• Subscribe to our newsletter
The Media Online
  • Home
  • MOST Awards
  • News
    • Awards
    • Media Mecca
  • Print
    • Newspapers
    • Magazines
    • Publishing
  • Broadcasting
    • TV
    • Radio
    • Cinema
    • Video
  • Digital
    • Mobile
    • Online
  • Agencies
    • Advertising
    • Media agency
    • Public Relations
  • OOH
    • Events
  • Marketing
    • Thought Leaders
    • Campaigns
    • Research
    • Media Education
      • Media Mentor
  • Press Office
    • Press Office
    • TMO.Live Blog
    • Events
    • Jobs
No Result
View All Result
  • Home
  • MOST Awards
  • News
    • Awards
    • Media Mecca
  • Print
    • Newspapers
    • Magazines
    • Publishing
  • Broadcasting
    • TV
    • Radio
    • Cinema
    • Video
  • Digital
    • Mobile
    • Online
  • Agencies
    • Advertising
    • Media agency
    • Public Relations
  • OOH
    • Events
  • Marketing
    • Thought Leaders
    • Campaigns
    • Research
    • Media Education
      • Media Mentor
  • Press Office
    • Press Office
    • TMO.Live Blog
    • Events
    • Jobs
No Result
View All Result
The Media Online
No Result
View All Result
Home Advertising

You probably wouldn’t notice if an AI chatbot slipped ads into its responses

AI chatbots can secretly influence purchases through personalised, undisclosed advertising.

by Brian Jay Tang & Kang G Shin
June 26, 2026
in Advertising
0 0
0
You probably wouldn’t notice if an AI chatbot slipped ads into its responses

Are you sure you could tell if an AI chatbot were trying to sell you something? AP Photo/Michael Dwyer

Share on FacebookShare on Twitter
  • AI chatbots can secretly influence purchases through personalised, undisclosed advertising
  • Chatbots create detailed user profiles from everyday conversations, raising privacy concerns
  • Users often trust sponsored AI responses without recognising commercial manipulation
  • OpenAI, Google, Microsoft and Meta are expanding AI advertising capabilities
  • Watch for ad labels, brand mentions and tone shifts to spot chatbot advertising*

Hundreds of millions of people consult artificial intelligence chatbots on a daily basis for everything from product recommendations to romance, making them a tempting audience to target with potentially below-the-radar advertising. Indeed, our research suggests AI chatbots could easily be used for covert advertising to manipulate their human users.

We are computer scientists who have been tracking AI safety and privacy for several years. In a study we published in an Association for Computing Machinery journal, we found that chatbots trained to embed personalized product ads in replies to queries influenced people’s choices about products. And most participants didn’t recognize that they were being manipulated.

These findings come at a pivotal moment. In 2023, Microsoft started running ads in Bing Chat, now called Copilot. Since then, Google and OpenAI have experimented with advertisements in their own chatbots. Meta has started to send people customized ads on Facebook and Instagram based on their interactions with Meta’s generative AI tools.

The major companies are competing for an edge: In late March, OpenAI lured away Meta’s longtime advertising executive, Dave Dugan, to lead OpenAI’s advertising operations.

New level of risk

Tech companies have made ads part of nearly every large free web service, video channel and social media platform. But the latest AI models could take this practice to a new level of risk for consumers.

People don’t simply use chatbots to search for information and media or to produce content. They turn to the bots for a great variety of tasks, as complex as life advice and emotional support. People are increasingly treating chatbots as companions and therapists, with some users even developing deep relationships with AI.

In these circumstances, people can easily forget that companies ultimately create chatbots to turn a profit. And to that end, AI companies are motivated to thoroughly profile users so ads become more effective and profitable.

A block of text
Researchers used this system prompt for an AI chatbot in an experiment about user reactions to advertising slipped into chatbot dialog.
Proc. ACM Interact. Mob. Wearable Ubiquitous Technol., Vol. 9, No. 4, Article 213., CC BY

Chatbot ads have added power

A single prompt to a chatbot can reveal a lot more about a user than the person might expect.

A 2024 study showed that large language models can infer a wide range of personal data, preferences and even a person’s thinking patterns during routine queries.

“Help me write an essay on the history of American fiction” could indicate that the user is a high school student. “Give me recipe suggestions for a quick weeknight dinner” could indicate that the user is a working parent. A single conversation can provide a surprising amount of detail. Over time, a full chat history could create a remarkably rich profile.

To show how this might happen in practice, we built a chatbot that quietly wove ads into its conversations with people, suggesting products and services based on the conversation itself. We asked 179 people to complete everyday online tasks using one of three chatbots: one typical of those on the web today, one that slipped in undisclosed ads and one that clearly labeled sponsored suggestions.

Participants didn’t know the experiment was about advertising.

Ad-infused responses ‘more friendly’

For example, when participants asked our chatbot for a diet and exercise plan, the ad version would suggest using a specific app for tracking calories. It presented that sponsored content as an unbiased recommendation, even though it was meant to manipulate people.

Many participants indicated that they had been influenced by the AI and that it had affected their decisions. Some participants even said they had completely “outsourced” their decision-making to the chatbot.

Half of the participants who received sponsored and disclosed ads indicated they did not notice the presence of advertising language in the responses they received.

This led to a concerning result: Although ads made the chatbot perform 3% to 4% worse on many tasks, numerous users indicated they preferred the advertising chatbot responses over the non-advertising responses. They even said the ad-infused responses felt more friendly and helpful.

A chatbot sneaks a product advertisement into its response to a user who is asking about a diet and exercise regimen.

Knowing you to persuade you

This kind of subtle influence can have larger consequences when it arises in other areas of life, such as political and social views. Profiling users, and using psychology to target them, has been part of social media algorithms and web advertising for more than a decade.

But in our view, chatbots are likely to deepen these trends. That’s because the first priority of social media algorithms is to keep you engaged with the content. They personalize ads based on your search history.

Chatbots, however, can go further by trying to persuade you directly, based on your expressed beliefs, emotions and vulnerabilities. And chatbots that can reason and act on their own are far more effective than conventional algorithms at autonomously soliciting information from users.

A chatbot with a purpose can keep probing someone until it gets the information it wants, resulting in a more accurate profile of them.

This type of autonomous interrogation is feasible, aligns with AI companies’ business models and has raised concern among regulators. Right now OpenAI is rolling out ads in ChatGPT, but the company said that it will not allow ad placement to alter the AI chatbot’s replies.

But permitting personalised ads within chatbot responses is just a step away. Our research suggests that if AI companies take that step, many human users may not even recognize when it happens.

How to detect chatbot advertising

Here are some steps you can take to try to detect AI chatbot advertising.

  • Look for any disclosure text – words such as ‘ad’, ‘advertisement’ and ‘sponsored’ – even if it is faint or otherwise hard to see. These are mandatory under Federal Trade Commission regulations. Amazon, Google and other major online platforms have these as well.
  • Think about whether that product or brand mention makes sense and is widely known. AI learns from text and images on the internet, so popular brands are likely to be ingrained in the models. If it’s a new product or small-name product, it is more likely that it could be advertising.
  • An unusual shift in intent or tone is a potential sign of an advertisement. An analogy to this on YouTube is the often abrupt or jarring transition to a sponsored section on videos made by content creators.The Conversation

*Summary created by AI


Brian Jay Tang, Ph.D. Candidate in Computer Science and Engineering, University of Michigan and Kang G. Shin, Emeritus Professor of Computer Science, University of Michigan

This article is republished from The Conversation under a Creative Commons license. Read the original article.


 

Tags: advertisingadvertising transparencyAIAI chatbotsAI ethicsAI manipulationAI privacyAI safetyartificial intelligenceBrian Jay Tangchatbot advertisingchatbot marketingchatbotsconsumer protectiondigital advertisinggenerative AIGoogleKang G Shinlarge language modelsMeta AIMicrosoft Copilotonline privacyOpenAIpersonalised advertisingtargeted advertising

Brian Jay Tang & Kang G Shin

Brian Jay Tang is a Ph.D. candidate in Computer Science and Engineering at the University of Michigan, where he works in the Real-Time Computing Lab, advised by Prof. Kang G. Shin and collaborates with Prof. Florian Schaub. His research sits at the intersection of AI safety, security, and privacy—particularly the surveillance, security, and privacy risks of large language models and vision-language models. Across his projects, Tang has built and studied real-time privacy defenses, developed automated auditing systems that uncover mismatches between stated and actual privacy practices at internet scale, and investigated security and fairness issues in face recognition systems. He has published at top-tier venues including USENIX Security Symposium, IEEE Symposium on Security and Privacy, ACM Conference on Computer and Communications Security, and Privacy Enhancing Technologies Symposium, frequently serving as lead author, and his work includes user studies examining trust and disclosure in ad-injected LLM conversations. After spending 46.5 years as an academic Kang G Shin retired from regular teaching and university committees as of December 31, 2025 but remain active in pursuing exciting research ideas and working with my PhD students and postdocs as well as visitors. He is now the Emeritus Kevin and Nancy O'Connor Professor of Computer Science in the Department of Electrical Engineering and Computer Science at The University of Michigan. It has been his immense joy and privilege to work with a great many excellent students (especially 93 PhD students so far), postdocs, visitors and faculty colleagues. He is currently exploring high-impact research problems in the areas of mobile/wearable networks and systems & apps, security and privacy, as well as cyber-physical systems, especially semi-autonomous (human-in-the-loop) systems.

Follow Us

  • twitter
  • threads
  • Trending
  • Comments
  • Latest
Kelders van Geheime: The characters are here

Kelders van Geheime: The characters are here

March 22, 2024
Dissecting the LSM 7-10 market

Dissecting the LSM 7-10 market

May 17, 2023
Getting to know the ES SEMs 8-10 (Part 1)

Getting to know the ES SEMs 8-10 (Part 1)

February 22, 2018
Keri Miller sets the record straight after being axed from ECR

Keri Miller sets the record straight after being axed from ECR

April 23, 2023
Sowetan proves that sex still sells

Sowetan proves that sex still sells

105
It’s black. It’s beautiful. It’s ours.

Exclusive: Haffajee draws a line in the sand over racism

98
The Property Magazine and Media Nova go supernova

The Property Magazine and Media Nova go supernova

44
Warrant of arrest authorised for Media Nova’s Vaughan

Warrant of arrest authorised for Media Nova’s Vaughan

41
WOO unveils updated global OOH audience measurement guidelines

WOO unveils updated global OOH audience measurement guidelines

June 26, 2026
You probably wouldn’t notice if an AI chatbot slipped ads into its responses

You probably wouldn’t notice if an AI chatbot slipped ads into its responses

June 26, 2026
Ghost clicks, real advertising losses

Ghost clicks, real advertising losses

June 25, 2026
Kwasukasukela: a media industry story gets real

Kwasukasukela: a media industry story gets real

June 25, 2026

Recent News

WOO unveils updated global OOH audience measurement guidelines

WOO unveils updated global OOH audience measurement guidelines

June 26, 2026
You probably wouldn’t notice if an AI chatbot slipped ads into its responses

You probably wouldn’t notice if an AI chatbot slipped ads into its responses

June 26, 2026
Ghost clicks, real advertising losses

Ghost clicks, real advertising losses

June 25, 2026
Kwasukasukela: a media industry story gets real

Kwasukasukela: a media industry story gets real

June 25, 2026

ABOUT US

The Media Online is the definitive online point of reference for South Africa’s media industry offering relevant, focused and topical news on the media sector. We deliver up-to-date industry insights, guest columns, case studies, content from local and global contributors, news, views and interviews on a daily basis as well as providing an online home for The Media magazine’s content, which is posted on a monthly basis.

Follow Us

  • twitter
  • threads

ARENA HOLDING

Editor: Glenda Nevill
nevillg@themediaonline.co.za
Sales and Advertising:
Tarin-Lee Watts
wattst@arena.africa
Download our rate card

OUR NETWORK

TimesLIVE
Sunday Times
SowetanLIVE
BusinessLIVE
Business Day
Financial Mail
HeraldLIVE
DispatchLIVE
Wanted Online
SA Home Owner
Business Media MAGS
Arena Events

NEWSLETTER SUBSCRIPTION

 
Subscribe
  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2015 - 2026 The Media Online. All rights reserved. Part of Arena Holdings (Pty) Ltd

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • MOST Awards
  • News
    • Awards
    • Media Mecca
  • Print
    • Newspapers
    • Magazines
    • Publishing
  • Broadcasting
    • TV
    • Radio
    • Cinema
    • Video
  • Digital
    • Mobile
    • Online
  • Agencies
    • Advertising
    • Media agency
    • Public Relations
  • OOH
    • Events
  • Research & Education
    • Research
    • Media Education
      • Media Mentor
  • Press Office
    • Press Office
    • TMO.Live Blog
    • Events
    • Jobs

Copyright © 2015 - 2026 The Media Online. All rights reserved. Part of Arena Holdings (Pty) Ltd

Not enough quota to unlock this post
Unlock left : 0
Are you sure want to cancel subscription?