What it is
GTM loads once and then creates other tags according to rules held in Google’s interface. That is the point of it: marketing can add a pixel without a release. It is also the hazard, because the list of what your site loads is no longer in your repository and no longer matches whatever you verified last quarter.
The scanner gives tag managers their own category for this reason. Calling a container "analytics" or "advertising" would misstate it: its consent implications depend entirely on its contents.
What a scan matches
A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Google Tag Manager is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.
- googletagmanager.com: the container itself
- tagmanager.google.com: Google’s tag-management interface and related services
- googletagservices.com is classified separately as Google Publisher Tag because the host is commonly used for advertising delivery rather than the GTM container
Controlling it with consent
The adapter loads the container with denied Google Consent Mode defaults established before any tag runs, then sends consent updates as the visitor’s selected categories change, and updated denied states on withdrawal. Ordering is the whole game: defaults set after the container has loaded are defaults the tags never saw.
Setting consent requirements on the individual tags inside the container is work that has to happen in GTM, not here. GA4, Meta, TikTok and every other tag needs its own consent setting. Tags that ignore consent entirely, and advanced-mode cookieless behaviour, need manual review.
This one has a first-class adapter
Enter the identifier in the property’s technology list and the runtime applies that adapter’s control strategy. Depending on the vendor, that means withholding the loader, establishing denied defaults, or loading a functional surface with tracking opted out; the article above describes the exact behavior. Remove copies installed in a theme, plugin, app or tag manager first, or another installation can remain outside that control.
What breaks if it is refused: depends entirely on what is inside. Containers frequently carry functional tags (a chat widget, a scheduling embed), which is exactly why blocking the container wholesale is the wrong instrument.
Verifying it
Use GTM Preview alongside the browser network panel, and check every individual tag rather than only the container. Look specifically for duplicates and for non-Google vendors that do not participate in Consent Mode at all.
- Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
- After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
- After granting the relevant category: the expected loader or embed appears and the feature behaves normally
- After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior
Common questions
Should I block the GTM container until consent?
Usually not. Load it with denied defaults and gate the tags inside. Blocking the container tends to break functional tags and hides what is actually happening rather than controlling it.
Does Consent Mode cover non-Google tags in the container?
No. Consent Mode signals are read by Google tags. A Meta pixel or a chat widget inside the same container needs its own trigger condition or its own consent check.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Google: set up consent mode on websites
Vendor documentation
Checked
- Google: consent mode reference and consent types
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.