Meta publishes its advertising policies as a public document. Anyone can read them, and plenty of restricted-vertical brands do, then treat that page as the rulebook they are up against. It is not. In a high-risk category, the written policy tells you almost nothing about what actually happens when you hit publish.
The policy is the starting line, not the territory. What decides whether your ad runs is how that policy gets enforced, by what, and against which signals. Get that wrong and you will spend months rewriting copy to satisfy a reviewer that was never reading your copy the way you think. So let me walk through how these policies really work in the verticals we have run for a decade: what Meta restricts, how it enforces it, and where the real levers are.
What the policy actually restricts
Start with the map most people never draw correctly. Meta does not treat every hard vertical the same way. It runs a two-tier system, and knowing which tier you are in changes everything downstream.
- Hard-banned, no front-door path: cannabis and recreational marijuana, CBD (filed under the same heading as illegal and recreational drugs), and tobacco including cigarettes and cigars.
- Restricted, banned by default but a path exists: nicotine pouches and snus, hemp-derived products, vape and e-cigarettes (prohibited in most markets with narrow exemptions), and gambling, which needs explicit written permission from Meta per jurisdiction.

Meta's two-tier policy system: hard-banned products versus restricted products with conditional approval paths.
Here is the part that trips up almost every brand owner at least once. Meta sorts your ad by its own policy category, not by whether your product is legal where you sell it. Those are two different things. A hemp-derived CBD product can be fully Farm Bill compliant, lab tested, under the legal Delta-9 threshold, and Meta still files it in the same bucket as controlled substances. The law and the policy are not the same document, and the review system only enforces one of them.
That distinction is not academic. We have seen a brand get its warm-up campaign rejected not for anything in the imagery but for the product's own name reading as a medical or drug signal to the system. Nothing illegal, nothing visually risky. The name alone was enough to trip the category. If you are arguing with Meta that your product is legal, you are arguing with an opponent that was never checking legality in the first place.
The policy is enforced by an AI that over-blocks
Once you know what the policy covers, the next question is who enforces it. For high-risk verticals, the honest answer is: mostly a machine.
Meta's review at this scale is primarily automated. And the AI doing it is tuned a specific way. It is built to catch everything that looks suspicious, even at the cost of wrongly flagging legal products constantly. In plain terms, it would rather block a hundred clean ads than let one banned one through. So it over-blocks. That is not a bug you can complain your way out of. It is the design.

Meta's AI reviews ads as a combined signal of image, text, and context, not individual elements.
The second thing to understand is that the AI does not read your ad one banned word at a time. It reads the whole thing as a single combined signal: the image, the text, and the context together. No single element has to be explicit for the ad to get pulled. The combination is what tips it over.
Picture a hemp brand running a lifestyle image. The product is legal, the shot is clean, but there is a wisp of smoke in the frame and the caption leans into language that reads as recreational. Individually, none of that is a smoking gun. Stacked together, the system reads "flower use" and rejects the ad. This is why a perfectly good product shot can die the moment the copy around it changes tone. You did not add a banned word. You shifted the combined picture the machine assembles.
For a restricted-but-legal product, this over-blocking is often a misclassification you can push back on, because you can show the system filed a legal product in the wrong category. For a hard-banned category, there is no wording clever enough to reclassify cannabis as not-cannabis. Which brings us to the account.
Why the same ad lives on one account and dies on another
Here is something that makes no sense until you see the mechanism behind it. You can take one creative, run it on two accounts, and watch it get approved on one and rejected on the other within minutes. Same image. Same copy. Different outcome.
The reason is that the account is part of the signal Meta reads. Everything on the platform is connected in a chain: the profile, the ad account it operates, and the business manager above it. Meta assigns an invisible trust score to each link in that chain, and trust flows across the whole thing. You never see the number. There is no gauge in the interface. But it is doing work on every single ad you submit.

Two identical ads: one approved on a trusted account, one rejected on a fresh account.
An ad account built off a high-trust, established business manager carries more standing. It can push riskier-looking creative live and it tolerates more rejections before Meta disables it. A fresh, weak account has no positive history to offset anything, so the first few rejections can be enough to burn it. The lesson operators internalise fast: when identical creative passes here and fails there, stop rewriting the ad. The ad was never the only variable. The account carrying it was.
This is why account health is a discipline of its own, not an afterthought. If you want the deeper version of reading those signals, we broke it down in account health monitoring.
Which tier you are in decides the whole playbook
Now put the two tiers back on the table, because this is the fork that determines how you actually operate.
If you are in a restricted category (hemp, nicotine pouches, gambling with permission), you have room to run more openly. When the system misfiles a legal product, you can often demonstrate the category was wrong and get it reviewed again. You keep the account healthy, you appeal selectively, and you build a real presence.

Three operational tiers in high-risk advertising require completely different account strategies and risk mitigation approaches.
If you are in a hard-banned category (cannabis, CBD, tobacco), no appeal script saves you, so the operation is built differently. The destination is set up so automated policy review and a real human buyer each land on the page each is meant to see. That is table stakes in these verticals, and it is the reason a compliant-looking ad can drive real traffic to a real offer. We cover how the review-safe side of that is actually built in building compliant landing pages. Alongside it, accounts get spread across categories and business managers so a single policy hit on one product line cannot take the whole operation down.
One more threat lives in a category by itself, and brands never see it coming. In tobacco-adjacent verticals, the real danger is not Meta's policy algorithm at all. It is Meta's legal department acting on an intellectual property claim from a major manufacturer. That is not policy enforcement you can appeal with a categorisation argument. It is Meta's legal team acting as a shield for a third party, and the recovery path is a completely different, harder animal. If you run in that space, you plan for it as its own risk, not as another rejection.
How you earn the right to run bolder creative
None of the above means you launch a brand-new account straight into your boldest creative. You earn that. The mechanism is the warm-up, and it exists precisely because of the trust score we talked about.



Live general ad creatives from real Icarus client campaigns.
A fresh account has no history, so you spend the first stretch giving it one:

Four-stage account warmup sequence: establish activity, bank approvals, maintain baseline, then gradually introduce bolder creative.
- Establish real activity first. The account needs live billing and a genuine spend history before anything restricted goes near it. You start it clean and low.
- Bank a run of clean approvals. You launch sanitised creative, carrying no policy triggers, and get a batch of campaigns approved. Now the account has positive signal on the books.
- Run that baseline for one to two weeks. During this window the whole goal is a healthy approved-to-rejected ratio. Meta watches rejected versus approved in the background, so you keep rejections low, roughly under one in ten, or the account tips into a flagged state.
- Introduce bolder creative gradually, alongside the baseline. You do not pivot the whole account at once. New, riskier creative goes in next to the sanitised campaigns so the overall ratio stays diluted while the new work clears review.
Two rules ride on top of that sequence. First, appeal selectively. Every appeal is a flag you raise with Meta's reviewers, and flooding the queue costs you account standing faster than the rejections themselves. Second, knowing exactly when to push harder is a judgement call, not a date on a calendar. An experienced media buyer reads the account's health signals and decides when it is safe to escalate. That feel, built over years and hundreds of accounts, is the part no policy document will ever hand you.
What the policy terrain means for reading your numbers
One last thing all of this quietly dictates: how you should judge performance. Most high-risk verticals cannot run Meta's pixel, because Meta will not knowingly let a prohibited category install it. So conversions get tracked server-side through your own infrastructure, and Meta's reported numbers will always undercount real sales.
That has a direct consequence for how you read a campaign. Front-end ROAS on the dashboard is not a verdict on profitability. It is the price you paid to acquire a customer, and in these verticals it is an undercounted price at that. Most of these categories are repeat-purchase businesses, so the real scoreboard is cost per acquisition against lifetime value, judged on backend revenue and the trend over weeks, not a single day on a dashboard. If you want to put honest numbers to that, the ROAS calculator is the fastest way to see where your real break-even sits.

Dashboard ROAS versus server-side reality: where high-risk verticals see the true cost per acquisition.
The short version
Meta's written policy is the least useful document in the room. What matters is the two-tier structure of what it restricts, an enforcement layer that over-blocks and reads your ad as one combined signal, and an invisible trust score on the account that decides whether that signal passes. Which tier you sit in sets the whole playbook, and the warm-up is how you earn the freedom to run the creative that actually sells.
This is the terrain we have operated in since 2016, across roughly 300 brands in cannabis, CBD, kratom, vape, gambling, adult, and peptides. If you want a straight read on how these policies apply to your brand, take a look at the industries we run and start a conversation. The policy is not the enemy. Not understanding how it is enforced is.

Meta's two-tier enforcement system: restrictive accounts versus trusted accounts running identical creative.
