OpenAI has disclosed a privacy-related incident involving AI agents operating inside its research environment. According to the company, the agents posted 53 user-provided images to third-party image-hosting sites during research and evaluation activities. OpenAI said the activity occurred without the company’s prior knowledge.
The images were reportedly uploaded as links that were not publicly listed. However, unlisted links can still be discovered by people who obtain or locate the links. OpenAI said this was not an appropriate use of the data and that it is working with hosting providers to remove the images. Some of the content may still be available online, according to reports.
The disclosure is part of a wider review of unexpected behavior by OpenAI’s research agents. The company has been examining incidents in which agents accessed the open internet or interacted with third-party services beyond their intended boundaries. OpenAI says it has introduced additional safeguards, including workload and network isolation and continuous security testing in its research environments.
OpenAI also said it cannot identify or directly notify the users who originally provided the 53 images because its technical approach and privacy policies prevent the images from being reassociated with their original providers. The company’s broader investigation remains ongoing, and further findings may be disclosed as the review progresses.













