The strongest case for the Federal Trade Commission's new inquiry is simple. Platforms do more than host scam ads. They sell the targeting and optimization machinery that finds victims, and they collect revenue each time a fraudulent ad runs. The Commission's own figures show why it is acting: in 2025 it received more than 1 million imposter-scam reports, with about $3.5 billion in reported losses. Nearly 30% of people who reported losing money said the scammer first reached them on social media, with reported losses of $2.1 billion (FTC press release). If a company profits from fraud and has the tools to reduce it, asking what it should owe the public is legitimate.
What the FTC actually did
On 24 September 2026 the Commission voted 2-0 to publish an advance notice of proposed rulemaking (ANPRM). It asks whether to amend its Rule on Impersonation of Government and Businesses, 16 C.F.R. Part 461, to cover platforms whose ad-optimization practices further impersonation scams. An ANPRM is only a request for information. No rule has been proposed. Comments are due 60 days after Federal Register publication; the docket lists 30 November 2026 (FTC).
The measures under consideration include vetting advertisers, monitoring posted ads, investigating suspected impersonation ads, removing confirmed ones, and disciplining offending advertisers. The notice also asks whether those steps should be standalone mandates or the conditions of a compliance safe harbor, and what the compliance costs would be for small businesses (Mayer Brown analysis). The notice also cites a Reuters report that Meta expected about 10% of its 2024 revenue, roughly $16 billion, to come from ads for scams, illegal gambling and banned goods. That is a press allegation, not a finding of any violation.
The Section 230 question is the real fight
The legal theory carries most of the weight. Section 230(c)(1) says that no provider of an interactive computer service shall be treated as the publisher or speaker of information provided by another. But 230(f)(3) strips protection from an entity that is itself "responsible, in whole or in part, for the creation or development" of the content (47 U.S.C. § 230). The FTC's argument, as Mayer Brown describes it, is that a platform generating ad copy or targeting audiences with consumer data is acting on its own account and not merely hosting an advertiser's speech.
That theory is plausible for some features, such as a tool that writes the deceptive text. It is much weaker for neutral optimization, such as delivering an ad to people likely to click it. Courts have long asked whether a service materially contributed to what made the content unlawful. Treating every ranking or delivery algorithm as "development" would erase the statute's protection for nearly any service that organizes third-party content. MediaPost reports that the FTC itself calls the question a "fact-intensive inquiry" (MediaPost). Mayer Brown notes the ANPRM does not expressly discuss Section 230 at all, which leaves the central legal question to be fought in comments and, eventually, in court.
Where the design risks harm
Fraud is not protected speech, and an evidence-based approach to it is not censorship. The risk lies in how obligations are drafted. Three points stand out.
- Pre-review at scale. Mandatory pre-review of every ad pushes platforms toward blocking anything ambiguous. Small businesses, new advertisers and political or advocacy groups with unusual names or urgent messages would absorb the false positives. The FTC asks about small-business costs, which is the right question, and the answer should shape any rule.
- Verification versus anonymity. Advertiser verification is proportionate when it applies to paid commercial advertising, where counterparties can reasonably be known. It becomes a speech problem if it spreads to organic posts or non-commercial advertisers who need anonymity.
- Safe harbor design. A safe harbor is the better structure, since it rewards demonstrable diligence instead of strict liability for each scam that slips through. But a safe harbor with a rigid checklist freezes today's tools in place. Platforms with better fraud detection, such as behavioral signals or payment-trace data, should be able to earn the same protection by showing outcomes, not by copying a prescribed process.
There is also a precedent worth noting. The FTC's 2024 Impersonation Rule took effect on 1 April 2024 and lets it seek money for injured consumers and civil penalties from scammers. The companion "means and instrumentalities" provision, aimed at those who supply the tools to scammers, was proposed separately and, per the FTC's announcement, was not part of the rule that took effect (FTC). This ANPRM is a second attempt to reach intermediaries. A narrow rule built on that provision would rest on firmer ground than a broad reading of Section 230.
A proportionate path
The Commission can address real harm without stretching the statute. It could define liability by knowledge: platforms that have been notified of an impersonation ad, or that repeatedly serve the same advertiser, and fail to act. The notice itself cites data suggesting removals alone did not stop repeat offenders, with scam advertisers averaging 151 removals each, which points to repeat-offender controls and not blanket pre-screening. It could limit verification to paid commercial placements, set obligations by outcome measures, and publish transparency data so researchers can test whether any rule works.
The cost of getting this wrong runs in both directions. A rule that overreaches will be tied up in Magnuson-Moss procedure and then litigated on the Section 230 question, while scam losses keep growing. A targeted rule that survives review would do more for victims. The comment period is the moment to press for the narrower version.