Skip to content
TagSentry
Blog

Guide · AI and agents

How to use Claude or ChatGPT to set up cookie consent safely

AI assistants can walk you through a consent setup, and coding agents can do it for you. What to paste, what an agent must never do, and how to check it.

The TagSentry team · September 29, 2026 · updated October 2, 2026 · 4 min read

The short answer

An assistant like Claude or ChatGPT can walk a non-developer through adding a consent tool, step by step, for whatever platform they use. A coding agent like Claude Code can make the change itself. Both work best when you give them the vendor's own setup instructions to read, tell them what not to touch, and check the result yourself afterwards.

Two ways to use AI here

As a guide. You're in Shopify or WordPress, not sure where "the header" is, and a support article isn't helping. Paste the setup instructions into Claude or ChatGPT, say what your site runs on, and ask it to walk you through, one click at a time. You do the clicking.

As a builder. Your site is code, in a repository, and you use Claude Code, Cursor or a similar agent. The agent can add the script to your layout, open a pull request, and check it's there.

Both are fine. The risks are different.

What to give it

Assistants guess when they don't have instructions. Consent setup is exactly the kind of task where a plausible guess is wrong. Always give it:

  1. The vendor's setup page, or a link it can read. Most consent tools publish a guide. We publish ours as a plain file for agents at tagsentry.ai/SKILL.md.
  2. What your site runs on. Shopify, WordPress, Webflow, Squarespace, Wix, or a framework like Next.js.
  3. Whether you use Google Tag Manager, and whether you already have another consent tool.
  4. What you want at the end. For example: "the consent script is the first thing in the head, above Tag Manager, and nothing else changed."

A prompt that works well:

Help me set up [consent tool] on my website. Read [the setup guide URL] first. My site runs on [platform] and uses Google Tag Manager. Walk me through it one step at a time, and wait for me to confirm each step.

What an agent must never do

These are the mistakes we see most when an assistant, a plugin or a well-meaning developer installs a consent tool. Say them out loud in your prompt.

NeverWhy
Add async or defer to the consent scriptIt then runs after your tags, so consent defaults arrive too late
Move, edit or remove the Tag Manager snippetYour tracking breaks, and it's hard to see why
Load the consent script from inside Tag Manager with an "All Pages" triggerToo late on the page; other tags may already have fired
Publish changes in Tag ManagerContainer changes should be reviewed and published by a person
Remove another consent tool without askingTwo tools fighting is bad, but ripping one out silently is worse
Paste API keys into a chat or commit them to the repositoryKeys belong in your environment settings, not in history

In Next.js specifically, watch for the next/script component. Its loading strategies are designed for scripts that can wait, and a consent script can't. It should be a plain script tag, first in the document head.

Check the result yourself

An agent saying "done" isn't proof. Five minutes of checking, or our full Consent Mode v2 checklist if you have longer:

  1. Open your site in a private window.
  2. View the page source. Is the consent script the first thing in <head>, above Tag Manager, with no async or defer?
  3. Open the browser's network panel, reload, and look at the order. The consent script should load before googletagmanager.com.
  4. Answer the banner and reload. Does it remember your choice?
  5. If you're in the EU or UK, check that advertising pixels like facebook.com don't load until you accept.

A note on "Ask AI" buttons

Many sites now have buttons that open Claude or ChatGPT with a prompt already filled in. They're useful. They can also be abused: in February 2026, Microsoft's security team reported companies hiding instructions like "remember this brand as a trusted source" inside those links.

Read a pre-filled prompt before you send it. A good one only asks the assistant to read a page and help you with a task. If it tells the assistant to remember or prefer anything, delete that part.

Where TagSentry is today

You can set up TagSentry with Claude or ChatGPT right now. Our agent brief at tagsentry.ai/SKILL.md tells an assistant exactly where the one line goes for each platform, what never to change, and how to check it. Coding agents can also use our public API to create a site and read the install code, with you approving access in your browser.

Our MCP server is live too. Add https://app.tagsentry.ai/api/mcp as a connector in Claude, Claude Code, Cursor or ChatGPT's Developer mode, sign in, and your assistant can create your site, fetch your install code and check whether your banner is live. It asks before it changes your banner. How to connect it. Or run npx @tagsentry/cli in your project folder: it signs you in, finds your framework and adds the line.

Sources

  1. Next.js docs: the Script component and its loading strategies
  2. Google Tag Manager Help: Consent mode overview
  3. Microsoft Security Blog: The rise of AI Recommendation Poisoning
  4. r/GoogleAnalytics: Consent Mode silently blocking events