As of June 2026, UK businesses and consumers using ChatGPT are seeing something new: advertisements. OpenAI confirmed the UK as the first European market to receive its ChatGPT Ads pilot — and with it, a significant shift in how your conversations with the AI tool are being used. For IT experts and data protection consultants, the rollout raises immediate questions about what this means for workplace data security, UK GDPR compliance, and the hidden costs of "free" AI tools.
The News: ChatGPT Begins Serving Ads to UK Users
On 6 June 2026, OpenAI VP of Monetisation Benji Shomair confirmed the UK launch of ChatGPT's advertising pilot, making the UK the fifth territory globally and the first in Europe to receive ads within the ChatGPT interface. The rollout is currently a managed pilot: businesses wishing to advertise must register directly with OpenAI's ad team rather than using a self-serve platform.
The timing is notable. OpenAI simultaneously updated its EU/UK ad privacy policy on 2 June 2026, introducing a requirement for explicit user consent before serving personalised ads — a direct response to UK GDPR's "legitimate interest" restrictions. Users who opt in to personalised advertising can be served ads based on their past conversations, ChatGPT's memory feature, and prior ad interactions. Users who decline will see only contextual ads tied to the current session, approximate location, and time of day.
That distinction — opt-in versus opt-out — is precisely where IT specialists are urging UK businesses to pay close attention.
Expert Analysis: What ChatGPT's Ad Consent Actually Means for Your Data
The ad policy update is not just a privacy notice tweak. It reveals the depth of data ChatGPT has been accumulating across user sessions — and how that data is now being used commercially.
"The problem most businesses don't realise," says the kind of IT consultant ExpertZoom connects clients with, "is that their employees are already opted in by default to ChatGPT's memory and conversation logging features. The ad rollout is simply the moment that data starts generating revenue for OpenAI — and where businesses lose control of the narrative."
There are three layers to the concern:
Data training on the free tier. ChatGPT's free plan still uses conversation inputs to train OpenAI's models. This is not new, but the ad rollout has put it back under a spotlight. Under UK GDPR, using a tool that processes personal data in this way requires a lawful basis — and "we're using a free tool" is not one. Businesses that allow staff to input client names, project details, or correspondence into free-tier ChatGPT are potentially in breach, particularly if no data processing agreement (DPA) is in place.
Memory and context persistence. The memory feature, which allows ChatGPT to recall information from previous sessions, is now a building block for ad targeting. If a user's ChatGPT account remembers that they work in healthcare, manage a property portfolio, or are dealing with a legal dispute — that context can, under opt-in consent, shape which ads they see. For corporate accounts, this memory persists across employees using a shared login.
No DPA on free or Plus plans. OpenAI provides a data processing agreement only to Team plan subscribers (£20 per user per month) and Enterprise clients. Without a DPA, businesses using free or Plus-tier ChatGPT have no contractual guarantee about how data is stored, where it is processed geographically, or when it is deleted.
According to the ICO's 2026 guidance on AI tools, organisations must conduct a Data Protection Impact Assessment (DPIA) before deploying any AI tool that processes personal data at scale. In February 2026, the ICO fined MediaLab.AI £247,590 specifically for failing to conduct a DPIA before processing children's data — a signal that enforcement is no longer theoretical.
For UK businesses using ChatGPT in any client-facing or data-rich context, the ad rollout is a forcing function: configure your setup correctly, or risk becoming an enforcement headline.
When a Chatbot Becomes a Compliance Problem: A Concrete Case
Take the example of a five-person UK property management firm that started using the free tier of ChatGPT in early 2025 to draft tenant communications, summarise tenancy agreement clauses, and answer staff queries about leasehold regulations.
By July 2026, three staff members have active ChatGPT accounts with memory enabled. Over 18 months of use, those accounts have accumulated conversation history referencing tenant names, property addresses, rental arrears figures, and details from ongoing disputes. Under ChatGPT's ad policy, those users — if they previously clicked through a consent dialogue without reading it — may now be opted in to personalised ad targeting based on that conversation history.
Here is the if/then logic that applies directly to this scenario:
- If the firm's staff are using free-tier ChatGPT (no DPA in place) and memory is enabled and they have not verified their consent settings since June 2026, then tenant personal data is being processed by OpenAI without a valid legal basis under UK GDPR — potentially triggering a breach report obligation under Article 33 of UK GDPR within 72 hours of the firm becoming aware.
- If the firm upgrades to OpenAI's Team plan at £20 per user per month (£100/month for five users), deploys a DPA, disables memory for all accounts, and trains staff on acceptable input rules, then it falls within a compliant configuration — with a clear audit trail should the ICO ask.
The cost of compliance: £100 per month and a half-day of IT setup. The cost of a notifiable breach: ICO investigation, potential fine up to 4% of annual turnover, and reputational damage with tenants. For a firm processing hundreds of tenancy records, the maths are straightforward.
An IT consultant on ExpertZoom can audit your team's current ChatGPT configuration, check consent status across accounts, and build a remediation plan — typically within a single two-hour session.
What UK Businesses Should Do Now
IT specialists advising UK clients post-ad-rollout are recommending a four-step immediate response:
1. Audit active accounts. Identify every employee using ChatGPT in any form — free, Plus, or Team. List which accounts have memory enabled and which consent settings are active. This can be done via OpenAI's account settings under Data Controls.
2. Check your tier and DPA status. If any business-related processing is happening on free or Plus tiers, move to Team or Enterprise, or stop using those accounts for anything involving personal data. A DPA must be in place before any client or employee data is processed.
3. Update your DPIA. If your organisation already has a DPIA covering AI tools, it needs to be reviewed in light of the ad rollout and the June 2026 policy update. If you have no DPIA, creating one is now urgent, not optional. The ICO's DPIA template is available on ico.org.uk.
4. Set an acceptable use policy for AI tools. Staff need clear written guidance on what categories of data can and cannot be entered into any AI tool. Client names, case references, financial figures, and personal details should be off-limits on any non-Enterprise plan.
For businesses that have already integrated ChatGPT deeply into their workflows — using it for internal knowledge bases, automated email drafting, or customer service responses — an IT consultant can assess integration-level risks and recommend whether a switch to an on-premise or privacy-preserving alternative is appropriate.
The arrival of ChatGPT ads in the UK is not just a product update: it is the moment the "free AI tool" model was revealed for what it is. Your conversations have always had commercial value — now that value is being monetised visibly. For UK businesses, the question is no longer whether to think about AI data governance, but how quickly they can act.
For practical guidance on auditing your business's AI tool use and ensuring UK GDPR compliance, an IT consultant on ExpertZoom can review your current setup and recommend specific steps — from account configuration to staff training.
Disclaimer: This article provides general information only and does not constitute legal or data protection advice. Businesses with specific compliance concerns should consult a qualified IT consultant or data protection officer.

Rhys Morgan