A complaint about one fake iPhone alert reached 577 points and 272 comments in a September 13 Hacker News snapshot, the highest-scoring Hacker News candidate in this publishing cycle. The YouTube banner copied an iOS storage warning and presented Yes and No as if they were system controls. Google reportedly reviewed the ad twice after users flagged it and said it broke no rules. Yet Google's published policy names that visual trick among its prohibited examples.
The mismatch matters because Google says Gemini-powered systems stopped more than 99% of policy-violating ads before they ran in 2025. It also says Gemini helped its teams take action on more than four times as many user reports as in 2024. The fake alert tests the recovery path behind those claims: what happens after pre-serve checks miss an ad and a viewer supplies fresh evidence? In this instance, the answer was two clean verdicts for a creative that appears to match Google's own examples almost line by line.
The ad copied a system warning
Chris Greening, who publishes the Atomic14 engineering blog, wrote that the ad had appeared in his YouTube app for a couple of months. Its artwork imitated an iPhone dialog saying the phone's storage was full, added a warning that some features might stop working, and displayed two choices. Greening said he accidentally tapped it while his phone really was running low on space. That timing may have been coincidence; the post supplies no evidence about how the ad was targeted. The visual deception does not depend on targeting. It works by borrowing the authority of the operating system.
Greening reported the ad and received a response saying it did not violate Google's policies. He submitted a second report and got the same result, according to his account and the response images he published. He also wrote that other people had reported the creative and received the same reply. The public record is narrow: the post does not identify the advertiser, document the destination reached by every tap, or reveal whether a person or an automated system made either decision. Those gaps rule out claims about malware, the advertiser's intent, or a system-wide failure. They do not erase the visible design or the two reported review outcomes.
Google's misleading ad design policy says ads must make it clear that a user is interacting with an advertisement. Its prohibited examples include ads resembling system warnings, ads that look like dialog boxes, and image ads with controls such as multiple-choice options that do not work as presented. The storage creative described by Greening contains all of those traits. The policy also says this class of violation usually brings a warning before an advertiser account can be suspended, so rejecting the creative would not automatically require the harshest account penalty.
The placement adds another clear rule. Google's requirements for YouTube and Discover ads apply the standard Google Ads policies to those formats and separately prohibit misleading claims and false urgency. An invented storage emergency inside a system-style box asks the viewer to react before checking whether iOS produced the message. Even if the advertised app itself were legitimate, the creative can still fail the design rule. Ad safety review has to judge how the pitch gets the click as well as what waits at the destination.
The second clearance is the harder failure
Google's claim that its systems stopped more than 99% of policy-breaking ads before they served concedes that some submissions still ran. The company's 2025 figures make the scale plain: it blocked or removed more than 8.3 billion ads and suspended 24.9 million advertiser accounts. Google attributes 602 million of those ad actions and 4 million account suspensions to scams. A single miss cannot disprove its 99% pre-serve figure, which Google reports from its own enforcement data. This case sits in the smaller group that got through.
A user report is supposed to open a second route into enforcement. Google's help page says a reported ad goes to its Trust and Safety team for a policy check, with action taken when the ad violates a rule or the law. Reporting also does not block the ad for the person who filed the complaint. That makes an accurate decision and a useful reason especially important: a viewer can do exactly what Google asks and remain exposed to the same creative.
The two reported clearances show how a miss can survive that second route. The response in Greening's post only says the ad does not go against Google's policies; it does not explain which policy was tested or why the fake controls were acceptable. A reviewer who saw only account history or destination signals could miss the creative-level issue. A reviewer who saw the screenshot had a direct match against multiple examples in the policy. The available evidence cannot tell us which data reached the reviewer, and that missing trace is part of the problem.
Gemini already works inside Google's ad defenses
Greening ran the image past Gemini and published its answer. The model classified the ad as disallowed, pointing to the imitation system alert, inert controls, and fear-based wording in the creative. That is a useful demonstration of visual policy matching. It is not a controlled evaluation: the post does not provide the full prompt, model version, repeated trials, or false-positive tests. A consumer Gemini answer cannot stand in for the production classifiers, thresholds, and evidence available to Google's ad systems.
Google is already using Gemini in those systems. Its 2025 Ads Safety Report says models inspect hundreds of billions of signals, including account age, behavioral cues, and campaign patterns. The company says a majority of Responsive Search Ads were reviewed instantly by the end of 2025, with expansion to more formats planned during 2026. It does not state on that page whether the same instant review covered the YouTube format in Greening's post. The practical question is where the visible cue disappeared between upload, publication, and two user reports.
Google also says the newer system reduced incorrect advertiser suspensions by 80% in 2025. That goal creates a real calibration problem: an enforcement model that rejects too freely can shut down legitimate campaigns, while a cautious one lets more harmful ads run. This creative should be an easier case than a disputed product claim because the design policy supplies concrete visual examples. A useful review tool could show the matched feature and rule to the decision-maker, then preserve that reasoning for an appeal or repeat report.
The 99% figure leaves out recovery quality
Google presents 99% as the share of policy-violating ads caught before they served. Its published summary does not explain how it counts violations that no system identifies. The percentage also says little about how long a missed ad remains active, how often valid reports receive a no-violation response, or whether a repeat complaint gets a different level of review. Google says action was taken on over four times as many user reports in 2025, but it gives no false-negative rate for those report decisions or results split by ad format. Volume can rise while the same obvious miss passes through more than once.
Time from the first valid report to removal would show how long exposure continues. The share of repeat reports that overturn an earlier decision would test escalation, while format-level error rates could expose differences between image-heavy YouTube placements and Responsive Search Ads. Google publishes enormous enforcement totals; pairing them with those narrower measures would tell viewers and advertisers how the complaint loop performs after automation fails.
Google can now reclassify or remove the ad, explain why two reports returned clean decisions, and check visually similar creatives against the same system-warning rule documented in Greening's post. Its next Ads Safety Report can disclose report accuracy and removal time by format. Until then, the 99% pre-serve claim and this twice-cleared fake dialog can both be true. The unresolved issue is how quickly Google's review system learns about the part that got through.