AI September 29, 2026 bearish ⇧ 300 pts across 2 threads

AI platforms leaking conversation data to advertisers

A new PDF study circulating on HN documents multiple AI providers sharing sensitive conversation data with third-party advertisers. The most concrete example: Grok's conversation permalinks lacked access controls, so any tracker receiving the URL could read the full chat. Other providers are leaking conversation titles, prompts, and screenshots alongside persistent user identifiers that enable cross-platform tracking.

The HN response cuts through the euphemism fast. Multiple commenters point out that calling this a 'leak' is generous: if ad revenue is part of the business model, sharing conversation-derived data with advertisers may be a feature, not a bug. The pattern connects to an older thread in the mix about AI-generated articles flooding content platforms, and a general unease about what these systems are optimizing for when users aren't paying directly.

This lands at a bad time for the industry. The Netherlands moving off Microsoft over sovereignty concerns (see below) is one data point. AI conversation data going to advertisers is another. Both feed the same underlying anxiety: that depending on US-based centralized platforms means your data is not yours.


So what?

Any product built on top of consumer AI platforms that handles sensitive user conversations needs to treat those conversations as potentially visible to third parties. For B2B founders especially, this is a liability and a sales objection waiting to happen. The safe assumption right now is that free or ad-supported AI tiers are monetizing conversations. Price accordingly, disclose accordingly, or route sensitive workloads through API-only, contractually bounded integrations.

Read these