\n\n\n\n Google Wrote the Rules and Still Can't Enforce Them - AgntHQ \n

Google Wrote the Rules and Still Can’t Enforce Them

📖 5 min read•815 words•Updated Sep 13, 2026

What if the reason dodgy ads keep slipping through isn’t that Google’s filters are weak, but that the people running the filters are also the people getting paid when the ads run?

I ask because the pattern doesn’t add up any other way. Google has policies against counterfeit goods. Explicit ones. The Advertising Policies Help pages prohibit the sale or promotion of goods carrying a trademark identical to or substantially indistinguishable from someone else’s. That’s not vague. That’s a rule you could enforce with a lookup table and a lawyer. And yet the scams keep coming.

The verification theater problem

In 2026, Google expanded its Limited Ad Serving policy to cover every surface it owns. Search, Shopping, YouTube, Gmail, the Play Store, Demand Gen. Accounts that get classified as “unqualified advertisers” run into throttling across the board rather than in one silo. On paper, that’s the right direction. Advertiser verification plus reduced serving for anyone who hasn’t cleared the bar is roughly what you’d design if you were serious about the problem.

So why did agencies using Google Ads get hit with phishing scams in April 2026?

Ginny Marvin, Google Ads product liaison, addressed it on LinkedIn: “While we proactively monitor for unusual account activity to stop these incidents, advertisers must remain alert.” Read that again with a reviewer’s ear. The first clause is Google describing its own systems. The second clause is Google handing the problem to you.

I’m not saying Marvin is spinning anything. She’s being straight about the limits of the system, which is more than most product liaisons manage. But the shape of the statement tells you where the accountability actually sits. Detection is best-effort. Vigilance is your job.

Why this is structurally hard, not just poorly executed

Let me give Google the fair hearing it deserves. Ad fraud is adversarial. Every filter you ship is a spec sheet for the next bypass. Counterfeit sellers rotate domains, spin up fresh accounts, and cycle creative faster than any manual review process can keep pace. Phishing crews targeting agencies aren’t attacking Google’s ad systems at all, they’re attacking the humans with account access. No amount of policy language fixes a media buyer clicking a convincing link in a fake invoice email.

Scale makes it worse. An automated system operating at Google’s volume has to pick its error mode. Aggressive filtering means legitimate advertisers get killed by false positives, which generates furious complaints and lost revenue. Permissive filtering means bad actors get through. Google has picked permissive, and Limited Ad Serving is an attempt to have it both ways: throttle the suspicious without banning them outright.

That’s a reasonable engineering compromise. It’s also a business decision dressed as a safety feature, and those two things being the same decision is exactly the conflict I opened with.

The AI layer isn’t helping

Here’s what makes 2026 different. AI-generated ad copy and auto-applied recommendations are now standard operating procedure inside Google Ads. Analysis of real ROI benchmarks this year keeps landing on the same warning: following every recommendation blindly inflates spend without improving profit.

Think about what that means for quality control. The system that generates the ads and the system that polices the ads are both automated, both owned by the same company, and both optimized against metrics that reward volume. When Google tests things like strength match labels and expands AI reporting, as it did in late June 2026 alongside the June 2026 spam update, it’s adding more automated machinery to a stack that already has an enforcement gap.

More automation on the generation side without proportional investment on the enforcement side widens the gap. That’s not a conspiracy. It’s just what happens when one side of a system gets more funding than the other.

What I’d actually tell you to do

Since Google has told you plainly that vigilance is your responsibility, treat it as a real operational task rather than a vibe:

  • Assume any urgent email about your ad account is a phishing attempt until proven otherwise. Log in directly, never through a link.
  • Audit auto-applied recommendations weekly. The default is on, and the default is not optimized for your margin.
  • Report suspicious activity when you see it. The reporting pipeline is imperfect, but it’s a signal input, and Google’s detection improves on volume.
  • Lock down account access. Fewer people with edit permissions means a smaller surface for social engineering.

My honest read

Google’s stated policies are strict and the direction of travel in 2026 is genuinely toward tighter controls. I’ll credit that. What I won’t credit is the framing that positions advertiser vigilance as a partnership when it functions as a liability transfer.

You’re paying for distribution on a platform where the platform sets the rules, profits from the traffic, and asks you to catch what it misses. That arrangement can still be worth it. Just price the unpaid security work into your calculation before you decide.

đź•’ Published:

📊
Written by Jake Chen

AI technology analyst covering agent platforms since 2021. Tested 40+ agent frameworks. Regular contributor to AI industry publications.

Learn more →
Browse Topics: Advanced AI Agents | Advanced Techniques | AI Agent Basics | AI Agent Tools | AI Agent Tutorials
Scroll to Top