An OpenAI cookie may be following some users beyond ChatGPT and onto third-party websites.
Security researcher Buchodi found that an OpenAI __obi cookie can be included in requests made from websites using the company’s advertising technology. The cookie can remain in a browser for up to a year, giving OpenAI a persistent identifier that may reappear when the same browser visits participating sites.
The finding does not show that OpenAI can see everything a user does online. But it raises new privacy questions about how activity outside ChatGPT may be linked through the company’s advertising infrastructure.
How the OpenAI identifier follows users across sites
Web tracking for advertising has become so common that many users already expect some level of it. OpenAI has also used cookies for years, and the __obi cookie itself is not a novel tracking technology, according to Buchodi. The more interesting part of this discovery is how OpenAI classifies and deploys it.
For starters, OpenAI places __obi under the Analytics section of its cookie policy rather than its Marketing section. OpenAI describes analytics cookies as tools for understanding how its services perform and how users interact with them. In contrast, its policy separately defines marketing-performance cookies as those used to measure the effectiveness of marketing campaigns.
OpenAI lists __obi with a one-year lifespan. Additionally, Buchodi found that the mechanism can work even when a user is signed out of ChatGPT. During testing, anonymous identifiers remained stable for at least 27 days.
When a participating website loads OpenAI advertising code, the browser can send the __obi cookie back to OpenAI alongside information transmitted by the site. Depending on what the website sends, that could allow activity on different pages to be associated with the same browser identifier.
iOS appears to limit some of the tracking
Apple's browser privacy protections are designed to restrict many forms of cross-site tracking, which may reduce how this mechanism works on iPhones and iPads.
Buchodi's testing focused on Chrome for Android. Desktop browsers and other mobile environments were not tested, so the extent of the behavior across platforms remains unclear.
Just when OpenAI is doubling down on its commercial angle
The timing of this discovery is hard to ignore: OpenAI is rapidly turning ChatGPT into an advertising business. OpenAI’s ad operation reached a $1 billion annualized revenue run rate on August 31, 2026.
That growth came less than a year after OpenAI began deploying ads inside ChatGPT. That means advertising is now one of the revenue streams OpenAI is building alongside subscriptions, enterprise services, and API usage, making it increasingly important to measure what users do after seeing an ad.
That helps explain why OpenAI has built technology that can connect users’ activity on an advertiser’s website. It also comes at a time when retailers and AI companies are constantly fighting for customers’ data, suggesting that data generated by web visitors' activities outside an AI chatbot has become increasingly important.
The privacy tradeoff of convenience
For users, the tradeoff is becoming clearer: ChatGPT offers a convenient place to search, research, shop, plan, and get answers, but OpenAI is also building a system that can make that activity more valuable for itself and advertisers.
ChatGPT can potentially hold highly personal information. And although the company claims it doesn’t use personal conversations for advertising, advertising has traditionally relied on getting a user’s interests right, which raises a major data-privacy question regarding this __obi cookie.
The research does not show that OpenAI can see everything a user does online.
The practical concern for users is that an identifier originating from an AI service can now appear in activity outside that service, giving users another piece of data to consider when deciding what they share with ChatGPT and how much of their online activity they are comfortable having tied back to the platform.
Other news: TeamFiltration attackers targeted 5,714 accounts across 28 Microsoft 365 tenants, compromising seven forgotten service accounts that lacked MFA and may have used default or predictable passwords.





