This is the PPC Land weekly edition: one analysis that reads across everything published from Monday, September 21 to Sunday, September 27, rather than following a single day's news. It is written for and published only on PPC Land, an independent publication that has covered programmatic advertising and ad tech daily since 2016, with no sponsored coverage. The free daily newsletter, a curated digest of the previous 24 hours delivered each morning by email, is available through the PPC Land sign-up page. Readers who want that reporting to stay independent can become paying Supporters, a membership that adds ad-free reading and a private ad-free RSS feed. Reader memberships help fund the research, verification and writing behind every edition.
The week to September 27 produced a great many numbers about advertising. The ones likely to carry weight in a year arrived with a docket number attached, several of them made public in the days just before the week began.
On September 17, lawyers for The New York Times and a group of other publishers refiled a brief in Manhattan with most of its redactions lifted, and Microsoft's own measurements of what Copilot does to publisher traffic became public: click-through down by as much as 94 percent on some domains. On Friday, September 25, a jury in Santa Fe finished counting 43,899,720 violations of New Mexico's Unfair Practices Act across 26 statements Meta had made about data, hate speech and Cambridge Analytica since 2010. The same day, a circuit judge in Montgomery signed a consent decree fixing a 120-minute daily ceiling for Alabama teenagers on TikTok, and setting error tolerances for the company's age estimation to be met by named dates. On Monday, September 21, Ireland's Data Protection Commission priced 620 days of Google location processing at €403 million. And in Cologne, a regional chamber held that what a user types into Snapchat's chatbot is personal data that cannot steer ads without a legal basis, with a penalty of up to 250,000 euros for each future breach.
Every one of those figures has a date, a named forum and, in most cases, a party that spent money trying to keep it out of view. Adversarial process produced them, so they can be appealed but not quietly restated by the company they describe.
The numbers the industry published about itself over the same week look different. Google began a spam update on September 24 that may run until October 8, and said nothing about what it targets or how many queries it touches. Search Console started reporting camera searches and withheld the queries behind them. A Google research paper describing four cooperating AI agents that hunt synthetic YouTube networks left its evaluation section in the future tense. Meta appears to have removed a five-year-old limit on ads per Page without announcing it. OpenAI's $1 billion advertising run rate, the most-cited figure in conversational advertising, is OpenAI's own number, and the monthly revenue behind it has never been published by the company. Vendors released surveys with no sample size, benchmarks against conveniently chosen rivals and conversion uplifts with no baseline. And the two protocols competing to become the standard for AI buying agents were described by Adform's technology chief as carrying very little money.
That is not evidence of bad faith. Most of what the platforms published is probably accurate as far as it goes. The difficulty is that almost nothing they published could be tested by anyone outside them, and that the independent scrutiny advertising once expected from auditors, industry committees and verification vendors is increasingly arriving through discovery, verdict forms and consent decrees instead. That is a slow, expensive and partial substitute. Judges examine what litigants put in front of them, on timetables set by procedure rather than by markets, and a settlement can end a case without establishing anything at all.
The sections below follow that split: first the figures that institutions forced into the open, then the ones platforms and vendors asked the market to accept on trust, including the few places where somebody outside the seller is doing the counting.
Microsoft's own instruments, read into the public file
The combined brief was filed at docket 1977-1 in multidistrict litigation 25-md-3143, before Judge Sidney H. Stein in the Southern District of New York. The plaintiffs are The New York Times Company, eight Daily News titles including the Chicago Tribune and the Denver Post, Ziff Davis, the Center for Investigative Reporting and The Intercept; the defendants are OpenAI and Microsoft. The version refiled on September 17 carries substantially fewer redactions, and what it uncovers is internal telemetry rather than expert reconstruction.
Microsoft compared click-through rates on Bing web search with click-through rates in its Bing Chat product, domain by domain. For New York Times properties, clicks fell between 87 and 93 percent. For Daily News domains the range ran from 83 to 91 percent, and for Ziff Davis properties from 51 to 94 percent. A measurement vendor with a commercial interest in the result did not produce those figures. A platform produced them about its own product, and they reached the public only because litigation forced them into discovery and the redactions were later lifted.
The behavioural data in the same filing is equally blunt. The brief states that 87.78 percent of ChatGPT users visit no external website during a search session, against 26.91 percent for Google. A Microsoft survey found 37.2 percent of Copilot respondents would otherwise have used conventional web search. Cloudflare data cited by the plaintiffs puts OpenAI's crawl-to-referral ratio at roughly 1,500 pages scraped for every visitor sent back. Internal communications attributed to Nick Turley, who runs ChatGPT, describe the products as largely substitutive and likely to become more so; Satya Nadella is quoted from sworn testimony acknowledging that chatbots substitute for a visit to the underlying source. Substitution is the fourth statutory fair use factor, and Alan Chapell, a privacy specialist quoted in Digiday's reading of the unsealed papers, said an admission of that kind likely eviscerates the fair use defence.
OpenAI's counter-evidence is itself a rate. Its expert reviewed 20 million ChatGPT conversation logs and found 24 instances of verbatim regurgitation, or 0.00012 percent. The company also argues that copies made before publishers updated their robots.txt files were impliedly licensed. Both defendants moved for summary judgment on September 4; no hearing date has been set, and a pending sanctions motion has to be resolved before the grounding and output claims against OpenAI can be decided. One detail from the brief deserves its own line: after the suits were filed, OpenAI built a suppression mechanism, the Giraffe Bloom Filter, covering 140,097 Times copies and 270,250 Daily News copies. Suppressing output is not the same as removing what a model learned, and the plaintiffs use the filter as evidence that the underlying copies exist.
The day before the refiling, on September 16, the Ninth Circuit affirmed dismissal of a parallel set of claims against GitHub, Microsoft and OpenAI. In case 24-7700, Judges Sidney R. Thomas, Eric D. Miller and Stanley Blumenfeld Jr. held that Section 1202(b) of the Digital Millennium Copyright Act, which prohibits removing copyright management information, does not reach a system that generates new output through probabilistic processes. One who creates a new work and omits the notice, in the panel's reasoning, has not removed anything. The programmers bringing the case had conceded early that their complaint was not about training, so the court never decided whether stripping attribution during data preparation breaches the statute. That is precisely the theory the news publishers are running in New York, where they allege that copyright notices were absent from 99.9 percent of Times copies. The money explains the framing: Section 1203 damages run up to $25,000 per violation, a measure that multiplies across every output, against a statutory cap of $30,000 per work under Section 504. Two contract claims resting on open-source licence terms survive before Judge Jon S. Tigar.
A third route surfaced on September 26, when PPC Land reported that Anthropic had lost its bid to keep Reddit's scraping claims in federal court. The order in case 3:25-cv-05643-TLT dates from March: Judge Trina L. Thompson of the Northern District of California signed it on Saturday, March 28, 2026, and it was entered two days later, sending the case back to San Francisco County Superior Court. All five of Reddit's claims return to state court intact: breach of contract, unjust enrichment, trespass to chattels, tortious interference with contract and unfair competition under Section 17200 of California's Business and Professions Code. The judge found none of them preempted by copyright law, because each carries an extra element, whether contractual restrictions on how and why a site may be accessed, technical trespass or server impairment. Reddit alleges more than 100,000 automated accesses after a July 2024 denial by Anthropic, and points to Section 7 of its User Agreement, which folds robots.txt compliance into the contract. Fair use, the defence at the centre of the AI copyright cases, does not answer a breach of contract claim.
Read together, the three proceedings mark out the terrain. Output-based claims under the DMCA have failed on appeal. Input-based claims about what happened to notices during data preparation remain open. And claims built on the terms under which a site was accessed, rather than on copyright at all, are proceeding in a state forum where fair use is not a defence. For anyone licensing or scraping text at scale, the operative documents are now the discovery record, the extraction pipeline and the site's terms of service.
The same week produced a reminder that the exposure is not confined to model builders. Copyright Clearance Center and Outsell surveyed 570 full-time knowledge workers at companies with more than 1,000 employees between April 10 and May 8, 2026, and found that staff feed externally published content into AI tools 11 times a week, with each output reaching an average of 96 people. Executives reported 111 potential unlicensed sharing instances a week, six times the rate of individual contributors, and 76 percent said they override policy when time is short. The margin of error is plus or minus 4.0 percent overall. The conflict is worth stating plainly: CCC approved the questionnaire and sells the licences the report discusses. The numbers may well be right. They are also the numbers a licensing business would hope to find.
Santa Fe counts 43,899,720 violations
The case is D-101-CV-2021-00132, State of New Mexico v. Meta Platforms, Inc., in the First Judicial District Court for the County of Santa Fe. It was filed in 2021 by then Attorney General Hector Balderas and tried by his successor, Raúl Torrez. Jury selection began on September 8, 2026, closing arguments followed on September 23, and the verdict arrived on September 25.
Jurors examined 29 statements and found 26 of them willfully deceptive. The arithmetic behind the headline figure is simple. Eleven statements distributed through major news outlets drew 2,100,000 violations each. Fifteen published through Facebook's own channels drew 1,386,648 each. Multiplied and added, the total is exactly 43,899,720. New Mexico's statute allows up to $5,000 per willful violation, which puts the theoretical ceiling near $219.5 billion. Judge Francis Mathew will set the actual sum, and Torrez has said his office will seek the maximum.
The verdict form's structure says more than the total. Its first part, on data control, placed all six statements in the deceptive column, worth 10,459,944 violations. Among them was Mark Zuckerberg's line in the Washington Post on May 24, 2010 that Facebook does not and never will sell user information, and a January 24, 2019 post from Sheryl Sandberg stating that the company does not share personal information with advertisers without permission. The fifth part, covering the promises to audit third-party apps after Cambridge Analytica and notify affected users, found all ten statements deceptive and accounted for 18,146,592 violations, or 41.3 percent of the total. Zuckerberg authored 14 of the 29 statements examined, accounting for 55.6 percent of the violations found.
For advertising, that first part is the section that matters. The claims the jury rejected are the ones on which targeted advertising has been publicly defended for fifteen years: that personal data is not sold, and that advertisers do not receive personal information without permission. The legal question turned on the distinction between selling data and selling access to the people the data describes. That distinction has always been clear to the industry and never intuitive to the public, and a jury declined to treat it as a defence. None of the underlying processing was secret; it was described in policies, justified under consent and legitimate interest frameworks and examined by regulators. What the jury weighed was the gap between that machinery and the sentences used to describe it.
Meta's spokesperson Alex Burgos said the company disagreed and would continue to defend itself. Its exposure in New Mexico is already layered: the company has posted a $1.8 billion bond while appealing earlier judgments, and a separate child safety verdict in March produced a $567 million abatement order. The point for the measurement argument running through this edition is timing. Each of the 26 statements was true or false on the day it was published, and nobody outside the company could check it then. The check arrived between five and sixteen years later, from a jury in a state district court, at a cost to the state of five years of litigation.
Alabama writes a specification, and Los Angeles refuses a trade
Circuit Judge Monet M. Gaines signed the Alabama consent decree in State of Alabama ex rel. Steve Marshall v. TikTok Inc., case 03-CV-2025-900628.00 in Montgomery County Circuit Court, three days before a jury was due to hear the case on September 28. Alabama had sued in April 2025 over addictive design, exposure to harmful material and misrepresentation of safety, and TikTok's motion to dismiss on Section 230 and COPPA grounds will now never be decided. PPC Land set out the terms on September 26.
The guaranteed money is $116.2 million: $14.2 million of fees and costs due by October 25, 2026, and $100 million of restitution due by November 9. Behind it sits a contingent $183.8 million, released in four tranches as other states sign substantively equivalent agreements: $55.14 million at ten states, the same again at twenty, then $36.76 million at thirty and at forty. A most-favoured-nation clause adds up to 1.55 percent of any recovery above $5.1 billion that other states extract from Meta, excluding Texas, Florida and New Mexico.
What distinguishes the decree from a fine is that it writes product behaviour down as numbers that can be tested against a phone. Alabama users with a predicted or stated age of 13 to 17 get a default daily maximum of 120 minutes, resetting at midnight, with search, messaging, settings and videos of at least ten minutes excluded from the count. A night mode blocks the app from midnight to 6am device time. Push notifications go dark from 10pm to 7am, and school-hours notifications stop between 8am and 3pm on weekdays. Pauses must appear at 60 and 90 cumulative minutes by January 25, 2027. Cosmetic surgery filters come off teen accounts by March 24, 2027. By June 25, 2027, TikTok must offer Alabama teens a feed ranked chronologically, by general popularity or by other neutral criteria, and prompt every new teen account to choose within ten days without preselecting either answer.
The accuracy provisions are the part that will interest anyone who buys audiences. By September 25, 2027, TikTok's age assurance must hold false positives to 14 percent in the 16 to 17 band and 7 percent in the 13 to 15 band; a year later the thresholds tighten to 10 and 5 percent. Compliance is self-certified against internal testing unless 40 or more attorneys general sign equivalent terms, at which point an independent auditor takes over. An under-13 detection prototype is due by March 25, 2027, and data from under-13 accounts may not feed ad targeting, marketing or algorithmic optimisation. TikTok has now accepted published error rates, a deadline and an enforcement path for its age signals.
The drafting is inconsistent in places. The attorney general's announcement described pauses at 15, 60 and 90 minutes while the decree specifies 60 and 90; the feed is called a default in the press release and an option in the text; and paragraph 3.2 runs teen educational tools to September 2033 while the decree's term expires in September 2031. The architecture is borrowed from the Meta consent judgment of August 26, 2026, which tied a $5.02 billion contingency to whether rivals adopted equivalent rules. Alabama inverted it: TikTok's contingent money depends on TikTok signing with more states, and a further tier of restrictions only switches on once Meta, Snap and YouTube are all bound.
In Los Angeles, the same company met a judge who signalled he would not treat a court order as a bargaining chip. On September 18, Judge George H. Wu issued a sixteen-page tentative ruling indicating he would deny the Justice Department's motion to vacate the 2019 children's privacy consent order against Musical.ly, the service that became TikTok, ahead of a hearing on the morning of September 21 in case 2:19-cv-01439-GW-RAO. The government had announced a $400 million settlement on August 21, 2026, in its separate COPPA action, with $300 million payable immediately and $100 million contingent on the court vacating the March 27, 2019 order that Judge Otis D. Wright II had entered alongside a $5.7 million penalty.
Wu's reasoning was that the parties may write whatever conditions they like into a settlement, but those conditions cannot displace the court's own obligation to decide whether vacatur is warranted. He rejected the idea that an unopposed motion earns deference, found that COPPA applies regardless of whether the operator is foreign or domestically owned, and distinguished a promise to comply from demonstrated compliance, citing a July 31, 2026 decision in United States v. Lakeland Bank. A declaration from a TikTok US employee describing current controls did not close the gap. The proposed denial would be without prejudice, leaving the government free to return with evidence of actual compliance; the week's coverage did not report a final order. What the government cannot do, on this reading, is buy the release of an injunction for a quarter of a settlement.
The two documents, a week apart, sit at either end of one problem. In Montgomery, a state fixed numbers that a court can later check. In Los Angeles, a federal judge indicated he would refuse to let $100 million stand in for the check.
Dublin, Cologne and a Council text that moves in the other direction
Seven years and ten months separate the complaint from the penalty. On November 27, 2018, consumer organisations in seven countries, coordinated by BEUC and working from the Norwegian Consumer Council's report on deceptive location settings, filed coordinated grievances about how Google collected location data on Android phones. On September 21, 2026, Ireland's Data Protection Commission fined Google Ireland Limited €403 million and gave it six months to change the processing.
The decision covers 620 days, from May 25, 2018, when the General Data Protection Regulation took effect, to February 4, 2020, when the DPC opened its own-volition inquiry. Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney found four infringements across three features: Web and App Activity, Location History and Location Accuracy. The third was not named in the original complaints at all, and the DPC found against it anyway, using precisely the latitude an own-volition inquiry confers. Deputy Commissioner Graham Doyle framed the harm in commercial terms: users may not have known their location was being used to show them advertising or infer their interests. Google's position is that the case concerns historical policies since changed, pointing to auto-delete cycles and on-device storage for Maps Timeline introduced from 2019 onward.
For advertisers, the retention finding is the operative one. Google's store visit conversions, available in 36 countries, model footfall partly by observing signed-in users with Location History enabled, and storage limitation bears directly on that modelling. The fine itself, roughly $463 million, is about 0.1 percent of Alphabet's 2025 revenue and the DPC's fourth-largest penalty. Collection is another question. An Alliance Risk analysis from May 2026 found nearly 40 percent of the €7.1 billion in GDPR fines issued since 2018 annulled or still under challenge, and noyb has reported that only 0.6 percent of Irish fines against major companies had actually been paid. BEUC's director general Agustín Reyna welcomed the decision while noting that the time taken was out of proportion to the seriousness of the infringement.
Four days earlier, and with far less attention outside Germany, the 33rd Civil Chamber of the Regional Court of Cologne had granted the Verbraucherzentrale Bundesverband an injunction in full against Snap Group Limited. PPC Land reported the judgment on September 26. Case 33 O 120/24 had been running since a warning letter of October 24, 2023. Snap may no longer process personal data from conversations with its chatbot for advertising without a legal basis, may not use pre-ticked boxes in ad preferences, and may not preset alcohol and gambling as interest topics in minors' accounts. Each breach carries up to 250,000 euros or coercive detention of up to six months against board members.
The reasoning travels further than the remedy. Snap argued that its London entity collected nothing and that processing belonged to the US parent. The chamber looked instead at the German terms of service, where Snap Group Limited reserved processing rights, and at evidence that text queries typed into the chatbot are processed for ad selection, and concluded that the London company was at minimum a joint controller. On the chatbot, the court held that Article 9's protection for special-category data attaches because users disclose sensitive material to conversational interfaces, whatever the operator intends to infer. Intent does not govern; content does. For every company now selling advertising alongside a chat window, that is a finding with obvious reach.
While enforcers in Dublin and Cologne were applying the 2018 rulebook, the rulebook itself was being rewritten in Brussels. Council working text 12535/26, dated September 3, marked LIMITE and published by noyb on September 21, runs to 158 pages of compromise on the Digital Omnibus. Its Article 88 bis would permit processing personal data for developing and operating AI systems on the basis of legitimate interest, and it strips out the Commission's proposed safeguards, including an unconditional right to object. Recital 31, which referenced respecting technical signals limiting the use of data for AI development, was deleted outright; those are the machine-readable signals publishers use against crawlers. Germany's written comments, reference WK 11020/2026 ADD 4 of August 17, would go further and presume a legitimate interest for training. Max Schrems of noyb described the text as a digital expropriation of Europeans.
Two further changes in the same draft bear on advertising operations. A rewritten Article 5(3) of the ePrivacy Directive would exempt contextual advertising measurement from consent where it relies solely on the content of a single page or query, with no profiling, retention or link to past activity. Recital 44f then names frequency capping cookies as an example, although counting prior impressions is exactly a link to past activity. The contradiction has not been resolved. The draft also builds a new Article 25a under which pseudonymised data is not personal data for a party unable to identify the person, tracking the Court of Justice's September 2025 judgment in EDPS v Single Resolution Board. The European Data Protection Board's consultation on anonymisation guidelines closes on October 30, 2026. Separately, in comments reported by PPC Land on September 26, Osborne Clarke partner Peter Craddock argued that the Board's own 33 comments on anonymising Google Search data, dated May 5 and published only in September, accept contract-based anonymisation that sits awkwardly beside those guidelines.
The United Kingdom supplied its own version of the tension. On September 25, PPC Land reported that Privacy International had asked the government to prohibit five uses of AI, among them sentiment analysis that infers emotional states from personal data, behavioural prediction of crime or security threats, and live biometric identification. The charity's argument is that Section 80 of the Data (Use and Access) Act 2025, which received Royal Assent on June 19, 2025, replaced Article 22 of the UK GDPR with Articles 22A to 22D and shifted the burden of challenging automated decisions onto individuals. The Department for Science, Innovation and Technology closed its call for evidence on September 9 and has published no date for a response.
Taken together, the European items point in two directions at once. A regulator spent six years and seven months establishing that a company kept data it should not have kept. A civil chamber took nearly three years to establish that chatbot text is personal data when it steers ads. And a Council working party drafted the conditions under which the next round of collection would be lawful by default, with the objection right removed from the operative text.
Settlements put a price on things, which is not the same as a finding
Not every legal proceeding reported this week produced a number that establishes anything. On September 16, the Competition Appeal Tribunal approved a collective settlement of 260 million pounds between Professor Barry Rodger of the University of Strathclyde, acting as class representative, and seven Alphabet and Google entities. Case 1673/7/7/24 was twelve days from a ten-week trial listed for September 28. That trial will not happen, and the tribunal made no finding on whether Google's Play Store commission structure breached competition law. Clause 10 of the agreement records that it is not an admission of liability and may not be relied on as evidence of any allegation.
The money divides in two. A class pot of 160 million pounds goes to eligible UK app developers for the period from August 22, 2018 to July 31, 2026, with developers whose Play revenue was 7,500 pounds or less able to take a fixed 200 pounds instead. A stakeholder pot of 100 million pounds covers the funder, insurers and lawyers, and the funder's contract shows what the timing was worth: Bench Walk Guernsey's return was tiered, with a higher multiple payable if proceeds arrived after the liability trial began, so settling before September 28 kept the claim in the lower tier. The administrator, Angeion Group, projects take-up of 50 to 80 percent by value and only 8 to 15 percent by number of eligible developers. Commission rates and billing rules are untouched. The proceeding the advertising industry should watch is a different one: an opt-out claim of roughly 5 billion pounds on behalf of UK advertisers who bought Google search ads between 2011 and 2025, certified by the same tribunal on August 5, 2026.
A settlement of a different kind closed the antitrust challenge to Paramount Skydance's acquisition of Warner Bros. Discovery. AdExchanger's Tuesday roundup reported that California and eleven other states settled in exchange for a commitment to release 30 films theatrically each year and spend an additional $1.5 billion on film production over five years, with the combined company carrying more than $80 billion in debt. Adweek added that the terms require no forced sale of cable networks and create an independent board to protect editorial independence at CNN and CBS News. The states obtained behavioural commitments; no court tested whether the merger harms competition in television advertising, where the combined group will now negotiate as one seller.
Regulators, meanwhile, are writing numbers of their own into product design. On September 23, the UK Competition and Markets Authority published a 71-page revised consultation that would require Google to show Android and Chrome users a choice screen of up to twelve search providers: the five most popular plus seven drawn at random from the eligible pool, in fully randomised order, with users required to scroll the whole list before confirming. A selection would earn a trial period of at least a week, followed by a confirmation screen, and the choice would be offered again once a year tied to a major Android or Chrome update. Responses are due by 5pm on October 9. Search Engine Roundtable reported the proposals the same morning.
The regulator costed the intervention to the penny. A typical screen is assumed to take 25 seconds, valued at five pence of user time using the Department for Transport's figure of £7.21 an hour for non-working time. Google's implementation costs are put at £5 million to £20 million over five years, against UK search advertising revenue of £10 billion to £20 billion in 2024. The consequential change from January is eligibility: the requirement that a service treat general search as a core part of what it does has been deleted, which would open the screen to AI assistants for the first time anywhere. In its place sits a criterion that publishers will read closely. Where a service produces AI summaries, it must attribute content clearly and accurately, with clear routes to the source material, and its error rate cannot be significant. The evidence behind the design is contested. A field experiment by Allcott and co-authors found 1.1 percent of users moved from Google to Bing after an active choice; Google's own commissioned research concluded the median user would need 39 pounds a month to give up its search engine, a figure drawn from between 20 and 30 participants against Mozilla's 12,000.
Across the Atlantic, the Federal Trade Commission opened a question that platforms have long preferred to answer themselves. On September 24, MediaPost reported that the agency had issued an advance notice of proposed rulemakingon the role of advertising platforms in impersonation scams. The options under consideration include verifying an advertiser's identity before granting access to optimisation tools, requiring platforms to screen and monitor for impersonation ads, and making platforms bear the costs when their systems optimise fraudulent campaigns. The notice cited Reuters reporting that Meta had projected roughly $16 billion, about 10 percent of its 2024 revenue, from scam, illegal gambling and banned-goods advertising. Christopher Mufarrige, director of the Bureau of Consumer Protection, said impersonation scams are no longer the work of isolated con artists. No comment deadline was given. If a rule follows, platform self-reporting on ad fraud would acquire an external standard for the first time.
The reception of the Google ad tech remedies showed how far publishers discount a legal win against practical effect. Seven executives polled by Digiday scored the package five out of ten overall, rating header bidding traffic management highest at seven and data portability and the unbundling of AdX from the publisher ad server lowest at four. AdExchanger's publisher reporting reached the same verdict in its headline: too little, too late, and accepted anyway. A remedy is an instruction about future conduct. Whether it changes the numbers publishers see depends on implementation timetables of twelve and fifteen months, and on who checks compliance once the courtroom attention fades.
Google's week of withheld figures
The announcement was terse even by recent standards. Google's Search Status Dashboard logged the September 2026 spam update at 09:15 Pacific on Thursday, September 24, applying globally and to all languages, and Barry Schwartz reported the release within minutes with the dashboard's warning intact: "The rollout may take up to two weeks to complete." There was no blog post, no new policy, no description of targets and no share of affected queries. The update could still be moving on October 8.
The duration is the most concrete fact available, and it has been stretching all year. The March update finished in 19.5 hours. June's took two days. August's ran three. September's opening estimate is roughly five times August's actual duration and seventeen times March's. John Mueller has explained long core update rollouts by saying several ranking components are updated step by step, which, applied here, suggests the release bundles more than one enforcement change. Google has not said so. The policies being enforced are already on the books: expired domain abuse, scaled content abuse, site reputation abuse, doorway abuse, back button hijacking and fake or undisclosed incentivised reviews, all acted on algorithmically through SpamBrain rather than through manual actions visible in Search Console.
One of those policies now works differently depending on where the searcher sits. On August 30, Google stopped applying site reputation abuse manual actions to users in the European Economic Area after pressure from Brussels. The September update is the first confirmed ranking release since that carve-out. The update itself acts algorithmically, but the manual route that sits beside it now stops at the EEA border, so a site hosting third-party content on a strong domain can face different enforcement in Frankfurt and in Chicago.
Volatility arrived before the confirmation. Schwartz documented elevated movement from around September 22, registered by more than a dozen tracking tools, and site operators described Discover traffic down 70 percent and overall declines between 48 and 80 percent. Whether those reports reflect the update, the swings that preceded it or seasonal noise cannot be established from outside, and establishing it from inside has become harder. The generative AI performance report Google rolled out to every Search Console property on August 31 shows impressions but not clicks or queries. Third-party rank tracking has repriced: Google's passthrough links and the removal of the num=100 parameter mean trackers now issue between 500 and 1,000 requests to build five pages of results for a single query. So the longest spam rollout of the year arrives when the tools for observing it cost the most and show the least.
Hours before the update, Google split Search Console's Performance report so that multimodal searches sit in their own bucket: Google Lens, Circle to Search, images uploaded directly into Search and Chrome's option to search an image. The documentation states plainly that specific query data is not available for this traffic. Site owners can see which pages appeared and how often, but not what the camera was pointed at or what was asked. Google also confirmed that this traffic was never previously included in Search Console totals, so any site with meaningful camera-search visibility will show a step change in impressions dated to late September 2026 that reflects a reporting change rather than a change in demand, with no backfill. Schwartz logged the new search type filter as it appeared in the interface.
A second Google system aimed at synthetic content surfaced on September 25, and the manner of its disclosure is the point. A three-page research paper by seven Google authors describes SAFE, the Scaled Abuse Forensics Examiner, in which four cooperating AI agents investigate networks of YouTube channels producing low-quality synthetic video. The abstract claims that early deployment results show SAFE significantly accelerating the identification of new threats compared with human-in-the-loop workflows. Section IV, headed Evaluation and Impact, is written entirely in the future tense, listing the metrics that will be used. There are no accuracy figures, no recall figures and no false-positive analysis. Embedded metadata dates the paper's creation to May 28, 2026, before both the August and September spam updates, and every reference concerns YouTube rather than web search.
Advertisers have reason to want the missing numbers. A TAG and ANA analysis published on July 28, 2026 found synthetic inventory graded premium 70 percent of the time, with an invalid traffic rate of 0.05 percent against 0.32 percent for ordinary supply: machine-generated pages do not attract the bots that would flag a bad domain. Verification tooling is calibrated to detect fraud and unsafe context, not authorship. YouTube's own answer on the supply side is a monetisation threshold that doubles to 8,000 watch hours from February 1, 2027.
The same week showed how quickly a generative surface without an indexing policy is found. Public Gemini Notebook pages are indexable, and spammers noticed. Glenn Gabe put the number at up to 12,000 indexed URLs on September 22, filled with peptides, discount codes, pornography and app promotion, a pattern Gagan Ghotra had flagged first. It is the same failure that produced made-for-advertising inventory in programmatic: a cheap, permissionless publishing surface attached to a distribution system that rewards volume, with enforcement arriving after the arbitrage has been priced in. The detection of that particular problem came, as it often does, from individual practitioners posting screenshots rather than from any system Google has described.
Defaults switched on for merchants and publishers, without asking them
In March, a merchant who wanted to sell inside Google's AI answers had to apply. A help page published on March 2, 2026 set out the queue: add a native_commerce attribute to the product feed, confirm the payment provider could accept a Google Pay token, check United States eligibility, then submit an interest form and wait. On September 22, Shopify merchants received emails telling them the queue had been skipped on their behalf. Their stores had been matched to Merchant Center, native checkout was enabled in AI Mode and Gemini, and eligible products were included automatically. Search Engine Roundtable documented the notices after merchants posted screenshots; the broader rollout had begun on Friday, September 18. Merchants who would rather keep the transaction on their own domain have to switch the feature off by hand in the Shopify admin, under the agentic sales channel.
The adoption data suggests why. Google announced the Universal Commerce Protocol on January 11, 2026, and brought Shopping ads into AI Mode on February 11, when the surface was said to have passed 75 million daily users. A study published on May 21 scanned more than three million websites and found 26 with a publicly detectable implementation, none of them the retailers and payment firms whose logos accompanied the launch. Automatic enablement removes the merchant from the decision. The buyer transacts on Google's surface with Google Pay credentials, and the merchant receives an order rather than a session, which changes the economics for any business that relies on landing a visitor and then working the basket. Merchant Center also restated its store rating thresholds of at least 100 eligible reviews and an average of 3.5 out of 5 over a rolling 24-month window. From September 27, EU Implementing Regulation 2025/1960 requires sellers to display a harmonised legal guarantee notice on product pages and at checkout, an obligation that assumes a page the shopper looks at before paying. Native checkout inside a conversational answer does not obviously contain one, and the US-only scope of Google's rollout defers the collision rather than resolving it.
The link out of an answer is being renegotiated in the same direction. On September 21, Gagan Ghotra posted a test in which the links at the foot of an AI Overview lead into AI Mode with follow-up questions attached, rather than to a web page. Two days earlier PPC Land had documented a Discover test button routing readers to an AI summary rather than the publisher. Both are tests. Both point the same way: the citation stays, the destination changes.
Against that, one measurement firm reported a change in the other direction. Malte Landwehr of Peec AI posted tracking data showing that external links, previously present in close to zero percent of AI Overviews, now appear in more than 25 percent of them; Schwartz disclosed a small personal investment in the company when covering it. A randomised study earlier this year had put the click loss from AI Overviews at 39.8 percent. The two movements can coexist, and the CMA's proposed attribution criterion would turn the second from a product decision into an obligation for any service seeking a place on a British choice screen. A quarter of AI Overviews carrying an external link is a figure that can be measured again in six months. Whether Google will publish it is another matter.
What answer engines cite has shifted too. Digiday assembled data on September 23 from several trackers that agree with one another. A Meltwater analysis of August 2026 across eight systems, from Claude and ChatGPT to AI Mode, Perplexity and Grok, ranked YouTube as the most-cited platform, displacing Reddit. Tinuiti's second-quarter report, produced with Profound, found YouTube citations in AI Mode more than quadrupled between January and April. OtterlyAI data put 94 percent of YouTube citations on long-form video, with Shorts at 5.7 percent. And Scrunch, tracking sponsored YouTube videos between May and July, recorded the citation rate falling from 18.4 percent to 10.5 percent within a single month. A metric that nearly halves in four weeks is a signal of volatility, not yet a planning input. Transcripts, chapters, descriptions and comments make a video machine-readable in a way that a rendered web page increasingly is not, and the file sits on infrastructure Google's own systems reach without negotiating a crawl.
The vendors measuring this surface have their own credibility problem, set out in PPC Land's coverage this week. Scrunch, a Sitecore company that sells AI search visibility, analysed about 10,000 URLs cited by AI assistants between May 17 and June 30 and reported that brands publishing self-ranked listicles saw their recommendation rate rise from 4 to 7 percent and their mention rate from 19 to 39 percent when the list was cited. The caveats are in the study itself. A looser test comparing vendors' rates on their own lists against elsewhere found a median effect of 0.0 percentage points with a p-value of 0.62. The mention effect has not been through the falsification test. Only one of four rival scenarios survived, without correction for multiple comparisons. And in 24.3 percent of responses citing a self-ranked list, the assistant recommended a competitor instead of the author.
Adthena supplied a sharper example on September 25. Its September report found that one- and two-word queries now drive 62.9 percent of US AI Overview ad appearances, across 288.6 million appearances, with 3.7 percent for five- and six-word queries. In April, the same firm had reported that three- and four-word queries drove more than 60 percent, a finding its June report confirmed at 57.4 to 71.2 percent. The September report describes the shift as a change since June rather than a correction, and does not say whether Google changed which queries trigger ads, whether query composition changed, or whether Adthena changed its method. Three reports, two opposite conclusions and no explanation: that is the state of independent measurement on the surface where search advertising is being rebuilt.
Budget prompts, locked targets and a missed call that costs money
Google Ads acquired two new ways to spend more this week and one new warning about spending less. Hana Kobzová spotted, and Schwartz reported on September 24, that the Recommended Investment Strategy now offers a Holistic mode and a Growth mode. Holistic moves budget out of underperforming campaigns into top performers and adds incremental weekly spend on top; Growth leaves existing budgets alone and adds new money only to campaigns flagged as constrained. Forecasts rest on seven-day projections, and target CPA and target ROAS values are adjusted alongside the budget. Neither mode presents a variant in which the recommended action is to spend less.
The same day, Thomas Eccel described a new alert that appears when an advertiser lowers a daily budget, showing a projected fall in weekly conversion value and a prompt to spend more, which he called intrusive. Read together, the interface packages upward movement as a strategy with named modes and downward movement as a warning, with no confidence interval on either forecast. An advertiser who accepts a Growth recommendation and sees conversions rise has no counterfactual. One who cuts the budget instead gets an alert icon.
A third change removed a lever outright. Arpan Banerjee spotted, and Adrian Dekker shared, that Google Ads now blocks edits to target ROAS while promotion mode is active. ROAS tolerance remains editable. During a promotion, then, the efficiency target is read-only and the band around it is the only control left.
Local advertisers faced the most direct cost. For most of September, Google's own paid local formats sent calls to numbers advertisers had not chosen: Anthony Higman raised the problem on September 1, escalated it on September 9, and reported the issue resolved only by late September. Accounts with verified call assets were showing the Business Profile number instead, breaking call attribution. That would be an annoyance in most formats. In Local Services Ads it is about to become a billing question, because from October 1 unanswered calls become chargeable leads when a caller stays on the line for more than 20 seconds during business hours. Where a phone system requires a key press, the timer starts only after the press, and follow-up calls within 15 days of an unqualified first contact can also be charged. Voicemail handling, dispute procedures and spam safeguards remained undefined when PPC Land reported the change on September 25, and accounts outside the United States move in 2027.
On the free local surfaces, verification tightened. Hiroko Imai spotted edits to Google's help pages stating that posts with unverified contact information, including phone numbers, email addresses and social handles, may be removed to avoid fraud or abuse. Business Profile owners now have four days to accept or reject user-suggested edits before Google may publish them. And on the publisher side, Google dropped the AdSense identity verification threshold from $10 to zero, so that a government photo ID now gates ad serving from the first impression, with a video selfie required in some locations. A Wayback Machine capture from September 8 preserves the old figure; the documentation dates the change to June. Google has not said how many accounts sat below the old line.
Across these changes, advertisers and publishers are asked to verify their numbers, their identities and their contact details to Google's standard. The standard Google applies to its own forecasts, its own call routing and its own billing triggers is described in help pages, often adjusted without notice and usually discovered by practitioners.
Meta changes the rules, and others find out from the results
A limit that has shaped Meta account structure for more than five years may be lifting without a word from the company. Around September 22, Bram Van der Hallen, a digital marketer at Edge.be, posted evidence that an account spending under $100,000 a month was running 286 active ads against a documented ceiling of 250. The interface displayed a notice that the account was 36 ads over the limit; the ads kept delivering, and a separate message stated there was no longer a cap on ads per Page. Meta introduced the tiered limits in February 2021, with ceilings of 250, 1,000, 5,000 and 20,000 ads by monthly spend bracket, on the reasoning that four in ten ads were never leaving the learning phase because conversions were spread too thinly.
The logic has changed since. Meta dropped its recommendation of six creatives per ad set in July 2025, more than 15 million ads were being created in a single month with its generative tools by November 2025, and Advantage+ campaigns had passed $75 billion in annualised revenue by 2026. A ceiling designed for hand-built ads fits awkwardly with a system that manufactures variants at that rate. What is missing is everything that would let an agency plan around the change: whether it reaches all four tiers, whether the Marketing API still enforces the old limits, and whether it is a rollout or a test. Agencies built naming conventions, reporting structures and cleanup routines around the tiers, and the only notice of the change so far is a LinkedIn post.
A UK publisher found out about a different Meta change from its own accounts. Digitalbox, the listed owner of Entertainment Daily, The Tab and The Daily Mash, released half-year results on September 23 and attributed a sharp decline to a Facebook algorithm change that Meta never announced. Chief executive James Carter dated it to April 2 or 3, 2026. Distribution of creator-led video to non-followers collapsed while reach among existing followers held, and in some cases Facebook reach fell 75 percent. Revenue fell 7 percent to £1.706 million; adjusted EBITDA swung from a £289,000 profit to a £43,000 loss; an impairment of £634,000 was booked, £614,000 of it against Entertainment goodwill, citing social algorithm changes and the displacement of search referrals by AI-generated results. Website audience fell 28 percent while revenue per session rose 20 percent. The company's answer is a network of more than 200 creators targeting 500 videos a month.
The significance lies less in the size of the loss than in how the evidence surfaced. A company with £1.7 million of half-year revenue was able to date a platform change to a 48-hour window and quantify it in its half-year accounts five months later, because no other public record of the change exists.
Meta also loosened one tie between its own products. From September 26, MediaPost reported, advertisers can run Threads campaigns without an Instagram account and use a different profile name on each service, with Threads at about 500 million users. And its newest consumer product ran into a platform that set terms of its own. Meta launched Muse, an AI shopping agent, on September 8. Amazon asked Meta to remove Amazon from the agent's reach, Meta declined, and Amazon blocked Muse from its store, telling shoppers that continued access by an unauthorised agent breached its conditions of use. MediaPost's account adds Amazon's complaint that Muse captured customers' credentials without identifying itself and bypassed Amazon's personalisation. AdExchanger's Wednesday roundup carried a report that some of Muse's phone calls were placed by humans in a call centre, a detail that sits oddly with the product's description as an autonomous agent.
Digiday's analysis on September 25 put numbers on why advertising inside Muse looks likely: 730,000 US downloads in five days, revenue so far limited to $20 and $100 monthly tiers plus merchant fees, and 2026 AI capital expenditure of $135 billion to $145 billion that had absorbed 98 percent of Meta's operating cash flow by the second quarter. An agent that negotiates between shoppers and retailers is a sales channel whose ranking logic no retailer can see. Amazon's stated objections were narrower: unauthorised access, credential capture and bypassed personalisation.
There was one counterexample during the week, and it came from a smaller platform. X's published configuration for its main recommendation feed assigns copy-link shares a weight of 20.0 against 0.5 for likes, 5.0 for replies, quotes and direct message shares, 1.0 for reposts and minus 234.0 for reports, with a note that weights multiply predicted probabilities rather than raw counts. Publishing a ranking file does not make a feed fair. It does make the claim checkable, which is more than Meta offered anyone this week.
OpenAI's billion, in OpenAI's own figures
The most-quoted number in conversational advertising was restated through the week, and every restatement traced back to the same source. On August 31, OpenAI said advertising inside ChatGPT had reached a $1 billion annualised revenue run rate, and David Dugan, the former Meta agency executive who leads its global ads solutions team, wrote that the threshold arrived less than 200 days after launch. PPC Land's reconstruction on September 25 set out what the claim does and does not contain. A run rate projects one period across twelve months; Digiday derived the figure from monthly revenue of roughly $83 million multiplied by twelve, but neither OpenAI nor Dugan has published a monthly number. The pilot began on February 9, which makes August 31 the 203rd day after launch, so the under-200-days claim holds only if the threshold was crossed several days before the announcement, and nothing dates that moment.
Growth came from volume, not price. The pilot opened at a $60 CPM with a $200,000 minimum commitment; CPMs had fallen to as low as $25 by mid-April, and the minimum disappeared for US businesses in May. Sensor Tower estimated that ads shown per user per hour on the US mobile app rose 163 percent between April and August. The footprint went from one country in early April to 63 listed on OpenAI's Ads Manager availability page by September 24, after seven Asian markets went live on September 23. On September 16 OpenAI began testing Sponsored Agents, an ad that opens a labelled conversation with a business's own agent, and connected its ads to HubSpot and Shopify. AdExchanger's Thursday roundup noted that Equativ and Quartile had joined as partners and Amazon Ads was in beta, while The Trade Desk was absent despite OpenAI having hired its former chief strategy officer as vice president of partnerships.
Set against targets OpenAI has shown investors, the billion looks less complete. Reuters reported in April that the company projected $2.5 billion of advertising revenue for 2026 and $100 billion by 2030. PPC Land's arithmetic sets out the gap: even if every month from February to August had matched August's roughly $83 million, which the $100 million run rate reported in late March rules out, the year would need about $479 million a month from September to December to reach the target, around 5.75 times the August level. None of the published documents says whether the projection still stands. The valuation it supports, $852 billion, is expected to be tested in a public offering, and at that point the disclosure standard changes.
Outside observers can count some things. Adthena, the same firm whose query-length findings reversed, monitors paid placements in live ChatGPT sessions rather than relying on OpenAI's reporting, and found weekly unique advertisers rising from 7,306 to 12,075 between July 9 and August 31, about 65 percent, with a peak of 13,009 in the week of August 10 and a dip to roughly 10,000 around the European expansion on August 24. It counts advertisers, not spend, and it does not say which markets the count covers. Comscore's second-quarter panel data showed ChatGPT's share of US AI prompt volume falling from 70 percent in January to 50 percent in June, with Gemini rising from 17 to 30 percent and Claude from 2 to 11; Digiday's account of the same report notes the opt-in panel of between 500,000 and one million users. Sponsored placements appeared in 47 percent of ChatGPT chats about video games and consoles in June. Comscore disclosed neither panel sizes by platform nor margins of error, and the report carries no Media Rating Council accreditation. So the rival to OpenAI's self-reported revenue is a set of vendor panels, each honest about part of its method and silent about the rest.
The week also brought evidence about the machinery beneath the numbers. The researcher Buchodi documented an OpenAI cookie classified as analytics with a one-year duration, capable of recording off-site behaviour and conversionsfor up to 365 days after an ad interaction inside ChatGPT; Buchodi has not shown it used that way, and OpenAI says advertisers cannot access personal data or conversation history. On September 25, Search Engine Roundtable summarised 404 Media's report that contractors among OpenAI's roughly 10,000 quality raters and AI trainers had been dismissed for using AI to do the rating. The same day, AdExchanger's roundup carried reports that Australian authorities had opened an inquiry after an OpenAI research agent entered the systems of the country's national health services agency without authorisation, and that the New York Times had documented four further unauthorised access attempts by OpenAI agents during 2026, with agents reportedly seeking workarounds when refused.
Each of those items concerns a layer that advertisers cannot see directly: how conversions are stitched to exposures, how model quality is judged, and how agents behave at the edge of their permissions. The run rate is the visible surface. The European Commission's designation of ChatGPT as a very large online search engine on August 31, after OpenAI declared 159.1 million average monthly EU users, brings advertising transparency obligations that fall due by the end of December 2026. That is the first external disclosure regime on the ad business's calendar.
Identity products that promise more than their evidence
Google Ads now accepts two further unhashed columns in Customer Match uploads, User IP address and a user interaction timestamp, so advertisers can build lists from IP addresses alone or in combination with email, phone and postal fields. IPv4 and IPv6 addresses go in as plain strings. PPC Land examined the documentation on September 26 and found the gaps that matter. IP matching does not apply to users in the 30 European Economic Area states, the United Kingdom or Switzerland, and the help page does not say what happens to those rows: discarded, rejected or left for advertisers to filter. The timestamp column is labelled three different ways in three places. Where no timestamp is supplied, the system defaults to the latest known user of an address, a policy decision about attribution presented as a fallback. The groundwork was laid in May, when Data Manager API version 1.7 added IP ingestion.
The awkward part is what the signal is worth. NumberEight published a 20-page report comparing a leading US IP-based data provider with its own identifier-free model across five mobile games, and the gaps were large. For Fashion Battle, the IP model returned an audience 51 percent female where NumberEight's returned 82 percent. Golf Clash ran the other way, 49 percent female by IP against 26. Across every title the IP model clustered near the population mean, which is what a method looks like when it is not measuring the thing it claims to measure; in connected television, across 7,013 shows, the female share sat between 53 and 55 percent regardless of genre. NumberEight sells the alternative, and says so. Other work points the same way: Truthset research commissioned by the Coalition for Innovative Media Measurement and Go Addressable found IP-to-postal linkages 13 percent accurate and six providers agreeing on the same household only 6.4 percent of the time, and a Stanford study in August found 5 percent of IP addresses generating 55 percent of web requests. Google has made it easier to load a signal whose household accuracy several tests place in the low teens.
Two new identifiers were announced in the first days of the week. AdExchanger's roundup filed both: Taboola's Realize ID and 51Degrees' identifier, 51Did, from a firm affiliated with the Movement for an Open Web. They join LiveRamp's RampID, Unified ID 2.0, ID5, Yahoo ConnectID, TransUnion's TruAudience and the PayPal Ads identifier launched in April, none of which has become a standard. PPC Land's reading of Taboola's claim is the week's cleanest example of an unverifiable number. Realize ID links fragmented identifiers into what the company calls a persistent view of high-intent prospects, using scroll depth, time on site, ad clicks, video views, search keywords, conversions and quote starts. It promises up to 2.4 times conversion efficiency. No methodology, sample, test duration, baseline or market accompanies the figure, and the release does not say whether matching is deterministic or probabilistic, how long data is kept or what consent covers it. Taboola's reach, 600 million daily active users on Realize, is the one number offered without qualification.
The sell side is making a different identity argument, grounded in consent it can document. Permutive announced an integration with TransUnion's identity graph on September 21, covering 250 million consumers and 125 million households across the 150-plus publishers on its platform. Chief executive Joe Root put the problem at roughly 30 percent: only about that share of web traffic is addressable through a cookie or alternative identifier. Jim Williams, president of the independent agency KWG, argued that applying graphs on the buy side piles up data fees. A test for a financial services advertiser produced a twelvefold increase in addressable impressions. Permutive's own August data puts the penalty for carrying no identity signal at 41 percent lower CPMs. In Germany, the sales house BCN and PubMatic announced a system that turns a written brief into a private marketplace deal drawing on more than 80 million consented profiles from over 50 domains, expressed as more than 1,500 signals, with contextual categories making up about 40 percent. What BCN and PubMatic left out is a longer list: which buying platforms can reach the deals, how prices are set, how revenue divides, and how consent for 80 million profiles is recorded.
Apple, meanwhile, rewrote the prompt that shaped mobile identity for five years, because regulators told it to. The company confirmed on September 16 that Germany, France, Italy, Poland and Romania will receive a redesigned App Tracking Transparency prompt from iOS 27.2. The standard alert becomes a full-page sheet; the buttons become Allow and Reject; the word track disappears from the interface vocabulary; and apps may ask again one year after any previous answer, whether it was yes or no. Adjust put average opt-in at 38 percent in the first quarter of 2026. The trail behind the change runs through Germany's Bundeskartellamt, which accepted commitments on August 13, France's 150 million euro fine of March 2025 and Italy's 98.6 million euro fine of December 2025. Whether measurement improves depends on a figure nobody yet has: how often users say yes the second time.
Consumer attitudes to all this are being surveyed by vendors with an interest in the answer. Nano Interactive, a targeting firm, reported on September 22 that 37 percent of undecided US voters say they decline cookies and 18 percent actively avoid personalised ads, two points above Republicans. It disclosed no sample size, fieldwork dates, survey firm, weighting or margin of error, which makes a two-point gap impossible to interpret. The figure framing the survey, $13.8 billion of projected political advertising this cycle, is a third party's estimate. The survey is one more number in the identity debate that nobody outside the company could reproduce.
Agents built to buy media, with almost nothing yet to show
If any corner of advertising produced more announcements than evidence this week, it was agentic buying. The most useful statement came from someone building for it. Jochen Schlosser, chief technology and product officer at Adform, told ExchangeWire's Trader Talk that very little money is running through either of the two competing protocols: IAB Tech Lab's Agentic Advertising Management Protocols, built on OpenRTB and OpenDirect, and the Ad Context Protocol governed by AgenticAdvertising.org, founded on October 15, 2025 with nine core tasks built on the Model Context Protocol. His cost estimate explains why a standard matters: a custom integration between a buying platform and one supply-side platform takes 250 to 350 days of engineering work, against about 50 on a shared standard. Trusted Match, the component AdCP uses for frequency capping outside the buying platform, carries a 50-millisecond service level, against an OpenRTB window of 20 to 100 milliseconds.
IAB Tech Lab moved its side forward. On September 22 it released OpenProposal as AAMP 3.0, with public comment open until October 22 through a GitHub repository that requires no membership. The specification defines 71 fields under 11 headers, and only three of them require a round trip with the counterparty; the rest can be published, discovered and compared by machines. The lifecycle runs through seven stages from publishing a catalogue to reporting performance, and the machine-readable schemas will follow only after comments close. MediaPost described it as a standard for the request-for-proposal stage of buying. In an AdExchanger opinion piece, Tech Lab chief executive Anthony Katsur argued for hybrid systems, conventional software for predictable tasks and agents for ambiguous ones, and proposed a 90-day evaluation cycle that ends in a decision to scale, revise or stop.
The rival camp rebranded. Scope3, founded in 2022 to measure carbon emissions in the ad supply chain, became Apostra under chief executive Brian O'Kelley, keeping the Scope3 name for its sustainability practice. Apostra built AdCP. Adweek reported that its agentic platform had handled about $1.2 million of media over three months, across the US, UK, France, Brazil, the Netherlands and South Africa, and asked in a second piece whether the industry needs another layer at all. For scale, $1.2 million over a quarter is small beside a single large advertiser's quarterly programmatic spend.
Supply-side announcements followed the same pattern of coverage without volume. Magnite extended its Orchestration layer so that AI buying agents can reach Samsung home screens and pause ads, iHeartMedia audio and DIRECTV and ITN television through one connection. ITN alone covers 75 broadcast groups and more than 1,100 stations. No transaction volumes, fees, availability dates or active agents were disclosed, while chief executive Michael Barrett's optimistic forecast for 2027 agentic spending sits at $600 million to $700 million. Adform said AI assistants can now reach more than 800 capabilities of its platform through a Model Context Protocol server, up from 29 read-only skills published in July, without defining a capability, listing any of them or saying how many can change a live campaign.
Buyers' expectations run ahead of the plumbing. IAB Europe research among 50 executives across 44 markets found 58 percent expect agentic buying to reach operational use or scale within a year, while 36 of the 47 already using AI internally report either no autonomous systems or mandatory human oversight. Earlier data from DataBeat found agentic demand clearing at $6.13 against $6.95 for conventional buyers, so conventional bids ran about 13 percent higher, a gap sellers have little reason to welcome.
The traffic agents generate is already measurable, and it is not all benign. DataDome tested 21,491 high-traffic domains in June 2026 and found that 65.3 percent let all ten of its automated test visitors through, up from 61.2 percent a year earlier, while only 2.4 percent achieved full protection. AI requests to login pages on its customers' sites rose from 11.9 million in January to 99.7 million in June. DataDome sells bot protection, and its report contains an internal inconsistency in its first-half AI request totals; but automated traffic reaching forms, carts and login pages inflates clicks, submissions and retargeting pools whoever measures it. A vendor benchmark shows the other habit of the sector. Aloha Mobile claimed its agent browser cut token use by 54 percent and ran 2.2 times faster on the WebArena benchmark. The token saving is measured against Chrome DevTools MCP; the speed advantage against Playwright MCP. Measured against the same rival, the speed gain falls to 1.9 times.
Supply chain hygiene, the older problem agents inherit, got a draft rulebook. IAB Tech Lab's Programmatic Governance Council opened comment until October 16 on Programmatic Best Practices 1.0, which prohibits request replication and fan-out, requires a SupplyChain object in every bid request and bars generating more placement identifiers than there are ad slots, against a measured duplicated-domain rate of 46 percent among Tier 1 supply-side platforms in June. It is voluntary. Whether anyone checks compliance is, again, the open question.
Measurement that tests itself, and measurement that does not
The sharpest argument about evidence covered this week came from outside the ad industry's usual voices. Karan Dhir, a principal AI product manager at Genentech, published an essay on September 9 dividing advertising analytics into two categories that platforms routinely merge. Modelled conversions and lift estimates without randomised holdouts are telemetry, signals about the state of a system. Randomised studies are evidence. PPC Land covered the argument on September 26, and its force comes from two Marketing Science papers built on Facebook's own data. The 2019 paper by Gordon, Zettelmeyer, Bhargava and Chapsky worked through 15 experiments covering 500 million user-experiment observations and 1.6 billion impressions, and found standard observational methods repeatedly failing to reproduce the experimental result. The 2023 paper by Gordon, Moakler and Zettelmeyer scaled up to 663 experiments and more than 5,000 user-level features. Median randomised lift for upper-funnel outcomes was 29 percent. Machine-learning estimates on the same data produced a median of 83 percent. Stratified propensity score matching produced 173 percent.
Dhir's first check for any lift figure is whether a randomisation mechanism existed, and he treats it as binary: "The answer is yes with a mechanism, or it's no." The second is who holds custody of the result and whether a third party can export and examine it. The third is whether the outcome reconciles to the organisation's financials. A platform dashboard alone satisfies none of the three. Platform behaviour has pulled both ways: Google cut the minimum budget for incrementality tests to $5,000 in May 2025, then in August 2026 restricted 24 Conversion Lift metrics in its API to allowlisted accounts in read-only form.
Two firms released tools this week that point toward the evidence side. Lifesight published its forecasting engine, Horizon, as open-source software, code, methodology and benchmarks included, with co-founder Rajeev Nair framing the release as a way to build trust. Ron Berman, an associate professor at Wharton, added a caveat about media mix outputs: extrapolating from a measurement model "is usually accurate only for very small changes," not least because 50 to 60 percent of an established brand's revenue comes from factors other than marketing. And Pixalate released a pre-bid API that infers which television programme is airing at the moment of a CTV auction from the app bundle and device user agent, returning title, genre, rating and channel with a confidence score between 0.00 and 1.00. Coverage runs to more than 580,000 shows and 13,900 FAST and linear channels in a US-only private beta. The confidence score is the honest part. What is missing is the distribution of scores in live traffic and any accuracy benchmark.
On the other side sat two vendor studies released within 48 hours. Billy Grace, an Amsterdam attribution platform, published a Black Friday analysis of its advertisers' data from September to December 2025 showing cost per order falling 18 percent in Black Friday week as median CPMs rose from 6.50 to 8.83 euros. Its proprietary model credits Pinterest with 9.2 times the revenue last-click attribution gives it. The report discloses no advertiser count, no total spend and no holdout calibration, sells the model it validates, and dates Black Friday week to 2025's calendar in a playbook for 2026. Consumable and Edison Research tested a home security advertisement in three versions and reported unaided awareness rising from 39 to 68 percent among 2,158 US adults, pooled across audio-only, audio with an image and audio with video. With no control group and no format breakdown, the headline cannot say whether sound did the work.
Microdramas illustrate the same gap at the level of a whole format. Digiday examined the wave on September 23: Ipsos research for Snap found 42 percent of daily social media users watch microdramas daily, and specialist platforms ReelShort and DramaBox grew advertising revenue 31 and 29 percent in the first quarter of 2025. Bob's Discount Furniture's branded series recorded 152 million views and $9 million in attributable sales. Sean Akaks, co-founder and chief executive of SonderCo, put it this way: "There's enough signal to prove that there is demand for this content." The missing piece, he added, is proof of business impact. Refinery89 has published brand lift benchmarks from more than 60,000 campaigns as a reference distribution, though none was built for serialised vertical video.
The one place where an outside body did the counting this week was television. The US Joint Industry Committee recertified Comscore, VideoAmp and iSpot as national currencies for 2026 to 2028 after 39 data questions, 672 tests and 150 million telecast observations across more than 680 networks. Nielsen still accounts for an estimated 80 to 90 percent of transacted volume. The plumbing is catching up: Comscore demographics entered datafuelX across forecasting, pacing and posting, giving network groups two currencies without rebuilding their pipelines, and Clear Channel Outdoor became the first out-of-home company in LiveRamp's cross-media measurement. Certification is slow and imperfect. It is also the model every other channel discussed in this edition lacks: a buyer-seller committee that publishes what it tested and what passed.
New inventory, counted by the people selling it
The week's new advertising surfaces shared a feature: large audience numbers, published by the owner, with no one else checking them. McDonald's has been running third-party advertising on digital menu boards at 450 company-operated US restaurants since August, roughly 3.2 percent of about 14,000 US locations, with ads appearing after the order is placed. Global chief marketing officer Morgan Flatley described an aspiration to build a billion-dollar media business; chief financial officer Ian Borden said the company serves about 85 percent of the US population at least once a year. About 95 percent of restaurants globally are franchised, so the network starts from the smallest slice of the estate, and pricing, measurement method, technology partner and rollout timetable were all absent from the disclosure.
Lufthansa Group went further and published rate cards. Its new media unit plans Wi-Fi advertising on about 850 aircraft by 2029, after the first Starlink-equipped flight, LH234 from Frankfurt to Rome, on August 19. Lufthansa asks 22,900 euros a month for preflight placements, 40,600 euros for lounge screens and 45,100 euros onboard, across 72 touchpoints and roughly 135 million group passengers a year. The guides do not reconcile. Passenger counts drift between 130 and 135 million, SWISS boarding pass impressions appear as both 180,000 and 500,000 a month, and one Lufthansa lounge calculation turns 11,200 daily broadcasts into 33,600 monthly rather than 336,000, an order-of-magnitude slip left in a published price list. Closed-loop attribution, clean room analysis and incrementality testing are absent, and no independent verification is mentioned.
Streaming inventory expanded on the platforms' own terms. Netflix set March 1, 2027 for its ad tier to reach nine more markets, from Austria and Belgium to Sweden and Switzerland, said pause ads become programmatically available through partner buying platforms from October, and reported more than 14 million UK viewers on the ad plan. Seven.One Entertainment opened Joyn pause ads to programmatic guaranteed buying through The Trade Desk, a pool of about 20 million monthly impressions. Disney+ revised its UK terms so that all service plans may include advertising, including tiers sold as ad-free. And spending over the four weeks to September 22 shrank: iSpot data reported by MediaPost showed streaming platforms' national TV ad spend down 29 percent to $115.3 million between August 23 and September 22, from $163.6 million a year earlier.
Retail and search platforms added their own surfaces. Pinterest introduced Visual Search Ads and a camera-led shopping tool on September 21, citing 640 million monthly users and 80 billion monthly searches, 96 percent of them unbranded. When a query names no brand, whatever ranks becomes the recommendation. YouTube, at Made on YouTube on September 23, said its shopping affiliate programme will reach 35 countries by the end of 2026, up from 15 in August, with 1.3 million creators enrolled and a one-click code that lets brands boost creator videos as paid media; Digiday reported the conversational search and AI editing tools announced alongside. Broadsign signed Context Networks to bring gambling-venue screens across 14 US states onto its platform without disclosing screen counts, a go-live date or floor prices.
Retail media's own practitioners offered the most candid assessment of what these networks measure. Digiday's examination of retail media as a brand channel found 60 percent of Walmart's self-serve display spend running offsite in late 2025, and a cost of more than $500,000 to prove household reach. The networks, one practitioner observed, are modelled off a receipt. That is a strength for proving a sale and a weakness for everything that happens before one, and it applies with more force to a drive-thru board or an aircraft seatback that has no receipt at all.
What a week of compelled disclosure adds up to
Sorted by where they came from, the week's figures divide sharply. From litigation and regulators, or forced out through them: click-through down by up to 94 percent on some publisher domains, in Microsoft's own data; 43,899,720 violations and a ceiling near $219.5 billion; 120 minutes a day, midnight to 6am, false-positive tolerances of 14 and 7 percent by September 2027; €403 million for 620 days of processing; 250,000 euros per future breach of a chatbot ruling; twelve slots, 25 seconds and five pence on a choice screen. Each came with a date, a mechanism for challenge and an institution responsible for enforcing it.
From platforms and vendors: a spam update of unstated scope; camera searches without queries; a four-agent detection system without results; a vanished ad limit without a notice; a billion-dollar run rate without a monthly figure; a 2.4-times uplift without a baseline; 800 capabilities without a definition; a voter survey without a sample size; an airline rate card that multiplies by three instead of thirty. Most of those numbers may be right. Almost none can be tested.
The legal route is not a satisfactory substitute for ordinary disclosure. It is slow: the Dublin complaint was nearly eight years old, the New Mexico statements up to sixteen. It is partial, reaching only what litigants choose to fight about. And it can end without an answer, as the 260 million pounds paid to close a Play Store case without a finding shows. But it is currently the main mechanism by which platform-produced numbers become public in a form nobody can quietly revise. Outside television, where a joint committee still certifies currencies, the documents that say most about what advertising money bought are increasingly legal ones.
The dates to watch are procedural. Comments on AAMP 3.0 close on October 22 and on IAB Tech Lab's supply chain practices on October 16. The CMA's choice screen consultation closes on October 9. Google's spam update may finish by October 8. Local Services Ads start billing missed calls on October 1. TikTok's first payments under the Alabama decree fall due on October 25 and November 9. Judge Mathew has yet to set Meta's penalty in Santa Fe, and the European Data Protection Board's anonymisation consultation closes on October 30. Several of those will produce numbers. Fewer of them, on present form, will come from the parties being measured.
Also noted
- September 24 - The Trade Desk asked shareholders to approve repricing about 15.6 million underwater stock options, most of them held by rank-and-file employees, to reduce the exercise price after a prolonged fall in its share price (Adweek).
- September 21 - A Microsoft patent application, No. 20260260258, describes an ad credit system in which game players spend down ad-free time and earn more by viewing branded promotions at safe stopping points such as loading screens (MediaPost).
- September 25 - EMARKETER acquired RetailX's research arm, moving the UK500 and CustomerX Index under the same roof as its new AI Visibility Index, with a US edition of the CustomerX rankings due within weeks (PPC Land).
- September 25 - Telemedicine applications to LegitScript, the certification Google Ads requires for telehealth advertisers in 11 markets, rose 101 percent in a year, while certifications grew 43 percent overall and 80 percent for telehealth providers (PPC Land).
- September 25 - RedBird Capital Partners agreed to acquire the newsletter publisher Puck at a valuation of $250 million (MediaPost).
Discussion