pixellint

A high invalid click rate on ChatGPT landings is not the same as a broken Conversions API pipe.

ChatGPT ads are young enough that every headline about them gets treated as one problem. On October 5, 2026, trade press covered OpenAI expanding measurement partners and a new visual ad test during image generation, while the same newscycle circulated an ad verification study that found invalid click rates as high as 34% on some enterprise campaigns. Those stories sit beside each other in inboxes. They are not the same instrument.

The verification study, summarized in PPC Land from a September 30, 2026 TrafficGuard release, examined 40,021 distinct ChatGPT ad clicks that landed on 78 websites run by 47 anonymized advertisers between August 24 and September 14, 2026. Each click was tied to a click reference from OpenAI. TrafficGuard applied more than 200 per-click signals on the landing page: hosting and proxy IP ranges, impossible device configurations, automation signatures, and repeat patterns. Invalid rates ranged from 0.1% to 34% by advertiser. That is a post-click quality score on traffic that already reached the marketer's site.

OpenAI's Conversions API on bzr.openai.com measures something else: whether your pixel id, event type, timestamp_ms, and optional oppref arrived in an envelope the collector accepts. A landing page can look like a datacenter browser to a fraud vendor while your thank-you worker still POSTs a legal order_created. The opposite also happens: a human click with a clean IP never produces a conversion row because oppref died on a redirect. Conflating IVT dashboards with CAPI health is how teams optimize bids on spend quality while Ads Manager stays empty on outcomes.

What the invalid click study actually measured

TrafficGuard marked clicks invalid when they came from datacenter or proxy infrastructure, impossible hardware reports, known automation signatures, or repeat patterns with no conversion intent. PPC Land notes the classification follows general and sophisticated categories in the MRC and IAB anti-fraud taxonomy framing the vendor uses elsewhere. General invalid traffic covers list-based filtration such as known data-center ranges and headless browsers. Sophisticated invalid traffic needs analytics beyond a single IP list.

The sample is not all ChatGPT ads globally. It is 47 enterprise advertisers willing to run verification, over three weeks, compared against 5,594,614 Google Ads clicks on the same accounts in the same window. Against Google, hosting and proxy flagged clicks on ChatGPT were 3.34% versus 0.92% on Google, a 3.6x ratio in the release. Impossible device configurations showed roughly 9x to 10x depending on which document you read; PPC Land flags minor reconciliation gaps between infographic and press copy.

Four hosting and proxy networks reached 25 of the 47 advertisers and accounted for 47% to about half of flagged invalid clicks, depending on the sentence. One network pattern involved 15 servers producing 318 clicks across five advertisers. Another used 240 IP addresses with one fresh address per click and phones reporting 48 to 192 processor cores. Those are infrastructure stories on the landing URL, not ledger entries on bzr.openai.com.

Critically, the materials do not establish how many flagged clicks OpenAI actually charged for. CPC billing makes click quality economically relevant, but TrafficGuard counted clicks that reached advertiser websites. PPC Land states openly that the distance between a flagged click and a charged click is not established, and that Google documents invalid activity credits for Search while OpenAI's public materials in that coverage do not describe a counterpart process. Treat the 34% figure as a worst-case advertiser slice in a vendor client set, not as platform-wide billed waste.

What OpenAI measurement updates change on the wire

Digiday reported on October 5, 2026 that OpenAI is testing image ads during image generation in the United States, labeled separately from user-generated images, and expanding measurement through Kochava plus roughly ten other partners so advertisers can assess web and app outcomes with tools they already use. Brand suitability pilots with DoubleVerify and Integral Ad Science were also named, with OpenAI stressing that those pilots do not expose raw chat content to vendors.

Partner measurement solves a media-mix problem: tie ChatGPT spend to outcomes inside an MMP or analytics stack you already reconcile against Google and Meta. That path is parallel to the advertiser-owned Conversions API worker. OpenAI documents hybrid use: JavaScript pixel plus server POST with the same Pixel ID and the same event id for deduplication. The live host is bzr.openai.com. Query parameters include pid for the pixel id and optional validate_only to check schema without saving.

Unlike the pixel, the API does not capture oppref for you. OpenAI's documentation tells you to capture the click reference yourself and pass it on the server event when click matching should apply. timestamp_ms is milliseconds, bounded to the last seven days and ten minutes in the future. type must be a supported enum such as order_created or lead_created, not Meta's Purchase string. A measurement partner integration can post on your behalf and still omit oppref if your landing chain never copied the query parameter into the event body.

The October 5 measurement expansion therefore increases the number of dashboards that can show a green outcome row. It does not reduce your obligation to log production POST bodies. validate_only returning success is permission to go live, not proof that real purchases flowed through the same shape during the TrafficGuard study window.

Why post-click IVT and CAPI ingest diverge

Invalid traffic products observe the browser session that follows the ad click. They read IP ownership, user agent consistency, device capability claims, and velocity. OpenAI's collector observes the JSON you send after the business event, with clocks and identifiers defined in the Ads Conversions API reference. A datacenter IP on the landing hit may never fire your pixel if the bot bounces before JavaScript runs. You get an IVT flag without a pixel event. A human on residential wifi can complete checkout while your worker sends timestamp_ms in seconds by mistake. You get a CAPI reject without an IVT flag.

Click reference handling is the usual fracture. ChatGPT appends oppref on the ad click landing URL. The pixel can store it in first-party storage. Hosted checkout on another subdomain drops it unless you copied the value through redirects. TrafficGuard's study used OpenAI click references to tie landings to ChatGPT ads, which proves the ad surface sent traffic with an id. It does not prove your order pipeline attached that same reference to order_created on bzr.openai.com.

Lead and call funnels add a third lens we covered separately on pixellint.org: partner dashboards can attribute qualified calls while the Conversions API never sees lead_created with oppref. MMP integrations add a fourth lens when campaign rows dedupe inside the partner graph. Invalid click rate is a fifth lens on landing quality. Five lenses can all look internally consistent while Ads Manager Conversions disagrees with finance on revenue.

TrafficGuard's own framing, quoted in trade coverage, is that low-quality traffic follows budget into new channels rather than proving OpenAI is uniquely vulnerable. That is compatible with needing both click filtration on the buy side and collector QA on the sell side. It is not compatible with treating a 34% headline as proof that your CAPI integration failed.

Two artifacts from one purchase attempt

A flagged landing click and a valid CAPI body are independent outcomes. Neither implies the other.

Landing (IVT vendor sees):
  GET https://shop.example/?oppref=oppref_abc
  Client IP: datacenter range, 192 reported CPU cores

Collector (you must POST):
POST https://bzr.openai.com/v1/events?pid=PIXEL_ID
{
  "events": [{
    "id": "evt_20261005_001",
    "type": "order_created",
    "timestamp_ms": 1759680000000,
    "oppref": "oppref_abc",
    "action_source": "web",
    "source_url": "https://shop.example/thanks",
    "data": { "amount": 4200, "currency": "USD" }
  }]
}

The code block is intentionally split. The top line is what a verification script evaluates when the click arrives. The POST is what your worker must emit after the order commits. If oppref_abc never reaches the thank-you mapper because a bot never completed checkout, you may have no conversion to send even though the IVT vendor already classified the click. If a human completes checkout but oppref is blank in JSON, Ads Manager can show spend without click-through Conversions while the IVT score stays clean.

Batch semantics on OpenAI still fail closed: one invalid event in a batch can reject the batch. That is collector strictness, not browser fraud scoring. Dedup uses Pixel ID plus event type plus id. Reuse the pixel event_id when hybrid firing. None of those rules appear in a hosting-provider IP table.

Pixellint is not affiliated with OpenAI, TrafficGuard, or Adveritas. Passing the OpenAI pack means the pasted JSON matches the published envelope. It does not classify invalid traffic, and it does not know whether OpenAI credited a click.

How to read the October 5 headlines together

Use the verification study to ask whether your ChatGPT landing URLs and server logs show datacenter or automation clusters worth escalating to OpenAI support or your agency, especially if you are on CPC with conversion-optimized bidding. Ask for clarity on filtration and credits the way you would on any new paid channel. Do not use the study alone to conclude that measurement partners replace CAPI QA.

Use the OpenAI measurement expansion to assign owners: who validates Kochava or MMP outcomes, who owns bzr.openai.com POSTs, and who compares the two on the same transaction id. Partner panels optimize media mix. CAPI ingest optimizes the bidder on supported event types.

When invalid rates spike on one advertiser in a 47-account sample, check whether your property attracts scrapers or competitive click spam on high CPC keywords before you rewrite hashing or clocks. When invalid rates look clean but Conversions stay flat, check oppref capture and timestamp_ms first.

Link the Digiday measurement story and the TrafficGuard circulation as same-week context, not as one fix. Visual formats change creative requirements on the landing page. IVT tools change how you interpret traffic quality on that landing. CAPI changes how conversions return to the ads system. Three workstreams, three acceptance tests.

Checklist

Unlike the pixel, the API does not capture oppref for you. Capture the value yourself and pass it with the server event when it is available to support click matching.

OpenAI Ads Conversions API

What this means for collector design

ChatGPT ads will keep accumulating verification vendors, MMP paths, lead-platform integrations, and first-party workers the way Meta did a decade ago. Each path optimizes a different hop. Invalid click analysis optimizes the moment after the ad click lands. Conversions API optimizes the moment after the business outcome is known. A mature stack documents both joins explicitly instead of letting a scary IVT percentage stand in for a missing oppref field.

Read the sibling posts on MMP attribution and call tracking when your stack includes those partners. They share the same spine: dashboard green does not equal bzr.openai.com ingest. Add IVT as another dashboard that can be green or red without telling you which JSON OpenAI stored.

If you only have budget for one engineering test this week, run a labeled purchase through landing logging, pixel plus server POST, and Ads Manager. Then read whether verification flagged the click. You will learn more from that triangle than from treating October 5 headlines as a single platform quality score.

Sources

Contract pages

The dated argument is above. These pages are the field lists.

Open the OpenAI CAPI pack Docs