On June 18, the Council of the European Union quietly buried a proposal that would have done something almost every internet user claims to want: kill the cookie banner. The plan, part of the European Commission’s broader digital-rule modernization, would have shifted consent preferences to the browser level — set it once, forget it, no pop-up on every site you visit. The Council’s position paper scrapped it. No vote, no fanfare, just gone.
Privacy advocacy group noyb, which has spent years litigating against the banners, called the outcome “baffling.” The group noted that the very member states that posture as champions of cutting red tape — Germany and France among them — were the ones standing in the way. Billions of clicks per year, preserved.
The easy story here writes itself: Europe can’t get out of its own way. The regulatory machine that gave us GDPR now can’t undo its most visible, most loathed side effect. The bureaucrats who mandated consent cannot bring themselves to admit the consent mechanism is broken. It’s a satisfying narrative if your priors are that Brussels is a self-licking ice cream cone of rule-making.
But the easy story misses the money.
The Compliance-Industrial Complex
GDPR did not just create cookie banners. It created an entire industry whose revenue depends on those banners existing. Consent management platforms — CMPs — are now a multi-hundred-million-euro sector. Companies like Cookiebot, Usercentrics, and OneTrust built their European businesses on the proposition that navigating consent is too legally perilous to do yourself. Privacy consultancies staffed up. Law firms opened dedicated GDPR practices. Conference organizers filled hotel ballrooms in Brussels and Berlin with compliance officers hungry for CE credits.
A browser-level consent setting — the Commission’s proposal — would have been an extinction-level event for much of this ecosystem. If the browser handles consent, the website doesn’t need a CMP. If the website doesn’t need a CMP, a lot of subscription revenue evaporates. The threat wasn’t theoretical. It was existential.
“We spent three years building our consent pipeline to handle the edge cases most sites don’t even know they have,” one CMP account executive told me, between sessions at a privacy-tech conference in Brussels last month. “Browser-level consent solves the easy 80 percent. Our entire value proposition is the hard 20. If the easy part goes away, so does the foot in the door.”
Browser-Level Consent Was the Real Threat
The Commission’s proposal was elegant in its simplicity. Users would set their cookie preferences once in their browser settings — a yes/no for tracking, maybe a few granular toggles. Websites would be required to honor that preference for at least six months. No pop-ups, no dark patterns, no “legitimate interest” pretzel logic buried behind a second screen. The browser becomes the enforcement point.
For users, it would have been a genuine improvement. For the CMP industry, it would have been a disaster. The entire business model of a consent management platform is that consent must be collected at the site level, with all the friction and legal exposure that implies. Move consent upstream to the browser, and the CMP becomes a solution in search of a problem.
This is not a story about regulatory incompetence. It is a story about regulatory capture — not by the tech giants people love to hate, but by the mid-sized compliance vendors who have become quietly indispensable to the post-GDPR internet. They don’t have Google’s lobbying budget, but they have something more potent: a direct line to the data protection authorities and trade associations that shape Council working groups. They are the experts who get called when a ministry drafts a position paper. They are the stakeholders who show up to consultations.
Who Actually Called Brussels
The noyb report notes that the Council’s reversal came after “intense lobbying.” It doesn’t name names, but the contours are clear. The browser-based consent model threatened to disintermediate an entire layer of the ad-tech and compliance stack. The companies in that layer had every incentive to argue that browser consent would be insufficiently granular, that it would undermine user control, that it would create new security risks. These are the same arguments the industry has used for years to resist any simplification of the consent regime.
And they worked. The Council’s position paper doesn’t say “we listened to the CMP lobby.” It says the proposal needs “further study” and raises concerns about “technical feasibility” and “user autonomy.” Translated: the people who profit from the current system convinced enough member states that the current system, however annoying, is the least bad option.
The irony is thick. The cookie banner is universally despised. Users hate clicking through them. Publishers hate the bounce rates they cause. Even regulators privately admit the regime has failed its original purpose — meaningful consent is a fiction when everyone just jabs “accept all” to make the pop-up go away. And yet the banner survives, not because anyone loves it, but because killing it would disrupt a set of businesses that have grown dependent on its existence.
The Uncomfortable Lesson
If you are a right-of-center observer, the temptation is to file this under “regulation always fails.” But that lets too many people off the hook. The regulation didn’t fail on its own terms — it was captured. The GDPR created a market, the market created incumbents, and the incumbents defended their turf. That is not a story about government overreach. It is a story about how any sufficiently large regulatory framework will generate a constituency that profits from its complexity, and that constituency will fight simplification harder than any ideologue.
The cookie banner is not a bug in the GDPR. It is the GDPR working exactly as the compliance industry wants it to. The next time you jab “accept all” on a news site, remember: someone, somewhere, is billing by the hour to keep that button there.
Sources
- Why Europe Can’t Kill the Cookie Banner - Truth on the Market
- The EU wants to kill cookie banners
- E-book Privacy and marketing cookie consent in Europe (2026): what you should prepare for | iubenda
- How to Achieve EU Cookie Compliance: 2026 Guide - CookieYes
- EU Member States (and Google) suddenly want to keep …