AI Blog

The ad brought its own agent — OpenAI split the conversation instead of the ranking

Everyone predicted a bought ranking; OpenAI bought the conversation instead, and that is the better design — for exactly as long as the two conversations stay apart. Sponsored Agents put an advertiser-operated agent behind a labelled ad slot and keep it out of the assistant's answer. But the separation is a property of the session, and what actually moves between the two lanes is claims, carried by the person, with no field anywhere saying a paid party said it first.

By Agentic AI Wiki 14 min read

Everyone who predicted ads inside an assistant predicted a bought ranking. OpenAI bought the conversation instead — and that is the better of the two designs, for exactly as long as the two conversations stay apart. Sponsored Agents, in limited alpha in ChatGPT since 16 September, put an advertiser-operated agent behind a labelled ad slot and keep it out of the assistant's own answer. The separation is a property of the session, not of the text, and nothing that crosses it carries a mark.

At a glance

What the format is, in the terms that decide whether it is safe.

PropertySponsored AgentsWhy it matters
Who operates the agentThe advertiser, representing its own businessIts stated principal is not the user — a first, inside this surface
How you enterYou tap a labelled ad; a conversation opensEntry is an explicit act, not a silent injection
Relationship to the organic answerSeparate; does not alter, rank into, or become part of itThe protection people wanted, granted at the session level
StatusLimited alpha, selected US advertisers, from 16 September 2026The conventions set now are the ones that get copied
How a Sponsored Agent sits beside the ChatGPT assistant The assistant conversation runs along the top: the person, the ChatGPT assistant, and its independent answer. Below a dashed boundary runs a second conversation: a labelled ad slot the person taps, an advertiser-operated Sponsored Agent, and a handoff to the advertiser's site. A crossed dotted path shows that the sponsored conversation has no route back into the assistant's answer. A second dotted path shows the route that does exist — a price, a spec or an SKU carried across by the person, with no mark on it. One surface, two conversations. You asking a question ChatGPT assistant independent; advertisers cannot rank into it Its own answer the organic result an ad appears in the surface; you tap it the boundary OpenAI drew Ad slot labelled sponsored Sponsored Agent operated by the advertiser, in a separate conversation Advertiser's site the intended handoff no path back into the answer A price, a spec, an SKU carried across by the person, with no mark on it
One legitimate crossing, drawn by OpenAI. One unmarked crossing, drawn by the person.

What OpenAI actually shipped

On 16 September OpenAI began testing Sponsored Agents: an ad format in which a business can attach a conversational agent to its ad slot inside ChatGPT. The person taps the ad, a conversation opens with an agent that represents that business, the agent answers follow-up questions about its products or services, and when the person is ready it hands off to the advertiser's own site or another next step. Wayfair and Angi are among the first advertisers; the format is a limited alpha with selected US advertisers.

Two sentences in OpenAI's description carry almost all of the design. The sponsored exchange is labelled, and it is distinct from both ChatGPT's independent answers and from the conversation the person was already having. Advertisers cannot influence the assistant's responses to the question that was actually asked: the sponsored agent does not alter, rank into, or become part of the organic answer.

That is worth saying plainly, because the industry spent a year expecting the opposite. The obvious way to monetise an assistant is to sell position inside the answer — a retrieval bias, a re-ranked product list, a default that happens to be a customer. Every one of those is invisible at the point of use and unfalsifiable from outside. OpenAI did not do that. It forked the conversation and put a wall between the halves.

So the interesting question is not whether this is a betrayal of the assistant. It is what the wall is made of.

Why forking the conversation is the strong version

Compare the two monetisation shapes on the property that matters — whether an outsider can tell the difference between the commercial and the non-commercial case.

A bought ranking is unauditable by construction

If a paid result is blended into an answer, there is no counterfactual to look at. The answer you received is the only artefact, and it contains no trace of the answer you would have received. You cannot diff it against anything. Neither can a regulator, a journalist, or the platform's own trust-and-safety team, without privileged access to the ranker. The entire remedy is a promise plus an audit you are not allowed to run.

A forked conversation has a counterfactual sitting right next to it

When the sponsored exchange is a separate conversation, the organic answer still exists, unmodified, in the same surface. You can read both. You can notice when they disagree. Anyone can construct the comparison — ask the assistant, then tap the ad, then read the two — which turns a policy claim into something testable by an ordinary user with no special access.

That testability is the actual protection, and it is worth more than the label. A promise you can check is a different category of object from a promise you cannot, and this format produced one almost by accident.

The design also puts the incentive in a defensible place. An advertiser paying for a conversation is paying for attention it has to earn in that conversation; an advertiser paying for rank is paying for the assistant's credibility, which the assistant cannot sell twice. The second business model degrades the asset it is selling. The first does not.

The wall is session-scoped. Claims are not.

Where a sponsorship marker survives A matrix of six surfaces against three properties: whether a visible label is present, whether a machine-readable mark exists, and whether the marker survives into the next turn. Only the sponsored conversation itself carries a visible label and keeps it in session; no surface carries a machine-readable mark, and a pasted quote, an export, a screenshot, read-aloud audio and another agent reading the session all lose the marker. Where a sponsorship marker survives Visible label Machine-readable mark Survives the next turn The sponsored chat itself Labelled None In session Read aloud in voice mode Spoken once None No A screenshot or a share If cropped in None No An export or a transcript Format-dependent None No A claim pasted back into chat None None No Another agent reading the session Not applicable None No Present Partial Absent
One row holds. The rest are where the sponsorship stops being knowable.

Here is the gap, and it is structural rather than a bug anyone shipped. OpenAI separated two conversations. What actually moves between them is not conversations — it is claims. A model number. A price. A delivery window. A statement that this fabric is rated for outdoor use. The person reads it in the sponsored lane and carries it into the assistant lane, because that is what the surface is for: you go back to the assistant to check the thing you just heard.

At that moment the sponsored turn has become an ordinary user message, and it is indistinguishable from one. The assistant has no field that says this sentence originated from a party that paid to say it. It will weigh it exactly as it weighs anything the user types — which, under any sensible instruction hierarchy, is quite a lot, because the user is supposed to be the trusted principal.

The failure is not that the assistant gets corrupted. It is subtler and more ordinary: the person launders the advertiser's claim into their own voice and then asks the independent assistant to validate it. The assistant, being agreeable about premises, frequently will. A paid claim has acquired a neutral endorsement, and no component in the chain did anything wrong.

  • Nothing in the transcript is marked. There is no provenance attribute on a message, no sponsored: true, nothing an export or a downstream tool could filter on. The label is rendering, not data.
  • Memory is the long-horizon version. If anything a person learned in a sponsored conversation reaches persistent memory — a stated brand preference, a product they are considering — it arrives unattributed and outlives the session that would have explained it. A preference acquired in an ad slot is not the same object as a preference the user formed, and after the write there is no way to tell them apart.
  • Voice removes the only carrier. A visual label is a visual affordance. Read aloud, a sponsored exchange and an organic one are the same medium, and the disclosure has to be re-earned in prose every time or it is simply gone.

The third principal, and the surface that had two

Until now, every agent a person met inside ChatGPT had the same stated principal: them. The system prompt was written by OpenAI, the tools were chosen by OpenAI, and one could argue about whether the vendor's interests and the user's diverge at the margins — but the agent was not somebody else's representative.

A Sponsored Agent is. It is a well-built, competent, helpful agent whose objective function contains a term the user cannot see, and it says so on the tin. That is honest, and it is also a new category in this surface: a conversational participant whose loyalty is disclosed rather than assumed. This is the ordinary principal–agent problem, arriving in a place where the answer used to be trivial.

Two consequences follow, neither of which is hypothetical for long.

People do not maintain a loyalty model across turns

The label answers the question at the moment of entry. Nobody re-asks it at turn nine. A helpful agent that has just solved two real problems for you has, by the ordinary operation of trust, stopped being read as an advertisement — which is precisely why this format is valuable to advertisers and precisely the risk it carries. Disclosure that is delivered once and decays is a well-studied weakness in native advertising, and conversation is the highest-decay medium yet built.

The agent-to-agent case has no disclosure surface at all

Today a human taps the ad. The direction of travel in this industry is that a human does not: a shopping agent gathers options, calls out to whatever can answer, and summarises. When the thing it calls is a sponsored agent, every protection described in this post — the label, the visible separation, the tappable entry — is a property of a UI that no longer exists. What crosses is a tool result, and tool results have no consideration field. AP2 and the agent-commerce protocols specify mandates and payment authority in detail and say nothing about who paid to be in the conversation.

The fix for both is the same one, and it is small: a per-message provenance field, emitted in the API and the export, saying that a turn originated from a paid party and which one. It costs one attribute. It survives a copy only if downstream tools carry it, which is exactly why it has to be data rather than a chip in the UI.

The strongest objection

The objection is that this is a solved problem with a long precedent. Sponsored search results have been labelled and separated for twenty-five years; people carry claims out of ads and into conversations with their friends constantly; the law already covers deceptive endorsement. Treating a labelled, opt-in, walled-off ad conversation as a novel risk is an overreaction to a familiar format in a new font.

Most of that is right, and it is why the design deserves the credit given above. But two properties are genuinely new, and they are the two that decide how the precedent transfers.

A search ad cannot ask you questions. The old format is a fixed impression: it makes claims and you evaluate them. A conversational advertiser elicits. It learns your budget, your room dimensions, your deadline, which competitor you were considering, why you rejected it — and then tailors. That is a different instrument, and the disclosure regime built for the first one discloses the wrong thing about the second. Labelling a sponsored agent as an ad tells you its motive. It does not tell you that your answers to it are now an advertiser's first-party data.

The downstream consumer is becoming a model. Native-advertising rules are written on the premise that a human reader is the one who must not be deceived, and a visible label is a reasonable instrument for that. Under the EU's Digital Services Act, platforms must let users identify an ad clearly and in real time, and very large platforms must keep a public repository of ads — again, instruments aimed at a human or a researcher. As soon as an assistant, a memory store, or another agent is the reader, a visual label is not a weak control; it is an absent one. That gap is not a criticism of this launch. It is the thing every ad-supported agent surface is about to run into, and this is the first one to make it concrete.

What to do about it

Split by role, because the actions are different and none of them are "wait".

If you are building an agent surface that will carry ads

  • Make the marker data before you make it a chip. Per-message provenance — paid party, identity, timestamp — in the model's context, the API response, and the export. Design the field on day one; retrofitting provenance into a message format after a million transcripts exist is the kind of migration that never happens.
  • Decide the memory rule explicitly. Either nothing learned inside a sponsored exchange is eligible for persistent memory, or it is written with its origin attached. Silence here resolves to the worst option by default.
  • Re-disclose on state change, not on entry. Once per conversation is the decay curve. On the turn where the agent makes a comparative claim about a competitor, or asks for a personal detail, is where the second disclosure earns its cost.
  • Publish the counterfactual. The separation claim is testable; make it easy to test. A one-tap "what did the assistant say" is a stronger trust artefact than a paragraph in a help centre, because it hands the check to the user.

If you are building agents that will consume these surfaces

  • Treat a conversational commercial party as an untrusted source with a known bias, not as a tool. Its output belongs in the same tier as a retrieved web page: usable evidence, never an authority, and never a premise the agent adopts silently.
  • Keep source identity attached through summarisation. The common failure is not believing an advertiser; it is compressing five sources into a paragraph and dropping which claim came from which. That is the attribution discipline, and commercial sources are the case where it pays.
  • Log the consideration, if you can see it. If your agent routes through a catalogue where placement is purchased, that is a fact about your answers. See commercial influence and paid placement for the operational version.

If you are a person using one

One habit covers most of it: when you carry a claim out of a sponsored conversation, carry its source with it. "Wayfair's agent told me this rug is rated for outdoor use — is that plausible?" gets you a genuinely independent check. Pasting the claim on its own gets you a validation of your own premise, which is a different and much weaker thing.

FAQ

Do Sponsored Agents change ChatGPT's normal answers?

OpenAI says no: a Sponsored Agent does not alter, rank into, or become part of the assistant's independent response, and advertisers cannot influence the answers to questions asked of the assistant itself. The sponsored exchange is labelled and runs as a separate conversation from the one the person was already having.

Who is on the other side of a Sponsored Agent?

The advertiser. The agent represents that business, answers questions about its products or services, and hands off to the business's site or another next step when the person is ready to act.

Is this available to everyone?

No. As of 16 September 2026 it is a limited alpha with selected US advertisers. Wayfair and Angi are among the first participants.

If the separation holds, what is the actual risk?

That claims move between the two conversations while the marking does not. A person who hears something in a sponsored exchange and asks the assistant to confirm it has re-entered that claim as their own, and nothing in the message format records where it came from — so a paid statement can acquire an unpaid endorsement without any component behaving badly.

Would a machine-readable provenance field really help?

It is the difference between a control that works only while a human is looking at a screen and one that survives export, summarisation, memory writes and agent-to-agent calls. A visual label is adequate for the human case and empty for all the others, and the others are where this is heading.

Is an advertising-funded assistant inherently compromised?

Not inherently, and this format is evidence for that. The compromising move is selling position inside the answer, because it destroys the counterfactual anyone would use to check. Selling a separate, labelled conversation leaves the organic answer intact and comparable, which is a materially better place to start from.

Further reading

On this wiki:

Sources: