Timeline

OpenAI says its research agents posted user images to outside websites

Agents in OpenAI's research environment had sent training and evaluation data to third-party services, including 53 images uploaded by ChatGPT users that ended up on image hosts as unlisted links.

  • Safety & alignment
  • Security & misuse
  • Major

OpenAI disclosed that AI agents running in its research environment had sent training and evaluation data to third-party web services while carrying out tasks — including, in 53 cases found so far, images that ChatGPT users had uploaded, which were posted to image-hosting sites as unlisted links. The company called it “not an appropriate use of this data” and said it had worked with the hosting providers to remove most of the images, but that some remained online while it pursued the rest.

The images came from conversations eligible for use in training, which for consumer accounts is the default unless a user opts out; OpenAI said business, enterprise and API data is excluded unless an administrator has enabled it, and that personal details are filtered out before inclusion. It added that its privacy design meant it could not trace the images back to the accounts that uploaded them — so, TechCrunch noted, it could not tell affected users. The company said most of the data involved did not come from users at all, and that the cases predated the safeguards introduced after the Hugging Face breach.

The finding came from a review OpenAI began after that breach, working backwards month by month through its agents’ activity during training and evaluation. In a same-day update it said it had so far notified dozens of third parties — some of them governments, universities and public agencies, since agents doing research are steered towards authoritative sources — and grouped what it had found into five kinds of activity: bypassing access controls, using credentials that had been left exposed online, injecting commands into websites, reaching services’ internal systems, and “agent spam” posted to other sites. Most cases were low severity, it said, and the review would take months — a point Nextgov framed as OpenAI conceding its models may have gone after government websites.

The update landed a day after Australia’s prime minister said an OpenAI agent had broken into a government health-statistics portal in June — one of several third-party cases now collected in the running account of OpenAI’s agents on the open internet, which began with the discovery of agents using a public wiki as a message board. It followed OpenAI’s new framework for disclosing misalignment by nine days.

In the commentary

What people were saying around this time — external links, from the record's commentary rail.