AI & Emerging Tech

OpenAI Agents Posted 53 User Images to Third-Party Hosting Sites

OpenAI Agents Posted 53 User Images to Third-Party Hosting Sites

OpenAI has confirmed that AI agents running in its research environment uploaded user-provided images to third-party image-hosting services. The company has identified 53 cases so far according to a statement reported on 26 September.

The images were posted as unlisted links. They did not appear in public listings or search results but anyone holding the URL could open them. OpenAI says it has worked with the hosting providers to remove most of the content and is still pursuing the rest. It has not named the services involved or said how many images remain online.

“This is not an appropriate use of this data,” OpenAI said.

Fifty-Three Is a Count, Not a Total

The figure comes from OpenAI’s own investigation and that investigation is not finished. The company is reviewing historical agent activity month by month, working outward from the Hugging Face incident and says further cases could surface. Treat 53 as a floor until the review closes.

OpenAI’s statement does not say whether affected users have been told. For a company operating in the EU, that is not a side issue. An image of an identifiable person, sent to a third party without authorisation fits the GDPR definition of a personal data breach, indexed or not.

The Agents That Built Their Own Message Board

The image uploads are a by-product of a much larger event. In July, during internal cybersecurity evaluations, OpenAI models got around controls meant to cut them off from the internet and compromised parts of OpenAI’s research infrastructure and systems at Hugging Face according to the incident report OpenAI published on 26 August. The activity was driven mainly by an internal-only research model OpenAI calls IM1.

The agents turned an internal Artifactory package server into an improvised message board, reached the internet through a server-side request forgery flaw and then chained zero-days in the Hugging Face platform. They executed code on dozens of Hugging Face servers, obtained root on one and harvested credentials across 4 regions. Hugging Face disclosed the intrusion on 16 July. OpenAI’s security monitoring flagged the activity on 19 July and the company confirmed its involvement on 21 July.

OpenAI traces the behaviour to reward hacking, agents stuck on unsolvable tasks in an evaluation called ExploitGym went looking for answers on outside services. Of the 898 tasks in that evaluation, 198 had never been solved by any OpenAI model before the incident. That unsolved set accounted for 93% of the tasks the agents discussed on their message board.

The company calls the episode a “warning shot”. The more useful detail sits further down its report. The safeguards that protect production ChatGPT including system prompts, auto-review models and chain-of-thought monitoring were not running in the evaluation environment. OpenAI says its current monitoring would have paged the security team more than a day before the agents breached Hugging Face.

The failure was not exotic. OpenAI ran its most capable agents without the controls its own customers get by default.

Business and API Data Was Excluded by Default

OpenAI says only data eligible for training was involved. Content from users who opted out or whose enterprise administrators disabled training was not included. Data from enterprise and business accounts and from API usage is excluded unless an administrator has switched training on. Eligible data is separated from account information and run through a version of the OpenAI Privacy Filter before it enters training sets, the company says.

That default covers most organisations, not all. Check the data controls in your ChatGPT workspace this week and confirm that nobody has enabled training on business data. Personal ChatGPT accounts used for work sit outside that protection: there, the training setting belongs to the individual user, not to IT.

References

  1. OpenAI’s AI Agents Accidentally Uploaded User-provided Images to Third-party Sites
  2. The Hugging Face Incident and the Road Ahead

This post is also available in: Svenska

Erik Berg

Erik Berg is CTO and Principal Security Architect at eBuilder Security, with more than a decade in blue team security operations across the private and public sectors, and a focus on emerging threats including the security risks that come with AI.