What Does NOT Work: Letting an API/Script Agent Run Unsupervised — the Actions That Need a Human Checkpoint
An agent with API or Scripts access to a Google Ads account can execute changes faster than Google's own review and enforcement systems can react — that speed is exactly what turns a small misconfiguration into a suspended account or a burned budget before a human notices. This page lists the specific action classes Google's documentation flags as high-risk when automated, and where Google itself forces a human checkpoint by design.
Irreversible or High-Blast-Radius Actions
Bid strategy changes are not free to make repeatedly: changing a bid strategy setting triggers a "Learning" status while Google Ads recalibrates toward the new objective, and this can take up to 3 weeks or 1-2 conversion cycles — the duration driven mainly by number of conversions accumulated, length of conversion cycles, and the specific bid strategy involved. — support.google.com/google-ads/answer/13020501
Scripts run on a hard clock and cannot be undone
Google Ads Scripts that run longer than 30 minutes (60 minutes for certain manager-account scripts) will time out and may leave modifications half-applied; Google's own documentation warns "changes to your scripts can't be undone." — support.google.com/google-ads/answer/188712
Bulk bid/budget changes destabilize budget-limited campaigns
for campaigns on Target CPA/Target ROAS that are already overperforming their target and budget-limited, bulk-adjusting budgets can cause visible performance fluctuations. — support.google.com/google-ads/answer/17125145
Broad match keyword additions at scale outrun the data an agent has to justify them: broad match lets Smart Bidding learn faster by matching on signals beyond keyword text. That still requires enough conversion volume for the algorithm to model against — an agent adding broad match keywords in bulk without first confirming the account clears Google's documented conversion-volume floor risks expanding reach before the data exists to support it. — support.google.com/google-ads/answer/10195720
See What Does NOT Work: Broad Match and Smart Bidding Without Guardrails — where automation burns budget instead of saving it for the full mechanics of that last failure mode, and Bidding Strategies: Manual, Smart Bidding, and When Each Applies — matching the strategy to the conversion data you actually have for what a correctly data-backed bid-strategy change looks like.
Policy-Violation Risk Multiplier: Mass Ad Edits Outrun Human Review
Google enforces policy violations with a strike system: the first violation gets a warning only (no strike); the first strike triggers a 3-day temporary account hold; a second strike within 90 days triggers a 7-day hold; a third strike results in permanent account suspension. — support.google.com/adspolicy/answer/10922738
Holds do not pause the clock — they compound it
creating new violating ads while an account is already on temporary hold from a prior strike triggers an additional strike immediately, so an agent that keeps editing during a hold accelerates straight toward suspension instead of waiting it out. — support.google.com/adspolicy/answer/10922738
One policy, one counter, many ads
all violations of the same specific policy count toward the same strike progression, so a single mass ad-copy edit that reintroduces one violating pattern across dozens of ads can rack up multiple strikes in parallel or rapid succession rather than one. — support.google.com/adspolicy/answer/10922738
Some violations skip the strike system entirely
Circumventing Systems — trying to trick or bypass Google's ad review process, including cloaking and using multiple accounts to evade a prior suspension — is classed as egregious and results in immediate account suspension with no prior warning, regardless of strike count. — support.google.com/adspolicy/answer/15938075
Why an agent is uniquely dangerous here
mass-editing ad copy across dozens or hundreds of ads at once submits all of them for policy review simultaneously, compressing what would normally be days of staggered human edits (and staggered human-noticed rejections) into minutes — collapsing the time window in which a human would normally catch and stop a bad pattern before it repeats. — support.google.com/google-ads/answer/188712
See Google Ads Policy Taxonomy: What Gets an Ad Disapproved vs an Account Suspended for the full policy-tier structure this strike system sits inside.
Overspend Risk: Rules and Scripts Run Without a Real-Time Human Check
Automated rules do not execute instantly: Google's documentation states a standard turnaround of up to 2 hours after conditions are triggered, with no guarantee of faster or real-time execution. — support.google.com/google-ads/answer/16719424
Concurrent rules can conflict
when multiple automated rules are scheduled to run on the same entities at the same time, the system may encounter incompatible changes, which can result in errors. — support.google.com/google-ads/answer/16719424
Reactive bidding rules can spiral
lowering bids automatically based on short-term low click-through rates can create a negative feedback loop where the ad declines further in ranking, which drives CTR even lower, which triggers further bid cuts. — support.google.com/google-ads/answer/16719424
Conversion lag breaks conversion-based rules run on short windows
conversions take longer to record than clicks, so conversion-based automated rules and scripts need longer timeframes to avoid acting on incomplete data — a rule evaluated on too short a window is reacting to a partial count. — support.google.com/google-ads/answer/16719424
Automated budget adjustments hit the same budget-limited fragility as bulk manual changes: campaigns on Target CPA/Target ROAS that are budget-limited and overperforming their target can see performance fluctuate when automated budget adjustments are applied. — support.google.com/google-ads/answer/17125145
UNVERIFIED — no documented ceiling on rule frequency
Google's automated-rules documentation does not explicitly guarantee frequency caps or upper bounds on execution counts per day when rules are scheduled to run multiple times daily; this is a gap in the official guidance, not a confirmed safety feature, and should not be assumed to exist.
Where Google Requires a Human in the Loop by Design
API access itself is gated in stages, not granted all at once. A new developer token starts at Test Account Access — test accounts only, capped at 15,000 operations/day. — developers.google.com/google-ads/api/docs/api-policy/access-levels
Production access requires a human-reviewed application
Basic Access (needed to manage production accounts) must be applied for via the API Center, and approval typically takes 5 business days. Standard Access (unlimited operations) requires Basic Access first, then a separate application, taking roughly 10 more business days. — developers.google.com/google-ads/api/docs/api-policy/access-levels
Explorer-level tokens are deliberately boxed in
they cannot create customer accounts, manage users, access keyword planning tools, or interact with billing services — an agent running on an Explorer token structurally cannot perform those actions regardless of what it's instructed to do. — developers.google.com/google-ads/api/docs/api-policy/access-levels
MCC permission grants cannot exceed the granter's own level
in a Manager Account hierarchy, an admin can only grant access levels up to their own, and granting Admin access requires already holding Admin access — so an agent cannot escalate its own permissions past what the human operator holds. — support.google.com/google-ads/answer/7459700
Identity and category checks are human-paced, not API-paced
advertiser identity verification requires legal documentation (government-issued photo ID for individuals; organization registration plus a government ID for organizations) and review can take up to 5 business days, or up to 30 days in rare cases. — support.google.com/adspolicy/answer/9703665
Safe for autonomous execution (no human sign-off required)
read-only reporting and data extraction; adding negative keywords from a pre-reviewed, human-validated list. — support.google.com/google-ads/answer/188712, support.google.com/google-ads/answer/2472779
Requires human review/sign-off before execution
any bid strategy change (learning-period reset risk); budget increases beyond a pre-defined threshold such as >10% of daily budget (runaway-spend risk); new campaign creation (unpredictable targeting/spend/structure effects); any ad copy touching restricted categories (healthcare, financial, gambling, etc. — heightened policy risk); mass ad edits, e.g. updating copy across >100 ads at once (compounded policy-review and strike-accumulation risk). — support.google.com/google-ads/answer/13020501, support.google.com/google-ads/answer/16719424, support.google.com/google-ads/answer/2472779, support.google.com/adspolicy/answer/16114090, support.google.com/adspolicy/answer/10922738
Explicitly prohibited, automatic blocking required
opening new accounts or using multiple accounts to evade policy enforcement or account suspension; cloaking or showing different content to Google's review process than to actual users. — support.google.com/adspolicy/answer/15938075
Related
- Managing Google Ads Programmatically — API, Scripts, and MCC, and Where an Agent Needs a Human Checkpoint — this page's checkpoint policy is the safety layer that page's "safe-automation guardrails" section points to; read that page first for the access mechanics (API vs Scripts vs MCC), this one for what to gate before letting an agent touch them. - Google Ads Policy Taxonomy: What Gets an Ad Disapproved vs an Account Suspended — the full policy-tier structure (prohibited/restricted/egregious) behind the strike-system claims above; needed to classify a specific ad edit before deciding if it needs sign-off. - What Does NOT Work: Broad Match and Smart Bidding Without Guardrails — where automation burns budget instead of saving it — the same overspend and learning-period mechanics from the Smart Bidding side; this page adds the agent-speed multiplier on top. - How to Respond to a Suspension or Disapproval Without Making It Worse — the sequence that avoids turning a fixable violation into a permanent ban — what to do once a guardrail here was missed and a strike or suspension already landed. - Bidding Strategies: Manual, Smart Bidding, and When Each Applies — matching the strategy to the conversion data you actually have — defines the learning period and data prerequisites this page treats as a reset risk whenever an agent changes a bid strategy.
Why this page matters for the objective
the wiki exists to let a marketer or their AI agent run Google Ads without burning budget or triggering suspensions — an agent is the fastest way to do both if it isn't told which actions are safe to automate and which need a human to look first. This page is that checkpoint list, sourced entirely from what Google itself documents as risky, gated, or explicitly prohibited.
Verified against
34 claims checked against these sources · 4 refuted and removed
- support.google.com/google-ads/answer/13020501
- support.google.com/google-ads/answer/2472779
- support.google.com/google-ads/answer/188712
- support.google.com/google-ads/answer/16719424
- support.google.com/google-ads/answer/17125145
- support.google.com/google-ads/answer/10195720
- developers.google.com/google-ads/api/docs/api-policy/access-lev…
- support.google.com/adspolicy/answer/10922738
- support.google.com/adspolicy/answer/15938075
- support.google.com/google-ads/answer/7459700
- support.google.com/adspolicy/answer/9703665
- support.google.com/adspolicy/answer/16114090
What links here
Source: Sinapsi — verified compositional memory, queryable by LLMs. Query this wiki live from your assistant over MCP, or build your own verified wiki (public, or private for your team). CC BY 4.0 — reuse with attribution to Sinapsi.