Reading the Minds of the Masses: Ads in ChatGPT Are Only a Bridge

Ads in ChatGPT are not about the format of the card, but about the profiling infrastructure underneath it. Protection starts at the login layer.

8/25/2026
Reading the Minds of the Masses: Ads in ChatGPT Are Only a Bridge
Watch the login layer, not the ad

We are entering, for good, an era in which artificial intelligence stops being a research toy. The arrival of advertising integrations and targeting in the major AI services is not just a new way to monetize, it is a fundamental shift for the whole industry.

On 24 August, advertising in ChatGPT went live in 31 European countries. The format is emphatically modest: a separate card under the answer with a Sponsored label, only on the free plan and on Go. That modesty is the most interesting part.

What used to look like paranoia is gradually becoming a standard business model: free users can turn into the product, and their conversations into fuel for targeting. And the key question is not even about the good faith of one particular company. It is about the absence of external, independent auditing of the ranking algorithms.

In the six months since the pilot, a full performance stack has been assembled: from CPM to CPC and on to conversion optimization, plus geotargeting, custom audiences, a proprietary pixel and a conversions API. That is not how you build a tidy caption under an answer. That is how you build a foundation. The card is the interface of today, the infrastructure beneath it is designed for tomorrow.

Properties of the environment: why AI advertising is more dangerous than any search engine

The main problem here is not data collection as such. The problem is how exactly we will perceive the answers of an algorithm once they are commercialized.

The objective expert effect

A banner in a search engine is read instantly: banner blindness and critical thinking kick in. But a neural network is perceived as an impartial adviser. Its native recommendation of a service or an idea is read as expert advice.

A strike at personal vulnerability

People often write things into a chatbot that they would not even ask Google: their fears, their doubts, their personal and professional pain. A native nudge delivered at a moment of emotional vulnerability affects the mind far more strongly than classic advertising.

Soft shaping of the picture of the world

This is no longer about a Buy now call to action. It is about a gradual shift of priorities. By selecting the right arguments, an algorithm can gently shape the tastes and views of a reader.

And the absence of public examples of aggressive advertising right now is not yet proof that it will be absent in the future. It is a property of a closed environment, where the boundaries of recommendations are not subject to outside verification.

The main line: where does profiling begin?

Any native manipulation becomes possible only at one moment: when the service identifies the user and links their actions together.

As soon as a digital profile is created, the query history, the email, the phone number and behavioural markers are attached to it. With no cross-service profile there is no precise manipulation across platforms either. That is why the basic defence is not built at the stage of privacy settings inside the chat. It is built at the very first step, at the moment of signing in.

While developing a next generation authentication concept, I built an access-first approach into it. It is an architecture that rules out the possibility of assembling a cross-service portrait:

  • No cross-service identifiers (emails, phone numbers, social graphs);
  • The service receives only a confirmation of the right to enter, without any data that would let it link the activity of a user across different resources;
  • Architectural separation of the fact of authorization from the collection of a behavioural trail.

The honest limit of the approach: anonymous sign-in does not protect against analysis of the context inside one particular session, but it denies the system the main thing, the ability to accumulate a long-term digital portrait of a person beyond a single service.

Short-term gain versus long-term resilience

Over a short distance, a business model built on data collection and aggressive targeting always looks more attractive for extracting profit quickly. Yet the history of the IT market shows that monetizing the privacy of other people inevitably runs into a crisis of trust and a regulatory dead end.

The Cambridge Analytica scandal cost Facebook billions in fines and a fundamental loss of user trust. Apple, meanwhile, made privacy its main commercial advantage, and its decision to let users turn off tracking redistributed the revenues of entire industries.

In the long run the winning architecture is always the one that accounts for the interests of everyone in the deal, instead of turning the user into raw material. Building fully anonymous authentication systems is not a rejection of commerce. It is an investment in resilience, where the service gets access and the user keeps their digital sovereignty.

Corporations will keep building deep profiling tools, that is their business model. But another technological vector is developing in parallel, one where the architectural autonomy of the person remains the priority.

The Sponsored card of today is the most harmless thing that can be built on the infrastructure assembled underneath it.

While everyone discusses the format of the ads, the thing to watch is the login layer. Everything else is decided there.

Read more