Usually, this is because you can easily detect some of the anomalous behavior but not all of it. So you'll have some activity which is obviously anomalous, some which is obviously legitimate, and some which could be either. And sometimes when you've detected some that are obviously anomalous, most of the rest of the activity ends up being in the category of "could be either" with almost none left in the obviously legitimate.
So from Google's point of view, I'm sure they ban the account so that they 1) don't end up paying a lot of money to users for the "could be either" activity, and 2) don't need to keep expending server resources continuously categorizing and serving the obviously anomalous traffic.
Google's plan is to make it sufficiently expensive to avoid detection in the aggregate that selling fake clicks isn't a viable business proposition. The fraudsters have inverted the game: they can't beat Google's detection algorithms, so they can't sell you fake clicks, but they can sell you protection from their fake clicks.
Google's move at this point seems to be lessening the punishment for fake clicks so it's still not economically viable to sell them but also not economically viable to use them as a threat.
The publisher wants to show little clickfraud to keep their rates high, but don't get the data to handle nor often have the technical resources to prevent it if they knew. The advertiser doesn't really understand the modern ad market so sees "fraud" and will go to the agency that promises zero fraud, even if they're more expensive than just eating the fraud. The ad server doesn't really care per se, and can't do much because (outside RTB optimization) the publishers are the only ones who can really do the work to prevent the fraud. But they need to keep the publisher and agency happy, so they measure it. Both the publisher and agency get unhappy if the numbers are high, no matter how true they are or how inefficient it would be to bring them down - so the ad servers are either incentivized to lie (in practice meaning, not investing much in fraud detection) or to kick publishers with high fraud rates off.
(The closely-related question is why fraudulent clicks matter at all, when CPM/CPC rates should pretty quickly decline in proportion to target the same number of real people for the same price. But no matter how much we tried to sell actually useful features - e.g. no ads for your vacation planning service on a news article about a plane crash - all any customer ever cared about was click fraud!)
Put another way: someone testing Google Ads with a $100 ad buy is (my guess) 1000x more valuable than a (new to Google) publisher someone showing $100 worth of ads. If the former experiences fraud, they leave. If the latter has their $ yanked by google, eh, there's still trillions of ad slots per day available.
Put another way, actual relationships with customers solve this problem trivially.
The amazing thing to me is Google treats almost everyone the same. From a site getting $5 a month to $5,000 to $50,000. About the only difference I've noticed is I sometimes get to have conference calls with people who have the same suggestions. I've provided Google with billions of (legit!) ad impressions over the years and wouldn't even get a phone call before being kicked off.
If the fraud rate is high enough, they likely can't pick out any real users anymore, as they get lost in the noise.
They don't.