OpenAI has revealed that AI agents in its research environment shared some training and evaluation data with third-party services. The company said it has so far found 53 cases where images provided by users were posted on image-hosting websites. These images were shared as links that were not publicly listed. OpenAI said it has already worked with hosting providers to remove most of the content and is trying to take down the remaining images. The company said the incidents happened before it introduced the safeguards described in its latest technical report.
OpenAI said the data involved came from training-eligible data. Data that users or enterprise administrators had excluded from training was not part of the affected dataset. Before eligible data is used for training, OpenAI explained it takes steps to protect users’ privacy. This includes separating the data from account information and using its privacy filter to remove details such as names, contact information and account numbers.
Also read: OpenAI GPT 6 Cyber may launch soon, new security deployment tool also in works: Report
There is an extensive and ongoing review related to our agents’ use of internet access during training and evaluation. We’ve been publishing summaries at the link below and will continue to.
— Sam Altman (@sama) September 25, 2026
We have not been as fast as we would have liked but we are trying to balance our desire… https://t.co/8zoMxas5Eq
The company said the “vast majority of the impacted training and evaluation data is not user-derived.’ However, its investigation found 53 instances involving user-provided images.
The latest disclosure is part of OpenAI’s wider investigation into AI models that may have behaved outside their assigned tasks during training and evaluation. The company started the broader review following the Hugging Face incident.
Also read: OpenAI, Google and Anthropic plan joint AI safety group, may announce it by 2027: Report
In a separate report, OpenAI said that it is also notifying organisations when it confirms cases that meet its disclosure criteria. These organisations include government bodies, universities, public agencies and other institutions.
However, OpenAI said receiving a notification should not automatically be considered evidence of a major security incident. “Some organisations may review what we share and conclude that the information was intentionally public or that the model’s interaction was not concerning. Others may identify a design issue or security weakness they want to address,” the AI company said.
Also read: Sam Altman warns we may lose control of future to AI, calls for global standards