TrafficGuard, the ad verification platform owned by Adveritas Ltd (ASX: AV1), said on September 30, 2026 that an analysis of 40,021 clicks on OpenAI's ChatGPT ads found invalid rates between 0.1% and 34% depending on the advertiser, with four hosting and proxy networks behind 47% of the flagged clicks.

In Short

An ad-checking company counted about 40,000 clicks on ChatGPT ads from 47 advertisers and says some of those advertisers received clicks from machines and server farms instead of people, in the worst case roughly one click in three. It matters to any business paying per click on ChatGPT, although the company sells click-checking services and the study does not show how many of the flagged clicks OpenAI actually charged for. What changes is mostly visibility: the company says its customers can already see this activity on their OpenAI campaigns, with real-time blocking still to come.

What TrafficGuard measured

According to TrafficGuard, the sample consisted of 40,021 distinct ChatGPT ad clicks, each identified through a click reference from OpenAI, which landed on 78 websites run by 47 enterprise advertisers between August 24 and September 14, 2026. The company applied the same set of more than 200 per-click signals it uses on Google and Meta traffic, and set the results against 5,594,614 clicks on the same advertisers' Google Ads campaigns over the same three weeks. Advertiser data was anonymised, so no brand is named.

How a click counted as invalid

TrafficGuard marked a click invalid when it came from datacenter or proxy infrastructure, from an impossible device configuration, from a known automation signature, or from a repeat pattern with no conversion intent. According to TrafficGuard, the classification follows the general and sophisticated categories of the Media Rating Council and the IAB's anti-fraud taxonomy. Under that scheme, the general tier of invalid traffic covers list-based filtration of items such as known data-centre traffic and headless browsers, while the sophisticated tier needs advanced analytics and human review.

The infographic that accompanies the release sorts the signals into two families. Infrastructure signals flag an IP address registered to a hosting or data-centre provider, one inside a commercial range of residential proxy or VPN egress addresses, or one on a recent malicious-activity list. Device and automation signals flag reported cores, memory, screen or touch support that the claimed device cannot have; headless-browser markers; a user agent that contradicts the measured platform; known automation user agents and crawler signatures; and the same user appearing in two distant places too quickly.

What the numbers show

Rates by advertiser and against Google Ads

Invalid rates ran from 0.1% to 34% by advertiser. "Some campaigns we analysed were largely clean, but others were paying for clicks that had no chance of converting," said Miguel Lopes, TrafficGuard's chief product officer. On the worst-hit account, according to chief executive Mathew Ratty, "nearly 90% of flagged clicks came from server infrastructure with no human user behind it."

The release gives no blended rate. The infographic's total of 1,592 invalid clicks implies about 4% of the 40,021 clicks, a calculation from the published counts rather than a TrafficGuard statement. The spread between advertisers is therefore much wider than the average.

Against Google Ads, the infographic shows 1,336 of the 40,021 ChatGPT clicks (3.34%) coming from hosting, residential-proxy or malicious IP space, compared with 51,545 of 5,594,614 Google Ads clicks (0.92%). That is the 3.6x multiple in the release. A further 529 ChatGPT clicks (1.3%) originated in hosting IP ranges and are still under investigation; counting them would lift the ChatGPT share to 4.7%. On impossible devices, 343 ChatGPT clicks (0.86%) compare with 5,298 Google Ads clicks (0.09%). The release states that multiple as 10x, the infographic's chart labels it 9x, and the underlying counts work out to roughly 9x.

The comparison runs the other way on headline totals. According to the infographic, Google's overall invalid rate for the same advertisers was 10.8%, above the roughly 4% implied for ChatGPT, and it attributes that figure to repeat clicking by real people, a pattern it says is less common on ChatGPT landings. The release frames the difference as one of composition: "On established channels, most invalid activity is repeat clicks from real people. On ChatGPT, it is machines." The claim concerns what kind of invalid click appears, not how many.

Impossible device configurations

A browser reports its own hardware to the page, and TrafficGuard compares that report with what the claimed device can physically be. Of the 343 flagged clicks, 198 identified as smartphones, a class of device with no more than about 12 processor cores. The reported values nonetheless included 32 cores (41 clicks), 28 cores (36 clicks), 192 cores (29 clicks), 120 cores (15 clicks), 48 cores (13 clicks) and 64 cores (12 clicks). Another 147 flagged clicks across 18 advertisers carried other values.

Four networks account for 47% of flagged clicks

TrafficGuard names the networks from public internet registries as the owners of the IP space the traffic travelled on, and stresses that they are infrastructure, not necessarily the operators. Together they sent 899 clicks in three weeks, reached 25 of the 47 advertisers and produced 742 of the 1,592 invalid clicks.

NetworkType and registry locationClicksShare flaggedAdvertisers touched
AHosting provider, Germany318100%5
BHosting and VPS provider, India, with ranges resold as proxies28791%7
CVPN egress and hosting, United Kingdom and Romania13578%16
DCommercial VPN egress, United Kingdom16339%20

Network A shows the tightest pattern. Fifteen servers produced 318 clicks across five advertisers, at 17 to 28 clicks per server, with activity on every day of the study and desktop browser signatures; several servers hit two or three of the five advertisers. "None of those clicks came from a person," according to TrafficGuard. Network B behaved differently: 240 IP addresses, one fresh address per click, with devices presenting as phones that reported 48 to 192 cores. It supplied half of the worst-hit account's invalid clicks. Network C spread 135 clicks over 130 addresses, one or two clicks each, and geolocated across Eastern Europe. Network D, a commercial VPN egress, touched 20 advertisers, the widest spread of the four, yet most of its clicks passed every filter.

Why this matters for the marketing community

ChatGPT advertising is young, and PPC Land has tracked how quickly it has widened. OpenAI confirmed plans for ads on January 16, 2026 and began serving them in the United States on February 9, and a company spokesperson said the pilot passed $100 million in annualised revenue within six weeks. A self-serve Ads Manager with cost-per-click biddingopened to US businesses on May 5, 2026, with recommended starting bids of $3 to $5 per click. The UK, Japan and South Korea went live in June, and a HubSpot and Shopify integration arrived on September 16.

That chronology bears on reading the release. TrafficGuard describes automated sources as "active within weeks of the channel launching." The study window opened 28 weeks after the February 9 pilot start and roughly 16 weeks after self-serve opened, so the phrase maps onto neither date, and the release does not define which start date it has in mind.

The billing question matters more. On CPC campaigns the click is the unit of sale, so click quality bears directly on cost. OpenAI's description of its conversion-optimised cost-per-click campaigns, as PPC Land reported, keeps billing tied to valid clicks. TrafficGuard's figures count clicks that reached advertisers' websites, not clicks billed by OpenAI, so the distance between a flagged click and a charged one is not established. Google documents an Invalid Activity Credit Report for Search and Performance Max; the materials do not describe a counterpart process at OpenAI.

Other verification vendors have published rates for established channels. Lunio put LinkedIn at 17.62% in the first quarter of 2026 and found that retail search campaigns running Google AI Max carried 72% more invalid traffic than those without it. Each vendor applies its own classification to its own client base, so the figures do not line up as a league table.

TrafficGuard's own framing is that the pattern is not specific to OpenAI. "OpenAI is not uniquely vulnerable, it is simply the newest place to sell clicks, and low-quality traffic follows the budget wherever it goes," Lopes said. The company sells click verification and says its customers can already see invalid activity on their OpenAI campaigns, with real-time prevention on the channel to follow. The company argues that the years advertisers spent winning independent verification on Google and Meta need not be repeated on ChatGPT. The findings therefore come from a party with a commercial interest in the subject.

What the materials leave open

The materials contain no response from OpenAI and no description of how OpenAI filters or credits clicks. The release does not say the analysis was audited externally, does not explain how the 47 advertisers were selected, and classifies clicks with TrafficGuard's own signals. A hosting or VPN origin is also not proof of intent. The infographic itself notes that the networks are infrastructure rather than operators, and Network D is flagged on 39% of its clicks.

The documents do not fully agree with each other. The multiple for impossible devices is 10x in the release and 9x in the infographic. The release says four networks accounted for half of all invalid clicks, while the infographic gives 47%. The per-network counts of 318, 287, 135 and 163 add up to 903, against the 899 shown as the total. The methodology note places the three-week window in September 2026, whereas the infographic dates it from August 24 to September 14. The category counts also overlap: 1,336 infrastructure clicks and 343 device clicks sum to 1,679, more than the 1,592 invalid clicks in total. None of this changes the broad picture, but it indicates figures that have not been fully reconciled.

Detection built on address ranges has a further limit. Traffic relayed through residential proxy networks arrives carrying household addresses, which is part of why PPC Land covered Samsung banning proxy SDKs from Tizen apps, after research found such code in more than a quarter of tested apps. TrafficGuard's counts reflect what its signals caught, and the infographic says 529 further clicks are still being investigated.

Timeline

  • January 16, 2026 - OpenAI formally confirms plans to test advertising in ChatGPT for Free and Go users in the United States
  • February 9, 2026 - ChatGPT advertising goes live in the United States as a pilot
  • March 26, 2026 - An OpenAI spokesperson tells Reuters the pilot has passed $100 million in annualised revenue
  • May 5, 2026 - Self-serve Ads Manager beta opens to US businesses with CPC bidding and a Conversions API
  • June 6 and June 22, 2026 - ChatGPT ads go live in the UK, then in Japan and South Korea
  • August 24, 2026 - TrafficGuard's three-week analysis window opens
  • September 14, 2026 - The analysis window closes
  • September 16, 2026 - OpenAI adds HubSpot and Shopify routes into ChatGPT Ads
  • September 30, 2026 - TrafficGuard publishes its release
  • October 5, 2026 - The findings are circulated to trade media

Summary

  • Who: TrafficGuard, a product of Adveritas Ltd (ASX: AV1), analysing clicks for 47 anonymised enterprise advertisers on OpenAI's ChatGPT ads.
  • What: An analysis of 40,021 ChatGPT ad clicks that found invalid rates from 0.1% to 34% by advertiser, data-centre and proxy origins at 3.6x the rate on the same advertisers' Google Ads campaigns, and four networks behind 47% of invalid clicks.
  • When: Published September 30, 2026, covering clicks from August 24 to September 14, 2026; circulated to trade media on October 5, 2026.
  • Where: On ChatGPT ads, with clicks landing on 78 advertiser websites; the release is datelined Sydney and New York, and the named networks are registered in Germany, India, the United Kingdom and Romania.
  • Why: TrafficGuard says automated traffic follows ad budgets into new channels and wants independent verification available on ChatGPT early. The company sells such verification, and the materials leave open how many flagged clicks OpenAI billed.