The ad was fine. The page it led to was the breach
Two brands bought one promotional package. The Instagram ad passed. The landing page it pointed at did not, and the phone call meant to keep them apart was never written down.
By Katie Delaney · 2026-08-06 · 19 min read
A paid package, a phone call, and the brand safety gap that became an ad#

Two brands bought one promotional package. The paid social ad passed. The page behind its Learn more link did not. On 5 August 2026 the Advertising Standards Authority published ruling A26-1329510 against Costcutter Supermarkets Group Ltd and Mondelez Europe Services GmbH, UK branch, trading as Cadbury, and upheld the complaint in part: the Instagram creative was cleared, the destination it drove traffic to was found to be paid-for advertising space, and in breach ASA ruling A26-1329510. For a decade brand safety has been sold as adjacency, as the company your ad keeps. This ruling moves the brand safety risk downstream, to where your ad sends people.
The ads were seen on 12 February 2026. Ad (a) was a cartoon animation: a rabbit's head, coloured egg shapes spinning, on-screen text reading SPIN to WIN Cadbury Treats, the words Sponsored by Cadbury in the top right corner, the Costcutter logo in the bottom right. A hyperlinked Learn more carried the curious onward, and consumers, the ASA agreed, were likely to follow that scent.
Onward meant a webpage on www.bestwayretail.co.uk headed SPRING has finally SPRUNG, carrying photographic images of the packaging of Cadbury Biscoff Filled Egg, Cadbury creme egg, Cadbury Mini eggs, Cadbury Mini eggs bar and Cadbury creme egg bar. Three of those images included prices. Products, packaging and prices: the trail ran from a brand tease to a shopping shelf in a single tap. Every brand safety brief written last year would have called that a landing page. The ASA calls it an ad, and every brand safety inventory has to catch up.
complaint, from the campaigning organisation Bite Back, was enough to turn a promotional landing page into regulated ad space
That single complaint challenged both ads against rules that came into force on 5 January 2026, when new provisions in the CAP and BCAP Codes on the advertising of less healthy food and drink products took effect. Those rules reflect the Communications Act 2003, the Advertising (Less Healthy Food Definitions and Exemptions) Regulations 2024 and the Advertising (Less Healthy Food and Drink) (Brand Advertising Exemption) Regulations 2025 ASA. Media recorded: social media, paid ad, and website, own site. Two channels, one purchase, one purple palette.
Nobody was fined. The ASA does not levy fines in these rulings; it told both parties that ad (b) must not appear again in the form complained of, and to ensure that their paid-for ads placed on the internet were not for identifiable less healthy products ASA. The cost sits elsewhere: in the brand perception damage of a public upheld finding, and in the quiet brand safety rework of every campaign built the same way. That is where brand safety now lives, downstream of the placement, in the undergrowth nobody audits.
Payment decides brand safety responsibility. Control does not#
Costcutter sold off-the-shelf promotional packages. One of them, the Seasonal Takeover, bundled paid social with the creation of a bespoke landing page on a website owned and managed by Bestway Retail Ltd, an affiliate company to Costcutter. Mondelez bought that package ASA. Bundles of that shape are exactly where brand safety exposure accumulates, quietly, one packaged asset at a time.
Mondelez was conscious of the requirements of the Code, so it had agreed with Costcutter in advance to vary the Seasonal Takeover so that it would not make any payment for advertising space on www.bestwayretail.co.uk, and it paid a lower fee for the varied package. In the ASA's summary of the advertisers' account, this was agreed by phone and there was no written contract or agreement ASA. The intention was impeccable. The instrument was a chat.
The ASA was unmoved. It considered Mondelez had therefore paid for the full package, including the gamified landing page, albeit that they had received a substantial discount on the usual price ASA. A discount is evidence of payment, not evidence of exclusion. Pay less for a thing and you have still paid for it.
We noted Mondelez said they had had no input into, or control over, the content of the landing page. However, the test in law related only to whether a person (which included businesses) had made payment for an ad to be placed on the internet; the extent to which they had control over the ad's content was not relevant.
Read that twice if you buy media through packages, affiliates or retail media networks. Control is the comfort blanket brand safety teams burrow into: approval rights, asset lists, sign-off gates. The statutory test asks about none of it. It asks who paid. A brand can carry responsibility for a page it never saw, never briefed and never approved, because its budget put that page online. This is the part of brand safety that contracts solve, not creative.
Costcutter's own marketing literature did the rest of the work, describing the Bespoke Gamified Landing Page as a fully customised digital experience built exclusively for your brand or campaign, and the paid social element as intended to target and engage shoppers with campaign messaging, driving traffic to the game page ASA. Sold as one funnel, bought as one bundle, judged as one purchase.
Products, packaging and prices
A bespoke gamified page showing five named Cadbury Easter lines, three of them with prices, reached from a paid ad in the same purchased package. On the ASA's reading it depicted identifiable less healthy products, so the brand advertising exemption could not reach it and rule 15.19 was breached.
Brand, not basket
Ad (a) carried the Cadbury name, logo and purple tone applied across a wide product range, a generic bunny that was not a brand character, and block egg colours that were not the speckled pastel shades of actual Mini Eggs. No specific product was identifiable, so the exemption applied. That is the same reasoning any funded destination has to survive.
The practical fix is not glamorous. Whatever you carve out of a media package, carve it out in writing, itemised, named and priced. A phone call is not a paper trail, and a substantial discount reads to a regulator like a receipt. A brand safety review that never reads a contract is only reviewing half the risk. That belongs in the governance layer of your brand strategy, not in the inbox of whoever booked the paid social.
One page, two tests, and the asymmetry at the heart of brand safety#
Here is the finding most coverage will miss. The landing page counted for one test and was expressly excluded from the other, in the same ruling, about the same page, on the same day. Miss the asymmetry and you will build the wrong brand safety control.
For identifiability, the question of what an ad is for, the page counts. That test comes from section 368Z14 of the Communications Act 2003, reflected in CAP Code rule 15.19, and the ASA considered that in identifying what an ad was for, consumers' understanding was likely to be influenced by any material in a link in an ad which consumers were likely to access. It agreed with Bite Back that people were likely to click, and that the products shown behind the link would inform how they read the Instagram ad ASA. For brand safety, that is the half of the rule that follows the click.
For the brand advertising exemption, the page is invisible. The wording of the Regulations dictated that only the content of the ad itself was relevant; extraneous material, including the content of a linked landing page, was not relevant. So the ASA assessed ad (a) in isolation, without reference to the content of the landing page ASA. One page, two treatments, no contradiction.
| The brand safety question | Identifiability test | Brand advertising exemption |
|---|---|---|
| What it asks | What is this ad for, as consumers would understand it | Does the ad depict a specific less healthy product, or only a brand |
| Where it comes from | Communications Act 2003 section 368Z14, reflected in CAP Code rule 15.19 | Advertising (Less Healthy Food and Drink) (Brand Advertising Exemption) Regulations 2025 |
| Does the landing page count | Yes. Material behind a link consumers are likely to access informs their understanding | No. Only the ad's own content is relevant, extraneous material is not |
| Effect on ad (a) | Consumers' reading of the ad was informed by the products shown on the page | Assessed in isolation, exemption applied, this point was not upheld |
| Effect on ad (b) | Not applicable, ad (b) is the page itself | Depicted identifiable less healthy products, upheld, rule 15.19 breached |
In isolation, ad (a) survived. All the Cadbury Easter products were classified HFSS under the Department of Health and Social Care's Nutrient Profiling Technical Guidance and fell within less healthy food Category 4, described in law as Confectionary including chocolates and sweets. The ad itself depicted none of them. The Cadbury name, logo and purple tone are applied across a wide product range, no specific Cadbury product is named Cadbury Treats, the bunny was generic rather than a Cadbury brand character, and the spinning block colours were not the speckled pastel shades of actual Mini Eggs. Brand, not basket. The exemption applied ASA.
Both Costcutter and Mondelez were found to have paid for ad (a) to be placed online, and Mondelez was found to have paid for the package that included the page.
A discounted but purchased landing page is paid-for advertising space, regardless of who controlled its content.
For identifiability, material behind a link consumers are likely to access informs their understanding of the ad.
For the exemption, only the ad's own content is read. Ad (a) showed brand assets and passed. Ad (b) showed named products and did not.
Ad (b) had no such cover. It depicted specific less healthy products, so it breached CAP Code (Edition 12) rule 15.19 on the placement of less healthy food and drink product advertisements online. Same campaign, same purple, same purchase, opposite brand safety outcome.
The asymmetry is a design, not a quirk. One test asks how a consumer reads the ad, so it follows the consumer down the link. The other asks what the ad contains, so it stops at the ad's own edges. Any brand safety model that encodes only one of those rules will get half its destinations wrong, in whichever direction the assumption happened to run.
Three rulings, one day, and the shape of brand trust#
The same day produced two further upheld rulings, each carried by a single complaint, and together they sketch how the regulator is reading intent in 2026, and how far brand safety now reaches.
The Turmeric Co. ran website testimonials with specific words visually blurred out, so one customer line read: I have had a [blurred words]...has halved at least since I started my shots. The page carried the heading Regulations mean we can't show everything on this page. The ASA found the blurring reinforced the medical reading, effectively inviting consumers to infer the blurred content, and it breached CAP Code rules 15.6 and 15.6.2 ASA ruling A26-1337420. The testimonials were removed. For brand safety, redacting the regulated claim can itself be the claim: blurred, but blaring.
Jaded London sent a marketing email, seen on 27 May 2026, showing a model beside a scooter holding a lit cigarette. The advertiser argued the object was ambiguous and not the focal point of the image. The ASA found the ad had the effect of portraying smoking as appealing and therefore irresponsibly glamorised it, breaching CAP Code (Edition 12) rule 1.3 on social responsibility ASA ruling A26-1342047. Owned-channel email sits fully within the ASA's remit and inside brand safety scope, and an incidental prop carries the same test as the headline creative.
Regulations mean we can't show everything on this page
had the effect of portraying smoking as appealing and therefore irresponsibly glamorised it
The pattern across all three is the same. The regulator reads the whole experience a consumer actually has, not the asset a marketer actually made: a page behind a link, a blur over a word, a prop in the corner of a frame. Brand trust is rarely lost in the hero image. It leaks from the details nobody thought worth a sign-off, which is exactly the terrain our work on ASA rulings and social proof keeps returning to.
The ASA has ruled on campaigns where the ad copy and landing page part company, and landing-page drift can itself be the breach.
The statutory direction of travel is consistent with that. The Digital Markets, Competition and Consumers Act 2024 brought drip pricing, fake reviews and subscription traps into live consumer-protection enforcement on the same principle: the experience is the claim. Marketing trust is being defined by what happens after the click, in every regulated category from confectionery to healthcare and regulated gaming. Brand safety, in that light, is brand trust with a paper trail.
For a brand safety programme, that means widening the audit surface until it matches the map a customer walks. Every destination, every owned channel, every automated email, every affiliate page rendered under someone else's domain but funded from your budget. It is more ground than most brand safety teams have mapped, and the next complaint is already foraging along its edges, tracking the line your budget left through the bracken. Disciplined content operations make that mapping cheap; ad hoc ones make it a fire drill at eleven at night.
The evidence behind brand safety anxiety, and what it does not show#
Set the ruling beside the wider brand safety mood and something odd surfaces. A global study published on 29 July 2026 by DoubleVerify reports that 42% of consumers say low-quality or uncanny AI advertising negatively affects their opinion of a brand, that 56% cannot consistently identify AI-generated content, that 63% globally say AI-powered tools improve their online experience (50% in North America), and that 40% view polished, professional AI ads positively.
Handle those numbers with gloves. The entire published methodology is a single sentence: the findings are based on a DV-commissioned global survey of 22,000 consumers across 22 markets and 2,020 marketers and advertisers across 21 markets. No fieldwork dates. No research partner. No panel-versus-survey designation, no sampling frame, no weighting, no margin of error, and the 22 markets are never named. DoubleVerify sells media-quality measurement, so the study is vendor-commissioned and commercially self-interested. Research like this lives in permanent twilight: enough light to see a shape, not enough to name it.
The marketer figures from that same one-sentence-methodology DoubleVerify survey carry the sharper point. 53% say they are concerned about ads running alongside low-quality AI content, and 45% say the same about high-quality AI content. Eight points is a thin discount for quality. A further 48% are concerned about using AI for ad creative at all, rising to 63% in North America. Read together, the anxiety is not really about output quality; it is about association, provenance and the ability to explain a decision to somebody later. That is a governance problem wearing a creative costume, and it is the same shape as the brand safety problem the ASA has just described.
DoubleVerify's chief executive frames the whole thing as a question of craft. His own marketer numbers suggest craft is only half of it, and provenance is the rest.
AI is rapidly reshaping how content is created, how consumers experience media and how advertisers reach audiences. Our research confirms that AI itself is not what determines engagement. The quality of the output does.
The legal backdrop hardened three days before the ruling. AI Act Article 50 transparency obligations have applied since 2 August 2026, covering direct interaction with individuals, AI-generated content, emotion recognition, biometric categorisation and deepfakes, which must be clearly and visibly labelled and carry machine-readable marks. Penalties reach 15 million euro or 3% of global annual turnover for companies, and up to 750,000 euro for EU institutions European Commission. The voluntary Code of Practice on AI-generated content had, as at 31 July 2026, either over 180 or about 190 signatories depending which Commission page you read, so quote it as a range. The labelling icons are optional. The Article 50 obligations are not.
A specialist reading from Lewis Silkin, published on 31 July 2026 and offered as interpretation rather than law, holds that deployers are those who use AI systems under their authority and who control how the system is used, and that both advertisers and agencies can be deployers. Background tidying, lighting and colour adjustments, cosmetic touch-ups and product re-scaling are exempt. Labels must be clear, distinguishable and understandable, appearing when content first reaches its audience rather than buried in metadata, which means platform-only labels are insufficient.
Where does that leave the brand safety plan? Audit destinations, not just placements. Put every carve-out in writing. Treat any page your budget funds as ad space until a contract says otherwise, and treat vendor statistics as weather rather than ground. Brand safety has stopped being a filter list; it is the whole path a person walks after your ad earns the tap, which is why the same audit should cover your paid search destinations and your AI labelling obligations at once. When you want a fox to walk that path beside you, we are one short conversation away.
Frequently asked questions#
Did the ASA fine Cadbury or Costcutter over the landing page?
No. The ASA does not levy fines in these rulings and none was issued here. It ruled that ad (b) must not appear again in the form complained of, and told Costcutter Supermarkets Group Ltd and Mondelez Europe Services GmbH, UK branch, trading as Cadbury, to ensure that their paid-for ads placed on the internet were not for identifiable less healthy products. The brand safety cost is reputational and operational, not financial.
Why did the Instagram ad pass when the page it linked to failed?
The Instagram ad showed brand assets only: the Cadbury name, logo and purple tone used across a wide product range, a generic bunny that was not a brand character, and block egg colours that were not the speckled pastel shades of real Mini Eggs. No specific less healthy product was identifiable, so the brand advertising exemption applied. The landing page showed five named Cadbury products, three with prices, so the exemption could not save it.
Does a linked landing page count when the ASA applies the brand advertising exemption?
No. The ASA was explicit that for the exemption assessment, the wording of the Regulations dictated that only the content of the ad itself was relevant, and that extraneous material including the content of a linked landing page was not relevant. It does count for a different question, identifiability, where material behind a link consumers are likely to access informs their understanding of what the ad is for. Same page, two tests, two answers, and a brand safety model that has to hold both.
We had no control over an affiliate page. Are we still responsible for it?
Potentially yes. Mondelez said it had no input into or control over the landing page's content, and the ASA found that irrelevant. The test in law relates only to whether a person, including a business, made payment for an ad to be placed on the internet. If your money put the page online as part of a package, control over its content does not decide responsibility. Editorial oversight is good brand safety practice; it is not the legal test.
Is a verbal agreement enough to carve a page out of a media package?
The ruling suggests not. Mondelez agreed with Costcutter in advance to vary the package so that it would not pay for advertising space on the affiliate site, but that was agreed by phone with no written contract. Mondelez paid a lower fee and still received the page, so the ASA considered it had paid for the full package with a substantial discount. Itemise the exclusion in writing, priced at zero, or assume you have bought it.
What should a brand safety programme change after this ruling?
Widen the surface a brand safety audit covers. Inventory every destination your media budget funds, including pages on affiliate or retail media domains, then read each one against the strictest rule the campaign triggers rather than the rule the ad alone triggers. Record who the paying person is for each placement, keep the carve-outs in the contract, and re-run the check whenever a seasonal creative refresh changes what a page displays.
Does this brand safety ruling only apply to less healthy food and drink advertising?
The specific rules do, but the reasoning travels. Payment rather than control decided responsibility, and that logic is not limited to one category. Two other rulings published the same day showed the ASA reading a blurred testimonial and an incidental prop in a marketing email with the same whole-experience lens. Any regulated category buying bundled media, from healthcare to gaming, should assume funded destinations are in brand safety scope.
Read more on this topic#
The regulator read your as seen in strip as a promise
The companion piece on how the ASA reads the claims you did not think were claims.
Read the pieceAI generated advertising just lost the right to stay quiet
The labelling duty arriving alongside this one, from a different direction.
Read the pieceThe regulator asked who signed off the campaign, and nobody knew
Why the paperwork behind an approval is the control, not the intention.
Read the pieceThe regulator stopped reading your ad and started reading your funnel
Supervision moving from the creative to the mechanics beneath it.
Read the piece
Want to know what your funnel would look like to a regulator?
folkfox audits the whole journey, placement and destination together, so the page your ad points at is one you would be happy to defend.