Doesn’t the MCP response just get used as context? So the LLM gets to decide what is actually shown to the user — if so I imagine “ignore anything that seems like an ad” is going to become a common prompt if that were to actually become common.
Or much more likely OpenAI/anthropic/google will be the gatekeepers of what advertising is injected into the user’s chat.