ChatGPT Ad Tracking Cookie Follows Users Across Third-Party Advertiser Websites

ChatGPT Ad Tracking Cookie Follows Users Across Third-Party Advertiser Websites

Artificial intelligence platforms are increasingly becoming part of everyday browsing, search, shopping, and decision-making. That makes the data surrounding AI interactions particularly sensitive. When an AI platform is connected to an advertising ecosystem, the security question is no longer limited to what users type into a chatbot. It also extends to how identifiers and behavioral data move between the AI service and the wider web.

A new investigation reported by Cybersecurity News has highlighted exactly this concern. OpenAI’s advertising measurement system reportedly uses a cross-site cookie called __obi that can connect activity on third-party advertiser websites with a user’s ChatGPT account or device-linked identifier. The mechanism was reproduced across 936 advertiser pixels on 1,029 hostnames, raising significant questions around cross-site tracking, data collection, and consent.

The discovery is particularly notable because ChatGPT is an AI service where users may discuss highly personal subjects that they would not normally share with conventional advertising platforms.

How the Tracking Mechanism Works

The reported mechanism begins when a user opens ChatGPT.

According to the investigation, the ChatGPT client generates a random identifier and requests a short-lived signed token from OpenAI’s backend. That token contains information including an account-linked subject value, the obi identifier, and a consent decision indicating analytics_allowed.

The token is then sent to:

bzr.openai.com

The service reportedly responds by setting the __obi cookie on the .openai.com domain.

The cookie has several important properties:

  • SameSite=None
  • Secure
  • A maximum lifetime of approximately one year

The SameSite=None configuration is particularly important because it allows the browser to include the cookie in cross-site requests.

This makes the cookie fundamentally different from cookies restricted to the originating site.

Once the identifier exists in the browser, it can potentially accompany requests generated when the user visits other websites that have OpenAI’s advertising measurement pixel installed.

From ChatGPT to Third-Party Websites

The advertising ecosystem creates the bridge between ChatGPT and participating advertiser websites.

Companies running ChatGPT advertising campaigns can install OpenAI’s measurement pixel on their websites. The pixel loads OpenAI-hosted code and sends advertising conversion events back to OpenAI infrastructure.

When a visitor already has the __obi cookie, the browser can automatically attach the identifier to those cross-site requests.

That creates a potential chain:

ChatGPT → __obi identifier → advertiser website → OpenAI advertising pixel → OpenAI measurement infrastructure

The investigation observed this behavior across 936 advertiser pixels and 1,029 hostnames, demonstrating that the mechanism was not limited to a single website or isolated implementation.

The researchers also observed the identifier across commercial websites, showing that the mechanism can operate across a broad advertising ecosystem.

What Can Be Collected From Advertiser Websites?

The privacy implications become more significant when looking beyond the cookie itself.

The investigation reported that OpenAI’s advertising software can receive information intentionally provided by advertisers and can also collect information from advertiser webpages.

Observed sources included:

  • Form fields
  • Rendered webpage content
  • Tag-management systems
  • Identity-related information
  • Conversion events
  • Page URLs and paths

The research reported observed data including hashed email addresses, phone numbers, and names, as well as location information such as country, region, city, and postal code.

The researchers also reported that page paths remained visible even though query strings were removed from observed URLs.

That matters because URLs and page paths can reveal the subject of a user’s activity.

The investigation reported paths associated with areas such as:

  • Medical conditions
  • Debt-related services
  • Legal-intake services

This does not mean that every advertiser page sends sensitive information. It does demonstrate why advertising telemetry can become sensitive when it is attached to a persistent identifier.

Tracking Can Also Occur Without a ChatGPT Login

Another important finding concerns users who are not logged into ChatGPT.

The investigation reported that anonymous users could receive a device-linked subject identifier that remained stable for at least 27 days during testing.

This means that the absence of a ChatGPT login does not necessarily eliminate the tracking mechanism.

Instead, the system can potentially operate using a persistent anonymous identifier associated with the device or browser context.

That distinction is important.

Anonymous does not necessarily mean untrackable.

An identifier can remain anonymous in the sense that it is not directly labeled with a person’s name while still allowing activity from the same browser or device to be correlated over time.

The Consent Question

One of the most important aspects of the investigation is how the __obi cookie is classified.

OpenAI’s cookie policy reportedly lists __obi as an analytics cookie rather than a marketing cookie. The investigation also observed synchronization tokens carrying:

consent_decision: analytics_allowed

The researchers reported observing this even in cases where marketing consent had reportedly been denied.

This creates an important privacy question.

If an identifier is used to connect activity across third-party advertiser websites, should that activity fall exclusively under an analytics classification?

The investigation does not resolve that legal question. Instead, it documents the technical behavior and highlights the resulting discrepancy that privacy professionals need to examine.

OpenAI acknowledged a privacy inquiry but had not provided a detailed response regarding the classification or consent behavior at the time of the Cybersecurity News report.

Browser Limitations Matter

The tracking mechanism is not universal across every browser environment.

The research primarily reproduced the behavior on Chrome for Android.

Safari’s Intelligent Tracking Prevention blocks third-party cookies, meaning the reported cross-site cookie mechanism should not operate in Safari or other iOS browsers based on WebKit.

This provides an important reminder for security and privacy teams:

Browser privacy controls can materially change the behavior of third-party tracking technologies.

However, organizations should not assume that one protected browser environment automatically protects users across every device, operating system, or browser.

Why This Is a Security Issue, Not Just an Advertising Issue

At first glance, advertising cookies may appear to be primarily a marketing or privacy concern.

For enterprises, however, the issue extends into cybersecurity.

Organizations increasingly use AI platforms for:

  • Research
  • Software development
  • Customer support
  • Legal analysis
  • Business intelligence
  • Security operations
  • Financial analysis
  • Internal knowledge management

That makes AI-related identifiers and behavioral data increasingly valuable.

If an identifier can connect activity from an AI service with activity on external websites, it potentially creates a broader behavioral profile than either system would reveal independently.

The risk becomes especially important when employees use AI services while simultaneously accessing corporate resources.

Security teams therefore need to consider not only what data enters an AI platform, but also what telemetry leaves the platform and where it can be correlated.

AI Platforms Need a Different Privacy Security Model

Traditional web tracking is already well understood.

Advertising networks have used pixels, cookies, device identifiers, conversion tags, and cross-site measurement systems for years.

The difference with AI assistants is the context surrounding the service.

A user might ask an AI assistant about:

  • A medical issue
  • Financial difficulties
  • A legal problem
  • A confidential business project
  • A software vulnerability
  • An internal security incident
  • A customer problem

The sensitivity of AI usage means that privacy architecture around AI platforms deserves the same level of scrutiny traditionally applied to identity systems, SaaS applications, and sensitive data flows.

This is where organizations need visibility into AI applications, AI-related data flows, third-party integrations, and behavioral activity rather than treating AI as simply another website.

Seceon: Extending Visibility Into the AI-Driven Environment

aiSIEM / CGuard: Correlating Identity, Network, and Application Activity

For organizations deploying AI services across the enterprise, aiSIEM / CGuard can help bring together telemetry from identities, endpoints, networks, applications, cloud environments, and other infrastructure.

In a scenario involving third-party AI advertising or tracking infrastructure, security teams need the ability to correlate:

User identity → endpoint → browser activity → external domains → cloud services → application behavior

This broader visibility can help security teams identify unexpected communication patterns and understand how sensitive enterprise activity interacts with external services.

The goal is not simply to block legitimate advertising infrastructure.

It is to establish visibility into what external services are communicating with enterprise endpoints and whether that behavior aligns with organizational policy.

aiXDR-PMax: Protecting the Endpoint and Browser Environment

aiXDR-PMax provides endpoint-focused visibility that can complement network and application telemetry.

From a security perspective, browser activity is increasingly part of the enterprise attack surface. Malicious extensions, compromised websites, injected scripts, credential theft, and unauthorized data collection can all occur through browser-based workflows.

Endpoint telemetry can therefore provide an additional layer of context when suspicious browser processes, applications, or outbound connections appear.

For organizations concerned about sensitive AI usage, endpoint visibility can help establish which applications and processes are communicating with external services and whether that behavior is consistent with enterprise policy.

aiTRiSM (Upcoming): Governing the Expanding AI Ecosystem

The emergence of AI advertising ecosystems also reinforces the need for dedicated visibility into enterprise AI usage.

Seceon’s upcoming aiTRiSM is relevant to this evolving environment because organizations increasingly need to discover and understand AI applications, AI agents, LLM APIs, and AI-driven workflows operating across their environments.

This becomes especially important as employees adopt AI tools outside centrally managed enterprise applications.

Organizations need visibility into:

  • Which AI services are being used
  • Which AI applications and agents are operating
  • What AI-related workflows exist
  • Where shadow AI may be appearing
  • How AI services behave over time
  • Whether AI usage aligns with organizational governance requirements

The broader objective is to treat AI usage as an environment requiring security visibility and governance rather than as an isolated productivity tool.

The Bigger Lesson: AI Privacy Is Becoming an Infrastructure Problem

The __obi investigation demonstrates how quickly the boundary between AI platforms and conventional advertising infrastructure can disappear.

A cookie may look like a small technical component, but its significance comes from the systems connected to it.

In this case, the reported mechanism connects an AI service, an identifier, third-party advertiser websites, browser behavior, advertising pixels, and OpenAI’s measurement infrastructure.

That creates a data-flow problem that cannot be evaluated by examining any single component in isolation.

For security teams, the lesson is straightforward:

AI governance must include data flows, third-party integrations, browser telemetry, identity correlation, and external communications.

As AI becomes embedded deeper into enterprise workflows, organizations will need to understand not only which AI models employees use, but also what surrounding infrastructure those AI services connect to.

What Organizations Should Examine Now

Security and privacy teams should consider reviewing:

  • Enterprise policies governing consumer AI services
  • Browser and third-party cookie controls
  • AI application inventories
  • Shadow AI usage
  • Third-party advertising and analytics pixels
  • External domains accessed by AI-related applications
  • Identity and session correlation mechanisms
  • Data transmitted to AI and advertising platforms
  • Consent management configurations
  • AI-related SaaS integrations
  • Sensitive-data exposure through browser and AI workflows

Organizations should also distinguish between advertising measurement, analytics, personalization, and security telemetry. These categories may have very different privacy implications even when they use similar technical mechanisms.

Conclusion

The reported ChatGPT __obi cookie investigation is not simply another story about web advertising.

It highlights a broader transformation in the digital ecosystem: AI platforms are becoming connected to the same identity, advertising, analytics, and measurement infrastructure that has shaped the conventional web for years.

The investigation reproduced a mechanism across 936 advertiser pixels and 1,029 hostnames, showing how an identifier created during interaction with ChatGPT could subsequently appear in requests associated with third-party advertiser websites.

For enterprises, the most important takeaway is visibility.

Security teams need to understand how AI services interact with endpoints, browsers, identities, cloud applications, and external infrastructure. Privacy teams need to understand what identifiers exist, how long they persist, where they travel, and what consent controls actually govern them.

As AI becomes a permanent layer of enterprise computing, AI security can no longer be separated from data security, identity security, application visibility, and privacy governance.

Footer-for-Blogs-3

Categories

Seceon Inc