- Researchers at sheets.works opened one AP News article, clicked nothing, and found 618 cookies in the browser, 586 of them set by 162 other companies.
- Blocking third-party cookies cut the median from 379 to 46 on the ten heaviest pages, but ad scripts still wrote cookies under the site's own name.
- Leaders should ask who controls the code running on their pages, and what it sets before a visitor answers the banner.
The web cookie was designed so that no company could follow you from site to site. A test published this week suggests the ad market found its way around that design long ago, and that the consent banner you are asked to click comes after the fact.
The test began with a single AP News article on protests over evictions in Spain. On 9 October 2026, a clean Chrome profile loaded it over a home internet line in India. A banner asked whether the visitor agreed to share data with AP's 630 partners. The researchers left it unanswered and scrolled to the end of the story.
Who put them there
AP set 32 of the 618 cookies itself. The other 586 came from 162 other companies whose code arrived with the ads and the video player. Many were ad-auction firms a reader would never knowingly visit. The researchers say 26 of the cookies asked to stay for 400 days, the longest Chrome allows.
A cookie is a short line of text a website asks your browser to store. A cookie from the site you are reading is a first-party cookie. One set by another company's code on that page is a third-party cookie. Lou Montulli, who created cookies at Netscape in 1994, built them so that each site could read only its own notes. He told NPR that ad networks following people across sites was "a big violation of the spirit of cookies."
One article, or forty-six
The team repeated the visit on 46 articles across news, recipe, weather, reference and forum sites in the US, UK and India. The middle result was roughly 260 cookies per page, and nearly 90% of them came from parties other than the publisher. The outside cookies traced back to 305 distinct companies over the whole run.
The same names kept returning. Of the 47 sites that loaded, 38 carried a Google cookie that the site itself had not set. The Trade Desk appeared on 37. While a typical article loaded, identifiers drawn from those cookies were forwarded to around 55 other web domains. This is called cookie syncing: companies that never met you swap their private IDs for you and compare notes.
Why blocking third-party cookies does not settle it
Chrome has a setting to block third-party cookies. The researchers switched it on and reloaded the ten heaviest articles. The median fell from 379 cookies to 46. That looks like a fix.
It is only part of one. Ad companies' scripts run inside the page, so they can write cookies into the site's own jar. Those count as first-party. With blocking on, nine of the ten heaviest sites still held Google advertising cookies. IDs also kept moving inside the web addresses of requests, about 25 per article sent to about 17 other domains.
The lesson here is that a privacy control lives where the user can see it, while tracking lives where the page owner's code runs. A setting in the browser, or a banner on the page, governs one layer. The ad tags operate in another.
The banner is a weaker control than it looks
Most pages showed visitors no consent prompt at all. Viewed from India, just 8 of the 46 articles displayed one. The Guardian and the Financial Times were the only two that waited for a reply before setting cookies. AP News set its 618 with the question still on screen. Fandom set 359.
Regulators in Europe have acted on this. In December 2021, the French regulator CNIL penalised Google (€150 million) and Facebook (€60 million) because declining cookies took more clicks than accepting them. A further Google penalty of €325 million followed in September 2025, in part because ad cookies were harder to decline.
In India the picture differs. The 2023 data protection act is silent on cookies, and the researchers note that the bulk of its consent provisions only apply from May 2027. The Advertising Standards Council of India found in January 2025 that only 3 of the 50 most-visited sites met basic consent requirements.
Limits of the test
This was one run, from one place, on one day. Every page load triggers a fresh ad auction, so the researchers caution that totals can shift by tens of percent from one visit to the next. Six sites, including Reuters and the Daily Mail, blocked their browser. The results describe the sites tested, not the whole web.
Questions to put to your team
If your company runs a website with ads or marketing tags, you carry this risk even though you did not write the code. Ask these questions:
First, what does our site set before a visitor answers the banner, and who last measured it? Second, which outside scripts can write cookies under our own domain name? Third, how many partners do we list for consent, and can we name what each one does? Fourth, does our tag review cover the IDs sent in web addresses, or only cookies?
Montulli had the chance to block outside cookies when Netscape held about 80 percent of browsers. He passed, judging that the web's ad income depended on them. He said blocking them would have cost the web about 90% of its revenue, a figure he gives from memory. The test shows that decision still shapes what happens in a reader's browser before any question is answered.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: sheets.works.




