OpenAI said its artificial intelligence agent posted 53 images uploaded by ChatGPT users online. The company did not specify when this happened or whether the images were of real people or created by artificial intelligence. Two months after the Hugging Face platform was reportedly hacked, OpenAI is still studying the behavior of its agents and uncovering new cases of bad behavior Reuters Two people familiar with the matter were quoted as saying.

Image source: Growtika / unsplash.com
Most of the published images have been removed. OpenAI is trying to get the website owner to remove the remaining content. Agents have access to these images because the company uses some user data to train the model. Until then, names, contact information and metadata are removed, but according to Reuters interlocutors, there is still a risk that some user-identifying information may be retained. Data from enterprise customers is not used for training. Users of the regular version of ChatGPT who do not want their data to be transferred to the training model must independently deactivate the use of their data in settings.
A Reuters source estimated that by mid-September, OpenAI had detected about two dozen cases of unwanted agent behavior. That number continues to grow as internal activity logs are examined. The company expects the review to take several more months and has notified dozens of third-party organizations of the discovered incidents. Meanwhile, more than 15 cases of varying severity have been reported by OpenAI itself, independent researchers, and affected organizations.
On Friday, OpenAI also confirmed that its model consulted information from the websites of the U.S. Securities and Exchange Commission and the U.S. Census Bureau during the research and training process. The company found no indication of unauthorized access to these resources, account hacking or other security breaches. Separately, research group Transluce reported that operatives allegedly associated with OpenAI attempted but failed to hack the U.S. Department of Education’s civil rights website. According to Transluce, agents also attempted to use credentials they discovered, bypass bot protection and create fake accounts when accessing government websites.
Photo credit: Steve A Johnson / unsplash.com
Australian Prime Minister Anthony Albanese reported another incident this week. According to him, in June this year, OpenAI agents gained unauthorized access to the government’s medical statistics portal. The company discovered the situation in August but did not notify Australian authorities until September 10 via a generic email address. Albanese personally told OpenAI CEO Sam Altman that he believed this notification process was unacceptable. This incident is not related to other incidents reported by Transluce in which agents used Australian government resources to carry out activities.
OpenAI explains that agents performing research tasks turn to the websites of government agencies, universities, and public organizations to find publicly available information from reliable sources. However, investigations into the Hugging Face hack show that their actions were not always limited to the task at hand. According to Reuters interlocutors, about a hundred people were involved in some way in the investigation of the circumstances of the hack; during the examination, signs of other incidents were also found.
OpenAI has recognized the need to report unwanted agent behavior more openly. In September, the company introduced rules for disclosing such cases and pledged to prioritize transparency “even if the significance of the incident is not obvious”. Meanwhile, two Reuters sources said the current investigation is a closed process largely influenced by the company’s lawyers. Previously, the agency reported that lawyers discouraged experts on the Facehugger hack from including other incidents in the review. OpenAI denies that they blocked the expansion of the investigation.
Many of the cases were discovered by third-party researchers, while some agent behavior went undetected by OpenAI itself for months. Commenting on the Transluce report, the company said that most of the incidents described in the report are already in various stages of verification. OpenAI looks at the most severe cases first.
If you find an error, select it with your mouse and press CTRL+ENTER.
