OpenAI Agent Leaked 53 User Images, Owners Cannot Be Identified

International|
|
||
AP-Yonhap News - Seoul Economic Daily International News from South Korea
AP-Yonhap News

OpenAI has belatedly confirmed that one of its artificial intelligence agents leaked 53 user images outside the company. The firm cannot determine whose images they are, meaning it cannot even notify the people affected.

53 ChatGPT User Images Posted Externally; Some Still Being Deleted

According to internal investigation findings OpenAI recently released through X, formerly Twitter, an AI agent operating in the company's research environment posted 53 user-supplied images to an outside image hosting site.

The images had been provided by users of ChatGPT and other OpenAI services and were later included in AI model training data. The agent is believed to have taken the images while accessing internal training data during research.

The posted images were in link form and did not appear in public listings, but the possibility that outsiders could find them remains. OpenAI said the agent "did not use this data appropriately," adding that it had worked with hosting providers to delete most of the images and that the rest were being removed. The company did not disclose whether the 53 images were photographs of real people or AI-generated images. It also did not say when or why they were posted.

No Way to Notify Users; A Paradox Created by Anonymization

The bigger problem is that there is no way to inform affected users of the leak.

OpenAI said that because of its technical data-handling methods and its privacy policy, it cannot reconnect the leaked images to the users who originally provided them and therefore cannot notify those individuals directly. The anonymization process that strips names, contact details and metadata from AI training data has made it difficult to trace the original users after the incident.

The images that went outside the company came from general users who had not separately opted out of having their data used for AI model training, according to the disclosure. Data from enterprise service customers is excluded from training by default, but general users' data can be used unless they opt out.

The incident also differs from a typical hacking case in which an outside attacker breaks into a server and extracts data. Here, an AI agent operated by OpenAI accessed internal training data and then posted it directly to the open internet outside the company.

Full Review After Hugging Face Breach; Government and Institutional Sites Also Accessed

The leak was discovered as OpenAI retroactively examined the past activity of its AI agents.

After confirming in July that its agents had broken out of a controlled research environment and intruded into the AI development platform Hugging Face, OpenAI has been strengthening security in its research environment and reviewing past activity logs since August.

According to The New York Times, the agents were found to have generated about 1 million shortened internet links to evade security controls. OpenAI regards the Hugging Face case as the most serious incident identified so far.

The investigation also confirmed that agents had accessed government agency websites including the U.S. Securities and Exchange Commission and the Census Bureau. OpenAI said the agents only retrieved publicly available information from those sites.

OpenAI has notified dozens of governments, universities and public institutions about cases in which its agents bypassed security controls or used websites in ways not intended. About 20 cases of inappropriate behavior had been identified as of mid-September, and new cases have continued to surface.

OpenAI Chief Executive Sam Altman said on X on the 25th that the company was "trying to balance transparency and investigation" as it worked to gain a clear picture of petabytes of agent activity logs and cooperated with affected institutions, adding that the process had not moved as quickly as it had wanted.

Original reporting by Kim Yeo-jin for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
4:02

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.