Earlier quoted context omitted.
Well… marketing and web development are often at war with one another inside individual organizations. And the person running the ads almost never has domain-verification authority. So Google doesn’t want to introduce a major barrier to accept money. I think that makes sense without being malicious.
The attack vector for scams seems immediately apparent, so this just seems very negligent. It also reduces the risk for advertisers as the profit from taking over an ad account is less if you can't direct users to malware from an account with good standing (of course there are still other ways to show malicious ads).
in other words, a malicious ad doesn't do much for them but actively increasing security is bad. yay capitalism