Picture a nightclub with the strictest door policy in town. Three ID checks, a metal detector, a bouncer who remembers faces from two years ago. And yet every weekend, somebody who absolutely should not be inside is on the dance floor buying rounds. Not because the security failed, exactly, but because the queue is a few million people long and it never stops moving.
That’s roughly the situation with Google Ads. The verification has gotten tighter. The policies have gotten stricter. And dodgy ads keep showing up anyway.
I write about AI agents for people who don’t build them, and this is one of those stories where the machinery behind the curtain actually matters to your daily life. So let’s talk about what’s going on, in plain language.
What “dodgy” actually means here
Two broad categories. First, phishing scams, where someone tries to trick you into handing over credentials or money. Second, policy violations, which covers things like counterfeit goods and dangerous products. Google’s own advertising policies prohibit the sale or promotion of counterfeit goods, defined as items carrying a trademark or logo identical to or substantially indistinguishable from the real thing.
Both types keep appearing. Not because nobody’s watching, but because the volume of ads flowing through the system is enormous and the people submitting the bad ones are actively trying to look legitimate.
The scams aren’t just aimed at you
In April 2026, agencies using Google Ads were hit with phishing scams. Read that again, because it flips the usual story. These weren’t consumers clicking a fake ad. These were the professionals who run ad accounts for a living, being targeted directly.
Ginny Marvin, Google Ads product liaison, addressed it on LinkedIn: “While we proactively monitor for unusual account activity to stop these incidents, advertisers must remain alert.”
That sentence is doing a lot of work. It’s an honest admission that automated monitoring catches some things and not others. If experienced ad agencies can get phished, the rest of us should probably lower our confidence about spotting a fake at a glance.
Google is tightening the door policy
The response has been more gatekeeping. Google expanded its Limited Ad Serving policy to cover all Google Ads surfaces, meaning Search, Shopping, YouTube, Gmail, the Play Store, and Demand Gen. Accounts classified as “unqualified advertisers” get restricted reach until they establish more credibility.
Think of it as a probationary period. New or unverified advertisers don’t get the keys to the whole building right away. It’s a sensible design, and it also tells you something about the underlying problem: if you need a probation tier, you’ve accepted that some bad actors will always get through the front door.
Where the AI part gets interesting
Here’s what I find genuinely worth thinking about. Google is running AI on both sides of this problem.
On the defensive side, automated systems monitor for unusual account activity. On the advertiser side, 2026 has made AI-generated ad copy and auto-applied recommendations standard practice. The machine writes the ads, and the machine polices the ads.
And even legitimate advertisers are learning that automation isn’t a substitute for judgment. Following every Google recommendation blindly inflates spend without improving profit. The system optimizes for what it can measure, not for what you actually want.
That’s the same lesson, in a different costume. An automated system tuned to catch fraud will catch the patterns it knows. Anything that looks new enough gets a free pass until someone flags it.
What this means for you
If you use Google Ads, or if you just use Google, a few practical takeaways:
- Report suspicious activity when you see it. Human reporting is part of how these systems learn what to catch.
- Treat unexpected messages about your ad account with suspicion, even if they look internal. Agencies got fooled by exactly this.
- Don’t auto-apply every recommendation. Automation is a tool, not a manager.
- Verification badges and account age tell you something, but not everything.
The uncomfortable honest answer
Why is Google still serving dodgy ads? Because moderation at this scale is a moving target, not a solved problem. Every new policy layer, the Limited Ad Serving expansion, stricter counterfeit rules, more verification, raises the cost of running a scam. It doesn’t eliminate the scam.
The pattern shows up everywhere AI handles volume no human team could review: spam filters, content moderation, fraud detection. The systems get better. The adversaries adapt. Neither side finishes.
The useful mindset isn’t outrage that Google hasn’t fixed it. It’s understanding that you are part of the filter. The bouncer at the door is doing their job. Someone still has to notice the guy stealing coats in the back.
🕒 Published: