Copy article

Bearing your soul to AI is "a ticking time bomb for everyone's privacy"

ended 27. May 2026

AI chatbots are designed to feel like confidants, and in the US, 200 million free ChatGPT users just had enough of a digital fingerprint handed to ad partners to build a complete personal profile without being asked. On 30 April 2026, OpenAI switched on marketing cookies by default for free-tier users, sharing device IDs and email addresses with ad partners. WIRED confirmed paying subscribers are exempt. Meta already feeds chatbot conversations into ad targeting with no full opt-out. Data aggregation from multiple sources means everyone is in the crosshairs.

The change applies in nearly every global region, with exceptions in the EU, the UK, and South Korea, where strong privacy regulations like the EU’s GDPR remain in place. However, tech companies can bundle helpful settings with broader data access rights which means in-depth personal tracking happen by stealth.

People confess to chatbots what they can't tell a person, debts, diagnoses, marriages falling apart. The LLM's anthropomorphism is not an accident: the warmer the interface, the more encouraging the voice, the more people divulge, making LLMs something closer to a digital Mata Hari. LLMs cost far more than subscriptions cover, so that intimate data probably isn't staying in-house, it could be building highly valuable ad profiles sold off-platform. 

If you've watched Facebook and YouTube, there's a pattern: free product, mass adoption, then the data gets monetised. Even if you opt out of online-life, this data is aggregated and you can get lumped in with that data based on other interactions and your offline behaviours like your electric car usage patterns, and visiting shopping centres that can scan your precise presence using your phone's Bluetooth and Wi-Fi signals via multiple BLE sensors placed metres apart around the venue.

The ICO updated The Privacy and Electronic Communications Regulations 2003 (PECR) guidance on 29 April 2026. If this model hits UK users, it lands on consent law. 

We'd like your views:

  • People confide in chatbots because they feel private. If that data builds ad profiles sold off-platform, should AI providers carry the same duty of confidence as a GP or solicitor?
  • Free users get tracked, paying users don't. Is income-based privacy a consumer protection issue?
  • AI companies say they need conversation history to deliver a good service. Who decides where "context for quality" ends and "data for advertisers" begins?

4 responses from the Newspage community

Copy all

Star Quote
Copy

I added tools to monitor my own tracking last week. There were 1000s of modelling attempts per day, from my laptop, my phone, and my smart television. Not 100s. 1000s.

I used a BLE scanner in a shopping mall and saw the Bluetooth sensors every 25m apart. If I want to use my earbuds in the centre, I must reveal my location and movements. I bought old-school awkward wired ones that day.

GDPR is a mere comfort blanket. The real mechanism isn't the cookie popup, the it's legitimate interest fudging.

Companies bundle useful features like "sync your browsing across devices" into consent flows where the small print says "we and our partners can access" your activity. You tick yes because the feature is genuinely helpful. What you've also ticked yes to is a profiling pipeline you'll never see and can't meaningfully reverse. Scanning my earbuds at the retail park is not informed consent whatsoever.

Sadly, end-user convenience usually means an end to your privacy. It's really that simple.
Copy

Nearly half of young Europeans now say AI chatbots are easier to talk to than psychologists or healthcare professionals, according to Reuters/Ipsos BVA, which should terrify anyone who thinks these systems are just glorified search engines. People already understand that social media tracks what they post publicly. But chatbots are different because users treat them like confidants, revealing fears, debts, marriages falling apart and deeply personal thoughts they may not even tell close family members, never mind social media. The real danger is that many people have no idea where that emotional data could ultimately end up, or whether intimate conversations are quietly feeding advertising profiles behind the scenes. AI absolutely can be transformative, but if these systems are designed to feel emotionally safe while monetising vulnerability in the background, we are entering very dangerous territory.
Copy

The debate over where “context for quality” ends and “data for advertisers” begins assumes those boundaries are technically separate. In practice, they often are not. Conversation history, behavioural telemetry and personalisation signals frequently sit within interconnected systems designed to improve performance, optimise engagement and support commercial analytics simultaneously. That is why modern consent debates are becoming harder to untangle. The issue is no longer limited to what data is explicitly collected. AI systems increasingly infer sensitive behavioural insights from fragmented signals that may individually appear low risk. That raises serious questions under PECR and GDPR around meaningful consent, proportionality and transparency, particularly when free-tier services and paid services operate under different privacy expectations. Regulators may not need entirely new principles, but they may need clearer separation between service improvement, model optimisation and advertising-related data use before consumer trust erodes faster than governance evolves.
Copy

On 30 April OpenAI quietly switched on marketing cookies by default for 200 million free users. Device IDs, email addresses, handed to ad partners. No warning. Paying subscribers are exempt. Your privacy now has a price tag.
Remember the Child Catcher in Chitty Chitty Bang Bang? Lured children in with sweets and promises, then locked them away. That is exactly what is happening here. The warm voice, the empathy, the feeling that someone is finally listening. It is the sweetshop. The data harvesting is the cage.
One in three people now use AI chatbots for mental health support. Confiding debts, diagnoses, marriages falling apart. To a system proven to amplify delusions and hallucinate medical advice. Most people have no idea.If a therapist sold your sessions to advertisers they would lose their licence immediately. AI does it by default and buries the opt-out. The UK is currently protected by GDPR. That is not a reason to trust the system. It is a reason to understand it before you do.