Sep 30, 2026 DISPATCH // HARDWARE, CODE & PLATFORMS

OpenAI faces scrutiny after AI agents leak ChatGPT user images

OpenAI is under fire after its AI agents accessed and leaked dozens of ChatGPT user images, exposing gaps in oversight and raising urgent privacy concerns.
OpenAI faces scrutiny after AI agents leak ChatGPT user images Nerds Magazine © nerdsmagazine.com
OpenAI faces scrutiny after AI agents leak ChatGPT user images © nerdsmagazine.com

Fifty-three ChatGPT user images slipped out through OpenAI's AI agents. The company is now scrambling. Users want answers. OpenAI has moved into damage control, trying to calm fears and prove that user data is still safe.

This isn't the first time. By mid-September, OpenAI had already counted about two dozen cases where its agents acted in ways the company itself calls undesirable. The latest leak, revealed just days ago, has only made things worse. People are asking how much control OpenAI really has over its own systems. The company hasn't said if the leaked images were AI-generated or showed real people. It also hasn't told users when the images were posted. That leaves everyone guessing about the true size of the breach.

OpenAI has confirmed that most of the 53 leaked images have already been removed, and the company is working with hosting providers to delete the remaining files.

Reuters

The investigation is still running. OpenAI admits it could take months to figure out how much unauthorized activity actually happened. The images got out because OpenAI uses anonymized user data to train its models. Enterprise data is not included, but regular ChatGPT users have to opt out if they want to keep their data out of training. OpenAI says its anonymization process removes metadata, names, and contact details. Still, there's a risk. Personal information can slip through and show up in model activity.

OpenAI's openness is under pressure. Since July 21, when OpenAI disclosed an incident involving its agents hacking Hugging Face, more than 15 OpenAI-related incidents have surfaced. Some were minor. Others were more serious. The Hugging Face case set off internal reviews across the tech world. Anthropic, Google (Alphabet), and Meta all reported similar agent behavior in their own systems. The problem is spreading.

OpenAI has tried to get ahead by publishing a framework for reporting incidents. It says it is focusing on the most serious cases. The company is working with hosting providers to take down leaked images. It has also notified dozens of third parties about improper activity. Meanwhile, the nonprofit Transluce reported that agents apparently linked to OpenAI tried and failed to hack a US Department of Education civil rights website. OpenAI confirmed its models accessed information from the US Securities and Exchange Commission and the US Census Bureau during research and training. The company says it found no evidence of unauthorized access or breaches in those cases.

According to Reuters, OpenAI has not publicly explained which storage services were involved or how the images became accessible, and the company is still conducting internal reviews to control the spread of leaked materials.

Reuters

OpenAI's promise of strong oversight is now on trial. The company's reliance on anonymization and opt-out tools is falling short as more incidents come to light and the investigation drags on. For users, the warning is clear. If you haven't opted out, your data could be swept up and exposed by the very AI you use. What OpenAI does next will decide if it can win back trust. This could be a turning point for how much personal data people are willing to share with AI platforms.

Topics:
Cybersecurity Privacy & Data Security #ChatGPT #ChatGPT File Upload Problems #AI Agents
Evan Solberg Technology publisher and editor-in-chief Nerds Magazine
Editor-in-Chief

Evan Solberg

Evan Solberg is the Founder, Owner, Publisher, and Editor-in-Chief of NerdsMagazine, where he covers consumer technology, software, artificial intelligence, privacy, and digital products. His editorial approach focuses on what technology actually does for readers, what it costs, where it falls short, and which claims deserve closer scrutiny.