If Google can verify my identity three different ways before letting me spend $50 on a Search campaign, why did an agency I know get phished last month through an ad that sailed through the same system?
Sit with that question for a second, because it’s the whole story of Google Ads in 2026. The verification machinery has never been bigger. The policy documents have never been longer. And yet phishing scams targeting the very agencies that run Google Ads campaigns are common enough that Google’s own product liaison had to post about it on LinkedIn.
I review AI tools for a living, and Google’s ad platform is now, functionally, an AI tool. AI-generated ad copy is standard. Auto-applied recommendations are standard. Automated policy enforcement is standard. So let’s review it the way I’d review any other AI product: does it do the job it claims to do?
The Verification Theater Problem
Google expanded its Limited Ad Serving policy this year to cover every surface it owns — Search, Shopping, YouTube, Gmail, the Play Store, Demand Gen, all of it. Accounts classified as “unqualified advertisers” get throttled until they prove themselves. On paper, that’s exactly the right move. New account, no track record, limited reach until you’ve earned trust. Great.
Except the dodgy ads keep coming. Phishing scams and policy violations persist despite the increased verification and ad quality measures. Google’s answer, delivered by Ginny Marvin in April: “While we proactively monitor for unusual account activity to stop these incidents, advertisers must remain alert.”
Read that again. The company that built the verification gauntlet is telling its paying customers that vigilance is partly their job. Marvin asked advertisers to report suspicious activity. That’s not a safety system. That’s a neighborhood watch program run by the people paying rent to the landlord who owns the locks.
Strict Policies, Loose Enforcement
To be fair — and I try to be fair even when I’m annoyed — Google’s written policies are genuinely strict. Counterfeit goods are flatly prohibited: anything carrying a trademark identical to or substantially indistinguishable from a real brand’s mark gets banned. Dangerous products, same treatment. If you judged Google Ads purely by its policy documentation, you’d think it was the most locked-down advertising platform on earth.
But a policy is a promise, and enforcement is the product. What we actually have in 2026 is a platform that ships weekly changes — the June spam update, strength match label tests, expanded AI reporting, broadened financial advertiser rules — while the foundational problem of bad actors buying ad space remains unsolved. Even Google’s own community of watchers is skeptical of the churn. One commentator reviewing the June changes put it plainly: “I’m not sure I’m a fan of this, but again, Google made this change for some reason.”
Made this change for some reason. That’s the level of confidence the ecosystem has in Google’s enforcement roadmap right now.
Why This Should Bother You More Than It Does
Here’s the part that connects to what I do at this site. Google Ads in 2026 runs on automation. AI writes your copy. AI applies recommendations to your account — sometimes whether you wanted them or not — and following those recommendations blindly inflates your spend without improving your profit. The benchmarks bear this out.
So you’ve got an AI system aggressively optimizing to extract more budget from legitimate advertisers, running alongside an enforcement system that can’t reliably keep phishing ads off the platform. One of those systems works extremely well. Guess which one generates revenue.
I’m not claiming conspiracy. I’m claiming incentives. Ad quality enforcement is a cost center. Auto-applied recommendations are a profit center. When a company pours engineering talent into one and asks LinkedIn followers to help with the other, you don’t need a whistleblower to understand the priorities. You just need to look at where the automation actually got good.
What You Should Actually Do
If you’re running ads or managing them for clients, take Marvin’s advice seriously even if it stings: stay alert, and report suspicious activity when you see it. Not because it’s your job — it shouldn’t be — but because right now nobody else is going to catch it first.
Second, treat auto-applied recommendations like a salesperson’s suggestions, not a doctor’s orders. Turn them off where you can, audit them where you can’t. The AI optimizing your account is optimizing for Google’s definition of success, and 2026’s ROI data says that definition is expensive.
And third, adjust your mental model. Google Ads isn’t a walled garden with occasional intruders. It’s a marketplace where the security guards are excellent at checking your ID and mediocre at stopping the guy selling fake watches by the entrance. Plan accordingly, budget skeptically, and keep your login credentials somewhere a phishing ad can’t reach them.
Google will keep publishing weekly policy updates. I’ll keep reading them. But until enforcement catches up with the paperwork, the dodgy ads aren’t a bug in the system. They’re the part of the system nobody’s been paid to fix.
🕒 Published: