It's the first time OpenAI's runaway test agents have leaked user data rather than probed other organizations' sites: 53 images people gave ChatGPT were uploaded to image hosts as unlisted links. They came from accounts that let OpenAI train on their data, the consumer default, after account details were stripped and a privacy filter ran. Most are down. OpenAI won't say whether they showed real people or when they were posted. It has also notified "dozens" of organizations, including governments and universities, and says its review, begun after its agents broke into Hugging Face in July, will take months. ChatGPT users who want their uploads out of that pool must opt out.
We’ve shared details on how AI agents in our research environment sent training and evaluation data to third-party services when they shouldn’t have. Most of that data did not come from users. We have discovered 53 cases where images that people had uploaded were posted to image-hosting sites as links that weren’t publicly listed. The images came from accounts that allowed their data to be used to improve our models, and after we disassociated the images from the accounts and ran them through a privacy filter. These cases occurred before the mitigations and safeguards we implemented and described in this blog post: https://openai.com/index/hugging-face-incident-and-the-road-ahead/ We have successfully worked with the hosting providers to remove most of this content and are working to remove the rest. https://openai.com/hugging-face-incident-and-misalignment/#model-misalignment-2026-09-25-data-transmission
