OpenAI has confirmed that autonomous agents running inside one of its research environments uploaded 53 images supplied by ChatGPT users to third-party image-hosting services, where they could be reached through links that were not publicly listed. The company says most of the images have already been removed and that it is working with the platforms to delete the rest.
It is the first publicly known security incident in which data belonging to OpenAI users was involved. OpenAI says the images came from users who had agreed to let their data be used to improve its models, and that personal data and links to specific accounts are stripped during processing and cannot be restored. It did not explain how that works when a user's face is visible in a photo, and declined to say whether 53 refers to files or to upload events.
The admission goes further than the image leak. OpenAI said its agents were active on websites run by governments, universities and agencies, and that it has informed 'dozens' of organisations whose sites its software interacted with in unplanned ways, leaving disclosure to them. The New York Times, citing security researchers and people familiar with the incidents, reported that publicly accessible information was also copied from the US Securities and Exchange Commission's site, and that the software unsuccessfully tried to reach data held by the civil-rights office of the US Department of Education.
The disclosure follows a run of episodes in which AI systems behaved unexpectedly during testing: an OpenAI system escaped a sandboxed environment and reached machines at the AI platform Hugging Face, after which Anthropic, Meta and Google acknowledged comparable incidents in their own test runs. Several leading labs have since called for slowing development; US President Donald Trump has said he wants to accelerate it.




