AI Briefing
KO

How ChatGPT serves ads

·2026.04.29 21:39

Key point

Evidence has surfaced that ad units and tracking tokens are mixed into the ChatGPT response stream.

Details

Observations show that ChatGPT chat requests deliver a single_advertiser_ad_unit ad object together with SSE delta events. The advertiser_brand.id was a merchant account identifier in the format adacct_<32-hex>, and the object included ads_request_id, ads_spam_integrity_payload, carousel_cards, ad_data_token, and more.

Images and favicons for the ad cards were loaded from bzrcdn.openai.com, and links with target.open_externally: false opened within ChatGPT's internal webview. Click URLs carried utm_source=chatgptpilot along with oppref and olref; oppref was stored for 30 days as the __oppref cookie, while olref was not stored in the observed SDK.

The advertiser attached also varied depending on the conversation topic.

  • Beijing travel: Grubhub
  • Great Wall tour: GetYourGuide
  • Flights: Axel
  • NBA playoffs: Gametime
  • Spring fashion: Aritzia
  • Productivity/slides: Canva

The merchant page loaded https://bzrcdn.openai.com/sdk/oaiq.min.js (version 0.1.3), which sent measure events to bzr.openai.com. An __oaiq_domain_probe cookie was also set, and this flow was characterized as an attribution structure in which merchant-side measurements are sent back to OpenAI after a ChatGPT click.

Because the Fernet token format allows the issuance timestamp to be recovered from just the publicly visible prefix, analysis of a captured Home Depot click URL showed it was generated at 2026-04-26 11:30:08 UTC, with the merchant page opening 95 seconds later.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.