Google has never been investigated over its ad library. We scored it against the ones that were.

July 22, 2026Google Search
EU ad-library transparency score: we scored every big ad library against DSA Article 39; Google got an F.

Most of the Digital Services Act asks platforms to manage vague things: systemic risk, diligence, mitigation. Article 39 is different. It names the fields. Every very large platform has to keep a public repository of every ad it runs in the EU, showing the ad, who advertised, who paid, when it ran, how it was targeted and how many people it reached, member state by member state. It has to be searchable, reachable by API, and kept for a year. That specificity is what makes it the one ad-transparency duty you can score, field by field.

So we did, for all four big repositories, against twelve requirements drawn from the text of Article 39 itself. Each requirement is scored from zero to one for how fully the library delivers it, using the Commission’s own proceedings, independent audits, and our own live testing. The result is a single number out of 100.

Nobody is close to full marks. But the spread is the story: two libraries pass, two fail, and the one that has never been investigated fails as badly as the one the Commission fined.

The scoreboard

EU AD-LIBRARY TRANSPARENCY SCORE · DSA ARTICLE 39
Repository Score Grade DSA status
Meta
Meta Ad Library
85 / 100
B Investigated on other grounds
TikTok
Commercial Content Library
80 / 100
B Breach found; binding commitments
Google
Ads Transparency Center
33 / 100
F Never investigated
X
X Ads Repository
14 / 100
F Fined €120M

Meta leads on 85 and TikTok on 80, both a B. Then a cliff: Google scores 33 and X 14, both an F. The ranking is almost the inverse of enforcement. X, the only platform fined, is last. TikTok, under a binding order to fix its library, is second. Meta, under investigation on other grounds, is first. And Google, the only one of the four never subject to a single DSA proceeding, is in the failing tier.

Where Google sits

Google is the quiet case. No preliminary finding, no commitment, no fine, not even a formal investigation. On paper that looks like a clean record.

The score says otherwise: 33 out of 100, an F, level with the platform the Commission fined. Google’s Ads Transparency Center shows targeting by country and nothing more. Its reach data is delayed and stripped of demographics. It carries no influencer or branded-content disclosure. You cannot search it by what an ad says, only by advertiser name. Its DSA impression data lags around 90 days, most of an election campaign. The advertiser identity it does show is often flagged “verified” yet reads as gibberish, and the field for who paid does not surface correctly.

It also misses a requirement most people overlook. Article 39(3) says ads a platform removed for breaking its rules must still appear in the repository, with a reason. Google files removed ads in a separate library instead, which breaks the trail for anyone trying to study enforcement in one place. Meta and TikTok keep removed ads in the repository; X does not.

So the platform the Commission has never touched runs a repository as weak as the one it fined, and far behind the two it has pressured. The lesson is not that Google is uniquely bad. It is that enforcement attention and repository quality have come apart, and Google is the clearest proof.

The full scorecard

THE FULL SCORECARD · 12 REQUIREMENTS × 4 LIBRARIES
Article 39 requires
Meta
85 B
TikTok
80 B
Google
33 F
X
14 F
1. The ad itself
Art. 39(2)(a)
1.0
Creatives stored and shown
0.7
Spark ads shown but not marked SMT
0.5
Creative shown, no ad URL SMT
0
Ad content missing EC
2. Who advertised
Art. 39(2)(b)
0.7
Self-declared, weakly verified audit
0.7
Self-declared SMT
0.7
“Verified” but often gibberish SMT
0.5
Raw CSV only audit
3. Who paid
Art. 39(2)(c)
0.7
“Paid for by” self-declared audit
1.0
Funding data now full SMT
0.3
Not surfacing correctly SMT
0
Paying entity missing EC
4. When it ran
Art. 39(2)(d)
1.0
Run dates shown
1.0
Run dates shown
1.0
Date range shown
0.5
Buried in CSV dumps audit
5. How it was targeted
Art. 39(2)(e)
1.0
Full targeting shown SMT
1.0
Targeting criteria shown SMT
0.2
Country only SMT
0
No workable disclosure audit
6. Who it reached
Art. 39(2)(g)
1.0
Member state, age and gender
0.5
Ranges only; per-state due Dec 2026 EC
0.2
Delayed, no demographics SMT
0
No usable reach data audit
7. Influencer / branded
Art. 39(2)(f)
1.0
Branded ads fully shown SMT
1.0
Covered by design
0
Not shown SMT
0
Not shown SMT
8. Removed ads
Art. 39(3)
1.0
Kept in the repository SMT
1.0
Kept in the repository SMT
0
Shunted to a separate library SMT
0
Not provided SMT
9. Searchable & reliable
Art. 39(1)
0.75
Keyword searchable SMT
0.7
Now keyword searchable SMT
0
Advertiser lookup only audit
0
No searchable tool EC
10. API access
Art. 39(1)
0.3
Rate-limited; Art. 39 bars limits SMT
0.3
Registration wall, no public API SMT
0.3
No general API; ~90-day lag audit
0
Access barriers block scrutiny EC
11. One-year archive
Art. 39(1)
1.0
One year; seven for political
1.0
One-year archive
0.75
One year, but ~1/4 lags 90 days SMT
Unverifiable behind barriers
12. How current the data is
Art. 39(1)
0.7
Ads appear within ~24h audit
0.7
24h updates (binding) EC
0
DSA impression data lags ~90 days audit
0.5
Batched CSV, not continuous audit
Score / 10085803314
Every score carries the finding behind it. Evidence tier: EC Commission finding · audit independent audit · SMT our own live test · no public evidence (excluded). The “removed ads” row is Art. 39(3): ads taken down must still appear in the repository.

Four of the twelve requirements are delivered in full by no platform at all: a verified advertiser identity, a working search, an open API, and data that is actually current. Rate limits and registration walls are the common thread on the API row, and Article 39 leaves no room for them: it requires programmatic access, plainly.

What a high score does not mean

One honest caveat. This scores the repository as a disclosure tool. It does not score whether a platform’s ads are any good, or whether its ad review works.

Meta is the sharpest example. It tops the table on 85, and its Ad Library is genuinely the most complete of the four. Yet researchers at AI Forensics used that same library’s data to document thousands of approved pornographic ads and tens of thousands of health-scam ads reaching hundreds of millions of people in the EU. That is not a contradiction. It is the point. A working ad library is exactly what lets outsiders catch bad ads. The libraries that score highest are the ones doing the job Article 39 was written to force.

The bottom line

Line the scores up against the enforcement record and one pattern holds. The platform that was fined runs the worst library. The platform that has never been investigated is failing almost as badly. Two libraries earn a B, two earn an F, and one of the two failing has never once been examined. Article 39 was meant to make advertising legible. So far it has forced two repositories to a passing grade and left the other two, one fined and one untouched, well short.

Methodology: scores come from our Article 39 Scoreboard, which grades all twelve requirements against European Commission proceedings, independent audits (principally Mozilla and CheckFirst’s 2024 stress test and AI Forensics’ 2025 investigations) and our own live testing of each library. Each requirement is scored from 0 to 1 for how fully it is delivered; requirements with no public evidence are excluded. Full case timelines are in our DSA Enforcement Tracker. Libraries last tested July 2026.

Latest blog posts

View All