Google Topics Is Retired: What Actually Changed
Chrome never blocked third-party cookies, and Google retired the Topics API in October 2025. Here is what changed, and what still matters.
The original version of this post was written in 2023, when Chrome was on track to block third-party cookies and the Topics API looked like the thing that would replace them. Both of those things stopped being true. Third-party cookies still work in Chrome, and Google retired the Topics API in October 2025. What follows is the current state of the story, and the parts of the privacy argument that still hold.
The premise that expired
Google first said in January 2020 that Chrome would block third-party cookies within two years, and built the Privacy Sandbox as the set of browser APIs meant to take over ad targeting and measurement once cookies were gone. That plan went through several reversals. In July 2024 Google dropped the fixed deadline and proposed a user choice prompt instead. On 22 April 2025, Anthony Chavez, Google's VP of Privacy Sandbox, wrote that Chrome would "maintain our current approach to offering users third-party cookie choice in Chrome" and would not roll out the standalone prompt at all. Third-party cookies stay in Chrome, blocked by default only in Incognito, and otherwise controlled through Privacy and Security settings. That announcement is here.
Six months later the replacement stack followed. On 17 October 2025 Google announced the retirement of ten Privacy Sandbox technologies, naming low adoption and ecosystem feedback as the reason. The retired list covers the Attribution Reporting API, Protected Audience, Protected App Signals, Private Aggregation and Shared Storage, Related Website Sets, SelectURL, the SDK Runtime, IP Protection, On-Device Personalization, and Topics, on both Chrome and Android.
What Topics was
Topics was the second attempt at a cookie replacement, after the Federated Learning of Cohorts (FLoC) proposal was retired in 2022 following privacy criticism. The idea was to keep interest-based advertising without exposing a browsing history. Chrome would sort the sites you visited into a few hundred coarse categories, such as fitness or travel, hold them on the device, and hand a caller up to five topics per week, with one drawn at random to add noise. The specific sites you had visited were never meant to be shared, and the API was gated behind an enrollment process.
The design left two things unresolved, and both were raised while it was still live. First, Google decided which categories counted as sensitive and which were fair game to share, so the classification of a topic was Google's call rather than the user's. Second, the value of the signal depended on how many sites a caller was present on. Google's own ad systems run on a large share of the web, so they had more topic coverage than smaller competitors. That asymmetry is the reason the UK regulator got involved at all.
Where it ended
The API is being removed from Chrome. The Blink intent to deprecate and remove states the plan plainly: deprecate in Chrome 144, then remove in Chrome 150. The Chrome 144 release notes confirm the deprecation. When removal lands, document.browsingTopics() goes away, the browsingTopics option in fetch() becomes a no-op, the Sec-Browsing-Topics request header stops being sent, and the browsing-topics permissions policy feature is removed. Google's own Privacy Sandbox feature status page lists Topics under "Deprecate and remove" for both Chrome and Android, alongside Protected Audience, Attribution Reporting, Shared Storage, Related Website Sets and Fenced Frames.
Very little of the initiative survives. The status page keeps CHIPS, FedCM, Private State Tokens, the Storage Access API, storage and network state partitioning, User-Agent reduction and Client Hints, bounce tracking mitigations and the frame-ancestors directive. Those are the pieces that either shipped broadly, had cross-browser support, or served a security purpose rather than an advertising one. IP Protection, the feature meant to mask your IP in Incognito by routing qualifying third-party requests through a two-hop proxy, is marked "Discontinue": it never shipped to stable. Incognito still blocks third-party cookies, but it does not hide your IP address from the sites you visit.
What the CMA actually decided
The original post said the CMA was investigating. That investigation is over. The CMA accepted binding commitments from Google in February 2022 to keep the Privacy Sandbox from favouring Google's own ad business. Once Google confirmed it would neither deprecate third-party cookies nor prompt users about them, the competition concern those commitments addressed stopped applying. The CMA consulted in June 2025, received 15 responses, and on 17 October 2025 issued its decision to release the commitments. The case is closed. The decision document gives the reasoning: because Google does not intend to restrict third-party cookies in any other way, keeping the monitoring burden in place would be disproportionate.
What still holds
The mechanism changed. The underlying concern did not. Google still sees a large share of web activity through Search, its ad network, Analytics, and its own properties, and none of the retirements change that. Dropping the Sandbox removes an on-device processing layer and leaves third-party cookies in place, so the amount of cross-site tracking in Chrome is closer to where it started than to where the 2020 plan was heading.
Default behaviour is still the lever. Chrome allows third-party cookies unless the user changes the setting, and the 2025 decisions removed the prompt that would have put the choice in front of everyone. The people most likely to be tracked are the ones least likely to open Privacy and Security settings.
Third-party cookies are only one tracking method. Fingerprinting, first-party data collection after a sign-in, and server-side matching all work without them, which is why blocking cookies alone does not make a browser private. The differences between browsers matter more now than the fate of one API: Safari, Firefox and Brave block third-party cookies by default, and Chrome does not.
What to do with this
If you care about cross-site tracking, the practical steps have not changed much. Pick a browser whose defaults match your preference, and if you stay on Chrome, open Privacy and Security settings, set third-party cookies to blocked, then check that it stayed set. Add an extension-based blocker such as uBlock Origin to cut requests before they leave the browser, and reduce your fingerprinting surface rather than relying on cookie controls alone. A hardened Firefox is a reasonable baseline, and so is Chromium with the same settings applied.
One older post on this site is now partly out of date for the same reason. The piece on Google's plan to protect users from IP tracking describes IP Protection as forthcoming, and Google has since retired it.
Bottom line
The Topics API is not a live privacy trade-off to debate. It is a retired feature that is being deleted from Chrome. The claim worth checking now is the one Google is still making: that keeping third-party cookies and letting users manage them in settings is a sufficient answer. That is not a claim about a new technology. It is a claim that the default is good enough, and the part a reader can actually test by opening their own settings.