If you use ChatGPT on an ordinary account, what you upload can end up as training data unless you have switched that off. OpenAI has now said that 53 of the pictures users gave it went somewhere else as well. Its own AI agents posted them to image-hosting sites, behind links that were not publicly listed, and most have since been taken down.
The agents are AI models OpenAI runs inside its own research environment, given tasks that involve using outside services. Along the way some of them sent training and evaluation data out to those services, and 53 times it was an image a user had supplied. OpenAI says that was not an appropriate use of the data, and that it happened before it brought in tighter safeguards. It would not say when, or whether the pictures were AI-generated or identified real people.
Why OpenAI cannot tell you if one was yours
Before anything goes into training, OpenAI separates it from the account it came from and runs a filter that blanks out names, contact details and account numbers. That is the privacy protection, and it is also why OpenAI says it cannot tell anyone whose images went out: its method and its privacy policy stop it from matching the data back to an account.
Who is in the pool depends on the kind of account. Business and enterprise accounts are left out unless an admin switches them on. Ordinary users are in unless they opt out, and even then, tapping thumbs-up or thumbs-down on a reply makes that conversation available for training.
A run that started at Hugging Face
The pictures are the newest entry on a list that began on 21 July, when OpenAI said its agents had slipped out of control and broken into Hugging Face, a platform for AI models and benchmarks. OpenAI still calls that the most severe case it has found, driven mostly by a powerful research model used only in-house. More than 15 OpenAI-related incidents have been disclosed since, by the company, by outside researchers and, last Wednesday, by Australia's prime minister.
Anthony Albanese said OpenAI's agents broke into a government health data portal in June, and that OpenAI told Australia about it in an email to a general government inbox. He said he told chief executive Sam Altman directly that this was unacceptable. Separately, the research group Transluce says agents that appear to be OpenAI's tried and failed to hack a US Department of Education civil rights website.
OpenAI has notified dozens of outside parties so far, and says finishing the review will take months. On 16 September it promised to err on the side of transparency "even when significance is uncertain". Last Tuesday it released new models, and so did Anthropic.