On September 25, 2026, OpenAI disclosed that it had so far confirmed 53 cases in which an AI agent running in an internal research environment posted images provided by users to an external image-sharing site. The images were placed behind links that do not appear in the site's public listings. Most have been deleted, and deletion of the rest is continuing. What the company is investigating is not images posted during conversations with its commercial product, "ChatGPT agent," but activity in research environments used to train and evaluate models. Even if users' data was in a state where it could be used for training, why did it end up posted to an outside site? Comparing the published explanations shows that permission to use data and control over where an agent can send it are separate problems.

AD

Images usable for training still shouldn't be posted externally

OpenAI acknowledges that it was not appropriate for research agents using third-party services to send training and evaluation data outside. It says most of the affected data did not come from users. Among it were cases in which user-provided images were placed on an image-sharing site, 53 of them. Permission to use data to improve models does not mean the data may go anywhere.

Determining which data is eligible for training, separating account information, and controlling outbound transfers are distinct stages. The first two alone could not prevent images from being posted to a third-party site.

Stage What OpenAI says What the incident shows
Deciding what is eligible for training Data is sorted by user settings and enterprise administrator settings OpenAI says data not eligible for training was not included
Separating account information and reducing personal data The incident explanation says account information is detached from the relevant data and personal information is masked OpenAI says the images cannot be linked back to the accounts that provided them
Controlling agents' outbound transfers The company says it has strengthened safeguards and monitoring against data exfiltration in research and evaluation environments Before these safeguards were introduced, user-provided images were posted

The first two rows are conditions and processing applied before data is handled as training data. The last is control over agents that touch that data when they use external services. OpenAI has not disclosed which tools or transmission routes were used for the individual posts, or why the agents posted the images. So it is not possible to say that a particular loophole was the cause. Still, since posting to an outside site did occur, it is clear that defining how training data is handled is not enough to prevent this kind of incident.

The term anonymization also calls for caution. OpenAI's explanation of Privacy Filter describes a model that finds and masks names, contact details and similar items in text, and states explicitly that it is not a tool that guarantees anonymization. The incident notice says a version of Privacy Filter is used on training data, but OpenAI has not said how it processed the images that were posted, or whether it inspected or altered visual information such as faces and backgrounds. Severing the link to an account is not the same as making the people or places in an image unidentifiable.

The figure of 53 is the number of posting cases OpenAI has identified so far in a retrospective investigation. The company has not disclosed how many users provided the images, the total number of images posted, or how many times third parties viewed them. It cannot be read as meaning that 53 people's images were seen, or that only 53 images left the company. The investigation is ongoing, and the final count is not yet settled.

The links at the destination did not appear in the image-sharing site's public listings. That indicates the images were hard to find on the site, but it does not indicate access restrictions that would stop someone who knew the URL from viewing them. At the same time, there is no basis for asserting that anyone actually viewed the images. The name of the destination service, how long the links remained live, and the content of the images have not been disclosed. OpenAI says it worked with the hosting provider to delete most of them and is deleting the rest. It has not said how many remain.

OpenAI says that because training data was detached from the original accounts, it cannot link the images back to the users who provided them, both technically and under its privacy policy. This design is meant to keep account information from staying attached to training data, but in a post-incident investigation like this one it also limits the clues for identifying which users an image relates to. The same OpenAI update page says it notified dozens of affected third parties. It does not say it individually notified the users who provided these images.

AD

A retrospective review that began with the Hugging Face incident

The disclosure emerged from an investigation that followed the July breach involving Hugging Face. According to OpenAI, a research model running in an internal cybersecurity evaluation at that time bypassed the mechanism restricting its internet access and accessed both internal research infrastructure and Hugging Face's systems. The company has since broadly reviewed activity in its research environments, including outbound data transfers and unauthorized contact.

However, it has not said whether the posting of the 53 images was done by the same agent as the Hugging Face breach, or whether it used the same loophole. The relationships OpenAI has shown are that the breach triggered the broad investigation, and that the image postings occurred before safeguards introduced later. The company is now going back month by month through logs of research and evaluation runs. The number of confirmed cases could still grow.

As countermeasures, OpenAI cites verification to confirm that models do not take data outside, attack testing of research environments, and additional monitoring. These are improvements the company describes, not results proving that recurrence has been prevented on every route. Since the specific route of the image postings has not been disclosed, readers also cannot check which of the measures addressed the route in this case.

What users can change is future data use

For consumer services, if you do not want future conversations used to improve models, OpenAI's official help page explains that you can open "Settings" in ChatGPT, go to "Data controls" and turn off "Improve the model for everyone." You can also opt out of training use through the Privacy Portal. Either one applies to new ChatGPT conversations and Codex tasks, and the page does not say it reaches back to past conversations. Codex has a separate setting for including an entire environment in training, which is not linked to the ChatGPT change.

Temporary Chats are not used to improve models while they remain temporary. If you save one and turn it into a regular chat, it follows the account's settings. Also, even after opting out of training, if you voluntarily send feedback, for example through a rating button, the related conversation as a whole may be used for training. ChatGPT Business, Enterprise, Edu and the API are excluded from training by default, and handling changes if an administrator enables data sharing.

Changing settings alters the conditions for data newly used from now on; it is not an action that removes anything already placed on an image-sharing site. When will the remaining images be deleted? How far will OpenAI identify the posting routes and the scope affected, and what will it say about contacting users? Only with further disclosure on these points can the reliability of connecting research agents to external services be assessed more concretely.