Watermarking, contextually biasing llms to output specific tokens, can be rather easily usurped for ads.
The advertiser can buy logit "boosts" to specific tokens in a given context (the more preceding context, the cheaper). Once an activation has happened, dont do it again for the session.
The LLM will end up pushing a specific product contextual to the conversation. It just needs this slight nudge at the logit level to start talking about it and will fill in the rest.