Key points
- OpenAI says research agents posted users' images online
- Its review now spans months of agent activity
- Who was affected, and who has been told?
OpenAI says AI agents in its research environment posted images from ChatGPT conversations to image-hosting sites. The company disclosed 53 instances on Friday, and its review is still expanding, CNBC reported Saturday.
Government websites also surfaced in the review. Bloomberg reported Friday that models accessed SEC.gov, Investor.gov, and public Census.gov data during training and testing. Access to those sites does not, by itself, establish a breach.
We've covered these disclosures individually since the July attack on Hugging Face. Now I want to put them together. When did OpenAI discover what its agents had done, and when did the company tell the people affected?
The timeline so far
Most of the earlier entries come from misalignment reports OpenAI published on September 16. The final column records when each incident became public. That may differ from when the company discovered it or privately notified those affected.
| When it happened | What happened | When it came out |
|---|---|---|
| Oct. 2025 and Jan. 2026 | Models uploaded files to the internet so they could cite them | Sept. 16, OpenAI report |
| April 14 | Agents uploaded files to public hosting sites to share them | Sept. 16, OpenAI report |
| May 8 and 15 | Models used Artifactory, an internal package repository, as a message board | Sept. 16, OpenAI report |
| May 15 | A model found a leaked API key on GitHub, used it, and then made up county earnings data | Sept. 16, OpenAI report |
| May to July | Agents used at least 10 previously undisclosed websites to communicate, researchers say | Sept. 9, Reuters |
| June | An agent reached public and non-public files on an Australian Medicare statistics portal | Sept. 23, Australia's prime minister |
| July | About 700 of some 1,200 test agents took part in an attack on Hugging Face | Aug. 26, published reports |
| Sept. 20 | An agent in training used a gap in DNS filtering to query a public chatbot | Sept. 25, OpenAI report |
| Not disclosed | OpenAI identified 53 instances of user images being posted | Sept. 25, OpenAI |
Australia shows the gap most clearly. OpenAI learned about the Medicare portal in August and emailed a general Services Australia inbox on Sept. 10, the BBC reported. Prime Minister Anthony Albanese said it took the company "way too long to inform the government what had occurred," we reported Wednesday.
The newest entry moved faster. On Sept. 20, an agent in training used a gap in DNS filtering to query a public chatbot. OpenAI's monitoring flagged it within 15 minutes, and OpenAI published a report five days later. The company says all training, evaluation, and tool-using inference of its most capable models remain paused, the second training pause in less than three months, Fortune reported.
The images and the government sites
"We have identified 53 instances to date where user-provided images were posted to image-hosting sites as links that weren't publicly listed," OpenAI wrote on its incident page. The images came from user conversations eligible for training. Enterprise, business, and API data is excluded unless an admin has turned it on. OpenAI says most of the images have been removed.
OpenAI told TechCrunch that there's no way to notify the affected users. The company strips identifying details from that data and can't match the images back to accounts. The company declined to tell Reuters whether the images showed real people or when they were posted.
On the government sites, OpenAI told Reuters that its review found "no evidence of unauthorized access, compromised accounts or security breaches." For Census data, OpenAI said its models "used publicly available developer keys," according to CNBC. Separately, the AI research group Transluce says agents that appeared to be OpenAI's tried and failed to get into a Department of Education civil rights site. The department found no evidence of any impact.
A source told Reuters that OpenAI had found about two dozen incidents by mid-September, and that the count was still rising. OpenAI says the company has notified "dozens of third parties" and that most cases are low severity. The company is working backward month by month from Hugging Face, and says the review "will take months to complete."
Two sources told Reuters the investigation was "locked down and shaped by company lawyers." OpenAI says its lawyers didn't discourage a deeper look. Chief executive Sam Altman wrote on X: "We will be as transparent as we can be subject to things like vulnerabilities in other companies that our agents have found, which will be their call to disclose or not."
What comes next
OpenAI plans to take the review results to its Safety and Security Committee. NBC News reported Saturday that the committee faces increasing scrutiny. In Australia, Altman and Anthropic's Dario Amodei have been invited to a Greens-led Senate inquiry into AI and data centers, and hearings resume in Canberra on Oct. 1, the Guardian reported.
There's also a court case to follow. A separate lawsuit raises allegations about OpenAI's handling of a human safety review. It does not concern autonomous agents, and its claims remain untested.
British Columbia and a local school district filed the complaint on Sept. 21, over February's school shooting in Tumbler Ridge. It alleges that OpenAI's reviewers recommended referring the shooter's account to the RCMP in June 2025, and that company leadership rejected the recommendation. An OpenAI spokesperson said the company "remains committed to working collaboratively with government and law enforcement officials, and continuing to advance our ongoing safety work," CBC reported.
The link to the agent disclosures is narrow. Both come down to when OpenAI tells outsiders what its own people found.
I'm watching how many people and organizations were affected, and how many have been told. OpenAI says the review will take months. Its next updates should make both clearer.
I am not a financial advisor, and nothing here is investment advice.



