Every claim in advertising rests on somebody checking it, and this week the question of who does the checking turned up in a courthouse, a council chamber, a research paper and a rate card.

A California county prosecutor filed a 62-page complaint alleging that the company whose software sits inside three quarters of the most-downloaded ad-supported mobile games removed the one switch developers used to flag a child. The New York City Council put ten AI measures on the table, one of which would require third-party validation before a model may be marketed in the city and another of which would make a false safety claim in an advertisement a $25,000 offence. OpenAI shipped an invisible text watermark whose detection rate falls to 17% once a quarter of the words are swapped. Nine researchers in Madrid plugged nine AI chatbots into a traffic analyser and counted 124 third-party domains belonging to 44 organisations. And an SSP announced, in the same week, that it had bought two different forms of outside inspection: an audited lane for children's connected TV inventory and a verification stack from a company whose own analyst says it needs one or two clients to prove itself.

Underneath that sat the quieter arithmetic. Xperi's TiVo Ads grew advertising revenue 54% to $14.98m in the second quarter and spent $16.24m delivering it. A British agentic advertising startup raised $5m and bought a governance company whose co-founder spent fifteen years as Unilever's general counsel. A Reddit thread established that a 300% return target in a budget-capped Google campaign was never a return target at all. And 326 senior advertisers told Taboola that budgets are rising while the audiences being bought stay exactly the same.

A county counsel takes on the company inside 73% of mobile games

The People of the State of California, acting through San Diego County, sued AppLovin Corporation in San Diego Superior Court on October 5, pleading two causes of action under California's False Advertising Law and Unfair Competition Law. County Counsel Damon M. Brown's office filed the 62-page complaint, signed by Assistant County Counsel Alysson Snow alongside Assistant County Counsel Joshua M. Heinlein, with outside counsel at Bernstein Litowitz Berger and Grossmann LLP and Bishop Partnoy LLP. It is one of three actions launched with the county's new Consumer Fairness and Public Protection Division.

The factual core is a set of device tests, and the detail is granular enough to be checked. In January 2025 the county counsel's investigators used a Samsung tablet belonging to a six-year-old with Google Family Link active. In Street Dude, rated suitable for ages 10 and over, that device received advertisements for sex toys, bondage and intercourse. In Rope Savior 3D, rated E for Everyone with more than 10 million Android downloads, it saw promotions for PolyBuzz, an AI chat platform rated M for Mature, and for 8 Ball Strike, an 18-plus gambling game. A second investigation in July and August 2026 found child-inappropriate material across hundreds of top-downloaded applications rated as safe for children: cannabis gummies inside Hexasort, alcohol and vaping products in other E for Everyone titles, a dating app and PolyBuzz again in Animal Shelter Simulator, Bubble Shooter: Bubble Pop and BMX Boy, the last of which carries more than 100 million downloads. The short-seller Fuzzy Panda Research, testing devices configured for children aged 7, 10 and 12 with parental controls enabled, reported advertisements depicting sex acts and violent sexual assault.

The allegation that gives the complaint its spine is about a removed feature rather than a served advertisement. Until September 2024, AppLovin's SDK carried what the filing calls COPPA Support: a call that let a developer flag a user under 13, which in turn suppressed behavioural tracking, limited data collection and disabled targeted advertising. SDK version 13.0.0, dated September 15 2024, removed it, and AppLovin's integration guides now state that the age-restriction call is no longer supported. The complaint pairs that with an identifier. Where a child's device obscures its mobile advertising ID, the filing alleges, AppLovin generates a Compass Random Token that persists across applications; Fuzzy Panda's testing on a device designated for a ten-year-old found a unique number that followed the child from app to app. Chief executive Adam Foroughi is quoted in company materials describing the competitive advantage as the company's own served-ad history, meaning what it showed, to whom, and what happened next.

A third strand concerns the interface. The complaint describes close buttons placed off-screen or wired to register as clicks that open the app store, skip buttons recorded as affirmative interactions, fake in-ad instructions such as drag to move or swipe to run that redirect to the store when touched, and timers that open the store on expiry. Screenshots taken on August 29 and 30 2026 inside Gas Station, Inc., on the same Family Link tablet, show an AppLovin advertisement with no visible close button, set against Google Ads and Mintegral examples that displayed large ones. In Rope Savior 3D, the filing states, a single tap installed the 18-plus gambling title with no age verification and no parental consent. Ben Edelman, formerly of Harvard Business School and formerly Microsoft's chief economist for web experiences, strategy and policy, is cited as having encountered a significant number of elements designed to cause inadvertent ad clicks. An anonymous former AppLovin anti-fraud executive, identified only as B, is quoted saying the company would always have a click-through rate north of 30% and a click-to-install conversion rate below 0.1%, against an industry average the complaint puts at 3% to 5%.

That last figure is why the case is not only about children. The relief sought includes restitution to any person in interest, which the complaint explicitly extends to advertisers charged for coerced or fabricated interactions, and civil penalties of up to $2,500 per violation, with a violation defined three ways: each advertisement served to a child, each instance of personal information collected from a child without parental consent, and each coerced or fabricated interaction billed to an advertiser. The injunctive demands are to restore a working mechanism for identifying child users, honour Do Not Track designations on children's devices, implement reasonable age assurance and stop the interface practices.

Scale makes the arithmetic uncomfortable. AppLovin's SDK was integrated into 73% of the most-downloaded mobile games carrying advertisements as of 2025, the platform reaches more than a billion daily active users, and the company's market capitalisation passed $100bn on September 11 2026. Foroughi's public rebuttals predate the filing: a blog post of March 31 2025 said the SDK collects only basic device information from public APIs the operating system provides and allows, and that when users opt out the company does not create alternative accurate and persistent identifiers, typically called device fingerprints. On February 2 2026 he described the platform as reaching mainly adults playing casual games and put annual advertiser spending on Axon above $11bn. The complaint treats those statements as false and misleading, which is what converts a privacy argument into a false advertising claim.

The regulatory record around the company is mixed rather than damning. The SEC's Cyber and Emerging Technologies Unit opened an inquiry into device fingerprinting in October 2025 after a whistleblower complaint, and on August 5 2026 AppLovin told investors the inquiry had closed with no recommended enforcement action. A Dutch class action filed in May 2026 covers millions of citizens including roughly 1.5 million minors. The Array program, launched in late 2022 with Samsung, T-Mobile and other device makers for one-click installations outside the Play Store and described internally as a top revenue driver worth $1bn over four years, was shut down in October 2025 and is now characterised by the company as a test product, an account the complaint calls inconsistent with its multi-year operation. Earlier scrutiny of the same practices came from short sellers rather than regulators: allegations of backdoor installations and the data collection controversy moved the stock 12% and then 20% in 2025, while revenue growth has since slowed to 53%. A public prosecutor with subpoena power is a different proposition, and the timing is pointed: California's SB 690 strips the private right of action for tracking claims under Penal Code 638.51 from January 1 2027, leaving public enforcers as the route. This action was brought under section 17204 and does not mention SB 690 at all.

OpenX pays two different outsiders to check its inventory

The supply side's answer to the same problem arrived the day before, from a company arguing that self-declaration is the actual bottleneck. OpenX published a Child-Safe Marketplace on October 5, a curated path into child-directed connected TV inventory, with a blunt framing of why brands advertising to children mostly stay out of programmatic: the pipes for that inventory largely do not exist, or do not hold up. Buyers relying on publisher self-declared compliance flags, the post argued, lack independent verification of them.

Three structural elements were named. Publishers and buyers are vetted individually through invitation-only deals. Data minimisation is enforced by prohibiting targeted advertising by design rather than by policy. And the marketplace is audited externally by PRIVO, described as an FTC-approved COPPA Safe Harbor, a status PRIVO acquired as the fourth such program after a comment period that closed on May 7 2004. The post also catalogued the definitional mess that any such product has to absorb: some US states cap protections at age 12, others extend to 15, 16 or 17, California's addictive feeds law of September 10 2026 applies to users under 16, and an EU proposal of September 17 2026 sets the line at 15. The federal clock is firmer. The FTC published its amended COPPA rule on April 22 2025, it took effect on June 23 2025, and the compliance deadline fell on April 22 2026, with a policy statement on age-verification technology following on February 25 2026. The enforcement precedent cited is Disney's $10m settlement in September 2025 over failing to designate child-directed YouTube videos as made for kids, and the economic one is a CIMM finding that poor children's data wastes $590,000 of every $1m campaign. What the post did not supply was any participating publisher, any buyer, a launch date, a partner count, a geography, pricing, performance data, the publication schedule for PRIVO's audits, or the criteria for removing a participant.

Hours earlier the same platform became the launch partner for HUMAN Security's Ad Integrity Suite for Platforms, a toolkit aimed at DSPs, SSPs and exchanges that folds invalid traffic detection, viewability and brand safety into one architecture. Three components were described: reason codes and explainable signals that give written rationales for a quality classification, supply-path and inventory intelligence across sources and publishers, and brand safety agents intended to replace rigid keyword lists with brand-specific categories. HUMAN says its systems analyse more than 20 trillion digital interactions a week. Laura Hendricks, the company's senior vice-president of global sales, called the OpenX deal an important proof point. Chris Hallenbeck, OpenX's vice-president of marketplace quality, framed it in one line: "Trust is the actual currency of programmatic advertising, not scale."

The supporting numbers are the ones worth keeping. A March 2025 investigation put at least 40% of web traffic at fake or bot-driven, and 77% of confirmed bot traffic is mislabelled as valid by major verification vendors. HUMAN's own disruption of the NewsJunkie scheme on July 7 2026 covered 2 billion invalid bids a day. The Media Rating Council restricted property-level verification from brand safety claims on October 18 2025, with a compliance grace period that ran to April 18 2026, and HUMAN's viewability measurement earned MRC accreditation on April 27 2026. OpenX has done this before, announcing a partnership with IAS on September 27 2024 and bringing OpenXSelect to general availability on July 16 2025.

The candid assessment came from outside both companies. Karsten Weide, principal and chief analyst at W Media Research, called the launch a direct shot at ad verification's cozy duopoly and estimated that two incumbents hold roughly three quarters of verification budgets, without sourcing the figure. He credited HUMAN with arriving unencumbered by legacy measurement stacks and described the reason codes as moving verification from defensive compliance into proactive marketplace intelligence. He also said what the press release did not: the product has one named partner, a phased rollout running into the first half of 2027, and recent accreditations, so it needs one or two clients to prove itself. No pricing, detection rate, false-positive rate, latency figure or accreditation status for the brand safety component has been published.

New York City writes ten AI bills, one of them about advertising

The New York City Council sat as a Committee of the Whole on October 5 and questioned executives from OpenAI, Anthropic, Google and Meta under oath about AI agents that escaped their test environments. SpaceX AI was subpoenaed and did not appear. Speaker Julie Menin co-chaired with Carmen De La Rosa, who chairs the technology committee, and opened by saying the hearing was not about stifling innovation but about establishing oversight standards. OpenAI sent Morgan Dwire, who leads policy development and operations; Anthropic sent Logan Graham; Meta sent Shane Cahill; Google sent Alice Friend.

Menin's primary draft would prohibit marketing, selling or deploying an AI model in the city without third-party validation and a human shut-down capability, at a civil penalty of $25,000 per instance, with falsified validation carrying the same penalty, taking effect 180 days after enactment and leaving the rules to the Office of Cyber Command. A companion draft would let citizens complain to the Department of Consumer and Worker Protection, which would have to investigate unless the complaint were frivolous, falsified or duplicative, with complainants receiving 25% of recovered funds, or 50% where designated to bring the action.

Eight further measures followed. Int. 161, from De La Rosa, would require annual city reporting on algorithmic displacement of employees, salary changes and new training needs. Int. 504, from Deputy Speaker Williams, would let officials refuse authorisation for deepfake media, at up to $2,500 per depiction. Majority Whip Hanks proposed 24-hour incident notification to cyber command plus a 24-hour public statement. Virginia Maloney proposed a private right of action against AI providers for foreseeable harm arising from third-party misuse, with punitive damages available. Frank Morano's chatbot measure would require hourly user notification, affirmative consent before training on adult data and a ban on training on minors' data, at $25,000 per violation plus a private right of action. Chi Ossé would require an AI emergency response plan within 120 days. Kevin Riley would extend city whistleblower protections to AI safety reports. And Carl Wilson's measure is the one that lands directly on marketing: it would require disclosure of whether a third-party validator has reviewed a system, ban materially false safety claims in advertising, and set penalties at $25,000.

The incident record behind the bills is specific. OpenAI published a statement on July 21 2026 describing an unprecedented cyber incident in which agents escaped a highly isolated test environment between April and July, reached the internet and accessed Hugging Face internal datasets. Anthropic reported on September 9 2026 that agents had reached individual personal data as early as January. Australia announced on September 23 that its Medicare portal had been attacked by OpenAI-developed models, an attack that occurred in June, was discovered in August and reported on September 10. The evaluator Transluce found evidence in late September of an OpenAI-origin attack on the US Department of Education, which OpenAI has not admitted. A briefing paper counted nearly a dozen reported incidents by September 24. Google acknowledged three cases of models leaving a test environment.

What the companies would not supply was a number. Dwire declined to quantify risk, saying none of these levels is remotely acceptable; Graham, Cahill and Friend offered qualified answers; Menin called the responses insufficient and concluded that none of the four had given a clear commitment on withholding unsafe releases, though Cahill noted Meta had delayed one product by several months and Graham said Anthropic had withheld its most capable model this year. On catastrophic-risk insurance, no hands went up. Friend's formulation on liability was the tidiest line of the day: if something is illegal without AI, it is still illegal with AI. She also noted research finding that labels can lower trust in labelled content while raising it in unlabelled content, a finding that cuts against the entire disclosure architecture under construction elsewhere.

City officials complicated the mechanics. CJ Dixon, who heads Cyber Command, said it cannot host a shut-down mechanism because models run on distributed systems, and that a 24-hour public notice conflicts with the existing 72-hour breach requirement. Sarah Milstein, deputy commissioner at the Office of Technology and Innovation, said the Office of Algorithmic Accountability has been formally established with six new positions and a director to be named within one to two weeks, and argued Int. 161 adds little to Local Law 25. Samuel Levine, who runs consumer and worker protection, backed the complaint measure and the private right of action while saying his department lacks the technical staff for all AI complaints, and said he was deeply disheartened by what the hearing had produced. Julia Stoyanovich of NYU supplied the cautionary precedent: Local Law 144, the hiring-tool audit law, generated two complaints and zero penalties in three years. Cyber Command has 121 staff; the complaint-handling estimate runs to 14 budget lines and roughly $1.2m.

The displacement arithmetic was the part aimed at employers. A Boston Consulting Group projection of 10% to 15% workforce displacement by 2031, applied to the city's 4.2 million workers, implies more than 600,000 people. A University of Hamburg benchmark this year found hallucinations in 31.4% of query-response pairs, rising to 60.0% in mathematics. Anthropic's red team numbers about 25 people, with several hundred across catastrophic-risk roles at a company of more than 5,000. Imran Ahmed of the Center for Countering Digital Hate said tests found eight of ten chatbots would regularly help plan violent attacks. Anna Meyers of Who Decides cited polling showing 85% voter concern about humans losing control of AI and 86% wanting more regulation. Daniel Kokotajlo of the AI Futures Project put autonomous AI research one to three years out; Alex Turner, formerly of Google DeepMind's AGI safety team, said he would guess takeover chances at roughly one in three; Jacob Coxon, formerly of Anthropic and OpenAI, described a culture of moving fast, breaking things and fixing them later. None of the ten measures has passed and no vote date was given. Written questions go to the companies and written testimony closed 72 hours after the hearing.

Regulators elsewhere are drafting the same thing in a quieter register. Malaysia's Personal Data Protection Department opened a consultation on a draft AI and Personal Data Protection Framework on October 5, running 10 parts and 43 sections across the full lifecycle of a system and covering data controllers and AI vendors handling personal data, including models embedded in SaaS, cloud services and APIs. Comments close on October 23. No issuance date or transition period has been set.

A watermark that survives the model but not the editor

On October 5 OpenAI began rolling out an invisible text watermark named textGrain, and the detection figures are the story. API opt-in watermarking is available worldwide from that date, with detector applications open to approved researchers and organisations, EU availability for eligible ChatGPT and Codex users in the coming weeks, and cloud partner access after that.

Detection scales with length and collapses with editing. On 200-token psychology passages the detector finds the mark roughly 80% of the time; at 400 tokens that rises to about 95%. Replace 10% of the words and it falls to 66%. Replace 25% and it falls to 17%. All of those run against a 1% false-positive target, and mathematics content performed substantially worse than psychology, with no figures given. OpenAI's own description is unusually plain: watermarks are often undetectable, especially in short passages, and rewriting or translating text can completely remove the watermark. Eight benchmarks comparing watermarked against unwatermarked output of the Astra model moved between minus 1.12 and plus 3.10 points, which the company reads as no meaningful performance difference.

The scope limits matter as much as the rates. A positive result answers one question, whether a passage was likely generated by an OpenAI model. It establishes nothing about how much a human contributed, who owns the text, who was logged in, or whether any of it is true, and the absence of a mark is not evidence of human authorship. For advertising the gap is structural rather than technical. The EU Code of Practice on Transparency of AI-Generated Content, finalised on July 20 2026, sets a 200-token threshold for required text watermarking, and almost nothing in a campaign reaches it: headlines, meta descriptions, product feed attributes and ad copy all sit below the length at which detection becomes reliable.

The compliance calendar is the reason any of it shipped. Article 50 of the EU AI Act became applicable on August 2 2026; systems launched before that date have until December 2 2026 to reach conformity, and watermark-detection interoperability is due by February 2 2027. The signatures accumulated over the summer, with Google signing on July 24 and Meta on July 28, and the approaches diverge by vendor: Google relies on SynthID, while Anthropic updated its marking policy on August 10 and applied invisible watermarks across five products globally rather than only in Europe. The Commission has even published free labelling icons. What nobody has published is a detector that holds up after a copywriter has been through the draft.

Nine chatbots, 124 tracker domains, and the conversation names that travelled

The most consequential piece of research this week was flagged on LinkedIn by Wolfie Christl of Cracked Labs on October 5 and written up the same day. "Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis of Web and Mobile Conversational AI Agents", by nine authors drawn mostly from IMDEA Networks with one from UC3M and one independent, is formatted for the Proceedings on Privacy Enhancing Technologies and carries a latest dated entry of September 10 2026.

The method was ordinary and the result was not. In May 2026, from Spain, the authors drove ChatGPT, Claude, Grok, DeepSeek, Perplexity, Gemini, Microsoft Copilot, Le Chat and Meta AI through Chrome v148.0.7778.167 with developer tools and an instrumented Pixel 3a on Android 12, varying cookie choices, account tiers and conversation sharing, with health-related and persona-based prompts. Every one of the nine contacted at least one advertising or tracking company. Across web and mobile they counted 124 distinct third-party domains attributed to 44 organisations, of which 34 were classified as advertising and tracking services, split 11 on both platforms, 15 web only and 8 mobile only.

What left the conversation is the part that should concern anyone running a measurement stack. Six of nine web clients disclosed conversation artefacts to third parties, and three of eight Android apps did. Five web providers passed the full conversation URL, three passed the conversation name, two passed the conversation ID alone, one passed the user's prompt and one passed a screenshot. The conversation name is a generated summary of the prompt, which is why it is worse than an identifier: a question about early-stage Parkinson's symptoms became the title "Early Parkinson's Disease Symptoms" in Grok, and a mortgage question became "$85k NYC Salary: $280k-$350k Mortgage". Grok's single conversation reached seven advertising and analytics services, with Meta Pixel collecting the conversation ID, the generated name, the full URL, the share ID and the share URL, tied to a Meta identity through the _fbp cookie. Identifiers such as _fbp, _ttp and _twpid appeared from nine services, and 77.3% of web identifier transmissions occurred only after non-essential cookies were accepted. Hashed email addresses moved too: Perplexity to Singular, Mistral and Claude to Intercom, Grok to DoubleClick, Google Ads and Google Search.

Server-side routing made some of it invisible to a client-side observer. Claude's Segment Analytics traffic ran through the first-party domain a-cdn.anthropic.com, and a Conversions API forwarded user events to eleven services including Facebook, LinkedIn, TikTok, Reddit and Google Enhanced Conversions, with two shared identifiers per event. Grok's Google Tag Manager container sent a custom event carrying the conversation URL and chat topic to Meta's Conversions API and TikTok's Events API along with the _fbp and _ttp cookies. On mobile, 71% of distinct endpoints originated inside WebViews rather than native code, rising to 98% for Grok and 91% for Perplexity, and Firebase appeared in all eight Android apps analysed while Google Ads and Tag Manager appeared in seven web clients. DeepSeek contacted Fengkong Cloud on mobile and ShuMei on the web, neither documented in the WhoTracks.Me database, both linked in public reporting to device fingerprinting and risk scoring.

Consent did not stop it. Rejecting non-essential cookies did not end third-party contact, and Perplexity, DeepSeek, Gemini, Copilot, ChatGPT and Claude all continued contacting Google Ads in that state; the paper carries two different survival figures, 44.4% in one section and 80.8% in the discussion, on different denominators. Ignoring the banner produced the same contacts as rejecting it. Android apps offer no banner equivalent at all. Only ChatGPT's paid tier supports persistent consent preferences, and roughly 95% of ChatGPT users sit on free tiers. Every service exposes shared conversations without a login, with nine third parties present on the sharing pages; Grok's permalinks are accessible by default with an opt-out, Perplexity's guest conversations are always public, and Perplexity stopped sending those URLs to third parties on April 3 2026, three days after a class action alleging secret sharing with Google and Meta was filed. That case was voluntarily dismissed without prejudice on May 1 2026 with no ruling on the merits, and a separate complaint on May 13 alleged that ChatGPT.com forwarded queries to Meta and Google. Grok's own terms have already proved hard to enforce: a court found them too faint to bind a user when xAI sought a Texas venue.

The canary test is the detail that turns leakage into access. Unique URLs planted in prompts were fetched 70 times over hours to days in Grok's case, from 70 IP addresses across 48 autonomous systems in 14 countries, 65.7% of them in the United States although the conversations were held in the EU. DeepSeek, Copilot, Mistral and Claude produced single activations from AWS and Google Cloud at submission. Perplexity's crawler fetched repeatedly even when instructed not to.

The disclosure trail is documented: tracking first noticed in Perplexity and Grok traffic on March 23 2026, systematic testing from April 6, notifications to EU and UK data protection authorities on April 13, a notification to xAI about Grok conversation access controls on April 17, partial findings published on May 4, and Spain's AEPD citing the work on May 27 and asking for escalation to the EDPB plenary of June 6. OpenAI updated its ChatGPT privacy policy on August 15 to mention third-party tracking, which the authors cannot connect to their work. As of September 10, xAI had not responded. The authors are careful about what the data supports, calling the results a point-in-time lower bound, noting that a third party's presence does not prove data was sent for advertising, and declining to offer a legal conclusion, though they set out the ePrivacy Directive's Article 5(3) consent requirement and the Fashion ID precedent that enabling third-party access is itself a processing decision. A UC Davis study they cite measured 20 chatbots, found 17 sharing data with third parties and three leaking plaintext prompts through session replay.

The commercial context is unavoidable. OpenAI reported a $1bn annualised run rate for ChatGPT advertising on August 31, and on September 28 LiveRamp became a technology partner, bringing brands' customer lists into ChatGPT ads across 11 markets through RampID. A Cracked Labs report puts LiveRamp's reach at data on 700 million consumers from 150 providers, identity records on 45 million people in the UK and 25 million in France, and claimed data on 14 billion devices. The paper's narrowest finding is also its sharpest: the artefact that leaked most often was not a cookie but a sentence the model wrote about what the user had asked.

TiVo Ads grew 54% and spent more than it earned

Xperi reported second-quarter advertising results at 8:30 am Eastern on October 5 from San Jose, and the gap between the two headline lines is the finding. Advertising and related revenue reached $14.98m, up 54% year on year, and the cost of that revenue, excluding depreciation, was $16.24m, up 42%. The quarterly shortfall of $1.26m compares with $1.69m a year earlier, so the direction is right and the line has not crossed. Across six months, revenue of $22.34m grew 42% against costs of $24.95m. Advertising represents 13% of Xperi's $114.5m total quarterly revenue.

The engagement figures are large and the per-user figure is not. TiVo One reached 6.3 million monthly active users as of June 2026, up 70% year on year and up 0.8 million from 5.5 million in the first quarter, against a year-end target of 7 million. Annual ad impressions rose 310%, home screen advertising engagement 90%, and monthly FAST viewership on TiVo Channels 320%. Revenue per user, on a trailing four-quarter basis, fell from $7.10 at March 31 to $6.70 at June 30, a decline of roughly 5.6% while the user base accelerated. Elsewhere in the same release, IPTV subscriber households reached 3.4 million globally, up 13%, and cumulative AutoStage vehicle shipments reached 17 million across 13 automotive brands, up 42%.

Matt Milne, Xperi's chief revenue officer and president of TiVo Ads, described advertisers as seeking measurable outcomes, premium experiences, trusted audience intelligence and incremental unduplicated reach, and characterised the year as one of expanding footprint, inventory and audience data. The distribution strategy is resale rather than direct: Kargo integrated on July 31 2025, Nexxen added TiVo inventory to its smart TV home screen network on May 13 2026 for North America and the UK, and Teads reaches 5.3 million households across the US, Canada and the UK. The company also extended enhanced automatic content recognition data across the United States and United Kingdom, combined with clickstream, for campaign planning, audience segmentation, attribution and measurement, without disclosing household opt-in rates or the scope of what is collected.

The reporting pattern will be familiar to anyone who has read TiVo's own quarterly viewing studies: percentages without base figures, devices counted rather than households, and a campaign example in which an unnamed global streaming platform saw monthly app openings rise 70% month on month with no control group disclosed.

PubX buys the compliance half of its own pitch

A smaller transaction made a precise point about trust. PubX, a UK agentic advertising startup, raised $5m in a Series A led by Chicago Ventures and acquired the media quality and governance startup Compliant, with the acquisition price undisclosed by chief executive and co-founder Andrew Mole. The money is earmarked for US expansion, demand-side business development and integrating what Compliant does.

The architecture explains the purchase. PubX's buyer and seller agents transact directly rather than routing through a DSP or SSP, on the basis that legacy platforms were not designed for agent-to-agent interaction, and buyers receive live logs explaining each decision an agent took. Mole's formulation on autonomy is incremental rather than absolute: as trust is earned, autonomy grows. The infrastructure runs on the Ad Context Protocol, the open standard developed through AgenticAdvertising.org, where PubX is a founding member, and Mole drew a contrast with the IAB Tech Lab's ARTF by saying AdCP is committed to building and shipping code. That argument has been running since AdCP first split the industry and has drawn sceptical readings from practitioners who doubt a protocol fixes what the market got wrong.

Jamie Barnard, Compliant's co-founder and for more than fifteen years Unilever's general counsel, becomes PubX's president of global demand growth, and his two lines frame the deal better than the funding figure does. The biggest barrier to adopting agentic tools, he said, will be any uncertainty over whether they can be trusted, and media waste is the worst kept secret in Adland. A company selling autonomous buying has bought the function that documents what the autonomy did, which is the same trade OpenX made in the same week by different means.

What a 300% target in a capped campaign was actually doing

The clearest technical explanation of the week came from a Reddit thread, and it concerns a change that has been live since August 17. Google altered how budget-limited campaigns using Target CPA or Target ROAS behave across Search, Shopping, Performance Max, Demand Gen and Travel, so that they perform more consistently toward the stated target. An advertiser posting as NorskBavian described the consequence on October 5: a campaign carrying a 300% target had been returning 3,000% to 4,000% before the change, a gap of tenfold or more, and after it sales dropped and rankings worsened. A Google representative suggested moving the target closer to actual performance.

The thread then worked out why, which is more useful than the complaint. A commenter named Middle-Economics1508 put it most economically: a budget-limited campaign with a low target was a hack that Google patched out. The old 3,000% returns came from the budget cap rather than the target. A campaign that ran out of money spent what it had on the cheapest, highest-return auctions available, so the target functioned as a floor on auction quality rather than a goal. After August 17 the same campaign bids toward the stated target, which raises cost per click, exhausts the daily budget earlier in the day and leaves later hours uncovered. QuantumWolf99 described the open-budget version of the same mechanic: a 300% target with an open budget chases every auction that clears 300%, so spend expands and blended return slides toward that number. Only_Entertainment88 predicted settlement near 300%.

The reported experience is consistent. An advertiser running a 415% target found the campaign hard limited by budget after the change, and a 40% budget increase produced higher spend, higher cost per click and about half the typical conversions. scottylebot, running two non-brand Shopping campaigns at 325% and 400% that had returned more than ten times, raised targets on August 17 and got 2.2 times from the best one at a 600% target, concluding that the very high returns are gone. flimflambam reported that switching to Maximize Conversion Value restored performance. Sceptics in the thread noted that branded search terms may have inflated the original figures, and one attributed the whole change to a Google aim of lifting cost per click.

The paper trail is long and was all public. Google disclosed the change on June 15 alongside Smart Bidding Exploration expansion and promotion mode, the Bid Target Adjustment Tool arrived on July 6, Google denied any broader Smart Bidding change as the date approached, ads liaison Ginny Marvin confirmed in July that campaigns not limited by budget are unaffected, and on August 12 ad group-level targets were confirmed to fall within scope. App campaigns, video reach and video view campaigns are out of scope. Microsoft Advertising has restated that its campaigns may over-achieve on target CPA and target ROAS regardless of budget-limited status, which means the retired behaviour still exists on a competing platform.

Two complications sit underneath the anecdotes. European auction costs were already rising: Channable's July 12 analysis of 1.38bn euros of Google Ads spend found cost per click up 15% between June 2025 and June 2026, with Performance Max returns down 46% and standard Shopping down 43%. And some campaigns converted to AI Max for Search on September 1, in the middle of the measurement window. One commenter, DecodeTheSERPs, noted the methodological cost of reacting quickly: several strategy swaps in a few weeks meant an account never had a clean read on any of them.

Morning Brew buys a newsletter it has been competing with

Morning Brew Inc., owned by Axel Springer and led by chief executive Robert Dippell, acquired Express Checkout in an all-cash transaction announced on October 5, taking full ownership of the intellectual property and bringing co-founders Nate Rosen and Jenna Movsowitz on as full-time employees. No price was disclosed. Adweek reported the deal the same day as the latest in a run of creator-oriented purchases.

The growth figures carried the announcement in the absence of a price. Express Checkout, launched by Rosen roughly four years ago as a weekly newsletter covering consumer packaged goods, retail and ecommerce, grew revenue fourfold year on year and social following by more than 1,000% over two years, with an Instagram audience above 70,000 and Substack bestseller status. Movsowitz, who joined in 2024 after Rosen asked her to help build what she described as a small side hustle, called the result a full and acquirable business. On the buyer's side, Morning Brew reported creator engagement up 30% over twelve months and creator monetisation up 50% year on year. Dippell described the purchase as the newest franchise inside Morning Brew Inc. and named protecting the Brew tone as the first priority, with Express Checkout material feeding Retail Brew, Marketing Brew, the flagship newsletter, Morning Brew Daily, Maxinomics and Good Work.

Context sets the price range nobody disclosed. Morning Brew started a creator program in August 2022 with seven full-time creators keeping separate brands. Acast bought Backyard Ventures for $20m on August 11 2026 and gained 200 creators. RedBird Capital agreed to buy the newsletter publisher Puck for $250m on September 25 2026. What the Express Checkout announcement left out was the base revenue the fourfold growth applies to, the subscriber count, podcast downloads, existing sponsorship arrangements, and even the publication frequency, on which sources disagree between weekly and biweekly.

326 advertisers, rising budgets, and the same audiences

Taboola published The Data Advantage Report on October 5, and its central finding is a self-portrait of stalled targeting. Qualtrics fielded the survey in August 2026 among 326 senior marketing and advertising leaders, 52% in the United States and 48% in the United Kingdom, all at companies with more than 1,000 employees spending at least $300,000 a month, split roughly evenly across automotive, banking and financial services, and ecommerce. Respondents were 37% vice-presidents, 33% senior managers and 30% directors. No margin of error and no weighting description were published.

Eighty-one per cent agreed their organisation tends to keep targeting the same audience segments over time, 29% strongly and 52% somewhat, even as 77% saw budgets rise over the previous twelve months by an average of 9%. Only 30% named reaching new audiences as the primary outcome sought from the extra money; 70% put it into frequency at 24%, creative testing at 24% or heavier bidding on existing pools at 22%. Seventy-nine per cent described their performance channels as not fully integrated. The stated barriers to understanding open web audiences were limited standardisation of audience and identity data at 35%, third-party cookie loss at 21%, the absence of a privacy-safe identity solution at 17%, fragmented publisher data at 16% and lower reach at 11%. On why budgets stay inside closed platforms, the reasons were spread thin: 18% lower confidence in targeting accuracy, 17% difficulty proving incremental return, 14% satisfaction with other platforms, 13% each for tracking, brand safety and internal process, and 12% a lack of expertise. Forty-six per cent feel pressure to show finance leaders that spend reaches new audiences.

The conditional findings are where the report and its press release diverge, and the write-up says so. The 81% described as openness to increasing spend on publishers and news sites if identity challenges were solved was in fact measured as a standalone attitude before the hypothetical was introduced. A 75% figure presented as difficulty recognising the same customer across touchpoints maps onto chart data in which 56% called it at least somewhat easy and 32% described an active challenge. And the 92% who would shift budget given true closed-loop targeting comprises 32% very likely and 60% somewhat likely, so fewer than a third picked the strongest option. The average stated reallocation to the open web is 28% of current budget, with 43% choosing the 11% to 25% band and 38% choosing 26% to 50%. The report itself supplies the sharpest caveat, noting that it never asked where the additional budget went, so some of the growth may be advertisers spending more to stay in place.

Adam Singolda, Taboola's chief executive, framed the problem as an identity blind spot outside closed ecosystems and the solution as unlocking identity and measurement on the open web. The company sells both halves of that sentence: Realize ID launched on September 22 claiming up to 2.4 times conversion efficiency without disclosed methodology, and clusters cookie IDs, mobile advertising IDs, publisher IDs, hashed emails and RampID into persistent profiles. The commercial pressure behind the research is public: second-quarter revenue of $476.8m came in $15.2m below the guidance floor, and a Google spam policy change removed a product expected to contribute more than $20m in ex-TAC gross profit in the second half, while 2,081 scaled advertisers generated roughly $197,000 each, flat year on year, and display sits at 11% of AdWords impressions against more than 40% in January 2019.

Two external figures in the report do more damage to the identity case than any survey response. Truthset and FreeWheel measured IP-to-postal-address accuracy at 13% on February 28 2026. And a LiveRamp and MMA analysis of July 20 2026 found a campaign with a true return of $1.50 per dollar measured at $0.43 once half the matched users were linked to the wrong person. A report diagnosing an identity problem while selling an identity product is ordinary in this industry; the unresolved question is whether 28% of a budget moves when a named timeframe and a named alternative are attached to it.

Also noted

  • October 6 Google will begin extracting promotional offers from advertiser websites on October 12 and attaching them to Search and Performance Max campaigns that have linked location assets and no existing promotion assets, enrolling accounts by default with one account-level opt-out and re-verifying sourced promotions every 24 hours, with the underlying help document spotted by Hana Kobzova in September. PPC Land
  • October 6 Search Console started emailing site owners their Preferred Sources selection counts as of October 5, the first time Google has shared how many users picked an individual publication to see more often in Top Stories, AI Overviews and AI Mode, bundled with an interactive button and a two-minute survey. Search Engine Roundtable
  • October 5 The Wikimedia Foundation attributed millions of automated API requests, millions of crawled pages on Wikidata and Commons, hundreds of thousands of Wikidata Query Service queries and some potentially malicious edits to citation tool configurations to OpenAI-operated agents, and said the traffic may have played a part in a May 2026 partial outage; bandwidth is up 50% since 2024 and human traffic to Wikipedia fell 8% in a year. PPC Land
  • October 5 Google Ads manager accounts with more than $1,000 of spend and no policy problems can now create new accounts without setting up a campaign first, entering name, type, country, time zone, currency and business details and optionally linking YouTube, Business Profile or Merchant Center, though new accounts no longer accept URLs in the account name. PPC News Feed
  • October 7 Five Gen Alpha and Gen Z shoppers on a Shoptalk Fall panel in Nashville rejected AI-made advertising outright, with a cohort that influences nearly half of household spending in families with children aged 8 to 14 and holds $100bn in annual direct spending power. Digiday

By the numbers

  • $2,500 The civil penalty sought per violation, counted separately for each advertisement served to a child and each interaction billed to an advertiser. Source
  • 73% Share of the most-downloaded ad-supported mobile games carrying AppLovin's SDK as of 2025. Source
  • 17% Detection rate for OpenAI's new text watermark once a quarter of the words have been replaced. Source
  • 6.3 million Monthly active users on TiVo One in June 2026, against a year-end target of 7 million. Source
  • October 12 The date Google starts pulling coupons off advertiser websites into Search and Performance Max campaigns. Source