Technology
OpenAI tools post user images from ChatGPT online
Key Points
OpenAI tools post user images from ChatGPT online September 26, 2026Artificial intelligence giant OpenAI on Friday acknowledged that its AI tools had posted images users provided to ChatGPT on online sites, without the company's knowledge, in yet another example of AI agents operating outside of their confines. In a post on X, the company said its AI agents had sent "training and evaluation data to third-party services when they shouldn't have," adding that most of the data shared did not...
OpenAI tools post user images from ChatGPT online
September 26, 2026Artificial intelligence giant OpenAI on Friday acknowledged that its AI tools had posted images users provided to ChatGPT on online sites, without the company's knowledge, in yet another example of AI agents operating outside of their confines.
In a post on X, the company said its AI agents had sent "training and evaluation data to third-party services when they shouldn't have," adding that most of the data shared did not come from users.
However, they had found 53 cases where images that people had uploaded to ChatGPT were posted to image-hosting sites as links that were not publicly listed.
"The images came from accounts that allowed their data to be used to improve our models, and after we disassociated the Images from the accounts and ran them through a privacy filter," it said.
The company said it had removed most of the content and was working to remove the rest.
Apart from the images, OpenAI confirmed a New York Times report that its tool had accessed websites of US federal agencies but that they only retrieved publicly available information.
Rising fear of rogue AI
The latest disclosure comes amid heightened global concerns about AI systems escaping human control and hacking into external websites, as well as industry calls for a slowdown on AI development — a move which OpenAI said it supports.
Friday's post also clarified that the cases of unauthorized sharing occurred before a fresh round of safeguards were implemented over a month ago.
In July, OpenAI had said internal cybersecurity evaluations showed that its models circumvented controls designed to isolate them from the internet. OpenAI CEO Sam Altman on Friday said it was "still the most severe event we've seen."
"We are continuing to review agent activity in research and evaluation runs, working backward month by month starting from the Hugging Face incident," OpenAI said in a safety blog post on Friday, adding that it would "provide further updates" in time.
Investigation finds OpenAI agents attempting hacks
AI evaluator and research lab Transluce on Friday said that it also found that AI agents, appearing to originate from OpenAI, attempted a rudimentary hack on the US Department of Education website for the department's civil rights office. The agents did not succeed, according to the independent investigation.
The company said it found "additional rogue activities," some of which were not directly attributable to OpenAI, targeting other government agencies, including the Justice Department and the Commerce Department, as well as some state government websites in California, Maryland, Illinois, Texas and New York.
Edited by: Sean Sinico
AI (ORG)
Images (ORG)
OpenAI (LOCATION)
New York Times (ORG)
US (LOCATION)
Sam Altman (PERSON)
Transluce (ORG)
the US Department of Education (ORG)
the Justice Department (ORG)
the Commerce Department (ORG)
California (LOCATION)
Maryland (LOCATION)
Illinois (LOCATION)
Texas (LOCATION)
New York (LOCATION)