Consent Management Tools
I've tested many consent management tools, and most are selling snake oil. The problem isn't the EU.
In the following example (Screenshot 1), a popular consent management tool automatically scanned my specifically prepared website and detected the absence of a banner—not whether one was necessary. Its report then recommended a "Cookie-Banner" (literally). My test site doesn't set any cookies at all. But the tool doesn't read the privacy policy sitting right there or grasp the context of what's actually required. It gets even weirder: the tool scored my site at 12%, but that simply means only 2 of 17 checks passed. Most of the "failures" are questions that don't apply to my site but were still counted against me. A site with zero cookies and no tracking, branded 12%.

Screenshot 1: The scanner gives a cookie-free test site a 12% score because only two generic checks pass.
The second screenshot shows another consent tool that randomly invented preferences for third-party vendors. The correct output in both cases would have been "you're fine," but the tools instead concluded, "you're failing."

Screenshot 2: The generated banner lists Google and Intercom even though neither vendor is present.
Almost every consent management tool I tested creates a false sense of absolute necessity by framing your site as a compliance failure.
Every tool I tested uses at least a handful of misleading social engineering techniques. The overall scheme is "manufacture a problem, then present yourself as the cure": fear-first framing; manufactured deficiency and false positives; borrowed authority combined with unconditional "musts"; presumptive possession; false visual hierarchy; verbal effort asymmetry; hedged, unfalsifiable threats; pseudo-rigor as credibility; and more. Unfortunately, this is the new "normal"; it's the house style of the entire compliance SaaS category. But beneath all of these techniques is information asymmetry: the scheme only works if you don't know that the requirement for consent is conditional and highly dependent on context and use case. Many people whose job it is to know this stuff simply don't.
Legally Required Cookie Banner?

A tongue-in-cheek banner for a site that uses one first-party cookie and sends no data to third parties.
This screenshot shows the "cookie banner" of a popular U.S. company that provides analytics and consent management services. Did you know that cookie banners are not, in themselves, legally required in the EU? Consent—not a banner—is legally required if a website or app chooses to store or process non-essential data. Ursula von der Leyen would not be proud.
So what is the actual "cure"?
If you're building a digital product—whether a website, web tool, or digital business—your job is to understand its data processing, privacy, and security requirements and build them into the product from day one. Don't hand the problem to a consent tool as an afterthought.
This article was originally published on LinkedIn in a slightly shorter form.