Data Measured

9 Jul 2026 · GTM · medium severity · fix verified 9 Sept 2026

Container behavior for unsupported installation paths (/gtag/js, /gtag/destination)

'Previously, these containers degraded to a restricted state where only Google-provided tags and variables were permitted to run. Moving forward, the ID used to load the container will control this behavior.'

Source: Google Tag Manager release notes — Jul 9, 2026.

What it breaks

Containers loaded through a gtag path that relied on the restricted state now run everything; consent-gated custom tags may fire where they did not before.

Who it hits: Sites that load GTM through gtag.js snippets or a tag-management proxy.

The fix

Check how the container is loaded (menu path in the checklist) and confirm consent gating on every non-Google tag.

fix artifact · #A-006

Screenshot-free GTM checklist

Every step named by menu path, never by picture — it survives the interface redesigns that make every screenshot guide wrong.

verified_on
2026-09-09
next re-check
2026-12-01
status
current

Open the artifact →

Sources linked on every entry · artifacts stamped and re-verified · ← all changes