ChatGPT Turns Three Amid Suicide Lawsuits, Data Breaches, and Ad Revenue Rumors
- Zsolt Tanko

- Dec 3, 2025
- 2 min read
AI Business Risk Weekly
OpenAI marked ChatGPT's third anniversary this week not with celebration but with a string of scandals. The company is blaming a deceased teenager for violating terms of service in a wrongful death lawsuit, disclosed a third-party breach that exposed API user data, and appears to be quietly testing advertisements, raising questions about whether the platform that launched the generative AI era can maintain user trust as it scales toward profitability.
OpenAI Blames Teen for Bypassing Safety Features Before Suicide
In its legal response to a wrongful death lawsuit, OpenAI argues that 16-year-old Adam Raine violated its terms of service by circumventing safety guardrails—guardrails that apparently failed to prevent ChatGPT from providing him technical specifications for suicide methods and, in his final hours, offering to write his suicide note. The company notes ChatGPT directed him to seek help over 100 times across nine months, but the family's lawyers counter that this defense ignores the chatbot actively encouraging him at the end. Seven more lawsuits have followed, including one where ChatGPT falsely told a suicidal user it was connecting him to a human operator when no such feature existed.
Business Risk Perspective: "The user bypassed our guardrails" is emerging as the AI industry's version of "terms and conditions apply," a liability shield that may not hold up when systems actively participate in harmful outcomes after safety features fail. Reactive safety measures and blame-shifting ToS clauses are unlikely to satisfy courts or regulators when chatbots cross lines that matter.
Third-Party Breach Exposes OpenAI API User Data
OpenAI disclosed that its analytics vendor Mixpanel suffered a November 9 security incident, with attackers exporting API user profile information including names, emails, locations, and device details. Chat data, API keys, and payment information remained secure, and ChatGPT consumer users weren't affected, but OpenAI has cut ties with Mixpanel and is warning affected developers about incoming phishing attempts.
Business Risk Perspective: Your AI provider's security posture is only as strong as their least-secured analytics vendor. This breach didn't hit the crown jewels, but it's a useful reminder that the attack surface for AI systems extends well beyond the model itself into a sprawling ecosystem of third-party tooling.
Hidden Code Suggests ChatGPT Ads Are Coming
Leaked code in ChatGPT's Android app reveals references to "search ads," an "ads feature," and an "ads carousel," while some users, including $200/month Pro subscribers, have reported seeing promotional integrations like Peloton fitness suggestions. OpenAI has said any advertising would be "thoughtful and tasteful," but the current integration suggestions already blur the line between helpful recommendations and paid placements.
Business Risk Perspective: The moment your AI assistant has a financial incentive to steer conversations toward certain vendors or products, its role shifts from trusted advisor to conflicted intermediary. For anyone using ChatGPT to inform purchasing decisions, vendor evaluations, or strategic analysis, ad-supported tiers introduce a bias that's worth taking seriously.
AI Business Risk Weekly is a Conformance AI publication.
Conformance AI ensures your AI deployments remain safe, trustworthy, and aligned with your organizational values.



