To protect their business by protecting their reputation.
The scale of Google's advertising business(es) means that a loss in revenue from poor public perception of their ads is likely to be far more than a few thousand small ad buyers (those spending <US$5000/mo) getting cut off, which would barely register as a rounding error (<0.1% of just AdWords revenue alone.)
A rare anecdote of Joe Schmo not getting his 97.54 payout is effectively meaningless.
Fraud detection costs money. If there is no money changing hands, why spend the money on detection?
By "paying for clicks", I was thinking that they'd be paying some service to click on the ads, rather than writing their own scripts or doing it manually.
Not to defend Google here but... how did you determine this? By seeing those < 0.01% of issues where it goes wrong? How did you determine the magnitude here and how do you know the systems aren't right in > 99.999999% cases?
Google's willingness to shut down a lot of things on what seem like a very surface level fingerprinting means it's pretty rock solid to predict what will happen.
Google wants you to believe both that it can detect a website owner doing bad things (blackhat SEO, click fraud on ads on their site to earn more money, etc), yet simultaneously that they can catch any bad actors faking those things to damage you (negative SEO, click fraud to terminate your own accounts, etc)
That obviously isn't possible. Google cannot determine the intent behind anonymized actions. They just want you to believe that they can in order to discourage people from trying to game the system.
I've heard of Twitter and YouTube accounts being suspended for buying followers, but anyone with $5 can send tens of thousands of fake followers at anyone's account.
The only real solution these services have is to silently ignore the faked traffic whenever they observe it. Anything else can be gamed from either side.