Some info here : - https://mobile.twitter.com/Chronotope/status/151390041563242...
It does, but if you read carefully you'll see there's no source saying that's how that's being implemented. It's all speculation on the author's part. In fact, one of the sources linked (wired.com) says the opposite, claiming that it's "based on a user’s IP address", which wouldn't require any HTTP header injection.
I already stopped trusting my ISP after it was announced that one of the three UK LTE internet providers had implemented the "log absolutely everything" clause in the snoopers charter... I guess now the cats out of the bag, Vodafone is likely the provider, since they can probably build upon what they have already implemented and sell it to 3rd parties. Pretty gross.
If I had to guess, they probably have a process similar to a cookie sync to obtain this id.
Sending just the IP would be useless, as the publisher already has the IP address (and sends it to bidstream, although it is truncated for privacy) so there would be little incentive to pay for the carrier data.
I worked in adtech for a while, and designed a system similar to this for a large UK carrier, although it never ended up being implemented as carrier was worried about optics.