Mathieu Roche, co-founder and chief executive of the identity company ID5, today called Apple's latest Safari restrictions an attack on the business model of the open web. His LinkedIn post came 19 days after iOS 27 began cutting ID5's domains off from Safari on updated iPhones and iPads, and a day after AdExchanger reported that Apple can now block hundreds of data and ad tech firms through a list it updates remotely.

In Short

Apple's newest iPhone software stops Safari from contacting a short list of advertising data companies, and the boss of one of them, ID5, says the real target is websites that pay their bills with ads. If you run a site that sells ads, the tools that recognise returning readers and lift the price of each ad may not load at all for people on an updated iPhone. Apple now keeps that list in a file it can change at any moment without telling anyone, so the companies on it, and the advertisers who rely on them, cannot tell who will be cut off next.

A post aimed at Cupertino

Roche published the post on LinkedIn today. It is a rare public response from one of the companies on Apple's blocklist: AdExchanger said on October 2 that the initially blocked firms had not replied to its requests for comment. The post opens with the charge that Apple "has decided to dial up its attack against web advertising." The new version of what he calls Apple's "so-called 'Intelligent Tracking Prevention' (ITP) mechanism", he wrote, was "released without warning or consultation in iOS27" and "limits the ability for web publishers to recognize their visitors and make money from advertising."

Then comes the central claim. "This move is not against ID5.io or any other adtech company," Roche wrote, "it is an attack against the business model of the web and in favor of mobile applications, where Apple can apply a 30% tax on everything."

Although ID5's own domains sit on the list, Roche did not argue his company's case. He cast ID5 instead as a veteran of earlier rounds that had helped clients and partners through "previous flavors of ITP, App Tracking Transparency, and Chrome's 3P cookie removal attempts", and "will deal with iOS27 like we dealt with previous initiatives, so that publishers who work with us can continue to monetize their loyal, consenting traffic and keep the Internet free."

The final third of the post turns to process and power. Roche wrote that he would like Apple to sit down with industry organisations so that data-driven advertising and data protection "keep reinforcing each other", adding: "Unfortunately, they have not been willing to do that." Then: "Apple has been found guilty of weaponizing privacy for its own business benefit by the EU already. Maybe more regulators should look at their business practices and decide whether a monopolistic operator should regulate how companies are allowed to do business with their clients." The post closes with a variation on a familiar maxim: "With great power should come great responsibility -and even greater accountability."

The post describes no technical workaround, makes no reference to The Trade Desk or Google, and names none of the industry organisations it says Apple has declined to meet. Apple has given no public explanation for the list.

What iOS 27 changed

Apple began rolling out iOS 27 on September 14. Within a week, The Trade Desk could no longer serve advertisements in Safari on updated devices, and on September 29 AdExchanger reported the problem alongside a list of identity and data services added to Apple's block list during September: Unified ID 2.0, ID5, Audigent, LiveRamp and Permutive. According to AdExchanger, the release extends an existing Apple policy of unconditionally blocking data broker domains that perform addressable ID matching and facilitate tracking across sites.

The mechanism had sat in public code since February, as PPC Land's reading of the eleven lines WebKit merged showed. Charlie Wolfe opened WebKit bug 307853 at 14:27 Pacific time on February 13, 2026, with a description field of three dots, and commit 307525@main landed 81 minutes later, adding 11 lines to a single file, Source/WebKit/Platform/cocoa/WebPrivacyHelpers.mm.

The first block defines a macro, IS_REQUEST_UNCONDITIONALLY_BLOCKABLE, that returns false for every domain in the public repository. Only Apple's internal builds import WebPrivacyHelpersAdditions.mm - a file the repository names but does not contain - which can supply the real definition. Anyone compiling WebKit from public source gets a switch that blocks nothing. The second block places a check inside a function called isRequestBlockable, ahead of a branch that exempts domains Apple's tracker data marks as not blockable, so a listed domain is blocked before the exemption is ever consulted.

One domain, every subdomain

The check does not receive a hostname. It receives a registrable domain, the public suffix plus one label, which browser engineers call the eTLD+1. Every host under a listed domain falls with it. That was the core of The Trade Desk's complaint: adsrvr.org carries the company's ad requests and creative delivery as well as cookie matching, and an entry for the domain cannot tell them apart.

The same rule explains the shape of ID5's exposure. Ian Meyers, The Trade Desk's senior director of engineering, reproduced nine entries in WebKit bug 324771, which he filed on September 21: tainted.example, uidapi.com, adsrvr.org, id5-sync.com, eu-1-id5-sync.com, rlcdn.com, pippio.com, permutive.com and ad.gt. Apple has not confirmed the list, and the ticket does not say how Meyers compiled it. Two of the nine belong to ID5. The first, id5-sync.com, is the source string ID5 uses when its identifier travels in OpenRTB bid requests. The second, eu-1-id5-sync.com, needs a line of its own because it is a separate registrable domain, not a subdomain of the first. A third entry, uidapi.com, is the domain behind Unified ID 2.0, and it also appears in bid requests when ID5 distributes The Trade Desk's European identifier on a publisher's behalf.

From nine names to hundreds

That list may already be out of date. On October 2, AdExchanger reported, citing two sources with direct knowledge of the WebKit updates, that the short list had been scrapped in favour of a library of hundreds of customer data platforms, ad tech and martech companies, data sellers and identity graph operators. According to AdExchanger, Apple devices now call a remote list at regular intervals, so Apple no longer needs an iOS release to add or remove a vendor. The full list sits in a private GitHub repository.

Two consequences follow if those sources are right. Vendors may not know they have been added, or whether they have moved from a potentially blocked tier to an actively blocked one. And the original five, ID5 among them, remain blocked on iOS 27. AdExchanger pointed to WebKit commit 172f52ace994, where rule names such as isRequestToKnownCrossSiteTracker sort vendors into categories, as a sign of wider bans on customer data platforms, data management platforms and buying platforms. Apple has confirmed none of it.

The reports also diverge on scope. AdExchanger said the blocks extend to other mobile browsers, because browsers on Apple devices must run on WebKit; a 2020 change put WebKit's tracking prevention into every iOS browser through WKWebView. Meyers' ticket, however, documents only Safari 27 on iPhone and iPad running iOS 27, and records nothing about macOS.

Not quite the ITP of 2017

Roche described the change as a new version of Intelligent Tracking Prevention. The label is widely used as shorthand for everything Safari does against tracking, yet the mechanism is different in kind - and the difference matters to anyone hoping to work around it.

ITP, which Apple added to Safari in 2017, was about memory: how long cookies and stored data survived. A 2019 revision capped cookies written by JavaScript at seven days, and on March 24, 2020 Safari blocked all third-party cookies by default, a change WebKit engineer John Wilander set out in a blog post. Each time, the industry moved identity into first-party storage, server-side infrastructure and shared identifiers such as ID5's.

The iOS 27 hook is about connection. The February code places it beside the tracker lookups that feed Safari's network-level protections, next to a function soft-linked from Apple's libnetwork library behind a guard named HAVE(SYSTEM_SUPPORT_FOR_ADVANCED_PRIVACY_PROTECTIONS) - not in the cookie code. A restriction on storage shortens how long a browser remembers someone. A block on the request means the call never leaves the device.

Earlier releases had been heading this way. Safari 26 made Advanced Fingerprinting Protection the default for all browsing in September 2025, restricting what classified scripts can read. A July review of the Safari 27 beta source found connections to Bing and LinkedIn advertising servers cut by IP address. Meyers' only attachment is a screenshot titled as showing requests blocked on a yahoo.com article in non-private browsing.

How much warning was there?

The public record bears out only part of the claim that the change came "without warning or consultation". The switch was visible in WebKit's repository from February 13, seven months before iOS 27 shipped. In July, analytics engineer Mariusz Brucki's beta review flagged the category of unconditionally blockable domains, noted that its contents sat in an unpublished Apple file, and observed that Apple's release notes barely mentioned tracking changes. What nobody outside Apple could see was the list itself.

Meyers' ticket shows how thin the process is after the fact. Wilander, who manages WebKit privacy and ad tech at Apple according to AdExchanger, replied on September 22 that Apple was investigating. On September 28, after Meyers asked for an estimate, Wilander said he would report back if and when changes were available to test. The ticket reached Apple's internal tracker that evening, seven days after it was filed; Wolfe's February ticket had got there within six seconds. No published criteria govern entry to the list, and no appeal route is documented.

What ID5 has riding on Safari

ID5 is a London company, incorporated in April 2017, that issues a shared pseudonymous identifier, the ID5 ID, and operates an identity graph linking it to cookies, mobile advertising IDs and connected television identifiers. Most publishers pick it up through Prebid.js, which stores it locally under the key id5id. After a $20 million Series B in April 2024, it acquired the US graph company TrueData in November 2025; Roche told AdExchanger the combined graphs recognised about 1.5 billion users across 665 million households. ID5 also cites Sincera data putting deployment near 100,000 sites in January 2025. Neither figure has been independently audited.

Safari is where identifiers of this kind were supposed to earn their fees. Third-party cookies have not worked there for six years. After Google said on April 22, 2025 that Chrome would keep them - a reversal Roche criticised sharply at the time - and then retired most Privacy Sandbox technologies on October 17, 2025, Safari and Firefox remained the main browsers where cookies could not do the job. In December 2024, OpenX and ID5 reported a 58% increase in Safari desktop reach, and 37% on mobile web, when the ID5 ID was present, compared with cookie-based solutions. Those were vendor figures. Cloudflare data for the third quarter of 2025 put Safari at 15.1% of global browser traffic, against 66.3% for Chrome.

The cost of losing identity had already been priced, at least by vendors. Permutive's own August data, cited in PPC Land's September 30 analysis, put the penalty for carrying no identity signal at 41% lower CPMs, and its chief executive, Joe Root, estimated the addressable share of web traffic at roughly 30%. The ID5 block falls into that category for publishers: the impression is still sold, minus the identifier. The adsrvr.org entry does not, because a bid that cannot reach the browser is never priced at all.

Roche gave no detail on how ID5 intends to respond. Any of its methods that requires Safari to reach a listed domain is closed at the request itself.

The 30% argument

The claim that Apple favours apps "where Apple can apply a 30% tax on everything" compresses several fee regimes into one number. Apple has charged 30% on most digital goods sold through the App Store since the store opened, with 15% for small businesses and for subscriptions after their first year. A US federal judge barred Apple on April 30, 2025 from charging commission on purchases made outside apps, and EU terms in force since October 1, 2026 set the in-app purchase rate at 26%, with a 5% Core Technology Commission on sales outside the store.

Advertising is a separate matter. Apple's commission applies to purchases of digital goods and services; advertising revenue a publisher earns inside its own app is not subject to it. Apps also come with their own tracking regime. App Tracking Transparency has required permission for cross-app tracking since iOS 14.5 shipped on April 26, 2021, and Flurry put opt-in rates at between 11% and 15% in the period after its release. A publisher that moves readers from Safari into an app swaps one Apple rulebook for another.

Roche's argument stands on firmer ground when it turns to Apple's own advertising. Apple's advertising terms, effective July 28, 2026, let Apple Ads content run on devices, operating systems, web applications and other properties the company does not operate. Apple's placements report through its AdServices API rather than the aggregated, delayed AdAttributionKit postbacks other networks rely on, an asymmetry European regulators have examined. The company writing Safari's network rules is, in other words, a growing seller of advertising too.

The regulatory record

Roche's statement that Apple was "found guilty of weaponizing privacy" by the EU needs unpacking. No EU institution has ruled against Apple's privacy rules as such. The findings Roche appears to have in mind came from national competition authorities applying EU competition law to App Tracking Transparency. France's Autorité de la concurrence fined Apple 150 million euros in March 2025, finding that users had to consent twice to allow tracking but refuse only once. Italy's competition authority fined Apple 98,635,416.67 euros on December 22, 2025, in a case built on Article 102 of the Treaty on the Functioning of the European Union rather than the Digital Markets Act.

Germany took a different path. The Bundeskartellamt reached preliminary findings in February 2025 that the framework may treat third-party developers unfairly compared with Apple's own services, then closed the proceeding in August 2026on commitments to redesign the prompt, with no fine and no finding of infringement. Apple rejected the authority's preliminary assessment and maintains its rules comply with competition law. On September 16, Apple told developers that apps in Germany, France, Italy, Poland and Romania would move to an alternative tracking prompt once iOS 27.2 ships.

The European Commission's own penalty, 500 million euros on April 23, 2025 under the Digital Markets Act, concerned anti-steering in the App Store, not privacy. The national cases all concerned consent for tracking inside apps; none has touched WebKit's network rules. Roche's appeal for wider scrutiny would carry that debate from the App Store into the browser.

The Google question

One detail from the original reports cuts across Roche's framing. According to AdExchanger, the yahoo.com ad call in Meyers' screenshot showed The Trade Desk's bids blocked while Google's, delivered through ad.doubleclick.net, went through. That domain is not among the nine entries Meyers reproduced, and on October 2 AdExchanger said it was still trying to establish whether any Google property sits on the longer list.

Roche's post does not mention Google, and the omission sharpens the puzzle rather than settling it. If Apple's target were web advertising as such, why would the largest web advertising business keep serving? If it were cross-site identity, why list adsrvr.org, a domain that delivers creative? Apple has answered neither question.

Why this matters for marketers

For buyers, the immediate effect is a gap in reach that gives no signal of its own. Campaigns bought through a demand-side platform whose delivery or identity domains are listed simply do not serve in Safari on iOS 27, and frequency capping and measurement built on blocked identifiers lose the Safari slice of the picture. Publishers lose the identity signals that lift Safari prices.

The larger change is procedural. Safari's cookie restrictions were set out in public WebKit posts, and App Tracking Transparency arrived with almost a year of notice. The iOS 27 list shipped without a release note and, if AdExchanger's sources are right, can now change between releases with no outside record. Any media plan touching the hundreds of firms reportedly on the probationary list carries a variable nobody outside Cupertino can observe.

Roche's post is an opening position, not a filing. Whether competition authorities take up his suggestion, whether Apple answers The Trade Desk's ticket, and whether ID5 finds a route around a block on its own domains will decide how far his framing holds.

Timeline

Summary

Who: Mathieu Roche, co-founder and chief executive of ID5, a London-based identity company whose domains id5-sync.com and eu-1-id5-sync.com appear on the list of domains Safari blocks on iOS 27. Apple, which maintains the list, has given no public explanation. The Trade Desk, LiveRamp, Permutive and Audigent are also affected.

What: In a LinkedIn post, Roche called the iOS 27 change an attack on the business model of the web that favours apps, where Apple can charge commission, said Apple had refused to meet industry organisations, and suggested more regulators examine its practices. The change itself is an 11-line WebKit hook that blocks requests to listed registrable domains before tracker exemptions apply, now reportedly backed by a remote list of hundreds of companies.

When: Roche posted today, October 3, 2026. The WebKit hook was committed on February 13, 2026, iOS 27 began rolling out on September 14, 2026, and AdExchanger reported the expanded remote list on October 2, 2026.

Where: Safari 27 on iPhone and iPad running iOS 27, according to The Trade Desk's ticket, with AdExchanger reporting that other mobile browsers using WebKit are affected too. The regulatory precedents Roche cites come from France, Italy and Germany.

Why: Safari remained the main browser where cookies do not work after Chrome kept them in 2025, making it the market where identifiers such as ID5's earned their fees. A block at the request level removes that signal entirely, and the list governing it can reportedly change without notice, leaving vendors, publishers and buyers without a way to know who will be blocked next.