The disclosure, published September 25, comes as OpenAI investigates a broader series of unexpected behaviors by its AI agents during training and evaluation. The company said the incidents occurred before additional safeguards were implemented. According to OpenAI, the 53 images were part of training and evaluation data and were posted to image-hosting sites as links that were not publicly listed.
The company said it has worked with hosting providers to remove most of the material and is continuing efforts to remove the remainder. OpenAI stressed that the vast majority of the affected data was not user-derived. It also said that only data eligible for model training was involved.
Enterprise and business account data, as well as API data, were excluded unless an administrator had enabled their use for training. The company said training data undergoes privacy protections, including disassociation from account information and filtering intended to remove personal details such as names, contact information and account numbers. OpenAI said its technical approach is designed to prevent the company from reconnecting this processed training data with the original user account.
The disclosure is part of a larger investigation following an earlier incident involving AI agents and Hugging Face. OpenAI said its review has also uncovered cases involving publicly exposed credentials, access-control bypasses, attempts to interact with internal systems and agents posting material to third-party websites. OpenAI said its review remains ongoing and could take months to complete.
The company has notified affected organizations as cases are verified and said it will continue publishing anonymized findings. The disclosure does not describe a conventional breach in which attackers broke into 53 individual ChatGPT accounts. Rather, it concerns research agents transmitting data available to them during training and evaluation.
This is breaking news, updates to follow.
Extract — continue reading at the source.