Six out of nine of the most popular AI chatbots routinely exposed user input to third parties, new European research reveals.
Multiple chatbots disclosed sensitive user data to advertising companies through trackers – a piece of code used to identify and target users on the web with customised advertisements, which are widely used across the web.
And tech companies may have been able to link conversation summaries with personal identifiers, allowing users to be targeted based on their conversations with AI.
The researchers aimed to establish the connection between existing tracking technologies and AI advertising. “We basically connected the dots, and wanted to test whether and how AI bots integrate tracking and advertising services,” said Narseo Vallina-Rodriguez, who led the study.
Vallina-Rodriguez is part of a group of researchers who investigated the use of ad trackers in the most popular AI providers with colleagues at Imdea, a public research institute in Madrid.
Their findings warn of “tensions” between tech company practices and obligations to users under privacy laws.
Sensitive user-data shared
“We already knew that tracking is pervasive, even without AI. But now you have the most super-invasive phenomena on the internet, which is AI,” said Itxaso Domínguez de Olazábal, a policy adviser at digital rights group Edri.
Users often share information about their health, psychological state, finances, and other intimate matters in AI prompts. The study shows how users who asked AI questions about such matters could have sensitive details summarised in a chat title shared with third parties.
“Now, big tech has access to much more intimate information which users tell AI. It’s crazy, the details are so intimate. My friends ask AI bots about relationships, or they use ‘doctor AI’,” said Domínguez de Olazábal.
GDPR rules require companies to make clear how users’ data is harvested, but researchers question “ambiguous expressions” used to explain the role of trackers in T&Cs.
And the ePrivacy directive requires users to consent to cookies unless they are “strictly necessary”, but researchers found that even when users rejected non-essential cookies, AI bots Perplexity, DeepSeek, Gemini, Copilot, ChatGPT and Claude still connected to Google Ads.
All of the top nine most popular chatbots were found to integrate at least one third-party advertising or tracking service.
Read more
EU data chief adds voice to unions’ fears of ‘carte blanche’ use of workers’ data for AI
Consent and transparency ‘shortcomings’
A preview of the study, released in May, prompted the Spanish privacy watchdog AEPD to request for the European Data Protection Committee (EPDC) to share preliminary findings with European counterparts “for knowledge and assessment”.
The final paper, titled ‘Prompt like a Butterfly, Sting like a Tracker’, has been accepted for publication at an academic forum in Delft next year.
Findings “highlight tensions between current practices and obligations under the GDPR and ePrivacy Directive, exposing broader shortcomings in consent, access control, and transparency mechanisms,” the paper reads.
It reveals that Grok, operated by Elon Musk’s SpaceXAI, exposed public links to conversations by default, allowing trackers to routinely access whole conversations, with TikTok also processing screenshots of Grok conversations.
Read more
Grok scandal prompts MEP move to ban non-consensual AI porn in new omnibus
Meanwhile, Mistral, France’s flagship AI firm, did not offer users a choice to reject non-essential cookies.
But offering such a choice might soon be redundant anyway. “The tracking industry is moving towards paradigms called cookie-less and identity-based tracking. So they are circumventing anti-tracking capabilities,” Vallina-Rodriguez told EUobserver.
One way, or another …
Some suggest that using browsers with anti-tracker technologies can help users avoid surveillance.
This article continues, but the full version is available only to EUobserver.com subscribers. Visit account.euobserver.com/membership
AI Brief
Your highlights
Six out of nine of the most popular AI chatbots routinely exposed user input to third parties, new European research reveals.
Multiple chatbots disclosed sensitive user data to advertising companies through trackers – a piece of code used to identify and target users on the web with customised advertisements, which are widely used across the web.
And tech companies may have been able to link conversation summaries with personal identifiers, allowing users to be targeted based on their conversations with AI.
The researchers aimed to establish the connection between existing tracking technologies and AI advertising. “We basically connected the dots, and wanted to test whether and how AI bots integrate tracking and advertising services,” said Narseo Vallina-Rodriguez, who led the study.
Vallina-Rodriguez is part of a group of researchers who investigated the use of ad trackers in the most popular AI providers with colleagues at Imdea, a public research institute in Madrid.
Their findings warn of “tensions” between tech company practices and obligations to users under privacy laws.
Sensitive user-data shared
“We already knew that tracking is pervasive, even without AI. But now you have the most super-invasive phenomena on the internet, which is AI,” said Itxaso Domínguez de Olazábal, a policy adviser at digital rights group Edri.
Users often share information about their health, psychological state, finances, and other intimate matters in AI prompts. The study shows how users who asked AI questions about such matters could have sensitive details summarised in a chat title shared with third parties.
“Now, big tech has access to much more intimate information which users tell AI. It’s crazy, the details are so intimate. My friends ask AI bots about relationships, or they use ‘doctor AI’,” said Domínguez de Olazábal.
GDPR rules require companies to make clear how users’ data is harvested, but researchers question “ambiguous expressions” used to explain the role of trackers in T&Cs.
And the ePrivacy directive requires users to consent to cookies unless they are “strictly necessary”, but researchers found that even when users rejected non-essential cookies, AI bots Perplexity, DeepSeek, Gemini, Copilot, ChatGPT and Claude still connected to Google Ads.
All of the top nine most popular chatbots were found to integrate at least one third-party advertising or tracking service.
Consent and transparency ‘shortcomings’
A preview of the study, released in May, prompted the Spanish privacy watchdog AEPD to request for the European Data Protection Committee (EPDC) to share preliminary findings with European counterparts “for knowledge and assessment”.
The final paper, titled ‘Prompt like a Butterfly, Sting like a Tracker’, has been accepted for publication at an academic forum in Delft next year.
Findings “highlight tensions between current practices and obligations under the GDPR and ePrivacy Directive, exposing broader shortcomings in consent, access control, and transparency mechanisms,” the paper reads.
It reveals that Grok, operated by Elon Musk’s SpaceXAI, exposed public links to conversations by default, allowing trackers to routinely access whole conversations, with TikTok also processing screenshots of Grok conversations.
Meanwhile, Mistral, France’s flagship AI firm, did not offer users a choice to reject non-essential cookies.
But offering such a choice might soon be redundant anyway. “The tracking industry is moving towards paradigms called cookie-less and identity-based tracking. So they are circumventing anti-tracking capabilities,” Vallina-Rodriguez told EUobserver.
One way, or another …
Some suggest that using browsers with anti-tracker technologies can help users avoid surveillance.