Meta Loses Its DSA Shield Over Deepfake Ads: What the Warsaw Ruling Actually Changes

The Court of Appeal in Warsaw held that Meta cannot invoke the Digital Services Act's hosting exemptions for fraudulent ads using Rafał Brzoska's likeness. Its reasoning names a pre-publication inspection stage — which makes this a finding about architecture, not just liability.
By Sukrit Bhatia
August 19, 2026
l
13
 min read
What are deepfakes — business risk overview article
Table of Content
No items found.

On 27 March 2026 the Court of Appeal in Warsaw held that Meta Platforms cannot invoke Articles 6 and 7 of the EU's Digital Services Act — the hosting exemptions — in the dispute over deepfake advertisements that used the likenesses of InPost founder Rafał Brzoska and Omenaa Mensah to promote unverified investment platforms. The court's stated reason was not slow removal. It was that Meta's role in the advertising process is “conscious, active and directed at generating financial gain.”

In August 2026 the dispute flared again: a fresh fraudulent ad carried an AI-generated image of Brzoska in handcuffs, and after he criticised Meta publicly his own Instagram account was blocked, then restored. Poland's digital affairs minister called that “censorship in its darkest form.”

The reasoning is more durable than the row. To defeat passivity, the court asserted that Meta verifies advertising content before publication — which locates an inspection stage that already holds the creative and already decides whether it runs.

  • The hosting shield fell on architecture, not conduct. The Court of Appeal in Warsaw found Meta verifies ad content before publication, approves campaigns, supplies targeting and takes payment — participation that “excludes its neutrality” and so falls outside DSA Articles 6 and 7.
  • It is interim, partial and appealable. Relief was upheld for Mensah but narrowed for Brzoska, on the basis that remedies must attach to specific infringements rather than impose general monitoring. No final damages were awarded.
  • An injunction did not stop recurrence. The Regional Court in Warsaw barred Meta from accepting new deepfake ads of Brzoska on 7 November 2024. Fresh fraudulent creatives appeared in August 2026.
  • Enforcement fired fastest at the victim. The paid creative required two courts and a regulator; the impersonated person's own account was blocked within days of his complaint.
  • Paid advertising is the tractable case. One submission funnel, an identifiable paying account, an existing review queue, and a static complete artefact — the easiest position a detector is ever given, and still handled by litigation.
  • No artefact analysis is claimed here. Nothing in this article is a detection result.

A Polish appeal court has removed one of the legal foundations platforms rely on when fraudulent advertising uses a real person's face. On 27 March 2026 the Court of Appeal in Warsaw held that Meta Platforms cannot invoke the hosting exemptions in Articles 6 and 7 of the EU's Digital Services Act in the dispute brought by InPost founder Rafał Brzoska and his wife, Omenaa Mensah, over deepfake advertisements that used their likenesses to promote unverified investment platforms. The court's reason was not that Meta failed to remove the ads quickly enough. It was that Meta's role in the advertising process is, in the judgment's words, “conscious, active and directed at generating financial gain.”

That finding got a second life on 17 and 18 August 2026, when a fresh fraudulent Facebook advertisement appeared carrying an AI-generated image of Brzoska in handcuffs, surrounded by police. Brzoska criticised Meta publicly. His Instagram account was then blocked, and later restored. Poland's digital affairs minister, Krzysztof Gawkowski, called that “censorship in its darkest form”.

The political story is the one that travelled. The more durable one is the reasoning, and it deserves a closer read than it has had, because the test the court applied is only incidentally a legal test. Strip out the citations and the Court of Appeal made a finding of fact about system architecture: that an advertisement passes through a stage where the platform inspects it, decides whether to allow it, applies targeting to it, and charges for it. Everything downstream of that stage — the notice, the complaint, the regulator, the two years of litigation — is remedy. The court found the inspection point. It just had no reason to say what an inspection point is for.

At a glance

The Court of Appeal in Warsaw held on 27 March 2026 that Meta Platforms cannot invoke the Digital Services Act's hosting exemptions for the fraudulent advertisements it distributed using the likenesses of InPost founder Rafał Brzoska and Omenaa Mensah — because its role in the advertising process is, in the court's words, “conscious, active and directed at generating financial gain.” In August 2026 a fresh deepfake ad appeared, and it was the victim's account that got blocked.

27Mar
Appeal judgment
Court of Appeal in Warsaw, 2026 — written justification published end of April
2Arts.
DSA shield denied
Court held Meta cannot rely on Digital Services Act Articles 6 and 7
2courts
Polish rulings against Meta
Regional Court in Warsaw, Nov 2024 · Court of Appeal, Mar 2026
1account
Blocked in August 2026
Brzoska's Instagram — not the fraudulent advertisements

What the Court of Appeal actually held

The dispute did not begin in 2026. According to the account published by SKP, the law firm acting for the claimants, the Regional Court in Warsaw granted an interim injunction on 7 November 2024 that barred Meta from displaying — and from accepting — new advertisements containing deepfakes of Brzoska or fabricated claims about Mensah, with financial penalties threatened for breach. The advertisements at issue used Brzoska's image “manipulated using deepfake technology”, and, in Mensah's case, fabricated news copy that redirected users to links promoting investments on unverified platforms. The same court held that such advertisements “may constitute a violation of image rights and reputation” and that “online platforms may be held liable for the advertisements they display.”

Separately, Poland's data protection authority had already ordered Meta to stop running advertisements that used Brzoska's personal data and likeness after he complained that deepfake material was being distributed without adequate verification.

Meta appealed. The Court of Appeal in Warsaw ruled on 27 March 2026, with the written justification published at the end of April. It did not give the claimants everything: interim relief was upheld in relation to Mensah but narrowed for Brzoska, with the court stressing that remedies must be “closely linked to specific infringements” rather than imposing broad, open-ended monitoring duties on the platform. No final damages were awarded at this interim stage, and the judgment remains subject to further appeal. Those limits matter, and anyone reading this ruling as a general-purpose platform-liability weapon is reading it too enthusiastically.

The three findings that carried it

What survives the narrowing is the safe-harbour analysis. The court asked whether Meta qualified as a passive hosting provider entitled to the DSA's liability exemption, and answered no, on three grounds that are worth separating because they behave differently:

  1. Meta verifies advertising content before publication. Not after a complaint — before the ad is served. This is the finding that does the technical work.
  2. Meta decides whether to allow a campaign, and supplies advanced targeting. The platform is not a neutral conduit choosing nothing; it optimises who sees the creative.
  3. Meta is paid for it. The commercial relationship is with the party placing the fraudulent ad.

Taken together the court concluded that Meta's participation “excludes its neutrality” — and neutrality is the entire basis of the hosting exemption. The claimants have also signalled that they intend to seek disclosure of the revenue Meta earned from advertisements using their likenesses, which would convert an abstract argument about incentives into a number.

Case timeline

Brzoska and Mensah v Meta Platforms — from deepfake ad to appeal judgment

Two years, two Polish courts and one data-protection regulator. The dates below are drawn from the Anadolu Agency report of 18 August 2026, the SKP law firm's account of the November 2024 interim injunction, and published analysis of the Court of Appeal judgment.

1
notice, no removal
MAR–JUL 2024
2
16 months to appeal
NOV 2024
3
ads keep running
MAR 2026
4
AUG 2026
1
The campaign

Deepfake ads promote fake investment platforms

Advertisements on Facebook and Instagram use Brzoska's manipulated likeness, and fabricated claims about Omenaa Mensah, to drive users to unverified investment platforms. Brzoska notifies Meta in July 2024.

Paid distributionReported to Meta
2
First order

Regional Court in Warsaw grants an injunction

On 7 November 2024 the court bars Meta from displaying or accepting new ads containing deepfakes of Brzoska, warning of financial penalties. Poland's data protection authority separately orders Meta to stop running ads using his personal data.

7 Nov 2024Interim relief
3
Safe harbour falls

Court of Appeal: Meta cannot invoke DSA Articles 6 and 7

The 27 March 2026 judgment finds Meta's role in the advertising process “conscious, active and directed at generating financial gain.” Relief is upheld for Mensah and narrowed for Brzoska. The judgment remains subject to further appeal.

27 Mar 2026Hosting shield denied
4
The inversion

A new deepfake ad runs — and the victim's account is blocked

A fraudulent Facebook ad shows an AI-generated image of Brzoska in handcuffs, surrounded by police. He criticises Meta publicly; his Instagram account is then blocked and later restored. Poland's digital affairs minister calls it “censorship in its darkest form.”

Aug 2026Victim deplatformed

What Is Platform Safe Harbour Under the DSA?

Safe harbour is the principle that an intermediary is not liable for content it merely transmits or stores on a user's behalf, provided it does not know the content is illegal and acts expeditiously once it does. In the EU this originated in the e-Commerce Directive and now sits in Articles 4 to 6 of the Digital Services Act, with Article 8 confirming that no general monitoring obligation may be imposed on providers.

The exemption is conditional, not automatic, and the condition is passivity. A provider that plays an active role — one giving it knowledge of, or control over, the material — falls outside it. That carve-out has existed in EU case law since long before deepfakes, most prominently in trade mark disputes over keyword advertising. What the Warsaw judgment does is apply the passivity test to paid advertising carrying a synthetic likeness, and find that the advertising business model does not fit inside the shield built for hosting.

This is a narrower proposition than “platforms are liable for deepfakes”, and a more useful one. It says the exemption tracks the platform's actual involvement. Where a platform inspects, prices and targets a creative asset, it owns the consequences of what that asset does. Readers tracking how this fits the wider compliance picture may find our analysis of what is changing in deepfake regulation in 2026 and of AI Act Article 50, eIDAS 2 and explainable detection useful context, since transparency obligations and liability rules are converging on the same set of assets from different directions.

The part that is a technical finding, not a legal one

Here is the sentence in the reasoning that should interest anyone who builds content-integrity pipelines rather than argues about them: Meta verifies advertising content before publication.

The court asserted that as an established fact about how the product works, in order to defeat passivity. But read it as an engineer rather than a litigator and it says something else. It says a pre-publication inspection stage exists, it already receives the creative asset, and it already makes an allow-or-refuse decision on it. That is not a capability someone needs to build. It is a stage that needs a check added to it.

This distinction matters because the public debate about platforms and deepfakes is almost always framed as a scale problem: too much content, too fast, detection is imperfect, therefore only reactive takedown is feasible. That framing is defensible for organic posts. It is much weaker for paid advertising, and the reasons are structural rather than technical:

  • The population is bounded and enumerable. Every ad creative is submitted through one funnel, by an identifiable paying account, before it is distributed. There is no equivalent of the open web's unbounded ingest.
  • A review latency budget already exists. Ad review is not instantaneous today. A synthetic-media check does not have to fit inside a real-time serving path; it has to fit inside a review queue that already exists.
  • The high-risk subset is trivially identifiable. An advertisement depicting a recognisable public figure endorsing a financial product is a narrow, self-selecting category. It does not require screening everything to screen the thing that keeps generating litigation.
  • The economics are inverted from the usual argument. Fraudulent likeness ads are paid placements. The platform earns revenue on the specific items in question, which is precisely why the Warsaw court found neutrality excluded.

None of that means detection is easy or that a check at review time catches everything. Detection quality varies sharply by generator and by manipulation type, a point we have written about at length in why some deepfake generators are harder to detect and the traces generators leave behind. A still image of a named individual in a fabricated scenario — the handcuffs creative described in the August reporting — is a different analytical problem from a talking-head video, and a different one again from an injected video stream in a verification flow. Where analysis of a submitted asset is comparatively tractable is that the artefact is static, complete and in hand: no live session, no capture pipeline, no adversary reacting in real time. That is the easiest position a detector is ever asked to work from, which is what makes the placement argument worth making at all.

Where the control point sits

The court did not ask a platform to detect deepfakes. It described a review stage that already exists.

The Court of Appeal in Warsaw grounded its rejection of the hosting exemption in what Meta already does to an advertisement before it runs: verify it, target it, and take payment for it. That finding matters technically, not just legally — it locates an inspection stage that a synthetic-media check could occupy. The panel on the left is the control model the last two years of Polish litigation describe. The panel on the right moves one step earlier.

Today — remedy after distribution
Advertiser submits creative
Account may be new, anonymous or resold
Ad review: policy, targeting, billing
The stage the court called “conscious, active”. Whether it tests the creative for synthetic manipulation is not something an outsider can observe — and no ruling in this case suggests it did.
Published, targeted, paid for
Reach is purchased. The likeness is already in front of an optimised audience.
Victim or public reports it
Detection is outsourced to the person being impersonated
Notice → regulator → court
Two Polish courts and a data protection authority, across roughly two years
Structural problemEvery control in this chain fires after the money has been spent and the impression delivered. Takedown is the only lever, and litigation is what makes it move.
Shifted — inspection before spend
Advertiser submits creative
Same input, same account risk
Ad review: policy, targeting, billing
Unchanged — the stage the judgment already attributes to the platform
Synthetic-media check on the creative
Runs on the asset itself, in the same pass that already reads it for policy. A likeness-bearing ad is a bounded, high-value population — not the open web.
CleanProceeds to delivery on the normal path
FlaggedHeld for human review before any spend clears
Decision is logged and reviewable
Produces the audit record a regulator or court would otherwise have to compel
What changesThe control moves ahead of purchased reach. A named person's likeness is checked before it is monetised, rather than after they notice it and complain.

Note on scope: this diagram describes control-point placement, not Meta's internal systems, which are not public. It makes no claim about what Meta's ad review does or does not test for, and no artefact from this case has been analysed — see the article's unverified-claims section.

The inversion: the advertisements ran, the victim's account did not

The August 2026 sequence is worth stating plainly, because it is the clearest illustration of what a purely reactive control model produces. A fraudulent advertisement using Brzoska's likeness was distributed as a paid placement. He objected publicly. His own account was blocked. It was later restored, and Meta did not immediately respond publicly to the minister's accusation.

Whether that block was an automated enforcement action, a manual error, or something else is not publicly established, and we are not going to guess. But the shape of the outcome is instructive regardless of cause. Enforcement fired quickly and decisively against an authenticated, identifiable account belonging to the person being impersonated — and slowly, through two courts and a regulator, against the paid creative doing the impersonating. Whatever the intent, the system's fast path pointed at the victim.

That is what happens when the only reliable signal a pipeline has about a likeness-based fraud is a complaint. Complaints come from named accounts. Fraudulent advertisers are anonymous and disposable. Optimise a moderation system for signals it can actually act on, and it will disproportionately act on the people who report, not the accounts that offend. This is a design consequence, not a conspiracy — and it is not fixed by better complaint handling. It is fixed by generating a signal about the creative before the creative is distributed.

Why takedown is structurally the wrong control point

Every enforcement mechanism visible in this case sits downstream of distribution and payment. That is the common thread linking it to the other major named-incident enforcement story of this month, in which Australia's corporate regulator reported removing more than 19,400 online scams while deepfaked public figures continued to drive losses. Removal volume is a measure of how much got through.

The table below compares where a control can sit, and what it can still recover once triggered.

Control point Fires when Still recoverable Evidence in this case
Creative inspection at ad review Before any impression is served or spend clears Everything — no reach, no loss, no remedy needed Court found a pre-publication verification stage exists
Account-level advertiser vetting At onboarding, before campaigns run Most — but defeated by resold and disposable accounts Minister's charge: responsibility shifted to anonymous advertisers
User or victim report After targeted distribution Future impressions only Brzoska notified Meta; ads recurred into Aug 2026
Regulator order Weeks to months after harm Prospective compliance in one jurisdiction Polish DPA ordered ads using Brzoska's data halted
Interim injunction Months after harm Prospective conduct, under penalty Regional Court in Warsaw, 7 Nov 2024
Appellate ruling on liability Roughly 16 months after the injunction Legal precedent; no impressions unwound Court of Appeal in Warsaw, 27 Mar 2026

Table 1: Control points in the Brzoska and Mensah v Meta timeline, ordered by how early they can fire and how much harm each can still prevent.

Read down the third column and the pattern is unambiguous. Recoverable harm collapses to nothing after the first row. A court can change future conduct and set precedent; it cannot unwind a delivered impression or return a victim's savings. That is not a criticism of courts. It is an argument about where a control belongs, and it is the same argument that applies inside a bank's onboarding flow — which is why the difference between liveness detection and deepfake detection keeps mattering in remote verification flows. Detection placed after the decision it was supposed to inform is documentation, not control.

What this means for platforms, advertisers and verification providers

For platforms and ad networks. The Warsaw reasoning turns operational facts into liability exposure. Pre-publication verification, campaign approval, targeting and payment are exactly the features that make an advertising product commercially valuable, and they are now the features cited to defeat the hosting exemption. There is no version of a modern ad platform that is passive. The defensible position is not to argue passivity but to be able to show what the review stage tested for, and when. Note the shape of the relief too: the court narrowed Brzoska's injunction because remedies must attach to specific infringements rather than general monitoring, which is consistent with the DSA's prohibition on general monitoring obligations. A targeted check on likeness-bearing financial ads fits that framing considerably better than either doing nothing or screening everything.

For named individuals and the companies they front. Brzoska had a court order in hand from November 2024 and the advertisements still recurred in August 2026. An injunction constrains a platform's conduct; it does not constrain an adversary who regenerates the creative and resubmits from a new account. Executives whose likeness carries financial credibility should assume recurrence is the default and that their own reporting is currently load-bearing infrastructure — which, as the account block showed, is a fragile place to stand.

For verification and detection vendors. There is an uncomfortable implication here for our own side of the industry. If the technically easiest artefact to analyse — a static, fully-formed creative asset submitted voluntarily through a controlled funnel, with no live session and no adversarial timing pressure — is still being handled by litigation rather than inspection, then the constraint being hit is not detector accuracy. It is that nobody with access to the ingest point had a reason to look. At DuckDuckGoose we build DeepDetector for exactly this class of problem: bounded, high-stakes assets where a decision has to be made before something irreversible happens. The Warsaw judgment is the first ruling we are aware of that describes the insertion point in a platform's own advertising pipeline with this much specificity, and it did so for entirely unrelated reasons.

For regulated advertisers and financial institutions. If a fraudulent investment ad using a public figure's likeness reaches a customer and that customer loses money, the platform's liability position is now genuinely unsettled in at least one EU jurisdiction — but the customer relationship, and the complaint, still lands with the institution. Gawkowski framed the stakes as the savings of millions of Poles, and said his ministry is preparing legislation to implement EU rules holding large platforms responsible for user safety. Institutions should expect to be asked what they detected and when, irrespective of where the ad was served.

What We Have Not Verified

This analysis is built from published reporting and secondary accounts of court documents. The following are explicitly outside what we can stand behind, and we would rather name them than let them pass as established:

  • No artefact has been analysed. We have not obtained the handcuffs image, the 2024 investment-video creatives, or any other advertisement in this case, and we have run no detection on any of them. Nothing in this article is a detection result. We make no claim about how any specific creative was generated, what model produced it, or what a detector would return on it.
  • We do not know what Meta's ad review tests for. The court found that a pre-publication verification stage exists. Whether that stage performs any synthetic-media analysis is not public, and we do not assert that it does or does not. The control-point argument in this article is about placement, not about a gap we have measured.
  • Whether the August account block was automated or manual is unknown. We describe the sequence and its effect. We do not attribute intent, and we have seen no evidence that the block was retaliatory.
  • The exact publication date of the appeal judgment is inconsistent across sources. We have seen both 29 and 30 April 2026 for the written justification. The judgment date of 27 March 2026 is consistent across the accounts we read; we say “end of April” for publication rather than pick one.
  • The duration and precise scope of the Polish data protection authority's order are not confirmed. The order itself is reported by Anadolu Agency and others. A three-month duration appears in some secondary summaries; we have not read the decision and do not state a duration.
  • The 2024 campaign start and notification dates are secondary. March 2024 for the disinformation campaign and July 2024 for Brzoska's notice to Meta come from Polish legal-trade summaries rather than from documents we have read. The 7 November 2024 injunction date comes from claimants' counsel, an interested party, though it is the most specific account available.
  • No loss figure exists for these advertisements. Unlike comparable regulator-reported campaigns, we have found no published total attributable to the Brzoska or Mensah ads. We have not estimated one.
  • Meta's position is largely unstated. Meta did not immediately respond publicly to the minister's August accusations, and we have not obtained a substantive company response on the appeal ruling. Its arguments are known to us only as characterised by the court and by claimants' counsel.
  • Gawkowski's title varies between sources. The English-language wire reports we read describe him as Poland's digital affairs minister; Polish outlets also refer to him as deputy prime minister. We use the former.

An analysis of the actual media artefacts in this case is pending. If the creatives can be obtained, the findings will be added here rather than asserted now.

Frequently Asked Questions

Did a Polish court rule that Meta is liable for deepfake advertisements?
Not finally. The Court of Appeal in Warsaw ruled on 27 March 2026 that Meta cannot rely on the Digital Services Act's hosting exemptions in Articles 6 and 7, because its role in the advertising process is active rather than passive. That removes a defence at an interim stage; it does not decide final liability or award damages, and the judgment remains subject to further appeal.

What is safe harbour under the Digital Services Act, and why did Meta lose it here?
Safe harbour exempts an intermediary from liability for content it passively hosts or transmits. The exemption is conditional on that passivity. The Warsaw court found Meta verifies advertising content before publication, decides whether to allow campaigns, provides advanced targeting and receives payment — participation it described as “conscious, active and directed at generating financial gain”, which excludes neutrality.

Why was Rafał Brzoska's Instagram account blocked?
Publicly reported facts are that the account was blocked shortly after he criticised Meta over a fraudulent advertisement using an AI-generated image of him, and that it was later restored. The cause has not been publicly established. Poland's digital affairs minister characterised the block as censorship; Meta did not immediately respond publicly.

Can deepfake advertisements be detected before they are published?
Paid advertising is a more favourable case than open-web content, because every creative arrives through one submission funnel, from a paying account, before distribution, and a review stage already exists. Detection is not perfect and varies by generator and manipulation type. But a submitted ad creative is a static, complete artefact analysed outside any live session, which is the most tractable position for a detector.

Does this ruling apply outside Poland?
Directly, no — it binds in Poland and is subject to further appeal. Indirectly it matters more, because it interprets the Digital Services Act, which applies across the EU, and because the passivity test it applies is drawn from established EU law rather than anything Poland-specific. Other claimants in other member states can run the same argument.

What should an organisation do if its executives' likenesses appear in fraudulent ads?
Assume recurrence rather than resolution: a court order changes platform conduct but not an adversary's ability to regenerate a creative and resubmit from a new account. Preserve the artefacts and the ad identifiers as they appear, since analysis later depends on what was captured at the time, and do not rely on the impersonated individual's own reporting as the primary detection mechanism.

Methodology

The August 2026 sequence is taken from the Anadolu Agency report of 18 August 2026 and TRT World's account of the same events, both read directly. The 7 November 2024 interim injunction is taken from the published account of SKP, the law firm acting for the claimants, and is flagged above as an interested source. The Court of Appeal judgment of 27 March 2026 — the DSA Articles 6 and 7 finding, the “conscious, active and directed at generating financial gain” language, the partial narrowing of relief, and its appealable status — is taken from published analysis of the judgment; we have not read the judgment text itself. Where sources conflict, the conflict is stated rather than resolved. No claim in this article rests on a single unattributed source, and no figure, name or date appears here that we did not see in a source cited below.

Corroboration for the underlying news event was measured across the reporting gathered on 18 and 19 August 2026, and the story was assessed against a four-part test before being written: a specifically named entity, multiple independent publishers, a hard fact anchor in the form of a named court or regulator, and confirmation that the event is a real incident rather than a press release or opinion piece.

Last update: Q3 2026.

Sources

  1. Anadolu Agency — Polish minister accuses Meta of censorship in deepfake scam dispute (18 August 2026)
  2. TRT World — Polish minister accuses Meta of ‘darkest’ censorship in deepfake scam dispute
  3. SKP Law — Interim injunction ordering Meta Platforms to cease displaying infringing ads (Regional Court in Warsaw, 7 November 2024)
  4. XYZ — A Warsaw judgment with global implications for Meta's advertising model
  5. Prawo.pl — Brzoska kontra Meta: kiedy platforma odpowiada za reklamy deepfake?
  6. CyberDefence24 — Brzoska kontra Meta. Gawkowski: żądam realnych działań
  7. Fortune — Polish billionaire weighs legal action against Meta over deepfake ads (August 2024, background)
  8. Money.pl — Brzoska on the appeal ruling
By Sukrit Bhatia
DuckDuckGoose AI

About the author

By Sukrit Bhatia
DuckDuckGoose AI

Discover the Power of Explainable AI (XAI) Deepfake Detection

Schedule a free demo today to experience how our solutions can safeguard your organization from fraud, identity theft, misinformation & more