Brand Safety in the Conversation, Part 1: The Surface Is Different
By Dave Byrne and AJ Brown • October 6, 2026
In early September, Adweek reported that four ad buyers had brought the same three requests to OpenAI: they wanted to see the prompts that triggered their ads being shown; they wanted a better sense of the conversation environment surrounding those ads; and they wanted evidence that the people who saw those ads went on to buy something. All three are reasonable and consistent with what buyers have requested of every new environment since the display banner ad. That anyone is asking at all tells you that genAI environments like ChatGPT have stopped being treated as an experiment, and are now a proper media channel where real money gets allocated.
The problem is that this environment cannot answer any of these questions in the form they were asked. There is no page to inspect, no publisher to name, and no content to evaluate that existed prior to the ad running, because the AI-generated answer next to the ad was written moments earlier, tailor-made for an audience of one, and in most cases it will never be reproduced in that same form again. The only parties in a position to see what surrounded the ad are the platform that sold it and the person asking questions in what they expect is a private, one-on-one chat environment.
There is too much to unpack here for one article: the variables are new, and many of the old rules for digital ads don't work in generative AI, so we will be publishing five pieces on this (and with the pace at which AI is advancing, who knows if the five we have planned will be enough):
- This one covers why the surface is different from anything advertisers have bought before.
- Part 2 asks what adjacency means when the content beside your ad was dynamically generated seconds earlier.
- Part 3 lays out the additional factors that have to sit alongside the existing content taxonomies, which still apply but no longer cover enough on their own.
- Part 4 covers what a published policy would have to commit to, and what it would take to enforce it.
- Part 5 covers the controls, reporting and verification that would make any of it checkable.
We are writing about ad-supported genAI environments generally, and we use OpenAI as the example throughout only because it is the clear leader in terms of AI platforms selling ads inside an assistant at any real scale, which makes it the only place the problem is concrete rather than theoretical. Everything we discuss in this series will apply to whoever is next.
Intent and Lessons from Search
During AJ's time at Twitter, more than nine in ten of the brand safety incidents his team dealt with related to ad misplacement stemmed from ads in search results rather than the timeline. Obligatory disclaimer: that figure was based on the incidents AJ’s team was aware of - not an official company statistic, and X has since completely overhauled how they decide which search placements to serve ads in - but the pattern behind it is what matters. People searching for news about #ParklandShooting, a celebrity’s death, or the latest natural disaster were furious when they saw ads slotted among the search results for those topics (as were the advertisers who saw their ads there). People scrolling a timeline full of accounts they had chosen to follow tended to take less issue with ads being next to that content, even if that content was similar to what they might encounter in search.
People generally expect to see ads as they passively scroll their timeline, but someone actively searching for something has told the platform precisely what that moment is about, and they’re much more scrutinizing of what’s returned back to them. An ad that misreads the moment gets read as a response to what the person just searched. Whether or not [redacted household name brand advertiser] intended to have their ad serve on #ParklandShooting, people are much more likely to conclude that the placement was intentional because it happened in search.
Chat takes this dynamic considerably further than search, because a single search query is a fragment and a conversation with an AI chatbot is a narrative, carrying whatever the system remembers about you and an emotional register the assistant is actively responding to. People who see an ad in chat may be more likely to assume it was picked because of everything the assistant knows about them.
Buyers are right that catching people close to a decision gives these environments tremendous commercial appeal, and the early numbers support them: one agency quoted in the Adweek article reported its client's cost per thousand impressions down 33 percent and cost per click down 26 percent when using ChatGPT Ads. OpenAI leaned in hard on mid-funnel positioning at Cannes this year, using the incredibly high intent signals that genAI chatbots receive from users as a selling point, and rightly so. But the upside and the risk are the same property of the surface, seen from two directions.
Who Gets to Check
Every framework the industry currently relies on looks at something that already exists, whether that is a page, a post, a video, an image or an episode. The common assumption is that you can crawl it, score it, list it and use pre-bid controls to avoid it before an ad ever runs.
It is worth being fair about what an AI assistant can do here, because it is more than any crawler can manage. The model has written the answer before the ad is attached to it, it has the whole session in front of it, and it has whatever it retains about the person it is talking to as background. On paper, that is richer context than the open web has ever offered an advertiser, and a platform would be right to point that out as a selling point.
The trouble is that nobody outside the platform can see any of that context, and there is no shared taxonomy to measure it against, so whatever the system concludes about a conversation’s relevance for a particular advertisement cannot be compared with what another platform concludes, or what the same platform concludes for a different user. Many of the problems that turn up in conversations do not have names in the existing categories, which were written for content a publisher produced deliberately.
Because every conversation is unique, you cannot sample a slice of inventory and generalize from it the way you can with a site or a channel. And a judgment made before delivery can be overtaken by whatever gets said in the next ten turns, with the ad still sitting exactly where it was placed. The result is an environment with more context available and less of it checkable than anything the industry has bought before.
A Walled Garden Without the Fittings
In genAI environments, a single company writes the answer, picks the ad, measures what happened, and produces the delivery report, which is a structure the industry already knows well. Google, Meta, Amazon, TikTok and others have done this for years, and our industry has spent a long time discussing it.
What those environments have that chat doesn't is everything the industry built on top of them: adjacency definitions, category taxonomies, buyer-side controls, agreed standards and some form of independent verification, all of which exist because advertisers organized and spent the better part of a decade demanding them. None of it arrived voluntarily and none of it arrived quickly. Chat has the walled garden structure and little of the surrounding industry apparatus, and the history of every other environment suggests that the gap does not close on its own.
The verification firms are working on it with the likes of DoubleVerify's AI work covering AI crawlers and scrapers, automated browsing by AI agents, and AI slop across the open web and social. As we were finalizing this piece, OpenAI announced brand suitability pilots with DoubleVerify and IAS, in which both firms will assess how OpenAI applies its brand safety standards in a controlled testing environment, without access to private user conversations. It's a meaningful first step toward independent verification, but testing safeguards against chosen scenarios is different from verifying where live ads actually landed, a distinction we'll dig into in Part 5.
All of this is moving in the right direction. But as we saw several years ago with made-for-advertising inventory and a lack of a shared, operationalizable definition of the problem, we’ll end up with a patchwork of platforms and vendors working from conflicting definitions developed in silos if each individual player is left to identify and address these issues alone.
Live and Search at the Same Time
Search gives you intent, and as the Twitter pattern shows, intent often leads to objection. The industry's answer was negative keyword lists and blocked query categories, and on the worst days, switching off entire classes of query. Live gives you content nobody can review in advance, where risk arrives in real time and no amount of pre-flight checking helps, so the answer there was a delay buffer, somebody watching, an escalation path, a kill switch and a make-good when a break landed badly.
A chatbot conversation is both of those at once. The person arrives with something specific they want, and the material around the ad is the dynamically generated response in that moment. That combination breaks the existing answers we have for search and live separately, because each one quietly assumes the other condition is absent. Keyword lists work on search because the query is short and the page behind it already exists to be checked. Delay and monitoring work on live because one broadcast is watched by a great many people, so a single person in a control room protects everybody at once.
In chat, every conversation is its own live stream with an audience of one, which means a million conversations are a million live feeds to monitor. No monitoring approach designed for broadcast survives that arithmetic, and the only thing capable of watching at that scale is another model, owned by the platform, which leaves you back where you started with one party as the sole witness. Two further qualities sit on top of all this. Like messaging, the surface invites people to tell it things about themselves, and like a recommendation engine, it shapes decisions that carry consequences. Neither makes the combination any easier. The live comparison is worth holding onto, though, because it is the one environment that was ever “solved” for content it could not see in advance, and we come back to live controls in Part 5.
The Trust Paradox
As the Adweek piece lays out, advertisers want greater transparency into the environment surrounding their ads. The longstanding paradigm is that greater transparency makes for happier advertisers. But in this case, the environment is a one-on-one conversation, and most people expect a heightened level of privacy when engaging in one-on-one conversations. The more parties are made privy to what’s discussed in that one-on-one conversation, the less likely a user will be to share more information about themselves, their intentions, and their needs in the future.
The reason why chatbot environments have unprecedented levels of visibility into user intent is because users disclose unprecedented amounts of information to these platforms. Users are only going to share that level of information if they feel they can trust the platform to safeguard the contents of their conversations, and for purposes of this series, that means withholding the contents of those conversations from advertisers. Essentially, the more opaque the platform is to advertisers, the more users are likely to trust it. This is the tension that runs through the rest of the series, without a resolution. Users trust an assistant more when it shares less about their conversations with advertisers, while advertisers say they need more transparency and independent measurement before investing, and the platform is stuck in the middle.
Showing buyers the prompts is the clearest case. It is a fair ask, and it is the chat equivalent of the search term reports buyers have relied on for twenty years, but it is also a request to see what somebody typed into a query box they believed was private. Every bit of context handed to advertisers comes off the user's side of the ledger.
Platforms are aware that their value proposition hinges on users continuing to provide them with unprecedented amounts of information, and thus have erred on the side of opacity to date. OpenAI says advertisers get aggregate performance data and no access to chats, chat history, memories or personal details, its policies already keep ads away from mental and personal health, emotional reliance and what it calls sensitive user journeys, and it says it does not show ads to accounts it identifies as belonging to minors. That is a better opening position than many social platforms held years into selling advertising.
Our concern is verification. The DoubleVerify and IAS pilots are a start, but the emphasis all three companies placed on running them without access to private user conversations illustrates this paradox. The real test comes after the pilots: whether, and in what form, outside parties will be able to evaluate live conversations without eroding the privacy that makes users willing to share in the first place.
The lack of transparency and measurement does not appear to be deterring marketers. OpenAI’s ads business was running at about a billion dollars a year by late summer, up from a hundred million pace in March, against a stated target of two and a half billion for the year. Buyers are spending without being able to see where their ads land, which suggests market pressure alone is not going to force anything.
When the Ad Works Against the User
Most ad misplacements are simply in poor taste. They can negatively impact the viewer’s perception of the brand, but they don't necessarily leave the person meaningfully worse off as a result. Our concern is placements where the user's situation gets worse precisely because the ad “worked.” For example: someone in a financial emergency is shown a payday lender and takes out the loan; someone who has a gambling problem is served a sportsbook promo and signs up; someone with an eating disorder sees an ad for an appetite suppressant and buys it.
This can happen in any digital environment. During Dave's time at Spotify, alcohol ads ran on podcasts about addiction recovery. During AJ’s time at Twitter, users with self-described gambling addictions posted about having been served gambling ads, leading to a partnership with the UK Gambling Commission to address the problem. But chat raises the stakes in two specific ways:
- The Platform Knows More: In a feed, during a podcast, or before a video, ads are targeted primarily using signals the platform has inferred, so a gambling ad reaching someone with a gambling problem is a targeting error the platform had limited ways to foresee. In chat, people share significantly more information about their state and intent than they do by typing keywords in a search bar or through their social media likes or follows. The ChatGPT user may have stated the problem outright in the same conversation where the ad appears. The upside to that is there's a lot more context available for the platform to assess to determine whether an ad is appropriate in that moment or not, but it looks worse when something goes wrong. In these situations, the "we couldn't have known" defense is a tougher case to argue.
- Ads Interpreted as Advice: In a feed, before a video, or on a web page, people generally understand an ad as being separate from the content around it. In chat, the ad renders in the same moment as a personalized answer is generated by the chatbot. Even if the ad and the chatbot response are visibly separate, they appear together and both are triggered by what the user asked. In this setup, the ad can read as part of the answer. A lender's ad next to the assistant's advice on debt can look like one of chat’s recommended options.
This doesn’t mean that every ad in a sensitive conversation is harmful, and there are certainly cases where this dynamic could be beneficial. A therapy service like BetterHelp could be genuinely useful to someone working through stress. But for someone in acute crisis, who needs a crisis line, a paid subscription offer may still be the wrong intervention. Again, these risks exist elsewhere too, but we argue that the chatbot environment raises the stakes of ad misplacement for the reasons above.
Problems That Go Unseen
On public platforms, ad misplacements and content monetization issues often fix themselves in a sense — many people (users, watchdogs, the press) can see ads next to an unsuitable piece of content, on an unsuitable user profile, or elsewhere, take a screenshot, and flag it to the platform. That public visibility is how many brand safety problems are detected.
Chat removes that because each placement is seen by one person in a private conversation, and the combination of conversation and ad usually can't be reproduced (ChatGPT strips ads from conversation exports). So each incident reaches fewer people than a bad placement in a feed would, and almost nobody is in a position to notice it. No verification vendor can observe it, and the brand may never learn its ad appeared beside someone in distress. A problem that might surface within hours on an open platform can persist unnoticed in chat.
Lower reach per incident also doesn't mean fewer incidents. If an ad system consistently misreads a certain kind of conversation, it repeats that mistake across thousands of private sessions. On a public surface, those repeated incidents would pile up into a visible pattern. In chat, each one has an audience of one, so the pattern is less likely to become visible.
This is why brand safety in chat can't rely on the public complaints that have traditionally triggered fixes. It needs privacy-preserving monitoring, testing and controls built for a surface where brands can't see individual conversations, which we return to in Part 5. The challenge is catching low-volume, high-severity failures without turning private conversations into public inventory.
What This Means for Marketers
- The asks laid out in the Adweek story are reasonable but vague, and are based on what you’ve come to expect from other digital surfaces. Knowing what you want visibility into does not yet tell you what form it could take here.
- Expect the controls you already know to arrive by name before they arrive in substance. Ask what the control actually inspects, whether it looks at one turn or the whole conversation, and how often it gets it wrong.
- Separate reputational damage from harm to the individual in your internal risk assessments: ask whether and how your monitoring accounts for each, and how you would learn about a problem that nobody posts publicly. A bad pairing in chat may reach far fewer people than a public placement (and therefore pose less reputational risk) but low reach does not mean low harm. The person affected may be dealing with something serious offline, and you are less likely to hear about it unless the incident escalates beyond a screenshot.
None of this has a settled answer yet, ours included. What does brand safety mean when the environment is a conversation that keeps changing, and the only party who can see it is the one selling the ads? We’ll focus on this in Part 2. If you work on the platform side, the buying side, verification or policy and you think we have this wrong, we would love to hear it.
Topics: measurement, Twitter, ad placement, Platforms, ethics, artificial intelligence, generative ai, genAI, OpenAI, Spotify, verification
Want To Stay Ahead In Brand Safety?
Sign up for the BSI Newsletter to get our latest blogs and insights delivered straight to your inbox once a month—so you never miss an update. And if you’re ready to deepen your expertise, check out our education programs and certifications to lead with confidence in today’s evolving digital landscape.
