25 September 2026 · OpenAI
OpenAI agents posted 53 users' images on the open internet
OpenAI agents sent training and evaluation data out of the research environment while they used services from other companies. In 53 cases, images that people had put into ChatGPT ended up on image-hosting sites, behind unlisted links. Most have been removed. Some are still online.
By Mara Masaeva · maramasaeva.comUpdated 29 September 2026
HarmConfirmedMore than one independent source, or a primary document.
What happened
It is the first publicly known case of OpenAI agents mishandling user data.
The images came from users whose ChatGPT data could be used for training, because they had not opted out. According to OpenAI, data from enterprise and business accounts and from the API is excluded by default, unless an administrator turns it on. Data that can be used is separated from account information first. A privacy filter then removes names, contact details and account numbers before training.
The cases date from before the safeguards described in the August technical report. OpenAI says it worked with the hosting providers and had most of the material removed. It is still working on the rest.
In mid-September OpenAI had found roughly two dozen incidents of agents behaving in unwanted ways, Reuters reported, citing a person briefed on the matter. By 25 September the same review had turned up this case.
What it cost
Fifty-three people gave an image to a chatbot. Software from the company behind that chatbot then published it on the internet. The people have not been named, nobody asked them, and some of the images are still public.
No other entry in the dossier has such an exact count of victims. Most entries are about infrastructure and arguments. Here the cost falls on individual people, whose only mistake was not reading a settings page.
What may follow
The mechanism is the same as in the other incidents in the dossier. The agents used ordinary outside services to get their work done, and the data went along. Nobody decided to publish anyone's pictures.
The exception for enterprise accounts will be quoted in sales conversations. I find the view of Conrad Stosz of Transluce more useful. He told Axios it is entirely plausible that an enterprise user gives an agent an instruction, the agent has access to sensitive information, and the agent then does something that reveals part of it.
My notes
This is the only entry with a count of victims. Use it once, near the end, when people stop thinking about hackers and start thinking about themselves.
The exception for enterprise accounts will come up. Answer with what Stosz said, not with the sales line.
Read next
Sources
- Axios: OpenAI models posted user images online in latest security episodepress · main source
Madison Mills, 25 September 2026, following Reuters.
- OpenAI, 25 September update on transmitted training and evaluation dataprimary
The company's own account, including how the privacy filter works.