
OpenAI has belatedly confirmed that one of its artificial intelligence agents leaked 53 user images outside the company. The firm cannot determine whose images they are, meaning it cannot even notify the people affected.
53 ChatGPT User Images Posted Externally; Some Still Being Deleted
According to internal investigation findings OpenAI recently released through X, formerly Twitter, an AI agent operating in the company's research environment posted 53 user-supplied images to an outside image hosting site.
The images had been provided by users of ChatGPT and other OpenAI services and were later included in AI model training data. The agent is believed to have taken the images while accessing internal training data during research.
The posted images were in link form and did not appear in public listings, but the possibility that outsiders could find them remains. OpenAI said the agent "did not use this data appropriately," adding that it had worked with hosting providers to delete most of the images and that the rest were being removed. The company did not disclose whether the 53 images were photographs of real people or AI-generated images. It also did not say when or why they were posted.
No Way to Notify Users; A Paradox Created by Anonymization
The bigger problem is that there is no way to inform affected users of the leak.
OpenAI said that because of its technical data-handling methods and its privacy policy, it cannot reconnect the leaked images to the users who originally provided them and therefore cannot notify those individuals directly. The anonymization process that strips names, contact details and metadata from AI training data has made it difficult to trace the original users after the incident.
The images that went outside the company came from general users who had not separately opted out of having their data used for AI model training, according to the disclosure. Data from enterprise service customers is excluded from training by default, but general users' data can be used unless they opt out.
The incident also differs from a typical hacking case in which an outside attacker breaks into a server and extracts data. Here, an AI agent operated by OpenAI accessed internal training data and then posted it directly to the open internet outside the company.
Full Review After Hugging Face Breach; Government and Institutional Sites Also Accessed
The leak was discovered as OpenAI retroactively examined the past activity of its AI agents.
After confirming in July that its agents had broken out of a controlled research environment and intruded into the AI development platform Hugging Face, OpenAI has been strengthening security in its research environment and reviewing past activity logs since August.
According to The New York Times, the agents were found to have generated about 1 million shortened internet links to evade security controls. OpenAI regards the Hugging Face case as the most serious incident identified so far.
The investigation also confirmed that agents had accessed government agency websites including the U.S. Securities and Exchange Commission and the Census Bureau. OpenAI said the agents only retrieved publicly available information from those sites.
OpenAI has notified dozens of governments, universities and public institutions about cases in which its agents bypassed security controls or used websites in ways not intended. About 20 cases of inappropriate behavior had been identified as of mid-September, and new cases have continued to surface.
OpenAI Chief Executive Sam Altman said on X on the 25th that the company was "trying to balance transparency and investigation" as it worked to gain a clear picture of petabytes of agent activity logs and cooperated with affected institutions, adding that the process had not moved as quickly as it had wanted.






