Programmatic

AI slop is eating your programmatic budget: the MFA problem

MFA sites are a structural arbitrage: cheap impressions, thin content, and audiences that mostly are not there. Generative AI lowered the content cost to near zero, which means the supply keeps growing. The fix is not a better blocklist.

AI slop and MFA programmatic brand safety: ink line illustration of a tangle of dotted supply-path lines, an empty rectangular ad frame, and sparse ruled lines, with a small solid orange blot caught in the tangle.

Bottom line

MFA sites win open exchange auctions on CPM alone and deliver audiences that are mostly not there. Generative AI lowered their content cost to near zero, accelerating supply faster than exclusion lists can track.

  • The fix is inclusion-list thinking: define a verified publisher set and weight impressions toward private marketplace deals.
  • Push your DSP for supply path optimisation. MFA sites monetise through aggregators, not direct SSP relationships.
  • Connect quality decisions to outcome metrics, not CPM. The campaign that looks efficient on impression-side reporting is often the least effective on business outcomes.
  • Exclusion lists decay constantly. Quarterly review of your inclusion list is the maintenance cadence that keeps them honest.

What MFA sites actually are (and why the definition keeps shifting)

Made-for-advertising sites are properties built primarily to capture programmatic ad revenue rather than to serve readers. The content is incidental. The business model is the inventory stack: dense ad units, aggressive refresh logic, auto-play video, and traffic sourced through content recommendation widgets that deliver high impression counts at low reader attention.

The label has been contested since it emerged as an industry term. Some publishers with legitimate audiences run high ad density out of necessity; some MFA operators have learned to mimic editorial trappings convincingly. The structural signal matters more than the surface. A site whose revenue model only works when ads outnumber content, or whose traffic collapses without paid sourcing, is functionally MFA regardless of how the masthead reads.

Generative AI has sharpened the problem. Content that once required a room of low-cost writers can now be produced at near-zero marginal cost per page. A site that previously needed weeks to build topical depth for a given keyword cluster can produce hundreds of articles overnight. The barrier to launching a credible-looking MFA property has dropped close to zero, which means the scale of the problem grows with every model capability improvement.

Google's own publisher policies are explicit about the structural failure: ads served on pages where paid promotional material outnumbers publisher content are a policy violation. The same policies prohibit serving ads on "low-value content" and on pages with "embedded or copied content from others without additional commentary, curation, or otherwise adding value." Those policy lines describe the MFA playbook almost word for word. The gap between policy and enforcement is where the arbitrage lives.

How MFA inventory routes into brand budgets

Most brands running open exchange programmatic are not buying MFA inventory directly. They are buying audiences, keywords, and contextual categories through a DSP, and the DSP's algorithm finds the cheapest impression that matches the targeting parameters. MFA sites are structured to win those auctions: they produce high volumes of cheap impressions in broad content categories (news, lifestyle, finance, entertainment) that match common targeting setups.

The path from brand budget to MFA site typically runs through a supply-side platform and multiple intermediaries. Each hop adds a margin cut and reduces transparency. By the time the impression renders on the MFA property, the buying team's dashboard shows a category match, a viewability number (often technically accurate because the ad did render), and a CPM that looks efficient. What it does not show is that the page had seventeen other ads loading at the same time, the reader was driven there by a clickbait widget, and the session lasted under thirty seconds.

The efficiency signal is a trap. MFA inventory tends to show lower CPMs because the supply volume is enormous and the audience quality is poor. A campaign that achieves a low CPM by routing a large share of spend to MFA inventory is not an efficient campaign. It is an inefficient one that looks efficient on the metrics that get reported.

Industry bodies including the IAB Tech Lab and ANA have published guidance that classifies MFA inventory and calls for supply chain actors to flag or filter it. The IAB Tech Lab released a formal MFA Definition and Detection Framework in 2024; the ANA has published supply chain transparency studies and recommendations covering the same problem. Verification vendors DoubleVerify and IAS both operate MFA classification categories within their brand safety products. But classification operates at the domain or URL level, and MFA operators are faster at creating new domains than classifiers are at flagging them.

The structural fix is not faster classification. It is reducing the open exchange pool available to MFA operators in the first place, which is an inclusion-list problem rather than an exclusion-list problem. We return to that below.

Detection signals buyers can use

No single signal is definitive. MFA sites that have learned to game one detection vector often fail on another. The reliable approach is to evaluate signals in combination and to weight structural evidence over surface indicators.

Ads-to-content ratio. This is the defining structural signal. A page where ad units occupy more visual space than editorial content is flagging its own purpose. Counting ad slots versus word count is a crude proxy; a more useful measure is visual real estate. Pages with interstitials before content loads, ads above the fold with editorial content below, or sticky video units overlaying text are all high-ratio patterns. Google's publisher policy language about "more ads or other paid promotional material than publisher-content" describes the threshold with some precision.

Traffic sourcing. MFA sites typically cannot sustain traffic organically because their content is not genuinely useful. They rely on paid distribution: content recommendation widgets (the "around the web" grids at the bottom of news pages), social arbitrage, and occasionally bot-amplified traffic. Sellers.json and ads.txt provide some supply chain transparency, but they do not reveal traffic sourcing. Third-party tools that analyse referral patterns can surface anomalous traffic compositions. A site drawing the majority of its traffic from paid content widgets is a red flag regardless of the content quality.

Refresh and session behaviour. Auto-refreshing ad units inflate impression counts without corresponding attention. A user who lands on a page, decides it is not useful, and leaves within twenty seconds may generate multiple ad impressions through refresh before departure. Session duration and pages-per-session are not metrics most buyers see in their DSP reporting, but they are available through publisher-level analytics that supply path transparency initiatives are beginning to surface.

Ad slot density and placement patterns. More than five or six non-native ad placements on a standard article page is an elevated signal. Ads placed inside the content body at unusually frequent intervals (every paragraph, for instance) indicate a page designed to maximise visual contact rather than reading flow. Sticky video players that continue running after the reader has scrolled past them exploit viewability measurement without capturing genuine attention.

Content depth and originality. Generative AI has made thin content harder to identify by surface reading. An MFA page generated by a language model may be grammatically correct and topically relevant. The diagnostic is depth: does the content provide original analysis, cite primary sources, or demonstrate expertise that could only come from direct experience? Shallow content that covers the same keywords as a hundred other pages without adding anything is the editorial equivalent of the ads-to-content signal.

Supply path optimisation reduces MFA exposure by cutting indirect hops. Buyers who push their DSPs to shorten supply paths see fewer MFA impressions in reporting, not because MFA sites disappeared, but because those sites monetise primarily through aggregators and resellers, not direct publisher relationships.

Inventory quality checklist

Run this against any placement domain you are considering adding to an inclusion list or want to audit in your current open exchange mix. The checklist is not a fraud detection system. It is a structured review of structural signals.

Inventory quality checklist (click to mark)
Ads-to-content ratio passes inspection Open 3 random articles. Editorial content should dominate the visual field. If ads are above, beside, between every paragraph, and sticky at the bottom, stop here.
Content depth is genuine Articles cite sources, show original analysis or direct experience, and could not have been produced by a single generic model prompt. Topical coverage matches claimed audience.
No auto-refresh ad units visible Sit on a page for 30 seconds without scrolling. If ad slots reload without a page action, the publisher is inflating impression counts.
Traffic sourcing is plausible Check if the site appears to have organic search presence, social presence, or direct audience. Heavy reliance on content recommendation widgets as inbound traffic is a red flag.
Supply path is direct or close to direct Check ads.txt for the domain. An authorised seller list dominated by resellers rather than the publisher's own SSP relationship indicates indirect monetisation.
Publisher identity is verifiable Can you identify who operates the site, find a contact, confirm the editorial team? Anonymous or recently registered domains with no identifiable publisher are high-risk.
Verification vendor classification is clean Run the domain through your verification vendor's MFA category check. Flag rather than block automatically, but note any classification and weight it alongside structural signals.
Your brand would be comfortable being seen here Not brand safety in the harmful-content sense. In the brand-value sense: if a senior stakeholder saw your ad on this page, would it reflect how you want the brand associated?
Checked: 0 / 8

How generative AI changed the MFA threat level

The MFA playbook predates large language models by years. Content farms in the early 2010s used low-cost outsourced writing to populate keyword-targeted sites with enough text to pass basic quality filters. What generative AI changed is the economics of scale and the speed of adaptation.

A competent MFA operator can now spin up a new domain, populate it with hundreds of contextually relevant articles, configure ad networks, and start bidding on supply within a few days. The content looks different from the machine-translated spam that characterised earlier content farms. It passes spelling and grammar checks. It achieves basic topical relevance. It does not pass an editorial quality test, but editorial quality is not what programmatic auctions measure.

The acceleration matters for buyers in three ways. Domain blocklists decay faster. A list of known MFA domains compiled last quarter is already partially stale because new domains have launched since. Exclusion-list strategies require continuous maintenance to remain effective. The similarity between AI-generated content on legitimate sites and AI-generated content on MFA sites also makes content quality harder to use as a standalone signal. Publishers with genuine editorial operations use generative AI to assist writers; the output can look superficially similar to MFA-generated text. And the volume of MFA inventory grows with model capability improvements, so the absolute amount of brand spend at risk increases even when percentages stay flat.

The connection to brand safety is real but specific. MFA sites are not brand-unsafe in the same sense that sites hosting harmful content are brand-unsafe. A financial services ad appearing on a thin lifestyle article is not a reputational incident. The harm is subtler: the ad delivered no genuine attention, consumed budget that could have reached a real audience, and contributed to a measurement environment where brands systematically overestimate campaign effectiveness. Reach and frequency metrics on campaigns with heavy MFA exposure are not accurate.

Leapbuzz runs a hard editorial gate on its own content for the same structural reason MFA operators exploit the lack of one. When content cannot survive reader scrutiny, it relies on algorithmic amplification. Content that earns genuine readership does not need the arbitrage. Sites that exist to generate ad impressions rather than serve readers are producing AI slop, and the distinction matters when your brand is paying for placement.

Inclusion-list thinking: why allowlists beat blocklists at scale

The dominant industry instinct is to fight MFA with exclusion lists: block known bad domains and keep the rest of the open exchange available. That is the wrong architecture for a world where new MFA domains launch continuously and AI-generated content makes surface-level detection unreliable. Inclusion-list thinking reverses the default: start with a defined set of verified publisher relationships and only expand when a new publisher passes review. The open exchange remains available for prospecting, but the bulk of impressions run against a curated pool.

In practice this means three structural moves. First, allocate a meaningful share of programmatic display budget to private marketplace deals with publishers whose audiences match your targeting and whose inventory you have reviewed manually. PMP deals bypass open exchange dynamics entirely; MFA inventory does not appear in PMP unless you build a PMP with an MFA operator, which requires active effort to avoid.

Second, ask your DSP to surface supply path information and prioritise direct publisher-SSP relationships over reseller chains. Supply path optimisation (SPO) reduces MFA exposure because MFA properties monetise primarily through aggregators, not direct SSP integrations. Third, apply the checklist above before adding any domain to an active inclusion list, and review the inclusion list on a quarterly cadence as new publisher data becomes available.

CTV and retail media sit outside the open web MFA pool. Inventory is smaller and more verifiable, publisher identity is clearer, and the arbitrage that dominates display does not transfer directly. The inclusion-list discipline matters most on open web display. For the CTV quality angle see the programmatic CTV partner guide; for closed-loop measurement see retail media CTV.

The measurement layer is where the inclusion-list shift produces the most visible results. When you move spend from open exchange to curated placements, reported CPMs usually rise. Apparent efficiency drops. But campaign outcome metrics, where they are measured properly, tend to improve or hold steady. A higher CPM against a real audience is a better investment than a lower CPM against a bot-amplified MFA property. Connecting your programmatic quality decisions to outcome measurement rather than impression-side efficiency metrics is the analytical move that makes the argument internally. See our media integration service for how we approach this measurement architecture with clients across Singapore, Australia, the US, Canada, and Malaysia.

Frequently asked questions

What is a made-for-advertising (MFA) site?

A made-for-advertising site is a web property built primarily to generate programmatic ad revenue rather than to serve readers. The defining characteristic is a business model that only works when ad density is high: more ads than editorial content, auto-refreshing slots that inflate impression counts, and traffic sourced through paid distribution networks rather than organic or direct audiences. The content is incidental. Generative AI has lowered the per-page content cost for MFA operators close to zero, accelerating the rate at which new MFA properties launch.

How does MFA inventory end up in brand campaigns?

Most brands do not buy MFA inventory intentionally. They set targeting parameters in a DSP and the algorithm finds the cheapest impression that matches. MFA sites produce high volumes of cheap impressions in broad content categories and win those auctions. The supply path typically runs through multiple intermediaries, so the impression renders on an MFA property while the DSP dashboard shows a viewable, contextually matched impression at an efficient CPM. The low CPM is the signal of low quality, not of efficiency.

What is the single most reliable detection signal for MFA inventory?

Ads-to-content ratio is the defining structural signal. A page where paid ad units occupy more visual space than editorial content is structurally MFA regardless of the content quality. Google's own publisher policies describe the threshold: pages where ads outnumber publisher content are a policy violation. Open 3 to 5 random articles on any domain you are evaluating. If ads dominate the visual field above, beside, and between every paragraph, the site is built around the ad inventory, not the reader.

Why is an exclusion list not sufficient to block MFA inventory?

Exclusion lists (blocklists) require you to identify bad domains and add them to a deny list. MFA operators using generative AI can create new domains faster than classifiers can flag them. A blocklist compiled last month is already partially stale. Inclusion-list thinking inverts the problem: start with a defined set of publisher relationships whose quality you have verified, and only expand when a new publisher passes review. The open exchange remains available for prospecting, but impressions are weighted toward curated inventory you have reviewed.

How does supply path optimisation reduce MFA exposure?

MFA sites monetise primarily through aggregators and reseller chains rather than direct publisher-SSP relationships. When buyers push their DSPs to shorten supply paths and favour direct integrations, the indirect pool where MFA inventory concentrates shrinks. Supply path optimisation (SPO) does not eliminate MFA exposure on its own, but it reduces it structurally by cutting the routes MFA operators rely on. Combined with inclusion-list curation and verification vendor MFA classification, SPO is one of three complementary controls.

Do DoubleVerify and IAS MFA categories catch all MFA inventory?

No. DoubleVerify and IAS both operate MFA classification categories within their brand safety products and those classifications are useful signals. But classification works at the domain or URL level and operates retrospectively. A newly launched MFA domain will not appear in classification databases until it has been identified, crawled, and categorised, a process that takes time. Generative AI has shortened the time from domain creation to active monetisation, so the lag between launch and classification has become more consequential. Use verification vendor MFA flags as one input among the structural signals in your checklist, not as a complete solution.

How is MFA different from ad fraud?

MFA and ad fraud overlap but are not the same. Ad fraud involves technically invalid traffic: bots generating fake impressions, domain spoofing, or hidden ad stacking. SIVT (sophisticated invalid traffic) detection tools flag these. MFA involves real (or partially real) traffic on pages designed to maximise impressions rather than serve readers. The impressions may be technically valid and viewable while delivering near-zero genuine attention. You can buy MFA inventory through a clean supply chain with no fraud detected and still receive poor value. Both problems exist on open exchange; MFA is the harder one to quantify precisely.

Does the MFA problem apply to CTV and retail media programmatic?

The structural MFA arbitrage that dominates open web display does not transfer directly to CTV or closed-loop retail media. CTV inventory pools are smaller, publisher identity is generally clearer, and the content-ad relationship is structured differently. Retail media networks operate within verified commerce environments where publisher identity is inherent. The inclusion-list discipline matters most on open web display programmatic. CTV and retail media have their own quality and measurement issues that are structurally distinct from the MFA problem.

What happens to campaign metrics when you shift from open exchange to curated inventory?

Reported CPMs rise. Apparent efficiency drops on impression-side metrics. The open exchange average CPM is lower than curated marketplace or PMP CPMs because MFA inventory holds the average down. When that inventory is removed from the mix, the average cost per impression increases. Campaign outcome metrics, where measured properly against business goals rather than impression volume, tend to hold steady or improve. The internal argument for the shift requires connecting programmatic quality decisions to outcome measurement rather than defending CPMs, which is an analytical conversation, not a media-planning one.

Related

Work with leapbuzz

Running open exchange spend you cannot account for? Let's audit the supply chain.

leapbuzz builds programmatic strategies for brands across Singapore, Malaysia, Australia, the US, and Canada that connect media quality decisions to outcome measurement. Inclusion-list architecture, supply path optimisation, and the measurement layer to prove it.

Talk to us