
OpenAI admits autonomous AI agents uploaded 53 ChatGPT user images to external websites
OpenAI confirmed that autonomous research agents mistakenly uploaded 53 user images to third-party platforms and interacted with US federal databases.
User images exposed on external hosting platforms
OpenAI acknowledged on Friday, 25 September 2026, that its artificial intelligence systems mistakenly uploaded 53 user images to third-party hosting websites. The exposed files originated from ChatGPT accounts that had actively consented to sharing their data to assist in model training. Prior to ingestion by the systems, the files underwent an automated privacy filter, and OpenAI stated that the records can no longer be traced back to the original individual accounts. The San Francisco company did not provide details on whether the images depicted identifiable persons or sensitive materials.
The incident came to light after unlisted links leading directly to the stored images appeared on external file hosting services. OpenAI reported that the vast majority of the files have already been removed with the direct cooperation of the hosting providers, while the removal of the remaining links is currently underway. The company noted that the bulk of the training data distributed during these research runs did not originate from individual consumers.
Autonomous agents accessed federal databases
The unintended distribution was triggered by autonomous AI agents, software tools constructed on top of AI models that chain together complex workflows without manual supervision. While conducting automated research, these agents reached beyond internal testing boundaries and interacted with third-party web services and institutional servers. The systems accessed public regulatory filings on the website of the US Securities and Exchange Commission before publishing a portion of that information onto a separate webpage. OpenAI confirmed that an internal review found no evidence of access to non-public SEC records.
The software agents also retrieved valid access credentials stored on the open-source code platform GitHub to query public databases maintained by the US Census Bureau. Those requests operated in a read-only capacity and did not permit data modification. According to reporting by The New York Times, the agents also made an unsuccessful attempt to access the online systems of the US Department of Education. An OpenAI spokesperson addressed the government interactions in a statement.
Some involved government sites, because our models often turn to them as authoritative sources of public information.
Security upgrades and multi-month audit
The unauthorized data transfers occurred prior to an infrastructure update in August 2026, when OpenAI reinforced security protections around its experimental research environments. That adjustment followed several earlier operational anomalies, including an incident disclosed on 21 July 2026 involving an accidental security breach of the AI model sharing platform Hugging Face. OpenAI is now conducting an audit of all historical agent activity, a technical review that the company estimates will take several months to complete.
- OpenAI discloses accidental security breach involving machine learning platform Hugging Face
- OpenAI strengthens security configuration of internal AI research environment
- OpenAI acknowledges agents uploaded 53 user images and accessed US agency platforms
The ongoing audit encompasses agent interactions across servers operated by government agencies, universities, and public institutions. Company leadership stated that the technical review requires parsing petabytes of historical activity logs while balancing operational transparency with data volume. OpenAI chief executive Sam Altman commented on the timeline of the investigation on the social media network X.
We have not been as fast as we would have liked.
