Anu Adegbola reported at Search Engine Land on August 7 that OpenAI shipped a batch of ChatGPT Ads updates: conversion-optimized cost-per-click campaigns in beta, dynamic URL parameters, integrations with Triple Whale, Hightouch and Sonar Optimize, better pixel validation diagnostics, a multi-product carousel format in testing, and launches in Brazil and Mexico this week.
One line in that list is a different kind of item. Automatic Advanced Matching is now on by default for all new web pixels, and on August 17 it turns on automatically for every existing pixel unless the advertiser goes into Tools, then Conversions, then Data Source, and switches it off.
AAM reads the information visitors type into your website forms, hashes it in the browser, and sends it along with the conversion event so OpenAI can match more of those conversions back to ad interactions. That is a change to what leaves your site and who gets it, and it is arriving as a default with roughly ten days of notice.
The mechanism is old. The counterparty is three months into the business.
None of this is novel. Meta shipped Advanced Matching years ago on the same logic, Google has its own version, and hashing in the browser is real protection against the plain-text version of this problem. Any performance marketer will tell you the signal measurably improves attribution, and OpenAI is not doing anything the rest of the ad industry hasn’t normalized.
What’s different is the age of the relationship. Meta’s pixel has fifteen years of case law, DPAs, agency governance, healthcare and financial-services carve-outs, and a small industry of consultants who know which fields to exclude. ChatGPT Ads has existed since the spring. I wrote about the Ads Manager launch in May and about the ad format where the click opens a conversation with your own agent two weeks ago. The pixels catching this change were installed by someone testing a new channel a few months back, and a test installation does not come with a governance plan.
Ten days versus a privacy review
At Oracle and Zeta I spent a good part of my life waiting on the other side of this exact process. A change to what customer data a tag collects goes to privacy, then to security, then to whoever owns the data processing agreement, and in a regulated industry it goes to compliance after that. Six weeks was a good outcome. Two weeks meant someone owed someone a favor.
Ten days from a Friday announcement, over a summer weekend, in August, when half the approval chain is out. The people who will find out about this are the ones whose agency mentions it in a September performance review, or whose privacy team runs a tag audit in the fourth quarter and asks a question nobody enjoys answering.
Worry less about the hash than about the form. Advanced matching pulls from what people type into your fields, and companies put strange things in fields. A quote form on an insurance site, an eligibility checker on a health system’s pages, an application form at a lender. Most privacy programs handle this with an explicit list of fields the tag may never read, and that list only exists where somebody built it. On a pixel dropped in during a channel test, nobody built it.
September is a month of defaults
OpenAI isn’t alone. Starting September 1, Google begins auto-upgrading Search campaigns that use automatically created assets or the campaign-level broad match setting to AI Max, with search term matching turned on by default, and text customization too for the ACA campaigns. Advertisers avoid it by turning the legacy features off or turning AI Max on themselves. Google did push the Dynamic Search Ads migration to February 2027 after advertisers pointed out what a fourth-quarter change would do to their planning, which is a real concession and worth crediting.
Two platforms, three weeks apart, both moving advertisers onto broader automated matching by making it the thing that happens if you do nothing. There’s nothing sinister here. Defaults are how any platform migrates a long tail that will never read the release notes, and both companies published the opt-out. But defaults are also where the actual product decisions get made, because most accounts never touch them.
The org problem underneath the checkbox
The reason this is worth twenty minutes of your week has less to do with OpenAI than with your own org chart. Ask who owns the ChatGPT pixel at your company and you will usually get a pause. Paid media assumes it belongs to analytics. Analytics assumes the agency owns it. The agency assumes the client approved it. It was installed in a sprint by someone proving a channel worked.
Every new AI ad surface is going to arrive this way, as a small tag added during a test that later starts doing more than it did on the day it went in. There will be more of these platforms next year, not fewer, and each one will ship its own version of an August 17 with its own opt-out buried two menus deep. A company that has to convene a meeting to find out who owns a tag is going to be late every time.
Do this before Monday
Pull the list of ChatGPT Ads pixels running on your properties, and make one person the owner of each. Then decide AAM on purpose. Plenty of advertisers should leave it on, because better conversion matching is the entire reason to run performance media, and the hashing is real. Ecommerce, most retail, most consumer subscription businesses, leave it on and take the signal.
If you operate anywhere near health, financial services, legal, education or anything else where a form field can contain a fact about a person you’re not allowed to share, opt out this week and turn it back on later with a field exclusion list your privacy team wrote. Reversing the decision costs a few clicks. Explaining eight weeks of collection you didn’t authorize costs considerably more.
And if you sell into marketing teams, put the September 1 Google change on the same page as this one and send it to your accounts. Being the person who told a CMO about a default before it flipped is worth more than another follow-up email, and it takes ten minutes.
