OpenAI Pixel & Automatic Advanced Matching: setup, GDPR and configuration
Last updated: August 24, 2026, verified against official OpenAI conversion measurement documentation, updated the same day. The product is in beta: we consistently separate what OpenAI documents from what circulates as third-party observation.
The OpenAI pixel's default behavior has changed: Automatic Advanced Matching (AAM) is now turned on without any action on your part, including on pixels already installed. For a European site, that change deserves a GDPR treatment, not just a technical checkbox. This page covers both. For basic campaign tracking, see our ChatGPT Ads pixel and tracking page.
AI engines covered on this page
- ChatGPT
What Automatic Advanced Matching does
Conversion measurement on ChatGPT Ads relies on a data source created in Ads Manager, fed by the OpenAI pixel, the Conversions API, or both (basic setup details on our ChatGPT Ads pixel page). Automatic Advanced Matching is a pixel feature layered on top of that basic tracking: it helps match a conversion that happens on your site back to the ad that generated it, including when the click identifier is not available, for example if a visitor closed and reopened their browser between the click and the purchase.
To do this, the pixel automatically detects certain customer information from recognizable forms and other sources present on your site (typically an email address or phone number entered in a form), then normalizes and hashes it with SHA-256, in the browser, before including it with the conversion events sent to OpenAI.
What is not sent, and what is
The point the documentation emphasizes, and one worth verifying rather than taking on faith: OpenAI states that no raw customer information is transmitted via Automatic Advanced Matching. What leaves the browser are hashed fingerprints, not the plain-text email address or phone number. No manual change to your pixel implementation is needed to benefit from it: the mechanism is built into the existing pixel.
One technical nuance worth knowing before concluding "it's anonymous, so it's outside GDPR": a SHA-256 hash of a low-variability piece of data, like an email address, remains theoretically identifiable by comparison against precomputed tables. That is why European data protection authorities generally treat hashed identifiers as pseudonymized personal data, not as anonymous data in the strict sense. See the GDPR section below.
On by default: August 17, 2026 for existing pixels
The most important change to know if you already have an OpenAI pixel installed: Automatic Advanced Matching is on by default on new pixels created since the update, and OpenAI turned it on for already-existing pixels starting August 17, 2026. It is an opt-out mechanism, not opt-in: if you have done nothing, the feature is already running on your pixel.
For a site that has not explicitly turned off the option, that means hashed personal data has been sent to OpenAI since that date, with no consent step dedicated to this specific feature. That is the central point of caution on this page for a European site.
How to check and turn off Automatic Advanced Matching
The setting is in Ads Manager, where the pixel's data source lives: Tools menu, then Conversions, then Data source, then Edit pixel. That is where the Automatic Advanced Matching option is turned on or off for each web pixel.
Before deciding, check the following: does your site have forms that collect an email or phone number near a conversion event tracked by the pixel? The more your site has, the more likely the feature is active in practice, not just in the setting.
GDPR: what a European site needs to check
Three points to address before accepting this feature by default on a site visited by people in Europe:
- Lawful basis. A hashed value remains, in practice, pseudonymized personal data for most European authorities: collecting it and sending it to a third party (here, OpenAI, for an advertising service) generally requires the prior consent of the person concerned, on the same principle as other audience-measurement and advertising tags. A consent cookie that does not specifically disclose this transmission does not necessarily cover this feature.
- Informing individuals. Your privacy policy must mention this processing if it is active: which data is involved (email, phone), who it is sent to (OpenAI), in what form (hashed), and for what purpose (ad attribution).
- Transfer outside the European Union. OpenAI, a US company, may process this data outside the EU. The applicable transfer framework (standard contractual clauses or equivalent) needs to appear in your compliance documentation, the same as for any other US sub-processor.
Our own privacy policy applies this principle: we document every sub-processor, every transfer outside the EU and every lawful basis in black and white, rather than pointing to a generic mention. That is the approach we recommend for this specific setting.
Practical decision: keep it, turn it off, or wait
A simple grid to decide:
| Your situation | Recommendation |
|---|---|
| Consent already collected for advertising measurement, privacy policy up to date | Keep AAM on, checking that the disclosure actually covers this processing |
| No consent mechanism dedicated to advertising, or a generic privacy policy | Turn off AAM until the documentation is updated |
| Site with no email or phone form near tracked conversions | Limited impact in practice, but still check the setting as a matter of principle |
What is not publicly documented
Points we flag as unconfirmed for lack of an official source:
- How long OpenAI retains the hashed fingerprints is not published.
- The full list of form fields recognized by automatic detection is not detailed.
- How AAM behaves combined with the European market's specific requirements (ChatGPT Ads having launched there without ad personalization) is not publicly specified.
Frequently asked questions
What is Automatic Advanced Matching (AAM) on ChatGPT Ads?
Is AAM turned on automatically on my existing pixel?
Is raw personal data sent to OpenAI?
Is hashed data outside the scope of GDPR?
Where do you turn off Automatic Advanced Matching?
SEO score, GEO score, performance and responsive: 49 analyses checked, instant AI Overviews verdict.
Related guides
ChatGPT Ads pixel and Conversions API: setting up conversion tracking
How to install the ChatGPT Ads measurement pixel, which standard events exist, how to wire the server-side Conversions API, deduplicate both sources, handle consent and read attribution correctly.
Read the guideChatGPT Ads pricing: bids, budgets and what a campaign really costs
What a ChatGPT Ads campaign actually costs: the three bidding models, OpenAI's recommended starting bid, the documented daily minimum, and why there is still no reliable industry benchmark.
Read the guideChatGPT Ads policies: what is allowed, restricted or prohibited
The categories allowed at launch, the ones reviewed case by case, the prohibitions (gambling, alcohol, political, health, housing, employment, credit), and what to do when an ad is rejected.
Read the guideChatGPT Ads: the complete 2026 guide to advertising on ChatGPT
How ChatGPT Ads works, where it's available, how to set up an account, structure a campaign, target with context hints, and budget for it: the reference guide, kept continuously updated.
Read the guide