In May 2025, Scorpion announced it had become a technology partner supporting advertising in ChatGPT, enabling local businesses to create, launch, and manage ad campaigns inside OpenAI's conversational interface. The announcement was framed as a channel expansion story. It is not. It is a consent architecture story, and one that most enterprise marketing operations teams are entirely unprepared for.
Advertising inside conversational AI represents a structural departure from every digital advertising model that preceded it. Display ads sit beside content. Search ads respond to declared intent. Social ads interrupt feeds. Conversational AI ads occupy a fundamentally different position: they exist inside a dialogue that users perceive as private, personal, and responsive to their individual context. That perception changes everything about how consent, data collection, and personalization must work.
For enterprise marketing teams running campaigns across Oracle Eloqua, Adobe Marketo, Salesforce Marketing Cloud, and HubSpot, this is not a niche development. It is an early signal of a channel category that will require new consent frameworks, new data handling protocols, and new thinking about what constitutes a marketing touchpoint.
1. Historical context
The digital advertising industry has spent three decades building consent and tracking infrastructure around a single paradigm: the browser session. Cookies, pixels, UTM parameters, landing pages, form captures, and preference centers all assume a user interacts with content through a web browser or a mobile app with a visible interface layer.
This paradigm survived several transitions. It adapted to mobile. It adapted (painfully) to programmatic. It even survived the early social media era, because Facebook, LinkedIn, and Twitter still operated within a browser or app context where tracking mechanisms could function.
The first serious crack appeared with Apple's App Tracking Transparency (ATT) framework in April 2021. ATT did not eliminate tracking. It shifted the consent mechanism from an obscure settings menu to an explicit prompt, and opt-in rates collapsed. Flurry Analytics reported that in the first weeks after ATT launched, only about 4% of U.S. iOS users opted in to tracking. That number stabilized higher over subsequent months, but the damage to the assumed-consent model was permanent.
Google's long-running deprecation drama with third-party cookies in Chrome, which the company ultimately walked back in mid-2024 in favor of user-choice mechanisms, reinforced the same lesson: the era of passive, implied consent for data collection in advertising was ending.
Regulatory frameworks followed a parallel trajectory. GDPR (2018), CCPA (2020, amended as CPRA in 2023), and Brazil's LGPD (2020) all codified the principle that personal data processing requires a lawful basis, and that consent, where relied upon, must be informed, specific, and freely given.
But all of these frameworks were designed around the browser-and-app paradigm. Cookie consent banners, preference centers, and subscription center architectures assume the user can see and interact with a visual consent layer before data collection begins.
Conversational AI destroys that assumption. When a user asks ChatGPT a question and receives an answer that includes an ad, there is no banner. There is no visible pixel firing. There is no landing page with a privacy policy footer. The interaction happens inside a conversational flow that feels like a one-to-one exchange, not a media experience.
This is the gap Scorpion's announcement exposes. The company can now place ads inside ChatGPT. What neither Scorpion, OpenAI, nor the enterprise marketing ecosystem has established is a consent architecture that matches the intimacy and context-richness of conversational AI.
Source: IAPP US State Privacy Legislation Tracker, 2025
"There are over 11,000 solutions in the martech landscape now. The complexity isn't the number of tools; it's the number of data flows between them that nobody's mapped."
2. Technical analysis
To understand why conversational AI advertising creates a distinct privacy challenge, it helps to examine what data flows through these systems and how that differs from conventional digital advertising.
The data surface area problem
In a traditional search ad interaction, the advertiser receives limited context: the search query, the user's approximate location, device type, and (if cookies are present) some browsing history. The data surface area is bounded.
In a conversational AI interaction, the data surface area is vastly larger. A user's conversation with ChatGPT may include their job title, their company name, their current business challenges, their budget parameters, their technical stack, and their personal preferences, all volunteered naturally in the course of asking questions. OpenAI's privacy policy (updated March 2025) states that it collects "the content you provide" in conversations, and that this content may be used for model improvement unless the user opts out.
When an ad is served inside that conversational context, the question becomes: what data informed the ad targeting? If the ad is contextually targeted based on the conversation's content, then the conversation itself becomes an implicit data collection mechanism for advertising purposes. Under GDPR Article 6, this requires a lawful basis. Under Article 7, if that basis is consent, the consent must be informed and specific.
No current conversational AI platform has a consent mechanism that meets this standard for advertising use cases. OpenAI's terms of service cover data processing for model operation. They do not clearly establish a separate consent framework for advertising data processing, which is a distinct purpose under GDPR.
The attribution black hole
For enterprise marketing operations teams, there is a second technical problem: attribution. Current marketing automation platforms track touchpoints through known mechanisms: email opens, link clicks, form submissions, web page visits captured via automated tracking, and CRM record updates. These touchpoints generate structured data that feeds into multi-touch attribution models.
Conversational AI ad interactions generate none of these standard signals. A user who sees a contextual ad inside ChatGPT and later visits a website has an attribution gap between the ad impression and the site visit. The conversation context that led to the ad is not available to the advertiser's marketing automation platform. There is no UTM parameter appended inside a chat response. There is no cookie handoff from OpenAI's environment to the advertiser's domain.
Scorpion's announcement mentions that campaigns can be managed through its existing platform, but it does not describe how impression data, engagement data, or conversion data from ChatGPT interactions will flow into advertisers' existing analytics stacks. For enterprise teams running campaign reporting across multiple channels, this creates a measurement vacuum.
The consent chain fracture
In enterprise B2B marketing, consent is typically managed through a chain: a prospect provides consent on a form, that consent status is recorded in the marketing automation platform, and downstream communications respect that consent status. This chain depends on identity resolution: the ability to connect a known contact record to their interactions across channels.
Conversational AI breaks this chain in two places. First, the user interacting with ChatGPT is typically anonymous from the advertiser's perspective. Second, even if the user eventually identifies themselves (by clicking through to a landing page and submitting a form), the pre-identification conversation data that informed the ad targeting is not accessible to the advertiser and cannot be retroactively covered by the form consent.
As we explored in our analysis of identity resolution under agentic AI, the collision between AI-mediated interactions and identity resolution creates privacy paradoxes that current MarTech architectures are not equipped to resolve.
3. Strategic implications
The Scorpion-ChatGPT partnership is a small deal in revenue terms. It targets local businesses, not enterprise accounts. But it establishes a pattern that will scale. Google is integrating ads into AI Overviews. Microsoft has been experimenting with ads in Bing Chat since 2023. Perplexity launched an advertising program in late 2024. Within 18 months, conversational AI advertising will be a standard line item in enterprise media plans.
This scaling will force three strategic reckonings for enterprise marketing operations.
Consent management must extend beyond owned properties
Most enterprise privacy compliance frameworks focus on owned digital properties: websites, landing pages, preference centers, and email programs. They assume the organization controls the environment where data collection occurs.
Conversational AI advertising moves data collection into environments the organization does not control. The advertiser cannot place a cookie consent banner inside ChatGPT. The advertiser cannot control what conversational data OpenAI uses for ad targeting. The advertiser cannot audit the data processing pipeline between a user's conversation and the ad impression.
This means enterprise privacy frameworks must evolve to include third-party AI environment risk assessments. Marketing operations teams need to evaluate not just their own data handling practices but the data handling practices of every AI platform where their ads appear.
First-party data strategies become even more critical
The Simply Fish case study from Demand Gen Report (article 2 in the news set) illustrates a parallel point from a different angle. Simply Fish grew sales 25% over 18 months by shifting from discount-driven promotions to first-party data collection through QR codes, digital menus, and loyalty programs. The restaurant built a unified customer view from data collected on its own properties, under its own consent framework.
Enterprise B2B teams face the same strategic imperative at larger scale. As advertising channels fragment into conversational AI environments where data control is limited, the value of first-party data collected through owned channels with clear consent increases. Form capture strategy and data enrichment workflows that operate within controlled consent frameworks become the backbone of a privacy-compliant personalization strategy.
Teams that have not invested in data quality and first-party data infrastructure will find themselves increasingly dependent on opaque AI platform data, with growing regulatory exposure.
Intent signals need consent metadata
Enterprise marketing teams are investing heavily in intent data: signals derived from a prospect's research behavior that indicate purchase readiness. Conversational AI generates intent signals of extraordinary richness. A prospect asking ChatGPT "What marketing automation platform handles complex multi-division consent requirements best?" is expressing intent that would take dozens of web page visits to infer from traditional behavioral tracking.
But harvesting that intent signal for advertising purposes without explicit consent is precisely the kind of processing that regulators are likely to scrutinize. As we argued in our analysis of intent modeling and consent architecture, intent data without a corresponding consent framework is a liability, not an asset.
Enterprise marketing operations teams need to build intent signal taxonomies that include consent metadata: not just "this contact showed intent" but "this contact showed intent through a channel with this consent status and this data processing basis."
"Privacy is not a feature. It's a prerequisite. Any system that processes personal data for advertising must have consent baked into its architecture, not bolted on after launch."
4. Practical application
Enterprise marketing operations leaders can take concrete steps now to prepare for conversational AI advertising's consent challenges.
Audit your current consent architecture for channel gaps
Map every channel where your organization currently runs advertising or collects data. For each channel, document: what consent mechanism exists, what data is collected, what lawful basis applies, and whether your organization controls the consent mechanism or depends on a third party.
Most organizations will find that their privacy assessment covers owned properties comprehensively but has thin or nonexistent coverage for third-party AI environments. This gap needs a remediation plan before conversational AI ad spend scales.
Build a conversational AI channel policy
Before running any ads in ChatGPT, Bing Chat, Perplexity, or similar platforms, establish a written policy that addresses: what data the platform may use for targeting, what data flows back to your organization, how that data integrates with your marketing automation platform's consent records, and what disclosures you need to make in your own privacy policy.
This policy should be reviewed by legal counsel with specific AI and data privacy expertise. General marketing counsel may not have sufficient familiarity with the data flows inside large language model platforms.
Implement consent-aware attribution
Current multi-touch attribution models do not account for consent status at the touchpoint level. A website visit from a cookied user and a website visit from a ChatGPT ad click-through are treated identically in most attribution models, despite having fundamentally different consent profiles.
Work with your data services team to add consent metadata to your attribution data model. Each touchpoint record should include fields for: consent basis (explicit consent, legitimate interest, contract necessity), consent source (first-party form, third-party platform terms, no consent mechanism), and data controller identity (your organization, the AI platform, shared).
This metadata will become essential for regulatory reporting as conversational AI advertising scales.
Strengthen your first-party data collection
Every interaction you can move from an uncontrolled AI environment to your own double opt-in consent framework reduces your regulatory exposure. Invest in making your owned digital properties, your email programs through newsletter management, your events through events and webinars, and your direct engagement channels as compelling as possible.
The goal is not to avoid conversational AI advertising entirely. It is to ensure that your highest-value prospect interactions happen in environments where you control the consent framework.
Evaluate platform readiness
If your marketing automation platform cannot store and act on consent metadata at the touchpoint level, that is a gap that needs closing. A platform maturity assessment should now include evaluation criteria for consent-granular data handling. Can your platform enforce different communication rules for contacts acquired through different consent mechanisms? Can it suppress contacts whose only touchpoints lack verified consent? If not, you have compliance exposure that grows with every new AI advertising channel.
5. Future scenarios
Over the next 18 to 24 months, three developments will likely shape the intersection of conversational AI advertising and data privacy.
Regulatory attention will sharpen
The European Data Protection Board (EDPB) issued guidelines on AI and GDPR in late 2024, but those guidelines focused primarily on AI model training, not on AI-mediated advertising. As conversational AI ad products from OpenAI, Google, Microsoft, and others reach scale, regulators will turn their attention to the advertising use case specifically.
Expect at least one major European DPA to issue enforcement guidance on conversational AI advertising consent requirements by mid-2026. Organizations that have proactively built consent architectures for this channel will have a 12-to-18-month compliance advantage over those that wait for enforcement actions.
Platform-level consent standards will emerge (slowly)
OpenAI, Google, and Microsoft will eventually build standardized consent signaling mechanisms for their AI advertising products, similar to the IAB's Transparency and Consent Framework (TCF) for programmatic advertising. But TCF took years to develop and remains imperfectly implemented. A conversational AI equivalent will take at least as long.
In the interim, enterprise marketing operations teams must build their own consent frameworks rather than waiting for platform-level standards. The organizations that define internal policies now will influence the platform standards that emerge later.
Conversational AI will generate new categories of personal data
Conversational AI interactions generate data categories that do not fit neatly into existing data classification schemes. A user's conversational context, their question patterns, their expressed preferences within a dialogue, these are neither traditional behavioral data (page views, clicks) nor traditional declared data (form submissions). They occupy a new category that regulators, platforms, and enterprise data governance teams will need to define.
As we discussed in our analysis of enterprise AI trust layers, AI systems need a trust architecture before they need a productivity architecture. The same principle applies to AI advertising: trust infrastructure (consent, transparency, data governance) must precede performance optimization.
Enterprise teams that build their data management frameworks with this new data category in mind will be better positioned than those that try to retrofit existing classification schemes.
6. Takeaways
-
Scorpion's ChatGPT advertising partnership is a small deal that signals a large structural shift. Conversational AI advertising places ads inside interactions users perceive as private, creating consent challenges that current MarTech architectures do not address.
-
The data surface area of conversational AI is far larger than traditional digital advertising. Users volunteer detailed personal and business information in conversations, and current consent frameworks do not cover the use of that data for ad targeting.
-
Attribution models break when applied to conversational AI channels. No standard mechanism exists to pass touchpoint data from an AI conversation to an enterprise marketing automation platform.
-
Enterprise privacy frameworks must extend beyond owned digital properties to include risk assessments for third-party AI environments where ads appear.
-
First-party data collected through owned channels with explicit consent becomes more valuable, not less, as advertising fragments into uncontrolled AI environments.
-
Consent metadata should be added to attribution data models now, before conversational AI ad spend scales. Each touchpoint needs fields for consent basis, consent source, and data controller identity.
-
Regulatory enforcement specific to conversational AI advertising is likely within 18 months. Organizations that build consent architectures proactively will have a material compliance advantage.
-
Platform-level consent standards for AI advertising will emerge, but slowly. Enterprise teams should define internal policies now rather than waiting for industry frameworks.


