A privacy analysis by IMDEA Networks found that tested AI chat services contacted advertising and tracking parties and exposed conversation fragments such as titles, prompts, screenshots or links, though not every provider shares complete chat histories. Professionals with sensitive information must therefore verify the actual dataflows per AI product, account type and setting before entering anything.
Researchers at IMDEA Networks published, on 22 September 2026, a systematic privacy analysis of nine prominent AI chat services, including ChatGPT, Gemini and Anthropic's Claude. Using static and dynamic analysis of web and mobile versions, the researchers reported that some tested services sent conversation-derived artifacts to external advertising and tracking services, often alongside persistent identifiers that could enable user attribution. The study also reported that, in some tested cases, providers publicly exposed conversation permalinks without access controls, allowing trackers to read the entire conversation.
The study is the occasion for this piece, but precision matters. The researchers report exposure of conversation fragments — titles, prompts, screenshots or links — in tested implementations. That is something other than the claim that every provider passes complete chat histories to unrelated advertisers. That broader claim is not supported by the evidence.
What exactly did the IMDEA study establish about AI chat services and third parties?
IMDEA Networks found that AI chat interfaces are in practice connected to a surrounding ecosystem of advertising and tracking infrastructure, and that derived conversation data can leak in the process. This concerns titles, prompts, screenshots and in some cases publicly accessible conversation links, plus identifiers with which behaviour can be linked to a user. The researchers describe observed dataflows, not every possible flow at every provider.
Important is what the study does not show: that every tested platform shares integral conversations with unrelated third parties. The finding is more specific and thereby more usable — it shows that the service label "AI assistant" says nothing about what actually goes out.
What do Google's and OpenAI's own policies confirm about third-party access?
The providers describe in their own documentation a different, equally relevant route: authorised access by staff, suppliers and reviewers. That is something other than tracking, but it does mean that conversation content can leave the direct user-provider relationship.
- Google states in the Gemini Apps Privacy Hub that a portion of Gemini conversations is reviewed by human reviewers, including trained reviewers from Google's service providers, for improvement and quality. This applies to a subset, not to all chats.
- OpenAI describes in the EU Privacy Policy that it collects user content such as prompts and uploads and may share personal data with suppliers and service providers for, among other things, hosting, security, support, analytics and payments. That is a processing relationship described by OpenAI and not proof that complete chat histories are routinely provided to unrelated advertisers.
- OpenAI states in the enterprise documentation that access to enterprise conversations is limited to authorised personnel and specialised contractors for abuse monitoring — an arrangement in which access to enterprise conversations is described as limited to authorised personnel and specialised contractors for specified purposes.
- According to the documentation on data controls in ChatGPT, the entire associated conversation can be used for model training as soon as a user submits feedback. User actions and settings thus change the processing.
Our analysis: the core of the story is the difference between these two worlds. The study reports observed tracking behaviour and third-party contacts that are not the same as the authorised processing that providers describe in their official documentation; the policies describe that authorised processing. Both routes exist alongside each other, and neither follows from the service label.
What does this news mean for directors, lawyers and CISOs who process sensitive information?
In our analysis, because the IMDEA study reports that conversation fragments can leak via tracking at tested services, every organisation that puts client files, patient data or trade secrets into a general AI chat runs the risk that derived data ends up with third parties; we therefore recommend that the CISO have outgoing connections and identifiers tested per AI product used, under the actual account settings rather than a demo account. Because Google confirms that a subset of Gemini chats is reviewed by service providers and OpenAI describes supplier sharing, human access is not a theoretical risk; we therefore recommend that the controller set out in a processing agreement which reviewers or contractors may see content and under what conditions, before sensitive work starts. Because ChatGPT can use the full conversation for training upon feedback, one click by an employee changes the processing of the whole conversation; we therefore recommend that the AI policy contain an explicit instruction about feedback buttons, history and training settings, enforced through technical configuration where possible. Because the same provider describes specific access controls for enterprise conversations, "we use ChatGPT" is in our view no meaningful risk statement; we therefore recommend that the lawyer, at every procurement, name the exact product tier, account type and contract rather than the brand name.
How do I check, per AI service, which data goes to third parties?
Do not trust the label, but map the actual dataflows. In our analysis, the following steps follow from the findings of IMDEA Networks and the provider policies.
- Inventory every AI product and account tier used in your organisation, including free and private accounts; see also making personal AI use at work visible.
- Map prompts, titles, screenshots, conversation links, feedback and metadata separately, because the study reports that it is precisely derived fragments that leak.
- Test the service under the relevant consent and account settings and inspect whether identifiers allow linking to a person.
- Verify whether suppliers, contractors or reviewers can view content, and record that — tie this to the GDPR requirements for generative AI in the workflow.
- Prohibit sensitive material where the provider does not give a sufficiently specific, verifiable description of the dataflow; why a service label is no proof of safety applies here in full.
Those who want to secure this structurally will find further elaboration in the topic hub on AI privacy and GDPR. The conclusion remains sober: in our view the news value does not lie in panic over "AI shares everything", but in the finding that AI chat interfaces can expose conversation data via tracking and via service-provider relationships — and that only verification per service, tier and setting reveals what actually happens in your case.
Sources and references
Sources: The article relies on the privacy analysis by IMDEA Networks and on the official privacy and data documentation of Google and OpenAI.