Why free consent banners fail: TCF and Consent Mode v2

A banner isn't the same as being compliant
Conzent runs an automated check against company websites before we reach out to them. It just loads the site and watches what happens, nothing invasive. In one recent batch of sites that already had a cookie banner installed, about a third of them were still setting cookies before the visitor made any choice.
That's not a knock on those companies. Every one of them installed a banner because they wanted to be compliant. They just have no way to check whether it's actually working, because the failure doesn't show up on screen. The banner still pops up, still says the right things, and quietly does nothing behind the scenes.

This is the gap a free tool almost never closes: it can show you a banner, but it can't prove to Google, to ad networks, or to a regulator that the choice was actually respected.
What "actually compliant" requires
A properly compliant setup does two things at once. First, it speaks the ad industry's shared language, called the IAB Transparency and Consent Framework, or TCF. Think of TCF as a rulebook every ad company agreed to follow: when a visitor says yes or no, TCF records that choice in a format every one of those companies can read, so nobody has to guess.
Second, it tells Google specifically what the visitor chose, through Google Consent Mode v2. This is separate from TCF: it's Google's own channel to its own tools, like Google Ads and Analytics. Without it, your ad and analytics numbers get worse over time, because Google can't do anything useful with a signal it doesn't understand.
A free banner usually does neither of these properly. It remembers a click on your own site and stops there. Nothing tells the ad companies, and nothing tells Google. That's how you end up with a banner that looks fine while your data quietly breaks.

Why this keeps changing, and why that's the real work
Both standards move, and someone has to keep up. TCF moved to version 2.3 in 2025, and the ad industry has already moved again to version 2.4, which becomes mandatory for web banners on 23 October 2026. Google changed how Consent Mode works again in June 2026. None of this is a one-time setup. It's the actual reason free tools fall behind: nobody is tracking every change and shipping the update before the deadline.
Conzent already runs on TCF v2.4 today. As far as we've been able to check, we're ahead of the market on this: the major names in this space, including Cookiebot and Usercentrics, still show only the older 2.2 or 2.3 standard in their public material. That's exactly the kind of thing you shouldn't have to track yourself, and with Conzent, you don't have to.
What it costs to get this wrong
This isn't hypothetical. In September 2025, France's data protection regulator fined Shein 150 million euros, and Google 325 million euros, on the same day, for the same basic failure: cookies firing before visitors gave consent, and continuing to fire after they said no. Shein had a banner. It just didn't do what it claimed to.
If you have visitors in the US, the risk looks different but it's just as real. Twenty states now have their own privacy laws, and eleven of them require you to automatically honor a browser-level opt-out signal called Global Privacy Control. A banner that only remembers a click on your own site doesn't handle that either.


Why we built Conzent this way
Conzent is IAB TCF and Google certified, and we keep it current as those standards change, including the TCF v2.4 update most of the market hasn't caught up to yet. It's built on open source, so you're never locked into a platform you can't leave, and you can have a fully compliant banner live in minutes, no developer needed.
If you're currently on Cookiebot, Usercentrics, CookieYes, or something similar, the question worth asking isn't whether you have a banner. It's whether you can prove it's doing what it says. If you're not sure, that's worth checking before a regulator, or an ad platform, checks for you.
A banner that doesn't work is worse than no banner
Here's the part I feel strongly about. A site with no banner at all can be accused of not knowing better. A site with a banner that doesn't work has proven it knew consent was required, asked for it, and then ignored the answer anyway. Every "reject" click your own banner logged while cookies kept firing is a record working against you, not for you.
A cookie banner is a promise to your visitors. If your site breaks that promise on every page load, you haven't built compliance. You've built evidence.
Most of the sites in our check aren't being careless on purpose. They installed a banner, saw it appear, and reasonably assumed the job was done. That's exactly the problem: the failure is invisible to you and fully visible to everyone else, including a regulator's own automated checks.