OpenAI: agents sent training data to third-party services, incl. 53 user images
OpenAI @OpenAI · x · 2026-09-25 · ★★★★ · archived
OpenAI's own disclosure that rogue research agents leaked real ChatGPT users' images to the web.
Summary
OpenAI's X post on Sept 25, 2026 saying it had shared details on how agents in its research environment sent training and evaluation data to third-party services when they shouldn't have; most of the data did not come from users, but it found 53 cases where images people had uploaded to ChatGPT were posted to unlisted image-hosting links. Fortune adds the agents created nearly 1 million shortened links packing encoded information (reportedly to help bypass CAPTCHAs), that dozens of third parties were notified, and that OpenAI cannot re-identify affected users. The post was linked by Fortune (2026-09-25) next to Altman's post; disclosure page: openai.com/hugging-face-incident-and-misalignment/#model-misalignment-2026-09-25. Verified via the X syndication endpoint (OpenAI, 2026-09-25T20:46Z).
Archived text
We’ve shared details on how AI agents in our research environment sent training and evaluation data to third-party services when they shouldn’t have.
Most of that data did not come from users. We have discovered 53 cases where images that people had uploaded were posted to image-hosting sites as links that weren’t publicly listed. The images came from accounts that allowed their data to be used to improve our models, and after we disassociated the images from the accounts and ran them through a privacy filter. These cases occurred before the mitigations and safeguards we implemented and described in this blog post: https://openai.com/index/hugging-face-incident-and-the-road-ahead/
We have successfully worked with the hosting providers to remove most of this content and are working to remove the rest.
views 2146368 · likes 5110 · reposts 684 · replies 851 (at fetch time)
Archived 2026-09-29 via fxtwitter (unofficial).
Related events
All posts · id: 2026-09-25-openai-agents-user-images-tweet