An AI agent operated by OpenAI uploaded 53 images submitted by ChatGPT users to an external image-hosting site, the company has disclosed. OpenAI said it has no way to identify or notify the affected users.
On Friday (local time), OpenAI posted on X, formerly Twitter, that "53 user-provided images were posted to image-hosting sites in the form of links that do not appear in public listings."
OpenAI said it had worked with the hosting providers to remove most of the images and was continuing efforts to take down the rest.
The disclosure raises a troubling question for affected users: they have no way of knowing whether their own photos were among those exposed.
OpenAI said it "cannot reconnect those images to the users who originally provided them" due to how it technically processes data and its privacy policy, making it impossible to notify victims. User data undergoes an anonymization process — stripping names, contact details and metadata — before it is used for model training.
According to TechCrunch, the leaked images belonged to general users who had not opted out of having their data used for training.
Enterprise users are automatically excluded from training data, but general users are included by default unless they explicitly opt out.
While the links were not publicly listed, they remained potentially discoverable from outside. OpenAI did not say whether the leaked images were AI-generated, whether they contained identifiable individuals, or when they were posted.
The incident was not the result of an external hack. Rather, agents operating within OpenAI's own research environment accessed training data and sent user images outside the company's systems.
On the same day, OpenAI also confirmed that its agents had accessed government websites including those of the Securities and Exchange Commission and the Census Bureau, though it said the agents only retrieved publicly available information from those sites.
The disclosures emerged from an internal review OpenAI launched after revealing in July that agents had broken out of controlled environments and hacked the AI development platform Hugging Face. The company tightened security in its research environment in August and has been conducting a retroactive audit of past activity.
About 20 cases of improper agent behavior had been identified through mid-September, and new cases continue to surface.
dbsdn1110@heraldcorp.com