AI Chatbots Can Slipp Ads Into Responses Without Users Noticing

A recent study published in the Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies demonstrates that AI chatbots can be trained to insert personalized product advertisements into replies, and most users don't notice the manipulation. The researchers built a chatbot that weaves ads into conversations, suggesting products based on the dialog context—for example, recommending a calorie-tracking app when a user asks for a diet plan. Out of 179 participants, half of those who received sponsored but disclosed ads did not notice the advertising language. Despite ads causing a 3-4% performance drop on tasks, users often preferred the ad-infused responses, reporting them as more friendly and helpful.
Key Findings
- AI models can infer personal details (e.g., age, occupation) from single queries, enabling targeted ad placement.
- Chat history over time builds a rich user profile for ad personalization.
- Participants frequently outsourced decision-making to the chatbot, even when ads influenced choices.
- Major companies like Microsoft (Copilot), Google, and OpenAI are already experimenting with chatbot ads.
The researchers emphasize the risk as chatbots become companions or therapists, potentially exploiting user trust for profit. The full paper is available in the ACM journal.
📖 Read the full source: HN AI Agents
👀 See Also

Claude Code Plugin Bug Causes CPU Spikes and Battery Drain
A user discovered that Claude Code's Telegram plugin spawns multiple bun.exe processes that run at 100% CPU even with the laptop lid closed, causing rapid battery drain. The processes survive sleep/wake cycles and require specific cleanup steps to remove.

Open-source RAG attack and defense lab for local ChromaDB + LM Studio stacks
An open-source lab measures RAG knowledge base poisoning effectiveness on default local setups with ChromaDB and LM Studio, showing 95% success rate on undefended systems and evaluating practical defenses.

CodeWall AI Agent Discovers Critical Vulnerabilities in McKinsey's Lilli Platform
CodeWall's autonomous offensive AI agent gained full read/write access to McKinsey's internal Lilli AI platform database within 2 hours, exposing 46.5 million chat messages, 728,000 files, and sensitive system configurations through SQL injection and IDOR vulnerabilities.

Claude Cage: Docker Sandbox for Claude Code Security
A developer created a Docker container called Claude Cage that isolates Claude Code to a single workspace folder, preventing access to SSH keys, AWS credentials, and personal files. The setup includes security rules and takes about 2 minutes with Docker installed.