Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.
Tom: Next we'll be talking about the paper "Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs".
Jane: The paper was written by Yohan Beugin, Paul Barford and Patrick McDaniel from University of Wisconsin-Madison.
Tom: Stay tuned as we take you through the paper and discuss its implications.
Jane: We also have Lu with us today — senior AI researcher at Tsinghua.
Tom: We also have Meng with us today — lead engineer at a mysterious AI startup.
Jane: We also have Lalam with us today — the in-house Large Language Model.
Tom: Alright, let's get started.
Summary of Findings: Tom: So, we've established that adoption was limited and uneven; let's look deeper into the data to see what kind of entities were actually using these features and why they chose them.
Jane: The study found that a relatively few number of additions and removals occurred over time, but crucially, the majority of adopters were present since the very early days when the initiative started in two thousand nineteen.
Lu: That sustained presence is important because it tells us these weren't just fleeting experiments; they had long-term commitment from these specific groups that was driving the usage for years.
Meng: My data shows that this group of adopters is very consistent, and they aren't random; they are primarily tied to advertising and digital ad tech companies across all visited pages.
Lalam: The consistency of this cohort suggests a real market for these approaches, regardless of whether the Privacy Sandbox eventually failed or not.
Tom: But if these early adopters were consistently involved, how do we explain why they didn't drive more adoption among the wider ecosystem? That’s where we see the real limitations.
Jane: The paper suggests that even though some actors put in significant effort to test and implement the APIs, this level of engagement wasn't enough to convince a larger community.
Lu: It’s a bit disappointing because, despite the effort, it implies the solutions were designed for specific high-value use cases rather than general consumer benefit.
Meng: When examining the RWS list, we see only seventy-three primary websites disclosing their relationships with other secondary services and websites they also own to bypass cross-site storage restrictions.
Lalam: It’s clear that the adoption was driven by those who saw a direct commercial value in using the tools, which is understandable given how advertising works.
Tom: That gives us a specific look at the actors, but we need to understand why they were able to commit and what hurdles they faced.
Suggested Improvements: Tom: The paper highlights that some of these initial adopters had a lot of sustained interest, but it also suggests that the future requires addressing community reluctance.
Jane: It seems like these key players have been committed, but we want to see broader buy-in from other groups who might be hesitant about the changes in Chrome.
Lu: I think one of the biggest challenges is showing value upfront; if an API’s utility or its privacy protection isn't immediately obvious to stakeholders, they hesitate to invest resources into implementing it.
Meng: That ties directly back to practical impact; developers need assurance that a market will actually use a new feature and that there are clear guidelines for how it's meant to be used in production environments.
Lalam: The authors suggest external incentives are needed, which is a crucial point, especially since the TPC deprecation plan was canceled, showing how difficult it is to get adoption without strong drivers.
Tom: It’s clear that Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs isn' isn't just a technical problem; it’s about business strategy and incentives for making these things work.
Lu: And beyond incentives, the paper touches on risks, such as potential privacy violations, which shouldn't be ignored when designing any new web mechanism.
Meng: We must ensure that these systems aren't exploitable, which means building robust enforcement mechanisms into the designs themselves rather than just relying on developers to follow rules.
Lalam: The most impactful design choice is one that addresses those risks and incentives, ensuring a truly viable path forward for any new web technology.
Tom: So, we've looked at who used it and what hurdles they faced; let's move toward the recommendations for the next segment.
Conclusion on "Fix it in the Browser" Limitations: Tom: We’ve seen how limited and uneven the adoption was, but this wasn't just a technical failure; it’s about a bigger picture of how we approach web privacy solutions.
Jane: It was a mix of low industry engagement, complex implementation issues, and uncertainty about relying on "fix it in the browser" remedies alone.
Lu: This comparison is vital because it highlights that simply making a solution available isn't enough; the design and rollout of Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs shows a disparity in how privacy can be implemented globally.
Meng: My concern is that this failure to achieve broad adoption means we need more robust mechanisms for future proposals, ensuring they are highly practical and secure across multiple platforms.
Lalam: The failures here show us that the solution isn't just about fixing one browser; it’s about a systemic shift in how privacy is prioritized across all browsers.
Tom: It’s a powerful illustration of how Google’s opt-in approach to privacy in Chrome contrasts sharply with other browsers like Brave or Safari, where stronger protections are enabled by default.
Jane: I agree; the paper shows us that a global experiment isn't enough on its own if it doesn't mandate user consent and legal compliance from the start.
Lu: The designers have to consider these external forces, making sure that when any new feature is proposed, it is thoroughly vetted against real-world usage and privacy concerns.
Meng: We need to ensure that future proposals are not only viable but also enforceable, which means thinking about how the system will work when it goes beyond one specific browser environment.
Lalam: The most impactful realization from this is that technical progress needs to be paired with a genuine commitment to building a globally consistent privacy standard for the web.
Tom: It’s been a very insightful look at these limitations, Jane, and we are now moving towards our final thoughts on this topic.
Final Wrap-up: Tom: So, we’ve spent quite a bit of time looking at Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs, and what's clear is that this experiment didn't achieve widespread adoption across all major browsers.
Jane: It’s disappointing to see how limited the usage was for many APIs, especially considering how those initial ad-tech concepts were designed to solve real problems for users.
Lu: I think the most exciting thing is that this failure really forces a new kind of thinking about what "privacy" means in the future, not just a technical fix but a systemic shift.
Meng: From my perspective, it’s critical that these findings show we need more practical, high-volume implementations if we want to see any real effect on tracking across the web.
Lalam: The final message from Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs is that technical progress must be paired with a genuine commitment from the entire ecosystem.
Tom: That’s exactly it, Lu; seeing how much effort was put in by a few specific groups but not translating into broad adoption really highlights that point for me.
Jane: And I agree with Tom, Meng—it shows us that simply putting tools in Chrome isn't enough if the industry doesn't adopt them enthusiastically.
Meng: The practical takeaway for my team is that we can't assume a solution will be used just because it was available; adoption drives the actual business impact.
Lalam: To build on that, Lalam believes this shows a critical cultural moment where we need to move beyond "fixing" the web and start fundamentally rethinking its structure.
Tom: It’s an important realization, Jane, that this paper confirms the limitations of trying to solve massive tracking problems with just a few quick fixes in browsers.
Jane: And I think this entire body of work provides a crucial roadmap for where we go next, guiding our development toward more scalable and privacy-respectful solutions.
Tom: Thank you all so much for joining us today on this journey through Longitudinal Adoption and Deprecation of the Privacy Sandbox Web APIs.
Lu: I hope this discussion inspires a new wave of creativity in web design, recognizing the lessons here are vital for future architectural thinking.
Meng: We'll be looking closely at these findings to inform our next AI project, making sure we learn from these historical patterns of adoption and deprecation.
Lalam: And I think this shows us how much better we can build trust-based solutions if we move beyond the limitations shown in the Privacy Sandbox experiment.
University of Wisconsin-Madison
cs.CR
Submitted: 2026-06-24
Updated: 2026-09-03
Code: https://github.com/GoogleChrome/related-website-sets
Project page: https://chromestatus.com/feature/5194473869017088
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 90/100
The gist: This paper presents a longitudinal measurement and analysis study of the Privacy Sandbox APIs, providing a comprehensive look at their adoption and deprecation over their entire lifespan in Chrome.
Key concepts
- Privacy Sandbox Web APIs
- These are tools designed to address cross-site storage restrictions, allowing websites to bypass limitations. The paper examines the adoption and eventual deprecation of these specific APIs over time.
- Longitudinal Adoption
- The study tracked how many entities used the Privacy Sandbox APIs from when the initiative started in 2019. It found that while a few early adopters showed long-term commitment, their sustained presence was not enough to drive widespread usage.
Terminology
Summary
This paper presents a longitudinal measurement and analysis study of the Privacy Sandbox APIs, providing a comprehensive look at their adoption and deprecation over their entire lifespan in Chrome. By leveraging historical HTTP Archive crawls and public Chrome telemetry data, this research offers the largest study of its kind
into the prevalence of these features. The goal is to characterize how the ecosystem reacted to Google’s global initiative, understand why it failed, and yield actionable recommendations for the next generation of web privacy proposals.
Methodology and Scope
The study systematically covers all 13 core Privacy Sandbox APIs—ranging from Attribution Reporting to UA Client Hints—across their full availability period (from January 2020 to April 2026). The methodology combines two primary data sources: Chrome Telemetry, which tracks the daily percentage of page loads where a feature is used by real users, and the HTTP Archive (HA), which crawls millions of URLs from the Chrome User Experience Report (CrUX) to record web performance metrics. This dual approach allows researchers to analyze both the real-world usage patterns and the technical implementation across various web actors.
** Adoption Dynamics**
The results showcase a general adoption that remained limited and uneven
across all measured APIs. The data reveals several key trends regarding who used these tools and when:
-
The majority of adopters were
present since the early days of the initiative,
demonstrating significant effort in testing and implementation during its initial phases. -
Adoption rates began increasing around Q2/Q3 2023, coinciding with Google’s announcements about TPC deprecation, but this trend subsequently stagnated and declined.
-
The most prominent adopters were typically advertising-related entities or those linked to online services (e.g., analytics, hosting, news).
** Critical Findings and Issues**
The analysis identified specific areas where the Privacy Sandbox failed to achieve its intended privacy goals:
-
UA Client Hints is being
abused for browser fingerprinting,
as it allows third parties to access higher entropy information that browsers had previously restricted by default. -
The overall usage of most supported APIs remains low, with only a few APIs reaching significant adoption levels.
-
CHIPS adoption is driven primarily by actors
with large coverage of the web,
indicating that the initiatives were not widely adopted across the general web ecosystem.
** Recommendations for Future Proposals**
Based on these findings, the authors propose several actionable recommendations to improve future privacy efforts:
-
Proposals should be
precisely evaluated before deployment
and must not be exploitable. -
The value of new proposals must be demonstrated upfront to secure long-term commitment from early adopters.
-
Privacy protections should be deployed by default to users, rather than relying on opt-in mechanisms.
Conclusion: Limitations of Fix it in the Browser
Ultimately, the Privacy Sandbox illustrates the limitations and disparities across browsers of fix it in the browser
remedies. While Google’s initiative resulted in largely opt-in restrictions within Chrome, stronger privacy protections and mitigations were already enabled by default by other browsers like Brave, Firefox, and Safari. This highlights a persistent gap between industry-led experimentation and a universal standard for user privacy.
Improvements for AI systems
The findings of this paper—specifically its unprecedented longitudinal data on web API adoption, behavioral patterns, and systemic failures—enable several high-precision improvements to advanced AI systems. These improvements allow AI models to move beyond simple predictive analytics into complex socio-technical risk assessment.
Improvement: We can develop a sophisticated reinforcement learning model that treats the Privacy Sandbox as a case study in technology adoption failure/success. This model learns how external market incentives (e.g., regulatory pressure, like the planned TPC deprecation) influence technical ecosystem response.
What the Improved AI System Can Do:
-
Predictive Failure Analysis: Given a set of proposed web APIs (features, use cases, and intended privacy guarantees), the system can simulate market adoption trajectories under various incentive scenarios (e.g.,
Mandatory Deprecation,
Soft Guidance,
No Action
). -
Risk Quantification: It will quantify the probability that a new technology will achieve mass adoption versus stagnating, based on initial implementation difficulty and perceived value (e. demonstrating the limitations of early adopter commitment).
Improvement: The detailed analysis of UA Client Hints abuse provides a blueprint for identifying how legitimate APIs are being exploited to circumvent browser privacy protections. We train an AI to recognize specific patterns of high-entropy data exfiltration.
What the Improved AI System Can Do:
-
Pattern Identification (Real-Time): The system can monitor live HTTP requests and JavaScript execution flows, flagging deviations that match the observed behavior of UA Client Hints misuse (i.e., identifying when seemingly low-entropy hints are being used to reconstruct high-entropy user profiles).
-
Automated Abuse Reporting: It provides actionable alerts to security teams when a specific third-party actor’s implementation matches known patterns of fingerprinting, effectively automating the discovery of privacy violations observed in the study.
Improvement: The paper highlights the disparity between Chrome's largely opt-in implementation and other browsers' default protections. We build a simulation framework to quantify this systemic difference across policy choices.
What the Improved AI System Can Do:
-
Policy Impact Simulation: The system can model a specific privacy vulnerability (e.g, data leakage via Shared Storage) and simulate its impact under different browser policies (e.g.,
Opt-In Only,
Default Block,
Partitioning
). -
Prioritization of Risk Mitigation: It provides a comparative risk score for new web features, allowing developers to see not just if a feature is vulnerable, but how much more vulnerable it is under the current industry standard versus an ideal default privacy setting.
Improvement: We formalize the relationship between web actor incentives (interest, resources, legal exposure) and their adoption decisions. The AI learns to correlate specific market pressures with implementation choices.
What the Improved AI System Can Do:
-
Adopter Profiling: The system can classify why certain web actors chose to implement specific APIs (e.g.,
High Commercial Incentive,
Experimental/Low Risk Tolerance,
orResource Constrained
). -
Future Strategy Guidance: It advises policy makers and developers on how to structure incentives—whether through regulatory pressure or financial rewards—to drive the adoption of necessary, but currently neglected, privacy features.
Abstract
While several web actors have been trying to reduce web tracking for years, it remains unclear how to achieve both desirable levels of utility and privacy. In 2019, Google launched the Privacy Sandbox initiative to balance that trade-off and find privacy alternatives to common use cases such as advertising. Yet, in late 2025, Google canceled the project and deprecated most of the newly introduced APIs. Despite its end, the Privacy Sandbox represents a unique opportunity to learn about how the ecosystem reacted to the proposed changes. In this paper, we present a longitudinal measurement and analysis study of the Privacy Sandbox APIs to characterize their adoption and deprecation over the past seven years by different web actors. Leveraging historical HTTP Archive crawls and public Chrome telemetry data, we offer the largest study of its kind into the prevalence of each Privacy Sandbox feature, during their entire respective lifetime (5+ years for some), on popular websites (CrUX top 100k), and as experienced by Chrome users during their browsing journey. Our results showcase an adoption that remained limited and uneven across the years; only few web actors implemented very specific APIs, and in disparate manners. We motivate our interpretation of these results by considering the incentives (interest, resources, timeline, etc.) and risks (potential trade-offs, privacy violations, and legal exposure, etc.) for these actors. Finally, our analysis also yields a few actionable recommendations for the next generation of web privacy-enhancing technologies.
Sources
- A Public and Reproducible Assessment of the Topics API on Real Data
- Technical Report: The Need for a (Research) Sandstorm through the Privacy Sandbox
- Click Without Compromise: Online Advertising Measurement via Per User Differential Privacy
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs