Meta’s new “Facebook Verified” badge - initial observations and questions

Summary
On Friday 24 July 2026, Meta announced “Facebook Verified”, a free badge based on a video selfie, with rollout beginning on Monday 27 July.
The timing is interesting. The UK Online Safety Act 2023 (the “Act”) requires the largest platforms to offer their users the option to verify their identity (section 64), and to offer adult users a feature which filters out non-verified users (section 15(9)). Two weeks before Meta’s announcement, on 10 July, Ofcom published its register of categorised services, which designates Facebook as a Category 1 service, and opened its consultation on how Category 1 providers should meet the user identity verification duty in section 64 and the filter on non-verified accounts in section 15(9). That consultation closes on 2 October.
So one of the platforms most obviously in scope has launched a verification scheme of its own design, in the middle of the process that will determine what verification has to look like under UK law. It is not clear whether Meta intends the scheme to help meet the requirements of the Act or is rolling it out for other purposes, but the timing makes it worth asking whether it would. We use Facebook Verified as an opportunity to test how the draft User Identity Verification Guidance (the “Guidance”), which Ofcom has issued for consultation under section 65 of the Act, would work in practice.
Based on the very limited information available about Facebook Verified, it does have positive aspects. Meta says the badge is free and will be visible, and has told reporters that eligible users will be prompted to take it up, although it has not said so in its own published material. However, it also has significant drawbacks. The stated purpose is vague and is not tied to any specific risk associated with fake and anonymous accounts on Facebook. The check appears to be purely between two user-provided likenesses, with no independent source. There is no explanation of how it would prevent circumvention using synthetic identities, and no stated limit on how many accounts one face may verify. There is no mention of triggers to re-verify if characteristics change and no periodic re-verification. Meta has published no targets or documentation beyond a very short blog post, and nothing on how data will be handled from a privacy perspective.
Despite these shortcomings, we find that, due to the extensive flexibility which Ofcom proposes to hand platforms in its draft Guidance, Facebook Verified would arguably satisfy many aspects of it. The Guidance gives the regulator no clear basis for challenging the vagueness of the scheme’s purpose. Nor does it require Meta to record how it applied the Guidance, as documentation is only “encouraged”. And because the four principles which schemes are meant to satisfy are largely measured against the provider’s own purpose, a vague purpose gives them limited bite. The principle against which Facebook Verified seems most likely to fall short is “reliability”, where the Guidance is at its most substantive. Elsewhere, loose wording - such as saying only that schemes should check more than one attribute “in most cases” - makes it hard to say for certain how the scheme would be judged overall.
And even if Ofcom were to conclude that Facebook Verified does not satisfy section 64, the absence of any standard governing what counts as verification for the purposes of the section 15(9) filter means that Facebook Verified accounts could well pass through a future filter, and be seen by UK users who have opted to turn it on.
We observe that Facebook Verified is also not caught by the existing measure on profile labelling schemes in Ofcom’s illegal content Codes (ICU J3), which covers only paid-for and “notable user” labels. That gap follows from Ofcom’s own decision in 2024 to leave verification to the process now under consultation.
We then step back from Ofcom’s approach and consider how Facebook Verified matches up against the standards for verification schemes which we have previously proposed - finding that in many areas it falls short, with significantly more shortcomings than the LinkedIn scheme which we assessed in a similar way previously.
We conclude that Facebook Verified shows platforms recognise user appetite for verification and can offer it free of charge, but that it falls short of what users should be offered - underlining the need for Ofcom to set clear safety objectives and objective standards, including for how robust a scheme must be to pass the section 15(9) filter.
These are initial observations. Meta’s announcement is short, and some of what has been reported comes from press briefings rather than published Meta material. We have not so far been able to carry out a verification to check how it works in practice as it does not yet appear to be live in a country where we are located. We would welcome corrections or supplementary information.
What Meta has announced
Meta’s stated rationale for the new Facebook Verified badge is: “As AI makes it easier to generate content, profiles, and messages, we want to provide a way for you to know there is a real person on the other side of a profile.”
The mechanism is described as follows: “You record a short video selfie, which we check against your existing profile photos to confirm a match. The process is free and typically takes just a few minutes.”
Eligibility is for users who are “18 years and older on Facebook who are in good standing with our Community Standards, specifically those prohibiting fraud, scams, and deceptive practices, and who exhibit no evidence of inauthentic behavior.”
It is “not available for Pages or ProMode accounts”, and is rolling out “in phases, starting in select markets with plans to expand globally.”
On visibility and prominence of the scheme, Meta says “Once verified, your badge will appear across the places on Facebook where it matters most: Marketplace, Dating, Groups, and Profile to start. Over time, we’ll add badges in Feed posts as well.”
On cost, Meta states, “There’s no subscription fee - you verify once, and the badge travels with you across Facebook.”
What does the new badge signify exactly? Meta states that “The Facebook Verified badge means a profile belongs to a real person - someone who completed selfie verification and meets our trust and safety standards.” But it then goes on to offer an explicit disclaimer: “The Facebook Verified badge does not mean that Facebook endorses the user or guarantees their trustworthiness.”
Meta presents Facebook Verified as separate from Meta Verified, the paid subscription for creators and businesses. According to Meta, the Meta Verified badge means a profile “was verified by Meta based on your activity across Meta technologies, or information or documents you provided”. Subscribers “may need to upload photos of a valid photo ID” and may be asked for a video selfie, which human reviewers compare with the profile picture.
Notable silences
Meta’s announcements about Facebook Verified together run to only a few hundred words. They leave many questions unaddressed, including which markets it will be made available in. Meta did not name them at launch and, more than two months on, had still not done so as of 21 September 2026. We have not been able to access it in either the UK or Belgium, but this may vary for others. Whether the UK and EU are included and if so, when, is unknown.
Could Facebook Verified comply with Ofcom’s draft Guidance on section 64 of the UK’s Online Safety Act (user verification)?
Ofcom’s Guidance regarding section 64 of the Act “recommends that providers should design, operate and communicate their verification schemes” consistently with four principles: “relevance”, “reliability”, “inclusivity” and “clarity” (3.1). “Relevance” should be determined by reference to the purpose of the scheme (3.4).
Ofcom states: “When considering whether a provider has complied with [the user identity verification duties], we will take into account whether it has acted in accordance with this guidance. We encourage providers to document how they have taken our guidance into account when designing and implementing their verification scheme” (2.7).
Meta has published nothing about how it determined the scheme’s purpose or took the four principles into account, nor any targets for uptake or effectiveness. Ofcom could ask for internal records, but because documentation is only “encouraged”, not required, there may be nothing to ask for. That leaves Ofcom assessing the scheme itself, with few objective standards to assess it against, as the analysis below shows.
Purpose - Facebook Verified may pass
The first principle is relevance, and the first step in determining relevance is to determine the purpose of the scheme. Providers are to decide the purpose of their scheme, “that is, what the scheme sets out to do and how it will do it” (3.4). The Guidance explains that, “[i]n deciding the scheme’s purpose(s), providers should take into account the nature of their service, its user base, functionalities and the way it is used (including which users are likely to want to verify and why), as well as the type and levels of risk on the service” (3.4).
Meta states that “As AI makes it easier to generate content, profiles, and messages, we want to provide a way for you to know there is a real person on the other side of a profile.” This will be done by the user recording “a short video selfie, which we check against your existing profile photos to confirm a match.”
As noted above, this is vague, but it is all we have to work with. It does (barely) describe what the scheme sets out to do and how it will do it. Has Meta taken into account the “type and levels of risk on the service”? Meta’s stated purpose is about fake and AI-generated profiles in general. Its second announcement, published alongside Facebook Marketplace’s tenth anniversary, ties the badge to transactions and to “credibility and peace of mind that the person is real”. But it identifies no harm the scheme is meant to reduce, and the purpose is not tied to any specific risk on Facebook - fraud in Marketplace, romance scams in Dating, foreign interference - and Meta has not explained why a photo match is the right response to any of them. But Ofcom’s proposed Guidance does not require the purpose to improve safety, or to address the main risks associated with anonymous or fake accounts identified in the platform’s risk assessment. Overall, the Guidance does not set out a clear basis for challenging a vague and limited purpose, and so Facebook Verified’s purpose would probably pass.
Relevance - Facebook Verified may pass
Ofcom “recognise that in reality providers can never be completely certain as to a user’s identity” (2.11). The Guidance states that “There are a wide range of attributes which could be used to verify an identity, and some will be more relevant than others in different cases, depending on what the scheme sets out to do. This principle aims to ensure the identity attributes chosen, and the methods for checking them, support the overall purpose(s) of the verification scheme” (3.3).
With no published explanation from Meta, and no requirement on Meta to record one, how is Ofcom to assess whether the attributes chosen, and methods for checking them, support the purpose? The Guidance does list “facial similarity” as an example of a potentially valid identity attribute (2.15) and “automated detection of facial likeness, such as one-to-one facial recognition technology” as a potentially valid checking method (2.16). But is it sufficiently or appropriately relevant? Would other attributes and methods be more relevant? Beyond one illustrative example - a scheme to confirm that a user works for a particular organisation - the Guidance does not attempt to define which attributes or methods are relevant to which purposes, or set objective standards for when a person’s identity can be considered verified. It just refers back to “what the scheme sets out to do.” Where the purpose is as vague and general as Facebook Verified’s, this leaves maximum flexibility for the provider and makes it difficult for a regulator to challenge the choice made.
Ofcom says attributes should be “sufficient in number and significant enough in nature when combined to tell the provider something meaningful about the individual” (3.7), and notes in a footnote that more than one attribute will be needed “in most cases” (footnote 17). Meta checks only one attribute, so Facebook Verified could be challenged on this basis. But “in most cases” is a significant softening of how Ofcom put the same point in Volume 2 of this consultation, which said that a combination of attributes would be needed “in almost all cases” (consultation Volume 2, 11.63). The weaker formulation is the one in the Guidance, and it is the one a platform will rely on: Meta could argue that a live selfie video is sufficient for this particular purpose. The Guidance should use the stronger wording.
Reliability - Facebook Verified probably does not pass
The Guidance requires that a scheme must be reliable “so that providers can have confidence that users actually have the attributes they claim to have, and users have confidence in the process” (3.1, Table 1). First, there should be no self-declaration: providers should check claimed attributes “against a source separate and independent from the user claiming the attribute” (3.13-17). Second, anti-circumvention: providers should identify and mitigate misleading techniques “easily accessible to users”, such as impersonation, faked attributes and the buying and selling of verified accounts (3.18-20). Third, where a user changes a verified attribute in a way that suggests a risk of harm, re-verification may be required (3.21-24). Fourth, currency: attributes go stale, so providers should consider “offering users the option to verify regularly or make clear to other users when the user was last verified” (3.25).
We do not know whether and how Meta considered this principle in designing Facebook Verified. As with purpose and relevance, the lack of documentation is not fatal in itself, but it leaves us assessing reliability with minimal objective standards.
The first element of reliability is that the provider should check attributes against “a source separate and independent from the user claiming the attribute.” Facebook Verified compares a selfie video with profile photos the user uploaded themselves. Both sides of the comparison come from the user, so on the plain wording of the Guidance the check does not meet this test. The Guidance does accept one-to-one facial recognition as a valid checking method (2.16), but that goes to how a comparison is made, not to what it is made against. (Contrast LinkedIn, which checks against government-issued documents through a third-party provider.)
Meta does not explain how the verification method would address the second element, namely mitigating circumvention efforts, particularly AI forgeries. Meta makes no mention of liveness detection, presentation attack detection, or defences against injection attacks, despite the growth of AI being the stated rationale for offering the scheme now. Meta’s check only requires internal consistency between two artefacts the same person controls. There is potential for someone building a synthetic persona to generate the profile photographs and then generate a matching video. They never need to resemble a real person - only to resemble themselves. The check therefore seems to work best in the most naive case, someone using stolen photographs of a real stranger, and weakest against sophisticated bad actors. There is also no mention of how it would address the buying and selling of verified accounts.
Meta is silent about the third and fourth elements too, ie re-verification where a verified attribute changes and regular re-verification in all cases. Meta describes a one-time process. It says nothing about whether verification is ever repeated, what happens when a verified user changes their profile photo, or in what circumstances a badge is withdrawn. Ofcom’s Guidance contains a worked example of a reliability risk (3.21) in which a user verifies facial likeness with a selfie, displays that photo publicly, and then “could then change their photo to impersonate someone else”, noting that other users will believe the displayed likeness has been verified. That describes a risk in Meta’s design almost exactly, and Ofcom’s recommended mitigations - re-verification, and removal of verified status where a user will not or cannot re-verify - go to the heart of the problem.
The Guidance on reliability is sufficiently substantive that it appears the hardest principle for Meta to argue that Facebook Verified satisfies (absent other information).
Inclusivity - potential problems, insufficient information
The Guidance requires that the process must be inclusive “so that no adult user is unduly excluded from being able to verify.” Again, we do not know how Meta considered this, if at all, and can only try to work backwards from how the system works. There is no charge, which avoids excluding low-income groups (3.37), and no requirement for specific documents, which avoids excluding people who do not have them (3.35). There are however some limits. The user needs a camera, and must use a photograph of their own face as their profile picture. Facebook profile pictures are public, so verification depends on showing your face to everyone - a real barrier for some of the groups Ofcom itself identifies at 3.30, including people at risk of domestic abuse. In addition, facial recognition has its own well-documented bias issues; Ofcom warns of differential accuracy “for users of a certain ethnicity” (3.31). Meta has not explained how it assessed these barriers or weighed the trade-offs.
Clarity - insufficient information, application of Guidance unclear
The Guidance states that the process must be clear “so that users understand what identity verification means in practice on the service” (3.1, Table 1). The process must be clearly explained in statutory terms of service and should also be explained at the point verification is offered (3.39). At the point of verification, the provider should also state clearly “whether verified users and their content may be treated differently from other accounts” and if so, how (3.46). We have not been able to check how well these issues are explained at the point verification is offered as it does not appear to be available where we are located.
The Guidance defers to providers to decide whether or not to make the verification status visible (3.50). If it is visible, “information should be provided on which scheme the user has verified under” (3.52). Meta states the badge will be shown across Marketplace, Dating, Groups and Profile, and later in feed posts. It is unclear whether it will be visible in comments and messages. How will this badge be presented, and how will confusion with other “verified” schemes be avoided? Meta has not explained how the free badge is distinguished from the paid Meta Verified tick, or what users are told at the point of display (see also below on ICU J3). Press reports even disagree about what the badge looks like. According to one report, “[p]eople can tap the badge for an explanation of what it does - and does not - mean” but we have not seen separate confirmation of this. Absent more information and/or the ability to check how the scheme works in practice, we cannot assess whether the clarity principle is met.
Privacy - insufficient information
The Guidance does remind providers of the need to comply with data protection law (3.10, 4.7-8). Meta has not provided information about this. How is data handling and privacy addressed? Where will the selfie video be stored? Meta has told reporters that the video and the related facial data are deleted within 30 days of verification, but this does not appear in its published material, and Meta says nothing about what is retained in the meantime or what, if anything, persists afterwards. For what will data be used? Who is the controller? Will it be used to feed other systems? Meta’s existing facial recognition process (used to check images of public figures and high-profile individuals, confirm the identity of users who have lost access to their accounts and identify prohibited content) generates a numerical facial embedding. If the same or similar technology is used for Facebook Verified, the same privacy questions arise for the embedding data.
Does Facebook Verified meet the requirements for filtering (section 15(9))?
Neither the Facebook Verified announcement nor the reporting around it mentions an accompanying option for users to filter out non-verified accounts. Meta has announced no filter to go with the badge, so on its own Facebook Verified does nothing towards the section 15(9) duty.
However, Facebook Verified is potentially relevant to the implementation of a section 15(9) filter, because it is a verification scheme to which the filter may in the future apply.
The relevant measure is recommendation ADU A8 of the draft Additional Duties Code of Practice for Category 1 Services, and Ofcom sets out its reasoning in Volume 2 of the consultation: “A user does not have to be verified under section 64 in order to be verified for the purposes of the filter tool” (consultation Volume 2, footnote 246), and “a user can be verified under any identity verification scheme in order to be verified for the purposes of the filter tool, not only the user identity verification scheme offered pursuant to section 64 of the Act” (footnote 262).
The Act itself supplies no standard: it defines a non-verified user simply as someone who “has not verified their identity to the provider of a service” (section 16(7)). It therefore seems likely that accounts which have been verified according to the Facebook Verified scheme could be considered as “verified” for the purposes of any future filter, and therefore continue to be able to interact with UK users who have activated a filter on non-verified accounts.
The illegal content Codes do not reach Facebook Verified either
Ofcom’s illegal content Codes of Practice already contain a measure on profile labelling schemes. Recommendation ICU J3 has been in force since Monday 17 March 2025. It applies to large services at medium or high risk of fraud or the foreign interference offence that label user profiles under a “notable user scheme” or a “monetised scheme”. Where it applies, providers should have documented criteria for adding and removing labels. They should have safeguards against a labelled profile being altered to suggest it belongs to someone else, and a stated frequency for reviewing labels. On the profile itself, they should explain why it is labelled and under which scheme, backed by a clear public description of the scheme. Ofcom designed the measure “to mitigate the risks from impersonation, a tactic used by perpetrators engaging in forms of fraud and foreign interference” (illegal harms statement, Volume 2, 12.146). In the same paragraph it warns that “poorly operated and communicated schemes may introduce more risks than benefits for users who place trust in them”.
Facebook Verified falls between the two definitions. It is free, so it is not a monetised scheme. Its stated purpose is to show that “a profile belongs to a real person”, rather than that the account is notable, so it is not a notable user scheme either. ICU J3 does not apply to it. Yet the risks behind the measure are plainly present. Ofcom’s own risk profiles list fake user profiles as a risk factor for both fraud and foreign interference, and Meta is launching the badge in places including Marketplace and Dating. Lloyds Banking Group reports that, of the fraud reports its customers make, “around seven in 10 (68%) are shopping scam cases, starting on a Meta platform, such as Facebook, Instagram or WhatsApp” (Lloyds Banking Group, 8 June 2026). The scheme also recreates the confusion Ofcom pointed to when it drafted ICU J3: a paid tick and another tick side by side on the same service (illegal harms statement, Volume 2, 12.199). And because Facebook Verified is not a “relevant scheme”, nothing in ICU J3 requires a Facebook Verified profile to explain what its badge means or how it differs from Meta Verified.
This gap did not arise by accident. When Ofcom finalised ICU J3 in December 2024, it deliberately kept identity verification out of it. It said it would consider verification in its work on the categorised services duties, “to take a holistic view on the issue” (illegal harms statement, Volume 2, 12.218). The draft Guidance is that work. Yet it carries across only one of ICU J3’s protections for users who see a badge - saying which scheme a visible badge was issued under (3.52). Whether verified status is shown at all is left to the provider (3.50), explaining on the profile what a badge means is optional (3.51), and there is no requirement for a public description of the scheme of the kind ICU J3 recommends.
Would Facebook Verified meet the criteria proposed by Clean Up The Internet?
In a 2024 submission to Ofcom we set out eight criteria for assessing a verification process: accuracy, robustness and reliability; accessibility; affordability; visibility of verification status; account security and user authentication; privacy and data security; encouraging user awareness and uptake; and interoperability and user choice. We applied them to LinkedIn in a case study published on this site in June 2026. Here we apply the same eight to Facebook Verified, with two additions: purpose, and coverage.
Purpose - weak
We did not include purpose as a criterion in 2024: given the aims of the Act, it did not seem to need saying. Ofcom’s draft Guidance shows that it does.
In announcing Facebook Verified, Meta refers only in general terms to confirming that there is a real person behind an account (while creating a scheme that is far from watertight in doing so). It does not connect this to any specific risk on the platform, explain why confirming that a profile picture is a true likeness is the best way to achieve it, or say which harms the scheme should help tackle.
Clean Up The Internet developed our proposals for voluntary user verification as a safety measure, with the purpose of mitigating the harms associated with fake and anonymous accounts. A scheme which does not set out how it will improve safety falls short.
Accuracy, robustness and reliability - weak
As set out above, both sides of the comparison come from the user, nothing external is consulted, and there is no re-verification.
Nothing in Meta’s stated eligibility criteria prevents one person from verifying many accounts, and Meta has not said whether it checks a new verification against faces already verified on other accounts. Profile photos are retained and public, so Meta could in principle check for duplicates without keeping the selfie video. If it does not, one person could verify several accounts, and a user banned for violating the Terms of Service could obtain verified status for a “phoenix account”. If it does, that raises privacy questions of its own.
While buying and selling accounts is against Meta’s Terms of Service, and Meta regularly publicises action to remove such accounts, it is widely accepted that in practice enforcement is patchy, and a significant underground market exists for aged and SIM-verified accounts. Meta’s announcements for Facebook Verified make no mention of measures to prevent the buying, selling or transfer of selfie-verified accounts. A badge that could be obtained for many accounts, or sold on, would undermine the very thing it is meant to signal.
Accessibility - mixed
Facebook Verified does not require any specific official document, which avoids excluding users who do not have one . But, as noted above, it depends on a public photograph of the user’s own face, which excludes those who cannot safely show one, and facial recognition error rates can vary by ethnicity. Meta has published no accessibility assessment, no error rate data, and no breakdown of who is excluded.
Affordability - strong
Facebook Verified is free, with no subscription, so cost is no barrier to lower-income users, and verification is not bundled into a premium tier. This is the best feature of the scheme and the most useful precedent - it surely makes it harder for other platforms to argue to a regulator that offering a free scheme would be unduly burdensome.
Visibility of verification status - mixed
It is welcome that the badge will be displayed in several places. But it is not clear how it will be told apart from Meta Verified, it will not appear in feeds at launch, and Meta has said nothing about comments and messages. LinkedIn’s approach, where clicking the tick shows what was verified, by what method and when, sets the benchmark. One report suggests Facebook Verified’s badge can also be tapped for an explanation, but we have not been able to see what it says.
Account security and user authentication - unknown
A verified account is a more valuable target, so account security and recovery matter more once a badge is attached. Meta has not said whether verified users are prompted towards two-factor authentication, what happens to a badge if an account is hijacked, or whether recovering an account requires re-verification. Ofcom’s own labelling measure expects providers to record whether labelled users are treated differently, including in relation to account security (ICU J3.3(e)). The draft Guidance asks for nothing equivalent.
Privacy and data security - unknown
As set out above, the only published detail is a press briefing that the video and related facial data are deleted within 30 days. Where the data is stored, who controls it, whether a facial embedding persists and what else it may be used for are all unknown.
Encouraging user awareness and uptake - no commitment
A Meta spokesperson has told Inc. that eligible users will receive prompts on their profile or within Marketplace, Groups or Dating, rolling out over the coming months. That is a briefing to a journalist rather than a published Meta commitment, and we have not been able to view or assess any prompts in practice.
Meta has published no targets, no plan to collect data on effectiveness or impact, and no commitment to measure or publish results. LinkedIn, by contrast, set a public target of 100 million verified members when it launched verification in 2023, reported progress as it went (55 million in October 2024, 80 million in April 2025), and said in December 2025 that it had reached it.
Interoperability and user choice - none
Meta has not said that it will recognise verification or accept credentials from DIATF-certified providers, eIDAS 2.0, or any other framework, and has not published any outbound offer to share recognition with other providers.
Coverage - Pages and ProMode excluded
Pages and ProMode accounts are excluded, so the scheme does nothing for account types that feature in coordinated inauthentic behaviour: Meta’s own adversarial threat reports routinely record Pages removed alongside accounts in network takedowns.
What testing Facebook Verified tells us about Ofcom’s draft Guidance
Applying Ofcom’s Guidance to Facebook Verified highlights how (overly) flexible the Guidance is. The starting point of an assessment under the Guidance is Meta’s statement of what the purpose of the scheme is. Meta’s statement is vague and is not tied to the risks that Ofcom’s own risk profiles associate with fake accounts, but in the absence of any minimum standards in the Guidance, it could potentially be sufficient. Ofcom’s proposed laissez-faire approach to platforms setting the purpose of a section 64 scheme would make it hard for Ofcom to push Meta towards improvements which would deliver meaningful safety benefits for UK users, or address the harms around fake and anonymous accounts that Ofcom itself has identified. Ofcom should require schemes’ purposes to be relevant to improving safety and addressing the risks with fake and anonymous accounts identified in their risk assessments.
Turning to the principles, the Guidance indicates that Ofcom will take into account whether a platform has considered the principles, but when there is no documentation about the design of the scheme (as here), this leaves the regulator having to assess outcome without clear objective standards. The principles assessment sits inside a framework where the purpose is set by the provider - so Meta’s very modest purpose means a modest assessment of the principles. Facebook Verified would struggle to pass the reliability test and raises inclusivity questions, but arguably it can satisfy relevance (we could not yet assess clarity). Ofcom should set minimum objective standards for a verification scheme.
It is worth being clear about how much the principles could ever achieve, even applied firmly. Three of the four take the scheme’s design as given: relevance is defined by reference to the purpose the provider has chosen (3.3, 3.4), clarity asks whether users understand what verification means on that service, and inclusivity asks whether adult users are unduly excluded from the scheme as built. None supplies a reason to build a different scheme. Only reliability has free-standing content, because it asks whether a scheme does reliably what it claims to do rather than whether the claim was worth making.
That is a real constraint and we would not want it weakened. But it can only close off the routes by which a scheme becomes actively misleading - circumvention, impersonation after the fact, the sale of verified accounts. It cannot turn a scheme that is not addressed to the harms on the service into one that is. Facebook Verified with liveness detection, defences against injection attacks, a cap on the number of accounts one face can verify and periodic re-verification would be a much better scheme. It would still be a scheme whose stated aim is to confirm that a profile photograph resembles the person using the account. The only lever capable of pointing a scheme at harm is the purpose, and that is the one Ofcom proposes to hand over in full.
Meta has not built the filter which section 15(9) will require once the additional duties come into force. However, on Ofcom’s current proposals, if Meta did set up such a filter, users with a Facebook Verified badge (with no changes to the current scheme) could all be considered as verified for the purpose of passing the filter. The lack of any guardrails, in either the Guidance or the draft Code, around what passes for a verified scheme for the purposes of section 15(9) is a major loophole. A platform could establish both a section 64 scheme (to satisfy the Guidance) and a non-section 64 scheme (that is less protective of users), promote the latter but not the former, and enable all users of either scheme to pass through a filter. Facebook Verified demonstrates this is not a theoretical risk. This could mean that a UK user who chooses to activate the filter is still exposed to accounts which are not verified to even the Guidance’s own minimal principles. This would make the filter meaningless, or even actively unhelpful. Ofcom should make it clear that only section 64 schemes can pass the section 15(9) filter on non-verified accounts, or else establish other objective standards such schemes must meet in order to pass the filter.
Two other aspects of Facebook Verified can strengthen the regulator’s hand. First, by introducing Facebook Verified, Meta acknowledges that users have an appetite for verification schemes, and that the rise of AI-generated content and personas is increasing this appetite. Second, Meta is making its new scheme free and visible, and has told reporters that it plans to prompt users to take it up. These are choices Ofcom does not require, and which we have argued regulators should require. Meta having made them voluntarily makes it considerably harder for platforms to argue they are disproportionate.
How would Facebook Verified fare under the EU’s Digital Services Act?
Even if the circumvention and reliability questions were resolved, it is not clear that Facebook Verified would do much against foreign information manipulation and interference (FIMI), a primary concern of the EU’s DSA. Most fundamentally, Meta makes no mention of FIMI or disinformation in its stated purpose for the scheme, and does not offer any analysis of its own as to how Facebook Verified could help disrupt influence operations.
To the extent that FIMI relies on bot networks, they can create synthetic personae and Facebook Verified does not appear to have the capacity to detect this. FIMI also runs through paid human operators, contractor troll farms and recruited locals, all of whom have real faces and could presumably therefore pass this check. Whether bot or human, what defines FIMI is coordination, concealed origin and undisclosed backing, none of which a face check touches.
A more rigorous voluntary verification scheme would not completely block such activity. But by verifying more than one identity attribute, and focusing on the attributes most relevant to FIMI, it would make such activity significantly harder. It should not allow a bot to be verified. It should prevent a real human from being able to generate an unlimited number of verified accounts. It could anchor verified accounts to real world identities, making phoenix accounts more difficult and users more traceable in the case of criminal activity. It could make it harder for fake accounts to switch names or adopt different false names for different campaigns, or to make false claims about where they are located. And if they choose not to verify due to such friction, then a proper filter system should be able to exclude them.
Three features of the design of Facebook Verified compound its limitations for preventing disinformation. Pages are excluded altogether, and a great deal of influence infrastructure sits there. Badges are not on feed posts at launch, which is where influence content actually travels. There is no filter and no stated ranking effect, so unbadged accounts lose nothing in terms of visibility.
There is a risk Facebook Verified makes things marginally worse. A badge attached to a persona run by a paid human operator is a credibility upgrade, bought for the price of a selfie. The proliferation of unreliable verification schemes may be counterproductive, undermining users’ confidence in any verification scheme and diluting public appetite for verification.
The one clear DSA precedent on verification labels points the same way. On 5 December 2025 the European Commission found that X’s blue checkmark was a deceptive design practice - one of three breaches for which it fined X €120 million, the first non-compliance decision under the DSA (European Commission). A verification label that promises more than the check behind it delivers is, in the Commission’s view, a DSA problem.
EU officials should note that this is what a platform produces when left to design its own scheme: it falls well short of tackling the systemic risks the DSA and the Democracy Shield are concerned with. The case for making verification an obligation, with defined standards, is strengthened rather than weakened by this launch.
Conclusion
The launch of Facebook Verified represents a valuable opportunity to test Ofcom’s Guidance with a live case.
Meta’s decision to offer a free and visible verification scheme, which Meta has told reporters it plans to prompt users to take up, is in many ways a welcome step. Apart from anything else, it indicates that platforms recognise growing user demand for such measures, and that it is not disproportionate for regulators to require them.
However, as is generally the case with voluntarily offered safety measures from social media platforms, Facebook Verified falls short. Meta does not tie the scheme to any specific risk on its platform, and a one-time selfie comparison against the user’s own photos does not appear to address AI-generated personas, account trading or multiple accounts.
Ofcom’s draft Guidance leaves substantial ambiguity regarding how platform-designed verification schemes are to be assessed for compliance, to the point where, despite the shortcomings of Facebook Verified, it is conceivable that it could be deemed to comply with the Guidance in many respects. Its four principles can limit the ways in which a scheme is actively misleading, but they cannot make a scheme which is not directed at harm into one which is. In addition, neither the draft Guidance nor the draft Code sets any standard which a verification scheme must meet before its users count as verified for filtering purposes. On Ofcom’s own reading of the Act, that allows the users of a non-section 64 scheme such as Facebook Verified to pass through a section 15(9) filter. This leaves open a wide loophole where the feed of a UK user who activates the filter could remain populated by inadequately verified accounts.
Ofcom can close these gaps before the Guidance is finalised. It should require a scheme’s purpose to be tied to improving safety and to the risks identified in the service’s risk assessment; set minimum objective standards for verification, starting with its own “almost all cases” wording on the number of attributes; make clear that only section 64 schemes, or schemes meeting equivalent standards, can pass the section 15(9) filter; and ensure that any scheme which visibly labels a profile as verified carries at least the protections Ofcom already recommends under ICU J3.4.
From an EU perspective, Facebook Verified illustrates the limitations of relying on voluntary platform measures under the Digital Services Act (DSA). The scheme lacks any apparent focus on disrupting FIMI or disinformation, and this is reflected in design choices such as excluding Pages and leaving badges off feed posts at launch. European regulators should recognise that addressing systemic risks and protecting democratic integrity requires mandatory, standardised verification benchmarks rather than flexible, platform-led implementations.




Comments