Morning Overview

OpenAI’s new ad system will target you inside ChatGPT using your own conversations

Sen. Ed Markey has sent a pointed letter to OpenAI and other AI chatbot companies asking whether they intend to use the content of users’ private conversations to personalize advertising. The letter arrives as OpenAI builds out an ad system for ChatGPT, and as new academic research demonstrates that even anonymized chat logs can reveal personal details about users and, in some cases, re-identify them. Together, these developments raise a direct question for the hundreds of millions of people who type sensitive queries into AI chatbots every day: could your own words become the raw material for ad targeting?

Why conversation-based ad targeting inside ChatGPT matters now

The core tension is straightforward. People treat chatbot conversations like private exchanges, sharing health concerns, financial anxieties, relationship troubles, and career plans in natural language. If OpenAI or its competitors feed that dialogue into ad-targeting systems, the gap between what users expect and what actually happens with their data becomes enormous. Markey’s letter, addressed to OpenAI and other AI and chatbot companies, asks directly whether these firms plan to use the content of users’ conversations, including sensitive and personal information, to personalize advertising. The letter also asks whether outside data sources such as social media feeds or search histories would be layered on top.

That question is not hypothetical. OpenAI has publicly discussed plans to introduce advertising into its products, and the company’s massive user base makes conversation data an obvious asset. Unlike traditional web ads, which rely on cookies, browsing history, or declared interests, chatbot-based targeting could draw on the full texture of what a person says in their own words. A user asking ChatGPT about symptoms of a chronic illness, for example, would generate data far more specific than a search query on the same topic.

The risk is not limited to uncomfortable ad placements. A research paper titled “Inferential Privacy Leakage in Anonymized Conversational AI Logs,” published on arXiv, found that machine learning models can infer demographic attributes and even identify individual users from partial conversation histories in a donated dataset. The study’s findings suggest that stripping out names and email addresses is not enough to protect privacy when the conversation itself carries identifying patterns.

Markey’s letter and the arXiv research that supports its premise

Markey’s letter does not accuse OpenAI of already mining conversations for ads. Instead, it poses a series of specific questions designed to force the company into a public position. The senator asks whether conversation content, including sensitive or personal information, would feed ad personalization, and whether ad agreements would influence the responses ChatGPT gives to users. Those questions reflect a concern that advertising incentives could distort the product itself, not just the data practices around it.

The academic research adds empirical weight to those concerns. The arXiv paper used a donated dataset of conversational AI logs that had been anonymized and filtered for personally identifiable information. Even after that filtering, the researchers found that models could infer demographic attributes from the text and match partial conversation snippets to specific users. The paper, which is also listed in Harvard’s Astrophysics Data System, represents one of the first systematic attempts to measure how much identifying information leaks through the structure and content of chat logs alone.

The practical implication is that anonymization, the standard privacy defense for companies that want to use customer data, may not work for conversational AI logs the way it works for, say, aggregated web traffic. A person’s writing style, the sequence of topics they explore, and the specificity of their questions can function as a fingerprint. If an ad system processes those logs, even in supposedly de-identified form, the re-identification risk is real.

What OpenAI has not answered about ChatGPT ad targeting

Several critical gaps remain. OpenAI has not publicly responded to Markey’s letter or disclosed the technical architecture of its planned ad system. There is no public documentation showing whether conversation content would be processed for targeting, whether it would be anonymized first, or whether users would have a meaningful opt-out. The company has also not released any internal privacy assessments related to advertising.

The arXiv paper, while significant, has its own boundaries. The researchers worked with a donated dataset, not with production ChatGPT logs. OpenAI’s actual data pipeline may include additional safeguards, or it may not. Without access to the company’s systems or data-sharing agreements, independent researchers cannot measure the real-world re-identification risk with precision. The paper demonstrates that the risk exists in principle and can be measured in controlled conditions, but the scale of the problem inside ChatGPT’s live infrastructure is an open question.

There is also no regulatory framework specifically designed for this scenario. Existing U.S. privacy law does not clearly address whether AI conversation logs qualify as protected personal data when they have been stripped of traditional identifiers but remain behaviorally unique. The Federal Trade Commission has taken enforcement actions against companies that misrepresented their data practices, but no rule explicitly governs ad targeting based on conversational AI content.

For users, the practical takeaway is concrete. Anyone who shares personal details with ChatGPT or similar systems should assume that their words could, in theory, be analyzed for patterns that reveal who they are and what they care about. That does not mean OpenAI is currently doing so for ads, but it underscores why Markey is pressing for clear answers before an ad system is fully deployed.

What meaningful safeguards would look like

Markey’s questions implicitly sketch a set of guardrails that privacy advocates have long urged for other kinds of behavioral advertising. One is a bright-line rule against using sensitive categories-such as health status, sexual orientation, immigration status, or information about children-for ad targeting at all. Another is a requirement that any use of conversation content for commercial purposes be strictly opt-in, with clear, plain-language explanations of what data is being collected and how it will be used.

Technical safeguards could also play a role. For example, companies could process conversation data in aggregate, focusing on broad usage trends rather than individual profiles. They could limit retention periods, deleting raw logs after a short window. They could design ad systems that rely on contextual signals-what appears on the screen at a given moment-rather than long-term behavioral histories stitched together from many chats.

But as the arXiv research shows, even seemingly cautious approaches can backfire if they rely on storing rich conversational histories. The more text a system has from a single user, the easier it becomes to infer who that person is. That reality puts pressure on companies to minimize the amount of conversation data they collect and retain in the first place, not just to promise stronger protections after the fact.

The stakes for trust in AI assistants

Beyond legal compliance, the question of ad targeting inside chatbots goes to the heart of whether people will trust AI assistants with their most intimate concerns. If users begin to suspect that every confession about a medical scare or a family dispute might be quietly repurposed for marketing, they may hold back the very information that makes these tools useful.

Markey’s letter is an early attempt to force a public debate over those tradeoffs before the business model for AI assistants hardens around advertising. The arXiv findings, meanwhile, serve as a technical warning that traditional notions of anonymization may not be enough when the data in question is a detailed record of how a person thinks and speaks. Together, they pose a simple but unresolved question for OpenAI and its peers: will the future of chatbots treat conversation as a private space, or as another stream of behavioral data to be monetized?

More from Morning Overview

*This article was researched with the help of AI, with human editors creating the final content.