ChatGPT Ads Just Changed: Sponsored Agents, AI-Written Copy, and Why the Timing Is Concerning

ChatGPT Ads got a real upgrade this week. Sponsored Agents launched, ad copy now rewrites itself to match your conversation, and the program expanded to seven new countries. All of this landed within days of a report showing that hundreds of human contractors are reading full ChatGPT conversations, and most users have no idea it happens. Put those two stories side by side and the timing is not comfortable.


What Actually Changed in ChatGPT Ads This Week

On September 16, 2026, OpenAI published a product update that pushes ChatGPT Ads well past its original “banner under the answer” format. Four things shipped at once.

Sponsored Agents. Click an ad in ChatGPT and you can now start a live conversation with a business-run AI agent inside the app itself. You ask it questions, it answers, and it points you toward the company’s website when you are ready. OpenAI is testing this with select US advertisers right now, and it is a genuinely new interaction pattern. You are no longer just seeing an ad. You are talking to one.

AI-powered text customization. Advertisers can opt in to let ChatGPT rewrite their headlines and ad copy on the fly so the pitch fits the specific conversation you are having, and automatically translate that copy into whatever language you are using. In plain terms, the ad itself is no longer static. It reads the room, or more precisely, it reads your chat.

Ads Manager gets an AI assistant. Advertisers can now create and adjust entire campaigns using plain language prompts, and get AI-suggested creative based on their landing page.

Two new integrations. HubSpot and Shopify are now plugged directly into ChatGPT Ads, so businesses running CRM or ecommerce operations on those platforms can launch and track campaigns without leaving their existing tools.

Then, on September 23, OpenAI expanded the ads program to Indonesia, Malaysia, the Philippines, Singapore, Thailand, Vietnam, and Taiwan, bringing total coverage to more than 60 countries in under eight months since the first US pilot.

Taken on its own, this is a normal product roadmap. More markets, more automation, more ways for the ad system to feel native to the product. What makes it worth a second look is what else came out of OpenAI’s newsroom the same week.


The Report That Should Change How You Read All of This

On September 14, 404 Media reported on something internally called Project Lily. OpenAI pays hundreds of contractors, reportedly around $50 an hour, to read real ChatGPT conversations and rate the quality of the responses. Not snippets. Not isolated messages. According to the report, contractors often review whole conversations, and those conversations can include sensitive personal details that OpenAI says it tries, but does not always manage, to strip out before a human sees them.

Here is the thing that stings the most. A person familiar with the review process told 404 Media plainly that most users would never imagine a contractor somewhere is reading through what they typed. That is not a hypothetical concern about future risk. That is a description of what is already happening, right now, to accounts that never opted into anything resembling “let a stranger read my chat.”

OpenAI’s response, as covered by Yahoo Tech, was to point to a help center page that explains human feedback improves model quality. That page, according to 404 Media, was updated only after the outlet reached out for comment, which is its own small tell about how visible this information was beforehand.

There is also a legal wrinkle worth knowing. TNW reported that Europe’s top court settled a related question last year. In EDPS v SRB, the Court of Justice held that a company’s duty to tell people their data might be reviewed applies the moment the data is collected, not whenever someone gets around to checking whether a contractor could theoretically identify them. OpenAI would not say where it discloses the human review practice to users, which is precisely the gap that ruling was meant to close.

To be fair to OpenAI, it is not alone here. Google’s Gemini has a privacy page that says a subset of chats gets reviewed by humans. Anthropic confirmed to 404 Media that it also uses human review, though its own support documentation describes stripping account identifiers before review and applying it only when a user has opted in. That distinction, opt-in versus on-by-default, is exactly the point of friction with ChatGPT’s approach.


Why the Combination Is the Real Story

OpenAI has repeated a specific promise since ads launched in February: “we keep your conversations with ChatGPT private from advertisers,” and ads do not shape the model’s answers. Taken narrowly, that claim is probably true. Advertisers reportedly get aggregate performance numbers, not transcripts.

But that promise was never really about advertisers alone. It was about earning enough trust that you would feel comfortable seeing sponsored content sit right next to an AI assistant you talk to like a colleague, a tutor, or sometimes a confidant. Project Lily shows that “private from advertisers” and “private, full stop” are two very different sentences, and most users heard the second one.

Now layer this week’s product changes on top. Sponsored Agents mean an entirely new type of conversation, one you start because an ad prompted you to, now lives inside ChatGPT alongside everything else you type there. AI text customization means the system is actively parsing your conversation’s context well enough to rewrite a business’s pitch around it. None of that requires human eyes to work technically. But it does mean more of your intent, your language, and your context is being read, scored, and acted on by systems that a contractor workforce is also, separately, reading to improve.

What this really means is that the line between “the model understanding you to help you” and “the model understanding you to sell to you” keeps getting thinner, at the exact moment public trust in who reads the raw material took a real hit.


Step-by-Step: How to Limit What OpenAI Reviews and Personalizes

You cannot fully opt out of every form of review tied to safety and abuse monitoring, and OpenAI still reserves the right to review flagged conversations for policy violations. But you can meaningfully cut down what gets used for model training and ad personalization. Here is how, based on OpenAI’s own data usage documentation.

  1. Open ChatGPT settings. On web or mobile, tap your profile icon and go to Settings.
  2. Go to Data Controls. Find the section covering how your data is used, sometimes labeled “Data Controls” or “Improve the model for everyone.”
  3. Turn off “Improve the model for everyone.” This stops new conversations from being routed into training and review pipelines going forward. It does not retroactively pull back chats already reviewed.
  4. Visit the OpenAI Privacy Portal separately. Go to privacy.openai.com and select “Do not train on my content.” OpenAI says you do not need to do this in both places, but doing both removes any ambiguity about which setting actually took effect.
  5. Be careful with in-chat feedback. If you give a thumbs up, thumbs down, or written feedback on a response after opting out, OpenAI says the entire conversation tied to that feedback can still be used for training. If privacy is the goal, skip the feedback buttons on sensitive chats.
  6. Check your account tier. If you are on ChatGPT Business, Enterprise, Edu, or using the API, “Improve the model for everyone” is off by default. Free, Go, and Plus users are opted in unless they change it.
  7. Review your ad personalization settings. In the same Data Controls area, look for ad personalization options. You can turn off personalization based on your conversation history, which limits how much of your chat content ever factors into what ads or Sponsored Agents you see.
  8. Reassess what you type into free or Go tier accounts. If you regularly discuss health, legal, financial, or otherwise sensitive matters, this is a genuine reason to consider a paid tier where training and review are off by default, or to keep that category of conversation out of ChatGPT entirely.

Honest Limitations

A few things are worth being upfront about. First, opting out of training does not mean nobody ever reviews your account. OpenAI still reviews conversations flagged for safety, abuse, or policy violations regardless of your data settings, and it should, since that is how platforms catch genuinely dangerous behavior. Second, there is no independent, verifiable way for an outside user to confirm that a given opt-out setting fully removes their data from every review queue. You are trusting OpenAI’s documentation because there is currently no audit mechanism that lets you check. Third, this is not a ChatGPT-only problem. Gemini and Claude both use human review in some form, and the honest takeaway is not “avoid OpenAI,” it is “assume some human review happens somewhere unless a vendor explicitly proves otherwise, and adjust what you type accordingly.”


The Bottom Line

None of this week’s ad features are inherently bad. Sponsored Agents could genuinely help someone compare a mattress or a laptop without leaving the chat window. AI-adapted ad copy could mean fewer irrelevant pitches. Expansion to more countries just means more people get free access supported by ads instead of paywalls. Judged purely as product updates, this is competent execution.

But you cannot evaluate an advertising system in isolation from the trust assumptions it depends on. ChatGPT Ads work because OpenAI has told you, repeatedly, that your conversations stay private. The same week the company deepened how much it reads your conversation to build a better ad, independent reporting showed that “private” has a much narrower definition than most users assumed. That gap between the promise and the practice is the actual story here, and it is worth five minutes of your time to check your own settings today.


Know someone who spends half their day inside ChatGPT and has never once opened the privacy settings? Send them this one before you send them anything else today.


Sources

  1. OpenAI: Reimagining advertising with AI (September 16, 2026)
  2. OpenAI: ChatGPT Ads expands to Southeast Asia and Taiwan (September 23, 2026)
  3. OpenAI: Testing ads in ChatGPT
  4. 404 Media: Inside “Project Lily,” The Humans Reading Your ChatGPT Chats (Joseph Cox, September 14, 2026)
  5. Yahoo Tech: Humans may be reading your ChatGPT conversations. Here’s how to opt out (Kim Lyons, September 15, 2026)
  6. The Next Web: Hundreds of contractors are reportedly reading real ChatGPT conversations
  7. OpenAI Help Center: How your data is used to improve model performance
  8. Anthropic: Who can view my Claude conversations

Leave a comment

Website Built by WordPress.com.

Up ↑