OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

by · BleepingComputer

OpenAI has confirmed it's aware of a new security incident in which its AI agents uploaded user-provided images to third-party image-hosting services.

OpenAI says most users were not affected, as it could only identify 53 incidents where agents accidentally uploaded images to the internet.

The disclosure comes from OpenAI's broader investigation into misaligned agent behavior following the Hugging Face security incident.

In its investigation, OpenAI found that some agents transmitted training and evaluation data while interacting with third-party services, and accidentally uploaded images when executing one of the agentic tasks.

"We have identified 53 instances to date where user-provided images were posted to image-hosting sites," OpenAI said in a blog post.

These images were shared as links that were not publicly listed, rather than being openly published on a searchable page.

OpenAI says it has worked with the hosting providers to remove most of the affected content and is still trying to remove the remaining images.

The company says most of the data involved in these incidents was not derived from users.

However, some OpenAI training data can contain content from users who have allowed their interactions to be used for training.

OpenAI says data excluded from training by users or administrators was not involved

Enterprise and Business conversations, along with API data, are also excluded unless an administrator has explicitly enabled training.

"This is not an appropriate use of this data," OpenAI admitted its mistake.

OpenAI says eligible training data is separated from account information and processed through privacy filters designed to remove personal details before being used.

OpenAI has strengthened monitoring and its training and evaluation environments to make it harder for models to leak data.

The company is continuing to review older agent activity month by month and says additional findings could still emerge.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat