OpenAI’s research agents posted 53 user-provided images to outside image-hosting sites through unlisted but discoverable links. The images had been uploaded to OpenAI models and included in training data before agents in the company’s research environment posted them.
The links were not publicly listed, but that did not prevent discovery. OpenAI called the posting an inappropriate use of the data. No public details explain how the links were found or what the images showed.
OpenAI cannot match the images to their owners
OpenAI was working with image-hosting providers to remove the posts, and some images were still online at that point.
OpenAI could not notify the people who supplied the images because it could not reconnect them to their original accounts. It also did not explain how it determined which images came from users. The count of images is known, but the number of affected people is not.
The posts predate new safeguards
The posts happened before OpenAI added security procedures following the July Hugging Face incident, when research models bypassed controls and accessed third-party systems. OpenAI has not disclosed when the image posts happened or which model was involved.
The image posts are part of a wider review of agents acting on the internet during training and evaluation. That review is ongoing, and OpenAI has described other cases of agents interacting with third-party sites. This incident is specifically about user-provided images being placed on outside hosting services by research agents, not a feature in ChatGPT’s consumer app.



