OpenAI Probes AI Agents After User Images Leaked, Websites Accessed

Company review finds agents posted 53 user images and identifies dozens of incidents involving unauthorised or unintended activity across external websites

September 28, 2026 at 2:48 PM
icon-facebook icon-twitter icon-whatsapp

ISLAMABAD: OpenAI is working to determine the full scope of activity by its artificial intelligence agents after discovering that the systems had leaked user images and carried out unauthorised actions on external websites, according to people briefed on the matter and company disclosures.

The ChatGPT maker said its agents posted 53 images of users on image-hosting sites.

OpenAI said the links were not publicly listed, but people who obtained links could access the images. Most of the images have been removed, while the company is working with hosting providers to take down the remaining material.

OpenAI did not say whether the images were generated by artificial intelligence or showed real people, nor when they were originally posted.

The images were available to the agents because OpenAI uses some anonymised user data in training and evaluation.

The company says consumer ChatGPT users can opt out of having their data used for training, while enterprise data is not eligible for training.

Agent

OpenAI says its anonymisation process removes metadata, names and other contact information before using the user material. However, people familiar with the company’s practices told Reuters that anonymisation can carry risks that identifying information is not completely removed.

The image disclosure is part of an internal review that began after OpenAI’s agents broke into the artificial intelligence platform Hugging Face in July.

As of mid-September, one person briefed on the matter estimated that OpenAI had identified roughly two dozen incidents involving undesirable agent behaviour.

That number has continued to increase, as investigators examine internal logs and discover previously unknown activity.

READ ALSO: OpenAI Model Breaches Australian Government Website

OpenAI has said the review could take months because of the scope of the investigation. It has also notified dozens of outside organisations about improper activity.

Intruding government websites

The company separately confirmed that its agents accessed information from the websites of the US Securities and Exchange Commission and the US Census Bureau during research and training activities. OpenAI said it found no evidence of unauthorised access, compromised accounts or security breaches in those cases.

Agent

Researchers also reported that OpenAI agents attempted to access the US Department of Education’s civil rights website.

The disclosures followed an announcement by Australian Prime Minister Anthony Albanese that an OpenAI agent had breached a government health data portal in June. OpenAI later notified Australian authorities after discovering the activity during its investigation.

The Australian government said the agent gained unauthorised access to files on a Medicare statistics portal. There was no evidence that patient records or personal information had been accessed.

The incidents have highlighted a broader challenge facing companies developing increasingly autonomous AI agents: systems designed to search the internet, retrieve information and perform tasks can sometimes take actions beyond what their developers intended.

OpenAI said in September it was adopting a new disclosure framework for incidents involving misaligned model activity and would favour transparency even when the significance of an incident remained uncertain.

Agent

The company has also said the Hugging Face incident remains the most serious case identified so far.

OpenAI’s continuing review is therefore examining not only individual security failures but also how effectively the company can identify, track and contain autonomous systems once they interact with the wider internet.

Autonomous agents and drones are becoming a cause of concern, with systems making decisions beyond human control. As their use expands, experts warn that failures, misjudgments or compromised systems could allow them to act in unexpected ways, creating new security risks.

icon-facebook icon-twitter icon-whatsapp