MarTech Watch: Week 32, 2026

Week 32, 2026
Coverage window 31 July – 6 August 2026.

For the interpretation of this week, why the open-tracking pixel becoming a consent object is a schema problem rather than a legal one, and why two vendors moved the CDP inside the customer’s own warehouse in the same seven days, see the companion essay: Weekly MarTech Signals That Matter to Me: Part 15, Week 32. This page is the record; the essay is the read.

This week’s record

A quiet week for feature launches and a loud one for the things underneath them. Two threads dominate.

  • MoEngage published its July product release during this window, and it contains the first native email open-tracking consent management shipped by any platform on this watchlist. It is built against France’s CNIL recommendation (deliberation n° 2026-042, published 14 April 2026) and Italy’s Garante guidelines, whose compliance term is six months from publication in the Gazzetta Ufficiale on 29 April 2026, therefore 29 October 2026. MoEngage’s own documentation states 28 October; see the regulatory table below for why 29 October is the date derived from the provision itself. The consent lives in a new per-recipient system attribute held separately from subscription status, the pixel is suppressed automatically for non-consented recipients including in already-sent mail, and MoEngage states plainly that flows using Email Opened as a trigger or entry condition need review. The same release added an API Firewall with IP allowlisting for Data APIs, extended the Merlin Campaign Insight Agent to SMS, and published something almost nobody else has: explicit MCP session lifetimes, 30 days or 7 days idle.
  • Zeotap shipped its complete Composable CDP as a Snowflake Native App, running identity resolution, segmentation, orchestration and activation as containerised services on Snowpark Container Services inside the customer’s own Snowflake account. Four days earlier, Monetate acquired Simon AI explicitly to pair its personalisation layer with Simon’s warehouse-native composable CDP. Read alongside Databricks CustomerLake, still in private preview, the pattern is that the CDP is becoming a workload that runs in your perimeter rather than a system of record that holds your data in someone else’s.
  • Adobe Journey Optimizer opened an August section and, more importantly, shipped Custom outbound channels on 31 July: any HTTP-based messaging channel, including WeChat, Kakao Talk and Messenger, built through a no-code Channel Builder and available across campaigns, journeys and orchestrated campaigns with the full native-channel feature set, consent and governance enforcement included. That moves the long tail of regional messaging apps from outside the consent perimeter to inside it.
  • Adobe Journey Optimizer B2B published 2026.8 for deployment on 14 August, bringing person journeys toward parity with account journeys, and delivering the multi-event account-journey listener that 2026.6 had only declared as planned. Note there is no 2026.7.
  • Bloomreach 1.315 (5 August) validates authorisation before the Experiments editor opens. Small, and the third access-control tightening of the week alongside AJO’s WAF allowlisting and MoEngage’s API Firewall.
  • Treasure AI appears in this Watch for the first time from a dated product feed, following a source-discovery pass that found one. Its August release migrates the Google Enhanced Conversions connector to the Google Data Manager API, which is a migration deadline in disguise for anyone running enhanced conversions through any vendor.
  • Two acquisitions closed the July book: Monetate/Simon AI and ADA/Algonomy, both announced 30 July.
  • On the regulatory side, the FTC, Utah and Los Angeles County sued Hims & Hers over sharing medical conditions and site activity with Meta and Snap, and Illinois signed a Children’s Social Media Safety Act that pushes age signals to the device operating system and bans notifications between 10 p.m. and 7 a.m., the second such overnight rule after New York’s.

Quiet this week, verified: Braze (next release ~20 August), Adobe AEP (no August release), Adobe Marketo Engage (page unchanged since 18 June), Iterable, Tealium, HubSpot, Klaviyo, Optimove, Salesforce Marketing Cloud.

What changed this week

PlatformWhat changedSource
MoEngage (consent)Shipped (published in window)Consent / ComplianceEmail Open Tracking Consent Management, built against the CNIL recommendation and the Garante guidelines. MoEngage’s documentation cites 14 Jul 2026 for France and 28 Oct 2026 for Italy; both dates need care, and the regulatory table below sets out what the instruments actually say. An open-tracking consent toggle and country selector in Email General Settings; a new per-recipient system attribute moe_email_open_tracking_consent stored separately from email subscription status and settable via User Import, SDK or the server-to-server Data API; automatic pixel suppression for non-consented recipients in configured countries, including emails already sent; a dedicated open-tracking preferences link in every email footer, separate from unsubscribe and Manage Preferences; a full consent audit trail recording new state, previous state, timestamp and source; and a configurable fallback for recipients with no country attribute. Off by default. MoEngage states the consequences itself: open rates fall for brands with significant French or Italian audiences, and flows using Email Opened as a trigger or entry condition may need review.MoEngage July 2026
MoEngage (platform)Shipped (published in window)Governance / MCPAPI Firewall: IP allowlisting for MoEngage Data APIs so exposed credentials alone cannot reach the data, with single IPv4/IPv6 addresses, CIDR ranges and ranges, batch rule creation with a single publish, per-rule audit of who changed what and from where, and 30-day success counts per rule. Fails open; applies to server-to-server Data API traffic only, not SDK traffic. Auth flow revamp ending full-platform lockout on revoked SSO or IdP change, and publishing session boundaries: MCP sessions expire after 30 days or 7 days of inactivity, managed independently of Dashboard and Mobile sessions. Offering APIs (Create, Update, List) live and exposed as tools in the MoEngage MCP server. Amazon S3 gains cross-account role assumption, removing shared static access keys.MoEngage July 2026
MoEngage (engagement)Shipped (published in window)Product release / Agentic AIMerlin AI Campaign Insight Agent extended to SMS across One-Time, Periodic and Event-Triggered campaigns, adding connector and route performance comparison, spike and dip analysis, trigger-behaviour intelligence, event-level root-cause diagnosis across trigger condition, audience qualifier, timing window, connector routing and creative, and trigger-frequency benchmarking against historical baselines. New In-App trigger on push click. SMS URL shortening and click tracking for personalised links, removing the custom-Jinja workaround. Attribute Trend in Trending Items, mapped to any catalogue attribute. New connectors and channels: Telegram media/action/HTML, Reddit Ads Audience, Truecaller, Deepgram AI Voice, and AXS/Oztix/Ticketek/Ticketmaster dynamic content. Six new data sources: Superwall, Razorpay, NitroX, Xeno Loyalty, Xoxoday Loyalife, WooTag. Computed Traits at daily frequency on request.MoEngage July 2026
ZeotapLaunched (Aug 5)CDP / ArchitectureComplete Composable CDP available as a Snowflake Native App on Snowflake Marketplace. Identity resolution, profile unification, audience segmentation, journey orchestration, agentic AI and activation to 250+ destinations run as containerised services on Snowpark Container Services inside the customer’s own Snowflake account, with no customer data leaving the Snowflake perimeter. Installable directly from the Marketplace. This is not reverse ETL and not zero-copy read: it is the whole application executing inside the customer’s warehouse boundary, which collapses data residency, egress control and access review into the Snowflake account’s own controls.GlobeNewswire · Zeotap
Adobe Journey Optimizer (channels)Limited Availability (Jul 31)Channels / ArchitectureCustom outbound channel: administrators can bring any outbound HTTP-based messaging channel, such as WeChat, Kakao Talk, Messenger or a proprietary provider, into Journey Optimizer through a no-code Channel Builder. Once configured, custom channels are available across campaigns, journeys and orchestrated campaigns with the same full capability set as native channels: expression-editor personalisation, content experimentation, preview and proof, out-of-the-box reporting, and consent and governance enforcement. Adobe states this fills the gap left by custom actions, which were limited to journeys and lacked dedicated channel capabilities. Limited Availability.AJO release notes
Adobe Journey Optimizer (content)Shipped (Aug 5)Content / GovernanceFlexible Image Sourcing for AI Content Generation: content generation sources brand-approved images directly from Adobe Experience Manager Assets Essentials and above, under three modes. Balanced is Digital-Asset-Management-first with AI filling gaps and is the default; Assets is DAM-sourced only; Creative is AI. The default is a governance posture expressed as a product setting: the governed library is preferred out of the box and pure generation is opt-in.AJO release notes
Adobe Journey Optimizer (administration)Shipped / Limited Availability (Jul 30–31)Governance / MigrationWeb Application Firewall IP allowlisting for landing pages, letting organisations reject any request that bypasses their configured WAF layer so policies defined in tools such as Imperva are consistently applied (Jul 30). Self-serve creation and management of approved domains for complete and base URL personalisation, without a support ticket (Jul 30). Guided Adoption Capabilities, a dedicated workspace for migrating existing email content and journeys in from another marketing platform, Limited Availability (Jul 30). Countdown timer using AEM Dynamic Media for open-time personalisation (Jul 30). Language Settings duplication and cross-locale condition copying (Jul 30). “AI Assistant” renamed “Generate Content” throughout the product, naming only, no functional change (Jul 30).AJO release notes
Adobe Journey Optimizer B2BAnnounced, deploys Aug 14Product releaseRelease 2026.8, deployment date 14 August 2026 with phased rollout. Person lists, static and dynamic, targeting profiles by demographic attributes and experience-event history. Variant split path nodes for person journeys, previously beta for account journeys. Journey re-entry for person journeys. Multiple triggers and filters in Listen-for-event nodes on account journeys, which 2026.6 had declared only as planned. External split path and External action nodes for person journeys. AEP relational datasets appearing in the sandbox. Note the version sequence goes 2026.6 (10 Jul) to 2026.8; there is no 2026.7. The through-line is person journeys being brought to node-level parity with account journeys.AJO B2B release notes
Bloomreach EngagementShipped (Aug 5)GovernanceRelease 1.315, rollout 5–10 August. Single item: improved security for the Experiments editor. Access is validated before the editor opens, so only authorised users can load it.Bloomreach 1.315
Treasure AI (new to this Watch)Shipped (Aug 3–5)Product release / CDPAugust 2026 release. LINE Official Account becomes a first-class Always-on Campaign channel in Engage Studio, at parity with Email and Push across the full Draft to Finished lifecycle, supporting text, Imagemap and Flex messages (Aug 3). Google Enhanced Conversions Export connector migrated to the Google Data Manager API, so enhanced conversion events keep flowing after Google’s migration off the legacy Google Ads API; supports offline, online and store-sales conversions under a unified event model with no developer token required, hashed identifiers, conversion metadata including GCLID and consent, and request-level diagnostics (Aug 4). Azure Blob Storage import adds SAS token authentication for enterprises whose policies forbid sharing Storage Account Keys (Aug 5). “Remember Me” removed from the login page so sessions respect configured idle timeouts (Aug 5).Treasure AI August 2026
Segment (Twilio)No CDP items in windowCDP / MessagingNo Segment CDP items dated in window on the Twilio changelog, which is used here as the primary Segment source for the first time. Twilio platform items that touch messaging infrastructure: a new regional IP address for Event Streams webhooks in US East, subnet 3.80.20.0/25, effective 15 September 2026, affecting anyone who validates inbound Event Streams webhook traffic by source IP (Aug 4); SendGrid domain authentication drops the “Send to Coworker” action (Aug 3); WhatsApp Card and Flows support plus restricted API keys in Conversations (classic) (Jul 31).Twilio changelog
Adobe Marketo EngageEffective Jul 31DeprecationThe two announced 31 July deadlines have passed and remain documented as effective: SOAP API end of support and the REST Merge Leads 25-ID limit, where calls with more than 25 IDs in leadIds return error 1080 and are skipped. Remaining clocks: access_token query-parameter deprecation on 31 August 2026, and the static-list size limit on Get Lead Activities and Get Lead Changes from 30 September 2026, returning error 1003 for lists of 10,000 or more leads. No August release page exists; the current page is still titled July 2026 and last updated 18 June.Marketo release notes
InsiderOneSDK activity (Aug 5–6)Source gapNo product release-notes feed identified for a second consecutive run. The SDK changelogs at the Academy are live and dated: Android entries on 5 and 6 August 2026 covering in-app campaigns appearing in the first session after a device change, and a fix for a rare thread-exhaustion error during session stop or data flush. Recorded as SDK activity, not as a product release.InsiderOne Android SDK changelog
Delight.ai (adjacent)Launched (Aug 5)MCPDelight Agent MCP, giving natural-language access to live workspace data, including satisfaction scores, resolution rates and conversation transcripts, from external assistants including Claude, Codex and Cursor. Notable because write operations are included, putting it ahead of most vendor MCP servers on scope.CDP Institute
RelPro (adjacent)Launched (Aug 5)MCPMCP server piping B2B relationship intelligence, company relationships, contact details and intent signals into agent workflows without manual data export.CDP Institute
Algolia (adjacent)Shipped (Jul 31)Agentic AIAgent Studio expanded so commerce teams can embed AI agents directly into product search and discovery workflows, with data grounding, guardrails and cost controls.CDP Institute

Mergers, acquisitions and corporate moves

WhatDetailDateSource
Monetate acquires Simon AIMonetate acquires Simon AI, the agentic platform built on an AI-first composable CDP, to pair Monetate’s personalisation and experimentation with Simon’s warehouse-native customer profiles and omnichannel journey orchestration across 100+ channels. Terms undisclosed. Steve Maher is CEO of both companies; Simon AI co-founder Jason Davis continues to lead Simon AI as a Monetate company. Both platforms operate separately for now, with out-of-the-box integrations available immediately. Structurally the same move BlueConic made with Blueshift in June, with the difference that the data layer here is explicitly warehouse-native.Jul 30Businesswire · Monetate
ADA acquires AlgonomySingapore-based data and AI firm ADA completes its acquisition of Algonomy, the San Francisco customer data and analytics platform built on the legacy of Manthan and RichRelevance and serving 400+ brands. Terms undisclosed. Merges conversational AI with real-time personalisation and recommendation under one agentic growth platform, extending ADA to 34 combined markets across APAC, the US, MENA and Europe.Jul 30PR Newswire
Hightouch / LiveRamp / PublicisUnresolved for a seventh week. No Publicis statement, no bid withdrawal, no revised offer and no close progress since the 26 June deadline lapsed on Hightouch’s unsolicited $800M–$1.2B proposal for the RampID identity graph and LiveRamp Connect, which sits on top of Publicis’s announced all-cash take-private of LiveRamp.No changeAxios
HubSpot / Warmly · Zoom / Common Room · BlueConic / BlueshiftAll three still pending or silent. BlueConic has published nothing since the 17 June Blueshift acquisition: no integration roadmap, no combined branding, and no statement on how consent and identity resolve across the merged stack.No change,

Regulatory and industry, in window

WhatDetailDateSource
Email tracking pixels, FranceDeliberation n° 2026-042 of 12 March 2026, adopting a recommendation on tracking pixels in email, published in the Journal Officiel on 14 April 2026. Two points of precision that most coverage gets wrong. First, this is a recommendation and the CNIL states it is neither prescriptive nor exhaustive: the obligation itself sits in Article 82 of the Loi Informatique et Libertés, and the recommendation sets out how the CNIL reads that article for email pixels, complementing the EDPB guidelines and the CNIL’s own cookies recommendation. Second, 14 July 2026 is not the date consent became mandatory. It is the end of a three-month transitional accommodation for addresses collected before 14 April, during which pixels could continue without retroactively collecting consent provided recipients received clear and accessible information inside that window. The recommendation distinguishes pixels requiring consent from those exempt under Article 82.Published 14 Apr 2026; transitional information window closed 14 Jul 2026Légifrance, délibération 2026-042 · CNIL
CNIL question-and-answer document (missed by this Watch at the time)On 22 July 2026 the CNIL published a FAQ answering professionals’ practical questions on applying the recommendation. It covers whether tracking links as well as open pixels are in scope, whether the CNIL can act against actors not established in France, whether emails to employees at work addresses are excluded, the obligations falling on the sending platform rather than the sender, whether the security exemption extends to anti-fraud and bot detection, who counts as “administration”, how the commercial prospecting regime interacts with the deliverability exemption, which messages count as transactional, whether a newsletter pixel can be exempt, whether anonymous or aggregated collection avoids consent, and the mechanics of free, informed and provable consent. This is the most useful practical document in the whole affair and it was not captured in the week it appeared. Recorded here as a late capture.Published 22 Jul 2026CNIL FAQ
Email tracking pixels, ItalyLinee guida adopted 17 April 2026 under Article 154-bis of the Codice, published in Gazzetta Ufficiale Serie Generale n. 98 on 29 April 2026. The provision sets the compliance term itself: six months from publication in the Gazzetta Ufficiale, which gives 29 October 2026. Vendor documentation, including MoEngage’s, states 28 October; 29 October is the date derived from the text, and working to the earlier of the two costs nothing. Legal hook is Article 122 of the Codice privacy, read with the GDPR definition of consent, the right of withdrawal, and Article 25 on data protection by design and by default. In ordinary cases prior, free, specific and informed consent is required. Two obligations go further than France: withdrawal must be possible granularly, not as a single switch, and privacy by design and by default is named in its own right, aimed at reducing recipient identifiability. Exceptions exist for security purposes, strictly necessary technical requirements, and institutional or service communications, subject to proportionality and minimisation. The addressee list explicitly includes operators of bulk email sending platforms, so the ESP and CEP layer is directly in scope alongside the sender.Compliance term ends 29 Oct 2026Garante provvedimento · Garante press release
FTC, Utah and Los Angeles County v. Hims & HersThe FTC, the State of Utah and Los Angeles County sued Hims & Hers, alleging the telehealth company shared customers’ medical conditions and website activity with Meta, Snap and other third parties despite promising privacy, and that customers were enrolled and charged before meaningful consultations. The enforcement coalition is the new part: a federal regulator alongside a state and a county.Aug 4CDP Institute
Illinois Children’s Social Media Safety ActSigned by Governor Pritzker, taking effect in 2028. Platforms must obtain age information through device operating systems, restrict use of minors’ viewing histories, strengthen location privacy, and stop notifications between 10 p.m. and 7 a.m. Two points of note: the age signal is pushed to the OS layer rather than the platform’s own identity stack, and this is the second overnight notification rule after New York’s, which requires chronological feeds for minors and blocks overnight push from 25 January. Quiet hours for minors is becoming a jurisdictional patchwork.Aug 4 (effective 2028)CDP Institute
EU / TikTokThe European Commission preliminarily found TikTok in breach of the Digital Services Act over children’s account privacy defaults, exposing minors’ content to adults and recommendation feeds. TikTok may respond before any fine of up to 6% of annual revenue.Jul 28CDP Institute
EU age verification bypassedA security researcher demonstrated methods for circumventing the EU’s prototype privacy-preserving age-verification system, which was designed to confirm adulthood without disclosing identity. The concern raised is that failure of anonymous verification pushes governments toward more intrusive identification.Aug 4CDP Institute
Australia, facial recognitionThe privacy regulator updated its post-Bunnings guidance, warning retailers that facial recognition in public stores generally requires consent unless a narrow legal exception applies.Aug 4CDP Institute
UK / AppleApple filed a further legal challenge after the UK issued a new technical capability notice seeking access to encrypted iCloud data belonging to British users. The new order reportedly excludes American accounts, which the earlier one did not.Aug 4CDP Institute

Method note

Every release-notes and changelog page in this record was read in a browser, not fetched. Where a page is client-rendered and text extraction under-returned, the DOM was read directly. A source-discovery pre-flight ran before any vendor scanning and produced one resolved gap (Treasure AI, which has had a dated monthly release feed at docs.treasure.ai/release-notes all along) and one partially resolved gap (InsiderOne, where dated SDK changelogs exist but a product release feed still does not). The MoEngage July release is dated to a window rather than a day, because MoEngage labels releases by month only; it was verified absent on 30 July and present on 6 August.

Also next week

  • Salesforce Marketing Cloud SMS and WhatsApp consent mapping deadline, 17 August 2026.
  • Adobe Journey Optimizer B2B 2026.8 deploys 14 August.
  • Braze, next release ~20 August on the four-week cadence. The remote MCP server remains the standing top watch: exit from early access, published scope and permission documentation, and whether write access extends past content objects.
  • Iterable monthly release, ~21 August.
  • Klaviyo: an undated “custom agents without engineering” conversational agent builder sits on the highlights band with no date and no entry in the dated update list. Unresolved, and not reported here as an in-window item.
  • 6sense MCP server general availability was planned for August and had not been announced as of 6 August.