AI, Science, Security

OpenAI’s AI agents accidentally uploaded user-provided images to third-party sites

OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. OpenAI says most users were not affected, as it could only identify 53 incidents where agents accidentally uploaded images to the internet. The disclosure comes from OpenAI's broader investigation into misaligned agent behavior following the Hugging Face security incident.

In its investigation, OpenAI found that some agents transmitted training and evaluation data while interacting with third-party services, and accidentally uploaded images when executing one of the agentic tasks. "We have identified 53 instances to date where user-provided images were posted to image-hosting sites," OpenAI said in a blog post. These images were shared as links that were not publicly listed, rather than being openly published on a searchable page.

OpenAI says it has worked with the hosting providers to remove most of the affected content and is still trying to remove the remaining images. The company says most of the data involved in these incidents was not derived from users. Some OpenAI training data can contain content from users who have allowed their interactions to be used for training.

OpenAI says data excluded from training by users or administrators was not involved Enterprise and Business conversations, along with API data, are also excluded unless an administrator has explicitly enabled training. "This is not an appropriate use of this data," OpenAI admitted its mistake. OpenAI says eligible training data is separated from account information and processed through privacy filters designed to remove personal details before being used.

AI agents operating in OpenAI's research environment posted user images on public image-hosting sites without the lab's knowledge. After images that users uploaded to OpenAI models were included in training data, AI agents operating in the companyโ€™s research environment posted them on public image hosting sites.

Fifty-three โ€œuser-provided imagesโ€ were โ€œposted to image-hosting sites as links that werenโ€™t publicly listed,โ€ the company said for the first time. The images could still be discovered even if the links were not publicly listed.

โ€œThis is not an appropriate use of this data,โ€ the company said, stating the obvious. While the companyโ€™s privacy policy lists many uses of personal data collected from users, this kind of activity isnโ€™t one of them.

OpenAI said it was working with the hosting providers to remove this content, though some of it is apparently still online. OpenAI said it could not notify the affected users because โ€œour technical approach and privacy policyโ€ prevent it from โ€œreassociatingโ€ the images with the original providers, but declined to say how the lab determined whether the images were The news came in a post collecting public statements from the labโ€™s ongoing review of incidents in which its models escaped the companyโ€™s scrutiny, accessed the open internet, and misbehaved in various ways.

OpenAI said it would continue disclosing anonymized accounts of incidents like these, and said it had contacted dozens of victims, including governments, universities, public agencies, to notify them of the agentsโ€™ activities. This week, Australian prime minister Anthony Albanese said OpenAI agents broke into databases operated by his countryโ€™s national healthcare system, one of multiple cybersecurity incidents this year apparently caused by an OpenAI training or evaluation program.

According to OpenAI, its agents posted user-provided images on the internet before the company implemented a series of new security procedures, although exactly when or why this happened remains unclear. The new safeguards were instituted after its agents broke into Hugging Face, a platform for AI models and benchmarks.

The leakage of these images was revealed as the company faces allegations from mathematicians that OpenAI models cribbed from their work to solve long-standing problems in the field, which the lab denies. Questions about data privacy and security also complicate efforts to deploy AI tools in workplaces or to sell LLM-based assistants for consumers.

OpenAI stressed that its enterprise users are automatically opted out of having their interactions used to train future models; however, consumer users are opted in unless they affirmatively choose not to share their data. Even then, clicking the thumbs-up or thumbs-down button on a conversation will still make that interaction available to train future models.

This story has been updated to include OpenAIโ€™s statement that it is unable to identify the users that provided the images that were publicly posted. Topics AI, OpenAI When you purchase through links in our articles, we may earn a small commission.

This doesnโ€™t affect our editorial independence. Tim Fernholz Senior Reporter Tim Fernholz is a journalist who writes about technology, finance and public policy.

He has closely covered the rise of the private space industry and is the author of Rocket Billionaires: Elon Musk, Jeff Bezos and the New Space Race. Formerly, he was a senior reporter at Quartz, the global business news site, for more than a decade, and began his career as a political reporter in Washington, D.C.

You can contact or verify outreach from Tim by emailing tim.fernholz@ com or via an encrypted message to tim_fernholz.21 on Signal. View Bio October 13 โ€“ 15 San Francisco Your next big connection is at Disrupt.

Connect with 10,000+ founders, VCs, operators, and tech leaders. Explore tomorrowโ€™s breakthroughs, hear whatโ€™s shaping tech today, and save up to $200 by Sept.

BOOK NOW Most Popular Waymo is scaling fast: Hereโ€™s what the fleet data shows Kirsten Korosec Everything new coming to Metaโ€™s AI agent Muse Kirsten Korosec Lucas Ropek Meta made a Tamagotchi-like wearable for its Muse AI agent Lucas Ropek Anthropic says its biology lab has already found something big Julie Bort PitProโ€™s first tire-changing robot goes live in Canada Sean O'Kane Anthropic releases Opus 5.5 with lower prices and Fable-level performance Russell Brandom Metaโ€™s Muse is outpacing ChatGPTโ€™s early mobile launch Sarah Perez.


Discover more from ChuckysCarnage

Subscribe to get the latest posts sent to your email.

Leave a comment