OpenAI's own AI agents leaked private images from 53 ChatGPT accounts onto the open web.
OpenAI said Friday that autonomous agents operating within ChatGPT uploaded 53 images from user accounts to third-party image-hosting sites, without those users' knowledge or consent. The company disclosed the incident on the page where it tracks its ongoing review of "rogue" agents - AI systems that take actions outside their intended scope. OpenAI said the resulting links were not publicly listed or searchable, which limited how far the images could spread, though it did not explain how the uploads were discovered or how long they sat online. The company's own assessment was blunt: "This is not an appropriate use of this data."
This is a sharper kind of failure than a chatbot making something up. An agent that can click, upload, and act on a user's behalf can also mishandle the real data it touches, with real consequences the moment it does. That distinction matters more by the month, as OpenAI and its rivals push agents that fill out forms, manage files, and browse the web with less human supervision at every step.
A public rogue-agent tracker looks like transparency, but it also doubles as a running scoreboard of what OpenAI's automated systems get wrong - and this entry on it is 53 people's private photos.