Speculative prerendering and prefetch: the consent hole your tag manager cannot see
Modern browsers try to make navigation instant. Speculative prerendering and link prefetching load pages before the visitor clicks, so the next page appears immediately. That is good for performance. It is also a consent hole, because a prerendered page can execute scripts, fire tags, and set cookies before the visitor has made any choice at all.
What actually happens during a prerender
When the browser prerenders a page, it loads and renders it in a hidden state. Scripts run. Network requests fire. If your consent setup depends on the banner being visible and the visitor clicking accept, a prerendered page has already executed the analytics and marketing stack with no banner, no choice, and no record.
Prefetch is narrower: it fetches resources without executing the page, so it is mostly a cache play. Prerender is the dangerous one, because the page is fully alive. Chrome's Speculation Rules API lets sites declare which links to prerender, and many performance plugins enable it by default for internal links.
Why tag managers do not see it
Consent tooling typically hooks the page lifecycle: on load, show the banner; on accept, release the tags. A prerendered page goes through that lifecycle in a hidden renderer. Some consent platforms detect the prerender state and defer, but many do not. The tags fire, the cookies land, and when the visitor finally navigates, the page activates with tracking already running and no consent event recorded.
The gap is invisible in testing because developers test by loading pages directly. Prerender only triggers through the speculation rules, from a real navigation flow. Your staging tests pass while production leaks.
How to detect it
The detection is straightforward once you know to look. Enable the site's speculation rules, then navigate the way a visitor would: hover the links the rules target, or just browse. In DevTools, check whether cookies from analytics and ad vendors exist before any consent interaction. If they do, the prerender path is executing your tag stack without consent.
Automate it. Add a check to your consent test suite that walks the speculation flow and asserts no non-essential cookies or tracking requests occur before a consent choice. This is the kind of test that fails once, gets fixed, and then guards the behavior forever.
The fixes, in order of reliability
The most reliable fix is to gate script execution on activation and consent, not on page load. Scripts should check two things before doing anything tracking-related: the document is actually visible and activated, and consent has been granted. The document.prerendering flag tells you the first; your consent state tells you the second.
Next, audit which links the speculation rules target. Prerendering the checkout or the signup flow has marginal performance value and maximum consent risk. Restrict prerender rules to content pages where no tracking stack runs, or disable prerendering until the consent integration is proven.
Finally, talk to your consent vendor. Ask specifically how their script handles the prerender lifecycle. If the answer is vague, that is your answer: the integration does not handle it, and the gap is yours to close.
The bottom line
Every performance feature that executes code earlier is a consent feature that executes tracking earlier. Speculative prerendering is the current version of a very old pattern: the tag stack finding a new path to run before the choice. Gate on activation, gate on consent, and test the flow your visitors actually take, not just the page loads your test suite performs.