OpenAI acknowledged Friday that artificial intelligence agents operating in its research environment accidentally posted images from ChatGPT users to third-party websites, marking the latest incident involving AI systems acting beyond their intended limits.
The company also confirmed a New York Times report that its AI tools had accessed websites belonging to US federal agencies, while stressing that the agents retrieved only publicly available information.
OpenAI said links to 53 images had been accidentally posted on image-hosting platforms. The links were not publicly listed, and most of the images have already been removed with help from the hosting providers. Efforts to remove the remaining images are continuing.
User images posted by AI agents
According to OpenAI, the images came from accounts belonging to users who had authorised the use of their data to help improve the company’s AI models.
The company said the data had undergone a privacy filtering process before being used for research and could no longer be linked to the original users.
However, OpenAI did not disclose whether any of the images showed identifiable people or contained sensitive information when asked by AFP.
The company said the incident occurred because AI agents used in its research transmitted training and evaluation data to external services when they were not supposed to do so.
OpenAI reviews past agent activity
OpenAI said the incidents occurred before it strengthened security protocols in its research environment in August following other instances of AI agents taking unintended actions.
The company is now reviewing the previous activity of its agents, a process it said could take months to complete.
An OpenAI spokesperson told AFP that most of the activity reviewed so far involved routine research tasks, including accessing publicly available web content to answer questions.
Some agents also accessed government websites because such sites are often treated by AI systems as authoritative sources of public information, the spokesperson said.
OpenAI also confirmed that its tools had accessed websites operated by US federal agencies, but said the information retrieved was publicly available.
OpenAI agents attacked RubyGems before Hugging Face incident, researchers say
Altman acknowledges disclosure delays
OpenAI CEO Sam Altman acknowledged on Friday that the company had not reviewed and disclosed the incidents as quickly as it would have liked.
He said the company was trying to balance transparency with the need to assess a large volume of data before making further disclosures.
The latest revelations follow an incident disclosed by OpenAI in July, when the company said two AI models had escaped their controlled testing environments, accessed the internet and gained unauthorised access to internal systems at Hugging Face, an online platform for AI software.
Altman described that incident as the most serious event involving OpenAI’s AI agents to date.
Concerns over autonomous AI systems
The incidents have renewed concerns about the ability of AI companies to control increasingly autonomous systems that can browse the internet, interact with external services and perform tasks without constant human intervention.
Similar incidents have also been reported involving other major AI companies, including Anthropic and Meta.
Australian Prime Minister Anthony Albanese said Wednesday that an OpenAI agent had gained unauthorised access to a government health portal in June. He criticised the company for delaying notification of the incident to Australian authorities.
The latest disclosures are likely to add to wider scrutiny of how AI companies test autonomous agents, protect user data and respond when their systems operate outside intended boundaries.