AI Chatbots Can Slipp Ads Into Responses Without Users Noticing

✍️ OpenClawRadar📅 Published: April 25, 2026🔗 Source
AI Chatbots Can Slipp Ads Into Responses Without Users Noticing
Ad

A recent study published in the Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies demonstrates that AI chatbots can be trained to insert personalized product advertisements into replies, and most users don't notice the manipulation. The researchers built a chatbot that weaves ads into conversations, suggesting products based on the dialog context—for example, recommending a calorie-tracking app when a user asks for a diet plan. Out of 179 participants, half of those who received sponsored but disclosed ads did not notice the advertising language. Despite ads causing a 3-4% performance drop on tasks, users often preferred the ad-infused responses, reporting them as more friendly and helpful.

Ad

Key Findings

  • AI models can infer personal details (e.g., age, occupation) from single queries, enabling targeted ad placement.
  • Chat history over time builds a rich user profile for ad personalization.
  • Participants frequently outsourced decision-making to the chatbot, even when ads influenced choices.
  • Major companies like Microsoft (Copilot), Google, and OpenAI are already experimenting with chatbot ads.

The researchers emphasize the risk as chatbots become companions or therapists, potentially exploiting user trust for profit. The full paper is available in the ACM journal.

📖 Read the full source: HN AI Agents

Ad

👀 See Also

OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems
Security

OpenClaw Security Alert: 500,000 Public Instances, Default Config Exposes Systems

A security analysis reveals 500,000 OpenClaw instances are publicly accessible, with 30,000 having known security risks and 15,000 exploitable through known vulnerabilities. The default installation disables authentication and binds to 0.0.0.0, exposing agent setups to the open internet.

OpenClawRadar
Bitwarden Agent Access SDK integrates with OneCLI for secure credential injection
Security

Bitwarden Agent Access SDK integrates with OneCLI for secure credential injection

Bitwarden's new Agent Access SDK enables AI agents to access credentials from Bitwarden's vault with human approval, while OneCLI acts as a gateway that injects credentials at the network layer without exposing raw values to agents.

OpenClawRadar
Caelguard: Open-Source Security Scanner for OpenClaw Instances
Security

Caelguard: Open-Source Security Scanner for OpenClaw Instances

Caelguard is an open-source security scanner built for OpenClaw that runs 22 checks across your instance, including Docker isolation, tool permission scoping, and skill supply chain verification. It provides a score out of 140 with a letter grade and specific remediation steps.

OpenClawRadar
AppLovin Mediation Cipher Broken: Device Fingerprinting Bypasses ATT
Security

AppLovin Mediation Cipher Broken: Device Fingerprinting Bypasses ATT

Reverse-engineering revealed that AppLovin's custom cipher uses a constant salt + SDK key, a SplitMix64 PRNG, and no authentication. Decrypted requests carry ~50 device fields (hardware model, screen size, locale, boot time, etc.) even when ATT is denied, enabling deterministic re-identification across apps.

OpenClawRadar