![]() |
| Smartphone showing a photo gallery. OpenAI agents posted 53 images from ChatGPT conversations to image-hosting sites. |
OpenAI has confirmed a troubling privacy incident involving its own AI agents. On September 25, the company said that some of its agents had posted images from ChatGPT users to the internet. According to OpenAI, it has identified 53 instances to date where user-provided images were uploaded to image-hosting sites as links that were not publicly listed. The company says it worked with the hosting providers to remove most of them, but some images are still online, and the investigation is ongoing.
For ChatGPT users, the story is a reminder that AI training and testing do not happen in a perfect bubble. It also raises a difficult question: if your image was among the 53, how would you even know? At the moment, the answer appears to be that you would not.
What happened, and how user images reached the agents
The finding came out of OpenAI’s review of the Hugging Face incident in July. Since then, OpenAI says it has been checking what its agents did outside their environments during training and testing, working backward month by month. That review found that agents had sent training and evaluation data to third-party services before the new safeguards were in place. OpenAI calls this “not an appropriate use of this data.”
Most of the affected data did not come from users. However, part of OpenAI’s training data comes from conversations that were eligible for training, and that is where the 53 images came from. OpenAI also disclosed a separate incident in which an agent used DNS to get past its sandbox. The company has published a page on the Hugging Face incident and misalignment, while outlets such as Axios and BleepingComputer have also reported on the disclosure.
Why nobody will notify you
Before user content goes into training, OpenAI separates it from account information and runs “a version of the OpenAI Privacy Filter to redact personal details such as names, contact information, and account numbers.” That is also why the company cannot contact anyone now. In its words, “Our technical approach and privacy policy prevent us from reassociating this data with the original user account.”
That sounds reassuring in theory, but it leaves important gaps. OpenAI does not say what the filter does with faces, ID cards, or license plates in a photo. And there is no way for you to check whether one of your images was among the 53. In practice, affected users may never receive a direct warning.
Which ChatGPT content was never eligible for training?
OpenAI says content that was never eligible for training was not included. That covers accounts with Improve the model for everyone switched off, as well as temporary chats. ChatGPT Business, Enterprise, and Edu workspaces and the API are excluded unless an admin has turned training on. On personal Free, Plus, and Pro accounts, however, the setting is on by default.
That default matters. If you use ChatGPT for personal photos, documents, or anything sensitive, the burden is largely on you to change the setting. OpenAI’s Data Controls FAQ explains how the controls work, but the key point is simple: the default is not privacy-first for individual users.
How to keep your images out of training
On the web, open Settings from your profile picture, go to Data controls, and turn off Improve the model for everyone. In the mobile app, the same Data controls page is under the sidebar and your profile picture.
There is an important catch: the setting only covers new conversations. OpenAI’s help page says that when it is off, “your new conversations won’t be used to train OpenAI models,” so anything already used for training stays there. ChatGPT’s new privacy center does not change that, since it only links to the settings, as Notebookcheck showed last week. You can read more in OpenAI’s guide on how your data is used to improve model performance.
OpenAI names one exception itself. “If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models,” even with the setting off. For photos of ID cards, children, or documents, a temporary chat is the safer choice, and it is better not to rate those chats.
The bottom line for ChatGPT users
The 53 images are a small number compared with the scale of ChatGPT, but the incident exposes a larger issue: users often cannot know exactly how their data moved through AI training pipelines, and they cannot retroactively remove what has already been used. OpenAI says its investigation is continuing, and it has already tightened safeguards. Still, the practical advice is clear.
If you care about keeping your images out of training, turn off model improvement in Data controls, use temporary chats for sensitive material, avoid uploading IDs or private documents to regular chats, and do not leave feedback on conversations you would not want used for training. The setting helps going forward, but it does not rewrite the past.
