Grey Hat vs Blackhat in Direct Response: Where the Legal Line Actually Sits

11 min read

Reviewed by

Daily Intel Research Team

Evidence base

VSLs, ads, funnels, UTMs, transcripts, and market pattern review

Coverage

14+ languages · blackhat, greyhat, and whitehat patterns

8,226+

Videos & Ads

+50-100

Fresh Daily

$29.90

Per Month

Full Access

12.5 TB database · 72+ niches · cancel anytime

is grey hat marketing illegal or just against platform rules?

Grey hat marketing is, by itself, rarely illegal — it is a platform-rules problem first, and most tactics that get labeled grey hat never touch a courtroom. Meta, Google and TikTok each publish an advertising policy that bans behavior no statute prohibits: aggressive urgency copy, borderline health framing, a landing page dressed up as something it isn't. Break one of these rules and the consequence is an ad rejection or an account restriction, not a subpoena. Anyone weighing whether affiliate marketing suits their risk tolerance should separate that fact from the much smaller set of tactics that reach federal court.

Three legal lines run in parallel, and they rarely move together. Platform terms of service are a private contract a company enforces against its own users. Civil fraud statutes — the FTC Act, ROSCA — give a federal agency the power to sue for money and an injunction. Criminal statutes, wire fraud and bank fraud chief among them, put a named person in prison. A single tactic can cross one line, two, or all three at once, and each line carries a completely different cost.

LineWho enforces itWhat crosses itTypical consequence
Platform rulesMeta, Google, TikTok internallyCloaking, circumventing ad review, undisclosed health targetingAd rejection, account or business-asset restriction
Civil fraudFTC, state attorneys general, private plaintiffsUnsubstantiated claims, fake testimonials, negative-option violationsInjunction, monetary judgment, individual liability
Criminal statuteDOJ, U.S. Attorneys' officesWire fraud, bank fraud, money laundering, computer intrusionPrison sentence, asset forfeiture

which common practices are ToS violations but not crimes?

Most of what this industry calls grey hat lives entirely inside the first line: a contract violation with a contractual penalty, nothing more. None of the tactics below has produced a Department of Justice indictment standing alone, and enforcement stays inside the platform that wrote the rule.

The pattern across all five: the worst outcome is losing the asset, whether that's one ad account, one Business Manager, or an entire verified advertiser status. Nobody on this list goes to federal court unless the same tactic is also concealing a claim the FTC has already flagged as false.

  • Cloaking a landing page so Google's or Meta's review system sees one version while a visitor sees another — Google's Abusing the ad network policy names this 'evasive ad content' and suspends the account on detection, without a warning first.
  • Running several ad accounts under one operation without disclosing the relationship between them — Meta's Account Integrity standard treats a repurposed account as evasion and restricts the business asset, not the operator personally.
  • Sending clicks straight from an ad to an offer instead of through a compliance-reviewed bridge page, the choice covered in [direct linking versus a landing page](/learn/direct-linking-vs-landing-pages-in-affiliate-marketing) — a destination-mismatch risk for ad review, not a fraud claim on its own.
  • Running before-and-after transformation imagery that Meta permits for general cosmetic products but TikTok bans outright across a named set of MENA and African markets, so the same creative is compliant on one platform and a violation on another.
  • 'Warming up' a new ad account with small spend before scaling — a widely repeated tactic with no basis in any published Meta, Google or TikTok review document.

when does a policy violation become civil fraud the FTC can sue over?

A policy violation becomes civil fraud the moment the claim underneath it is false or unsubstantiated and money changes hands on the strength of it. The FTC's Health Products Compliance Guidance, issued December 2022, requires 'competent and reliable scientific evidence' — in practice, randomized controlled human trials — before a health or weight-loss claim runs, and states outright that animal or in vitro data alone will not substantiate a claim to a regulator.

Testimonials do not get a disclaimer out of this. The FTC's Endorsement Guides hold that phrases like 'results not typical' fail to cure a deceptive testimonial; the advertiser must instead disclose the results a typical consumer can expect, using the median where outliers skew the picture. The FTC's Gut Check guide lists seven weight-loss claims experts say simply cannot be true, including any claim of loss exceeding roughly three pounds a week for more than four weeks.

Penalty size depends on which FTC authority applies. Ordinary Section 5 deception cases proceed without a fixed per-violation fine, seeking an injunction and consumer redress instead. Cases built on a Notice of Penalty Offenses require the FTC to prove the company knew the conduct was unlawful and that a prior litigated decision — not a settlement — already condemned it; the per-violation ceiling for a knowing rule violation sits at roughly $53,088 as of August 2026, though the FTC's usual January inflation adjustment did not appear this year and the figure needs re-checking once it does.

when does civil exposure become criminal — wire fraud and the CFAA?

Civil exposure turns criminal when the deception funds a scheme to take money under false pretenses, or when the operator breaks into a computer system to pull it off. Wire fraud (18 U.S.C. 1343), bank fraud (18 U.S.C. 1344, carrying up to 30 years per count) and money laundering (18 U.S.C. 1956) are the statutes that convert a marketing dispute into a prison sentence, and each requires proving intent to defraud, not merely a false claim.

The criminal cases on the books involve theft layered on top of deception, not aggressive copy alone. USPlabs executives went to federal prison over the Jack3d and OxyElite Pro supplements — CEO Jacobo Geissler drew 60 months — for concealing a banned stimulant, not for hard-sell marketing. Blackstone Labs' founders each served roughly 54 months for conspiring to defraud the FDA and distribute anabolic steroids. Infomercial pitchman Kevin Trudeau drew 10 years for criminal contempt of a court order, not for the underlying weight-loss claims themselves.

One gap worth naming precisely: no known DOJ criminal prosecution targets a negative-option rebill funnel or a fake-news-site advertorial standing alone. That conduct is civil territory under ROSCA — the FTC's case against Adobe settled for $150 million in March 2026 — because ROSCA itself carries no criminal penalty. The rebill tactics that put someone in front of a grand jury are the ones layered with undisclosed transaction laundering or outright bank fraud, not the negative-option structure by itself.

does the FTC care about your intent or just the claim itself?

The FTC cares about both, and which one governs depends on which tool it reaches for. Under ordinary Section 5 deception authority, intent is irrelevant — the question is only whether the claim's net impression misleads a reasonable consumer, full stop. A marketer who genuinely believed an unsubstantiated claim is still liable for running it.

Under the penalty-offense authority used for the largest fines, intent becomes the entire case. Section 5(m)(1)(B) lets the FTC seek civil penalties only where it proves the company knew the practice was unlawful and a prior litigated administrative decision already said so, which is why the agency blankets an industry with Notices of Penalty Offenses before the lawsuits follow.

Individual liability follows a control-or-participation test regardless of who wrote the specific ad. In its 2026 complaint against TruHeight, the FTC alleged the co-CEOs each 'formulated, directed, controlled, had the authority to control, or participated in' the challenged practices — language broad enough to reach an owner who never touched the copy. The Supreme Court's Bartenwerfer decision reinforces the point from the other direction: a fraud debt survives bankruptcy 'regardless of [the debtor's] own culpability' where a partner committed the underlying fraud.

are aggressive advertorials grey hat or already over the line?

Aggressive advertorials are grey hat when they disclose what they are and stay inside substantiation rules; they cross into fraud the moment they impersonate a real news outlet or fabricate a fake one. A page that dramatizes results but labels itself as advertising and cites real evidence is pushing hard against the Endorsement Guides, not breaking the law.

The FTC has sued over the impersonation version repeatedly, and the pattern holds across a decade of cases. Tarr Inc. settled in 2017 over fake magazine and news sites carrying bogus celebrity endorsements from Dr. Oz, Paula Deen and Jennifer Aniston. Sale Slash built fake news sites with a phony Oprah Winfrey endorsement to sell garcinia cambogia and settled for a partially suspended $43.4 million judgment. LeanSpa ran fake sites bearing CNN, MSNBC and Fox News logos — the FTC's own release called it the agency's 11th case built on fake news sites for supplements.

Liability reaches past the advertiser into the network that approved the pages. A federal court held affiliate network LeadClick responsible for $11.9 million because it recruited the affiliates, approved or rejected their pages, paid them and bought their ad space — and rejected the network's Section 230 defense on appeal. That ruling is the reason a network's compliance review of affiliate creative is not paperwork; it is the fact pattern regulators use to reach the network's balance sheet.

what is the most aggressive position that is still legally defensible?

The most aggressive position that survives scrutiny is bold claims resting on real evidence, disclosed plainly enough that no disclaimer has to do the work of hiding anything. That means citing a randomized controlled trial when a claim states an outcome, disclosing the median result rather than a best-case testimonial, and building a negative-option flow that gives ROSCA's three elements — clear terms, informed consent, an easy way to stop — no gap to attack.

On the payments side the same principle holds: aggressive structure survives if it's disclosed, and collapses the moment it's hidden. Running several merchant IDs to spread volume across a high-risk stack is not itself a violation — it's a marketed feature among processors serving this vertical — but routing one entity's sales through a MID underwritten for a different entity is the undisclosed aggregation that turns a payments strategy into transaction-laundering exposure, the same fact pattern that feeds the ratios covered in how chargebacks actually get a merchant banned.

None of this removes the platform-rules risk covered earlier — an account can still get restricted for creative a court would never touch. But operators who last longest treat disclosure as the variable that moves a tactic between the three lines, not aggression itself. The claim can be as bold as the evidence supports; what can't survive is bold plus hidden, on any of the three lines at once. The older direct response books still worth reading argued the substantiation-first discipline decades before the FTC wrote it into formal guidance.

Quick decision checklist

Use this page as a decision aid, not a generic blog post. The practical question is whether the reader needs faster evidence about what is already working in VSL-driven direct response, especially across nutra, supplements, GLP-1, weight loss, blood sugar, and adjacent high-intent health markets.

Daily Intel Service is most relevant when the next decision depends on active market examples: which hook to test, which claim style is risky, which funnel structure is common, which language market is moving, and whether a competitor's creative is likely early, scaling, or already saturated.

  • Start with the TL;DR if you need the direct answer.
  • Use the table to compare trade-offs quickly.
  • Use the FAQ for answer-engine-ready summaries.
  • Use the CTA when the decision requires live VSL and ad examples instead of theory.

Daily Intel's coverage advantage

Daily Intel Service is positioned around category-leading variety and actionability: one of the broadest direct-response catalogs of VSLs and ad creatives across blackhat, greyhat, and whitehat advertising patterns, with enough context to understand what the advertiser is doing beyond the visible creative. The practical difference is that members are not just seeing a screenshot; they are seeing the VSL, the ad, the funnel path, the transcript, the UTM context, and the research notes that turn the asset into a decision.

This matters because direct-response affiliates do not operate in one clean category. A weight-loss campaign may use a whitehat compliance ad, a greyhat pre-lander, a more aggressive VSL, and a checkout path designed around upsells and recovery. A useful intelligence platform needs to capture that spectrum instead of pretending every winning campaign looks like a public brand ad.

Blackhat, whitehat, and multilingual signal coverage

Daily Intel tracks patterns across both blackhat-style and whitehat-style campaigns so operators can understand the market without blindly copying risk. Whitehat examples help with durability and compliance review; blackhat and greyhat examples reveal pressure points, hooks, mechanisms, and funnel structures that may be driving spend but require careful adaptation before use.

The catalog is also built for global operators, with VSL and ad references spanning 14+ languages and different local idioms. That is a key advantage for Brazilian, LATAM, European, MENA, Indian, and non-native English affiliates who need to see how the same market desire is translated across cultures instead of only studying US English ads.

Research needGeneric ad archiveDaily Intel Service
Creative volumeLarge raw databases with mixed relevanceCurated VSL and ad examples selected for direct-response usefulness
Blackhat and whitehat awarenessOften flattened into screenshots or URLsExplicit attention to compliance spectrum, cloaking risk, and claim style
Post-click contextUsually limited or inconsistentVSL, transcript, funnel path, checkout, upsell, UTM, and recovery notes where available
Language coverageSearch filters may exist, but context is thin14+ language and international idiom coverage for global affiliate research
Best use caseBroad browsing and historical lookupNutra, supplement, GLP-1, VSL, and direct-response campaign decisions

How to use the intelligence responsibly

The goal is modeling, not copying. Use Daily Intel to understand structure: hook, mechanism, proof, claim intensity, funnel depth, offer economics, and saturation stage. Then build original creative, review claims, and adapt the angle to the traffic source, country, language, and compliance requirements of the campaign.

A strong workflow compares multiple examples before acting. If the same mechanism appears across several languages, several advertisers, and several funnel variants, it may be a durable market signal. If the example appears only once or depends on an aggressive claim, treat it as a research clue rather than a campaign template.

  • Model structure, not protected creative assets.
  • Separate whitehat durability from blackhat persuasion pressure.
  • Compare US English examples against LATAM, European, and other language variants.
  • Use transcripts and funnel notes to build original briefs.
  • Keep compliance review separate from market research.

Methodology and source context

Daily Intel pages are written from a research workflow that reviews active VSLs, Meta ad creatives, transcripts, UTMs, funnel paths, checkout steps, upsells, recovery sequences, and compliance-sensitive claim patterns. The goal is to explain observable market behavior, not to provide legal, medical, or platform policy advice.

When the topic touches health claims, platform policy, or GLP-1 market research, validate the observable campaign signals against primary references such as Meta advertising standards, FTC health claims guidance, and Google helpful content guidance. Daily Intel adds the proprietary direct-response layer by mapping how those rules show up in active VSLs, Meta creatives, funnels, transcripts, UTMs, and checkout paths.

For deeper evaluation, continue through Daily Intel compliance and legal disclaimer, Inside the Issuer's Decision: How Your Transaction Gets Risk-Scored, MOR vs Your Own Merchant Account vs a PSP Aggregator, Which Merchant of Record Platforms Actually Accept Physical Supplements, Merchant of Record, Explained for Supplement Offer Owners, and What is a VSL?. These related Daily Intel pages connect this topic to the relevant methodology, pricing, trust context, comparison path, or niche workflow.

Founding rate — locked forever

Access curated VSL intelligence for $29.90/mo

  • 50–100 manually validated VSLs every day at 11PM EST
  • major niches niches, 14+ languages, blackhat-to-whitehat pattern coverage
  • live catalog VSL/ad catalog, transcripts, UTMs, full funnel maps
  • Cancel anytime — founding rate stays yours forever

Daily Intel Service delivers manually curated research around active-scaling VSLs, Meta creatives, UTMs, funnels, and nutra market movement.

$29.90/mo

$299/mo

Coupon LIFETIME-269-OFF auto-applied

Claim the rate

Secure checkout · Stripe

Frequently asked questions

  • Is grey hat affiliate marketing illegal?

    Grey hat affiliate marketing is a platform-rules label, not a legal one, and it is not illegal by itself. Meta, Google and TikTok ban tactics no statute prohibits, so an account can be restricted for grey hat creative that never draws a legal complaint. Civil fraud and criminal exposure sit on separate lines, triggered by false claims or theft.
  • What is the actual difference between grey hat and black hat in direct response?

    Grey hat pushes platform rules without crossing into a false or unsubstantiated claim; black hat crosses into deception the FTC can sue over, or theft a prosecutor can charge. The split isn't about how aggressive the creative looks — a bold, disclosed, evidence-backed claim can be more aggressive than a hidden one and still stay legal.
  • Can a fake advertorial or fake news site get an affiliate network sued, not just the advertiser?

    Yes — a federal court held affiliate network LeadClick liable for $11.9 million because it recruited the affiliates who built the fake-news pages, approved the pages, and paid for the traffic. Courts have rejected the argument that a network is a passive platform once it reviews and approves the specific creative running underneath it.
  • Does the FTC have to prove I intended to deceive people?

    It depends on which FTC authority applies. Ordinary Section 5 deception cases don't require intent — a false net impression is enough. Penalty-offense cases, which carry the largest fines, require the FTC to prove the company knew the practice was unlawful, which is why warning notices go out before the lawsuits do.
  • Is running multiple merchant IDs for one offer a red flag?

    Running several merchant IDs for one offer is not automatically a red flag — spreading volume across MIDs is a standard, marketed feature among high-risk processors serving supplements and subscriptions. The real violation is undisclosed aggregation: routing one entity's sales through a MID underwritten for a different business, which can trigger transaction-laundering exposure under federal bank-fraud statutes.
  • What's the single biggest legal risk in this industry right now?

    Negative-option billing that skips ROSCA's three elements — disclosed terms, informed consent, an easy way to cancel — remains the most litigated pattern in direct response, evidenced by the FTC's $150 million Adobe settlement in March 2026. State automatic-renewal laws in California, New York and Colorado add separate exposure, each with its own disclosure and cancellation-link requirements.

Continue the research path

Related pages

Next in complianceHigh Risk Merchant Account for PeptidesA direct answer for operators running paid traffic to VSLs and direct-response offers, written from verified sources rather than restated marketing.

Lock $29.90/mo forever

Coupon LIFETIME-269-OFF · Cancel anytime

Get Access