On 26 August 2026 Poland's Deputy Prime Minister and Minister of Digital Affairs, Krzysztof Gawkowski, asked the European Commission to fine Meta €250 million — about $291.3 million — under the Digital Services Act, over fraudulent advertising that Poland says Meta was told about and did not remove.
The evidence is a test by CERT Polska, Poland's national computer emergency response team, which reported 122 adverts it had already identified as fraudulent using an ordinary Facebook account. Meta declined to remove 106 of them — an 86.8% refusal rate. Ten were removed. Six were never answered at all.
Those figures are being reported as current. They are not. CERT Polska ran that test between January and November 2024 and published it on 25 November 2024, twenty-one months before the letter was sent. What Poland has handed Brussels is not a new measurement of a new problem. It is an old measurement of a problem that was itemised, acknowledged and never remedied — and that changes what the €250m request actually is.
- €250 million is the fine Poland asked the European Commission to impose on Meta on 26 August 2026. No fine has been imposed; only the Commission can penalise a designated Very Large Online Platform.
- 106 of 122 fraudulent adverts reported to Meta were not removed — 86.8%. Ten were removed and six drew no response.
- The test dates from 2024, not 2026. CERT Polska ran it from January to November 2024 and published it on 25 November 2024. Most coverage does not say so.
- Detection was never the failure. All 122 adverts had been identified as fraudulent before Meta was notified. What failed was the decision taken afterwards.
- The Commission has had a deceptive-advertising proceeding open against Meta since 30 April 2024, and preliminarily found Meta in breach of its notice-and-appeal duties on 24 October 2025.
- The requested fine is worth about 6.6 days of the roughly $16bn a year Reuters reported Meta internally projected from scam and banned-goods advertising.
On 26 August 2026 Poland asked the European Commission to fine Meta €250 million under the Digital Services Act. The evidence is a CERT Polska test in which 106 of 122 reported fraudulent adverts were left up — a test that ran in 2024, not this year.
What did Poland actually ask the European Commission to do?
Short answer. On 26 August 2026 Krzysztof Gawkowski, Poland's Deputy Prime Minister and Minister of Digital Affairs, wrote to European Commission Executive Vice-President Henna Virkkunen asking the Commission to fine Meta €250 million — about 1 billion zloty, or $291.3 million — under the Digital Services Act, for failing to remove fraudulent advertisements reported to it.
The request is not a lawsuit and not a national penalty. Under the DSA, enforcement against a designated Very Large Online Platform sits with the European Commission rather than with individual member states. Facebook and Instagram were both designated VLOPs on 25 April 2023, each reporting 259 million average monthly active users in the EU. What Poland has done is supply evidence to the body that already holds the enforcement pen, and attach a number to it.
Gawkowski announced the request publicly on 27 August. The quote that carried across the Polish press was blunt: “Ten dziki zachód na platformie musi się skończyć” — “This Wild West on the platform must end” (Wprost). To Reuters he framed it as a change of register rather than of position: “The time has passed for us to say ‘improve yourselves’... Now the time has come for penalties.”
The European Commission's response was measured but not dismissive. Spokesperson for digitalisation Thomas Regnier said fraudulent ads and deepfakes of this kind are “of course, a very serious problem”, and that the Commission would “certainly look at all this evidence and take it into account in our investigation” (Interia). The operative word is investigation, singular and pre-existing. Poland is not asking Brussels to start something. It is asking Brussels to finish something.
Why is the evidence behind the €250m request nearly two years old?
Short answer. The 122-advert test that anchors Poland's letter was run by CERT Polska between January and November 2024 and published on 25 November 2024 — twenty-one months before the letter was sent. Most English-language coverage presents the figures as current, and at least one outlet describes them as “a 2026 study”. They are not.
This is the single most consequential thing about the story, and it is the thing the wire coverage lost.
Read the source. CERT Polska's post Oszustwa reklamowe na dużych platformach internetowych (“Advertising fraud on large internet platforms”) is dated 25 November 2024. It describes a test running from January to November 2024, in which the national CERT reported adverts it had identified as fraudulent using an ordinary Facebook account — the same reporting button available to any user. Of 122 adverts reported, 10 were removed, 106 were closed with the status “Nie usunęliśmy reklamy” (“We did not remove the ad”), and 6 received no response at all.
Every one of those numbers appears verbatim in the August 2026 reporting of Gawkowski's letter. None of the English-language coverage read for this article dates them.
That matters in three directions.
It changes what the letter is. Presented as fresh evidence, a 86.8% refusal rate reads as a snapshot of a platform under strain. Presented as a 2024 measurement being re-submitted in 2026, it reads as an escalation after a remedy process failed — which is what the intervening documents show it to be.
It changes the strength of the Commission's position, and arguably improves it. A regulator weighing a fine cares about duration as well as gravity. A defect first measured and published in November 2024, formally itemised in December 2024, assessed as unremedied in March 2025, and still being cited in August 2026 is a defect with a documented two-year life.
And it changes what a reader should conclude about Meta's counter-numbers. Meta's reply cites removals between July 2025 and June 2026 — a window that begins eight months after the test ended. The two datasets do not overlap. Neither party is measuring the same thing, and no published source read for this article compares them on like terms.
To be precise about our own claim: we are not saying the figures are wrong, or that Poland misrepresented them. Gawkowski's letter, as reported, attributes them to CERT Polska, and CERT Polska stands behind them. We are saying that the figures are dated November 2024, that this is checkable in one click, and that the coverage does not say so.
Where does the reporting disagree, and what should you not repeat?
Short answer. Four details differ between otherwise reliable outlets: the date of the letter, which letter is being dated, how the 16 non-refused adverts split, and the month of the Warsaw appellate ruling. Each is set out below with both readings, because a page that silently picks one hands its error to everyone who cites it.
We are publishing this section because of a measurable failure mode in how machines now read pages like this one. In Cited but Not Verified (arXiv:2605.06635, 7 May 2026), Onweller and colleagues benchmarked 14 models on inline citations in research reports. Link validity stayed above 94% and topical relevance above 80% — but factual accuracy, meaning whether the cited source actually supported the claim, ran between 39% and 77%. The links work. The claims drift. When a page resolves a source conflict without showing its working, the resolution is invisible to anything downstream, and a wrong figure propagates with a live link attached to it.
So here is the working.
1. The date of the letter to the Commission: 26 August, with one outlier. Reuters, Polsat News, RMF24 and Polish-language reporting all date the letter to Virkkunen 26 August 2026, with the public announcement on 27 August. The Next Web dates it 18 August. We use 26 August.
2. But 18 August is not simply an error — it is a different letter. Polish reporting records a separate sequence: on 18 August Gawkowski wrote to Meta about fraudulent advertising; on 26 August the ministry received Meta's reply, which proposed a meeting; the ministry judged it inadequate and the same day the letter went to the Commission. Two letters, two recipients, eight days apart. Coverage that reports a single “letter” is compressing them. We have not seen either letter published in full, and we do not assert their contents beyond what is reported.
3. The residual 16 adverts: 10 removed and 6 unanswered, not 16 removed. Notes From Poland reports a 13% removal rate, 16 of 122; Cryptobriefing says Meta “removed only 16”. CERT Polska's own post splits the residual: 10 removed (8.2%) and 6 never answered (4.9%). Reuters carries the same three-way split. The distinction matters — a non-response is not a decision, and six unresolved notices is a different defect from six refusals.
4. The Warsaw appellate ruling: March or April 2026. The Next Web places the Warsaw Court of Appeal's rejection of Meta's hosting-liability defence in March; the Reuters copy read via Euronext puts the appellate ruling in April 2026. We have not read the judgment and cannot resolve it. Both months appear below wherever the ruling is referenced.
5. Two claims we could not verify at all, and therefore do not assert as fact. The DSA's maximum penalty is widely reported as 6% of global annual turnover; EUR-Lex refused automated requests during this research, so we have not read Article 74 directly and attribute the figure to the reporting rather than to the statute. Meta's FY2024 revenue of $164.50 billion is reported consistently and originates in Meta's own results, but sec.gov also refused automated requests, so that figure too is carried on secondary authority. Both are flagged again in the Methodology.
None of this undermines the story. The load-bearing facts — the €250m figure, the 26 August letter, the 122/106/10/6 breakdown, the November 2024 provenance, and the Commission's open proceedings — are corroborated across primary documents and multiple independent outlets. The point of listing the disagreements is that the next person to cite this page should inherit the uncertainty along with the numbers.
Table 1: Where the reporting disagrees. Presented rather than silently resolved, so that anything citing this page inherits the uncertainty with the figures.
What exactly did CERT Polska measure?
Short answer. Between January and November 2024, Poland's national computer emergency response team reported 122 adverts it had already identified as fraudulent, using a standard Facebook user account, and recorded what Meta did with each notice. Meta declined to remove 106 of them.
The methodology is the interesting part, and it is easy to skim past. CERT Polska did not use a privileged channel. It did not use trusted-flagger status, a law-enforcement liaison, or a regulator-to-platform hotline. It used the reporting button any Facebook user has, from an ordinary account, and then counted the outcomes.
That design choice turns the test into something more useful than an enforcement complaint. It is a measurement of the consumer-facing notice pathway — the one every victim, every relative of a victim, and every bank fraud team actually has access to. And it returned a refusal rate of 86.8%.
CERT Polska reported 122 fraudulent adverts to Meta. 106 stayed up.
Poland's national CERT ran the test from an ordinary Facebook account between January and November 2024, using the reporting button any user has. The refusal — not the detection — is the failure the €250m request is built on.
CERT Polska's post also supplies the context that makes the refusals expensive rather than merely irritating. It records that more than 50% of victims of phishing campaigns hand over their data within the first hour, and that the average campaign, first victim to last, runs 21 hours. Against a 21-hour attack window, a notice queue measured in days is not a slow control. It is not a control.
For scale, the same body reports blocking 80,000 harmful domains in 2023 and 75 million access attempts in 2024 through its Warning List. This is not an under-resourced observer. It is the national CERT, and its notices were declined at a rate of roughly six in seven.
Why does an 86.8% refusal rate mean detection is not the bottleneck?
Short answer. Every one of the 122 adverts had already been found, examined and named as fraudulent before Meta was told about it. Nothing about the outcome depended on Meta's ability to detect anything. What failed was the decision taken after the detection — adjudication, not identification.
This is the point where the story stops being about Poland and starts being about how content-integrity systems are actually built.
Most of the public argument about deepfake advertising is a detection argument. Can the classifier spot a synthetic face? How fast does it score a video? What is the false-positive rate at scale? Those are real questions, and for the enormous volume of content nobody has looked at, they are the only questions that matter. Meta's own defence is framed almost entirely in those terms: 159 million deceptive ads removed globally last year, 92% of them before anyone reported them.
But the CERT Polska test isolates a completely different stage. The adverts in the test were not missed. They were reported, reviewed, and left up. Whatever pipeline handled those 106 notices had the advert in front of it, with an accompanying assertion from a national CERT that it was fraudulent, and returned “we did not remove the ad”.
A detection improvement does not fix that. Better classifiers, faster scoring and broader coverage all act on the population of content nobody has flagged. They do not touch the population where a human or a policy engine has already looked and said no. If the refusal is a policy threshold problem, a language-coverage problem, a reviewer-capacity problem or an incentive problem, then every euro spent on detection leaves the measured failure exactly where it was.
The distinction has a practical edge for anyone building or buying content-integrity tooling. It is worth asking a vendor — and worth asking your own team — not just what proportion of synthetic media do we catch, but what proportion of the synthetic media we are told about do we act on, and how fast. The second number is rarely reported. In this case it was, and it was 13.1%.
Readers working through the upstream half of this problem may find our explainer on the artefacts generators leave behind and the walkthrough of how face-swap deepfakes are constructed useful; both are about identification, which is the stage this incident is not about.
What did CERT Polska ask Meta to do, and what happened next?
Short answer. On 4 December 2024, nine days after publishing the test, CERT Polska issued five specific demands. On 31 March 2025 it assessed the response and concluded Meta's actions “did not resolve existing problems”. Meta had declined the two most concrete asks outright.
This is the part of the record that turns a measurement into a grievance. CERT Polska did not publish a refusal rate and leave it there. It published a remedy list.
The five demands, from CERT Polska's 4 December 2024 post, were: a plan for effective detection of harmful content in Polish; expansion of the Polish-language moderation team; blocking accounts whose adverts and posts had been repeatedly flagged; ingestion of CERT Polska's Warning List and comparable local threat-intelligence feeds to filter malicious outbound links; and improved transparency and timeliness in the ad library.
Each of those is a request about the stage after detection. Not one of them asks Meta to build a better classifier.
Four months later, CERT Polska's assessment — reported by cyberdefence24 on 31 March 2025 — was that the response had not worked. User reports were still going unhandled. Meta declined to implement the Warning List for automatic domain blocking, offering instead a non-binding global alternative with no implementation timeline. It rejected the ad-library changes on technical grounds, despite indexing delays reaching 24 hours. CERT Polska's summary: “Wciąż brakuje rozwiązań systemowych” — “Systemic solutions are still lacking.”
Set against a 21-hour average campaign lifespan, a 24-hour ad-library indexing delay is not a transparency inconvenience. It means the public record of an advert becomes searchable at roughly the moment the campaign has finished harvesting victims.
Table 2: CERT Polska's five demands and their status four months later, per CERT Polska's own assessment as reported by CyberDefence24. Four of the five concern what happens after a fraudulent advert has been identified.
One figure from that March 2025 reporting is worth quoting with a caveat attached: an estimate that Meta earns around 20 million zloty a day from scam advertising in Poland, roughly €4.7 million at current rates. We have not been able to identify the derivation of that estimate or a primary source for it, and we do not rely on it anywhere in this article. It is recorded here because it circulated, not because it is established.
How does this connect to the Commission's own findings about Meta?
Short answer. The Commission opened formal DSA proceedings against Facebook and Instagram over deceptive advertising on 30 April 2024, and on 24 October 2025 preliminarily found Meta in breach of its obligations to give users a simple way to notify illegal content and to effectively challenge moderation decisions. That preliminary finding and the CERT Polska measurement describe the same defect from two directions.
This is, to our knowledge, a connection no coverage of the Polish letter has made, and it is the reason the letter is likely to land harder than its €250m headline suggests.
Take the two documents side by side.
The Commission's finding is doctrinal. On 24 October 2025 it preliminarily found that Meta had breached its obligations to provide users with simple mechanisms to notify illegal content, and to allow users to effectively challenge content moderation decisions. It is a statement about the design of a pathway. Virkkunen's framing at the time: “Our democracies depend on trust. That means platforms must empower users, respect their rights, and open their systems to scrutiny.”
CERT Polska's finding is empirical. It walked that exact pathway 122 times from an ordinary account and recorded what came back.
One is a regulator saying the notice mechanism is not adequate as designed. The other is a national CERT demonstrating what the mechanism returns in practice. They were produced independently, eleven months apart, and they agree. For a Commission case team weighing whether a preliminary finding should convert into a penalty, field evidence that the theorised defect produces the predicted outcome is close to the most useful thing a member state can hand over — which is presumably why Regnier said the Commission would take it into account.
The deceptive-advertising thread is older still. The Commission's 30 April 2024 opening of formal proceedings named Meta's “policies and practices relating to deceptive advertising and political content on its services” as a ground, alongside the CrowdTangle deprecation and the absence of an election-monitoring tool. That proceeding has now been open for twenty-eight months. CERT Polska's test was still running when it opened.
Table 3: The European Commission's DSA record against Meta. Poland's request attaches to the oldest open thread rather than opening a new one. Dates from Commission pages read directly.
Poland's letter, read against that table, is not a new front. It is a member state pushing on the oldest open thread with the newest available evidence — and complaining, in effect, about the pace.
The evidence behind Poland's €250m demand was published in November 2024
Read as a sequence, the €250m letter is not a reaction to a new finding. It is the sixth step in a chain that began with a measurement Meta was told about, asked to fix, and did not.
How big is €250m against the business it targets?
Short answer. Using Reuters' own conversion of €250m to $291.3m and Reuters' November 2025 reporting that Meta internally projected roughly $16 billion of 2024 revenue from scam and banned-goods advertising, the requested fine is worth about six and a half days of that revenue line. Against the narrower category of ads Meta's legal team flagged as higher legal risk, it is about fifteen days.
The arithmetic below is ours. Every input is a published figure and every step is shown, so it can be checked or rejected.
The inputs. Reuters reported in November 2025, from internal documents, that Meta projected about 10% of its 2024 revenue — approximately $16 billion — from advertising for scams and banned goods (Sherwood News, 6 November 2025). Reviewing the same reporting, Lawfare adds that Meta's legal team identified $3.5 billion every six months from advertisements deemed to carry “higher legal risk”, a category expressly including brand and celebrity impersonation — which is precisely what the Polish adverts are — and that internal documents showed Meta willing to forgo only $135 million, 0.15% of revenue, to act against suspicious advertisers.
The working. $16bn over 365 days is about $43.8m a day; $291.3m is therefore about 6.6 days. The higher-legal-risk line, $3.5bn per half-year, is $7bn a year or about $19.2m a day; $291.3m is about 15.2 days of that. If the widely reported 6% DSA ceiling is applied to Meta's reported FY2024 revenue of $164.50bn, the maximum available fine is about $9.87bn, of which $291.3m is roughly 3%. And the fine Poland is asking for is about 2.2 times the $135m Meta was internally prepared to give up.
Table 4: The requested fine set against the revenue line it targets. The arithmetic is ours; every input is a published figure and the working is shown in the text above.
Three caveats, because this kind of arithmetic invites over-reading. The $16bn figure is a projection from internal documents, not audited revenue, and Meta disputes its framing — a spokesperson called the underlying estimate “rough and overly-inclusive”. The revenue is global while the alleged conduct in Poland's letter is Polish, so the comparison sets a national complaint against a worldwide revenue line and is a measure of proportion, not of liability. And the 6% ceiling is a statutory maximum reserved for the gravest breaches; nobody expects it, and the Commission has never approached it.
What survives all three caveats is the direction. A fine of this size, against this revenue line, is not a deterrent priced to change behaviour. On Lawfare's account, Meta had already modelled that trade-off explicitly, weighing scam-ad revenue against the expected cost of regulatory action. A penalty worth under a week of the revenue it targets is inside the range that model was built to absorb.
What does the AliExpress fine tell us about the likely timetable?
Short answer. On 20 July 2026 the Commission fined AliExpress €550 million, its largest DSA penalty to date, roughly a year after issuing preliminary findings in June 2025. If the Meta notice-and-action thread follows a comparable interval from its 24 October 2025 preliminary findings, a decision would fall somewhere in late 2026 or 2027.
Poland's €250m is not a number pulled from the air, and the AliExpress case is why. The Commission fined AliExpress €550 million for failing to diligently assess and mitigate the risk of illegal, unsafe or counterfeit products reaching users. Poland is asking for a figure slightly under half that, for a failure of a similar shape: a duty to act on known risk, not discharged.
The procedural cadence is the more useful signal. Analysis by Lewis Silkin records preliminary findings in June 2025 and the fine decision in July 2026 — about thirteen months — with an action plan due from AliExpress by 20 October 2026, after which the European Board for Digital Services has a month to opine and the Commission a further month to adopt a final decision. It also notes the Commission “gave credit for the DSA's novelty” in setting the amount, which suggests later fines against later conduct have less mitigation available to them.
Applied to Meta, that cadence is the honest answer to “when will something happen”: not quickly. The notice-and-action preliminary findings are dated 24 October 2025. Thirteen months from there is late 2026. The deceptive-advertising proceeding opened on 30 April 2024 has not reached preliminary findings at all on that ground, as far as the published record shows.
We should be clear that this is a projection from one prior case, not a forecast. One data point is not a cadence, the two cases sit on different DSA obligations, and the Commission has given no timetable. But it is the only calibrated reference available, and it is a good deal more informative than the alternative of saying nothing.
Who was deepfaked, and why do the same names keep appearing?
Short answer. Three named figures recur across the reporting: InPost founder Rafał Brzoska, television presenter and businesswoman Omenaa Mensah, and President Karol Nawrocki. The pattern is consistent with what makes a public figure attractive to investment-fraud advertising rather than with three unrelated incidents.
Brzoska is the most documented case, and the reason Poland already has domestic law on this. He sued Meta over fabricated investment adverts using his likeness on Facebook and Instagram, some carrying false claims about his wife. Reporting read via Yahoo's copy of the Reuters wire records a Warsaw appellate ruling in April 2026 that Meta was responsible for the advertisements it hosts; The Next Web places the Court of Appeal's rejection of Meta's hosting-liability defence in March, describing the court as finding Meta “an active participant in the advertising” because it takes payment and supplies the targeting tools. As flagged above, we cannot reconcile the month and present both. We covered that case at the time in our analysis of the Warsaw court ruling on Meta's deepfake ads.
Omenaa Mensah, Brzoska's wife, appears in the same cluster of fabricated adverts. President Nawrocki appears in a separate strand: a fabricated video of the president promoting a fraudulent investment programme, which circulated on Facebook in August 2026 and prompted the ministry's earlier round of correspondence.
The selection logic is not mysterious. Investment-fraud advertising needs a face that carries financial credibility with a domestic audience and is recognisable enough that no explanation is required in a six-second pre-roll. A parcel-logistics billionaire, a television presenter and a head of state all satisfy that. So did the Australian and Indian equivalents: we have written about deepfaked Anthony Albanese investment scams and ASIC's response, about the Nirmala Sitharaman deepfake ad campaign in India, and about the fabricated Lawrence Wong conference used against Singaporean victims. Four countries, four heads of government or finance ministers, one advertising surface.
The mechanics of assembling that kind of campaign at volume are covered in our pieces on the synthetic-fraud supply chain and the Sapphire Network's deepfake ad operation, and the broader victim pathway in how deepfakes fuel romance and investment fraud. On the legal question of what a public figure can actually do about it, see whether it is legal to make a deepfake of a public figure.
What does Meta say?
Short answer. Meta does not engage with the 122-advert test directly. Its response is a volume defence: 159 million deceptive ads removed globally last year, 92% before any user report; 380,000 pieces of content and 137,000 adverts removed in Poland between July 2025 and June 2026; and a commitment to verify 90% of ad revenue sources by the end of 2026, up from 70%.
The full statement, as carried by Reuters: “Scammers are persistent criminals who use increasingly sophisticated tactics. That's why we continue to invest heavily in technologies and partnerships - with industry and law enforcement - to find, remove, and ultimately stop scammers.”
To Do Rzeczy, Meta added the global figure: “Last year we removed over 159 million deceptive ads globally, with 92% before anyone reported them to us.” RMF24 reports the advertiser-verification pledge. Polsat News reports Meta stating that fraudulent adverts typically disappear within seven days, and that the ministry received a written response on the evening of 27 August which Gawkowski judged unsatisfactory.
Read carefully, none of it answers the complaint.
The 92%-before-report statistic is a statement about the population nobody flagged. CERT Polska's test is exclusively about the population somebody did flag. Meta's own framing therefore concedes the shape of the problem: the 8% that reaches a human report is where the measured failure lives, and Meta's headline number says nothing about it.
The Polish removal counts — 380,000 and 137,000 — cover July 2025 to June 2026, a window beginning eight months after the CERT Polska test ended. They are not a rebuttal of the test; they are a different measurement of a different period, with no denominator. 137,000 adverts removed is unreadable without knowing how many were reported, how many were refused, and how quickly.
The seven-day disappearance claim is the one that sits worst against CERT Polska's own data. If more than half of phishing victims submit their details within the first hour, and the average campaign completes in 21 hours, then an advert that reliably disappears within seven days has been available for the whole of its useful life.
There is one item in Meta's response that is responsive: raising verified ad revenue sources from 70% to 90% by the end of 2026 is a change at the advertiser-onboarding stage, which is upstream of both detection and adjudication. Whether it addresses the Polish complaint depends on whether the accounts placing these adverts were unverified, and no source read for this article establishes that.
We have written separately about why volume statistics of this kind resist interpretation, in why security training cannot stop deepfake fraud.
Table 5: Meta's public response mapped against the specific allegation. Meta has not, in any source read for this article, addressed the outcomes of the 122 notices directly.
What does this change for identity verification and fraud teams?
Short answer. Very little about detection, and quite a lot about evidence. The Polish case establishes that a documented, dated notice trail is now the currency of platform enforcement in the EU — and that organisations whose executives are being impersonated should be building that trail themselves rather than assuming a platform report closes the matter.
Three practical consequences follow from the record above.
A platform report is not a remedy, and should not be logged as one. The measured outcome of reporting a fraudulent advert through the standard pathway, at least in this test, was an 86.8% chance of refusal. Any internal process that treats “reported to platform” as a closed state is recording a hope. The state that matters is “removed, on this date”, and the gap between the two needs to be visible in whatever system tracks it.
The notice trail is the asset. What made Poland's letter credible was not outrage. It was 122 timestamped notices with recorded outcomes, in a structured form, from a named institution. Organisations whose brand or executives are recurrently impersonated are sitting on the same raw material and mostly not capturing it: what was reported, when, through which channel, what came back, how long the advert stayed live afterwards. That dataset is what converts a complaint into evidence a regulator can use, and it is cheap to keep and impossible to reconstruct later.
Detection still matters, but at a different point in the chain. Nothing here argues against detection — it argues that detection deployed only as a reporting input inherits the refusal rate of whoever receives the report. Detection is worth far more where the organisation itself controls the decision: screening inbound creative in an ad network, verifying media in a KYC or onboarding flow, or checking a video call before a payment instruction is executed. DuckDuckGoose's DeepDetector is built for exactly that position in the chain — before an artefact is accepted, rather than after it has been published and reported. For the audio equivalent, our write-up of how voice cloning powers modern scams covers the same asymmetry.
For teams whose exposure is on the verification side rather than the advertising side, the relevant background is in how deepfakes bypass KYC, how injection attacks feed deepfakes into verification, and where deepfake detection fits in an identity verification stack.
What should a platform-facing fraud team do this quarter?
Short answer. Instrument the notice pathway you already use, so that in twelve months you have what CERT Polska had: a dated, counted record of what you reported and what happened to it.
- Log outcomes, not submissions. For every advert or account reported, record the date of the notice, the channel used, the response received, the date of any removal, and the elapsed time. The refusal rate is only computable if refusals are stored.
- Separate the two failure modes. A refusal and a non-response are different defects with different remedies. CERT Polska's 106 and 6 are reported separately for that reason.
- Measure against campaign lifespan, not against SLA. A response inside seven days is meaningless against a 21-hour campaign. The benchmark that matters is whether removal happened before the advert finished working.
- Use trusted-flagger status where you qualify. CERT Polska's test deliberately used an ordinary account, which is what makes it a measurement of the consumer pathway. If a privileged channel is available to your organisation, the ordinary pathway is the wrong one to rely on operationally — though it remains the right one to measure.
- Keep the creative. Preserve the advert itself, not just the URL. Fraudulent creative is taken down, links rot, and an evidence file without the artefact is much weaker a year later, which is when a regulator is likely to ask.
- Escalate to the DSA route where the platform is a VLOP. National consumer or advertising regulators are not the enforcement authority for designated platforms. The Polish case is a demonstration of the correct channel and of the evidence standard it rewards.
Broader regulatory context for European teams is in our overview of what is changing in deepfake regulation in 2026 and our analysis of AI Act Article 50, eIDAS 2 and explainable detection. Compliance teams tracking obligations across jurisdictions may also want our summary of AI fraud compliance regulations.
Frequently Asked Questions
Did the European Commission fine Meta €250 million?
No. Poland asked the Commission to impose that fine. As of 28 August 2026 no fine has been imposed on Meta over scam advertising. The Commission has said it will take Poland's evidence into account in its existing DSA investigation. Only the Commission, not a member state, can penalise a designated Very Large Online Platform.
When was the CERT Polska test actually carried out?
Between January and November 2024, published on 25 November 2024. This is checkable on CERT Polska's own site. Much of the August 2026 coverage repeats the figures without dating them, and at least one outlet describes them as a 2026 study.
What is the 86.8% figure?
It is the share of CERT Polska's 122 reported fraudulent adverts that Meta declined to remove — 106 of them. A further 10 were removed and 6 received no response at all.
Which public figures were deepfaked in the Polish adverts?
Reporting names InPost founder Rafał Brzoska, television presenter and businesswoman Omenaa Mensah, and President Karol Nawrocki. Brzoska has separately litigated against Meta in the Polish courts.
What is the maximum fine under the Digital Services Act?
It is widely reported as 6% of a provider's global annual turnover. We were unable to open the statutory text directly during this research and therefore attribute that figure to the reporting rather than to Article 74 itself. The largest DSA fine imposed so far is €550 million, against AliExpress on 20 July 2026.
Does this mean deepfake detection does not work?
No, and the case does not test detection at all. All 122 adverts had already been identified as fraudulent before Meta was notified. What the test measures is what happened after identification. Detection remains the right control wherever the organisation deploying it also controls the decision — ad intake, onboarding, payment verification.
Has Meta responded to the specific 122-advert test?
Not directly, in any source read for this article. Meta's responses cite global removal volumes, Polish removal volumes for July 2025 to June 2026, and an advertiser-verification commitment. None of those addresses the outcomes of the 122 notices.
How long might a Commission decision take?
There is no published timetable. The one comparable case, AliExpress, ran roughly thirteen months from preliminary findings in June 2025 to a fine in July 2026. Meta's notice-and-action preliminary findings are dated 24 October 2025. That is a projection from a single prior case, not a forecast.
Methodology
This article was assembled from primary documents where they could be read directly, and from independent reporting where they could not. Six European Commission pages were read in full: the VLOP designation list, the 30 April 2024 opening of formal proceedings against Facebook and Instagram, the 24 October 2025 preliminary findings on notification and appeal mechanisms, the 29 April 2026 preliminary findings on minors, the 20 July 2026 AliExpress fine, and the DSA policy overview. Two CERT Polska posts were read in the original Polish: the 25 November 2024 test and the 4 December 2024 expectations. Polish-language reporting from Polsat News, RMF24, Wprost, Do Rzeczy, Interia and cyberdefence24 was read in the original.
The Reuters wire could not be retrieved from reuters.com, which refuses automated requests; it was read instead via two syndications, Euronext and Yahoo News Canada, and is credited once in the source list rather than twice, since both carry the same copy.
Three documents we wanted and did not get: the DSA text on EUR-Lex, for Article 74(1) verbatim; the European Commission's full AliExpress press release on the presscorner domain; and Meta's FY2024 results on sec.gov. All three refused automated requests. Where a figure depended on one of them — the 6% penalty ceiling and Meta's $164.50bn FY2024 revenue — it is attributed to secondary reporting in the text and flagged again here. Neither figure is contested by any source we read; we simply have not verified them at source, and say so rather than implying otherwise.
Where outlets disagree, both readings are presented rather than one chosen. Those disagreements are set out in Table 1 rather than resolved silently, and Table 6 maps each load-bearing claim to the document it rests on. No media was analysed for this article, and no detection was run: DuckDuckGoose has not examined any of the adverts described, and nothing here should be read as a detection finding.
The arithmetic in the section on fine size is ours, computed from published figures with the working shown. It is a comparison of magnitudes, not an assertion about what any penalty should be.
Table 6: Claim-level provenance. Every load-bearing claim, the document it rests on, whether we opened that document ourselves, and how much weight it can carry.
Sources
- CERT Polska — Oszustwa reklamowe na dużych platformach internetowych (25 Nov 2024)
- CERT Polska — Oczekiwania wobec firmy Meta (4 Dec 2024)
- European Commission — Formal proceedings opened against Facebook and Instagram (30 Apr 2024)
- European Commission — Preliminary findings against TikTok and Meta on transparency obligations (24 Oct 2025)
- European Commission — Preliminary findings against Meta on minors under 13 (29 Apr 2026)
- European Commission — AliExpress fined €550 million for breaching the DSA (20 Jul 2026)
- European Commission — List of designated VLOPs and VLOSEs
- European Commission — The Digital Services Act package
- Reuters — Poland urges EU to fine Meta €250 million for scams and false ads (read via Euronext, 27 Aug 2026)
- Notes From Poland — Poland asks EU to fine Meta €250m over scam Facebook ads (27 Aug 2026)
- Polsat News — Rząd vs Meta. Jest wniosek do Komisji Europejskiej (27 Aug 2026)
- RMF24 — Oszukańcze reklamy. Gawkowski chce miliarda zł kary dla koncernu Meta
- Wprost — Gawkowski chce 250 mln euro kary dla Mety
- Do Rzeczy — Polska chce drakońskiej kary dla Mety. Jest reakcja firmy
- Interia — KE wykorzysta polskie materiały w sprawie Mety
- CyberDefence24 — Oszustwa na Facebooku. CERT Polska: Meta nie realizuje postulatów (31 Mar 2025)
- The Next Web — Poland has asked the European Commission to fine Meta €250m over scam ads
- Cryptobriefing — Poland urges EU to impose €250M fine on Meta
- KNEWS — Poland initiates €250 million fine against Meta over fraudulent ads
- Yahoo News Canada — Reuters copy, Poland asks EU to fine Meta €250 million
- Sherwood News — Meta projected 10% of 2024 revenue came from scams and banned goods (6 Nov 2025)
- Lawfare — Reuters blows the lid on Meta's fraud profit scandal (14 Nov 2025)
- Lewis Silkin — European Commission fines AliExpress a record €550 million
- Onweller et al. — Cited but Not Verified: Parsing and Evaluating Source Attribution in LLM Deep Research Agents (arXiv:2605.06635, 7 May 2026)
Reported 28 August 2026. Facts current as of that date; the Commission had issued no decision on Poland's request at the time of writing.














