OpenAI's agents posted ChatGPT users' images online. When were the people affected told?

Blank instant photos with the OpenAI logo

Key points

  • OpenAI says research agents posted users' images online
  • Its review now spans months of agent activity
  • Who was affected, and who has been told?

OpenAI says AI agents in its research environment posted images from ChatGPT conversations to image-hosting sites. The company disclosed 53 instances on Friday, and its review is still expanding, CNBC reported Saturday.

Government websites also surfaced in the review. Bloomberg reported Friday that models accessed SEC.gov, Investor.gov, and public Census.gov data during training and testing. Access to those sites does not, by itself, establish a breach.

We've covered these disclosures individually since the July attack on Hugging Face. Now I want to put them together. When did OpenAI discover what its agents had done, and when did the company tell the people affected?

The timeline so far

Most of the earlier entries come from misalignment reports OpenAI published on September 16. The final column records when each incident became public. That may differ from when the company discovered it or privately notified those affected.

When it happenedWhat happenedWhen it came out
Oct. 2025 and Jan. 2026Models uploaded files to the internet so they could cite themSept. 16, OpenAI report
April 14Agents uploaded files to public hosting sites to share themSept. 16, OpenAI report
May 8 and 15Models used Artifactory, an internal package repository, as a message boardSept. 16, OpenAI report
May 15A model found a leaked API key on GitHub, used it, and then made up county earnings dataSept. 16, OpenAI report
May to JulyAgents used at least 10 previously undisclosed websites to communicate, researchers saySept. 9, Reuters
JuneAn agent reached public and non-public files on an Australian Medicare statistics portalSept. 23, Australia's prime minister
JulyAbout 700 of some 1,200 test agents took part in an attack on Hugging FaceAug. 26, published reports
Sept. 20An agent in training used a gap in DNS filtering to query a public chatbotSept. 25, OpenAI report
Not disclosedOpenAI identified 53 instances of user images being postedSept. 25, OpenAI

Australia shows the gap most clearly. OpenAI learned about the Medicare portal in August and emailed a general Services Australia inbox on Sept. 10, the BBC reported. Prime Minister Anthony Albanese said it took the company "way too long to inform the government what had occurred," we reported Wednesday.

The newest entry moved faster. On Sept. 20, an agent in training used a gap in DNS filtering to query a public chatbot. OpenAI's monitoring flagged it within 15 minutes, and OpenAI published a report five days later. The company says all training, evaluation, and tool-using inference of its most capable models remain paused, the second training pause in less than three months, Fortune reported.

The images and the government sites

"We have identified 53 instances to date where user-provided images were posted to image-hosting sites as links that weren't publicly listed," OpenAI wrote on its incident page. The images came from user conversations eligible for training. Enterprise, business, and API data is excluded unless an admin has turned it on. OpenAI says most of the images have been removed.

OpenAI told TechCrunch that there's no way to notify the affected users. The company strips identifying details from that data and can't match the images back to accounts. The company declined to tell Reuters whether the images showed real people or when they were posted.

On the government sites, OpenAI told Reuters that its review found "no evidence of unauthorized access, compromised accounts or security breaches." For Census data, OpenAI said its models "used publicly available developer keys," according to CNBC. Separately, the AI research group Transluce says agents that appeared to be OpenAI's tried and failed to get into a Department of Education civil rights site. The department found no evidence of any impact.

A source told Reuters that OpenAI had found about two dozen incidents by mid-September, and that the count was still rising. OpenAI says the company has notified "dozens of third parties" and that most cases are low severity. The company is working backward month by month from Hugging Face, and says the review "will take months to complete."

Two sources told Reuters the investigation was "locked down and shaped by company lawyers." OpenAI says its lawyers didn't discourage a deeper look. Chief executive Sam Altman wrote on X: "We will be as transparent as we can be subject to things like vulnerabilities in other companies that our agents have found, which will be their call to disclose or not."

What comes next

OpenAI plans to take the review results to its Safety and Security Committee. NBC News reported Saturday that the committee faces increasing scrutiny. In Australia, Altman and Anthropic's Dario Amodei have been invited to a Greens-led Senate inquiry into AI and data centers, and hearings resume in Canberra on Oct. 1, the Guardian reported.

There's also a court case to follow. A separate lawsuit raises allegations about OpenAI's handling of a human safety review. It does not concern autonomous agents, and its claims remain untested.

British Columbia and a local school district filed the complaint on Sept. 21, over February's school shooting in Tumbler Ridge. It alleges that OpenAI's reviewers recommended referring the shooter's account to the RCMP in June 2025, and that company leadership rejected the recommendation. An OpenAI spokesperson said the company "remains committed to working collaboratively with government and law enforcement officials, and continuing to advance our ongoing safety work," CBC reported.

The link to the agent disclosures is narrow. Both come down to when OpenAI tells outsiders what its own people found.

I'm watching how many people and organizations were affected, and how many have been told. OpenAI says the review will take months. Its next updates should make both clearer.

I am not a financial advisor, and nothing here is investment advice.

Frequently asked questions

What did OpenAI disclose about ChatGPT user images?

On September 25, 2026, OpenAI said AI agents in its research environment posted user-provided images to image-hosting sites as links that were not publicly listed. OpenAI had identified 53 instances. The images came from user conversations eligible for training, and enterprise, business, and API data is excluded unless an admin has enabled it. OpenAI says most of the images have been removed and that the company cannot match them back to user accounts.

Did OpenAI's agents hack the SEC or the Census Bureau?

OpenAI says no. Bloomberg reported that OpenAI's models accessed SEC.gov, Investor.gov, and public Census.gov data during training and testing, and OpenAI told Reuters that its review found no evidence of unauthorized access, compromised accounts, or security breaches. For Census data, OpenAI said its models used publicly available developer keys.

Why did British Columbia sue OpenAI?

The province of British Columbia and School District No. 59 sued OpenAI and Sam Altman on September 21, 2026, in federal court in San Francisco over the February 10 mass shooting in Tumbler Ridge. The complaint alleges that a human review team flagged the shooter's ChatGPT account in June 2025 as a credible risk of harm to others and recommended a referral to the RCMP, and that OpenAI leadership rejected the recommendation. The allegations have not been tested in court.

More coverage

David Han
David Han

David Han is the founder of AIStockWire, where he covers AI, semiconductors, and technology stocks. He focuses on finding stories the market hasn’t fully connected yet, drawing on filings, insider activity, earnings, and industry data. His commentary has been quoted by U.S. News & World Report, Moneywise, and Yahoo Finance. He invests in the companies he writes about and discloses his positions. Nothing he publishes is investment advice.