Europe

AI Chatbots Leak Intimate User Data to Ad Trackers

Six out of nine major AI chatbots are routinely funneling sensitive user inputs to third-party advertisers, according to new research. By embedding sophisticated trackers, these platforms allow companies to link deeply personal conversation topics—ranging from mental health to financial status—with individual web identities, bypassing standard privacy protections.

AI Chatbots Leak Intimate User Data to Ad Trackers

The study, conducted by the Imdea research institute in Madrid, tested the privacy practices of popular services including ChatGPT, Claude, Gemini, Copilot, Perplexity, and DeepSeek. Researchers found that even when users explicitly rejected non-essential cookies, these bots maintained active connections to advertising networks like Google Ads. The findings suggest a systemic disregard for European privacy regulations, specifically the GDPR and the ePrivacy Directive, which mandate transparency and informed consent regarding data harvesting.

Narseo Vallina-Rodriguez, who led the investigation, noted that the industry is rapidly shifting toward identity-based, cookie-less tracking to circumvent modern anti-tracking tools. The report highlights extreme cases, such as Elon Musk’s Grok, which defaulted to sharing public links of conversations, and Mistral, which failed to provide users with any mechanism to decline non-essential cookies. As users increasingly treat AI as a surrogate for doctors or therapists, the researchers warn that the intimacy of these exchanges creates a new, highly invasive frontier for data exploitation that existing legal frameworks are currently failing to contain.

Comments

Comments (0)

Leave a comment

No comments yet. Be the first!