Ad Disclosure Language Inside AI Responses
Research shows ads embedded in AI responses slip past users based on placement, not labeling alone.

An AI response is different: users approach AI responses with a qualitatively different trust posture than they bring to a list of links, so the visual separation between a labeled ad and an organic AI response is doing more work than any "Sponsored" tag in search history. Users approach it as synthesized judgment, a single answer a system has already weighed and reasoned through on their behalf, rather than a shelf of options waiting to be picked over. That difference in posture is what makes disclosure inside AI responses a genuinely harder problem than slapping "Sponsored" above a link ever was, and it's why the visual separation between a labeled ad and an organic answer now carries more weight than any label in the history of search advertising.
The stakes aren't theoretical. Research out of the University of Michigan, Peking University, and the University of Hong Kong, published on arXiv by Xu, Chen, Deng, Huang, and Schoenebeck, found that ads folded directly into large language model outputs often slip past users entirely. That's a finding about geometry, not wording: where the commercial content sits, and how it's produced relative to the answer, decides whether any disclosure has a chance of registering at all. The regulatory backdrop makes the requirement explicit rather than aspirational. The paper cites the FTC's own position, that advertising which isn't identifiable as advertising to consumers is deceptive if it misleads them into thinking it's independent or impartial rather than paid for.
A companion paper by Qiu and Mei, also out of the University of Michigan, sharpens the picture further. Deployed systems today put commercial content almost entirely on the one tier that's easy to see and easy to govern: the visually separated sponsored unit. Meanwhile, subtler forms of influence, how information gets framed, which sources get surfaced, how a system nudges behavior, remain mostly undisclosed, and there isn't yet a real framework for detecting or attributing any of it. What the industry currently calls "disclosure," then, is really a first-generation form of restraint: platforms have agreed to keep the obvious commercial boundary visible, while the harder questions about influence buried inside the generative process itself stay open. The rest of this piece maps how differently the major platforms have drawn that visible boundary, and where it starts to blur.
The February 2026 ad launches and the formal disclosure moment
The shift from theory to product happened fast and within a narrow window.
OpenAI's move was notable partly because of what it reversed. For three years, the company had said ChatGPT would never carry advertising; it launched ads anyway on February 9, 2026. The pilot wasn't casual: advertisers needed a $200,000 commitment and paid a premium CPM, with launch partners including Target, Adobe, Williams-Sonoma, and Albertsons.
Google's approach arrived on a parallel track. Google began testing clearly labeled "Sponsored" placements inside its AI responses, starting in retail before expanding into other categories, according to the Weekly LLM Advertising Brief; inside AI Mode specifically, users see something Google calls a "Direct Offer," a tailored, recommendation-shaped ad sitting inside the answer itself rather than beside it. Microsoft moved at the same time, extending Copilot ads into conversational sessions through a mechanism it calls "ad voice," which places ads below the organic response based on the direction of the whole session, not just the last query.
None of this stayed confined to product roadmaps. The same February 2026 window saw candidates and advocacy groups start framing AI oversight as a voter-facing issue ahead of the 2026 midterms, which meant disclosure language jumped from internal product meetings to public political debate almost as soon as the ad units themselves went live. The channel crossed from experiment to line item in February 2026, when OpenAI launched ads on ChatGPT and Google formalized "Sponsored" placements inside AI responses, both events happening within weeks of each other and signaling that disclosure language became a live, practical question at scale. The self-serve Ads Manager opened on May 5, 2026, removing the spend minimums and opening the channel to a much wider advertiser base.
The four platform approaches to disclosure and what each communicates to users
Four companies faced the design challenge that an ad has to sit somewhere near an AI-generated answer, and arrived at four structurally different answers. Each answer is really a statement about how that platform wants users to understand the relationship between its commercial content and its own judgment.
A ChatGPT ad renders as a labeled sponsored card below the assistant's answer (not woven into the answer text), and the model's response is explicitly not for sale. That separation functions as the entire disclosure mechanism. The answer sits in one register, the paid card sits in another, and the geometry alone tells the user which is which. The Michigan arXiv paper singles this out as the clearest example of what it calls first-generation restraint, a visually separated sponsored unit kept apart from the organic response by design. OpenAI backs this with a tier structure: ads only reach logged-in adults on the Free and Go plans, while Plus, Pro, Business, Enterprise, and Education accounts stay ad-free, which functions as a kind of disclosure by architecture, since paying for a subscription buys the user out of the commercial layer. OpenAI's policy also builds in exclusions for what it calls "sensitive user contexts," covering emotionally reliant conversations and mental or personal health topics.
Eligible campaigns serve automatically inside Google AI Overviews and AI Mode, with no opt-in or opt-out control, so qualifying advertisers are already inside AI answers. Inside AI Mode, the "Direct Offer" format sits within the answer itself rather than below it, a genuinely different geometry from ChatGPT's card, and one that raises a distinct question: can a user reliably tell a recommendation from a response when both are phrased the same way? Google leans on the label word "Sponsored" to do the work of separating commercial from organic, a convention inherited from search, now applied to a surface where users may not carry the same label-reading habits.
Microsoft's Copilot goes further still by opting advertisers in automatically. All eligible campaign and ad types are automatically enrolled to serve inside Copilot, advertisers can't opt out, no particular ad is guaranteed to display, and the units themselves are built from assets advertisers already have running elsewhere. The "ad voice" mechanism reads the arc of an entire conversation to decide what's relevant. Microsoft has layered several distinct commercial surfaces on top of that base: Compare & Decide ad units and shopping campaigns, both dating to 2023, and Copilot Checkout, an in-conversation purchase flow that launched in January 2026. Checkout is the outlier of the group. It isn't an ad sitting near an answer at all, it's a transaction that starts inside the conversation itself, which raises a question none of the label-and-placement conventions above were built to answer: what does disclosure even mean once the commercial action is the conversational step? Google's AI Overview ads carry the "Sponsored" label, are limited to English, and exclude sensitive verticals including adult, alcohol, gambling, finance, healthcare, and politics. Microsoft Copilot.
Perplexity and Anthropic sit at the other end of the spectrum, and both are instructive precisely because they opted out. Perplexity launched sponsored answers in November 2024, later stopped signing new advertisers, and wound the entire program down, with leadership telling the Financial Times that a sponsored placement risks casting doubt over the whole answer, not just the sponsored part of it. By February 2026, Perplexity had walked away from advertising altogether, citing user trust concerns directly, and pivoted toward subscription revenue as an ad-free product. Anthropic never entered the market in the first place: Claude carries no ad placement at all. Non-participation is, in its own way, the most conservative disclosure posture available, since removing commercial content removes any need to disclose it at all, at the obvious cost of a revenue line the other three platforms are now building out. ChatGPT / OpenAI. Google AI Overviews and AI Mode.
Label language and placement geometry
Disclosure isn't one dial, it's three moving independently: the word chosen ("Sponsored," "Direct Offer," "Ad"), where that word is placed relative to the answer, and the conversational context the unit is placed in.
Take the words themselves first. Sponsored" is the term Google carries forward from search, and it works reasonably well for users who've learned to spot it in a list of ranked results, but its meaning bends when the surrounding material is synthesized prose instead of discrete results. Direct Offer," Google's AI Mode term is recommendation-shaped language that is more descriptive of what the unit does but potentially less immediately recognizable as commercial. The Xu et al. The paper is blunt that FTC rules require the ad to be identifiable as advertising at the actual point where a user encounters it, not merely labeled somewhere on the page in general, and this legal floor governs all of this.
Geometry does the heavier lifting in practice. The same empirical finding cited earlier, that ads embedded directly in LLM output often go unnoticed, means a below-answer card like ChatGPT's is structurally easier to spot than an ad woven into the response text itself. The paper identifies four influence tiers ordered by proximity to the generative process (product mentions, information framing, behavioral redirection, and long-term preference shaping), and only the first tier, product mention, is typically what current label language covers. Their framework also names the mechanism that makes disclosure possible at all: when an ad unit is generated separately from the answer and then inserted, there's a clean, locatable seam to label; once influence enters the generation process itself through framing or source selection, that seam disappears, and there's no boundary left to put a label on.
Google's "Direct Offer" sits right at that fault line. The brief describes it as explicitly "recommendation-shaped," meaning its format is built to resemble the AI's own organic recommendation style, a design choice that works directly against whatever the label is trying to communicate. Qiu and Mei's research backs up why that competition matters: LLM-generated framing can shift a user's attitude even when the underlying facts stay identical, and shopping agents show measurable position bias, so a seller can shift market share just by changing how a product is described, and none of that shift is touched by any current disclosure label. Perplexity's exit is the clearest evidence that these tensions aren't abstract. A company that builds its entire product on being a trustworthy answer engine looked at exactly this seam-versus-no-seam problem and concluded there was no label it could write that would keep a sponsored placement from casting doubt on the answer sitting right next to it.
Tone is the quieter variable that shapes how disclosure lands. OpenAI updated GPT-5.3 Instant specifically to soften follow-up phrasing and cut back on teaser-style language, on the reasoning that tone functions as trust infrastructure in its own right. An ad sitting inside a calm, measured answer reads as categorically different from the same ad sitting inside a response written to build anticipation, even if the label text is identical in both cases. The word used ("Sponsored," "Direct Offer," "Ad"), the visual position relative to the answer, and the conversational context in which the unit appears each communicate independently, and when they point in different directions, the result is ambiguity that label text alone cannot fix.
Disclosure gaps in sensitive conversational contexts
A "Sponsored" tag that works fine in a conversation about hiking boots or flight prices can fail entirely in a conversation about a medical symptom or a debt problem, and the label hasn't changed at all. What's changed is the user's relationship to the answer itself, since people bring a different, more dependent kind of trust to an AI's judgment on a health or financial question than they bring to a shopping query. Platforms have effectively conceded the point by carving out entire categories where ads simply don't run.
OpenAI's policy explicitly builds in what it calls "sensitive user contexts," a category defined to include emotionally reliant conversations, mental and personal health discussions, and other sensitive user journeys. Google's exclusion list runs in a similar direction, keeping AI Overview ads out of adult content, alcohol, gambling, finance, healthcare, and politics. Both lists amount to an admission that no combination of label and placement is adequate once the subject matter itself is high-stakes enough.
Qiu and Mei's paper gives the underlying reason. Generative AI systems get used in exactly the kind of open-ended, personalized, high-stakes decisions where users lean on the system's judgment the most, and that posture is qualitatively different from casual browsing, so the identical label word carries a heavier, riskier meaning depending on what's being discussed. There's a measurement problem behind the category exclusions too, and it works like this: the research brief notes that a majority of marketers have already run into AI-related incidents, hallucinated claims or off-brand content among them, while the tools to actually catch those failures lag well behind the rate at which platforms are shipping new ad surfaces. Category exclusions are a reasonable stopgap. They are not, on their own, proof that the underlying detection problem has been solved.


