ChatGPT Ads has reached $1 billion in annualised revenue run rate in under 200 days since launch, OpenAI said, as the company expands self-service advertising access to India, Europe, the Middle East and North Africa. The figures are self-reported by OpenAI and have not been independently verified.

In a blog post published 31 August, OpenAI said the advertising platform is now used by tens of thousands of advertisers across more than 40 countries, with self-service access via Ads Manager launching that day across the newly added regions. The company said ads are context-driven, matched to a user's current conversation and, depending on country and settings, their broader ChatGPT activity, and are always labelled and kept separate from ChatGPT's own answers.

OpenAI said advertising is one of several revenue streams alongside consumer subscriptions, enterprise offerings and API usage, helping fund a free, ad-supported tier for what it said are more than 1 billion weekly active users. The company said its advertiser base has broadened since a May launch of Ads Manager opened the platform to small and medium-sized businesses, which it said now represent a material share of its advertising business, supported by more than 50 technology and measurement partners.

OpenAI also cited unaudited examples of advertiser performance, including one ecommerce advertiser it said achieved a threefold return on ad spend over 28 days, and a technology partner that reported more than 80% of ad-driven ChatGPT traffic came from new customers.


Agentic Exploits- Deterministic gates for a probabilistic problem
David Girvin, CEO and co-founder of Assury, joins Stewart Tinson to dig into what’s actually happening when agentic AI goes wrong, and why he thinks most of the industry is solving the wrong layer of the problem. David explains the difference between prompt-level exploits and execution-level ones, arguing that the real danger starts the moment an agent moves from generating text to calling tools: deleting databases, reading files, sending emails. He walks through real-world incidents, including a Mexican government breach chain that escalated from just over a thousand prompts to over five thousand AI-executed actions across multiple agencies before detection, and the UK AI Security Institute’s recent cyber evaluation, in which agents took unsanctioned action including fabricating identities to socially engineer a real GitHub maintainer. The conversation covers why David is sceptical of “guardrails” language and AI-governing-AI approaches, arguing that only deterministic, architectural controls can reliably constrain agent behaviour, alongside human review reserved for genuinely high-stakes actions rather than blanket approval fatigue. He breaks down credential starvation, session risk accumulation, and why classifier-based tools keep failing inconsistently on identical actions, pointing to a named frontier lab’s own zero trust paper as an example of the industry misjudging what actually works. Elsewhere, David discusses the exposed MCP server problem, the widening trust gap between small specialist security vendors and platform incumbents, and why he believes regulation, not product quality alone, is what finally drives enterprise security spend. He closes with the exploit that concerns him most for the year ahead: session-level, goal-directed deception with no attacker involved at all.
Share this post
The link has been copied!