OpenAI AI agents leak 53 ChatGPT user images online, company working to take them down

HIGHLIGHTS

OpenAI has revealed that AI agents in its research environment shared some training and evaluation data with third-party services.

The company said it has so far found 53 cases where images provided by users were posted on image-hosting websites.

OpenAI said it has already worked with hosting providers to remove most of the content and is trying to take down the remaining images.

OpenAI AI agents leak 53 ChatGPT user images online, company working to take them down

OpenAI has revealed that AI agents in its research environment shared some training and evaluation data with third-party services. The company said it has so far found 53 cases where images provided by users were posted on image-hosting websites. These images were shared as links that were not publicly listed. OpenAI said it has already worked with hosting providers to remove most of the content and is trying to take down the remaining images. The company said the incidents happened before it introduced the safeguards described in its latest technical report.

Digit.in Survey
✅ Thank you for completing the survey!

OpenAI said the data involved came from training-eligible data. Data that users or enterprise administrators had excluded from training was not part of the affected dataset. Before eligible data is used for training, OpenAI explained it takes steps to protect users’ privacy. This includes separating the data from account information and using its privacy filter to remove details such as names, contact information and account numbers.

Also read: OpenAI GPT 6 Cyber may launch soon, new security deployment tool also in works: Report 

The company said the “vast majority of the impacted training and evaluation data is not user-derived.’ However, its investigation found 53 instances involving user-provided images.

The latest disclosure is part of OpenAI’s wider investigation into AI models that may have behaved outside their assigned tasks during training and evaluation. The company started the broader review following the Hugging Face incident. 

Also read: OpenAI, Google and Anthropic plan joint AI safety group, may announce it by 2027: Report  

In a separate report, OpenAI said that it is also notifying organisations when it confirms cases that meet its disclosure criteria. These organisations include government bodies, universities, public agencies and other institutions.

However, OpenAI said receiving a notification should not automatically be considered evidence of a major security incident. “Some organisations may review what we share and conclude that the information was intentionally public or that the model’s interaction was not concerning. Others may identify a design issue or security weakness they want to address,” the AI company said.

Also read: Sam Altman warns we may lose control of future to AI, calls for global standards   

Ayushi Jain

Ayushi Jain

Ayushi works as Chief Copy Editor at Digit, covering everything from breaking tech news to in-depth smartphone reviews. Prior to Digit, she was part of the editorial team at IANS. View Full Profile