
Here is a moment that increasingly happens in agency client reviews. The CMO opens a screenshot of a competitor's ad next to controversial editorial content. They turn to the room and ask, calmly, "Can this happen to us?"
The honest answer is that it can, on any programmatic campaign that is not actively configured to prevent it. The good news is that everything required to do so exists and is well understood. The less good news is that many agencies treat brand safety in programmatic as a default platform setting, not as an active control surface they configure, monitor and adjust over time.
This article looks at the six control layers that determine whether a programmatic campaign is actually safe, what each one protects against, and what advertisers should expect from a well-configured setup. It is the third in a series following the Programmads pillar article on the four misconceptions still holding agencies back and the article on completing the digital mix beyond search and social.
Brand safety used to be a media buying concern. In 2026, it is increasingly a question CMOs face from their boards, their regulators and the journalists who track where advertiser placements land.
Three shifts have changed the conversation:
First, public scrutiny of ad placement has intensified. Civil society organisations and journalists track which brands appear alongside problematic content, and a single screenshot can travel faster than any apology.
Second, regulators in Europe and beyond are formalising expectations around advertising adjacency, particularly in regulated sectors such as financial services, healthcare, alcohol and gambling.
Third, internal governance has tightened. Boards increasingly ask CMOs to evidence the specific safety controls that protect brand reputation, not just confirm that "we use a brand safety tool".
The result is a shift in expectations. Agencies are no longer asked "is your media buying safe?" but "what specifically have you configured to keep it that way?" Generic references to platform settings no longer satisfy that question. The answer has to be a specific account of the layers in place, and the evidence of how they are maintained.
Before the layers, a distinction worth holding. Brand safety asks whether a placement is universally unacceptable: hate speech, adult content, harmful content no advertiser wants to fund. Brand suitability asks something narrower and more useful. Is this environment right for this brand, at this moment, given its brand values and its risk tolerance?
A news site covering a natural disaster is not unsafe. It is unsuitable for an airline and perfectly suitable for an insurer. Brand suitability is where the actual editorial judgment happens, and it is the part no platform can answer on the advertiser's behalf. The six layers below serve both questions, but suitability is what turns them from a compliance exercise into a brand safety strategy.
Programmatic brand safety in practice is not a single setting. It is a set of six layers, each with a distinct role. A well-configured campaign uses all of them. Each layer is concrete, configurable, and auditable.
The first layer defines where the campaign is even allowed to bid. Two opposite mechanisms work together.
Whitelists restrict bidding to a curated set of environments: specific URLs, mobile apps, or YouTube channels that match the brand's positioning. A luxury brand might whitelist only premium editorial titles. A B2B software brand might whitelist business publications and trade press. In both cases, the effect is the same: the advertiser knows which publisher receives the spend.
Blocklists do the opposite. They remove environments unsuitable for the brand, even within otherwise allowed inventory: low-quality sites, environments with thin content, or known problem domains. This exclusion works at domain level, and it is also where supply path decisions belong. Buying the same publisher through four resellers instead of one direct path multiplies the surface where bad actors can intervene, and domain spoofing thrives on long, opaque supply chains.
These two mechanisms are not set-and-forget. Whitelists need quarterly review as new premium environments emerge. Blocklists need maintenance as poor-performing sites surface during campaigns.
The second layer filters by the type of content on each page or video, before the bid is placed.
Digital content labels classify inventory by maturity rating, modelled on cinema-style classifications (G for general audiences, MA for mature audiences). A toy brand configures the campaign to G only. A spirits brand configures to MA.
Sensitive content categories block placements next to content covering predefined themes that may damage the brand: tragedy, conflict, controversial political content, weapons, and a dozen other categories. The relevance varies with each advertiser's risk tolerance. An airline excludes "tragedy". A bank excludes "financial crisis". A consumer brand excludes "controversial".
These pre-bid filters are available in every major DSP, but they require active configuration per campaign. Default settings are rarely sufficient, and this is the single most common gap in programmatic campaigns that look protected on paper.
The third layer goes below content categories into the actual words on the page. Each brand has its own sensitivities that generic filters do not capture.
Keyword exclusion lists are custom-built per brand. A mineral water company excludes pages mentioning "pollution", "microplastics" or "groundwater contamination". A gaming company excludes pages discussing "addiction" or "regulation". A financial services brand excludes "fraud" or "scam".
Sentiment adds a further dimension. The same keyword can appear in an article praising a brand and in one attacking it, and a list that blocks on the word alone will block both. Modern pre-bid tools read tone as well as vocabulary, which is what keeps a keyword list from quietly removing the inventory an advertiser most wants.
There is no off-the-shelf list. The agency or its trading partner builds the list from the brand's positioning, recent reputational incidents and current sensitive topics. This is also the layer most often skipped, because it requires upfront work and ongoing maintenance.
The fourth layer does not configure delivery: it verifies it, after the impression is served.
Independent verification tools (IAS, DoubleVerify) audit ad delivery in real time. They confirm three things on every impression:
The ad ran on a safe domain that matches the campaign's brand safety rules
The impression was seen by a human, not by a bot or in a hidden iframe
The placement met viewability thresholds (typically 50% of pixels visible for at least one second)
That second point is where ad fraud detection sits. Invalid traffic, whether from bot networks, hidden placements or spoofed domains, does not just waste budget. It corrupts the reporting an advertiser uses to make every subsequent decision, which is why detection belongs in the verification layer rather than beside it.
The output is a daily or weekly report that the agency reviews and acts on. Domains flagged for issues are blocked. Discrepancies between DSP reporting and the third-party verification tool are investigated. This post-bid verification adds cost (typically 2 to 4 percent of media spend), but in 2026 it is the standard expectation for any campaign above a meaningful budget threshold.
The fifth layer is positive targeting: not what to avoid, but what to actively reach.
Audience layers define who sees the digital ad. First-party data (CRM, website visitors, customers matching a specific profile) is the most precise. Intent-based audiences capture users actively researching a category. Demographic and interest-based audiences provide broader reach.
Contextual targeting defines what content the ad appears next to. It analyses page content in real time and matches the ad to relevant editorial environments. A car brand can target articles about driving, automotive reviews or commuting, regardless of the user's identity. Contextual signals also carry a suitability benefit: they place ads next to content the brand has actively chosen, rather than merely content it has not excluded.
Together, contextual targeting and negative filtering replace the "anywhere, anyone" default of basic open-auction programmatic buying with a precision posture.
The sixth layer manages how often each user sees the campaign. Over-exposure is a brand risk in itself: a user who sees the same brand 15 times in a week perceives intrusion, not interest.
A unified frequency cap aims to recognise each user across smartphone, desktop and connected TV, and to stop serving once the threshold is reached. Budget then reallocates automatically to fresh users. In practice, the precision of this recognition depends on the identity signals available: it is most reliable in authenticated environments (logged-in CTV, mobile apps with persistent IDs) and less precise on the open web, where it relies on clean room synchronisation or probabilistic matching. Even with these limits, a unified cap is substantially more effective than running campaigns across separate DSPs with no coordination at all.
Frequency caps are typically set per week (three to five exposures is a common range), but vary by campaign objective and brand.
Configuring the six layers is the visible part. The invisible part is what determines whether these brand safety measures actually protect the brand over time.
A well-configured campaign has:
Most agencies get the initial setup right. Many fail on maintenance, monitoring and crisis readiness, because these require a dedicated operational discipline that is hard to sustain alongside other account responsibilities.
Three moves are worth starting now:
1/ Audit your live campaigns against the six layers. For each layer, document what is currently configured. Most audits surface at least two layers that are either at default settings or absent.
2/ Build a brand safety brief template. Every new advertiser onboarding should produce a documented brief: what the brand wants to avoid, which keywords are sensitive, what verification thresholds apply, where the risk tolerance sits. This becomes the configuration reference for every campaign and the auditable record for the client.
3/ Decide who owns ongoing operations. Brand safety is not a setup task: it is an ongoing operational responsibility. Agencies that try to fit it into account managers' existing workload tend to lose the maintenance cadence. The choice is to dedicate a brand safety operator internally, or to partner with a specialist trading provider that runs the cadence as a core service.
These moves do not require new brand safety tools. They require an operational posture that treats brand safety in programmatic advertising as an active control surface, not a default setting.
Brand safety is not a one-time configuration. It is a continuous discipline: weekly verification reviews, monthly keyword maintenance, quarterly whitelist refreshes, real-time crisis response.
For most independent agencies, sustaining this alongside campaign management, client reporting and new business development is not realistic. The operational depth required is closer to a specialist trading function than to a generalist account team.
The alternative is to partner with an AdTech provider that runs brand safety as a core service. The agency keeps ownership of the brief (what the brand wants to avoid) and the client conversation. The partner runs the operational layer: configuration, monitoring, verification reviews, and adjustments. The brand stays protected, the agency stays in command, and the advertiser receives the documented evidence of controls that boards increasingly require.
Ready to upgrade your clients' brand safety operations? Get in touch to discuss your next campaign.