Google's Gemini rejects the ad Google's own review approved twice

A YouTube ad the author ran into on an iPhone imitates an operating system alert: a banner styled like an iOS pop-up reading "iPhone Storage is Full," complete with iOS-style typography and two buttons, "Yes" and "No," that look like system controls. Neither button does anything specific; tapping anywhere on the banner redirects to a store or landing page. A second line adds pressure: "If you don't free up space soon, some features may not work properly." The author says a moment of inattention was enough to click through.
The author reported the ad to Google and got back a form response: the ad "doesn't go against Google's policies, which prohibit certain content and practices that we believe to be harmful to users and the overall online ecosystem." Assuming this was a slip, the author reported the same ad again and received the identical response. By the article's own count, Google's review process approved the ad twice, and the author says other people who separately reported it got the same reply.
To test whether AI could do better, the author put the same ad in front of Google's own Gemini. Gemini classified it "DISAPPROVED" and cited two violations: "Misrepresentation: Misleading Ad Design" and "Misrepresentation: Unreliable / Deceptive Claims." Gemini's evidence for the verdict spelled out why: the banner mimics a native iOS alert down to the typography and button styling, the "Yes" and "No" options are static images rather than working controls, and the storage warning fabricates urgency about the user's own device to push an install. Gemini's own recommended action was to disapprove the ad creative immediately, issue the advertiser a policy warning, and flag that repeated violations could lead to full account suspension.
The gap between the two verdicts is the article's whole point: Google's model rejected the ad in seconds; Google's review process had already cleared it twice. The author's first instinct, invoking Hanlon's razor, is charitable: reviewers simply cannot check everything, so the ad slipped through. A less charitable reading follows: an ad that generates a lot of clicks may not be something Google has much commercial incentive to remove. Either way, the piece closes with a direct appeal: Google already builds AI capable of catching this, and should use it to police its own ad inventory rather than leaving that job to a review process that let a textbook fake system alert through twice.
Key facts
- A YouTube ad mimics an iOS "iPhone Storage is Full" system alert, with fake "Yes" and "No" buttons that just redirect wherever they're tapped, plus a line warning that "some features may not work properly" unless the user frees up space.
- The author reported the ad to Google and got the reply that it "doesn't go against Google's policies"; a second report produced the same reply, so by the article's own count Google's review process approved the ad twice.
- The author says other people who separately reported the same ad received the identical response.
- Given the same ad, Google's own Gemini classified it "DISAPPROVED" for two violations, misleading ad design and unreliable or deceptive claims, and recommended disapproving the creative immediately and warning the advertiser, with account suspension possible for repeat offenses.
- The author's conclusion: Google's model rejected the ad in seconds while Google's own review process cleared it twice, and the piece argues Google should put its AI to work moderating its own ads.
Why it matters
The piece's argument is that Google's own Gemini is already capable of judging content this way, and the company is not using it. Here the same model is shown, by the author's own account, catching in seconds a disguised system alert that Google's review process had already cleared twice after being asked to look again. Google's ad business runs on reviewing enormous volume, and this is a concrete case where the technology to close a real gap in that review already exists inside the company; it simply was not applied to the company's own product.
Who it affects
Three groups: anyone served this kind of ad on YouTube or elsewhere in Google's network, since the design tries to trick a user into tapping what looks like their own phone's storage warning; the advertiser running the creative, since Gemini's recommended action was a policy warning against the account, with full suspension possible if the pattern repeats; and Google's own ad policy and review operation, whose "doesn't violate policy" verdict is contradicted, in public, by the company's own model.
How to use it
There is no product, price or signup to describe here. The practical part is how the author used Gemini: given the ad, the model returned a structured verdict: approve or disapprove, the specific policies broken, the evidence for each, and a recommended action. The piece's argument is that Google could run that same check inside its own review pipeline instead of leaving the judgment to a process that, on this ad, said twice there was nothing wrong. For a reader who spots a similar fake system alert ad, the lesson is not to treat a "doesn't violate policy" reply as the final word, and to report it again.
How solid is it
The piece quotes Google's rejection response and Gemini's classification, cited violations and recommended action in full rather than paraphrasing them, which is easy to check for internal consistency. What it does not establish: how the Gemini evaluation was obtained, which interface or model version, whether Google removed the ad or changed anything afterward, or how many people beyond "multiple" reported it. It is one person's account of one ad, not an audit of how often Google's review and Google's own models disagree.
Risks and caveats
Asking a model to judge a single ad on request is a different task from screening ad inventory at scale, where missing a real violation and wrongly blocking a legitimate ad carry different costs; the piece does not settle which approach Google should actually run in production. The advertiser, the exact ad and the reporting dates are not named, so none of this can be checked independently, and the piece includes no response from Google about how its review process works or why this ad passed. The author's harsher read, that clickable ads may not be in Google's commercial interest to remove, is offered as speculation, not as something the piece demonstrates.
“Google’s own model rejects the ad in seconds, yet Google’s review process approved it twice.”
— the article's author