One human, one review
Under the FTC's Consumer Review Rule each fake review is a separate violation carrying a penalty just above fifty thousand dollars. Meanwhile the cost of writing a fluent, specific, entirely fabricated review fell to approximately nothing. Platforms are trying to solve this by reading reviews more carefully. The review is the wrong object.
Picture an independent bookshop. The owner opens the laptop on a Monday and the rating has gone from 4.8 to 3.9 overnight. Twenty three new one star reviews, all posted between two and four in the morning, each one fluent and specific and quietly devastating. Several mention a rude member of staff called Dan. There is no Dan. There has never been a Dan.
She reports them. The automated review comes back within the hour: the reviews do not violate policy. She appeals, writes to a support address, posts publicly about it. Three weeks later eight of the twenty three quietly disappear. Nobody explains why those eight and not the other fifteen. The rating settles at 4.2 and stays there, and she has no way to know whether the shop that opened around the corner in March had anything to do with it, and no way to find out.
Now run the same machinery in the other direction. A seller with a mediocre product buys two hundred five star reviews for a few hundred dollars. Each review is well written, mentions a plausible detail, arrives on a believable schedule from an account with some history. The product ranks. It outsells a better product from a seller who did not buy anything. The consumer who reads those reviews is not deceived by any single one. They are deceived by the aggregate, which is the only thing they actually consulted.
Both stories run on the same fact: nothing in the system establishes that a review came from a distinct human being. Everything else, the writing, the timing, the account history, the star pattern, is a signal that can be manufactured, and manufacturing got cheap.
Short answer. Under the FTC's Consumer Review Rule, in force since late 2024, each fake review is a separate violation carrying a civil penalty just above fifty thousand dollars, adjusted annually. Platforms cannot durably fix this by classifying review text, because generative models write review text for free. The control that removes the class is proving each reviewer is a distinct human at submission, with no identity collected.
What is the penalty for fake reviews?
The Federal Trade Commission finalised its Rule on the Use of Consumer Reviews and Testimonials in August 2024, codified at 16 CFR Part 465, and it took effect that October. It prohibits writing, selling, buying, and disseminating fake or false consumer reviews and testimonials, along with a set of related practices including suppressing negative reviews and buying positive ones from insiders without disclosure.
The part that changes the arithmetic for a business is the penalty structure. Violations carry civil penalties per violation, currently just above fifty thousand dollars and adjusted annually for inflation, and the FTC issued warning letters to companies in December 2025 citing the adjusted figure. Because each individual review is a separate violation, exposure scales linearly with the thing a review broker sells by the hundred. A business that bought two hundred reviews is not looking at a fine. It is looking at a number with seven digits.
The United Kingdom moved in the same direction. The Digital Markets, Competition and Consumers Act 2024 made fake reviews a banned practice and gave the Competition and Markets Authority direct enforcement powers rather than requiring it to go to court first. In the European Union, the Digital Services Act pushes obligations onto the platforms themselves regarding illegal content and systemic risk.
So the regulatory position across three major markets is now roughly the same: fake reviews are illegal, the penalties are per item, and platforms are expected to have measures. The open question, and the one this piece is about, is what counts as a measure that actually works.
Why did fake reviews get so much cheaper?
For twenty years the constraint on fake review supply was writing. Producing a hundred reviews that read like a hundred different people took a hundred instances of a person sitting down and inventing a plausible experience. Review farms existed, but they were labour operations, and their output had recognisable tells because tired humans writing their fortieth review of a phone case repeat themselves.
Generative text removed that constraint completely. The marginal cost of a fluent, specific, stylistically varied review that mentions the right details went to approximately zero, and it went there quickly. Nothing else changed. The value of a review to a seller stayed exactly where it was, because consumers still read them and rankings still weight them.
When the cost of producing something falls to nothing and its value stays constant, you do not get a slightly worse version of the old problem. You get a different problem, and defences calibrated to the old economics fail in ways their designers did not anticipate. Every heuristic built on the assumption that fake reviews are expensive to produce, and therefore rare, and therefore detectable as outliers, inherits an assumption that is no longer true.
What is a reputation system actually assuming?
Step back from reviews specifically, because the interesting failure is more general.
Every reputation system, from restaurant ratings to seller scores to upvotes to peer review, rests on an assumption almost nobody states out loud: that the ratio of participating identities to participating humans is roughly one. Not exactly one. Roughly one. The system does not need to know who anyone is, and mostly should not, but it does need the population of voices to correspond in some stable way to a population of people.
Imagine a village that votes on things by dropping paper slips into a box. It works fine for a century. Then someone gets a printing press. The votes still look identical, the box still works, the counting is still accurate, and the result is now meaningless. Nothing about the ballot changed. What changed was the relationship between slips and villagers.
This is what computer science calls a Sybil attack, named after a case study of multiple personality, and Sybil resistance is the property a system has when creating many identities is expensive enough to make the attack uneconomic. Almost every real world reputation system achieved Sybil resistance accidentally, by borrowing it from something else. Amazon borrowed it from purchase records. Old forums borrowed it from the effort of building account history. Yelp borrowed it partly from device and behaviour signals.
None of those systems set out to solve Sybil resistance. They inherited enough of it for free that they never had to think about it, and now the inheritance has run out.
The identity to human ratio
Once you hold that frame, the diagnosis becomes simple. A review platform does not have a fake review problem. It has an unbounded identity to human ratio, and fake reviews are the symptom that presents first because reviews are where the money is.
This reframe matters because it tells you where to intervene. If the problem is the ratio, then examining the reviews harder cannot fix it, in the same way that examining the paper slips harder cannot fix the printing press. You have to change something about who gets to drop a slip in the box.
Why does verified purchase not solve it?
Verified purchase badges are a genuinely good control and deserve credit. Requiring that a reviewer bought the product raises the cost of a fake review from nothing to the price of the product, which for expensive items is a real deterrent and visibly reduces farm activity.
It has two limits, and the second one is the one that matters strategically.
The first is that a farm can buy the product. For a low cost item, or one where the seller controls the transaction and can refund it, purchase verification raises the price of a fake review by a few dollars, which prices out casual abuse and not organised abuse. Review brokers advertise this openly as a service tier.
The second limit is structural: verified purchase only exists inside a platform that owns the transaction. That is a small fraction of where reviews actually matter. A restaurant review site does not process your dinner. A local business listing does not process the plumber's invoice. A service marketplace often does not see the final engagement. An app store cannot verify a purchase for a free app. A software review site sits entirely outside the buying relationship.
Every one of those surfaces carries commercially decisive reviews and none of them can use the one control that works reasonably well. That gap is where fake review supply concentrates, and it is not an accident that it does.
Why do review classifiers keep failing?
The other dominant defence is machine classification of review text and reviewer behaviour. Platforms invest heavily here, publish takedown statistics, and remove very large volumes of content. This work is real and it does remove a lot of low effort abuse.
It also sits on the wrong side of an arms race that has recently turned. A text classifier trained to spot generated review text is competing against generation models that improve faster than classifiers do, that can be tested against public detectors before deployment, and that can be instructed to write in whatever register the classifier associates with authenticity. The classifier looks at the output; the adversary can iterate against the classifier. That asymmetry only goes one way.
The cost nobody counts
Here is the part that gets almost no attention and deserves a great deal, because it lands on people who did nothing wrong.
Every classifier has a false positive rate. When a review classifier fires incorrectly, a real customer who wrote a real review about a real experience has their review silently removed or suppressed. They usually are not told, or are told in a form message. They cannot appeal to anything that resembles a human. They have no way to demonstrate they are a real person, because the platform never established that in the first place and has no mechanism to establish it now.
Search any seller or consumer forum and you will find people describing exactly this, often people whose reviews were removed because they wrote enthusiastically, or wrote several reviews in a week after a house move, or wrote in a second language, or used a VPN. Non native English speakers are disproportionately affected, because fluent but slightly unusual phrasing is a signal both of a second language speaker and of a translation pipeline.
So the current equilibrium is that platforms fail in both directions at once. Fake reviews get through in volume, and honest reviewers get silenced with no recourse. Both failures come from the same root: the platform is guessing, from text and behaviour, at something it never established directly.
Any proposal in this area that does not improve the false positive side is not an improvement. It is a change of who suffers.
What would one human, one review look like?
The control is to establish, at the moment of submission, that the reviewer is a distinct human, without collecting who they are.
Concretely: before the review posts, the reviewer completes a brief interaction on their own device. A face match runs locally, on the device, and the face never leaves it. What the platform receives is a signed receipt containing a one way key that is stable for that person on that platform and reversible to nothing.
Here is the artifact.
{
"typ": "manav.presence.v1",
"event": "review.submit",
"rp": "reviews.example",
"subject": "biz_41c9f0",
"human_key": "hk_a83f21e7c4...",
"assurance": "device-bound",
"iat": "2026-09-12T09:14:22Z",
"exp": "2026-09-12T09:19:22Z"
}
The field doing the work is human_key. It is derived on the device and scoped to this platform. The same person returning next month produces the same key. A different person produces a different one. Nobody, including us, can turn it back into a face, a name, or an email address, and it does not carry to any other platform.
Pair it with subject, which names the business or product being reviewed, and the platform can enforce a rule it has never been able to enforce before:
const keys = await fetchOnce('https://manav.id/.well-known/manav-keys')
function acceptReview(receipt, review) {
if (!verifyEd25519(receipt, keys)) return reject('unverifiable')
if (receipt.rp !== 'reviews.example') return reject('wrong platform')
if (receipt.subject !== review.businessId) return reject('subject mismatch')
if (now() > Date.parse(receipt.exp)) return reject('expired')
// The rule: one human, one live review per subject.
if (hasLiveReview(receipt.human_key, review.businessId))
return reject('already reviewed this business')
return accept(receipt.human_key)
}
Read what that does to the bookshop's Monday morning. Twenty three one star reviews now require twenty three distinct humans, each present on a distinct device, each completing a liveness check. The farm that produced them for a few dollars cannot produce them at all. Not "cannot produce them cheaply". The specific capability it was selling, volume from few people, no longer exists on that surface.
And read what it does to the false positive problem, which is the half nobody addresses. The platform no longer needs to guess whether an enthusiastic reviewer is a bot, because it has evidence. The honest reviewer who used a VPN, or wrote in a second language, or posted three reviews in one week after moving house, carries a receipt. Guessing gets replaced by checking, and the person who paid the price for bad guesses stops paying it.
| Control | Fake reviews stopped | Honest reviewers blocked | Personal data retained | Works off platform? |
|---|---|---|---|---|
| Text classifier | Falling, adversarial | Meaningful and unmeasured | Review text, behaviour history | Yes |
| Account age and reputation | Low, farms age accounts | High for new users | Full account history | Yes |
| Verified purchase | Good where it applies | Blocks non purchasers with real experience | Purchase records | No |
| Phone or ID verification | Good | High, and deters anonymous honest reviews | Phone number or government ID | Yes |
| One human, one review receipt | Removes volume abuse | Low, and reversible on appeal | A one way key, no identity | Yes |
The last row's data column is the one to sit with. Every other control that meaningfully raises the cost of a fake review does so by collecting more about the reviewer. This one raises the cost by collecting less, because uniqueness and identity are different properties, and reputation systems only ever needed the first.
The same primitive is doing the work in survey panels, in model training data, and in paid conversions. Reviews are simply the surface where the regulator arrived first.
What this cannot do
The limits here are sharp and a platform should understand them before treating this as a compliance answer.
- It does not make reviews sincere. This is the big one. A real person paid twenty dollars to write a glowing review of a product they never used will produce a perfectly valid receipt, because a real person really is present. This control removes volume abuse, which is where the economics of review fraud live. It does not detect a bought opinion. The remedy for authentic paid reviews is disclosure enforcement under the same FTC rule, not cryptography, and anyone telling you otherwise is overselling.
- Uniqueness is per platform today. One human, one review of this business on this site is available now. One human, one review of this business anywhere would require cross platform nullifiers, which are on our roadmap and are not shipped. A determined actor can review the same business on five sites.
- It adds a step. Any friction at submission reduces review volume, and review volume has value to platforms. The honest framing is a trade: fewer reviews, each of which means something. Some platforms will not want that trade, and the ones whose business model rewards volume over trust will be slowest to adopt.
- It needs a fallback. Some people cannot complete a device based check. There must be a staffed alternative path, and any platform that uses this as an excuse to remove human support has made things worse, not better.
- It does not address suppression. The FTC rule also covers businesses suppressing negative reviews. A receipt on submission says nothing about what a platform does with a review afterwards. That is a governance and audit problem.
- Historical reviews stay unproven. This works going forward. The existing corpus does not retroactively acquire evidence, and platforms will run mixed populations for years.
What to do this week
- Count your exposure honestly. Multiply the number of reviews you have reason to doubt by the current per violation penalty. Do the arithmetic before someone else does it for you.
- Ask your trust and safety team for the false positive rate on review removals, and what happens to a real customer who is wrongly removed. If nobody can answer, that is the finding.
- Identify which of your review surfaces have no purchase relationship. Those are where abuse concentrates and where your best current control does not reach.
- Pick one high value subject category and pilot a presence receipt at submission. One category, ninety days.
- Report two numbers alongside each rating internally: the share of reviews carrying a receipt, and the distinct human count behind the score.
- Write the agent policy now. A person's assistant drafting a review of a real experience is different from an unattributed bot, and you want that distinction defined before the volume arrives.
- Keep a staffed appeal path and publish how it works.
The fake reviews demo runs the submission gate in a browser with no signup, and the developer documentation covers the receipt format and offline verification.
Frequently asked questions
What is the penalty for fake reviews? Under the FTC's Consumer Review Rule, at 16 CFR Part 465 and in force since late 2024, civil penalties run just above fifty thousand dollars per violation and are adjusted annually for inflation. Because each review is a separate violation, a business that bought a few hundred reviews faces seven figure exposure rather than a fine.
Does verified purchase stop fake reviews? Partly. It raises the cost of a fake review from nothing to the price of the product, which deters casual abuse. Organised farms buy the product. More importantly, it only works on platforms that own the transaction, which excludes restaurant listings, local business directories, free apps, and most service marketplaces.
Can platforms prove reviews are written by humans? Not with classifiers, which infer from text that generative models produce for free. They can prove it at submission by requiring a presence receipt: a signature produced on the reviewer's own device carrying a one way key, which establishes a distinct human without collecting any identity.
Does this mean reviewers lose their anonymity? No. The receipt contains a one way key scoped to that platform, with no name, email, phone number, or document. It cannot be reversed to a person and does not travel to other sites. Reviewers stay pseudonymous, and the platform holds less personal data than phone or ID verification would require.
How is this different from a CAPTCHA? A CAPTCHA estimates whether the current session looks automated, and modern tooling defeats that. A presence receipt establishes that a distinct human was present and produces a durable artifact tied to that specific review, which also gives uniqueness across submissions rather than a per session guess.
Can someone still buy real people to write dishonest reviews? Yes, and this is the honest limit. A paid human writing a review of a product they never used produces a valid receipt. This control removes the volume economics that make review farms viable. Bought opinions from real people remain a disclosure enforcement problem under the same FTC rule.
How do you comply with the FTC Consumer Review Rule? This is not legal advice, but the practical shape is: stop any prohibited practices including buying reviews and suppressing negative ones, document the measures you take against fake reviews, and be able to evidence them. A control that produces per review artifacts is materially easier to evidence than a classifier whose output is a confidence score.
Sources
- FTC Rule on the Use of Consumer Reviews and Testimonials, 16 CFR Part 465, final August 2024. ecfr.gov
- Federal Trade Commission, enforcement actions and warning letters on deceptive reviews. ftc.gov press releases
- Digital Markets, Competition and Consumers Act 2024, United Kingdom. legislation.gov.uk
- Competition and Markets Authority, work on online reviews. gov.uk CMA
- European Commission, Digital Services Act. digital-strategy.ec.europa.eu
- Trustpilot, transparency reporting on removed reviews. trustpilot.com/trust
- Amazon, statements and legal action on review brokers. aboutamazon.com
- J. R. Douceur, The Sybil Attack, on identity multiplication in peer to peer systems. Microsoft Research
A reputation system does not need to know who you are. It only ever needed to know that there is one of you.