Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

AEC Cookie (Google) – What It Is and What It Does

AEC is an HTTP cookie set by Google on the .google.com domain, mainly used for anti-fraud and anti-abuse protection across Google services. It typically lasts 6 months and is classified by CookieFix as strictly necessary.

Name
AEC
Provider
Google
Category
Necessary
Type
HTTP cookie
Lifetime
6 months
Domain / notes
.google.com
Consent
No, but it must be listed in the cookie policy

What is the AEC cookie?

AEC is a cookie set by Google when a visitor interacts with Google services embedded in a website, such as Google sign-in forms, reCAPTCHA, "Sign in with Google" widgets, or other components loaded from the google.com domain.

The cookie appears automatically, without any action from the site administrator, whenever the visitor's browser communicates with Google's servers through such embedded components.

What data it stores

AEC belongs to Google's family of security-related cookies used to detect automated traffic, suspicious requests, or abuse attempts against Google forms and services. The exact value format is generated and interpreted internally by Google; its content is not publicly documented by the provider.

The data is sent to the .google.com domain and processed by Google, not by the site hosting the embedded component.

What it is used for

The main purpose of the AEC cookie is to protect Google's infrastructure against abusive automated access—bots, malicious scripts, credential-stuffing attempts—targeting forms and services that involve Google.

For the site administrator, this cookie's presence is an indirect consequence of embedding Google components (sign-in, anti-spam checks, etc.) and contributes to their correct and secure operation.

Does it require consent?

CookieFix classifies AEC as a strictly necessary cookie, since its role relates to security and fraud prevention rather than statistics or marketing.

  • Under Law 506/2004 (transposing the ePrivacy Directive) and ANSPDCP guidance, cookies strictly necessary for a service explicitly requested by the user can be exempt from prior consent requirements.
  • The site administrator should still list this cookie in the site's cookie policy, along with its purpose and provider.
  • Administrators should verify exactly which Google components trigger this cookie on their site, to describe it accurately in the policy.

How to block or delete AEC

A visitor can manually delete or block the AEC cookie through browser settings (Chrome, Firefox, Edge, Safari), in the per-site cookie management section. Blocking it may affect the functioning of embedded Google components, such as sign-in.

For site administrators who want centralized control over all cookies, including declared strictly necessary ones, a CMP platform like CookieFix can automatically block third-party scripts until consent is given, for those opting for a stricter approach than the legal minimum.

Frequently asked questions

No, it's a technical security cookie used by Google to prevent fraud and abusive automated access, not for advertising tracking.

It is set by Google on the .google.com domain, as part of its services and components embedded in third-party websites.

Generally no, since it's considered strictly necessary for service security, but it should still be listed in the site's cookie policy.

Its typical duration is around 6 months, after which it expires automatically from the browser.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.