started · updated
AI chatbots leak user data to advertisers, researchers find
Researchers from IMDEA Networks and the Universidad Carlos III de Madrid have demonstrated that major AI models, including ChatGPT, Gemini, Claude, Grok, Perplexity, and Mistral, leak conversation data to advertising networks and third-party analytics platforms. Additionally, systems such as DeepSeek, Microsoft Copilot, and Meta AI were found to transmit device information and chat metadata to personal data brokers.
The study, which has been accepted by the Privacy Enhancing Technologies Symposium (PETS), concludes that conversational AI utilizes data extraction methods similar to traditional web services to facilitate ultra-targeted advertising. This finding challenges the perception of AI chatbots as confidential exchanges between users and providers.
The Spanish Data Protection Agency has been notified of these findings and has escalated the matter to the European Data Protection Board to determine if these transfers violate EU regulations. This follows a long-standing investigation into ChatGPT's data processing practices.
In a separate warning, the State Cyber Guard has alerted parents and educators that minors are particularly vulnerable to exposing sensitive information—such as full names, addresses, school details, passwords, and private photographs—while interacting with AI chatbots for schoolwork or entertainment. Authorities emphasize that AI should not replace professional medical or mental health advice and urge families to monitor how children use these tools.
Entities
Agencia Española de Protección de Datos · ChatGPT · Gemini · IMDEA Networks · Universidad Carlos III de Madrid