FTC Reddit Disclosure

FTC Enforcement Meets Reddit and AI: Disclosure for Community Link Earning

THE SHORT VERSION

The FTC’s fake-review rule defines a “consumer review” by where it was posted, not by what it says. A general discussion forum is not the venue the definition names, so four of the rule’s six operative sections do not reach a Reddit comment at all.

Two sections do reach it: the one covering testimonials by employees and agents, and the one covering bought engagement signals. The second catches upvotes, and almost nobody budgets for it.

British law deleted the venue clause. Under the DMCC Act a consumer review is any review of a product, a trader or a matter relevant to a transactional decision, and a separate banned practice covers simply posing as a customer.

The enforcement that arrives first is not a regulator. It is an unpaid moderator, it is account-level, and it takes your compliant history with it.

Three instruments below: the Classification Ladder, the Surface Map, and the Forfeiture Multiple, which prices how much of an account a single undisclosed comment puts at risk.

Every guide to promoting on Reddit repeats the same number. Nine to one: nine contributions of genuine value for every one mention of your own product. It is quoted as though it were a rule, and it is not one. The ratio came from a self-promotion wiki page written by moderators, it was never part of Reddit’s terms of service, and Reddit’s actual definition of spam does not mention ratios at all. The company defines spam behaviourally, as accounts that contribute primarily links to businesses they own or benefit from, judged on posting history rather than intention.

A ratio rule regulates volume. Every provision that can actually be enforced against a community link-earning programme, on either side of the Atlantic, regulates status: who wrote it, who caused it, what relationship existed, and whether the engagement was real. Volume is not a defence against any of them. Worse, complying with nine to one means publishing nine additional posts for every promotional one, which is nine more rows in the posting history that Reddit’s own definition reads and that any later investigator reads too. The rule the field follows makes the record larger and the disclosure no clearer.

This article is about what does apply. The answer turns on a definition almost nobody in link building has read, and because the American and British answers differ so sharply that the same comment can be out of scope in Washington and in scope twice in London.

The rule everyone quotes was written for a place your comments do not live

The instrument the field cites is the FTC’s Rule on the Use of Consumer Reviews and Testimonials, codified at 16 CFR Part 465, effective 21 October 2024. It is a trade regulation rule, meaning it defines specific practices as unfair or deceptive rather than merely interpreting the FTC Act, and courts can impose civil penalties on knowing violators.

Almost every summary skips section 465.1, which is where the rule does its real work. The rule does not regulate content. It regulates two defined objects, and it defines them narrowly.

What is a “consumer review” under the FTC’s rule?

Section 465.1(d) defines it as a consumer’s evaluation of a product, service or business that is submitted by that consumer and published to a website or platform dedicated in whole or in part to receiving and displaying such evaluations. The evaluation alone is not enough. The venue is part of the definition. A star rating on a retailer’s product page qualifies. A Trustpilot entry qualifies. A comment in a general-purpose discussion thread, on a platform built for conversation rather than for collecting evaluations, does not obviously qualify at all.

The phrase carrying the weight is “in whole or in part”. A platform does not have to be a review site end to end. A section of it will do. A subreddit created specifically to collect product verdicts, a forum’s dedicated reviews board, a marketplace’s question-and-answer panel: each is arguable, and the FTC’s own guidance confirms that a question-and-answer section falls outside only when the answers come from people with no connection to the company and no incentive to post. So rung one of the ladder below is a judgement call, not a lookup.

The second object is the consumer testimonial, defined at 465.1(f) as an advertising or promotional message that consumers are likely to believe reflects the opinions, beliefs or experiences of a consumer who has used the product. Note what is absent: any reference to venue. A testimonial is defined by function. If the message promotes and a reader would take it for a customer’s own experience, it is a testimonial wherever it sits. That is the object your community programme is manufacturing, whether or not anyone in the room has used the word.

Four sections miss. Two land.

Once the two objects are separated, the rule’s structure resolves into something the compliance commentary does not describe. Four of the six operative sections are written around reviews specifically, and therefore inherit the venue clause:

  • 465.2(c), procuring reviews from officers, managers, employees, agents or their immediate relatives for posting on a third-party platform.
  • 465.4, providing compensation or incentives conditioned on reviews expressing a particular sentiment.
  • 465.5(c), an officer or manager soliciting reviews from staff or relatives without instructing them to disclose.
  • 465.7, review suppression, including unfounded legal threats used to get a review taken down.

Read those four again with a Reddit programme in mind. Paying a contractor to post a favourable comment in a discussion thread is not caught by 465.4, because 465.4 is about reviews and the thread is not the venue. Asking your support team to go and say something nice in a community is not caught by 465.2(c) for the same reason. This is not a loophole worth celebrating and it is certainly not permission, because the FTC Act’s general prohibition on deceptive practices sits underneath all of it and the Endorsement Guides address undisclosed material connections wherever they appear. But it does mean the penalty-bearing rule, the one the dollar figure attaches to, largely does not reach the artefact the field is most worried about.

The provision that does reach you is about employment, not writing

Section 465.5(b)(1) makes it a violation for a business to disseminate, or cause the dissemination of, a consumer testimonial by one of its officers, managers, employees or agents that lacks a clear and conspicuous disclosure of the material relationship, where the relationship is not otherwise clear to the audience and the business knew or should have known about it. Every clause there is doing damage to a standard community programme.

“Agents” reaches the agency you hired and the freelancers it subcontracted, which is where most community posting actually happens. “Knew or should have known” removes ignorance as a defence and converts your procurement process into evidence. And “clear and conspicuous” is not a vague standard here; 465.1(c)(4) states that in an interactive electronic medium the disclosure must be unavoidable, and is not clear and conspicuous if a consumer must take any action, such as clicking a link or hovering over an icon, to see it.

That last sentence invalidates nearly every disclosure convention in community marketing. A note in the account bio requires a click. “Check my post history” requires several. A disclosure in the original post does nothing for a comment forty replies down that gets quoted on its own. The compliant version is a clause inside the comment, and it costs about six words.

The provision nobody budgets for is about upvotes

Section 465.8 prohibits selling, distributing, purchasing or procuring fake indicators of social media influence, where the buyer knew or should have known they were fake and that they misrepresent influence or importance for a commercial purpose. Section 465.1(j) defines indicators of social media influence expansively: followers, friends, connections, subscribers, views, plays, likes, saves, shares, reposts and comments. Section 465.1(h) defines the fake ones to include not only bot output and hijacked accounts but any signal that otherwise does not reflect a real individual’s or entity’s activities, which is broad enough to cover a coordinated ring of real humans voting to order.

Three features make this the sharpest provision in the rule for community work. It has no venue clause, so it applies to a discussion forum exactly as it applies to a review site. It binds “anyone”, not only a business, so the contractor and the vendor are exposed alongside the client. And it needs no classification argument at all, because a purchased upvote is a purchased upvote whatever the surrounding text turns out to be.

This is where the field’s attention is most badly misallocated. Enormous care goes into the wording of the comment, which is the part least likely to be caught by the penalty-bearing rule, and the engagement that makes the comment visible is treated as a small line item on a subcontractor’s invoice. The provision that reaches your Reddit programme is not about what you wrote. It is about who upvoted it.

KEY TAKEAWAY

Classify before you draft. On the FTC’s definitions, the wording of a community comment is the least-regulated part of a community programme, and the two most-regulated parts are the employment relationship of whoever posted it and the authenticity of the engagement that surfaced it. Compliance budget should follow that, not the copy deck.

Classifying a community post before you write it

The following ladder resolves the question in four rungs, in order. Stop at the first rung that puts you in scope; the rungs below it then tell you what else applies.

THE CLASSIFICATION LADDER

RUNG 1 — VENUE. Is this surface, or the specific section of it you are posting in, dedicated in whole or in part to receiving and displaying consumer evaluations? If yes, the full American rule is live, including the four review-specific sections. If no, skip to rung two and treat British law as your binding constraint.

RUNG 2 — CAUSE. Did the business write it, procure it, pay for it, brief it, or supply the account? “Caused the dissemination” is the statutory phrase and it is wider than authorship. A customer who posts unprompted breaks the chain. A customer given a discount code does not.

RUNG 3 — RELATION. What is the poster to the business: officer, manager, employee, agent, contractor, immediate relative, or genuinely unconnected? Anything other than the last item requires a disclosure inside the message, not in the profile, not in the flair, and not in a linked bio.

RUNG 4 — SIGNAL. Was any visibility signal purchased, coordinated, incentivised or automated? Upvotes, comment replies from adjacent accounts, cross-posting rings, engagement pods. This rung has no venue defence and no relationship defence. If the answer is yes anywhere in the supply chain, it is the finding that will be made first, because it is the one that leaves a timestamp pattern.

The output is not a score. It is a list of which provisions are live on this artefact, which tells you what a disclosure has to do and whether a disclosure is even the remedy. Rung four is never cured by disclosure.

The Surface Map

Applied across the surfaces a community programme actually uses, rung one produces a map worth keeping on the wall. Green means the surface sits outside the American review definition, so exposure concentrates in the testimonial and signal provisions. Amber is arguable. Red means the full review rule is live.

SurfaceUS: a “review”?UK: a “review”?Removed first by
General subreddit commentNo — venue failsYes — no venue testVolunteer moderator
Dedicated review subredditArguable — “in part”YesModerator or platform
Hacker News commentNo — venue failsYesCommunity flagging
Private Slack or DiscordNo — not publishedYes if consumer-facingChannel owner
Quora or Stack answerArguable — evaluationsYesCommunity moderation
YouTube commentNo — venue failsYesChannel owner
G2, Capterra, TrustpilotYes — squarelyYesPlatform integrity team
Retailer product pageYes — squarelyYesRetailer

The column that should stop a meeting is the third one. Every row is a yes.

Britain deleted the venue clause

The Digital Markets, Competition and Consumers Act 2024, whose unfair-trading provisions took effect on 6 April 2025, added fake and concealed incentivised reviews to Schedule 20, the list of thirty-two practices banned in all circumstances. Being on that list matters procedurally: the Competition and Markets Authority does not have to show the practice affected the average consumer’s transactional decision. The finding follows from the conduct.

The definition is what should interest anyone running a community programme aimed at British buyers. A consumer review, in the Act, is any review of a product, a trader, or a matter relevant to a transactional decision. Text, video, speech, a star rating. There is no clause about platforms dedicated to receiving and displaying evaluations, because Parliament did not write one. A fake consumer review is one that purports to be, but is not, based on a person’s genuine experience.

Is an undisclosed Reddit recommendation illegal in the UK?

If the poster is a trader posing as an ordinary customer, it is caught twice. Once under paragraph 13, because a comment recommending a product is a review of a product and the venue is irrelevant. And once under paragraph 25, which bans falsely claiming or creating the false impression that the trader is not acting for purposes relating to their business, or falsely representing oneself as a consumer. Paragraph 25 needs no review, no payment, no incentive and no platform. It describes the practice in a single line, and the CMA’s own fake-reviews guidance names it as a provision that review-related conduct can infringe.

Two further pieces of the British picture are worth holding. First, the duty to police runs to publishers, not only to advertisers: those who publish consumer reviews must take reasonable and proportionate steps to prevent and remove fake ones, and the CMA updated its compliance principles for social media platforms specifically to reflect that obligation. Second, this is not theoretical. On 26 March 2026 the CMA opened an investigation into Dignity Group Holdings over whether the company asked staff to write positive reviews of its crematoria. An insider-review case is live in Britain right now, and the regulator that opened it can fine without going to court first.

The consequence for a UK-facing programme is uncomfortable and simple. The American analysis, which is the one your agency or in-house link building specialist has read, gives you a venue defence. The British analysis gives you nothing of the kind, and the CMA has valued the market it is protecting at around £23 billion of annual consumer spending influenced by online reviews. If your buyers are in Britain, the American rule is the wrong document to be arguing about, and this holds across European markets with equivalent unfair-practice regimes.

KEY TAKEAWAY

The venue defence is jurisdictional. It exists in the United States because a definition was drafted around review platforms, and it does not exist in the United Kingdom because Parliament defined a consumer review by content and added a separate ban on posing as a customer. A single international community programme therefore has two different compliance surfaces, and the stricter one is at home.

The enforcement that arrives first is not a regulator

Both regimes above share a weakness as risk models: they are slow, they are discretionary, and they have never once been applied to a discussion-forum comment. The enforcement that actually lands on community link earning comes from the platform, it arrives in hours rather than years, and it is not appealable in any meaningful sense.

Reddit’s own first-quarter 2026 figures give the scale, and they belong in any serious set of link building statistics. Reddit’s automated systems detect roughly 25,000 spammy posts and comments a day. It blocks on the order of 23 million spam views daily and revokes close to two million inauthentic votes daily. Between July and December 2025, unpaid volunteer moderators drove more than half of all post and comment removals. These are the company’s own numbers, published while it sells a licensing story, so read them as directional rather than audited.

Why the supply of manipulation forced behavioural detection

The reason a conversation platform ended up building industrial-scale detection is worth understanding, because it explains why the pressure will not ease. In May 2026, Cornell Tech researchers Tingwei Zhang, Harold Triedman and Vitaly Shmatikov published a preprint titled Deep-Research Agents Can Be Poisoned via User-Generated Content, first reported by 404 Media on 15 June. They found that between 17% and 23% of the pages multi-step research agents retrieved came from user-generated sites, and that appending roughly thirteen words of promotional text to a single such source got the agent to name a fabricated product in 38% to 51% of runs where that source was retrieved, rising to 62% when the bait spanned several pages.

Thirteen words is the marginal cost of steering an answer, which is a fraction of the value of a single agentic visit. At that price the supply of manipulation is effectively unbounded, no filter that reads text can keep pace, and a platform’s only remaining lever is behaviour: account age, posting cadence, vote timing, cross-account correlation. Which is exactly the lever Reddit pulled. This also explains why the same platform is simultaneously the most valuable and the most hazardous surface in AI product recommendation work, and why multi-turn query chains keep returning to the same handful of threads.

The unit of forfeiture is the account

Behavioural detection has a consequence the field has not absorbed. A text filter removes a post. A behavioural system removes an account, and with it everything that account ever published, including the two years of genuinely useful answers that made it credible in the first place. A subreddit-level ban can also blacklist a domain, which takes out contributions from colleagues who did nothing wrong.

So the object at risk is not the comment. It is the standing of an account you do not own, on a platform you do not control, judged by a volunteer under rules that differ per community and change without notice. That is a materially worse custody position than any earned editorial placement carries, and it is the reason the next instrument prices exposure per account rather than per post. It is also why AI citation recovery after a community ban is so much harder than recovery from a manual action: there is nothing to fix and no one to appeal to.

The Forfeiture Multiple, and why tolerance should fall as an account matures

Community programmes are managed on a ratio. Here is the arithmetic that replaces it.

THE FORFEITURE MULTIPLE

Take one account. Let N be its total posts, V the total value attributable to it — citations held, referral earned, retrieval presence — and f the share of its posts that fail the Classification Ladder in a way disclosure cannot cure.

Because enforcement is account-level, detection of any non-compliant post forfeits all of V, not the f·N share that caused it. Value at risk per non-compliant post is therefore V ÷ (f·N), against an average post value of V ÷ N.

The ratio is 1 ÷ f. At f = 0.04, every non-compliant post risks twenty-five times the value it produces. At f = 0.01 it risks a hundred times.

The counter-intuitive result: the multiple rises as compliance improves, because the same total forfeiture is now concentrated on fewer posts. And V grows with account age. So the tolerable f falls as the account matures — the opposite of how programmes behave, which is to take more liberties once an account feels established.

Track f, not the promotional ratio. It is the only number in a community programme that is directly proportional to the thing you can lose.

The adjunct problem

The reasonable objection to everything above is that no regulator will ever open an investigation because of a forum comment, and that is very likely true. But it is the wrong probability to be estimating.

Reviewing the FTC’s first eighteen months of enforcement under the rule, DLA Piper’s July 2026 analysis observed that rule violations have appeared as adjuncts to matters centred on other deceptive conduct — misleading health claims, deceptive marketing of local services — rather than as standalone theories. The agency’s first public use of the rule was a set of warning letters issued on 22 December 2025 to ten companies, demanding written confirmation of corrective steps within five days; the recipients were disclosed months later. A final order on 15 July 2026 carried a $4 million judgment, suspended to $750,000 on inability to pay, in a matter that included allegations of employees posing as ordinary users.

So your exposure is not the probability that a regulator investigates your community programme. It is the probability that anyone opens on your business for any reason, multiplied by what your account history then contributes to the file. The first term is not small for a company of any size, and the second term is already written. That is the asymmetry: the conduct is discretionary, and the record is not.

A worked example: Kestrel Optics

Kestrel Optics is a Leeds direct-to-consumer prescription eyewear brand turning over £8.9 million, with a community programme that began in September 2024 and moved to an agency in early 2026. By August 2026 it ran four accounts: two staffed by employees, one operated by the agency under an enthusiast persona, and one belonging to the founder. Across twenty-six months the accounts had posted 312 comments, 47 of them carrying a link, and nine sat in threads that assistants retrieved for buying-intent queries about ordering glasses online in the UK.

In April 2026 the agency subcontracted “engagement seeding” at £340 a month: coordinated upvotes from a panel of accounts, timed to the first hour after posting. Nobody at Kestrel signed off on it specifically. It appeared on the invoice as a line item under community management.

In June 2026, moderators banned two of the four accounts after a member reported a cross-posting pattern. One hundred and eighteen comments went with them, including forty that had nothing promotional in them. By mid-July, two of the nine retrieved threads no longer surfaced Kestrel in assistant answers.

The August audit ran the Classification Ladder over all 312 comments. Rung one cleared almost everything: the subreddits were general discussion, not evaluation venues, so the American review sections were not live. Rung two caught 214 as business-caused. Rung three caught all 312, because every account belonged to an employee or an agent and not one disclosure sat inside a comment; three sat in profile bios, which 465.1(c)(4) does not accept. Rung four caught the entire April-to-June window, and rung four is the one disclosure cannot cure.

On the two surviving accounts, 194 comments remained, of which 12 failed the ladder incurably. That is an f of 0.062 and a Forfeiture Multiple of about sixteen: each of those twelve comments was risking sixteen times the value it produced, and the value it produced was one comment’s worth of retrieval presence.

The remedy was unglamorous. Engagement seeding was cancelled, saving £4,080 a year. Both surviving accounts began carrying an in-comment clause naming the employer on any post touching the category. And the honest cost, recorded rather than buried: median comment score on those accounts fell from 14 to 6 over the following eight weeks. Disclosure suppressed engagement, exactly as the sceptics predicted. What it also did was take removals to zero across the quarter, while the 118 comments on the banned accounts never returned and could not be rebuilt, because their value was their age. The loss that hurt was the ban, not the label.

The strongest version of the objection

Stated properly, the counter-argument is strong. No FTC matter has ever turned on a discussion-forum comment. The rule’s first stretch of enforcement produced ten warning letters and a pair of orders where the review counts rode along with other conduct. The CMA’s opening docket went to drip pricing and to review platforms, not to Reddit. Meanwhile disclosure has a measured cost in engagement, engagement is what surfaces a comment, and surfacing is the entire mechanism by which the comment earns anything. The objection is: you are proposing a certain loss to avoid a speculative one.

On regulators, that is conceded without qualification. Nothing here should be read as predicting an FTC action about Reddit, and a compliance argument that depends on one is worthless. Three things survive the concession.

  • The regulator is not the enforcer. Platform enforcement is running at industrial volume today, it is account-level, and it is the term in the expected-loss calculation that can actually be measured. Removing regulators from the model entirely leaves the case standing.
  • The trigger is not the conduct. Under the adjunct pattern, exposure is conditional on any investigation for any cause, and the record that would be read has already been written. You cannot improve it later without editing history, which creates a second and worse problem.
  • The cost claim is testable for the price of a quarter’s attention. Split the accounts, disclose on half, and measure removal rate, comment survival and citation persistence rather than upvotes. Nobody in this field has published that test, which is itself informative.

Two honest negatives belong on the record. The first is that disclosure probably does depress the signals that drive retrieval, because human discounting of vendor claims is precisely what an upvote measures; anyone selling compliance as free is selling something. The second is scope. Both regimes are consumer-protection instruments, so a genuinely business-to-business community presence — a private procurement channel, a closed practitioner group — carries narrower exposure. Narrower, not nil: paragraph 25 is about a trader misrepresenting themselves, and British advertising codes reach business audiences too. But the honest picture there is thinner than the picture painted above, and it should be stated rather than glossed.

What this changes about how you acquire links

Community link earning is the only acquisition channel in which the asset, the disclosure and the evidence are the same object, and none of the three is yours. You do not own a placement. You own standing in an account, on a platform you do not control, evaluated on its complete history by someone who owes you nothing. Every citation, mention and link the programme produces is a dividend on that principal, and the disclosure is the only thing that protects it.

That reframes the channel from a tactic into a concentration risk. A single ban can remove years of accumulated contribution in an afternoon, including the compliant part. An earned editorial placement on a publisher’s own domain does not behave that way, and nor do third-party listicle placements: they survive your account, your agency and your disclosure practice, because its custody sits with a third party who has their own reasons to keep it live. This is the same custody logic that makes Product Hunt launches and Hacker News threads high-variance rather than high-risk, and it is why local citations behave differently again.

So the allocation rule is not “stop using communities”. It is: use community surfaces for the work only they can do, which is answering a specific question in the voice of someone who has actually done the thing, and keep the claims your entity authority depends on somewhere whose custody does not sit behind a ban button. A published workspace page is only a partial escape, since its custody is still not yours. Treat the community account as an asset with a stated carrying cost, audit it the way you would audit a backlink profile, and price the disclosure into the plan rather than discovering it after a removal. Programmes that appear in training corpora through community surfaces inherit that same fragility, because a removed comment stops being refreshed even where an older copy persists.

THE MONDAY CHECKLIST

1. Pull every account your business or its agencies operate on community surfaces. Include contractor accounts. If you cannot produce the list in an hour, that is the finding.

2. Run the Classification Ladder over the last ninety days of each. Record f, not the promotional ratio, and compute the Forfeiture Multiple per account. No link building tool reports f for you; it is a manual count.

3. Read your agency contract for engagement, seeding, amplification or upvote language. Cancel anything that buys a visibility signal. Rung four is the only rung disclosure cannot fix.

4. Move every disclosure out of bios and flair and into the message body. One clause naming the employer, in the comment itself, unavoidable without a click.

5. If any of your buyers are British, stop reasoning from 16 CFR Part 465 and start from Schedule 20 paragraphs 13 and 25. The venue defence does not travel.

6. Do not delete historic posts wholesale. Edit to add disclosure where the platform allows it, and log what you changed. Deletion looks like concealment and removes the evidence that the rest was legitimate.

7. Split-test the cost. Disclose on half your accounts for a quarter and measure removal rate and citation persistence alongside engagement. Then argue from your own data.

The American rule asks where you posted. British law asks who you said you were. The moderator asks neither question, and answers first.

Leave a Reply

Your email address will not be published. Required fields are marked *

AI Advertising Disclosure Rules Previous post AI Advertising Disclosure Rules: What the 2027 Regime Means for Sponsored Citations
After NYT v OpenAI Next post After NYT v OpenAI: What the AI Copyright Rulings Mean for Content Strategy