BetaMaShop is in public beta. We improve it continuously, and your feedback shapes what comes next.
MaShop/Blog/Industry/Five Stars for a Discount Is Now a Banned Practice
IndustryAugust 20, 2026
Read · 5 min
fake reviews · consumer reviews

Five Stars for a Discount Is Now a Banned Practice

The CMA named five businesses in March 2026 over review practices most small shops use. What is banned, what is still allowed, and the policy to write.

Key takeaways
  • Offering a discount in exchange for a five star review is a banned practice in the UK, and the CMA named a food business over exactly that in March 2026.
  • The FTC rule has been in force since 21 October 2024 and covers AI generated reviews explicitly, with civil penalties available against knowing violators.
  • Asking customers for reviews is still fine on both sides of the Atlantic. Conditioning a reward on the review being positive is what crosses the line.
  • The UK goes further than the US by placing a positive duty on whoever publishes reviews to take reasonable steps to stop fake ones appearing, which catches a shop showing reviews on its own product pages.
  • Deleting or hiding one star reviews is now the more common way an honest small business gets caught, not buying fake ones.

A customer emails to say the mug arrived chipped. You refund them, apologise, and quietly delete the one star review they left an hour earlier. It felt like customer service. In the United Kingdom it is a banned practice, and in March 2026 the competition regulator opened investigations into five named businesses partly over that behaviour.

The rules on reviews changed on both sides of the Atlantic within the last two years, driven by how cheap it became to generate convincing text. What is striking, reading them side by side, is how little of the enforcement risk falls on the people buying fake reviews and how much of it now falls on ordinary shops doing things that used to be normal.

What actually changed?

Two regimes arrived within months of each other and they do not ask the same thing of you. One tells you what you may not do. The other adds a duty to actively police what appears on your site.

Comparison diagram contrasting the United States prohibitions on faking, paying for and suppressing reviews with the United Kingdom duty to publish a policy and screen reviews
The American rule is a list of prohibitions. The British one adds an obligation to act.

The American instrument is the Federal Trade Commission's rule on consumer reviews and testimonials, which took effect on 21 October 2024. The British one is the review section of the Digital Markets, Competition and Consumers Act, whose banned practices started applying in April 2025.

Are AI written reviews specifically covered?

Explicitly, and the rule says so in its own terms. The FTC's announcement of the final rule describes it as reaching reviews that misrepresent they are by someone who does not exist, including AI generated fake reviews, and the Commission was open that cheap generation was the reason for acting.

That framing matters because it closes an argument people were preparing to make. A review written by a language model, describing a purchase that never happened, in the voice of a person who does not exist, is a fake review regardless of whether a human typed it. The generation method is not a defence and it is not a mitigation.

What the rule does not do is ban AI from the review process generally. The Commission's own guidance notes there is no blanket prohibition on AI generated avatars in marketing, and virtual endorsers are permitted provided the testimonials are not false. A real customer who dictates a rambling review and asks a model to tidy the grammar has not created a fake review either. The test is whether the underlying experience and the person are real.

Can you still ask customers for reviews?

Yes, and this is the part worth being precise about, because the fear has spread further than the rule. The FTC's questions and answers guidance is direct: businesses may ask their customers for reviews, and generalised requests for feedback to purchasers are permitted.

Incentives are also allowed, within one condition. The guidance states that offering a reward is acceptable as long as there is no express or implied requirement that the review express a particular sentiment. Ten percent off your next order for leaving a review is fine. Ten percent off for leaving a five star review is not.

The word implied is doing quiet work there. A request that says "if you loved it, leave us a review" is steering sentiment without stating a condition. So is a follow up email sent only to customers who gave a high score in a private survey, which selects for positivity before the public review is even written. Both are the sort of thing a careful regulator reads as an implied requirement.

Disclosure is the other half. Where an incentive was given, that should be visible, and the UK rules treat paid or incentivised reviews that are not clearly marked as a banned practice in their own right.

Note

Go and read your own review request email today. If it contains the words "five star", "positive", "loved", or a star graphic pre filled at five, rewrite it. That single email is the most likely place a compliant small shop is currently non compliant, and fixing it takes ten minutes.

Who is the CMA actually investigating?

Ordinary businesses, for ordinary behaviour, which is what makes the case list instructive. On 27 March 2026 the CMA opened investigations into five businesses over fake and misleading reviews.

BusinessSectorWhat is allegedThe general lesson
AutotraderCar salesOne star reviews not published and not counted in star ratingsFiltering by rating is suppression
FeefoReview servicesThe same suppression patternYour review vendor's behaviour is your exposure
DignityFuneral servicesStaff written positive reviewsInsider reviews need disclosure
Just EatFood deliveryStar ratings presented in an inflated wayHow you calculate the average is a claim
Pasta EvangelistsFood deliveryDiscounts offered in exchange for five star reviewsConditioning a reward on sentiment

Not one of these is a fake review farm. Four of the five are things a small shop does without a moment's thought: hiding the worst review, letting a member of staff write a nice one, presenting an average generously, and trading a discount for stars.

The penalties attached to the regime are serious enough to concentrate the mind. The CMA can seek up to 10 percent of global turnover for a consumer law infringement, up to 5 percent for breaching undertakings, and up to 1 percent for withholding information. Those ceilings are aimed at large firms, but the practices they attach to are universal.

What does the UK duty require you to do?

Something the American rule does not: act in advance. The DMCC regime requires traders who publish consumer reviews to take steps to prevent fake reviews and undisclosed incentivised reviews from being published in the first place.

That word publish is broader than it looks. If your product pages display customer reviews, you are publishing reviews. The duty is not reserved for review platforms, and a shop that accepts submissions and shows them without any screening is the exact case the provision describes.

What counts as reasonable is scaled to what you are. Nobody expects a two person business to run the detection systems a marketplace runs. What the guidance points at is having a published policy that prohibits fake reviews and sets out your position on incentivised ones, and then applying it. A written policy plus evidence you followed it is the whole of a small shop's defence.

The practical shape of that for most shops: verify purchase before publishing where your platform supports it, label incentivised reviews visibly, never remove a review for being negative, and keep a log of removals with the reason. That last one costs nothing and is the record that answers the only question a regulator will ask.

Card listing the four lines that make up a workable review policy for a small shop, from verifying purchases to logging every removal

How much can this actually cost?

In the United States the number is per violation and it is not small. The FTC rule was written specifically to unlock civil penalties, which the Commission had lost the ability to pursue in some circumstances after a Supreme Court decision, and the rule authorises courts to impose them for knowing violations.

The ceiling comes from the FTC Act's civil penalty provisions, which are adjusted for inflation each year. The 2025 adjustment set the maximum at 53,088 dollars per violation, and the agencies confirmed in 2026 that the amounts were not adjusted, so the 2025 figures continue to apply. Per violation, in a context where each fake review can be counted separately, is the phrase to sit with.

The knowing standard is the meaningful limit for an honest business. A shop that misunderstood the incentive rule is in a different position from one that bought a package of two hundred reviews, and regulators on both sides have signalled that education comes before penalties for the first category. The CMA gave businesses a three month adjustment period after publishing its guidance in April 2025 rather than enforcing immediately.

That grace has now expired, which is the practical significance of the March 2026 case list. The period where "we did not know" was a complete answer has closed in both jurisdictions.

What about reviews written by your own people?

They are allowed and they need a label, which is the part that gets missed. The Dignity allegation is the clearest one on the CMA's list for a small business to learn from, because staff writing positive reviews rarely feels like deception to the people doing it.

Both regimes treat an insider review as legitimate only when the connection is disclosed clearly and conspicuously. The FTC's guidance is refreshingly undemanding about the wording, noting that a disclosure can be as simple as describing something as belonging to my company. Nobody is asking for legal language. They are asking that the reader knows.

The category of insider is wider than payroll. It reaches officers, managers and employees, and in substance it reaches anyone whose relationship a reader would want to know about: a founder's family, a supplier you also buy from, a freelancer you pay. If you would be uncomfortable with the reviewer's connection appearing next to the review, that is your answer about whether it needs to appear.

There is a version of this that catches conscientious shops. Asking your team to seed the first few reviews on a new product so the page does not look empty is an understandable impulse and a documented banned practice. The honest alternative is to show the page with no reviews and say so, which readers handle better than a wall of anonymous enthusiasm from week one.

Does your review vendor put you at risk?

Yes, and the Feefo investigation is the reason to check. A review platform sitting between you and your customers makes decisions about what gets published and how averages are calculated, and those decisions show up on your product page under your brand.

Three settings are worth auditing today. Whether reviews below a rating threshold are held, filtered or excluded from the average. Whether the default sort presents the best reviews first in a way that implies they are representative. And whether your integration syndicates a curated subset to your site while the full set lives elsewhere.

None of those is automatically unlawful, and some are ordinary product features. What creates exposure is displaying a figure or a set that implies completeness when the underlying data was filtered. Ask your vendor in writing what their default does, and keep the answer.

When can you remove a review?

For what it contains, never for what it says about you. That distinction is the entire test and it survives in both regimes.

Legitimate grounds are the ones any moderation policy would list: it is abusive, it contains personal data, it is obviously about a different product, it is spam, it is defamatory in a way you can substantiate, or it comes from someone who never bought anything. Publish those grounds, apply them consistently, and removal is defensible.

What the FTC rule prohibits under the heading of review suppression is narrower and sharper than general moderation. It bars using unfounded legal threats, physical threats, intimidation or knowingly false public accusations to get a negative review taken down, and it bars implying that the reviews shown represent all of them when negative ones have been filtered out. Those limits bite hardest at the moment you answer back, which is why drafting a review reply with AI needs a human on the last step.

Replying publicly and truthfully to a bad review remains fully allowed and is the better move anyway. The sentiment you cannot delete, you can answer, and a calm reply under a critical review does more for the next reader than the review's absence would have. Reading those reviews properly is its own discipline, which we went through in what AI reads in your reviews and what it misses.

What about fake reviews aimed at you?

This is the side of the problem the rules help with least, and it has grown for the same reason the rules exist. Generating a hundred plausible one star reviews now costs almost nothing, for the same reason an entire cloned storefront can be stood up in an afternoon, and a competitor or a disgruntled ex supplier can do real damage to a small shop's rating in a weekend.

Your remedies are procedural rather than legal in the first instance. Platform reporting routes exist and work better with evidence: dates clustered unnaturally, accounts with no purchase history, phrasing repeated across reviews, complaints describing a product variant you do not sell. Collect that before you report rather than sending an accusation, because a report with evidence attached moves and a report expressing outrage does not.

Detection tools deserve a word of caution here. Classifiers that claim to identify machine written text are far less reliable than their marketing suggests, and a false accusation against a real customer is itself a risk under the suppression rules. We looked at how much weight those detectors can bear in what AI content detection can honestly tell a shop, and the answer is not enough to justify removing a review on that basis alone.

What to do this week

The work is small and it is mostly writing things down. Rewrite the review request email so no sentiment is implied. Write four lines of review policy and put them on the site where customers can see them. Check whether your platform or review vendor filters by rating, because their default is your liability. Start logging removals.

Then check the claim you make about your own ratings. An average displayed on a product page is a representation about the reviews behind it, and if the calculation excludes anything, the page should say so. The same discipline applies to every performance claim a shop makes, which we set out in what you may claim about AI in your own marketing.

None of this is a reason to be nervous about reviews. Shops that display everything, including the critical ones, generally convert better than shops with an implausible wall of perfect scores, and buyers have learned to read a five star average with suspicion. Customer feedback is more persuasive when it is visibly unedited. The regulation has landed roughly where good practice already was. It is worth building the review surface honestly from the start rather than retrofitting it, which is how we approach the reviews and ratings that ship with stores built on our ecommerce website builder.

Comments 0

0 / 4000Your email stays private.
No comments yet. Be the first.

Keep reading picked for you.

Describe it. MaShop builds it.

Commerce apps and websites from one sentence. No card to start.

Start building