The Open Web Isn't Dead. It's Uninsured.
This essay explains why the open web never built a commercial model like AppLovin's, using the four clauses of an outcome contract. The open web can define an outcome, measure it and settle a campaign; what it cannot do is put a counterparty behind the miss — and the walled gardens cannot either. AppLovin, Meta and Google optimize toward outcomes and reprice when results miss; AppLovin's 10-K says no fixed price per action and Meta's documentation says the cost cap is not guaranteed. Criteo came closest to carrying real risk on the web, buying CPM and selling CPC from at least 2010, and broke each time a browser repriced the cookie it rented. AppLovin is pulling web demand into its in-app loop rather than rebuilding the web's; protocols like AdCP carry a CPA clause but, by their own admission, adjudicate nothing. Corrects Paparo's '40% in one quarter' (Ozone ad requests, year over year, eCPMs up ~30%). The word the tape supports is not dead but uninsured.
In English, please
In early August 2026, two advertising companies reported Q2 in the same week. Criteo, which for years let advertisers on the open web pay only when someone clicked, the closest the web came to paying for a result, shrank 11% and fell below a billion dollars in value. AppLovin, which sells ads inside mobile games, grew 53% with an 84% profit margin and still lost a fifth of its value on a tiny miss. A well-read industry newsletter called it the week the open web died. This essay argues the open web didn’t die; it never built the one thing that would have let it compete.
The thing is a contract. To sell a business result instead of an ad view, four things have to be settled: what counts as the result, who counts it, when the count is final, and who pays when the result doesn’t arrive. The first three are measurement jobs and can be bought from other companies. The fourth is money: someone has to absorb the losses when campaigns miss, and on the open web nobody ever has. Inside a single company like AppLovin, Meta or Google, nobody does that fourth job either — their own filings promise no fixed price per action and no guaranteed target, and nobody gets a refund when the target is missed. What they have is control of the whole loop: they see results fast, adjust prices for the next round, and keep the difference. The advertiser still carries the risk that the result doesn’t come.
The open web is built out of separate companies — one sells the ad space, another buys it, another verifies it, another matches identities — so no one sees enough of the loop to adjust prices against results, never mind carry any of the risk. Criteo tried for thirteen years, buying ad views and selling clicks and keeping the gap, and it worked until the browsers that owned the identifier it depended on (the cookie) changed the rules, repeatedly. AppLovin isn’t fixing that for the web; it’s pulling web advertisers into its own game-based system, where it can at least see results fast enough to reprice.
The author co-leads a measurement group for one of the new agent protocols and is blunt that protocols can standardise the first three jobs but cannot do the fourth, because it isn’t a specification, it’s a balance sheet. What to watch: whether any contract between two independent companies ever carries a priced premium for guaranteeing a result. Until then the right word for the open web isn’t dead. It’s uninsured.
On this page
Two prints, one question
In the first week of August 2026, Criteo and AppLovin reported Q2. Criteo, which for more than a decade sold the open web the closest thing it ever had to an outcome, printed revenue of $428 million, down 11%, and Contribution ex-TAC of $255 million, down 13%. The stock closed down 24% and the company was worth less than a billion dollars for the first time since the pandemic crash. AppLovin printed revenue of $1,923.7 million, up 53%, at an 84% adjusted EBITDA margin, landed about a million dollars under the floor of its own adjusted-EBITDA guidance, and fell 19.66% the next day.
Ari Paparo’s Marketecture newsletter filed both under one headline, The Week the Open Web Died. His axis was openness: walled gardens and “non-transparent, in-app” AppLovin won, open-web companies lost, therefore the open web is finished. “We’re done. It’s over.”
Three of the facts his argument rests on are looser than they read, so let me clear them before building anything on the same ground. The “40% in one quarter” is Ozone data reported by Digiday: publisher ad-request volumes down 32-37% year over year in the US and 39-41% in the UK. That is ad supply, not traffic, and year over year, not sequential, and the same dataset shows UK eCPMs up roughly 30%. Supply got scarce and repriced; demand didn’t vanish. His winners and losers don’t sort by openness either: Taboola, an open-web company, grew ex-TAC gross profit 11.8% and raised guidance, while Magnite reported two businesses in one print, CTV up 36% and open-web display up 2%. And the traffic loss he’s pointing at is real but sits at the top of the funnel: People Inc.’s own 8-K attributes a 22% drop in sessions to Google’s AI Overviews, with advertising revenue flat on higher rates.
So the week doesn’t prove the open web died. It raises a better question, one the industry has dodged since Criteo’s IPO: why did the open web never build a commercial model like AppLovin’s? The answer is not openness. It is a contract with four clauses. The open web controls too little of the first three to reprice against them, and nobody, inside a wall or outside it, signs the fourth.
The four clauses of an outcome contract
I spent last week on why nobody sells an outcome. To trade a result rather than an ad view, four things have to be settled: what counts as the outcome, who counts it, when the count is final, and who pays when the result doesn’t arrive. The first three are measurement work. The fourth is capital.
That fourth clause is where this essay has to be precise, because the winners of the week look like they hold it and, in their own filings and documentation, say they don’t.
AppLovin’s 10-K for 2025 describes its pricing in one sentence: “Advertisers set return goals for their campaigns and Axon Ads Manager targets users to match those goals. Return on advertising spend is measured based on either third-party or self-attribution. Advertisers are charged dynamically based on their campaign goals, rather than a simple fixed price per impression or per action.” Meta’s developer documentation for cost caps says it flatly: “Adherence to cost cap limits is not guaranteed.” Nobody refunds the advertiser when the target is missed. The advertiser still pays. What the platform faces is lower spend next quarter, a thinner margin, a falling share price. That is commercial exposure. It is not payment of the advertiser’s loss.
So there are three different things an outcome-priced product can be, and the industry uses one word for all of them.
The first is optimization toward an outcome. The seller observes results, reprices, retargets, and charges toward your goal. The risk of the outcome stays with you. AppLovin’s Q2 10-Q now describes its product as one “that deploys advertiser capital at their return goals”: the advertiser’s capital, the advertiser’s goal. This is what Meta’s Advantage+ and Google’s Performance Max sell, and what AppLovin sells above the install, and it is most of what “outcome buying” means today.
The second is action-based billing. The seller buys impressions and is paid only when a defined action happens, so it carries the variance between the impression and the action. Criteo’s CPC-on-CPM model was this. Affiliate marketing is this. AppLovin’s install pricing on action-billed campaigns is this too, one layer down from the return goal. Google’s pay-for-conversions on Display is this, and look at the conditions: more than 100 conversions in the last 30 days, 90% of them within seven days, a target CPA under $200. That isn’t a product tier. It’s an underwriting screen for the one layer Google will carry, and it screens for enough events, fast enough, small enough, for the law of large numbers to do the carrying.
The third is a guarantee of the outcome itself: a counterparty that pays when the business result doesn’t arrive. Nobody sells this at scale, inside the walls or outside them.
Owned loops don’t insure outcomes. They internalize the data, the auction and the economics needed to optimize toward them, and sometimes to carry the first layer of variance. The open web fragments those functions across companies. What it lacks, the walled gardens lack too: a counterparty willing to put capital behind the miss. The difference is that inside a wall one company controls the loop well enough to reprice. Outside it, nobody controls enough of the loop to try.
What Criteo carried, and what broke
Criteo is the cleanest test of the second tier, because it wrote the model into its 2013 IPO prospectus: “We primarily charge our clients based on a cost per click, or CPC, pricing model, and our clients only pay us when a user engages with (i.e., clicks on) the advertisement. However, we purchase advertising inventory from publishers on a cost per thousand impressions” basis. Buy the impression, sell the click, carry the difference. Ninety-nine percent of its revenue in 2010 through 2012 was sold that way. At the peak, 2017 and 2018, the difference was $941 million and then $966 million of Revenue ex-TAC on gross revenue of $2.3 billion, a 41% to 42% spread. That was real risk transfer, at the impression-to-click layer, across a company boundary, at scale, for a decade.
It held for as long as the loop’s inputs held. Criteo owned one input outright, the conversion tag on its clients’ sites. It rented the other two: the identity and intent signal that told it who was likely to click was a third-party cookie owned by the browser, and the exposure was bought on exchanges it didn’t run. Criteo could always count the click in its own logs. What the cookie gave it was the ability to predict the click, and prediction is what made the variance priceable.
Then the owners of the identifier changed the rules, repeatedly. In December 2017 Apple’s iOS 11.2 disabled the workaround Criteo used to reach Safari users, and the company raised its estimate of the hit to 2018 Revenue ex-TAC from 9-13% to “approximately 22%.” On 14 January 2020 Google said Chrome would phase out third-party cookies within two years and Criteo fell 15.9% in a day. By February 2024 half the inventory Criteo bid on carried no cookie at all, against 95% five years earlier. Then Google reversed, in July 2024, and retired the Privacy Sandbox in October 2025, and Criteo’s departing CEO said the quiet part: “We no longer plan our business around the deprecation of third-party cookies.” Retargeting was still 40% of the business exiting 2024.
The lesson isn’t that the web can’t carry risk. Criteo carried it, at the click layer, for a decade. It’s that a seller can only carry variance it can predict, and every signal the open web ever used to predict across that seam belonged to a browser or an operating system that could switch it off.
What AppLovin owns, and what it doesn’t
Why AppLovin’s loop is faster
The principle that cut Criteo’s cable is written down most plainly on the app side. Apple’s App Tracking Transparency defines tracking as “linking user or device data collected from your app with user or device data collected from other companies’ apps, websites, or offline properties.” It banned the cross-company join. It did not ban observing what happens inside your own SDK. Meta’s CFO put the cost of the ban at “on the order of $10 billion” for 2022.
AppLovin’s seam is shorter and more observable than anyone’s. It announced the acquisition of Adjust, a mobile attribution company, on 3 February 2021, eight weeks before ATT went live. An audit of 368 top games in spring 2025 found its MAX mediation layer in 73.1% of the top-downloaded titles; Tenjin’s benchmark across 146 billion impressions has AppLovin at 44% of iOS game ad revenue in the second quarter of 2026. MAX controls much of the supply, while attribution partners and platform signals return conversion data quickly enough for the model to reprice. Then there is density, which the web can’t copy even if it solved identity tomorrow. The median mobile game retains about 22% of players on day one and under 4% on day seven, so a game learns what a player is worth inside a week. AppLovin defines its own D7 window as purchases within 192 hours of the click. And the advertisers are the inventory: Liftoff’s data says roughly half of all casual-game installs come from ads shown inside other games. One population, paying itself, through one auction, at a cadence of days. The CEO said it on the Q1 2024 call: “The advertisers spend $1 and everything is measurable. It’s all closed loop.”
What AppLovin still rents
Now the accounting, stated carefully, because it is the most abused comparison in this debate. Criteo disclosed its spread as Revenue ex-TAC against gross revenue: $941 million on $2.3 billion of billings, after $1.36 billion of traffic acquisition cost. It reported gross because it was the principal that bought the impressions. AppLovin’s 10-Q says the opposite about itself: it is “an agent in these arrangements and presents revenue net of advertising inventory costs,” with the transaction price “determined dynamically based on advertisers’ campaign goals, less consideration paid or payable to publishers.” It does not buy the inventory. It facilitates the advertiser’s purchase of it and keeps the difference, so its $1.92 billion of revenue already is the spread. The two presentations encode exactly who owned the inventory risk. Its 84% adjusted EBITDA margin is a different thing again: how much of that spread remains after adjusted operating costs. Anyone who tells you AppLovin’s margin is Criteo’s take rate seen from the inside is skipping two steps. What the 10-K does tell you is how the spread widened. For 2025, “the volume of installations increased 3% and net revenue per installation increased 72%.” For the second quarter of 2026, installs fell 2% and net revenue per install rose 58%. Growth was spread per install, not installs. The filing attributes it to “improved AppLovin Ads performance”; the result is consistent with a model capturing more value per install through better prediction, pricing or campaign mix.
And here is what AppLovin does not own, in its own words. The count is often somebody else’s. AppLovin owns one attribution vendor, Adjust; the 10-K’s “either third-party or self-attribution” means the advertiser’s vendor, frequently AppsFlyer, credits the install. In June 2026 Moloco, Google, Meta and Unity each took minority stakes in AppsFlyer, over a billion dollars at a $2.7 billion valuation by press accounts, on terms the release spells out: each stake is “minority, non-controlling, and non-exclusive,” with no “preferential treatment in relation to AppsFlyer’s APIs, measurement signals, attribution logic, or commercial terms.” And the outcome is not warranted. On the Q2 call the CEO explained the miss: “There’s no guarantee that we’re always going to have lifts in every single period of three months.” Nothing in the cited terms creates a refund obligation when the target is missed. Advertisers paid for their installs at the prices the model set. The only miss in the print was AppLovin’s own, adjusted EBITDA of $1,613.8 million against a guidance floor of $1,615 million, and that landed on its shareholders as a 19.66% drop, on a stock already down from $241.58 billion at the end of 2025 to $102.32 billion on 21 August, with short reports and an SEC inquiry in between. That is exposure, not insurance. It is what optimization-toward-an-outcome looks like from the seller’s side when the model has a quiet quarter.
AppLovin’s web business makes the limit visible. By December 2024 it had, in the CEO’s words, a “run rate of roughly $1 billion a year of gross advertiser spend in the e-commerce category alone from around 600 customers,” and on the Q2 call the consumer vertical finished 28% above its Q4 2025 peak, with no dollar figure disclosed. Those conversions happen on advertisers’ websites and are counted by advertisers’ own tools. At the web’s edge AppLovin has Criteo’s position in reverse: it owns the exposure, a full-screen ad inside a game, and rents the count. Its incrementality is contested exactly as every open-web vendor’s was: the CEO claimed “nearly a 100% incrementality” on the Q3 2024 call, after the e-commerce pilot launched; Muddy Waters, from traffic data on 37 million users, estimates 25-35%. Separately, an SEC investigation into its data practices was reported in October 2025 and was “still active and ongoing” in February 2026. The order of operations Foroughi gave for new supply tells you what the web is to this loop: “Step one would be the obvious, just non-gaming apps… Then step two would be the open web. Step three would be Connected TV.” The web is a future supply source for an existing loop. It is not getting a loop of its own.
Why the open web can’t yet warrant an outcome
Put every actor from the August prints into one table: four clauses across the top, and in the last column not “who pays” but the honest version, who carries the variance and at which layer.
Read the bottom row against the deals of the summer. DoubleVerify to Nielsen for about $2.15 billion. IAS taken private by Novacap for about $1.9 billion. LiveRamp to Publicis at a $2.167 billion enterprise value. Paparo is right that these companies exist because the open web is fragmented. The sharper reading is that each is a clause of the outcome contract sold as a service: verification is clause two, identity is what lets clause two see across the seam. The open web built a whole industry for the measurement clauses. Nobody has ever bought the fourth clause, on the web or inside a wall, because nobody has ever sold it.
The attempts are on the record. Xaxis, in 2017, at a billion dollars of revenue, sold “guaranteed outcomes,” and its CEO explained why agencies couldn’t: “The ability to assume risk on measurable outcomes is something our agencies or mPlatform will never be able to do because of their business models.” What the guarantee meant in practice was overdelivering impressions free of charge when a campaign missed. That’s a make-good, not risk transfer. Affiliate marketing is the one cross-company channel that still prices the conversion itself: $13.62 billion of US spend in 2024, 9.4% of US e-commerce sales. It settled on a last click that was never agreed, only tolerated, which is why it never left the bottom of the funnel. And the structural numbers show the book a programmatic seller would have to carry variance on. The 2020 ISBA/PwC study could match only 12% of impressions end to end. It found 15 advertisers reaching 12 publishers through nearly 300 supply chains, and left 15% of spend as an “unknown delta.” The ANA’s 2023 study put 36 cents of every DSP dollar in front of a consumer. You cannot carry variance on a count you can’t reconcile.
The cleanest single exhibit is inside one company. Alphabet’s Q2 10-Q has Google Network revenue, the open-web line, down $51 million with impressions down 12% and price per impression up 13%, while Search grew 17%. Same bidder, same quarter, two loops. The one it controls end to end grew. The one it assembles from publishers shrank and repriced.
What to watch in 2027
A lot is being rebuilt across company boundaries, and this is where I have a seat at the table and an obligation to be the most skeptical person at it.
Clause one, what counts, is being standardised: Meta rebuilt its own loop after ATT on server-side conversion events, and conversion APIs and shared event taxonomies have followed. Clause two, who counts, is being capitalised as a neutral: four loop owners just funded a counter none of them controls, and the W3C’s Attribution Level 1 draft, dated 20 August 2026, has editors from Google, Mozilla and Meta. The one attempt to put the counter inside the browser structurally, Privacy Sandbox, was retired on 17 October 2025 with its Attribution Reporting API on about 21% of sites. Clause three, settlement, is what the agentic protocols are writing. AdCP carries a CPA pricing option, “charged a fixed price when the specified event_type fires.” I co-lead the Signals & Measurement working group for that protocol, and its measurement taxonomy says this, plainly: “AdCP does not run measurement models. It does not adjudicate between competing verification vendors. It does not define MRC counting conventions. It does not store or normalize attribution outputs.”
I read that sentence as correct and as a confession. A protocol can carry a CPA clause. It cannot make anyone pay when the conversion doesn’t come, because the fourth clause is not a specification. It’s a balance sheet. Someone has to hold capital against the miss, and no schema can write that in. A dense loop lets the seller reprice the next round; it does not pay for the last one.
The closest thing the web has to a new loop is retail media, and it confirms the rule. Commerce media took 15.6% of global ad spend in 2025, past television, because in WPP’s phrase it can “connect media exposure to ultimate purchase.” Walmart Connect grew 43% in its latest quarter and is exporting its first-party audiences to Yahoo’s DSP and DV360. That is the count leaving the wall. The loop stays home: a retailer can reprice against its own shoppers, but the moment its audience is bought through a third-party DSP against an outcome on a third-party site, the seam is back.
So three things to watch. First, the line item from last week’s essay: the day a contract between two independent companies carries a priced premium for warranting a result, the fourth clause exists on the web. Watch for the premium, not the press release. Second, the AppsFlyer structure. If four loop owners can hold a neutral counter to non-exclusive terms, the web has a rentable clause two with real capital behind it for the first time. Third, AppLovin’s step two. When the open web becomes its supply, either publishers get paid against a repriced, observed result for the first time, or they become one more rented exposure in someone else’s loop. Criteo already showed how the second version ends.
The open web can define an outcome, measure it and settle a campaign. What it cannot do is put a counterparty behind the miss, and nobody else can either; the walled gardens just control their loops well enough to hide it. The word Paparo wanted was “dead.” The word the tape supports is “uninsured.”
(Part 2 — how the missing clause gets built, and who pays the first premium: The Risk You Can Price.)