PubRev+ runs a mobile games studio with twenty-plus titles and pushes more than six billion CTV ad requests a day in the United States.
Mobile games and CTV. The two categories verification vendors flag harder than anything else in this business.
Neither fact appears in Charlie Castell's column in AdExchanger this week, which argues that publishers never consented to being graded and that ad tech never built anybody with real enforcement power.
AdExchanger notes The Sell Sider is written by the sell side. Sure. Sure.
That is not the same as mentioning that the author is the graded inventory, at six billion daily requests, while also selling monetization consulting to other people getting graded.
A column demanding that verification companies disclose their commercial stake in their own outputs might want to open with its own.
First, the feelz
The column opens with ICE.
The January RFI is real, and it is genuinely bad. EPIC called it a distillation of how commercial surveillance and state surveillance have been merging for years. The Register reported it covers personal, financial, location and health data. The obvious problem: buying the data is how you skip the warrant.
So. Two paragraphs of federal agents using our plumbing to find human beings.
Then Castell says he is not drawing a direct link between immigration enforcement and ad verification.
Then he draws it four more times.
The parallels are obvious. The pattern is the same.
Systems built for one purpose, used in ways their subjects never imagined.
Cool.
This is the oldest trick in opinion writing. Borrow the moral weight. Disclaim the comparison. Keep the weight.
You get masked agents and disappeared neighbors, deployed in a dispute about whether a crawler misclassified somebody's interstitial.
I would let it go if the emotion were decoration. It isn't. It's load-bearing.
Pull the ICE frame out and look at what's left.
No company named. No case cited. No publisher identified. No dollar figure.
Not one. Zip. Zilch. Nada.
The feelings are doing the argument's job because the argument has no evidence to do it with.
Is that appropriate in trade press? Honestly, I don't know, and I'm not the guy to write the etiquette column. Plenty of good writing runs on moral heat. I've written some. But when the heat is the only thing in the pot, somebody should say so.
Said.
Moving on.
"Ways we never intended"
Now the title.
We intended it. All of it. On purpose. For money. It’s a business, for goodness sake.
The product was never "put a banner near an audience."
From the first exchange forward, the product was: identify a specific human across unrelated contexts, assemble enough about them to price the impression, do it in under a hundred milliseconds.
That is not a side effect of the architecture.
That is the architecture.
The cookie was built to follow people. The mobile ad ID was built to keep following people once the cookie couldn't get into apps. The bidstream sprays device ID, IP, coarse location and app context to hundreds of endpoints the publisher cannot name, on every request, because the bid doesn't clear without it.
ICE didn't repurpose anything. ICE read the brochure.
A federal agency wanted to know where specific people sleep, work, pray and get medical care. It went shopping in the one industry that spent twenty years building precisely that, at population scale, and selling it by the CPM.
The RFI asks for "ad tech compliant" data. ICE never defined the phrase. Nobody could, because it doesn't mean anything. A contracting officer wrote it like it was a certification we hand out. That's how legible we've made ourselves to federal procurement, and I promise you nobody in that office was smiling when they typed it.
"Used in ways we never intended" is the gun manufacturer marveling that the product shoots people.
The surprise isn't that surveillance infrastructure got used for surveillance. The surprise is that we spent two decades calling it relevance and somebody finally called the question.
Castell gets within about a foot of this and then walks away. The infrastructure has consequences beyond campaign metrics. Correct! It always did. Everyone who built it knew.
The word isn't "unintended." The word is "sold."
"Publishers did not agree"
The consent argument is the spine of the piece. It breaks at the contract layer.
Publishers agreed. They signed the SSP and exchange agreements that specify verification. They took the demand that requires it. Every mobile publisher who ever dropped in a mediation SDK accepted terms referencing invalid traffic filtration, because the money on the other end doesn't move otherwise.
What Castell means, I think, is that publishers had no say in the standards. Fine. Real complaint. Different complaint.
But the sentence he wrote is that nobody agreed to give these companies this power, and that's just not so. The advertisers agreed. The advertisers are the customer.
A verification vendor's product is sold to the buy side, priced to the buy side, tuned to the buy side's risk tolerance, because the buy side is the one writing checks it would very much like to stop writing.
"We never consented" decodes to "our counterparties set terms we don't like."
That's a normal commercial grievance. Also a much less moving sentence. Which is presumably why it shows up wearing a costume.
The enforcement body that has existed since 1964
Here's the one that made me read the piece twice.
Castell writes that the IAB can't enforce, membership is voluntary, compliance is self-reported, and ad tech never built a body with real enforcement authority.
The Media Rating Council. Founded 1964. After congressional hearings into rigged TV ratings.
The receipts:
October 2016, it revoked accreditation on two DoubleClick for Publishers products, mobile web impressions and viewability, for blowing a compliance deadline. September 2021, it suspended Nielsen's national and local TV accreditation over pandemic undercounting and did not give national back for roughly nineteen months. April 2023, it revoked Comscore Media Metrix. Q3 2025, it revoked GumGum's content-level brand safety and URL reporting across desktop, mobile web and CTV, and revoked Meta's accreditation covering partner monetization policies and brand safety controls on Facebook and Instagram feeds and Facebook in-stream.
That is a body that took the seal off Nielsen for a year and a half and off Meta last year.
Now. Argue it's too slow. Too small. Funded by the audited. Structurally captured. Seven full-time employees policing an industry this size is a fat target and I'd read that piece in a heartbeat. Somebody should write it.
What you cannot do is announce in a national trade publication that the enforcement body was never built, without ever naming the sixty-two-year-old enforcement body.
Either he doesn't know the plumbing of his own industry or he's counting on you not to.
Pick one. Neither's great.
Same issue in miniature with the Publisher Coalition, which the column endorses as laying groundwork. I could not establish what it is, who runs it, who funds it, or whether PubRev+ is in it. A column arguing for transparent governance names its preferred governance body and states its own relationship to it.
He's right about one thing
The grievance underneath all this isn't fake.
Publishers do get delisted on garbage crawler data. No notice. No explanation. No appeal. No refund.
Adalytics, who I don’t love, already dragged this into the light, and its reports questioning verification vendor effectiveness pulled in Congress and the DOJ. Publishers lose real revenue on flags that wouldn't survive ten minutes of scrutiny, and the vendor that issued the bad flag pays nothing for being wrong.
That story is sitting there. Nobody has reported it properly, because reporting it requires named publishers, dated invoices and the actual flag logs.
Which is exactly what this column doesn't have.
So who enforces? Not us.
Castell wants a new industry body. I think that's backwards.
Enforcement is what governments do.
Every analogy in his own column argues against him. Financial markets have regulators because Congress made them. Food safety has inspectors because Congress made them. Advertising has the FTC because Congress made it. The common thread isn't that an industry organized itself. It's that an industry proved it couldn't, and the state showed up.
Voluntary bodies fail for a deeply boring reason. They're funded by dues from the companies they'd have to punish.
A trade association that seriously enforced against its top ten members would lose its top ten members, then its staff, then its lease. That's not cynicism, it's arithmetic, and it applies to a publisher-built framework exactly as hard as it applies to the IAB.
You want enforcement in programmatic? It isn't another standards body.
It's licensing.
License the traders
Here's the version I'd put on the table.
Anybody who buys or sells programmatic media for money gets a license. Fingerprints to the FBI. Criminal background check. Pre-licensure education. Continuing ed every year. A unique ID that follows the person, not the company, carrying public disciplinary history.
Not hypothetical. That's the SAFE Act, July 2008, passed after the mortgage business produced a global financial crisis.
Residential mortgage loan originators are now state-licensed or federally registered through NMLS. State licensure means fingerprints submitted for state and national criminal history checks, twenty hours of pre-licensure education, eight hours of continuing ed annually.
The identifier is the part that matters. It permanently identifies the originator. It tracks employment across state lines. It carries publicly adjudicated disciplinary actions with it, forever.
Read that again with ad tech in your head.
Our fraud problem is a re-entry problem.
The same forty people have burned down the same category six times under six different logos. The MFA operator becomes the CTV app developer becomes the retail media consultant becomes the AI something. Nothing follows them. No record, no bar, no disbarment, no reason to stop. The cost of getting caught is a new LinkedIn headline and a fresh Delaware entity.
A portable license with attached discipline kills that specific game. Not fraud in general. That game.
Pesach's estimate, flagged as an estimate and not a finding: twenty percent of this industry evaporates the day fingerprints are required. No data supports that number. Nobody's data supports any number, because nobody has tried it.
I'll only note that the people most upset about a background check are rarely the people with an empty file.
Who runs it? That's the hard part and I'm not going to fake it.
Not the IAB, per the dues arithmetic. Not the MRC, which audits methodologies rather than humans and has seven employees.
Three doors, realistically. Congress, appetite currently at zero. State AGs, who already have the consumer protection authority, are already circling ad tech, and only need one state to move a national market. Or the advertisers, privately, by contract: the ten biggest holdcos could agree tomorrow to transact only with licensed individuals and the market would fold within a year, because the money would require it.
Door three is the only one that happens fast.
Door three also hands licensing authority to the buy side. Which is the exact concentration of power Castell's column is complaining about.
Which is the honest ending.
The problem with governance in ad tech isn't that nobody built the body. It's that everyone who could build it has a reason not to, and everyone who wants it built wants to hold the pen.
Castell's column isn't an argument against that dynamic.
It's a specimen.
