OpenAI Ads Manager is now available to UK advertisers, while Dentsu has been named a UK launch partner for the ChatGPT ads pilot, with initial clients spanning finance and health as well as retail and travel. For regulated advertisers, the launch raises a new marketing-operations question: how do you approve and evidence a placement when the context that informs delivery remains private?

OpenAI says its ads system can consider the context and intent of the current conversation, together with the ad, landing page, advertiser-provided context hints and other permitted signals. Those hints describe the conversations, topics or keywords where an offer may be relevant, but they are not exact-match keywords and do not guarantee delivery in a particular conversation.

At the same time, the conversation is deliberately private from the advertiser: advertisers do not receive chats, chat history, memories or personal details and instead receive aggregated, non-identifying performance information such as impressions and clicks.

So the platform knows something important about the placement that the advertiser does not. The advertiser can help define where an ad belongs but cannot inspect the conversational context that caused an individual impression.

This is not simply a reporting gap to close, because the privacy boundary is part of the product. The operating problem is how to approve, monitor and evidence the placement without dismantling the feature that protects the user.

The ad card is not the whole placement

OpenAI describes a relatively contained creative unit: advertiser name, title, copy, landing page and image. Ads appear below ChatGPT responses, are labelled as sponsored and are visually separated from the answer. OpenAI also says ads do not influence the answer and run on separate systems.

Those separations matter because a regulated advertiser should not treat the assistant's answer as copy it wrote or sponsored merely because an ad appeared underneath it.

Yet placement context can still matter without becoming part of the creative. Where the conversation remains eligible under the platform's advertising policies, an insurance ad appearing beneath a broad comparison task may carry a different practical risk from the same ad appearing beneath a question about a specific loss or a conversation in which the user seems confused about what is covered.

OpenAI has controls intended to address the highest-risk cases. It says ads are not eligible to appear near sensitive or regulated topics, including personal health, mental health and politics. Advertisers in some regulated categories, including financial services and health, may nevertheless be eligible if they meet the platform's criteria.

For approval purposes, the distinction is between the content of a regulated ad and its delivery envelope: the range of conversations, audiences and circumstances in which the platform may decide that the ad is relevant.

Approving the card alone establishes only that the fixed creative was reviewed. It does not establish that the organisation considered the landing page, the context hints supplied to the platform, the eligible geography, the platform's sensitive-topic controls or the assumptions under which the campaign was judged suitable.

Regulated advertising already treats context as part of meaning

UK advertising rules do not assess wording in a vacuum. The CAP Code says the ASA will take account of the impression created by a marketing communication as well as its specific claims, judging the likely effect on consumers rather than the marketer's intention. The Code also requires marketers to hold documentary evidence for objective claims before distribution.

For financial services, COBS 4 requires relevant communications and financial promotions to be fair, clear and not misleading. The firm must take the nature of the client into account, while the accompanying guidance says the application of the rule should reflect the means of communication, the information being conveyed and the nature of the client.

None of those requirements means that an advertiser automatically becomes responsible for every word surrounding an ad on a third-party platform. The platform controls its response and placement system; OpenAI expressly separates the answer from the advertising.

They do mean that a regulated firm should be able to explain why the communication and its method of distribution were appropriate for the use it authorised. Where selection depends on conversational intent, the distribution logic becomes relevant to that explanation even if the underlying conversation remains unavailable.

This changes the object being approved from a file, headline or landing page to a versioned campaign configuration that joins the creative to a set of delivery instructions and platform controls.

A screenshot may no longer be a sufficient placement record

Regulated firms are accustomed to retaining the approved asset and the record of sign-off. That remains necessary, but it leaves a hole if the asset can be delivered according to contextual signals that are not visible in the screenshot.

The FCA's social media guidance offers a useful analogue. FG24/1 says firms should have an adequate system for signing off digital media communications and keep adequate records. It also warns firms not to rely on the platform itself to maintain those records because the firm does not control the channel.

For relevant financial promotions, COBS 4.11 requires an adequate record of promotions communicated or approved. The rules do not prescribe a ChatGPT Ads evidence pack, but they expose the practical weakness in retaining only the final card.

A useful campaign record would preserve the approved creative, landing-page version, context hints, targeting, exclusions, platform policies, eligibility settings and preview. It would also show who approved the campaign and why, when it launched and what changed later. Performance exports, complaints, exceptions and monitoring decisions should remain connected to that campaign version.

The record should not contain user conversations, since its purpose is to show which delivery envelope the firm authorised and which controls it expected to operate, not to reconstruct private chats after the event.

This also turns a change to a context hint into a controlled marketing change. If the hint expands the conversations in which an ad may be considered relevant, it may change the approved use even when no pixel in the creative has moved.

Test the system under non-ideal conditions

Review teams often test fixed requirements separately: the claim has evidence, the warning is present, the landing page works and the audience is allowed. Each check can pass while the complete system still fails to behave as intended.

A new benchmark called EnterpriseRAG illustrates the wider measurement problem. Although it is not an advertising study, it tests retrieval-augmented language models against complex instructions and imperfect enterprise information, including irrelevant material, missing knowledge and factual conflicts.

Across 13 models and 983 expert-validated samples, the researchers found that the best model satisfied 83.8% of individual constraints but only 26.8% of responses met every constraint. Performance fell particularly sharply when the system had to recognise insufficient or conflicting evidence.

Those numbers do not predict ChatGPT Ads performance. They show how success against each individual control can conceal failure across the whole system when several requirements have to hold at once.

For regulated advertisers, a defensible approval approach is to test scenarios around the approved campaign. Synthetic conversations can represent ordinary use, foreseeable ambiguity, vulnerable users, sensitive subjects, unsuitable intent and edge cases where the product should not be promoted. Reviewers can test whether the creative remains suitable, whether the context hints describe the intended envelope and whether prohibited or uncertain cases are excluded or escalated.

Those scenarios need not reproduce real users' private chats, only make the organisation's assumptions explicit and challenge them before and during delivery.

Aggregate campaign results remain useful, but they answer a different question: impressions, clicks, spend and conversions show delivery and outcome, not whether an ad was appropriate in each conversational setting. OpenAI's current reporting documentation lists campaign-, ad-group- and ad-level metrics and country and device breakdowns but does not expose conversation-level reporting, so monitoring must combine aggregate signals with purposeful tests and documented reassessment.

Measure the reviewers, not merely the queue

Putting a person in the loop does not solve this problem unless the organisation can tell whether the person is making reliable decisions.

Meta's CLARA research, published at KDD 2020, examined a different high-volume review environment: people applying content-policy protocols. Its starting point is familiar to compliance teams: human reviewers can make mistakes even when they follow a defined procedure, while sending every item to several people is expensive.

CLARA estimated both label confidence and reviewer performance. Meta reported that the system could estimate policy-violation rates robustly as reviewer quality changed, assess reviewers and reduce repeated review by using certainty to decide where more judgement was needed.

Although CLARA is not evidence about financial-promotion approval, it offers a more useful model for measuring expert review than counting completed tasks.

For contextual advertising, useful measures include the issue rate in a representative scenario set, detection of seeded high-risk cases, reviewer disagreement, confidence in borderline decisions, the result of second reviews and the time taken to detect drift after a campaign or platform change. The firm should also record residual errors found after approval rather than treating every sign-off as proof that the control worked.

Approval volume and turnaround time remain useful operational measures, but they say nothing about the quality of the judgement.

The privacy boundary should become an assurance boundary

Demanding the underlying conversations would be the wrong response to opaque context because it would transfer more sensitive information to advertisers and weaken the product's privacy design. The better response is to decide what can be proven at the boundary.

A workable assurance model would require the platform to provide clear definitions of contextual controls, versioned policies, previews, change notices, aggregated reporting and evidence that its own exclusions operated. The advertiser would define a narrow intended use, approve the full campaign configuration, challenge it with synthetic scenarios, monitor changes and retain the reasoning behind each decision. Independent assurance may eventually test the platform's controls without disclosing individual conversations.

This model will feel unfamiliar because it separates observability from disclosure. The advertiser may not be able to inspect the decisive signal directly, but it can still require testable controls around how that signal is used.

ChatGPT Ads is therefore more than another new channel, moving regulated marketing towards a form of approval in which the most important context may remain private while the system acting on that context still has to be governable.

Private should not mean unauditable. The work is to build an evidence trail that respects both sides of that sentence.

What teams need to know

Is ChatGPT Ads available to advertisers in the United Kingdom?

Yes. OpenAI currently lists the United Kingdom among the countries where Ads Manager is available.

Advertiser availability is distinct from which users and account types may see ads. The product remains in testing and availability can change as that testing expands.

How do I advertise on ChatGPT?

Start with OpenAI's official Ads page and follow the Sign Up to Advertise route. Once an account has access, advertisers can use Ads Manager; OpenAI also provides an Advertiser API for programmatic ad creation and performance monitoring.

Availability, supported markets and category eligibility can change while the product is in testing, so regulated advertisers should check the current requirements before building a campaign.

Can ChatGPT Ads advertisers see users' conversations?

No. OpenAI says advertisers do not receive chats, chat history, memories, names, email addresses or other personal details. Advertisers receive aggregated, non-identifying performance information.

If a user chooses to message an advertiser directly through an ad, the advertiser can see only the messages sent directly to it.

Do ChatGPT ads influence ChatGPT's answers?

OpenAI says no. Ads run on separate systems, appear below the response and are visually separated and labelled as sponsored. Advertisers cannot shape, rank or alter ChatGPT's answer.

What should a regulated advertiser approve?

The approval scope should extend beyond the visible card. It should cover the creative, landing page, context hints, targeting, exclusions, relevant platform controls and the assumptions defining the campaign's intended delivery envelope.

Changes to those elements should be assessed as campaign changes even when the creative remains identical.

How can a firm evidence a placement without retaining private conversations?

The firm can retain the approved configuration, platform preview, applicable policy version, scenario tests, reviewer rationale, change history, aggregate reporting, complaints, exceptions and subsequent monitoring decisions.

This preserves evidence of the control system without obtaining or storing private user chats.