EN FR ES PT DE AR 中文

Every Platform Has an Optimal Fraud Rate. It Isn't Zero.

Large platforms don't chase zero fraud, they budget for it. The internal rule that sets the tolerated level is the most dangerous file the business owns.

Listen7 min

Start with the number every platform pretends to be chasing: zero fraud. None of them are chasing it. The people who run large ad networks and marketplaces know the last increment of fraud is the most expensive one to remove, and the economics point the same way. Clearing that last sliver of bad actors costs more in lost revenue, false positives and reviewer time than the harm it prevents will ever register on a dashboard the company actually watches.

That is not cynicism. It is the economics of enforcement. Gary Becker set this out in his 1968 work on crime and punishment: the profit-maximising level of policing is never the level that eliminates all crime. Push enforcement past a certain point and each additional pound spent catches less and less, while the collateral cost of blocking legitimate customers keeps climbing. Every operator faces the same curve, and on the economics alone its optimum sits at a calculable point well short of zero.

Why would any company tolerate fraud it could remove?

Because removing it isn't free, and the losses land on someone else. Suppose an ad-vetting team is instructed that it may not eject a bad advertiser when ejecting them would cost more than a fixed fraction of revenue. That instruction, in this constructed example, is not a safety failure. It is a budget line. The fraud has been priced, capped and approved. The scam victim is an externality the pricing model doesn't include, because the victim never appears in the revenue column that the rule protects.

Read that way, the phrase 'we take fraud seriously' is doing a lot of work. A platform can take fraud extremely seriously as a cost centre and still run it at a deliberately non-zero level, in the same way a supermarket takes shrinkage seriously without hiring a guard for every aisle. The problem is not that platforms think this way. Every business with a loss function does. The problem is what happens when the loss function gets written down.

The number isn't the problem. The document is.

A tolerated-fraud rate that lives only in a manager's head is an operational judgement. The same rate, expressed as an internal policy that forbids removing profitable-but-harmful actors below a revenue threshold, is something else entirely. It converts a moderation failure into a decision. It turns 'we didn't catch it' into 'we modelled it, priced it and chose to keep it', which is the difference between negligence and premeditation in almost every legal system that matters.

This is the asymmetry nobody prices in. The financial upside of writing the rule down is a slightly tidier enforcement process. The downside is a discoverable exhibit with a timestamp and an author, sitting in a system designed to preserve it. Any business running a marketplace, an ad network or a user-generated platform should treat its own 'acceptable harm rate' analysis as a future court exhibit first and an operational tool second. The spreadsheet outlives the quarter it was built for.

Why is moderation strict on the harmless and soft on the harmful?

Because enforcement is calibrated along the revenue gradient, not the harm gradient. Automated systems are ruthless with material that is cheap to flag and cheap to remove: a hobbyist tutorial, a configuration workaround, a video that trips a copyright filter. They are permissive with material that is expensive to adjudicate and lucrative to keep: the scam advertiser paying full rate. The machine optimises the metric it can measure at scale, and harm is not that metric. Harm is slow, contested and human. Click-through is instant.

This is where a lot of platforms have quietly outsourced judgement to a pipeline that was never built to exercise it. Genuine adjudication is expensive, so it gets replaced by automated decisions with no human holding the hard cases. The result is a system that is confidently wrong at both ends: over-blocking the trivial, under-blocking the dangerous, and calling the aggregate 'moderation'. If you are building enforcement on top of automated agents, the failure mode is not the model being weak, it is the model being pointed at the wrong objective and left unsupervised.

What changed, and why your risk file is now an exhibit

Two things moved at once. First, remediation has always arrived late. The safety features a platform announces are, more often than not, artefacts of a settlement rather than proactive controls, because a fine priced below the revenue a harmful design produces is simply a cost of doing business. Regulators and state prosecutors have started saying so out loud: a state attorney general won a landmark jury verdict against a major platform over harms its own design produced, and the UK now imposes enforceable child-protection duties on services rather than waiting for them to volunteer.

Second, the penalty is changing shape. When fines were fixed sums, a tolerated-harm calculation was rational and safe: the downside was bounded and often smaller than the upside. As penalties move to a percentage of global revenue, and as product-defect theories treat a harmful design as a faulty product rather than protected speech, the bounded downside stops being bounded. The internal document that made the old maths work becomes the exhibit that proves intent under the new maths.

What would change this reading? If a platform published its tolerated-fraud threshold and then demonstrably removed actors above a fixed harm line regardless of what they paid, the 'budgeted negligence' argument would weaken considerably, because the rule would be calibrated to harm rather than revenue. That version exists in theory. It is rare in the wild, and the reason it's rare is the same reason the optimum isn't zero.

The practical takeaway for anyone operating a platform is unglamorous. Assume the fraud rate is non-zero, because it is. Then make sure the way you reason about it would survive being read aloud in a courtroom, which usually means calibrating enforcement to harm, documenting the harm line rather than the revenue line, and treating the whole exercise as a governance problem, not a spreadsheet. The optimal amount of fraud isn't zero. The optimal amount of self-incrimination is.

Questions people ask

Is there really an 'optimal' amount of fraud for a business?

Yes, in the narrow economic sense. Beyond a certain point, catching more fraud costs more than the fraud itself, both in direct enforcement spend and in wrongly blocking legitimate customers. Every business with losses faces this curve. The controversy is not that an optimum exists, it's whether platforms calibrate it to the harm inflicted on victims or only to their own revenue.

Does tolerating some fraud make a platform legally liable?

Tolerating it quietly is one thing; documenting a rule that keeps profitable bad actors in place is another. This is analysis rather than legal advice, but the general pattern is clear: an internal policy that prices and approves a harm level can be read as evidence of a deliberate choice, which is harder to defend than a genuine failure to detect.

How should a marketplace document its fraud and abuse controls?

Calibrate thresholds to harm rather than to revenue, and write down the reasoning that way. A control that says 'remove any actor above this harm line' reads very differently from one that says 'do not remove actors below this revenue cost'. Assume anything you record could be produced in litigation, and make the record describe the harm you prevent, not the income you protect.

Related

Written by an AI editorial persona of Abyshire's proprietary editorial system and reviewed by our team.