Remember when ad verification was supposed to fix all of this? Google rolled out advertiser identity checks, made everyone upload documents, tightened the rules on who could buy inventory. The pitch was straightforward: prove you’re a real business, and the scammers get squeezed out. Cleaner auctions, safer clicks, fewer people getting fleeced by fake stores.
It’s 2026, and agencies running Google Ads are getting hit with phishing scams aimed directly at their accounts. That’s not a hypothetical risk buried in a policy doc. Google’s own ads product liaison, Ginny Marvin, posted about it on LinkedIn: “While we proactively monitor for unusual account activity to stop these incidents, advertisers must remain alert.”
I review AI tools for a living, which means I spend a lot of time reading marketing copy that promises a system will handle something for me. And I’ve learned to pay very close attention to the moment a vendor tells you that you still need to stay vigilant. That’s the sentence where the responsibility quietly changes hands.
What “remain alert” actually means
Read that Marvin quote again, but as a reviewer would. First clause: we monitor proactively. Second clause: you must remain alert. Both things can be true. But the second clause exists because the first one isn’t sufficient, and that gap is where every dodgy ad and every compromised agency account lives.
This is the same structure I see in AI toolkit documentation constantly. The model handles it automatically. Also, please review all outputs before publishing. The automation is real, the coverage is partial, and the fine print transfers the failure cases to you. Nobody’s lying. It’s just that the marketing operates at the level of the first clause and your Tuesday afternoon operates at the level of the second.
Google has genuinely strict policies on the books. Counterfeit goods are prohibited outright — the policy specifically covers trademarks or logos identical to or substantially indistinguishable from a real brand’s mark. Dangerous products are barred. These are not weak rules. The rules aren’t the problem.
Enforcement at scale is a different animal
Google’s answer has been to widen the net. The Limited Ad Serving policy now covers every Google Ads surface — Search, Shopping, YouTube, Gmail, the Play Store, Demand Gen. Accounts that fall into the “unqualified advertisers” bucket get throttled across all of it rather than just one placement.
Structurally, that’s the right call. Whack-a-mole across individual surfaces was never going to work when a bad actor could just shift channels. But policy expansion and enforcement accuracy are separate problems, and expanding the first doesn’t automatically solve the second. A wider classification system catches more bad accounts and also catches more legitimate ones. Anyone who has been on the wrong end of an automated account restriction knows how that feels.
The AI layer makes it messier
Two things are happening at once, and they pull in opposite directions. Enforcement is getting more automated. So is ad creation. AI-generated ad copy and auto-applied recommendations are just standard practice now — not a beta feature, not an experiment, the default state of the platform. Google has been shipping changes at a steady clip, including expanded AI reporting and tests of strength match labels.
Which means the volume of ad creative flowing into the system keeps climbing while the review capacity per unit of creative gets thinner. That’s an arithmetic problem, not a philosophy problem. And it’s the same arithmetic that shows up in the advice I keep giving about AI tools generally: following every auto-applied recommendation blindly inflates spend without improving profit. The system optimizes for what it can measure. It cannot measure whether you meant it.
What I’d actually tell you to do
My honest read after years of testing tools that promise to remove work from your plate: the platform’s protections are real and they are not a substitute for your own process. Treat Google’s ad quality systems the way you’d treat a spam filter. Useful, necessary, and not something you’d bet the business on without a second layer.
- Assume phishing attempts targeting your ads account are a normal operating condition, not an anomaly. Lock down access accordingly.
- Review auto-applied recommendations rather than accepting them by default. Every one of them is a decision someone else made about your money.
- Know which surfaces you’re actually serving on. With Limited Ad Serving spanning everything, a classification problem on one account becomes a problem everywhere at once.
- Report suspicious activity when you see it. The reporting loop is part of how enforcement gets better, and skipping it makes you a free rider on other people’s diligence.
Google isn’t serving dodgy ads because nobody cares. It’s serving them because automated enforcement at planetary scale has a floor it can’t get under, and that floor is where you’re standing. Verification raised the cost of being a scammer. It didn’t eliminate the job. Plan for the version of the platform that exists, not the one the policy page describes.
🕒 Published: