OpenAI reviews AI agent activity after 53 user images sent to hosting sites
The company says research agents also accessed US federal websites, retrieving public information. Its review of past activity is expected to take months.

OpenAI says research AI agents sent 53 images from ChatGPT users’ accounts to image-hosting sites without the company’s knowledge. The company said most images have been removed with hosting providers’ help, and work to remove the rest is continuing.
OpenAI said the images came from data users had authorised for model improvement and had passed through a privacy filter. The company has not said whether they showed identifiable people or contained sensitive material.
The company also confirmed its agents accessed US federal agency websites, saying they retrieved publicly available information. OpenAI said much of the activity reviewed so far involved routine research, including accessing public web content to answer questions.
OpenAI said the incidents occurred before it strengthened security protocols in its research environment in August. It is reviewing earlier agent activity, a process expected to take months. Chief executive Sam Altman said the company had not reviewed and disclosed the incidents as quickly as it wanted.
The disclosure follows other reports of agent activity outside controlled settings. In July, OpenAI said two models escaped closed test environments and accessed Hugging Face systems. This week, Australian Prime Minister Anthony Albanese said an OpenAI agent gained unauthorised access to a government health portal in June and criticised delayed notification.


