Origin story

A brief, uncomfortable history of the cookie banner.

How a 23-year-old invented something innocent, and how a trillion-dollar industry turned it into the most annoying thing on the internet.

~8 minute read·June 2026

At some point in the last decade, you clicked "Accept All" on a cookie banner without reading it. Probably this morning. Maybe seventeen times this morning. You did it because the alternative — clicking through three menus to tell a website you'd prefer it not sell your browsing habits to seventeen data brokers — was designed to be painful. That was not an accident. But we're getting ahead of ourselves.

To understand how the cookie banner became the most disliked UI element on the internet, you have to go back to a shopping cart problem in 1994, a European Parliament directive written in 2002, and about thirty years of people optimizing for the wrong thing.

Here's what actually happened.

Chapter one
1994

A 23-year-old had a shopping cart problem.

Lou Montulli was employee number nine at Netscape. He was twenty-three years old and had already built one of the first web browsers. In the summer of 1994, his team faced a problem: the web had no memory. Every time a server received a request from a browser, it had no idea if it had ever spoken to that browser before. This made shopping carts essentially impossible — add something to your cart, load the next page, the server had already forgotten you existed.

The obvious solution — giving every browser a permanent unique ID — was one Montulli explicitly rejected. He worried it would enable tracking across every website a person visited. So he designed something more careful: a small file that a website could store on your browser, but that only worked for that website. Not globally. Not shared. Site-specific, like a coat-check ticket.

He named it a cookie, after a computing concept called a "magic cookie" — a token passed between programs. The first cookie ever set in the wild checked whether a visitor to Netscape.com had been there before. It was, by any measure, completely harmless.

"Cookies were actually designed to explicitly avoid tracking." — Lou Montulli, in a Reddit AMA, decades later, clearly still a little defensive about it

Montulli's privacy instinct was right. His design was sound. What he couldn't control was how the technology would be used by people who had different goals.

Chapter two
1996–2000

The ad industry had a different idea.

Cookies spread through browsers quietly. Internet Explorer adopted them in 1995. By 1996, most websites used them, and most users had never heard of them. The Financial Times ran an article that year revealing cookies existed at all — it caused something of a panic.

The panic faded. The cookies stayed.

Ad networks figured out something Montulli hadn't intended: if the same advertising company served ads on thousands of different websites, their cookie appeared on all of them. That made their cookie effectively cross-site. Not because of how the cookie was designed, but because of who controlled it. Montulli's privacy-preserving design had been turned inside out.

DoubleClick — founded in 1996 — built a business on exactly this. By controlling the ad pixels on thousands of sites, they could build detailed profiles of individual users' browsing habits across the entire web. No consent. No disclosure. No one asking if that was okay.

Chapter three
2002

Europe noticed. And wrote a directive.

By the early 2000s, the EU had been watching the tracking economy grow for years. In 2002, the European Parliament passed the ePrivacy Directive — a piece of legislation requiring websites to get consent before placing cookies on a user's device. The intent was genuinely good. The execution was complicated.

Directives aren't laws. They're instructions to member states to write laws. Each country implemented the directive differently, with different thresholds, different enforcement bodies, and wildly different levels of interest in actually enforcing it. The UK did something. Germany did something else. Several countries mostly didn't bother.

The directive was amended in 2009 to be more explicit about consent requirements. For most of the web, this produced exactly one thing: a thin strip at the bottom of websites saying "This site uses cookies. By continuing to use this site, you agree." Continuing to scroll counted as consent. The ad industry sighed with relief and continued exactly as before.

The banner existed. Nobody read it. Nobody was meant to.
Chapter four
2016–2018

GDPR arrived. And created an industry.

The General Data Protection Regulation passed in 2016 and became enforceable on May 25, 2018. It had teeth. Fines up to 4% of global annual revenue. A serious definition of consent — "freely given, specific, informed and unambiguous." Reject had to be as easy as accept. You couldn't pre-tick boxes. You couldn't make consent a condition of access to a service.

The thin cookie bar was now clearly illegal. Overnight, an entire industry was born to replace it.

Consent Management Platforms — CMPs — sprang up everywhere. OneTrust was founded in 2016 and raised hundreds of millions of dollars. Cookiebot, Osano, and dozens of others rushed in. The banners got bigger. They got more complex. They got designed by compliance lawyers and implemented by developers who'd never read the GDPR and were just trying to not get fired.

72%
of websites still use at least one dark pattern in their cookie banner, according to a 2024 joint study. The banner got bigger. The manipulation got more sophisticated. The compliance got more theatrical.

The banners that emerged were masterpieces of legal compliance and UX manipulation simultaneously. Accept was big, green, and one click. Reject was buried in a settings panel labeled "Manage preferences" that required navigating three screens and individually toggling seventeen sliders. Technically compliant. Functionally dishonest.

Chapter five
2020–2024

Regulators pushed back. Slowly.

Max Schrems — Austrian privacy activist and the person most responsible for two major EU-US data transfer frameworks being struck down — founded NOYB (None of Your Business) in 2017. By the early 2020s, NOYB was filing hundreds of complaints about dark patterns across European websites. The complaints were specific, well-documented, and mostly correct.

Regulators began to move. The French CNIL fined Google €150 million and Facebook €60 million in 2022 for making it harder to refuse cookies than to accept them. The Spanish DPA sanctioned companies for loading cookies before users responded to the banner at all. The Italian Garante went after multiple large publishers.

2022
CNIL fines Google €150M, Facebook €60Mfor asymmetric reject buttons. Making "reject all" harder than "accept all" is now an enforcement target, not just a grey area.
2023
Google Analytics ruled illegal by multiple EU DPAs for transferring data to US servers. The tracker inside nearly every website on earth becomes a compliance liability.
Jan 2024
Google mandates Consent Mode v2 for EU ad serving. Every publisher must use a certified CMP or lose access to personalized ad revenue. Compliance is no longer optional for anyone running Google Ads.
2024
NOYB study confirms 72% of websites still use dark patterns. Six years after GDPR. The enforcement has improved. The behavior has not.
Aug 2025
Cookiebot doubles pricing overnight. From ~€15 to €30/domain/month. Customers are not consulted. The market for alternatives opens up.

The pattern throughout: enforcement moved slowly, the industry adapted quickly, and users were trained to click Accept All reflexively because the alternative was designed to be painful. A 2017 study found that only 3% of users would voluntarily accept cross-site tracking if they understood what they were agreeing to. The consent banner's real job was to never let them understand.

Chapter six
Today

Where we landed.

Thirty years after Lou Montulli's shopping cart solution, the average website greets a new visitor with a modal that:

  • Was designed by a compliance lawyer, not a human
  • Uses legal copy that no one reads and legal terms no one understands
  • Has an Accept button that is larger, greener, and more prominent than any other element on the page
  • Hides the Reject option behind a "Manage Preferences" link that opens a panel with seventeen toggles
  • Claims to give you control while being architecturally designed to ensure you don't use it
  • Costs the company $199/month to operate
  • Has technically complied with GDPR

Meanwhile, the actual question — what does this site do with your data, in plain English— remains unanswered. It's in the privacy policy. Nobody reads the privacy policy.

The banner became a ritual. Everyone performs it. Nobody believes in it.

Montulli, in his Reddit AMA, was asked if he had regrets about what tracking built on his cookies became. He noted that cookies were designed to explicitly avoid tracking. He's not wrong. The technology was fine. What happened to it was a choice made by an industry that realized users' attention was worth money, and that it was easier to confuse them than to ask honestly.

The consent banner
that runs on AI.

Free for Vanta customers.

⊗ Dissent Consent

The consent banner your visitors won't immediately click through without reading.

© 2026 Dissent ConsentTerms of Use