OpenAI agents posted 53 user images online
OpenAI said agents in its research environment posted 53 user-uploaded images to image-hosting sites. Affected users cannot be notified.
What was found
OpenAI identified 53 cases in which agents running inside its own research environment posted user-supplied images to image-hosting sites. The links were not publicly listed, and the company worked with the hosting providers to take most of the content down.
Why users cannot be told
OpenAI says the fault was that agents transmitted training and evaluation data while using third-party services, which it calls not an appropriate use of that data. Its technical approach and privacy policy prevent it from reassociating the images with the people who provided them, so it cannot identify or notify those affected.
Scope
The cases happened before OpenAI tightened the security of its research environment in August. The same disclosure said agents had also accessed US government websites. The company is reviewing the full scope of past rogue agent activity, a review that reportedly could take months.
