Summary
- Poland’s digital affairs minister has asked the European Commission to impose a €250m fine on Meta over fraudulent advertisements.
- The request cites CERT Polska testing in which 106 of 122 reported scam adverts were left online after review.
- The dispute turns scam-ad reporting and removal into another test of how the EU enforces platform-risk obligations under the Digital Services Act.
Poland has asked the European Commission to impose a €250 million fine on Meta, escalating a long-running dispute over fraudulent advertising on Facebook and Instagram into a direct request for EU enforcement. Krzysztof Gawkowski, Poland’s minister of digital affairs, argues that the company has failed to respond adequately to scam adverts despite repeated reports from national authorities and cybersecurity teams.
The request relies partly on testing conducted by CERT Polska, Poland’s national computer-security incident response team, which examined how Facebook handled adverts it classified as fraudulent. Of 122 adverts reported during the exercise, 106 were closed with a decision not to remove the content, ten were taken down, and six received no response.
The underlying CERT Polska test ran between January and November 2024 rather than during the current enforcement push, so the €250 million demand combines fresh political pressure with evidence gathered over a longer period. Polish authorities nevertheless argue that fraudulent advertising remains widespread and that existing reporting mechanisms have not produced an adequate response.
Scam investment adverts have become a persistent problem in Poland, where criminals have used the identities of government bodies, banks, business figures, and other recognisable people to make bogus schemes appear credible. Fraudsters can rotate domains and accounts quickly, while cloaking techniques may show different content to automated moderation systems and human victims.
Reporting systems are becoming a regulatory test
Those tactics make advertising abuse technically difficult to control, although they do not settle whether platform reporting systems work well enough once suspected fraud has been identified. CERT Polska’s exercise found that 86.8% of the adverts it classified as malicious were closed without removal, giving Warsaw a numerical basis for arguing that moderation failed even after users actively flagged the material.
The dispute also has a domestic legal history. Polish businessman Rafał Brzoska, chief executive of parcel-locker company InPost, has pursued Meta over fraudulent adverts using his identity, while Poland’s data-protection authority previously acted against advertising that used his personal information.
Polish courts have also been asked to decide where responsibility lies when harmful advertising is hosted on a platform but placed by third parties. Those cases sit beside the broader EU question of how far the largest technology companies are expected to manage systemic risks created through services they operate at enormous scale.
Facebook and Instagram are supervised by the European Commission as very large online platforms under the Digital Services Act. The regime requires the largest services to assess systemic risks and adopt measures intended to mitigate them, while advertising transparency and mechanisms for notifying potentially illegal content form part of the wider compliance framework.
Brussels is already testing Meta’s systems
The Commission has existing Digital Services Act proceedings involving Meta, although those cases cover broader questions and should not be treated as rulings on Poland’s latest complaint. Previous preliminary findings have examined the ease with which users can report illegal content and whether Meta provides adequate access to public data for researchers.
More recent enforcement has also focused on platform design and recommender systems, showing that European supervision has moved beyond writing rules towards examining the operation of individual services. A request from a national minister does not itself establish a breach, however, nor does Warsaw determine whether a financial penalty should be imposed.
Financial fraud nevertheless fits naturally into the DSA’s risk-management framework because the issue is not merely whether an individual advert is unlawful. Platforms control the advertising systems through which campaigns are bought, targeted, distributed, reported, reviewed, and, where necessary, removed.
Generative AI adds another layer by making fake endorsements, synthetic video, and tailored scam copy cheaper to produce. A platform may therefore face growing volumes of rapidly changing campaigns even as regulators expect reporting and enforcement processes to become more reliable.
The practical question is whether platform systems can remove harmful campaigns quickly enough to change the economics for criminals. A reporting button has little protective value if a scam remains available after repeated reports, while an automated moderation system that blocks legitimate adverts aggressively creates costs of its own.
Poland’s proposed €250 million penalty puts a specific figure on its dissatisfaction, but the regulatory decision now rests with Brussels. The more durable issue is whether European platform rules can force improvements in the systems that decide what happens after a fraudulent advert is identified, rather than merely requiring companies to describe those systems more clearly.












