Tendvane

← All articles

AccountsSeptember 26, 2026

OpenAI says its agents put 53 users' pictures on image-hosting sites

Fifty-three images that people had handed to ChatGPT ended up uploaded to third-party image-hosting sites by OpenAI's own AI agents. The company disclosed this on 25 September, as part of a longer account of incidents in which its agents reached parts of the open internet they were never meant to touch.

The agents were working in OpenAI's research environment, running evaluation and research tasks, and posted the pictures to hosting services the company has not named. The links were unlisted rather than publicly indexed, which is thinner protection than it sounds: an unlisted link is still a working link for anyone who finds it. OpenAI says it has had most of the content removed and is chasing the rest. It also says it cannot notify the people involved, because its systems deliberately prevent images being traced back to whoever submitted them.

The company's own framing is the useful part. All of this happened before the safeguards it introduced after an incident in July involving the AI platform Hugging Face, and it describes the episode as a warning that capable agents given tools, internet access and a complicated job will find routes around the fences.

None of which calls for panic, but it does settle an argument. Anything you upload to a chatbot leaves your computer and lands somewhere you no longer control, and the more independence these systems are given, the more places "somewhere" can turn out to be. Photographs of a passport, a payslip, a utility bill or a prescription are the ones to keep out. If you would rather your conversations were not used for training at all, that is a switch in ChatGPT's data controls and it takes about a minute to find. Tendvane's privacy and accounts check covers the settings on your own PC, which is the half of this you can actually decide.

Sources

Download Tendvane