Website Building Stack

Google Ads Policies for Restricted Product Categories

Know the difference between prohibited and restricted categories before your account gets suspended.

Staff Writer · · 12 min read
Cover illustration for “Google Ads Policies for Restricted Product Categories”
Ad Policy Workarounds · August 26, 2026 · 12 min read · 2,605 words

Google Ads runs a tiered system, where restricted categories come with their own rulebook of certifications, geographic limits, and creative conditions, and treating that system like a grey zone is how accounts end up suspended. This piece walks through how the tiers actually work and what each restricted category demands, because the gap between "I think this is fine" and "Google thinks this is fine" is where most disapprovals live.

Four tiers structure everything: Prohibited Content, Prohibited Practices, Restricted Content, and Editorial/Technical Requirements. The one distinction that matters most here is the line between prohibited and restricted. Prohibited means the thing cannot show up anywhere, not in the ad copy, not on the landing page, full stop. Restricted means it can run, but only inside a specific set of conditions. Google's own wording draws this line cleanly: "unacceptable" content cannot be present in your ad or on your website, while "restricted" content cannot be present in your ad or be the primary focus of your website. That's a meaningfully looser standard, and advertisers who read "restricted" as "banned, but softer" are missing the actual mechanics. Restricted is its own track, with its own certifications and its own geographic rules, and it can even be blocked at the network level rather than the individual ad level, meaning some ad products just don't carry restricted content regardless of how compliant your campaign is.

Venn diagram: Prohibited vs. Restricted Content in Google Ads. Compares Prohibited Content and Restricted Content; overlap: Shared Enforcement.

What "Eligible (Limited)" actually means in the platform and why it doesn't self-resolve

Open a restricted-category campaign and you'll likely see a status called "Eligible (Limited)." It looks alarming the first time you see it, mostly because it sounds like a euphemism for "we're watching you." The ad is live, but constrained: limited inventory, limited audience, limited placements, limited geography, sometimes limited by policy vertical entirely.

Here's where advertisers get tripped up: they assume the label is temporary, like a review still in progress, and that it'll clear once Google finishes looking at it. Nothing about "Eligible (Limited)" resolves through patience. Resolving it requires action, and the action depends entirely on why the label showed up in the first place.

If certification hasn't been completed, you apply for it and wait for approval. If targeting is too broad for the category, you narrow the geography or the demographic parameters until they fit what the category allows. If the landing page is missing something, like responsible gambling disclosures or pharmacy verification details, you fix the page and resubmit. Three different causes, three different fixes, and the status label itself won't tell you which one applies to your account. That's the part that catches people off guard: you have to go diagnose the cause yourself before you can do anything about it.

Worth sitting with too: even once you're "Eligible (Limited)," your ad still won't reach every user in every location the way an unrestricted campaign would. The reach is structurally smaller by design, a function of how the category works rather than a flaw to troubleshoot.

The scale of enforcement that makes policy compliance non-negotiable

Diagram: Google Ads Enforcement at Scale: 2024 vs. 2025. Visualizes: Show the contrast between three key enforcement metrics across 2024 and 2025 to illustrate how Google's AI shifted from blunt account-level action to precise ad-level action.

Numbers help here, because "Google takes this seriously" is the kind of phrase that means nothing until you see the volume behind it. Google blocked or removed more than 8.3 billion ads in 2025. That's up from 5.1 billion in 2024, which itself followed 5.5 billion in 2023, with the 2024-to-2025 jump being the steeper one. A separate figure, 4.8 billion ads restricted rather than removed in 2025, shows that the "restricted" enforcement lever runs at a scale close to outright removal. This is a parallel enforcement system operating in the billions.

More than 99% of ads blocked or removed in 2025 were stopped before a single user saw them. Enforcement happens pre-impression, not in response to someone flagging an ad after the fact. That changes how advertisers should think about risk: there's no window where a non-compliant ad quietly runs and generates a few clicks before anyone notices. The system is largely built to catch it before it goes live at all.

Account suspensions tell an interesting, almost counterintuitive story. In 2025, 24.9 million advertiser accounts were suspended. In 2024, it was 39.2 million, itself a 208% jump over 2023's 12.7 million. So suspensions dropped from 2024 to 2025 even as blocked ads rose substantially. Read that twice, because it's not a contradiction: Google's AI appears to be catching problems at the individual ad level more precisely, rather than defaulting to shutting down the whole account. Google reported an 80% reduction in incorrect advertiser suspensions in 2025. The machine got better at telling the difference between a bad ad and a bad advertiser.

None of this sits still, either. Google made 35 updates to its Ads and Publisher policies in 2025, following more than 30 in 2024. That's roughly one policy change every ten days, on average, across the year. The system advertisers are navigating is Gemini-powered, automated, running at billions of decisions annually, and getting sharper.

Healthcare and medicines: certification requirements and what they actually cover

Healthcare isn't one policy; it's a spectrum stuffed inside one policy category. Some healthcare content is prohibited outright, no certification fixes that. Other healthcare content is restricted, meaning it can run, but only in specific countries and only by advertisers who've applied for and received approval.

Clinical trial recruitment falls into that restricted bucket. So do HIV home tests, addiction services, and prescription drug services. Online pharmacies need Google certification and have to meet specific criteria to get it; certification here is a gate, not paperwork you file after the fact. Advertising prescription drugs directly to consumers is generally prohibited, and the restriction is really about how the promotion happens, not simply who's doing the promoting.

Things got more layered in June 2025, when Google launched restricted drug term certification for healthcare advertisers. That's a new requirement specifically for personalized targeting involving pharmaceutical terms, stacked on top of whatever certification an advertiser already held. Then in July 2025, the Healthcare and Medicines Policy update reached telemedicine advertising in the UK and Singapore, a reminder that these updates aren't a US-only phenomenon.

Platform matters too. Inside Display & Video 360 specifically, healthcare certification covers pharmaceutical content and US addiction treatment services, not healthcare as a whole category. So a certification that clears you in one context doesn't automatically clear you in another. If you're running wellness apps, supplement brands, or medical device ads, the smart move is auditing exactly where your product sits on that spectrum before assuming a lighter compliance bar applies.

Gambling and games: how certification, geography, and account health interact

Gambling ads need Google certification, need to target only approved countries, need responsible gambling information visible on the landing page, and can never target minors. Four requirements, and missing any one of them is enough to trigger a problem. Google currently allows gambling advertising in roughly 55 approved markets, and that number moves. In November 2025, Google widened restrictions for offline gambling advertising, pushing the list of restricted regions from 21 up to 35. A market you could reach in October wasn't necessarily reachable in December.

Gambling policy changed 18 times in 2025 alone, according to bigbetty.io. No other restricted category came close to that update frequency. If there's one category where "set it and forget it" compliance guarantees a disapproval eventually, it's this one.

October 2025 brought a reclassification that closed a long-running workaround: any app or site offering a redemption mechanism, regardless of "no purchase necessary" language, now counts as Real Money Gambling. Sweepstakes-model advertisers who'd built campaigns around that distinction lost the workaround entirely.

Then the certification bar itself got tighter. The certification bar continues to tighten, with Google signaling that overall policy health across an account matters alongside holding the certification itself.

There's also a structural risk sitting above the individual account: certification compliance issues can carry consequences beyond the single account in question, making account management practices part of the broader risk picture.

On the practical side: certification reviews typically take two to eight weeks. Certification is domain-specific and market-specific, meaning a separate application is required for every country you're targeting. Expanding into a new region means the certification timeline starts over for that market.

Financial products and cryptocurrency: where licensing requirements and evolving regulations overlap

Google defines financial services broadly on purpose: products and services tied to managing or investing money and cryptocurrencies, including personalized financial advice. Personal loans, loan modification services, and credit repair services all sit in the restricted bucket rather than the prohibited one, meaning they can run, but only with the advertiser meeting licensing and disclosure requirements that Google checks for.

Part of that certification is Google's own bar, and part of it is really a reflection of whatever licensing status the advertiser holds externally; Google is checking that advertisers meet the regulation that already exists, rather than inventing new financial regulation of its own. Inside Display & Video 360, financial certification applies to specific product types rather than financial services as a whole.

The enforcement numbers back up how seriously this gets checked: financial services accounted for 327.8 million ads blocked or removed in 2025, the fifth-highest volume among all violation categories tracked. That's not a sleepy corner of the policy book.

Crypto runs its own version of this logic. Google allows advertising for certain crypto-related categories, but exchanges, wallets, and coin trusts all need certification to run. Mining hardware sellers and NFT games sit adjacent to that, not required to certify, but still expected to comply with general policy. What's flatly not allowed, certified or not, are ads promoting initial coin offerings, DeFi trading protocols, or the direct purchase, sale, or trade of cryptocurrencies.

The application process for crypto certification is subject to ongoing change, and advertisers should verify current submission procedures before starting the clock on approval.

The line Google draws in crypto centers on business model rather than asset type. A wallet provider can certify and run ads. A DeFi protocol, doing functionally similar things with different plumbing, cannot. That's worth sitting with, because it means the "is my crypto product allowed" question isn't answered by looking at the asset; it's answered by looking at what the business actually does with it.

Alcohol advertising: where the conditions sit entirely in targeting and creative, not certification

Alcohol breaks the pattern the other categories set up. There's no certification application at all here; the restriction lives entirely in targeting and creative decisions instead.

Three places carry the actual requirements. Audience targeting has to reach only people of legal drinking age in their region, and Age-targeting enforcement remains an active area of Google's policy work, and requirements can shift as policies are updated. Geographic targeting has to match wherever alcohol advertising is legally permitted, since laws vary by country and sometimes by region within a country. And the creative itself, plus the landing page, can't glorify excessive drinking; responsible drinking messaging is expected, and the landing page needs to hold up against whatever local law applies.

No certification gate means no single approval moment to clear and move on from. Noncompliance still triggers disapprovals; the enforcement lever is just the ongoing creative and targeting review instead of a certificate you earn once. Practically, that means alcohol advertisers carry a maintenance obligation that doesn't really end: audit targeting settings and creative periodically, because Google's age-targeting enforcement keeps evolving and yesterday's compliant campaign isn't guaranteed to stay compliant without checking.

This is the detail worth carrying into every other section of this piece: compliance inside the restricted tier doesn't look the same category to category. Gambling and healthcare lean on certification. Alcohol leans on targeting and creative. Crypto leans on business model classification. Treating all of it as one uniform checklist is how advertisers miss the actual requirement sitting in front of them.

Table: Restricted Category Requirements at a Glance. Compares Certification Required, Primary Compliance Lever, Geographic Restrictions, Key Ongoing Risk, and 1 more by Gambling, Healthcare, Financial/Crypto and Alcohol.

What happens after a disapproval and how the appeals process is structured

A disapproval isn't a dead end, but the road back depends heavily on what tripped the disapproval in the first place. For restricted-category issues specifically, the common paths are completing the required certification and resubmitting, editing the ad or landing page to close whatever gap triggered the flag and requesting review, or adjusting targeting parameters, whether that's geography or age, and resubmitting from there.

Account-level suspension is a different animal entirely, and a more severe one. Getting a suspended account reinstated runs through a separate process from appealing one disapproved ad, and it generally takes more to resolve.

There's a tool worth building into any workflow here: Google Ads Advisor, which flags policy violations before a campaign goes live. Using it before launch, rather than treating disapproval as the first real feedback loop, catches a meaningful share of issues before they cost you any time at all.

That 80% drop in incorrect advertiser suspensions Google reported for 2025 is a genuinely good sign about AI precision improving. But read it carefully: it also means legitimate businesses are still getting caught up in enforcement at real scale, just less often than before. Precision improving isn't the same as errors disappearing.

And the MCC-level risk raised earlier under gambling isn't unique to gambling. Policy violations inside managed accounts can affect the manager account's own standing, and its ability to operate in restricted categories across every account it manages, not just the one that slipped up. Given that Google pushed through 35 policy updates in 2025, a static, one-time compliance check at launch is a wager, not a strategy. Ongoing monitoring is what holds up over time.

Building a compliance process that holds up as policies change

Pull every category covered here together and one thread runs through all of them: restricted does not mean stable. Gambling changed 18 times in a single year. Healthcare added a whole new certification layer mid-year, unprompted by anything advertisers did. Crypto rebuilt its entire application process. None of these categories sat still long enough for a one-time compliance review to stay accurate for more than a few months.

So what actually holds up? A few habits, done consistently rather than once. Audit at campaign launch: confirm certification status, targeting parameters, and landing page requirements for the specific category and specific geography you're entering, because approval in one country tells you nothing about approval in the next. Build a calendar-based policy review into the workflow, since Google's update cadence in 2025 averaged more than one meaningful change per week. Run pre-launch checks through Google Ads Advisor or an equivalent process, catching problems before they become disapprovals rather than after. And for anyone managing restricted-category clients under an MCC, track certification status across every account under that manager, not just the one campaign that's currently live, since the accountability climbs the chain in ways a single-account review won't catch.

Geographic expansion deserves its own flag here, because it's a common trap: entering a new market inside a restricted category almost always means a fresh certification application, or at minimum a fresh check on whether that market permits the category at all. Existing approval somewhere else doesn't travel with you.

The system Google built for restricted categories exists to let legitimate advertisers operate in sensitive spaces, gambling, healthcare, finance, alcohol, crypto, while keeping bad actors out. The conditions function as the price of admission, part of how the platform works rather than a barrier standing apart from it. Advertisers who treat compliance as a live, ongoing process, checked and rechecked as policy shifts, are the ones still running campaigns a year from now. The ones who treat it as a box checked once at launch are the ones showing up in next year's suspension numbers.

Sources

  1. support.google.com
  2. support.google.com

More in Ad Policy Workarounds