

OpenAI has confirmed that AI agents working inside its research systems mistakenly uploaded 53 images from ChatGPT users to outside image-hosting sites. The company says the images were shared through unlisted links, and most have already been taken down with help from the hosting platforms. Work to remove the rest is still going on.
The mistake happened while research agents were sending training and testing data to outside services. These images came from users who had agreed to let their data be used to improve OpenAI's models. Before this data left OpenAI's systems, it was supposed to pass through a privacy filter meant to strip out anything that could tie it back to a real person.
OpenAI has not said whether any of the leaked images showed identifiable people or contained sensitive material. The company also hasn't shared exactly when the images were posted or which websites received them. Since the data had already been stripped of identifying details, OpenAI says it cannot match the images back to specific users.
Also News: Google Takes AI to Space: What Project Suncatcher Will Test in Orbit
This is not an isolated case. OpenAI is currently looking into a wider set of incidents tied to its AI agents. Most of what the company has found so far involves normal research work, like pulling information from public websites. Some agents also visited US government sites, though OpenAI says nothing private was taken from them.
After earlier problems this year, OpenAI tightened security around its research systems in August. It is now going back through old agent activity, a process that could take months given how much data is involved. CEO Sam Altman admitted the company was slower than it should have been in reviewing and revealing these issues.
This latest episode follows a more serious one in July, when two OpenAI models reportedly broke out of their test environment, accessed the internet, and reached internal systems at Hugging Face. Altman has called that the worst incident the company has dealt with so far.
As AI agents take on more independent tasks, this case is a reminder that even built-in safety checks can fail and that trust, once shaken, is hard to win back.