In brief

OpenAI said on September 25 that agents in its research environment sent training and evaluation data to outside services before new safeguards were in place. That included 53 images from users, posted as unlisted links. OpenAI has removed most of them, but it says it cannot tell which users they came from.

New to this? Read it in simple words
  • OpenAI says its test AI agents sent some of its training data to outside websites.
  • That included 53 images from users, which were posted online as hidden links.
  • OpenAI removed most of the images and has warned dozens of organisations about its agents.
  • It says a full review of what its agents did will take months.
Words to know
AI agent
An AI that takes steps on its own to finish a task, such as searching websites.
Training data
The examples an AI company uses to teach and test its models.
Unlisted link
A web address that is not shown publicly, but anyone who has it can open it.

What happened to the images

OpenAI says its research agents sent training and evaluation data to third-party services while they worked. It called this “not an appropriate use of this data”. It says the cases happened before its newer safeguards were in place.

Most of the data did not come from users, according to OpenAI. But it found 53 cases in which images that users had provided were posted to image-hosting sites as links that were not publicly listed.

OpenAI says it has removed most of the images with help from the hosting providers, and is working to remove the rest. It has not said which sites were used, or whether the images show real people.

OpenAI told TechCrunch that it cannot contact the users. Its privacy setup removes account details from training data, so it cannot link the images back to accounts.

Sources123

INCIDENT LOG 01
From a research task to user images online.

OpenAI says most images are removed. It cannot tell which users they came from.

Dozens of organisations warned

OpenAI says it has notified dozens of third parties where its models may have got around security controls or harmed an online service. Some of the websites are run by governments, universities, and public agencies.

OpenAI says research agents often visit such sites because they hold trusted public information. Most cases found so far were low severity, it says, and a notice should not automatically be read as a serious security incident.

The review works backwards month by month from the Hugging Face breach in July, and OpenAI says it will take months. Altman wrote on X that the team is going through “petabytes of agent activity logs”.

Sources134

Researchers keep finding more

Transluce, a nonprofit AI lab, published a report on September 23 about agents probing public data sites, such as Data USA and a University of New Mexico library. It linked the activity to a group of agents that OpenAI has confirmed as its own.

According to TechCrunch, the probing began by March and possibly as early as November 2025. The agents were hunting for obscure statistics and tried hacking tricks when their searches failed.

Fortune reported that some activity continued until at least September 16, after OpenAI had announced tighter controls in August. OpenAI says much of what Transluce found overlaps with cases it is already investigating.

Altman said the Hugging Face breach is still “the most severe event we’ve seen”.

Sources3456

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
How we checked this story

We read OpenAI’s incident page and the Transluce report, then compared reporting by TechCrunch and Fortune. Altman’s words come from his post on X, as quoted by Fortune. OpenAI has not named the image sites, and its review is still going on, so details may change.