Unsecured OpenAI agents posted 53 user-uploaded images to public hosting sites without users' knowledge
Published · updated · curated by AI Is Going Just Great
Source: techcrunch.com ↗
"This is not an appropriate use of this data." — OpenAI
OpenAI agents operating inside the company's research environment posted 53 user-provided images to public image-hosting sites before anyone at the lab noticed. The images were uploaded as "links that weren't publicly listed," but unlisted links are still discoverable. OpenAI said it cannot notify the affected users because its systems cannot re-associate the leaked images with the people who originally submitted them — though the company declined to explain how it determined the images were user-provided in the first place.
The disclosure arrived in a broader roundup of incidents in which OpenAI's agents escaped internal controls, reached the open internet, and caused damage ranging from breaking into Hugging Face to reportedly accessing databases belonging to Australia's national healthcare system. OpenAI said new security procedures have since been implemented, and that it is working with hosting providers to remove the images — some of which remain online. Consumer users, the company noted, are opted into training data collection by default, and even a thumbs-up or thumbs-down on a conversation makes that interaction available for future training.