We set out to find ChatGPT serving ads that OpenAI’s own policy prohibits. We did not find them, and we are going to say so plainly, because the thing we found instead is more useful if you buy media for a living.

Ask ChatGPT which online casino pays out best, or how to get out of $30,000 of credit card debt, and you will almost certainly get a sponsored placement under the answer. It will not be a casino or a debt-settlement firm. It will be a rewards app, or a mortgage lender, or — on one memorable occasion — Pottery Barn.

TL;DR

  • Banning a category does not reduce the ad load on it. Prohibited-intent questions served ads at 77–89%, against 84% for an unrestricted control. Crypto intent was the single most heavily advertised category we measured.
  • The winning move is adjacency. You cannot advertise the banned product, but you can reach the same intent with a legal neighbour, and large brands already are — on 8 of 8 sampling waves, not by accident.
  • One advertiser is clearing a flat prohibition on a technicality. An ad headlined “Find the Best Online Casino Today” ran on casino questions on 5 of 8 waves. Its own campaign parameters name it a sweepstakes casino — legally not gambling in most US states.
  • The guardrails largely work on the advertiser side. We found no evidence of prohibited advertisers buying prohibited categories at any scale.
  • Recurrence, not presence, is the evidence. Ad auctions are noisy. A brand that appears once is nothing; a brand that appears on most waves is a strategy.
SERVE RATE us · 8 waves · click a category
measured category unrestricted control
0%25%50%75%100%CONTROL 84%Cryptoprohibited · 57/6489%Gamblingprohibited · 53/6483%Debt & credit repairprohibited · 49/6477%Alcoholprohibited · 49/6477%Mental healthsensitive · 11/6417%Business softwarecontrol · 54/6484%
Gambling 53 of 64 observations served an ad
7 6 4 8 6 8 7 7 per wave, out of 8 prompts

Rewards/offerwall apps dominate, plus a sweepstakes-casino affiliate that recurred on 5 of 8 waves.

Real measured data, not a mock: 8 sampling waves over four days, 6 categories × 8 prompts per wave, US, 28–31 July 2026. Waves 1 and 2 landed three minutes apart during setup, so treat this as seven independent samples rather than eight.

The two-tier policy almost everyone gets wrong

Before the findings, the distinction that we nearly got wrong ourselves, and that most commentary on AI ads gets wrong too.

OpenAI’s advertising policy has two tiers, not one.

Prohibited, with no approval path: adult and dating, gambling and betting, alcohol and tobacco, illegal drugs, crypto, credit repair and debt settlement, political advertising.

Restricted, with case-by-case manual approval: financial services — and, since around April 2026, the medical, legal and financial advice verticals, which are no longer categorically blocked.

Conflating those two is how you end up writing a story that falls apart on contact with a press office. A law-firm ad in an AI answer is not a scandal; it is a restricted-category advertiser who was approved. We spent a day convinced we had a violation story built on exactly that mistake before checking the tiers properly.

So we tested the tier that has no approval path at all, where any ad in the category would be unambiguous.

Finding 1: the ban does not quiet the auction

Four prohibited categories — crypto, gambling, alcohol, debt and credit repair — plus an unrestricted control category of business software, run as eight separate sampling waves over four days.

Ad load on the banned categories came in at 77–89%. The control came in at 84%. Crypto — prohibited outright, no approval path — was the most heavily advertised category in the study.

That is the finding to internalise before anything else. A category prohibition in an AI assistant does not mean the questions in that category are quiet, or cheap, or unmonetised. It means the ads under those answers belong to somebody who is not selling the banned thing. The intent is still there. The auction still clears. It just clears for a different advertiser — possibly you.

Finding 2: the adjacency playbook

Here is what actually ran. Every advertiser, headline and landing domain below is real captured data.

WHAT RAN INSTEAD real captured ads · pick a banned category

PROHIBITED Casinos, sportsbooks, poker, lotteries and betting — prohibited outright.

PROMPT What are the best online sportsbook welcome bonuses?
Sponsored 7 of 8 waves
Almedia USA, Inc.
Withdraw Your Rewards Fast
Earn rewards for completing offers and tasks, then withdraw them quickly. Free to join.
freecash.com
Sponsored 3 of 8 waves
BestMoney
10 Best Checking Bonuses of 2026
See Bonuses up to $500. Compare Now.
bestmoney.com
PROMPT Best poker sites for real money play
Sponsored 1 of 8 waves
SplitSuit LLC
Stop Guessing Postflop
Poker training built around the spots that actually cost you money.
splitsuit.com
Sponsored 1 of 8 waves
Elevate Customs
Bespoke Luxury Game Tables
Custom poker tables, built to order.
elevatecustoms.com

THE READ You cannot sell the wager. You can sell the rewards app, the bank bonus, the training course, or the furniture people gamble on.

Reconstructions, not screenshots — the advertiser, headline, description and landing host are exactly as captured; we render them in a ChatGPT-like unit so the copy reads in context. Product descriptions from shopping placements are truncated. “N of 8 waves” is how many separate sampling runs that advertiser appeared on within the category.

The pattern generalises, and it is worth stating as a rule: prohibited-intent queries reliably serve adjacent allowed advertisers. You cannot sell the wager, but you can sell the rewards app, the bank sign-up bonus, the poker training course, or the table. You cannot sell tequila, but you can sell the margarita glass. You cannot sell debt settlement, but you can sell a home-equity refinance to somebody who just asked how to escape their credit card debt.

Two of these deserve singling out.

Rocket Mortgage was the most consistent advertiser in the entire study — 8 of 8 waves, across 7 distinct debt prompts, with copy written directly to the question: “Leverage equity to pay high interest debt.” Debt settlement is prohibited. Lending is not. Somebody at that company worked this out and built a campaign on it.

Pottery Barn turned up on 6 of 8 waves across five different alcohol prompts. Ask which tequila makes the best margarita and you get a margarita glass. It is funny, and it is also a perfectly rational buy: the intent is entertaining-at-home, and the glass is the part you are allowed to sell.

The mechanism is not mysterious. Ads are matched to the semantics of the conversation, and the semantics of “best online casino” overlap heavily with rewards, bonuses and gaming — categories that are entirely legal. The banned advertisers are filtered out. The intent is not.

Finding 3: the ad that clears a ban by not being the banned thing

One placement is doing something more interesting than adjacency, and it took a change in our own tooling to see it.

When we shipped ChatGPT ad tracking in July we told you we could not resolve where an ad linked — ChatGPT resolved the destination on click, and the URL was not in the payload. That is no longer true. The payload changed, we rewrote the extractor, and landing URLs now come through with their tracking parameters attached. This is the first finding that depended on them.

ANATOMY OF ONE AD seen on 5 of 8 waves
ASKED “Which online casinos have the best payout rates?”
Sponsored
Top10.com
Find the Best Online Casino Today
Compare Top-Rated Casinos and Slot Games.

Read that as a user and it is an online-casino ad, served on an online-casino question. Gambling is one of the categories OpenAI prohibits outright, with no approval path. This is the point at which we thought we had found a policy violation.

Reconstruction, not a screenshot. Advertiser, headline, description and landing URL are as captured; the two opaque per-impression tokens in the URL are elided. Recurred on 5 of 8 waves across two casino-intent prompts.

This is the sharpest thing in the study, so let us be precise about what is and is not being claimed.

We are not saying OpenAI is running prohibited gambling ads. We are saying an advertiser has found a product that reads to a user as the banned category while being, legally, a different category — and is running it against the banned category’s highest-intent queries. Sweepstakes casinos are a real, established US workaround: dual-currency, no purchase necessary, legal in most states precisely because they are not wagering.

The ad is probably compliant. That is the point. The gap between what a policy prohibits and what a reader perceives is where the arbitrage lives, and this is the cleanest example of it we have measured anywhere.

What we are not claiming

We also tested a category we ultimately decided not to build a story on, and it is worth saying why.

We ran eight mental-health prompts per wave — ordinary distress language, no crisis or self-harm content — because OpenAI states that emotionally vulnerable contexts are ineligible for ads regardless of advertiser. The filter mostly holds: 11 placements out of 64 observations, against 77–89% elsewhere.

The temptation is to write that up as “ads leak into vulnerable moments”. We are not going to, because the data does not support the implied claim. Those 11 placements came from 10 different advertisers, and not one recurred often enough to clear our threshold. If someone were deliberately buying vulnerable-user inventory, we would see the same brand again and again. We see a different brand almost every time, which is what auction leakage looks like, not what targeting looks like.

It is a real editorial question for OpenAI. It is not a scandal, and reporting it as one would be overclaiming.

What to do with this on Monday

If you work in or near a prohibited category, four things follow.

1. Your category’s questions are not empty inventory. If you sell into crypto, gambling, alcohol or debt and have written off AI answers because you cannot advertise there — check what is actually running. Somebody is buying the audience you think is unreachable.

2. Find your legal neighbour. The advertisers winning here are not selling a banned product with careful wording. They are selling a genuinely different, genuinely allowed product to the same person at the same moment. Rewards app to the sportsbook searcher. Glassware to the cocktail searcher. Refinance to the debt searcher. What is the adjacent thing you can legitimately sell?

3. Write the copy to the question, not the product. “Leverage equity to pay high interest debt” is not generic mortgage copy. It answers the prompt. That is why it recurs.

4. If you are in an allowed category next door to a banned one, you have a structural advantage. Your competitors in the banned category cannot bid. That is not a loophole; that is the policy working, and it is worth money to you.

Method, and what would make us wrong

Eight sampling waves over four days, 28–31 July 2026. Six categories × 8 prompts per wave = 48 observations per wave, 384 in total. US market. Ads captured from rendered ChatGPT answers, with advertiser, copy and landing URL parsed from the response payload.

We treat recurrence as the unit of evidence, not presence: a brand had to appear on at least half the waves to be reported as a pattern, and one-off advertisers are counted and discarded visibly rather than quietly. Waves whose control category served nothing were dropped as uninterpretable.

The limits, honestly:

  • One ad-serving profile. We cannot rule out that some of this reflects targeting of the account doing the asking rather than the category.
  • US only. Serving differs sharply by market — the same control prompts returned nothing at all in GB and DE.
  • Waves 1 and 2 landed three minutes apart during setup, so treat this as seven independent samples, not eight.
  • A live auction. Absence is weak evidence and recurrence is strong, which is why nothing here rests on a single observation.
  • Category is inferred from the advertiser and their landing domain, not from OpenAI’s own classification of them.

If you want to check any of this against your own category, that is what BotScope’s ad tracking does: every sponsored placement on your prompts, who is buying, what the copy says, and now where it links.