Chat window on a laptop screen surrounded by tracker icons illustrating conversational AI privacy risks

Researchers at IMDEA Networks audited nine prominent conversational AI services across web and mobile, and found that several of them hand conversation-derived artifacts (chat titles, prompts, even screenshots) to third-party advertising and tracking companies, often bundled with persistent identifiers that tie the data back to a named user. Some providers publish conversation permalinks with no access controls at all, so trackers can read the full exchange. Your process engineer pasting a deviation report into a free chat tool just became a data flow you cannot see or govern.

That turns an informal productivity habit into two concrete exposures: GDPR obligations you are already signed up for, and trade secrets you assumed stayed inside the building. Here is what the study actually found, and what to do about it on Monday.

Your Team Is Pasting Process Data Into Tools That Talk to Advertisers

Walk any plant floor office and you will find the same habit. A supplier email gets pasted into a free assistant to soften the tone. A defect photo gets uploaded to ask what the surface pattern might indicate. A CAPA draft gets rewritten in thirty seconds instead of thirty minutes. Nobody filed a request, nobody signed a DPA, and the work got done faster.

The assumption behind that habit is that the exchange stays between the employee and the model provider. The IMDEA Networks team tested it with static and dynamic analysis of both web and mobile deployments, looking for third-party Advertising and Tracking Services in the actual traffic. They found them.

Conversational AI privacy is not what the interface implies. It is what the packets show.

Chat window showing a sponsored product suggestion beside a conversational AI privacy warning icon

What the IMDEA Networks Audit Actually Measured Across Nine AI Services

The paper, titled “Prompt like a Butterfly, Sting like a Tracker,” examines both the web and mobile deployments of nine prominent conversational AI services. The researchers combined static analysis (inspecting the app and site code for embedded tracking libraries) with dynamic analysis (watching live traffic to see what actually leaves the device). That pairing matters. Code inspection tells you what a tracker could collect, and traffic capture tells you what it did collect.

The target of the audit was third-party Advertising and Tracking Services, abbreviated ATSes in the paper. The team mapped which ATSes were present, what data flowed to them, and whether consent banners, subscription tier, or access-control settings changed the outcome. They then ran a responsible disclosure process with the affected providers and with competent European Data Protection Authorities before publishing.

Conversation artifacts as a new category of tracked data

Standard web tracking collects page URLs, device fingerprints, and session identifiers. This audit found something different in kind: provider-generated conversational artifacts, including chat titles, prompts, and screenshots, being disclosed to third parties. These are not metadata about a visit. They are the content of the work.

Worse, the paper reports these artifacts often travel alongside persistent user identifiers that enable user attribution. An advertising network does not just receive a fragment of text. It receives a fragment of text it can link to a specific person over time, across sessions and across services.

Why consent choices and paid tiers did not reliably close the gap

The researchers explicitly tested whether consent choices, subscription tiers, and access-control mechanisms influence conversation exposure to third parties. If declining cookies or buying a paid plan cleanly solved this, the paper would be short. It is not.

The sharpest finding sits outside consent entirely. Some providers publicly expose conversation permalinks without access controls, which means trackers can read the whole conversation. No cookie banner governs that, and no subscription setting a plant manager toggles will fix it.

The Advertising Business Model Is Arriving in the Chat Window

None of this is accidental. Reuters reported that OpenAI partnered with Criteo on an advertising pilot for ChatGPT free-tier users in the United States in early 2026. Criteo is a retargeting company. Its entire product is matching a person to an ad and proving the match worked.

Follow the mechanics. Advertising needs attribution, attribution needs a persistent identifier tied to a real user, and relevance needs signal about what that user cares about. In a chat product, the richest available signal is the conversation itself. That is why the audit found conversation-derived artifacts travelling alongside persistent identifiers rather than either one on its own. The two only have commercial value together.

So treat the findings as architecture, not as a defect list. A bug gets patched after disclosure and the risk goes away. A revenue model gets built out, optimised, and extended to more surfaces, because the incentive points in one direction only. The IMDEA Networks researchers frame it plainly:

Our results demonstrate that conversational AI services introduce a novel privacy attack surface in which provider-generated conversational artifacts become subject to tracking and public exposure.

Note the phrase “provider-generated.” Your engineer never chose to publish a chat title. The platform generated it from the prompt, then shared it. Governance policies written around what employees submit do not cover artifacts the provider creates on their behalf.

The practical consequence for a manufacturer is that free-tier access stops being a cost-saving convenience and becomes a category of exposure you have not priced. Paid and enterprise tiers exist partly because the vendor no longer needs advertising revenue from you. The study also examined how subscription tiers and consent choices change conversation exposure, which means tier selection is a control, not a procurement preference.

If your quality team is running deviation analysis, supplier correspondence, or CAPA drafting through consumer accounts, you are funding one business model while operating under the assumptions of another. Those assumptions no longer hold.

Why This Costs More in a Regulated Manufacturing Environment

Trade secrets and supplier data in prompt text

A consumer pasting a birthday message into a chat window has a privacy problem. A quality manager pasting a supplier’s tolerance data into the same window has a contract problem, a trade-secret problem, and a GDPR problem at the same time. Most supply agreements contain confidentiality clauses that say nothing about onward transfer to advertising networks, because nobody drafting them in 2019 imagined that route existed.

Customer complaint records are worse. They usually carry names, addresses, phone numbers, and sometimes health or safety details tied to a product failure. Feed that text into a free assistant and you have a transfer of personal data to a processor you never assessed, plus possible disclosure to third-party trackers riding along in the app.

Then there is the permalink problem. The IMDEA researchers found that some providers “publicly expose conversation permalinks without access controls, allowing trackers to read the entire conversation.” An engineer generates a link to share a root-cause analysis in a supplier thread and assumes unlisted means private. It is not private. Unpublished process know-how, the kind you never patented precisely because you wanted it kept quiet, is now sitting at a readable URL.

The documentation gap your next audit will find

GDPR compliance is a documentation exercise as much as a technical one. Article 30 wants a record of processing activities. Article 6 wants a lawful basis per purpose. Your DPIA has to reflect the actual data flows in your organisation, not the ones you approved.

You cannot document a lawful basis for processing you did not know was happening. That is the core of shadow AI risk, and it fails an audit faster than a misconfigured retention rule, because the auditor is not looking at a gap in your controls. They are looking at a gap in your knowledge of your own operation.

The fix starts with visibility, not policy. A ban you cannot verify produces the same audit finding as no policy at all, only with worse optics.

Ready to find AI opportunities in your business?
Book a Free AI Opportunity Audit. It is a 30-minute call where we map the highest-value automations in your operation.

Building an AI Stack Where Prompts Stay Inside the Perimeter

Start with an inventory, not a policy. Pull browser telemetry and mobile device management logs and find out which assistants your people actually open, on which devices, and under which accounts. Shadow AI is only a risk while it is invisible; once you can name the tools, you can decide which ones stay.

Then close the two widest gaps. Block consumer mobile apps for work identities, because the mobile deployments carry embedded tracking libraries that the browser versions do not always load. And disable public share links outright. The researchers found providers exposing conversation permalinks with no access controls, which means an unlisted URL is not a private one.

A five-question vendor screen before any AI tool touches production data

Procurement questionnaires written for SaaS do not catch this. Add these five to every AI vendor review, and require written answers, not marketing pages.

  • Which third-party SDKs ship in your mobile app: named, with their function.
  • What conversation-derived artifacts leave your infrastructure: titles, prompt text, screenshots, attachments.
  • Are persistent identifiers transmitted alongside them: if yes, attribution to a named employee is possible.
  • Does consent refusal or a paid tier change the data flows: the audit specifically tested whether subscription tier altered exposure.
  • Will you contract to no training, no third-party sharing, EU data residency: in the DPA, not the FAQ.

A vendor who cannot answer question one within a week is telling you something useful.

What a controlled deployment returns compared with free-tier convenience

Enterprise agreements with the major providers, or self-hosted open-weight models behind your own firewall, remove the advertising layer entirely. You keep the drafting speed, the defect-pattern analysis, the CAPA summarisation. You lose the tracker.

The cost gap is real but small against one confidentiality breach with a tier-one customer. The IMDEA team ran responsible disclosure with European Data Protection Authorities, which means regulators now have the technical evidence. Through 2026, being able to show auditors exactly where prompts go becomes a procurement advantage, not a compliance chore.

Source: jorgegarciaherrero.com

Leave a Reply