The implication: purely client-side CMPs may be insufficient if high-volume agents fetch HTML without running JavaScript. Server-side allow/deny lists are back in fashion.
Publishers should log consent state at the edge for first-party APIs, not only for display ads.
Coordinate with security: aggressive blocking without telemetry can mask legitimate monitoring agents your SOC relies on.
