A new investigation into abusive advertisements exposes a question for Latin American platforms and their customers: can a safety decision follow the advertiser, the campaign and the money through every handoff?
A paid advertisement passes through a commercial system that can identify an account, accept a creative, allocate distribution and record a charge. That creates several opportunities to enforce a safety decision. When prohibited material reaches an audience, the useful operational question is where those opportunities failed and whether the same failure can happen again.
On September 8, the Tech Transparency Project reported finding 332 advertisements containing AI-generated child sexual abuse material on Facebook and Instagram. Its parent organization, Campaign for Accountability, said additional advertisements appeared after an earlier batch had been reported, and that some were placed by advertising agency partners. These are the watchdog’s documented findings, rather than a comprehensive measure of all advertising on Meta. Campaign for Accountability’s public announcement.
Meta’s published safety policies prohibit content or activity that exploits or endangers children. That establishes the company’s stated rule; it does not establish how effectively every advertising pathway enforces it. Meta Safety Center.
For technology leaders, the gap between a rule and its execution deserves its own audit trail. The operating model below is an editorial proposal, not a description of Meta’s internal architecture or a claim that one control would have prevented the reported incidents.
Follow the complete commercial transaction
Consider a hypothetical marketplace that sells sponsored listings through several agencies. Its creative review team can reject an advertisement, its account team can suspend a buyer, and its commercial team can end an agency relationship. Each action is useful. The control remains incomplete if the decision cannot be associated with the same campaign across those systems.
An internal record should connect the responsible advertiser, authorized intermediary, campaign identifier, creative reference, review decision, policy version, delivery state and relevant billing events. Access to that record should depend on the employee’s role. Customer-facing reports should disclose the minimum information necessary to explain an action.
The goal is to answer a bounded question: after a serious safety decision, which connected delivery paths were stopped, when did they stop, and who verified completion? A rejection ticket alone cannot answer that. Neither can a large aggregate removal count.
Australia’s eSafety Commissioner frames Safety by Design around provider responsibility, user empowerment, and transparency and accountability. Those principles support assigning responsibility throughout a service’s lifecycle rather than leaving users to discover and report every failure. eSafety: Safety by Design.
Treat intermediaries as part of the control boundary
An agency relationship introduces delegation. A platform may know the agency while having weaker visibility into the customer behind a particular campaign. A brand buying distribution may know its marketing partner while lacking a clear view of the downstream suppliers involved.
Procurement should make those relationships legible. Agreements should specify who verifies the advertiser, who responds to a serious incident, which records can be supplied, and what authority the platform retains to suspend distribution. A partner designation should carry measurable responsibilities and review dates.
NIST’s supply-chain guide provides a useful governance reference: it addresses establishing a cybersecurity supply-chain risk capability and communicating requirements to suppliers. Applying that discipline to an advertising relationship is an analogy; the guide does not certify advertising safety or prescribe this article’s controls. NIST SP 1305.
The practical extension is to assess a partner’s response under stress. Can it identify the responsible customer promptly? Can it stop a campaign across the channels it manages? Can it produce a consistent incident record? A questionnaire completed at onboarding provides little assurance about those capabilities months later.
Measure containment and recurrence
An executive dashboard should distinguish initial detection, containment and prevention of recurrence. They describe different stages of a response, and improving one does not prove improvement in the others.
Detection metrics should show how serious reports reach the responsible team and how long they wait. Containment metrics should record the interval between a confirmed decision and the end of active delivery. Recurrence metrics should track subsequent incidents associated with an already reviewed campaign or responsible entity, subject to appropriate confidence thresholds and appeal mechanisms.
The denominator matters. A percentage calculated from reviewed advertisements cannot describe all advertisements if the review sample is selective. A count of removals can rise because detection improved, abuse increased, or both. Reports should state the population, observation window, sampling limits and unresolved cases alongside their headline numbers.
False positives also impose costs. A system that suspends legitimate campaigns without a clear reason or workable appeal route can harm smaller businesses with limited operating reserves. Safety controls therefore need accountable review, proportionate restrictions and a way to correct erroneous decisions without silently erasing their history.
Build the evidence trail without spreading harmful material
An ordinary procurement team does not need to reproduce abusive advertisements to evaluate an incident response. It needs evidence that authorized specialists reached a decision, distribution stopped, associated systems received the decision, and the response was checked.
Design the record around case identifiers, controlled references, timestamps, decisions and receipt confirmations. Keep any legally required evidence handling with qualified personnel under the applicable rules. General dashboards, analytics exports and vendor presentations should not become additional repositories of harmful material or children’s personal information.
This boundary also improves operational clarity. A marketing manager can see that a campaign is suspended and who owns the case. A specialist can access the evidence needed for review. An auditor can inspect the sequence and verify that required controls operated. Those roles need different views of the same incident.
Testing should use benign fixtures and controlled simulations. For example, create an internal test campaign, issue a simulated severe-policy suspension, and verify that every connected delivery component acknowledges it. Then measure how the process handles a delayed response or a failed integration. The exercise evaluates the workflow without generating or distributing abusive content.
Brazil makes the regional question concrete
Brazil’s ANPD required covered platforms with more than one million registered users under 18 to publish their first ECA Digital transparency report by September 17, 2026. Its guidance calls for information about reporting channels, moderation, measures to identify unlawful activity and child accounts, and risk-assessment methods and results. The initial reporting period generally covers January through June, with a specified allowance for platforms lacking earlier systematic records. ANPD’s reporting guidance.
That is a Brazilian requirement with a defined scope. It should not be presented as a uniform rule across Latin America or as a duty imposed on every advertiser. Its operational significance is broader: credible transparency depends on records that already exist inside the service.
A regional company can begin by mapping the jurisdictions, products and suppliers relevant to its own operations. Legal teams determine applicable obligations; product, security and commercial teams make the resulting controls executable. A shared evidence model can support that coordination while preserving differences between national requirements.
Ask for a demonstrated response
At the next platform or agency review, choose one controlled incident scenario and request a demonstration. Trace the decision from intake to review, suspension, downstream acknowledgment, verification and appeal. Name the owner at every handoff and record the evidence each step produces.
Then examine the commercial incentives. The people responsible for stopping a harmful campaign need authority that survives pressure to preserve spend or meet a delivery target. Exceptions should require an accountable decision and remain visible to oversight.
The strongest procurement question is whether the provider can demonstrate a complete, timely response when a serious safety rule is triggered. Policies establish expectations. An audit trail shows which actions followed, where delays occurred, and what still requires repair.
