Written in 2018, the Media Rating Council's supplement on ad verification gives the term a working definition. "Brand Safety refers to practices and tools to ensure that a digital ad will not appear adjacent to or in a Context that can damage an advertiser's brand."1 The sentence names one party at risk: the advertiser. The same document says a page is judged an appropriate place for an ad "as determined by parameters set by the advertiser."1 A publisher reading that definition is the context, not the brand.

The published frameworks are written from the buyer's side

The best-known framework came from the Global Alliance for Responsible Media, a body the World Federation of Advertisers set up in 2019.2 Its Brand Safety Floor and Suitability Framework, in the June 2020 edition the Association of National Advertisers (ANA) hosts, does two things. It "Establishes a Safety Floor," described as "a limit that is not suitable for advertising support." It also "Creates a Suitability Framework," which it calls "graded definitions of topic treatments for advertising support."3 The floor section is headed "Excluded from monetization." Above the floor, eleven content categories are each graded at high, medium, or low risk.3

The eleven categories describe content a large advertiser does not want beside its ads. They are adult content, arms and ammunition, crime, death and injury, online piracy, hate speech, obscenity, drugs and alcohol, spam, terrorism, and debated sensitive social issues.3 Each describes a page and asks whether an ad should appear on it. The publisher's question, whether an ad from one of those categories will appear inside a page they wrote, is not the one the framework answers. GARM was discontinued in August 2024 after allegations the WFA said had "significantly drained its resources and finances"; the framework survives as a document, not a program.2

The industry's content taxonomy has the same orientation. IAB Tech Lab, the Interactive Advertising Bureau's standards body, says its Content Taxonomy "provides a 'common language'" for describing content, with typical uses in "contextual targeting and brand safety."4 Version 3.0 took it from roughly 400 categories to more than 1,500, and the current release is 3.1.4 It is a classification of pages, so that a buyer can name what to target and what to avoid. It is not a classification of ads.

The publisher's version of the problem has no standard name

AdSense does offer the publisher a control, and its name is instructive. The page says the options exist "To give you editorial control over the ads that may appear on your site."5 Its list of blocks includes individual ads, advertiser URLs, general categories, and sensitive categories.5 The sensitive list includes Politics, Religion, Dating, Consumer Loans, Weight loss, and Drugs & supplements.6 Google adds that "Our system classifies ads automatically," rather than relying only on the advertiser's own category.6

Two things follow from that page. The first is that a category block acts on the machine's classification of the ad, not on a person's reading. The second is a warning: "Blocking ads can have a negative effect on your earnings," because "Allowing all ads creates the most competitive atmosphere in the ad auction."5 On the buyer's side of the same company, a matching setting is called content exclusion. Google Ads describes it as a way to "opt out of showing your Display campaigns alongside content that may not be appropriate for your brand."7 The advertiser opts out of pages, the publisher blocks ads, and the warning about earnings sits on the publisher's page.

Scale is why a large network classifies by machine

The scale behind automatic classification is visible in the ANA's programmatic transparency study of June 2023. Across 21 member companies, US$123 million in spending, and 35.5 billion impressions, "The average number of websites for survey respondents was 44,000 top-level domains."8 No person reads 44,000 sites. A framework of eleven categories and three risk grades suits that scale, because software can assign a grade to a page.

The publisher's problem does not grow the same way. Suppose a site has two hundred articles. The number of advertisers whose ads could appear on those pages is bounded by how the network sells. A network that sells words rather than impressions, one advertiser per keyword per site per calendar month, has a bounded list of advertisers per site. A bounded list can be read by a person.

A person reading every ad is the small-network floor

On AdBubbles an ad is a bubble, a small panel that opens from a dotted underline on a word already in the publisher's copy. One script, the embed, adds the underlines inside the part of the page the publisher set as its scope. A bubble holds an "Ad" label, a headline, a short body, the advertiser's display domain, and one link. That text is the creative, and every creative is reviewed by a person before it goes live. A campaign rejected in review is refunded in full.

Six advertiser categories are not accepted at all: gambling, adult, weapons, cryptocurrency, supplements, and political. Four creative rules apply to everything else: no all-capitals, no emoji, one link, and a category chosen from a fixed list. The destination URL is checked when the campaign is saved and checked again every week. A reading of the creative cannot see the page behind the link, and that page can change after approval.

The difference from the AdSense list is in what is optional. An AdSense publisher may block Politics and Drugs & supplements; AdBubbles does not sell to political or supplement advertisers at all. The counterpart of the framework's graded part, above the floor, is the publisher's category exclusion. A publisher chooses it alongside the scope and the maximum bubbles per page, as part of the site's configuration. Because the category comes from a fixed list and a person has read the creative, the exclusion acts on a label someone has seen, not on an automatic classification. A reader can reach the ad policy from any bubble.

What a reviewer cannot do is decide who sees the ad. AdBubbles matches the words already in a publisher's copy to an advertiser who bought them. It does not select readers, does not follow anyone from one page or site to another, and does not promise any result. AdBubbles sets no cookie, stores no identifier, and collects no personal data from readers. The Federal Trade Commission's guide to native advertising lists "Ad" among the terms "likely to be understood," with "Advertisement" and "Paid Advertisement."9 Every bubble carries that label, and every link inside one is marked rel="sponsored noopener".

The exclusion is worth setting before the first bubble appears

The order of operations is the practical difference. Where a machine classifies the ad, the block acts on the machine's label and carries the warning about earnings. On AdBubbles the underline appears on words already in the copy, so the category exclusion can be chosen before any campaign is matched to the site. A publisher account costs nothing, and so does the embed. A publisher who adds a site can request a crawl of its sellable words, set the excluded categories against that list, and only then add the embed.