proceed, citing overbreadth concerns |
| Individuals provision | Informal hearing January 2025; unresolved as of the July 2026 agenda | 21+ months | Still under evaluation |
| New advance notice on platforms | October 1, 2026 | Fresh start | Narrowed to ad-optimization practices |
Applying the Commission’s own cadence to the current notice produces a sobering arithmetic. Ten months from an advance notice to a proposed rule would place a proposed rule around August 2027. A further sixteen months to a final rule would place that around late 2028, before any compliance date and before any litigation over Section 230 or the scope of Section 5 authority.
Two factors argue for the slower end of that range rather than the faster. The first is that the Commission is reopening a theory it withdrew under commenter pressure less than two years ago, which raises the evidentiary bar it must clear on prevalence and on cost-benefit analysis. The second is that the affected parties are among the best-resourced litigants in the economy, and the notice’s Section 230 discussion reads as preparation for a fight rather than a settled question.
One factor argues for the faster end. The Commission has built an unusually complete record in advance, citing its own enforcement docket, state court actions, academic work and investigative journalism inside the notice itself. A rulemaking that begins with a near-complete prevalence record can move faster than one that begins with an empty one. We weigh this as real but insufficient to pull a final rule inside the June 2027 horizon.
Wider context: notice and takedown arrives in advertising
The structural change hiding inside this rulemaking is not verification, which is an onboarding cost. It is the proposed complaint-and-takedown duty, which would create a channel through which an impersonated brand can compel a platform to act. The Commission asks what volume and type of complaint should trigger a duty to investigate, what steps the investigation should involve, and how much time a platform should get to remove a confirmed impersonation ad.
Retailers already know what this machinery looks like because they operate the product-listing version of it. Marketplace counterfeit programmes, brand registries and intellectual property takedown queues are the template, and they have a well-understood failure mode: they work for large brands with dedicated enforcement teams and work poorly for everyone else. Our guide to handling a counterfeit listing crisis sets out how uneven that process already is on the listings side.
Extending that model to advertising would be a meaningful expansion of brand leverage, because advertising impersonation is currently far harder to address than listing counterfeiting. A brand can usually find and report a counterfeit listing. It generally cannot see a scam ad that impersonates it, because the ad is targeted at someone else and may never be served to the brand’s own monitoring accounts.
This is also where the retail media build-out intersects with the regulatory one. Retailers that have spent the last three years standing up their own ad networks are, under the FTC’s definition, platforms that accept third-party paid listings. The compliance implication is that the obligation being drafted for Meta and Google is written broadly enough to describe a large retailer’s own ad business.
The same question is arriving in the next generation of ad inventory before that inventory is fully commercialised. Advertising inside AI assistants and agentic shopping surfaces will face the identity and provenance question from the beginning rather than retrofitting it, a dynamic we examined when assessing how AI ad platforms build out agency programmes. Verification infrastructure built for Meta and Google in 2026 and 2027 is likely to become the default admission standard for those surfaces too.
Implications for retailers, marketplaces and brands
For brand advertisers, the practical work is unglamorous and should be done before it is demanded. Entity records, beneficial ownership documentation, billing entity consistency and domain ownership need to match across every ad account, because verification failures cluster where a legal entity, a billing entity and a landing-page domain disagree. Agencies running pooled accounts across many clients face the largest reconciliation burden here.
For marketplace sellers and smaller merchants, the risk is timing rather than possibility. Verification is passable for a legitimate business, but a mid-campaign verification request during a peak trading window is a revenue event, and the risk-based selection criteria described by both platforms make peak periods a plausible trigger. Completing verification ahead of the 2027 selling calendar is cheap insurance.
For brands that are frequently impersonated, the strategic move is to build the evidence base now. If a complaint-driven duty is eventually adopted, the brands that benefit will be those that already run structured detection, keep timestamped records of impersonation instances, and can document platform response times. That record is also the most persuasive comment a brand can file before the November 30, 2026 deadline.
For retailers operating their own media networks, the governance question should be raised at board level rather than left to the ad operations team. The FTC’s platform definition is capability-based rather than size-based, and a retail media network that offers automated creative generation and audience targeting to third-party sellers sits inside the described conduct. Operators weighing that exposure should revisit the economics set out in our explainer on retail media networks.
| Scenario | Rough likelihood | What happens by June 30, 2027 | Falsifying observation |
|---|---|---|---|
| Base case: market moves first | Likely | No FTC final rule; proceeding at or before NPRM stage. Verification effectively mandatory on major platforms for higher-risk retail categories. Ofcom codes in force or imminent. | An FTC final rule published and in force before June 30, 2027 |
| Acceleration: rule outpaces expectation | Possible but unlikely | FTC issues an NPRM in H1 2027 on the strength of its pre-built record, compressing the normal cadence | No NPRM issued by December 31, 2027 |
| Stall: proceeding lapses | Possible | Comment record closes and no further action follows; verification still proceeds on platform policy and Ofcom alone | Any FTC procedural step after November 30, 2026 and before 2028 |
| Reversal: verification retreats | Unlikely | Platforms walk back verification targets under advertiser or competition pressure | Verified-advertiser revenue share disclosed below 80% at end of 2026 |
Caveats: what could go wrong
The most serious objection to this prediction is that it understates how fast the FTC can move when it has already built the record. The notice is unusually evidence-dense for an advance notice, citing the Commission’s enforcement docket, multiple state court complaints, watchdog research and a detailed economic theory of harm. An agency that treats the advance notice as a formality rather than a genuine inquiry could issue a proposed rule considerably faster than the ten-month historical gap suggests.
A second objection runs the other way and would also falsify part of the thesis. The Commission may conclude that enforcement under existing Section 5 authority is more durable than a rule that invites a Section 230 challenge, and simply keep bringing cases. If that happens, verification would still spread, but the regulatory narrative driving it would be a UK one, and the US component of this prediction would be the least load-bearing part of it.
Third, platform verification targets are commercial commitments rather than binding ones, and they can slip without consequence. A revenue target expressed as a share of advertising revenue is also easier to hit by verifying a small number of very large spenders than by verifying the long tail. If Meta reaches 90% of revenue while leaving most advertiser accounts unverified, the practical gate for small retail sellers would be weaker than this piece assumes.
Fourth, there is a genuine competition objection that the FTC itself raises. The notice asks repeatedly whether verification requirements would burden small businesses, whether platforms would pass costs through, and whether the rules would discourage innovation in AI advertising tools. A sufficiently strong small-business record could produce a narrower rule or none at all, and advertiser trade associations are well placed to build that record before November 30.
Fifth, scope could shift under the Commission’s feet. Impersonation is only one category of ad fraud, and a proceeding framed around ad-optimization tools could be broadened into general deceptive advertising or narrowed to financial services alone. Either move would change which retail categories are affected and when.
Finally, a jurisdictional caveat on the UK leading-indicator argument. Ofcom’s codes bind categorised services on a UK register, and the assumption that platforms will apply the resulting controls globally is an inference from past behaviour rather than a commitment. Platforms have geofenced compliance before when the cost of divergence was low, and advertiser onboarding is more geofenceable than a product feature.
Frequently asked questions
What exactly is the prediction being made here?
That advertiser identity verification likely becomes a practical requirement for US retail and marketplace advertisers before any FTC rule on platform impersonation liability takes effect. Specifically, we expect no FTC final rule in force by June 30, 2027, while verified status is likely a routine gate on major platform ad formats in higher-risk retail categories.
Is the FTC actually proposing a rule right now?
No, and the distinction matters. The October 1, 2026 document is an advance notice of proposed rulemaking, which asks whether a rulemaking should begin at all. A proposed rule would be a separate, later document, and a final rule later still.
Does Section 230 protect platforms from this?
The Commission argues it does not, on the basis that the conduct at issue is the platform’s own provision of ad-optimization services rather than the publication of third-party content. That position is contestable and likely to be litigated, which is one reason we expect a long timeline rather than a short one.
Why should a US retailer care about an Ofcom consultation?
Because the platforms that would have to comply are the same platforms US retailers buy from, and advertiser onboarding is expensive to build twice. The UK codes specify the verification, banning and re-registration controls in operational detail roughly eighteen months ahead of anything comparable in the United States.
What is the strongest argument against this prediction?
That the FTC has pre-built an unusually complete evidentiary record and could compress its normal rulemaking cadence substantially. If a proposed rule appears in the first half of 2027, the timing half of this thesis weakens considerably, though the verification half would still hold.
Could this make advertising more expensive for small retailers?
Plausibly, though the mechanism is friction rather than price. Verification imposes a fixed administrative cost that is trivial for a large advertiser and material for a small one, and the Commission is explicitly asking commenters to quantify exactly that pass-through.
Would any of this help a brand that is being impersonated today?
Not yet, and that is the gap. The current rule reaches the impersonator, not the platform carrying the ad, so an impersonated brand’s practical options remain platform reporting channels and litigation. The proposed complaint-and-takedown duty would change that, but it does not exist yet.
Do retail media networks fall within the FTC’s definition of a platform?
On the text of the notice, quite possibly. The definition covers public-facing sites or apps where third parties offer goods through paid advertisements or listings, which describes a retailer’s own ad network selling placements to third-party sellers. Whether the Commission intends that reach is one of the questions a comment could usefully probe.
When will we know whether this prediction was right?
There are three dated checkpoints. The FTC comment record closes on November 30, 2026; Ofcom is expected to publish final codes during 2027; and platform verification coverage should be observable from year-end 2026 disclosures. The primary test is whether an FTC final rule is in force on June 30, 2027.