
September 21, 2026 · Product & Privacy
A reverse-engineering write-up circulating this week describes an OpenAI advertising-measurement pixel at bzr.openai.com. The pixel is said to mint a JWT-bound cookie scoped to .openai.com, with SameSite=None and a one-year lifetime, so sites that embed it can ping OpenAI with a visitor identity linked to a ChatGPT account.
AI Weekly and other briefings reported that the pixel appears in public documentation rather than as a fully hidden tracker. That does not settle the product question: whether ChatGPT-scale consumer identity should be joined to off-platform browsing for ad measurement.
The finding arrives as labs race to monetize beyond subscriptions. Measurement pixels are standard in digital advertising, but attaching them to a widely used assistant changes the privacy surface. Users who treat ChatGPT as a private workspace may not expect their logged-in identity to travel with third-party site visits.
Regulators in the EU and California already police cross-site tracking. How OpenAI describes consent, retention, and opt-out will matter as much as the technical cookie flags.
Key takeaway OpenAI is operating an ad-measurement pixel that can associate external web visits with ChatGPT-linked identity—an ordinary ad-tech pattern with unusual stakes because of the assistant’s reach.
Photo: Unsplash. Sources: AI Weekly; AIToolsRecap; field write-up referenced Sept. 21, 2026.
