The Consent Tax
Cookie banners were meant to protect your data. A decade on, they're gutting the publishers who fund the open internet, and AI is about to make it worse.
The prevailing belief, on both sides of the current fight in Brussels, is that cookie consent banners are basically fine in principle and just need fixing in practice.
Tighten the dark patterns, ban the pre-ticked boxes, make reject as easy as accept, and the mechanism does its job. I don’t think that’s right. I think the mechanism is the problem, and I will get into why today.
New here? I’m Mike Harty. I’ve spent 15+ years building B2B programmatic infrastructure from the inside, and I still run that infrastructure day to day at FunnelFuel.
If the economics behind supposedly “free” data are your kind of argument, start with The Observer’s Paradox in B2B, on why chasing the wrong metric quietly breaks the thing it’s meant to protect, and The Dirty Secret of B2B Intent Data, on why more signal often makes a data problem worse rather than better.
Get next week’s argument on how to actually run CTV for B2B marketing by subscribing below
Before I do, if this is all sounding a bit alien, this is what we are talking about - a European problem which has been exported to our friends in North America.
Ten years of trying to put users in control of their data has done real, measurable damage to the thing that data was meant to fund, and to the users it was meant to protect.
Now it’s colliding with an AI-driven internet nobody designed it for. This is the law of unintended consequences playing out at internet scale. The clearest proof is that the EU push to unwind its own law is coming from people who built it.
What you’ll learn in this piece:
Why the EU is trying to dismantle a consent architecture it only finished rolling out a few years ago
What a decade of “click yes” banners actually did to publisher revenue, user trust and user comprehension, at the same time
Why hundreds of vendors sitting behind one banner broke understanding rather than building it
Why swapping the banner for a browser-level toggle doesn’t fix the underlying economics, it just moves who controls it
What’s really being exchanged when you click accept, and why the fear-based framing outruns the actual risk more often than not
Why AI’s zero-click search makes this the worst possible moment to strip publisher monetisation further
What an architecture built for today’s internet, rather than 2002’s, would actually need to do
You didn’t design ‘cookie’ consent this way. Nobody did.
I have quoted cookie because this extends far beyond a mechanism which itself has all but died a death. This is not just cookies, its essentially all tracking.
With that caveat out of the way, the legal root of the banner sitting on every site you visit is Article 5(3) of the ePrivacy Directive, EU law from 2002, before smartphones existed. It said, reasonably, that storing or reading information on someone’s device needs their consent first. GDPR arrived in 2018 and gave that requirement teeth.
Neither piece of legislation mandated the thing you actually experience today: a full-screen modal, a tabbed settings panel, a scroll of toggles for vendors you’ve never heard of. How is an average user of the internet ever going to make head nor sense of that?
That modal UX got built by the market responding to liability, not by regulators specifying a UI.
Consent Management Platforms scaled up. The IAB’s Transparency and Consent Framework standardised the plumbing and then got pulled over the coals for being illegal anyway, all of which points to a massive mess.
The Global Vendor List that sits behind most of those banners now runs past 1,200 registered vendors, ad servers, measurement providers, DSPs, SSPs and agencies, most of them invisible to the person clicking through. Somewhere in that scaling, a lightweight consent requirement turned into an entire industry of consent engineering, complete with its own dark-pattern arms race - pre-ticked defaults, reject buttons buried three taps deep, copy written specifically to nudge you toward “accept all” because that’s the outcome that keeps the lights on.
Nobody sat down and designed this. It’s what you get when a simple legal requirement meets a commercial incentive to maximise consent rates, repeated across millions of sites for a decade.
This is all a nuance of web based advertising, and noise which largely gets worked around within social ‘walled gardens’. This led to the de-funding of the open web, which reflects a pivotal moment in the defunding of quality journalism in favour of the proliferation in AI slop which has filled these walled gardens.
B2B vendor investment measured against attention time has never been weaker in the open editorial internet, and never been stronger then it is in these sloppy garden waters, all of which represents a missed opportunity - and these privacy laws have to take their share of the blame.
Three unintended consequences of one messy law
Here’s where I part with a lot of the privacy commentary on this.
The usual framing is that cookie banners are annoying but at least they’re protecting you. I’d argue they’re failing on all three fronts they were meant to help, simultaneously, for the same underlying reason: nobody priced in the value exchange they were regulating.
Publisher monetisation. Every rejected consent is inventory a publisher can’t monetise properly, on content they gave you for free. The consent banner sits between the reader and the business model that funds the article. For a decade that’s been treated as an acceptable cost of privacy protection. It isn’t. It’s a consent tax on the one business model that keeps the internet open rather than paywalled, and publishers have been paying it quietly for years. This defunds journalism and forces publishers down routes that jeopardise their real part in creating the value of the Internet - forcing behaviours like deploying more AI slop to replace the human crafted word because the latter isn’t economical anymore, and cramming more crappy user experience ads onto the page because they add a few precious cents of revenue to pay the bills.
User comprehension. Open a serious news site’s cookie panel and you’ll find a vendor list running into the hundreds, most of them companies you’ve never heard of and have no way to evaluate. That isn’t transparency. Transparency means understanding what you’re agreeing to. A four-figure list of unfamiliar businesses does the opposite. It manufactures distrust of a data exchange most users don’t have the context to assess, and it asks for that decision in the ten seconds before someone actually wants to read the article they clicked on. When you pull this apart, it borders on ludicrous. If I am trying to read a quick piece of industry news that my colleague has shared, in-amongst doing 101 other things, in what world am I going to inspect what sits behind a cookie banner? and if the alternative to clicking ‘accept’ is either being blocked from reading the news or having to pay, what choice am I really exercising? this is consent theatre and I call BS on it.
User experience. The annoyance is well documented and doesn’t need much defending. What’s less discussed is what that annoyance trains people to do: click accept without reading anything, on autopilot, which is the exact opposite of informed consent. A mechanism built to create meaningful choice has trained an entire generation of internet users to treat the choice as friction to clear as fast as possible.
Three failures, one root cause. The law tried to solve a data-literacy and market-structure problem with a consent-click, and a consent-click was never going to carry that weight.
Brussels wants to undo its own law now
This is the part that should give the “just needs better implementation” crowd pause.
The European Commission’s Digital Omnibus proposal, working through Parliament this year, aims explicitly at reducing cookie banner frequency and shifting consent toward centralised, one-click preferences set once at browser or OS level.
Privacy NGOs have gone further, with a “Kill the Cookie Banner” campaign pushing for exactly that outcome.
Google’s submission to the consultation argued for deleting the relevant provision outright, on the grounds that keeping it anchors the reform to what it called a proven-failed architecture. Meta went further still, arguing for scrapping Article 5(3) itself, the clause that requires consent before storing information on a device in the first place. I certainly don’t always agree with big tech and its big personal agendas, but they are right. We are now in danger of tweaking something that is fully not fit for purpose.
Read that lineup again. The regulator that built this, the privacy advocates who fought for it, and the platforms who profit from it are all now pointing at the same mechanism and saying it doesn’t work. They disagree fiercely about what should replace it, and the reform is reportedly getting bogged down in exactly that disagreement. But the premise that the current banner model has failed is close to consensus. Ten years after GDPR was supposed to have settled this, that’s a remarkable place to end up.
The strongest privacy argument, and where it still misses
I want to give the other side its due here, because waving away every consent requirement as bureaucratic overreach is its own kind of unintended-consequences trap.
The strongest version of the privacy case isn’t about banners at all. It’s about “pay or consent” models, where sites (Meta being the highest-profile example) offer a binary choice: accept tracking, or pay to avoid it. The European Commission fined Meta €200 million in 2025 for this, on the grounds that a subscription fee steep enough to be unrealistic isn’t a genuine alternative, it’s coercion wearing a choice’s clothing. The privacy zealots are still missing the point that any business, whether it is a publisher or a social media platform, has the right to charge money to use their services. This ingrained ‘the internet is free model’ is naive and these are big businesses. If their preferred model is advertising funded then they can bias their charging models towards that outcome, just like a shop can reduce the price on red sneakers to try and sell them over their green counterparts.
BEUC, the EU’s largest consumer group, says Meta’s revised model still doesn’t offer a fair one. Fair critique, and a different problem to the one I’m describing: it’s about power asymmetry between a gatekeeper and a user with no real second option, not about whether consent-by-click is the right mechanism in general.
Where the argument overreaches, in my view, is assuming the fix is more consent infrastructure rather than less. Shift the “consent moment” to the browser or the OS, which is the direction both the Digital Omnibus and the anti-banner campaigners are pushing toward, and the coercion problem hasn’t gone anywhere. It’s just moved. The problem this brings is the chance for the user to make one decision, going through the few extra clicks to select reject because it is a single ‘set and forget’ that then switches off monetisation for publishers. This will push more and more to charge, and that blocks content access for many users who are unable to afford it. And it goes against the model that publishers have been happy to extend since 1993 - offering their content free on an ad funded basis. I don’t see the losers in this model.
Additionally, if the browser contains universal consent, you’ve handed the decision to whichever company controls the browser or the device, which today means Google or Apple almost by default. That isn’t a neutral piece of infrastructure letting a technical signal travel with the user. It’s consolidating the exact leverage everyone’s worried about into two companies that often behave like monopolists, instead of distributing the friction across the open web. Fixing pay-or-consent coercion by centralising consent into a gatekeeper’s settings menu solves one power problem by creating a bigger one. Who is to say Google, for example, couldn’t or wouldn’t leverage that to push more of their own services. Their zero click search is being leveraged to retain users within Google, and distributing about 2% of the clicks that their original model distributed.
This is roughly where I land on browser-level consent generally: worth considering, dangerous if it’s the only lever. If you want the fuller argument for why, that’s a subscriber-only follow-up I’m working on now.
What you’re actually agreeing to, probably
Strip away the fear-mongering language most banners are written in, and the actual data handshake behind most “accept all” clicks is anonymised, segmented browsing behaviour used to serve more relevant ads. Not a file with your name and address in it. Not something saying Mike has been buying xyz and viewing these websites and looking at these health concerns. Just a random alpha-numeric identifier used in aggregate to pick up interests on a topic level to tie back to more relevant advertising. That’s meaningfully different to what the four-figure vendor list and the ominous copy imply.
I’ll hedge this properly rather than wave it away. There are legitimate re-identification risks when enough anonymised signals get combined across data brokers, particularly at scale and particularly with location data. “Anonymised” isn’t a synonym for “no risk.” That’s a real argument and it deserves better regulation than a click-through banner gives it. But the banner as currently built doesn’t communicate that nuanced risk either. It communicates blanket, undifferentiated alarm across every vendor on the list, whether that vendor holds sensitive location history or an anonymised interest segment used once to decide which ad to show. Undifferentiated fear isn’t better data literacy than no information at all. In some ways it’s worse, because it looks like transparency while functioning as noise.
This is the worst possible moment to make monetisation harder
Set the consent debate against what’s happening to publisher traffic right now and the timing gets worse, not better.
Chartbeat data cited in the Reuters Institute’s 2026 predictions report found publisher referral traffic from Google organic search down by roughly a third globally over the past year, driven by AI Overviews answering queries directly on the results page instead of sending users onward. Zero-click behaviour on AI search products like ChatGPT Search, Perplexity and Google’s AI Mode runs far higher again. ChatGPT’s outbound referrals to publishers have grown, but industry reporting is consistent that the growth isn’t close to offsetting what’s being lost elsewhere.
So where does this leave real journalism?
Publishers are watching two structural forces hit at once. A legal architecture restricting how they monetise the readers who do show up. A search and AI ecosystem sending them dramatically fewer readers to monetise in the first place, while training its models on the content those publishers produce.
Neither force was designed with the other in mind, because neither existed when the other was built. The ePrivacy Directive is 2002 legislation for a pre-smartphone internet. AI Overviews are technology from an internet nobody in 2002 could have modelled.
Layer today’s consent architecture on top of today’s search behaviour and expect the publisher economics to hold up, and you get the same mistake stacking on top of the first one. Call it the consent tax, round two.
What actually needs to change
None of this is an argument for scrapping consent altogether, and it’s not an argument that the open, free-to-read internet we’ve had since 1993 doesn’t deserve protecting. It’s the opposite. Most users, I believe, if the trade-off were ever explained to them properly, would choose that open internet over a pay-walled alternative. Protecting it means changing the mechanism, not just its cosmetics. All the consent leavers are find until it comes at an actual cost to you, and who in 2026 is feeling flush enough to start splashing the cash on buying more subscriptions?
Three things, in order of how tractable they are.
First: real technical enforcement of what’s already promised, blocking data flows before consent rather than after, rather than the cosmetic layer most CMPs currently provide.
Second: whatever replaces the current banner needs a genuine competition safeguard built in from day one, not bolted on afterwards, so “simplify consent” doesn’t become “hand two platforms the keys.”
Third, and this is the one nobody in the current Brussels fight is really discussing: publishers need an actual value-exchange model that doesn’t depend on a four-figure vendor list nobody reads. Fewer, better-understood data relationships tied to a specific, explainable exchange, rather than the current approach of maximising the number of parties behind one blanket toggle.
That third point is close to the thesis I’d argue professionally, not just as a newsletter opinion: the industry needs infrastructure built around a small number of legible, accountable data relationships, not thousands of anonymous ones hiding behind a single click. If you’re building on the buy or sell side and want to talk through what that looks like in practice, drop me a line at mike@funnelfuel.io.
Killing the cookie banner without fixing what it was trying to do won’t save the open internet. It’ll just move the consent tax somewhere less visible, and hand publishers a second structural headwind at the exact moment AI is already collecting on the first one.
Where do you land: is a browser-level, one-click consent signal actually a fix, or just a more efficient version of the same problem?




