Trust, Ethics & Regulation · established evidence
The Fake Review Rule Nobody Told Small Business Owners About: 16 CFR 465 in Plain English
The FTC fake review rule, formally the Trade Regulation Rule on the Use of Consumer Reviews and Testimonials at 16 CFR Part 465, took effect on October 21, 2024, and most small business owners have never heard of it. It converts fake-review practices from a case-by-case deception finding into a standing rule violation that carries civil penalties of up to $51,744 per violation. The rule names five specific practices: reviews from people who never used the product, including fake reviews written by an AI system; review gating and incentives conditioned on a positive sentiment; undisclosed reviews by company insiders; suppressing honest reviews through legal threats or intimidation; and buying fake followers or engagement. None of these require a regulator to prove intent to a court first. For owner-operated med spas, home services, dental practices, and small firms that depend on Google and Yelp, the exposure is real and largely invisible, because most of it is inherited from tools and habits that predate the rule.
What the FTC fake review rule actually is
On August 14, 2024, the Federal Trade Commission announced a final rule that, for the first time, makes specific fake-review practices a direct violation of a Trade Regulation Rule rather than a matter to be argued case by case. The rule was published in the Federal Register (2024-18519) and took effect on October 21, 2024. Its formal citation is 16 CFR Part 465, the Trade Regulation Rule on the Use of Consumer Reviews and Testimonials.
The mechanical change matters more than the headline. Before this rule, the FTC policed deceptive reviews under the general deception and unfairness authority of Section 5 of the FTC Act, which required the agency to build each case from the ground up. A Trade Regulation Rule is different: once a practice is named in the rule, a violation can carry civil penalties without the agency re-litigating whether the conduct is deceptive in the abstract. That is what puts a specific dollar figure, up to $51,744 per violation, behind conduct that many operators still treat as ordinary marketing.
The rule was not written for large platforms alone. It reaches any business whose reviews or testimonials are created, procured, or suppressed in the prohibited ways, which places the ordinary local service business squarely inside its scope.
The five practices 16 CFR 465 prohibits
The rule is easier to comply with once it is read as a list of concrete behaviors rather than a general instruction to be honest. As summarized from the rule text, five practices are named, and each has a direct analog in how local businesses already collect and manage reviews.
- Fake or fabricated reviews: reviews that claim to come from a real customer who does not exist, or from a person who never actually used the product or service, including fake reviews written by an AI system.
- Review gating and sentiment-conditioned incentives: screening customers by how they feel first and routing only the happy ones to a public platform, or offering a reward that is conditioned on leaving a positive review.
- Undisclosed insider reviews: reviews written by officers, managers, employees, or their immediate relatives that are presented as independent customer opinion without disclosing the connection.
- Review suppression: using unfounded legal threats, physical threats, intimidation, or false accusations to prevent or remove honest negative reviews.
- Fake social-media indicators: buying or selling followers, views, or other indicators of influence generated by bots or hijacked accounts to misrepresent a business or its standing.
Why these five, and not a general honesty standard
Each named practice targets a specific way the observable signal (a public rating, a testimonial, a follower count) can be decoupled from the underlying reality it is supposed to represent. A star rating is meant to aggregate genuine customer experience. Gating breaks that by filtering the input. Insider reviews break it by disguising the author. Suppression breaks it by removing the dissent. Bought engagement breaks it by manufacturing the signal outright. The rule is precise because vagueness is what let these practices persist for years under a general deception standard.
Are fake reviews illegal now, and what $51,744 per violation means
The short answer is that the named practices are now prohibited by a federal rule that authorizes civil penalties, which is a stronger legal position than the case-by-case deception theory that preceded it. The rule sets a maximum civil penalty of up to $51,744 per violation, a figure the FTC adjusts for inflation over time.
The caveat is what "per violation" means in practice. The rule is recent, and the enforcement record that would settle whether a violation is counted per fake review, per campaign, or per transaction is still thin. Treating the maximum as an automatic multiplier against every bad review would overstate what has actually been imposed. The defensible reading is narrower and still serious: the ceiling is high enough that a systematic practice, a gating funnel running for months, or a batch of fabricated testimonials, represents genuine financial exposure rather than a theoretical one.
Two further points keep the picture accurate. First, these are civil penalties, not criminal charges, and the FTC has historically pursued patterns and systems rather than isolated mistakes. Second, the rule sits on top of, and does not replace, the platform policies of Google, Yelp, and others, which enforce their own bans on gating and fake reviews independently and far more frequently than any regulator does.
Why owner-operated businesses carry the most exposure
The uncomfortable structural fact is that this rule lands hardest on the businesses least equipped to absorb it, and that is not an accident of enforcement so much as a property of where fake reviews come from in the first place.
The seminal empirical study of review fraud, Luca and Zervas in Management Science (2016), examined Yelp and found that a business is significantly more likely to commit review fraud when its organic reputation is weak, when it has few reviews or a recent run of bad ones, and when local competition intensifies. Chain businesses, which gain less marginal benefit from any single platform, committed fraud less often. The behavior concentrates, in other words, precisely among small independent operators under competitive pressure.
That is the exact profile of the owner-operated med spa, the home-services contractor, the two-chair dental practice, and the solo law firm. The temptation to buy a few reviews, to route unhappy customers to a private form, or to have a family member post a glowing testimonial is strongest for the businesses whose next customer is decided by the rating. The rule now attaches a federal penalty to the behavior that structural pressure makes most likely, in the segment that can least afford the penalty, which is why the exposure is not hypothetical for this audience.
Review gating and incentives: the rules most owners break without knowing
The practice that catches the most honest operators by surprise is review gating, because it was sold to them as a best practice by reputation tools for years. Gating is any workflow that asks customers how they feel before deciding where to send them, then routes the satisfied ones to Google or Yelp and diverts the unhappy ones to a private feedback form. It feels reasonable. It is now named as a prohibited practice.
Incentives and the endorsement rules that sit alongside 465
The fake review rule does not stand alone. The FTC also revised its Endorsement Guides at 16 CFR Part 255, effective July 26, 2023 (Federal Register 2023-14795), which govern testimonials and material connections. Those guides extended the definition of an endorser to include fictitious personas and virtual or AI-driven characters, and set a "significant minority" standard: a material connection must be disclosed if even a meaningful minority of the audience would otherwise be misled. Read together, the two instruments mean an incentive is not automatically illegal, but an incentive conditioned on a positive review is prohibited, and any incentive or relationship that would surprise a reasonable reader must be disclosed.
What compliant asking looks like
The compliant version of asking for reviews is not complicated, it is just different from the gating funnel. Invite every real customer you served, not a pre-screened subset. Do not condition any reward on the content or sentiment of the review. Point customers to the public platform directly rather than through a sentiment checkpoint. Disclose any material connection when a reviewer is an insider or was given something of value. The reviews that result are slower to accumulate than a gated funnel promised, but they are an asset the rule cannot touch rather than a liability waiting to be found.
One doctrine, two surfaces: astroturfing and dark patterns
It helps to see the fake review rule as one application of a broader legal idea rather than an isolated regulation. Review manipulation and interface manipulation are the same underlying problem expressed on two different surfaces, and the FTC treats them under the same unfairness and deception doctrine.
On the interface side, the design-research and legal community has a name for manipulative design that pushes a user toward an action they would not otherwise take: dark patterns, a category coined by Harry Brignull in 2010 and now actively monitored by the FTC and consumer advocates. On the reputation side, the parallel is astroturfing: manufacturing the appearance of organic customer sentiment that does not exist. Both exploit the same gap, the distance between what a system appears to reflect (free customer choice, genuine sentiment) and what it actually reflects (an engineered incentive structure). Recognizing the shared doctrine is useful because it tells a business owner where the line sits: the rule is not hostile to marketing, it is hostile to the specific act of making a signal say something the underlying reality does not support.
How aggressively will it be enforced?
A rigorous piece has to separate what the rule says from how forcefully it will be applied, because those are different questions with different confidence levels.
The rule text and its penalty authority are established and on the books. The intensity and durability of enforcement are less certain. The FTC launched a distinct enforcement lane called Operation AI Comply in September 2024, targeting deceptive AI claims, and named actions against DoNotPay and Evolv Technologies followed. Yet the agency also reopened and set aside its own 2024 Rytr consent order in December 2025, citing a change in administration posture. That reversal is evidence that federal enforcement priorities shift with the political calendar, and that treating any single administration's aggressiveness as a fixed floor would be a mistake.
The prudent conclusion is not to gamble on lax enforcement. A rule stays enforceable regardless of how often it is invoked, private platform policy enforces the same prohibitions far more routinely than any regulator, and a business that builds its reputation the compliant way is insulated from both. The uncertainty is about the odds of being pursued by the FTC specifically, not about whether the underlying conduct is prohibited or whether Google will remove gated reviews. Compliance is the strategy that is correct under every version of the enforcement future.
What a compliant review operation looks like
Put the pieces together and a compliant review operation is a short, testable checklist rather than a legal seminar. Every review comes from a real, identified customer who actually used the service. No step in the request flow screens customers by sentiment before deciding where to send them. No incentive is conditioned on positivity, and any material connection is disclosed. Honest negative reviews are answered, never suppressed by threat. Followers and engagement are earned, never purchased.
Most owner-operated businesses fail this checklist not through bad intent but through inheritance: an old reputation tool with a built-in gating step, an agency that set up a sentiment funnel years ago, a family member who left a review without disclosure, or a reflex to threaten a reviewer over an unfair one-star. The gap is rarely deliberate, which is exactly why it goes unseen until someone maps where every review actually comes from and how each one was solicited. That mapping is the first step, and it is worth doing before the exposure becomes a matter for a regulator or a platform to raise first.
The evidence
Key findings, with their sources
-
The FTC fake review rule (16 CFR Part 465) took effect October 21, 2024, and carries civil penalties of up to $51,744 per violation.
established FTC, Trade Regulation Rule on the Use of Consumer Reviews and Testimonials, 16 CFR Part 465, Federal Register 2024-18519; FTC press release, Aug 14, 2024.
-
The rule names five specific prohibited practices: fake or fabricated reviews, review gating and sentiment-conditioned incentives, undisclosed insider reviews, review suppression via threats, and purchased fake social-media indicators.
established FTC, 16 CFR Part 465, Federal Register 2024-18519, 2024.
-
The revised FTC Endorsement Guides extended the definition of an endorser to include fictitious and virtual personas and set a "significant minority" disclosure standard for material connections.
established FTC, 16 CFR Part 255, Guides Concerning the Use of Endorsements and Testimonials, Federal Register 2023-14795, effective July 26, 2023.
-
Review fraud concentrates among independent businesses with weak or volatile reputations under intensified local competition, while chains commit it less often.
established Luca, M. & Zervas, G., "Fake It Till You Make It: Reputation, Competition, and Yelp Review Fraud", Management Science, 62(12), 2016 (HBS Working Paper 14-006).
-
The FTC opened an AI-claims enforcement lane (Operation AI Comply, Sept 2024) but set aside its own 2024 Rytr consent order in December 2025, indicating enforcement posture shifts with administration.
contested FTC case dockets and press materials, 2024-2025, via Benesch Law and Lexology reporting.
Calibration
What is proven, what is promising, what is unproven
| Evidence tier | Tactics | What the evidence says |
|---|---|---|
| established | The rule text, its October 21, 2024 effective date, the $51,744-per-violation penalty ceiling, the five named practices, the revised Endorsement Guides, and the structural clustering of review fraud among small independents. | Federal Register 2024-18519 and 2023-14795; FTC press release Aug 14, 2024; Luca & Zervas, Management Science, 2016. |
| emerging | Exactly how a "violation" is counted and scaled in practice, and how fake reviews produced by AI systems will be detected and attributed, given how new the rule and its enforcement record are. | Rule effective Oct 2024 with a thin enforcement history; FTC Operation AI Comply as the nearest active lane, 2024-2025. |
| contested | The durability and intensity of aggressive federal enforcement across changing administrations. | FTC set-aside of the 2024 Rytr consent order, Dec 2025; documented shift in enforcement posture. |
Reference
Glossary
- 16 CFR Part 465
- The FTC Trade Regulation Rule on the Use of Consumer Reviews and Testimonials, effective October 21, 2024, which makes specific fake-review practices a direct rule violation carrying civil penalties.
- Review gating
- Screening customers by sentiment before deciding where to send them, routing satisfied customers to a public platform and diverting unhappy ones to a private form. Named as a prohibited practice under the rule.
- Insider review
- A review written by a company officer, manager, employee, or an immediate relative, presented as independent customer opinion without disclosing the connection.
- Material connection
- Any relationship between a reviewer and a business, such as employment, family ties, or something of value received, that would affect how a reader weighs the review and therefore must be disclosed.
- Astroturfing
- Manufacturing the appearance of organic, independent customer sentiment that does not actually exist, the reputation-side analog of manipulative interface design.
- Civil penalty
- A monetary penalty imposed for a rule violation, distinct from a criminal charge. Under 16 CFR Part 465 the maximum is up to $51,744 per violation, adjusted for inflation.
Straight answers
Frequently asked questions
Are fake reviews illegal now?
The specific practices the rule names, including fabricated reviews, review gating, undisclosed insider reviews, review suppression, and bought engagement, are now prohibited by a federal Trade Regulation Rule (16 CFR Part 465) that authorizes civil penalties of up to $51,744 per violation. That is a stronger legal position than the case-by-case deception standard that preceded it.
What is 16 CFR 465?
It is the citation for the FTC Trade Regulation Rule on the Use of Consumer Reviews and Testimonials, published in the Federal Register (2024-18519) and effective October 21, 2024. It bans five specific review practices outright rather than requiring the FTC to prove each case of deception from scratch.
Is asking customers for reviews still allowed under the rule?
Yes. Inviting real customers you served to leave a review is allowed and encouraged. What is prohibited is screening customers by sentiment before deciding where to send them, conditioning an incentive on a positive review, or failing to disclose a material connection. Invite everyone, condition nothing on positivity, and disclose insiders, and the request flow stays compliant.
Who is liable if a marketing tool or agency posts reviews for my business?
The rule reaches reviews and testimonials created, procured, or suppressed on a business's behalf, and the FTC's endorsement framework has long treated the advertiser as responsible for what is done in its name. Much of the exposure small businesses carry is inherited from a tool or agency running an old gating funnel, which is why mapping where every review comes from is the sensible first step rather than assuming a vendor absorbed the risk.
Does the rule cover reviews produced by AI?
Yes. The rule explicitly covers fake reviews that appear to come from a real customer but were produced by an AI system rather than a genuine user. A review is prohibited when it misrepresents a real customer experience, regardless of whether a person or a machine wrote the text.
Provenance
Sources
- FTC, Trade Regulation Rule on the Use of Consumer Reviews and Testimonials, 16 CFR Part 465 (effective Oct 21, 2024), Federal Register 2024-18519 (established)ecfr.gov
- FTC press release, "Federal Trade Commission Announces Final Rule Banning Fake Reviews and Testimonials", Aug 14, 2024 (established)
- FTC, Guides Concerning the Use of Endorsements and Testimonials in Advertising, 16 CFR Part 255 (revised effective July 26, 2023), Federal Register 2023-14795 (established)ecfr.gov
- Luca, M. & Zervas, G., "Fake It Till You Make It: Reputation, Competition, and Yelp Review Fraud", Management Science, 62(12), 2016 (HBS Working Paper 14-006) (established)
- Brignull, H., deceptive.design (formerly darkpatterns.org), 2010 onward, and "Deceptive Patterns", 2023 (established)
- FTC, Operation AI Comply enforcement sweep and the Rytr consent-order set-aside, 2024-2025, via Benesch Law and Lexology reporting (established as to actions and dates; contested as to enforcement durability)
Every figure above is attributed to a real, dated source and tagged with its evidence tier. Where a claim could not be verified to a primary source, it is not stated as fact.