ChatGPT ads are sponsored cards that appear below a response for users on the Free and Go plans, matched to the topic of the current conversation rather than to a cookie profile. Cookies still enter the picture in three places: the marketing cookies OpenAI sets to promote ChatGPT on other websites (switched on by default for free US accounts since 30 April 2026), the first-party attribution cookie an advertiser's site sets when someone clicks a ChatGPT ad, and the consent rules that decide whether either of those may be set at all.
As of September 2026, ads are live in the United States, Canada, Australia, New Zealand, the United Kingdom, Mexico, Brazil, Japan, South Korea and 31 European markets. The rules differ by region. The advertiser-side cookie is where most website owners have work to do.
Key takeaways
ChatGPT ads launched in the US on 9 February 2026 for the Free and Go plans. Paid plans and accounts OpenAI identifies as under 18 don't see them.
Since 24 August 2026 ads run across 31 European markets on a two-tier model: contextual ads on legitimate interest, personalised ads only after an explicit opt-in that OpenAI has not yet switched on in the EEA.
OpenAI's 30 April 2026 US privacy policy update lets it share cookie IDs, IP addresses and hashed email addresses with ad platforms to promote its own products. Wired found the Marketing Privacy setting on by default for free accounts and off for paid ones.
Advertisers measure conversions with the OpenAI Measurement Pixel, which stores a click identifier in a first-party
__opprefcookie on the advertiser's domain. That cookie needs prior consent under Article 5(3) of the ePrivacy Directive.The pixel initialises with consent set to true unless you call
oaiq("consent", false)before init or block the script until a visitor opts in.
What Are ChatGPT Ads and Who Sees Them?
ChatGPT ads are paid placements shown beneath a response, labelled as sponsored and visually separated from the answer. They appear only for users on the Free plan and the Go plan (roughly USD 8 or EUR 8 a month), never on Plus, Pro, Business, Enterprise or Edu accounts, never in Temporary Chats, and never to accounts OpenAI's age-prediction model flags as under 18.
Each ad unit carries the advertiser name, a favicon, a headline, a short description, an image and a landing page link. Advertisers buy on cost per thousand impressions (CPM) or cost per click (CPC), with OpenAI suggesting a starting maximum bid of USD 3-5 per click. A relevance-weighted second-price auction picks the winner.
The programme is still labelled beta: a focused pilot ran from February to April 2026, then self-serve onboarding opened in Ads Manager Beta, where campaigns are structured as campaign, ad group and ad. Every ad is reviewed before it serves, accounts pass business verification, and OpenAI says it has no cross-advertiser performance benchmarks yet.
The rollout has been fast. The US pilot began on 9 February 2026, Canada, Australia and New Zealand followed, the UK went live in June, and Mexico, Brazil, Japan and South Korea were added in August. On 18 August OpenAI announced 31 European countries from 24 August, with self-service Ads Manager access across those markets from 31 August. OpenAI says tens of thousands of marketers have advertised in ChatGPT, and trade press puts the business near a USD 1 billion annualised run rate.
None of this places OpenAI cookies on your site: ad selection happens on chatgpt.com. The cookies chatgpt.com itself sets are a separate topic from the ad system, the marketing cookies behind OpenAI's own campaigns, and the pixel you install if you advertise there.
| Layer | What is stored or shared | Who controls it | Consent rule |
|---|---|---|---|
| Ad selection inside ChatGPT | Current chat context, approximate location, device type, time of day, language; with personalisation on, past chats, memory and ad history. Held server-side against the account, not in advertiser cookies | OpenAI (OpenAI Ireland Limited for EEA and Swiss users) | EEA: legitimate interest for contextual ads, consent for personalised ads. US: personalisation on by default with an opt-out toggle |
| OpenAI's own marketing cookies | Cookie ID, IP address and hashed email or phone shared with social networks and ad platforms so OpenAI can advertise ChatGPT, Codex and paid tiers elsewhere | OpenAI and its marketing partners | US: on by default for Free accounts, opt-out via Marketing Privacy or Global Privacy Control. EEA and UK: prior opt-in through the cookie banner |
| Advertiser measurement | oppref click ID captured from the landing URL and stored in a first-party __oppref cookie; SHA-256 hashed customer data; server-side events via the Conversions API | The advertiser | EEA and UK: consent before the pixel runs. California and other US states: honour do-not-share opt-outs and the GPC signal |
How Does ChatGPT Decide Which Ad to Show?
The ads system scores eligible ads on expected relevance and outcome. It reads the context and intent of the current thread, the ad's landing page, title and copy, the context hints an advertiser attaches to an ad group, and, where personalisation is on, signals from the user's wider ChatGPT experience. Context hints are not exact-match keywords, so nobody can buy a specific phrase the way they would in search. Targeting is coarse by design: country level everywhere, with state, designated market area and ZIP code options in the US and a choice of iOS, Android or web surfaces, and OpenAI's crawler guidance notes that landing page content may also be used to judge when an ad is relevant.
Personalisation is the fork. With it on, OpenAI may use memories, reference recent chats, and look at which ads a user hid or clicked. With it off, ads still appear, but only the current thread, general location and language feed the selection. Users can review the topics used, delete ads data (removed within 30 days), hide or report an ad, or open the three-dot menu to see why it was shown. The controls sit under Settings > Ad Controls and are described on OpenAI's Ads in ChatGPT help page.
Advertisers get aggregate reporting: impressions, clicks, spend, click-through rate, average CPC and CPM, and conversions. They never receive chat content, chat history, memories, names, email addresses, precise location or IP addresses from OpenAI's ad system. If a user chooses to message an advertiser through an ad, the advertiser sees only those messages.
OpenAI also keeps ads away from personal health, mental health and political conversations, and doesn't accept political advertising. Where OpenAI offers it, Free users can switch to an Ads-Free mode that trades ads for lower message limits and fewer tools, a design choice that matters when the consent-or-pay question comes up.
What Changed When OpenAI Switched On Marketing Cookies by Default?
On 30 April 2026 OpenAI emailed US users about a privacy policy update. It would start using cookies to promote its products and services on other websites, while conversations stayed private and unshared with marketing partners. Wired compared the new policy against a saved earlier version and tested accounts, finding the Marketing Privacy setting switched on by default for two free accounts and off for paying subscribers.
The mechanics sit in OpenAI's help page on promoting its products on third-party properties. OpenAI shares two kinds of data with social networks and large advertising platforms. The first is identifiers that don't reveal a real-world identity: a cookie ID tied to the browser or device, an IP address, or an email address or phone number run through a hash. The second is basic commercial and browsing information, such as whether an account is on the free tier or whether the user visited a page describing a specific product. The partner matches those identifiers to its own records, which is how a free user who looked at Codex can see a Codex ad on Instagram, and how OpenAI measures whether that ad led to a sign-up.
This is OpenAI acting as an advertiser, not the in-chat ad system. The vehicle is the same marketing cookie stack any software company runs: the Meta Pixel, Google Ads conversion tags and LinkedIn Insight cookies already observed on chatgpt.com, now paired with account-level identifiers.
OpenAI's US privacy policy, current version dated 18 May 2026, classifies this sharing as "targeted advertising" or sharing for cross-context behavioural advertising under state privacy laws, which triggers an opt-out right. Logged-in users switch it off at Settings > Data Controls > Marketing Privacy. Logged-out visitors use the Manage Cookies or Your Privacy Choices link in the footer, and OpenAI states it recognises Global Privacy Control (GPC) as a legally valid opt-out signal. The same policy confirms OpenAI receives purchase data back from advertisers to measure and improve ads shown to Free and Go users, and that it doesn't run this sharing for users it knows to be under 18.
Default-on is a US design. In the EEA and UK the chatgpt.com cookie banner asks first, because Article 5(3) of the ePrivacy Directive requires consent before non-essential cookies are stored, and a pre-enabled marketing toggle would not satisfy it. The CNIL's EUR 325 million fine against Google on 1 September 2025 turned partly on cookies set during account creation where refusing personalised advertising was harder than accepting it.
How Do Advertisers Measure ChatGPT Ad Conversions?
Advertisers measure conversions with the OpenAI Measurement Pixel, a JavaScript SDK exposed as a global oaiq function and loaded from bzrcdn.openai.com, backed by a 1x1 image tag fallback and a server-side Conversions API. Click attribution relies on an oppref parameter that OpenAI appends to the landing URL, in the form ?oppref=gAAAAAb123. The pixel captures it and stores it in a first-party cookie named __oppref on your domain. It then sends the value with later events to bzr.openai.com.
Supported events include page_viewed, order_created, lead_created, subscription_created and trial_started, plus custom events. Click-through attribution uses a configurable click window; view-through attribution, where enabled, uses a fixed one-day window after an impression.
Matching goes beyond the click ID. The init call accepts a user object with SHA-256 hashes of email, phone number, external ID, first name and last name, plus plain-text country, city, region and postal code. With automatic advanced matching enabled, the pixel detects supported customer fields on your pages, hashes them in the browser and attaches the hashes to conversion events without code changes. The Conversions API accepts the same hashed identifiers server-side, together with IP address and user agent, and deduplicates against browser events by event_id. Stape's server-side Google Tag Manager tag reads and sets __oppref from the server container.
OpenAI's own Conversion Measurement guidance puts the consent burden on the advertiser: it says conversion data should be sent only after giving users clear information about the data collected on the site or app and obtaining every consent the law requires. The same page explains that, where modelled measurement is available, OpenAI estimates attribution for unattributed conversions from aggregated patterns, and that reported totals may include those modelled conversions. It also lists browser, consent and storage conditions among the reasons Ads Manager, GA4 and other platforms report different numbers. Measurement partners such as LiveRamp, Hightouch, Triple Whale, Fospha and WorkMagic can send events on your behalf using your Pixel ID and API key, which adds another processor to your data map.
Two limits matter for European campaigns. Custom Audiences let you upload email addresses, phone numbers or Google Advertising IDs to include or exclude known customers; inclusion needs at least 25,000 matched users, and OpenAI deletes the upload file within 24 hours of processing. They are not supported for campaigns targeting the EEA or Switzerland while personalised ads remain unavailable there. And the pixel's consent behaviour defaults the wrong way for EU traffic: consent initialises as true unless you explicitly set it to false before init or the pixel finds a stored denial. Events blocked while consent is false are not replayed when it later becomes true.
The documented pattern for a consent-gated install looks like this:
<script>
oaiq("consent", false);
oaiq("init", { pixelId: "YOUR-PIXEL-ID" });
</script>
// Later, from your CMP's consent callback:
oaiq("consent", true);A cleaner approach is to keep the SDK out of the page until consent exists. Any consent management platform with script blocking can hold the loader as type="text/plain" and rewrite it only after the visitor opts in to advertising cookies, which means no request to bzrcdn.openai.com and no __oppref cookie until then. If your site enforces a strict policy, the pixel needs script-src for bzrcdn.openai.com, connect-src and img-src for bzr.openai.com, and OpenAI's docs show how to pass a CSP nonce on the loader tag rather than adding unsafe-inline.
Do ChatGPT Ad Cookies Need Consent in the EU and UK?
Yes, on the advertiser's side. Article 5(3) of the ePrivacy Directive requires consent before information is stored on, or read from, a user's device unless it is strictly necessary for a service the user asked for. An attribution cookie that links a purchase back to an ad click is not strictly necessary for anything the visitor requested, so __oppref needs prior opt-in. UK PECR regulation 6 says the same, and the exemptions the Data (Use and Access) Act added for low-risk analytics don't stretch to advertising attribution.
The EDPB's Guidelines 2/2023 on the technical scope of Article 5(3), adopted in final form on 7 October 2024, list URL tracking parameters and tracking pixels as covered use cases. The oppref parameter, the cookie that stores it and the beacon that reads it back all fall inside the rule, whether or not the identifier counts as personal data.
Inside ChatGPT, OpenAI has built a different structure for Europe. Its Europe privacy policy, updated 24 August 2026 with OpenAI Ireland Limited as controller and the Irish Data Protection Commission as lead authority, splits advertising into two legal bases. Contextual ads that use the current chat, approximate location, time of day and device type run on legitimate interest, which users can object to. Personalised ads that draw on past chats, ad interactions and advertiser-supplied data run only on consent, and OpenAI says it will ask before switching personalisation on in the EEA. Measurement reporting to advertisers, delivered in aggregate, also sits on legitimate interest.
Whether that holds is the open regulatory question. In Opinion 08/2024 on consent-or-pay models, the EDPB said large platforms should offer a genuine alternative to behavioural advertising that doesn't cost money. OpenAI's model differs from the Meta case it was written for: declining personalisation still gets you the free product with contextual advertising, and in some regions an Ads-Free tier with reduced limits exists. Trade press reported that the Irish DPC had not commented publicly as of the 24 August launch, and no supervisory authority had opened a public inquiry at the time of writing.
| Region | In-chat ads: legal basis | Personalised ads | OpenAI marketing cookies | Advertiser pixel and __oppref |
|---|---|---|---|---|
| United States | No prior-consent requirement; state laws grant opt-outs | On by default, toggle off in Ad Controls | On by default for Free; opt out via Marketing Privacy, Your Privacy Choices or GPC | Do-not-share opt-out and GPC must be honoured in California and other opt-out states |
| EEA and Switzerland | Contextual ads on legitimate interest (Europe privacy policy, 24 August 2026) | Consent only; not yet offered at launch | Prior opt-in via cookie banner under Article 5(3) | Prior opt-in via cookie banner; Custom Audiences unavailable |
| United Kingdom | Live since June 2026; contextual by default | Explicit opt-in only, per OpenAI's European ad terms | Prior opt-in under PECR regulation 6 | Prior opt-in under PECR regulation 6 |
What Should Advertisers and Website Owners Do Now?
If you plan to advertise in ChatGPT, treat the OpenAI pixel like the Meta Pixel or Google Ads tag: an advertising technology that stores an identifier on the visitor's device and shares hashed personal data with a US company. Five steps cover most of the work.
Add the pixel, the
__opprefcookie and thebzr.openai.comendpoints to your cookie declaration under the marketing or advertising category, and name OpenAI as a recipient with a US transfer in your privacy notice.Block the loader until consent. Script blocking is the cleanest route; if you must run the snippet earlier, call
oaiq("consent", false)beforeinitand flip it from your CMP callback, remembering that blocked events are lost, not queued.Don't treat the Conversions API as a way around consent. Hashed email addresses are pseudonymised personal data under the GDPR, not anonymous data, and sending them server-side still needs a lawful basis and the same transparency.
For US traffic, connect the GPC signal and your do-not-share link to the pixel. Both the pixel and the API accept an
opt_outflag that excludes an event from future user-level personalisation, but the safer reading of a GPC signal is to suppress the pixel altogether.Keep UTM parameters on every destination URL so GA4 or Matomo can cross-check OpenAI's click counts, and make sure
robots.txtand bot protection allowOAI-AdsBot, which OpenAI requires for landing-page review, and ideallyOAI-SearchBotas well.
Kukie.io's scanner picks up the __oppref cookie and the bzrcdn.openai.com loader, categorises them as marketing, and holds the script until a visitor consents. Geo-detection shows an opt-in banner to EU and UK visitors and an opt-out notice to Californians. One pixel install can meet both regimes.
Frequently Asked Questions
Do ChatGPT ads use cookies to target me?
No. Ad selection happens on OpenAI's servers using the topic of your current chat and, if personalisation is on, your past chats, memory and ad history. Advertisers receive only aggregate view and click counts, never cookie IDs, chat content or your email address.
How do I turn off ChatGPT marketing cookies?
Sign in and go to Settings > Data Controls > Marketing Privacy and switch it off. If you're logged out, use the Manage Cookies or Your Privacy Choices link in the site footer; OpenAI's US policy also recognises the Global Privacy Control browser signal as an opt-out.
What is the __oppref cookie?
It's a first-party cookie the OpenAI Measurement Pixel sets on an advertiser's own domain. It stores the oppref click identifier from a ChatGPT ad landing URL so later page views and conversions can be attributed back to the ad click.
Are ChatGPT ads personalised in Europe?
Not at launch. Since 24 August 2026, EEA and Swiss users on Free and Go see contextual ads based on the current chat, approximate location, device type, time of day and language, which OpenAI runs on legitimate interest. Personalised ads using past chats and ad history require a separate explicit opt-in.
Does the OpenAI pixel need a cookie banner?
Yes for EU and UK visitors. The pixel stores a click identifier in a first-party cookie and reads it back on later visits, which falls under Article 5(3) of the ePrivacy Directive and regulation 6 of UK PECR. It should load only after a visitor opts in to marketing or advertising cookies.
Can I use ChatGPT free without ads?
In regions where OpenAI offers it, the Free plan has an Ads-Free option that removes ads in exchange for lower message limits and fewer tools. Turning off ad personalisation alone doesn't remove ads; upgrading to Plus or Pro does.
Check Your Site Before the Next Campaign
If you're adding the OpenAI pixel to a site that serves EU, UK or Californian visitors, start with a scan to see what it sets and where. Kukie.io detects the cookies and scripts on your pages, categorises them, and blocks advertising tags until your visitors make a choice.
