Three unrelated headlines landed in the past ten days, and they all say the same thing. The platform ships the capability. The advertiser owns the consent, the disclosure, the tag behavior, and the evidence when someone asks for it.
Google began identifying European devices by IP address for advertising on or shortly after August 3, and told publishers and advertisers they remain responsible for valid consent (PPC Land). The FTC, joined by Utah and Los Angeles County, sued Hims & Hers on July 29 over health data that its own pixels and customer lists sent to Meta and Snap (FTC). And on August 2, the EU began enforcing AI Act transparency rules that reach advertisers with no European office at all (European Commission). None of these are about the same product, the same regulator, or the same industry. All three move the same liability to the same desk.
The incumbent assumption
Marketing has treated the ad platforms as compliant infrastructure. If Google enables a targeting capability, if Meta accepts a customer list, if a generative tool produces an asset that clears brand review, the assumption has been that the platform's terms and the vendor's certifications carry the legal weight. Privacy and AI compliance get a once-a-year pass from legal, and marketing's job stays performance.
That assumption was never fully true, and this week it stopped being survivable.
The cost and consequence ladder
Get this wrong once, and a consent notice is out of date. Get it wrong twice, and a regulator names the brand, not the platform, as defendant. Get it wrong three times, and a compliance obligation with a penalty tied to worldwide revenue applies to a company that never opened an EU office.
Start with what changed this week. Google added a new consent-relevant purpose, device identification by IP address, to its European ad stack, and pointed the disclosure obligation at the advertiser (ghacks). Most consent management platform notices were written before that purpose existed. That is not a hypothetical gap. It is a gap that exists in production right now, on live European traffic, for every brand running paid media, measurement, or retargeting into the region.
Move to what enforcement looks like when the gap gets found. The FTC's complaint against Hims & Hers describes pixels and SDKs that automatically transmitted "Events" to advertising platforms, and customer lists that identified consumers by health condition or treatment type, then names the brand as the party that made deceptive privacy claims (National Law Review). This is an allegation, not a ruling. There is no judgment and no penalty amount yet. What it proves without a verdict is the mechanism regulators now use: your own tag manager becomes the evidence file, and your own influencer scripts become enforceable privacy representations.
Extend the ladder forward. From August 2, the EU AI Act's Article 50 transparency rules apply to organizations with no EU presence whose AI-generated output reaches EU audiences, with a maximum penalty of 15 million euros or 3 percent of worldwide annual revenue (Davis+Gilbert). Human editorial review of AI output is no longer a quality step. It is a compliance control with a fine attached to skipping it.
The evidence, read plainly
Two independent sources confirm the identifier change and its language. Google's own service email, quoted by PPC Land, added TCF Feature 3, "identify devices based on information transmitted automatically," and told publishers they remain bound by Google's EU User Consent Policy, which requires accurate disclosures and legally valid consent from end users in the EEA, the UK, and Switzerland (PPC Land). An independent report confirms the same responsibility-shifting language and adds that user-facing controls over IP-based personalization will not arrive until later this year or early next (ghacks).
Two independent sources also confirm the enforcement mechanics. The FTC's release quotes Bureau of Consumer Protection Director Christopher Mufarrige describing "consumers unknowingly locked into recurring subscriptions and the disclosure to third parties of consumers' most private health information without their consent" (FTC). Independent legal analysis of the same filing confirms the venue, the statutes invoked, and advises advertisers generally to audit pixels, SDKs, cookies, and server-side integrations, and to evaluate whether condition- or treatment-segmented customer lists could be construed as disclosing health information (National Law Review). This is a complaint, and the fact pattern is health-vertical specific. The mechanism it exposes, ordinary pixels and audience lists treated as the instrument of an unlawful disclosure, is not vertical-specific at all.
The same platform-changes-the-system pattern shows up in a fourth, smaller example. Starting August 17, Google's budget-limited Target CPA and Target ROAS campaigns will perform toward the stated target instead of beating it, and Google has confirmed it "will not automatically adjust your bidding targets or budgets" (Google Ads Help). The platform changes the mechanics. The advertiser owns the remediation, every time, regardless of whether the stakes are a bid target or a federal complaint.
The labeled binary
This is not a privacy problem that legal will eventually solve. It is a marketing operations problem that legal cannot solve alone, because legal does not touch the tag manager and the media team does not read platform terms of service.
That is not a compliance gap. That is an ownership gap. Someone has to own the register of what every martech and ad integration transmits, under what consent basis, with what disclosure, and who signed off on it. Right now, in most organizations, nobody does.
The operational decision
Assign a named owner for marketing-side compliance evidence this week, not after the next filing makes it urgent. That owner's first deliverable is one artifact: a current inventory of every pixel, SDK, customer-list upload, and AI-generated asset workflow, mapped to its consent basis, its disclosure language, and the person who approved it. The decision in front of you is not whether to become more careful. It is whether that register lives in marketing operations with a budget and an owner, or nowhere at all.
Build the register before the next platform email arrives telling you that responsibility for the next capability is yours too.
The verdict
The platforms are not going to slow the pace of what they ship, and the terms attached to it are not going to get more generous. Google did not ask advertisers whether they wanted a new identification method live in Europe this week. The FTC did not ask Hims & Hers whether its pixels were configured the way its privacy policy claimed. The only variable an executive actually controls is whether the evidence exists before someone asks for it.
Magnet's tracking and data foundations practice builds exactly this register: GA4 and GTM configuration audits, pixel and event inventories, consent-mode and CMP review, and audience-list hygiene, so the conclusion above becomes a scoped engagement instead of an open question. Talk to Magnet about a tracking and data foundations audit.
Sources
- PPC Land: Google to bring IP-based ads to EEA publishers from August 3
- ghacks: Google to use IP addresses for ad personalization in UK and EU starting August 3
- FTC: FTC, states act against Hims & Hers over deceptive, unlawful privacy practices
- National Law Review: FTC and states sue Hims & Hers over deceptive health data sharing and subscription
- European Commission: Commission starts enforcing AI Act rules and new transparency requirements from 2 August
- Davis+Gilbert: EU AI Act guidance expands AI disclosure rules for advertisers and PR teams
- Google Ads Help: Smart Bidding for budget-limited campaigns


