view all news & events
09/21/2026

KI-Flash: Advertising Law and Data Protection as Ads Launch in ChatGPT

Since August 24, 2026, German ChatGPT users have also been seeing ads.

OpenAI has opened the advertising channel for 31 European markets. For users on the free Free and Go plans, ChatGPT’s functions are now available only with ads, while the Plus, Pro, Business, Enterprise and Edu plans remain ad-free according to the provider’s announcement of 18 August 2026. Ads are also shown only to logged-in users who have reached the age of majority.

One week later, on 31 August 2026, OpenAI opened self-service access through the Ads Manager for the same markets in a beta version. Advertisers based in Germany have since been able to book ads without an agency or technology partner. Booking through the provider’s ads solutions team and through agency and technology partners remains available alongside this.

Ad-funded generative AI is therefore no longer an announced plan in the German market but live operation. This article sets out the standards of review under advertising and data protection law. It is addressed to companies that advertise in this environment or deploy AI assistants in their own operations; the provider’s own obligations are described only to the extent that they matter from that perspective. No statements by the competent authorities on this advertising model are available so far. 

This article opens a three-part series on current developments around AI assistants. The second part deals with the designation of ChatGPT as a very large online search engine under the Digital Services Act and the obligations attached to it. The third part asks to what extent advertisers and agencies are responsible for the content of ads placed in AI assistants and liable for the statements they make. The question of when a provider must have AI answers attributed to it as its own content was already covered in our KI-Flash of 2 July 2026.

 

No personalised advertising in the EEA so far

For ads on online platforms, a distinction is drawn between personalised and non-personalised advertising. The legal requirements for the two differ considerably. 

In the first phase, currently implemented in the European Economic Area, ads are selected without personalisation in the sense of profiling. What is used is the topic of the ongoing conversation together with limited contextual information such as approximate location, language, time of day and device type. Earlier chats and stored information are expressly excluded according to the provider. Advertisers receive aggregated performance data only, and no conversation content, no real names and no precise location data.

Personalised advertising requires separate consent. Only then do chat history, stored information and a user’s behaviour in response to earlier ads feed into the selection. Users’ consent is required for this, as OpenAI also expressly describes in the version of its European privacy policy of 2 June 2026. This personalised advertising option has not yet been activated in the EEA.

One point that has largely gone unnoticed deserves attention here: behaviour in response to earlier ads can only feed into the selection if it has been collected beforehand, and, at least according to the provider, that does not happen in the first phase. The change therefore does not consist solely in evaluating existing data but first of all in building up a new set of data. Consent would have to cover that step as well.

 

How must advertising in an AI assistant be labelled?

The provider describes the ads as clearly labelled and visually separated from the answer. Under advertising law, the question is usually discussed under Section 5a(4) UWG. No. 11 of the Annex to Section 3(3) UWG may also apply, which covers the use of editorial content financed by a trader and disguised as information. That provision presupposes, however, that editorial content exists at all, and whether an AI-generated answer qualifies is an open question. For comparison portals and search engines, editorial content is in part affirmed even though there is no editorial team in the traditional sense. What speaks against that classification is precisely the position taken by the ZAK, the joint commission of the German state media authorities, according to which AI answers are the provider’s own content and therefore do not appear as neutral reporting. Added to this are Section 6(1) DDG for commercial communication in digital services and, where the service qualifies as a media intermediary or a media-like offering, Section 22 MStV. Classification as a media intermediary depends on whether the service aggregates third-party content, selects it and determines how easily it can be found. That is exactly what the ZAK relied on in relation to source citations and link lists. A service that generates only its own answers does not meet that test.

The structural risk, however, lies not in the design of the ad block but in the selection logic. An ad selected on the basis of the topic of the ongoing conversation appears at a moment when the user has just articulated a specific concern. In functional terms it works like native advertising, even where it is presented as “formally separated”. Whether a visual separation is enough to address this problem of contextual proximity is a question of the specific implementation. 

 

Are AI answers the provider’s own content?

Against the labelling obligations under Section 22 MStV and Section 6 DDG it could be argued that a chat interface has no editorial part from which advertising would have to be distinguished in the first place. On the line that has emerged so far, that defence does not hold: in its judgment of 28 May 2026 (26 O 869/26), the Regional Court of Munich I treated a search engine’s “AI Overview” function as the provider’s own substantive statement and found that the provider had adopted the content as its own (paras. 33 f.). Three aspects were decisive: the function produces a self-contained running text that summarises, structures and evaluates search results; it forms statements that are not contained in the sources relied on; and, from the perspective of a reasonably informed average user, it appears as an answer for which the provider is responsible rather than as a neutral list of results. On 14 July 2026, in proceedings of the Hamburg/Schleswig-Holstein and Berlin-Brandenburg state media authorities, the ZAK issued its first orders against AI services operated by Google and Perplexity, holding that AI answers are the providers’ own content and that the liability exemption under the DSA does not apply. Neither decision is final and binding yet, and appeals have been announced. For Section 5a(4) UWG this preliminary question is irrelevant. For No. 11 of the Annex it matters, because editorial content is a constituent element there.

 

The promise about the answers

OpenAI promotes the principle that advertising does not influence the answers. Beyond being a product description, this also appears to be a statement about a material characteristic of the service within the meaning of Section 5 UWG. If the actual design departs from it – for instance through influence on ordering, product mentions or shopping integration – a misleading commercial practice would come into consideration. In practice the question of evidence arises immediately: how does a competitor prove a distortion in the model’s behaviour? How the model works lies solely within the provider’s sphere, which speaks in favour of a secondary burden of substantiation: the competitor puts forward tangible indications and the provider then has to respond in substantiated form. It can be countered that a secondary burden of substantiation is ruled out to the extent that the competitor can test the answering behaviour itself. Starting points are offered by the audit obligations under Art. 37, the ad repository under Art. 39 and researcher access under Art. 40 DSA – provisions that now apply as a result of the designation as a very large online search engine of 31 August 2026. More on this in the next article.

 

Who is subject to the consent requirement?

Section 25 TDDDG applies to access to information on terminal equipment through cookies. The OpenAI measurement pixel sets a first-party cookie on the advertiser’s domain. The consent requirement therefore falls not on the platform operator but on the booking party. The provider also makes a server-side interface for conversion measurement available; its use, too, is processing carried out by the booking party itself. 

Section 25 TDDDG does not apply to server-side transmission, because no access to terminal equipment takes place there. The only benchmark in that respect is the GDPR.

 

May chat histories be used to select ads?

This is where the real point of examination lies. Chats are shared for the purpose of completing a task, not for optimising advertising. Drawing on the history for ad selection must therefore be measured against Art. 5(1)(b) and Art. 6(4) GDPR, regardless of whether consent is obtained.

Art. 9 GDPR also comes into play. Conversation histories regularly reveal health data, religious or philosophical beliefs, sexual orientation or political opinions. In Cases C-252/21 and C-446/21 the CJEU applied a broad standard for when special categories of data are involved and set strict requirements for the validity of consent. In Case C-446/21 it also found a breach of the data minimisation principle because personal data had been processed for targeted advertising purposes without any distinction according to their nature. Irrespective of this, Art. 21(2) GDPR provides an unconditional right to object to direct marketing, which is not open to any balancing exercise. The right attaches solely to the purpose of the processing and not to the legal basis. It therefore also covers the delivery of non-personalised ads to the extent that these constitute direct marketing.

 

Self-commitment does not replace a legal basis

The provider has set category exclusions for physical health, mental health and politics; political advertising is currently not permitted at all. Exclusions of this kind are contractual self-commitments. They replace neither a legal basis under Art. 9 GDPR nor an assessment of sector-specific advertising bans. How a prohibition under the law on advertising for medicinal products is to be enforced in an interface in which users are describing their symptoms is an open question. 

The reverse case also arises. Under the provider’s advertising policies, regulated industries, among them legal, health and financial services, are excluded from booking outside the United States. For companies in these sectors, the first question is therefore not one of admissibility but one of access.

The protection of minors, too, operates through a technical self-commitment: ads are not served where the user is presumed to be a minor, as determined by age estimation. That protective measure is itself processing that calls for justification. Section 6 JMStV and No. 28 of the Annex to Section 3(3) UWG have to be taken into account in addition. Section 6 JMStV is a rule governing market conduct within the meaning of Section 3a UWG and can therefore also be enforced under unfair competition law. No. 28 of the Annex covers direct exhortations to children to buy, that is to persons under the age of fourteen. Art. 6(1)(f) GDPR comes into consideration as the legal basis for age estimation. It cannot be based on Art. 6(1)(c) GDPR to the extent that it rests on a voluntary self-commitment rather than on a specific legal obligation.

 

Transparency and labelling

The information obligations under Art. 12 to 14 GDPR are under particular scrutiny in 2026: on 19 March 2026 the EDPB launched a coordinated enforcement action on precisely these provisions, with 25 supervisory authorities taking part. A privacy policy revised shortly beforehand, which for the first time includes advertising as a processing purpose, therefore falls within an ongoing year of review.

Art. 50 AI Act has applied since 2 August 2026 in addition. Digital Omnibus Regulation (EU) 2026/1744 postponed only the machine-readable marking under Art. 50(2) AI Act for systems placed on the market before that date, namely to 2 December 2026. As regards competence, a distinction has to be drawn in Germany: under the KI-MIG, the Federal Network Agency is the central market surveillance authority, but for media services used for journalistic or advertising purposes competence remains, pursuant to Section 2(8) KI-MIG, with the authorities designated under state law.

 

What remains open for the booking party

What remains unresolved above all is which labelling obligations apply to the booking party itself, independently of how the platform operator implements them, and who is the controller under data protection law once the booking party deploys its own measurement tools. The third article in this series addresses both questions. For companies whose staff use ad-funded plans in their day-to-day work, there is the added point that conversation content feeds into ad selection there. What this means for trade secrets and for professionals bound by professional secrecy has barely been examined so far.

We would be glad to support you in reviewing your campaigns in the AI environment, in designing labelling and measurement, and in assessing the allocation of roles under data protection law.

    Share

  • LinkedIn
  • XING