A change to tracking rules can prompt two poor responses: update the banner and declare the work complete, or collect as much first-party data as possible and call it an AI foundation.
A better response starts with purpose. What decisions does the firm need to make? Which data is necessary and appropriate? What must clients and prospects understand? Which uses would remain unacceptable even if the technology allowed them?
That creates an opportunity to improve data architecture and governance. It does not make every compliance project an AI programme.
Replace the obsolete cookie story
The source predicted an imminent universal “death of third-party cookies” and tied strategy to Chrome market share. That chronology is no longer a safe basis for investment.
Browser behaviour, platform controls, consent requirements and enforcement continue to change. The enduring task is to maintain an inventory of storage and access technologies, advertising and analytics tags, server-side collection, SDKs and downstream recipients.
For UK implementation, use the ICO's current guidance on storage and access technologies, published in final form in 2026, together with current UK data-protection guidance and legal advice. Financial firms must also consider sector duties, client confidentiality and any relevant jurisdiction beyond the UK.
A vendor's classification of a tag as “essential” or “cookieless” does not determine the legal result.
Audit data flows before changing the interface
A banner is one control in a larger system. Create a current map covering:
- technology and provider;
- data collected or accessed;
- device and user identifiers;
- purpose;
- legal or permission basis;
- where and how long data is retained;
- recipients and international transfers;
- controls available to the person;
- owner and review date;
- behaviour when permission is absent or withdrawn.
Test what happens, rather than relying on configuration labels. Tags can load before a choice, consent states can fail to reach another system and old scripts can remain after a campaign ends.
Use browser inspection, tag management, contracts and system logs as evidence. Repeat the review after material releases.
First-party does not mean unrestricted
Data collected through the firm's own relationships may be more traceable than brokered audience data. It is still subject to purpose, fairness, transparency, minimisation, security, accuracy and retention requirements.
A wealth manager may hold detailed information because it is necessary to provide advice. That does not automatically permit reuse for behavioural targeting, model training or retention prediction. A prospect reading an article does not necessarily expect that event to alter the way an adviser treats them.
Separate service data, marketing permissions, analytics and research. Define acceptable connections and prohibited combinations. Give people meaningful controls where required and respect them across systems.
The strategic opportunity may be to reduce data, remove opaque suppliers and improve lineage, rather than create a “360-degree view”.
Consent architecture is a service
Where consent is the appropriate basis, manage it as a lifecycle. Capture the specific choice, source and time; propagate it to relevant systems; allow change; suppress uses; retain suitable evidence; and test withdrawal.
Consent is not always the correct basis, and one marketing choice does not cover every use. Legal and data-protection specialists should define the framework for actual purposes and jurisdictions.
Design the user interaction in clear language and avoid manipulative defaults. Refusing optional tracking should not block an unrelated service. Accessibility applies to preference tools too.
A central preference service may help. It creates a critical dependency that needs ownership, access control, monitoring and recovery.
Unify only what the decision requires
System integration can provide a more coherent view and reduce manual mismatch. “Put everything in one customer profile” is not a sufficient requirement.
Begin with a decision. If the firm wants to understand which content helps prospects prepare for a first conversation, define the minimum events and volunteered context required. Aggregate or de-identify where possible. Test whether the insight changes a useful action.
For a known client, service context may remain separated from marketing context by policy and access. Technical connection does not require universal visibility.
Define systems of record, identifiers, matching confidence, correction and deletion. False matches can combine two people's behaviour and create both poor service and privacy risk.
Progressive profiling can become pressure
Asking for information over several interactions may reduce form effort. It can also create an unexpectedly detailed profile.
Each request needs a clear purpose and value to the person. Do not infer sensitive traits from content use or gradually assemble fields merely because the CRM has space. A useful guide need not always be gated.
Explain what is optional and avoid asking a prospect to disclose sensitive financial circumstances through a marketing form. Move consequential information into an appropriate secure service with professional oversight.
The AI connection is conditional
Well-governed data can support AI uses such as approved knowledge retrieval, document classification, service triage or quality monitoring. Tracking reform may improve inventory, lineage, permissions and system ownership that those uses also need.
That overlap does not mean consent records are “training data”, or that a connected marketing profile should feed personalisation automatically. AI introduces additional questions:
- Is the proposed use compatible with the original purpose?
- Does it infer sensitive or consequential information?
- Can people understand and challenge the effect?
- What data reaches the model provider?
- How are outputs evaluated for accuracy and discrimination?
- Who reviews and remains accountable?
- Which records and logs are necessary?
- How are model and supplier changes controlled?
Use the ICO's AI and data-protection guidance and relevant sector governance. Assess each use separately.
Avoid three seductive examples
The source proposed content recommendation, automated adviser routing and prediction of clients considering departure.
A recommendation can be low consequence or manipulative depending on content, profile and effect. Test usefulness, explain personalisation where appropriate and provide a neutral route.
Triage can improve handling, but routing a financial-services enquiry may affect access to expertise. Use explicit criteria, monitor errors and provide human correction. Do not infer complexity or vulnerability from weak behavioural signals.
Retention prediction is especially sensitive. Declining engagement has many explanations. Labelling a client as likely to leave can change treatment and create a self-fulfilling result. A direct relationship conversation based on service evidence may be safer and more useful than an opaque score.
AI opportunity should not become a reason to expand tracking into higher-consequence profiling.
Build one investment case without double counting
The same data capability may support compliance, measurement and a future AI use. Show the shared dependency and avoid counting its full benefit three times.
Separate mandatory risk treatment from optional commercial capability. The board should see:
- the current compliance or control gap;
- the data and architecture change required;
- costs shared across purposes;
- incremental cost for each use;
- evidence of benefit;
- residual risk;
- ownership and review;
- options to stop at the compliant baseline.
This lets leaders approve a sound foundation without being forced to believe an untested AI return.
A practical sequence
- Inventory tracking and data flows.
- Remove redundant collection and suppliers.
- define purposes, permissions and ownership.
- Repair consent or other control implementation.
- identify one measurement decision the data should support.
- Improve quality and integration only to the required boundary.
- Evaluate any AI use as a separate consequential service.
- Monitor changes in technology, law, suppliers and behaviour.
Document what is intentionally not connected or reused. Good architecture contains boundaries as well as pipelines.
The source included an unnamed financial-services case, a CTO quotation, fixed lead-quality timing and several vendor statistics. Hold them until engagement records, permission and definitions are available.
Second, map the gaps between where you are and where you'd need to be for AI to work. This doesn't require an AI strategy - it requires an honest assessment of data quality, connectivity, and governance. Our AI Readiness scorecard is a good place to start if you want a structured way to benchmark yourself.
The opportunity in tracking change is the chance to replace accidental collection with governed, decision-useful data. AI may benefit from that work where a suitable use passes its own value and risk test.
There's a companion piece in Section 4 of The Briefing Room that covers how to build the business case for this kind of investment and get it past a board that's sceptical about spending on "infrastructure." Worth reading if the challenge isn't knowing what to do but getting approval to do it.


