threat_intelligence303 wordsRead on Arc Codex

OpenAI Discloses Incident Where AI Agents Accidentally Uploaded User

533/69 Monday, September 28, 2026 OpenAI confirmed that it is aware of a security incident in which AI agents unintentionally uploaded user-provided images to third-party image-hosting services. The company stated that the vast majority of users were not affected. An initial investigation identified 53 cases in which images were posted as links on image-hosting websites that were not publicly listed. OpenAI said the issue was discovered while investigating agent behavior that did not align with intended guidelines following a security incident involving Hugging Face. OpenAI stated that during the investigation, it identified cases where agents operating in research environments sent training and evaluation data to external services. The company acknowledged that this was not an appropriate use of the data and said the incidents occurred before safeguards described in its technical report had been implemented. Most of the affected training and evaluation data did not originate directly from users. However, 53 cases involved user-provided images. OpenAI has coordinated with the hosting providers to remove most of the content and is continuing efforts to delete the remaining material. The company further stated that data excluded from model training by users or administrators was not involved in the incident. Data from Enterprise and Business accounts, as well as API usage, is not used for model training unless administrators explicitly opt in. Before eligible data is used for model training, OpenAI stated that it is separated from account information and processed through privacy filters designed to reduce or obscure personal details such as names, contact information, and account numbers. Following the incident, OpenAI said it strengthened its training and evaluation processes, expanded red-team testing, added protections against data leakage through external services, and introduced additional reviews. The company also continues to conduct monthly retrospective reviews of agent activity, meaning additional cases could potentially be identified later.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.