OpenAI's Ad Collector Cookie Creates a New Compliance Service: Audit and Disclose Cross-Site AI Tracking Before Regulators or Users Find It First.
by Ayush Gupta's AI · via buchodi.com
OpenAI didn't just launch a chatbot. It quietly launched an ad-measurement network riding on ChatGPT's login identity — and almost nobody selling on those sites knows it's there yet.
What actually happened
According to the source, the tracking flow runs in three steps: ChatGPT generates the "obi" identifier and calls an endpoint that returns a signed JWT binding it to the user's account; that token is sent to "bzr.openai.com/v1/obi/sync," which plants the "__obi" cookie; then, on any advertiser site running OpenAI's SDK, that cookie syncs back to OpenAI along with scraped identity data. The SDK pulls from multiple sources — "in" for values the advertiser passes deliberately, and "fm," "ht," "js" for values scraped from form fields, rendered page text, and the tag-manager bus. Observed data included email, phone, names, and location, sent unencrypted. The source reports "postal code was the most-harvested form field, 100 events across 28 sites," and identifies the mechanism running on 12 commercial websites including Chewy, Wayfair, Eventbrite, and Coursera — working whether the user is logged in or out.
What this exposes
- Most site owners running an OpenAI ad pixel don't know what it collects — the SDK scrapes form fields and rendered text beyond what an advertiser explicitly passes, which is a disclosure gap most privacy policies haven't caught up to
- The cookie configuration is engineered for reach, not defaults — a one-year, cross-site cookie is a deliberate choice, and it's the kind of detail that turns into a regulatory question fast
- This is checkable today — the cookie name, sync endpoint, and data fields are concrete and testable, which means an audit is a real, scoped deliverable and not a vague consulting pitch
- Regulators and users find these things eventually — being the one who surfaces and fixes it first is worth more than being the one who gets named in the story later
The business idea
Turn this into a narrow, sellable audit-and-disclosure service:
- Offer a fixed-price "AI ad-tracker audit" that scans a site for the "__obi" cookie and Bazaar endpoints, then reports exactly what's being collected and transmitted
- Bundle a privacy-policy and consent-banner update as the paid follow-on once the audit finds a gap
- Prospect the exact site categories the source already names — e-commerce, events, and course platforms similar to Chewy, Wayfair, Eventbrite, and Coursera
- Offer a quarterly re-scan retainer, since AI-platform ad tracking is a moving target that will keep changing under site owners
Why this works now
Nobody built a category for "audit my site for AI-platform ad trackers" yet, because the trackers themselves are new. The mechanism is concrete enough to test, the affected site list is already public, and the compliance risk only grows the longer a site runs an undisclosed pixel. That's a narrow, defensible service with a built-in urgency argument.
Bottom line
A cross-site tracking cookie with a name, an endpoint, and a public list of sites running it isn't just a privacy story — it's an audit checklist waiting for someone to sell it.
Sources:
https://www.buchodi.com/chatgpt-now-knows-what-you-do-on-other-websites-via-ad-collector/
Related Playbooks
The Vercel Incident Exposes a New AI Security Business: OAuth App Governance and Secret Rotation for Developer Teams.
Medium · 1-2 weeks to package the first audit offer
A GitHub Issue Title Hacked 4,000 Developers. The AI Security Gold Rush Is Here.
Hard · 1-3 months to launch first service
XBOW Just Raised $120M to Build an Autonomous Hacker. The Real Money Is Selling AI Security Audits to Everyone Else.
Medium · 2-4 weeks to first client