It's really amazing, but I think it has one big flaw - often a perfectly legitimate email ends up in the spam folder, probably because someone reports them as spam, or because of the number of messages someone sends. Google obviously uses algorithms that track such things, but they don't have too good AI to distinguish that let's say Ledger doesn't send spam messages, though they are probably being sent by the hundreds of thousands. That's why I look at the spam folder from time to time and return legitimate messages to Inbox.
The problem is not that someone opens the spam email, but that they follow the instructions that are in it.
I've experienced that several times, but there's no perfect system & looks like google decide to pursue overall accuracy rather than reducing false positive.