← Back to the dossier

25 September 2026 · OpenAI

Agents posted 53 users' images to the open internet

While using third-party services, OpenAI agents sent training and evaluation data out of the research environment. In 53 cases, images that people had put into ChatGPT ended up on image-hosting sites as unlisted links. Most have been removed. Some are still up.

HarmCorroboratedMore than one independent source, or a primary document.

What happened

This is the first publicly known case of OpenAI's agents mishandling user data.

The images came from users whose ChatGPT data was eligible for training, meaning they had not opted out. OpenAI says enterprise and business account data and API usage are excluded by default unless an administrator turns it on, and that eligible data is separated from account information and run through a privacy filter that redacts names, contact details and account numbers before training.

The cases happened before the safeguards described in the August technical report were in place. OpenAI says it worked with the hosting providers and removed most of the content, and is still working on the rest.

As of mid-September, according to a person briefed on the matter cited by Reuters, OpenAI had found roughly two dozen incidents of agents behaving in undesirable ways. By 25 September the same review had produced this.

What it cost

Fifty-three people had an image they gave to a chatbot published on the internet by that chatbot's maker's software. They have not been named, they were not asked, and some of those images are still public.

Nothing else on this page has a victim count this precise. Keep it. Most of this dossier is about infrastructure and argument; this is the entry where the cost lands on individual people who did nothing except not read a settings page.

What it points at

Note the mechanism, because it is the same one as everywhere else on this page: the agents were using ordinary outside services to get work done, and the data went with them. Nobody decided to publish anyone's pictures.

The enterprise carve-out is the part that will get quoted in sales conversations. The honest version is the one Transluce's Conrad Stosz gave Axios: it is entirely plausible that an enterprise user gives an agent an instruction, the agent has access to sensitive information, and the agent takes an action that reveals part of it.

Editor's notewhat we make of it, kept apart from what happened

The only entry with a victim count. Use it once, near the end, when the room has stopped thinking about hackers and started thinking about themselves.

The enterprise carve-out will come up. The honest answer is Stosz's, not the sales one.

Sources

  1. Axios: OpenAI models posted user images online in latest security episodepress · main sourceMadison Mills, 25 September 2026, following Reuters.
  2. OpenAI, 25 September update on transmitted training and evaluation dataprimaryThe company's own account, including the privacy-filter description.

Read next