Google Ads is piloting a security requirement that stops users signed in with a free email address, such as @gmail.com or @yahoo.com, from completing sensitive actions on an advertiser account. Google set the rule out in a new help document, which says only corporate email accounts will be allowed to complete those actions, and Search Engine Roundtable reported the document on 6 August 2026. Google describes the requirement as "currently being piloted for a subset of advertisers", and says an email notification is sent to accounts enrolled in it.
Google says the reason is unauthorized access
In the help document Google says the change is there to "enhance account security and minimize the impact of unauthorized access". Search Engine Roundtable connects the pilot to the recent wave of Google Ads account hijacks. Read that way, the target is not the advertiser but the attacker who gets into a personal inbox and then walks into every ad account that one login controls.
The restricted actions are the ones that hand over control
Google gives two examples of sensitive actions: account linking updates and user access changes. It also states that the examples are "non-exhaustive and are subject to change without prior notice", so the set can grow at any point with no announcement.
The rest of the job carries on. Google states that users on free-domain email addresses can still view reports and make routine campaign edits, depending on their access level. The pilot sits on the permission layer, not on daily campaign work, so a Gmail login can still pause a campaign or move a bid while losing the ability to invite a new user. Because Google does not spell out which product links count as account linking updates, any planned rebuild of a GA4 to Google Ads link is worth scheduling around whoever holds the corporate login.
Multi-Party Approval starts at three administrators
The FAQ attached to the document adds a second layer. Google says that if an account already has 3 or more active administrators, inviting a new user or modifying administrator privileges will trigger Multi-Party Approval, which requires another existing administrator to approve the request. On those accounts one admin acting alone cannot grant access.
That changes the shape of onboarding for any team that adds people often. Adding an account manager stops being a thirty-second task and becomes a request that sits in a queue until a second administrator signs it off.
A moved account needs its own new passkey
The FAQ also confirms that a corporate account someone has moved to needs a new passkey of its own, because passkeys are tied to an individual Google Account. Moving a team member from a personal Gmail login to a company-domain login is two pieces of work rather than one: create the corporate account and grant it access, then set up a passkey on that account.
The pilot at a glance
Every line in the table below comes from Google's help document and its FAQ as reported on 6 August 2026.
| Item | What Google states |
|---|---|
| Who is covered | Users signed in with free-domain email addresses such as @gmail.com or @yahoo.com, within a subset of advertisers in the pilot |
| Example sensitive actions | Account linking updates and user access changes, on a list Google calls non-exhaustive and subject to change without prior notice |
| Multi-Party Approval trigger | An account with 3 or more active administrators, when inviting a new user or modifying administrator privileges |
| Passkeys | Tied to an individual Google Account, so a moved-over corporate account needs its own new passkey |
| Still allowed on a free-domain login | Viewing reports and making routine campaign edits, depending on access level |
What this means for Thai marketers
Thailand runs a lot of Google Ads work from personal Gmail addresses. Freelancers, small agencies and SME owners commonly hold client accounts on an address they set up years ago, and plenty of Thai businesses have never bought Google Workspace on their own domain. If Google enrols one of those accounts in the pilot, the person who has always granted access will be the person who can no longer grant it.
The fix is administrative rather than technical, and it is cheapest before the notification arrives. Work out which corporate-domain Google account should hold administrator rights on each Google Ads account, add it as an admin while a free-domain admin can still do so, and set up a passkey on it. A company that has no domain-based email at all has a bigger question to answer first, and answering it while campaigns are running normally beats answering it during a lockout.
Frequently asked questions
Is this already live on my account?
Only if Google has enrolled you. Google says the requirement is being piloted for a subset of advertisers and that enrolled accounts receive an email notification, so the notification is the signal. There is no public opt-in or opt-out described in the document.
Does this mean I can no longer log in with a Gmail address?
No. Google states that users on free-domain email addresses can still view reports and make routine campaign edits, depending on their access level. What the pilot blocks are the sensitive actions, with account linking updates and user access changes given as the examples.
Is the pilot running in Thailand?
The source does not state which countries or account types are in the pilot. Google says only that it covers a subset of advertisers, so a Thai account could be in it or not, and the email notification is the only stated way to know.
Do I have to do anything if I have not been notified?
Nothing is required, but two preparations cost little: make sure at least one corporate-domain Google account holds administrator access on each Google Ads account, and set up a passkey on that corporate account, since Google confirms passkeys do not carry over from another account.
What counts as a corporate email account?
Google's document draws the line between free-domain addresses such as @gmail.com or @yahoo.com and corporate email accounts, and the reported text does not define the term any further. In practice that reads as an email address on a domain the business itself controls.
An account access review is a dull hour that pays for itself the first time someone leaves the company or loses a password. If you want a second pair of eyes on who holds administrator rights across your Google Ads accounts, the Relevant Audience team can walk the list with you.







