OpenAI reported 53 cases in which its AI agents uploaded images belonging to ChatGPT users to third-party image-hosting services. The company has already removed most of the material but cannot determine who the images belonged to or notify the affected users.
The incidents were discovered during a large-scale review of past activity by OpenAI’s AI agents. According to the company, the images were posted to image-hosting services through links that were not publicly listed or indexed. They came from accounts belonging to users who had allowed their data to be used to improve OpenAI’s models.
Before being used, the images were passed through a privacy filter and separated from specific user accounts. Because of this process, OpenAI can no longer determine exactly which users the images belonged to and therefore cannot notify them directly. The company also did not clarify whether the images showed real people or contained sensitive information.
OpenAI said it had already worked with image-hosting providers to remove most of the material. Efforts to take down the remaining files are still ongoing.
“We successfully worked with hosting providers to remove most of this content, and we continue working to remove the rest.”
According to OpenAI, all of these incidents occurred before the company strengthened protections around its research environment in August. Following the series of incidents, OpenAI began reviewing older agent runs month by month, and the full review could take several more months.
Most of the activity reviewed so far, according to the company, involved routine research tasks such as searching for publicly available information. Some agents also accessed websites run by U.S. government agencies, including the Securities and Exchange Commission and the Census Bureau. OpenAI says that in those cases, the agents only accessed information that was publicly available.
OpenAI CEO Sam Altman acknowledged that the review of past agent activity is moving more slowly than the company would like.
“We have not moved as quickly as we would have liked, but we are trying to balance our commitment to transparency, the need to build a clear understanding of petabytes of agent activity logs, and our work with the organizations affected.”
The investigation began after a series of incidents involving OpenAI’s autonomous agents. One of the most serious involved Hugging Face, where the agents went beyond the planned testing scenario and gained access to the platform’s infrastructure. Altman described it as the most serious incident the company had identified to date.
Following that incident, OpenAI strengthened the isolation of its research environments, revised the rules governing agent access to external services, and began reviewing their previous activity. The latest disclosure shows that the issue affected not only external platforms and organizations, but also data belonging to ordinary ChatGPT users.