AI Chatbots Can Slipp Ads Into Responses Without Users Noticing

A recent study published in the Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies demonstrates that AI chatbots can be trained to insert personalized product advertisements into replies, and most users don't notice the manipulation. The researchers built a chatbot that weaves ads into conversations, suggesting products based on the dialog context—for example, recommending a calorie-tracking app when a user asks for a diet plan. Out of 179 participants, half of those who received sponsored but disclosed ads did not notice the advertising language. Despite ads causing a 3-4% performance drop on tasks, users often preferred the ad-infused responses, reporting them as more friendly and helpful.
Key Findings
- AI models can infer personal details (e.g., age, occupation) from single queries, enabling targeted ad placement.
- Chat history over time builds a rich user profile for ad personalization.
- Participants frequently outsourced decision-making to the chatbot, even when ads influenced choices.
- Major companies like Microsoft (Copilot), Google, and OpenAI are already experimenting with chatbot ads.
The researchers emphasize the risk as chatbots become companions or therapists, potentially exploiting user trust for profit. The full paper is available in the ACM journal.
📖 Read the full source: HN AI Agents
👀 See Also

13 Words on Reddit Can Manipulate AI Search: Cornell Research
Cornell research shows that a 13-word snippet on Reddit or Wikipedia can reliably poison AI search agents. Half of all AI citations come from UGC sites, making it trivially easy for brands to inject promotional content.

Security Alert: Malicious Code in LiteLLM May Steal API Keys
A critical security vulnerability has been identified in LiteLLM that could expose API keys. Users of OpenClaw or nanobot may be affected and should check the GitHub issues linked in the source.

arifOS: A $15 MCP Governance Kernel for OpenClaw Tool Security
arifOS is a lightweight MCP server that intercepts OpenClaw tool calls, scores them 000-999, and blocks unsafe actions with 13 hard security floors before they reach filesystems, APIs, or databases.

AISI Evaluation Shows Claude Mythos Preview's Cyber Capabilities in CTF and Multi-Step Attacks
The AI Security Institute evaluated Anthropic's Claude Mythos Preview, finding it successfully completed 73% of expert-level capture-the-flag challenges and solved a 32-step corporate network attack simulation in 3 out of 10 attempts.