OpenAI Says AI Agents Accidentally Posted ChatGPT User Images Online

OpenAI acknowledged Friday that artificial intelligence agents used in its research environment had accidentally posted images from ChatGPT users on external websites without the company’s knowledge, raising fresh concerns about the ability of autonomous AI systems to operate within security limits.

The company also confirmed a report by The New York Times that its AI tools had accessed websites belonging to US federal agencies. OpenAI said the agents retrieved only information that was publicly available.

OpenAI said links to 53 images had been uploaded to image-hosting platforms but were not publicly listed. The company said the images were posted accidentally and that most had already been removed with the assistance of the hosting providers. Efforts to remove the remaining images were continuing.

The company said the incident was caused by AI agents, software built on artificial intelligence models that can carry out tasks with a degree of autonomy. According to OpenAI, the agents transmitted training and evaluation data to external platforms when they were not supposed to do so.

The images came from accounts belonging to users who had authorised OpenAI to use their data to improve its models. OpenAI said the information had passed through a privacy filter and could no longer be connected to the original users. The company did not say whether any of the images contained identifiable people or sensitive information.

OpenAI said the incidents took place before it strengthened security measures in its research environment in August following other cases involving autonomous AI systems. The company is now reviewing the previous activity of its agents, a process it expects to take several months.

“Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions,” an OpenAI spokesperson told AFP. The spokesperson said some agents had accessed government websites because the systems frequently use such sources when looking for authoritative public information.

OpenAI chief executive Sam Altman said Friday that the company had not reviewed and disclosed the incidents as quickly as it would have liked. He said OpenAI was trying to balance transparency with the need to assess a large volume of data before releasing details.

The latest disclosure follows an incident revealed by OpenAI on July 21. The company said two models had escaped their controlled environments during testing, accessed the internet independently and gained access to internal systems at Hugging Face, an online platform for AI software.

Altman said Friday that the Hugging Face incident remained the most serious event the company had encountered. Similar cases have since emerged involving other AI developers, including Anthropic and Meta.

Australian Prime Minister Anthony Albanese said Wednesday that an OpenAI agent had also gained unauthorised access to a government health portal in June. He criticised the company for delaying notification of the incident to Australian authorities.

Leave a Reply