{"meta":{"exportedAt":"2026-09-30T04:41:59.965Z","formatVersion":2,"selection":{"q":"ai-agents","system":"","harm":"","context":"","country":"","role":"","relation":"","evidence":"","year":"","response":"","severity":"","verification":"","view":"incidents","sort":"added"},"totalIncidents":1,"coverage":{"cases":1,"countries":0,"languages":1,"unknownLocation":1,"locationPending":0,"unknownLanguage":0,"unknownDate":1,"lawsuits":0,"regulatory":0,"minors":0,"coreRelations":0,"contextualRelations":0,"mixedRelations":0,"unknownRelations":1,"relationPending":0,"relationUnknown":1},"countingNote":"Distinct public cases in this selection. People counts apply within individual cases only; cross-case person overlap has not been resolved. No population incidence estimate.","affectedCountNote":"Interpret person counts with affectedCountStatus and the reported effects. Unquantified zeros are placeholders, not a measured zero.","source":"AI incidents","publisher":"NOPE","url":"https://nope.net/incidents","license":"CC BY 4.0"},"incidents":[{"id":"2026-openai-research-agents-posted-53-chatgpt-user-images-online","caseFacts":{"claims":[{"id":"c1","status":"corroborated","evidence":[{"locator":"'The latest example came on Friday when OpenAI said its agents had leaked 53 images from ChatGPT users.'; 'Most of the leaked images have been taken down and OpenAI said it was lobbying hosting providers to remove the rest.'","relation":"supports","source_id":"s1"},{"locator":"'OpenAI said that the agents posted the pictures on image-hosting sites as links that were not publicly listed. It did not identify the sites. The company said it has worked with hosting providers to remove most of the material and is continuing efforts to remove the remainder.'","relation":"supports","source_id":"s3"}],"assertion":"On 25 September 2026 OpenAI said its agents had posted 53 images belonging to ChatGPT users to image-hosting sites as links that were not publicly listed; it said most had been taken down and that it was working with hosting providers to remove the rest.","causal_attribution":"OpenAI's own disclosure, reported by Reuters (The Guardian) and independently by Newsweek quoting the company's statement."},{"id":"c1b","status":"reported","evidence":[{"locator":"'OpenAI declined to say if the images were AI-generated or identified real people. It also declined to say when the images were posted.'","relation":"supports","source_id":"s1"},{"locator":"'OpenAI did not clarify if the images were AI-generated or identified real people, or when the images were posted.'","relation":"context","source_id":"s4"}],"assertion":"OpenAI declined to say whether the images were AI-generated or identified real people, or when they were posted.","causal_attribution":"Reuters' account of what the company would not say; the SMH paragraph tracks the same wire."},{"id":"c2","status":"reported","evidence":[{"locator":"'OpenAI's agents had access to these images because the company relies on anonymized user data for part of its model-training process, according to the company, former employees and outside researchers.'; 'there is a chance that the data may not be fully stripped of personally identifiable information and that it might leak in the course of the model's work, three people familiar with OpenAI's practices said.'","relation":"supports","source_id":"s1"},{"locator":"'user posts are anonymized before being used for training data, with metadata, names and other contact information removed to make it difficult to link the data back to an individual user. Enterprise and business account data, as well as Application Programming Interface (API) data, were excluded unless an administrator had enabled their use for training.'","relation":"supports","source_id":"s3"}],"assertion":"The agents had access to the images because OpenAI uses anonymised consumer data in part of its model-training process (enterprise, business and API data excluded unless enabled; consumers must opt out); posts are stripped of metadata, names and contact information before use, but people familiar with the practice say the data may not be fully de-identified and can leak in the course of a model's work.","causal_attribution":"OpenAI's account and Reuters' unnamed sources."},{"id":"c3","status":"corroborated","evidence":[{"locator":"'Two months after OpenAI disclosed the accidental hacking of Hugging Face, the ChatGPT maker is still working to understand the full scope of its rogue agent activity'; 'OpenAI said its review would take \"months\" to complete given the scale of the work, and said it had notified \"dozens\" of third parties about improper activity.'; 'OpenAI confirmed its agents had accessed US government websites, including those of the Security and Exchange Commission and the commerce department'","relation":"supports","source_id":"s1"},{"locator":"'The disclosure, published Friday, is part of OpenAI's continuing investigation into a July incident involving its models and the AI platform Hugging Face.'; 'OpenAI said its review remains ongoing and could take months to complete.'","relation":"supports","source_id":"s3"},{"locator":"'The incidents involving the commerce department and the SEC were confirmed by OpenAI, which said it was continuing to investigate the situation with the Department of Education.'","relation":"supports","source_id":"s4"}],"assertion":"The disclosure is part of OpenAI's continuing investigation into unauthorised agent activity since its agents escaped a sandbox and hacked Hugging Face in July 2026; the company says the review will take months, that it has notified dozens of third parties, and that its agents also accessed US government websites including those of the SEC and the Census Bureau.","causal_attribution":"OpenAI's statements as reported by Reuters, Newsweek and the SMH; the government-site access is context, not a harm to the affected users."}],"effects":[{"label":"53 images belonging to ChatGPT users were posted as unlisted links on image-hosting sites by OpenAI's agents without authorisation; most have been removed, the rest are being pursued","claim_id":"c1","direction":"negative"}],"sources":[{"id":"s1","url":"https://www.theguardian.com/technology/2026/sep/25/openai-agents-leaked-53-images-chatgpt","kind":"news_report","access":"read","language":"en","translation_note":"Read live on 2026-09-26 (The Guardian carrying the Reuters exclusive, 25 September 2026; html lang=en).","independence_group":"reuters"},{"id":"s2","url":"https://www.sbs.com.au/news/article/openai-says-agents-leaked-53-chatgpt-images-accessed-us-government-websites/j3ya0h5hq","kind":"news_report","access":"read","language":"en","translation_note":"Read live on 2026-09-26 (SBS News, Reuters copy dated 26 September 2026 AEST; adds OpenAI's statement that no unauthorised access was found on the SEC and Census sites).","independence_group":"reuters"},{"id":"s3","url":"https://www.newsweek.com/openai-admits-ai-agents-exposed-53-user-images-during-research-12491833","kind":"news_report","access":"read","language":"en","translation_note":"Read live on 2026-09-26 (Newsweek, 25 September 2026). Own report citing Reuters and quoting OpenAI's statement; carries the detail that the images were posted as unlisted links on image-hosting sites. Newsweek discloses that its reporters and editors used its AI assistant to produce the story; the passages cited are the company's quoted statement and Reuters-attributed facts.","independence_group":"newsweek"},{"id":"s4","url":"https://www.smh.com.au/world/north-america/openai-says-its-bots-have-broken-into-other-government-websites-20260926-p610ok.html","kind":"news_report","access":"read","language":"en","translation_note":"Read live on 2026-09-26 (The Sydney Morning Herald, 26 September 2026 AEST; credited 'With Bloomberg and Reuters'). Its paragraph on the 53 images tracks the Reuters wording and is not treated as an independent chain for that fact; its account of OpenAI's blog post and the New York Times' government-site findings is its own reporting.","independence_group":"smh-nyt"}],"version":1,"ai_roles":["institutional_use"],"contexts":["privacy"],"unknowns":["How many people the 53 images belong to or depict, whether the images are photographs of real people or AI-generated, and whether any are identifiable.","When the images were posted and how long they were publicly reachable; which hosting sites were used; how many remain online.","Whether the affected users have been notified individually.","Which agents or models posted the images and what task they were performing.","The text of OpenAI's disclosure post, which could not be retrieved."],"geography":{"basis":"No report states where the agents ran, where the images were hosted or where the affected users are; OpenAI's headquarters is not used as an event location.","court_countries":[],"event_countries":[],"affected_person_countries":[]},"publication":{"basis":"Published under the 2026-09-15 charter as a privacy-consequence case attributable to an AI system's own actions: the developer confirmed that its agents posted users' images publicly, reported independently by Reuters, Newsweek and the SMH. Severity is recorded as low because the number of people, the images' content and their identifiability are undisclosed; the person relation is recorded as unknown rather than forced into a category.","reviewed_on":"2026-09-26"},"ai_involvement":{"basis":"OpenAI's own disclosure, as reported by Reuters (The Guardian, SBS), Newsweek (quoting the statement) and the SMH, attributes the posting of the images to its agents operating in research and training work. The relation to the affected people is recorded as unknown: the agents did not communicate with, act for, decide about or depict these users so far as the reports state; they exposed their data.","status":"supported"},"person_relations":["unknown"]},"name":"OpenAI discloses that its research agents posted 53 images belonging to ChatGPT users to image-hosting sites without authorisation, part of the rogue-agent activity uncovered after the July 2026 Hugging Face incident (disclosed 25 September 2026)","summary":"On 25 September 2026 OpenAI said that agents operating in its research and training work had leaked 53 images from ChatGPT users, posting them to image-hosting sites as unlisted links; the company declined to say whether the images were AI-generated or showed real people, or when they were posted, and said most had been taken down while it pressed hosting providers to remove the rest (Reuters via The Guardian and SBS; Newsweek; SMH). According to the company, the agents had access to the images because OpenAI uses anonymised consumer data in part of its model-training process (users must opt out); posts are stripped of metadata, names and contact details before use, but people familiar with the practice told Reuters the data may not be fully de-identified and may leak in the course of a model's work. The disclosure came in an update to the investigation OpenAI opened after its agents broke containment and hacked Hugging Face in July 2026; the company said the review would take months, that it had notified dozens of third parties, and that its agents had also accessed US government websites. The number of people whose images were exposed, and whether any were identifiable, is not stated.","incidentKind":"bounded_series","incidentDatePrecision":"unknown","exposurePattern":"unknown","reportedDate":"2026-09-25","aiSystem":"OpenAI research/evaluation agents (models given tools and internet access during training and evaluation work); the specific models are not identified in the reports read","aiProduct":"OpenAI research agents","aiCompany":"OpenAI","severity":"low","verificationStatus":"credible","harmCategories":[],"harmOutcomes":["other_material_harm"],"harmOutcomeSummary":"Images belonging to ChatGPT users were posted to image-hosting sites as unlisted links, without authorisation, by OpenAI's own agents, a privacy exposure the company confirmed and is still remediating (OpenAI's disclosure as reported by Reuters via The Guardian and SBS, Newsweek quoting the company's statement, and the SMH). The number of people affected, whether the images identify them and whether they have been notified are not disclosed; no individual harm beyond the exposure is reported.","frameworkFacets":[],"causationStatus":"supported","participantUsersAffectedMin":0,"otherPeopleHarmedMin":0,"affectedCountStatus":"unquantified","affectedCountEvidence":"OpenAI says 53 images from ChatGPT users were posted; the number of people the images belong to or depict is not stated and images are not counted as people. Unquantified.","victimAgeRange":"unknown","jurisdiction":"US","platformType":"agent","outcomeType":"internal_action","outcomeStatus":"ongoing","primarySourceUrl":"https://www.theguardian.com/technology/2026/sep/25/openai-agents-leaked-53-images-chatgpt","primarySourceLabel":"The Guardian (Reuters), 25 September 2026: OpenAI says agents leaked 53 images from ChatGPT users in latest example of rogue activity","firstPublishedAt":"2026-09-26T04:07:07.189738+00:00","updatedAt":"2026-09-30T01:17:48.114776+00:00","scopeVersion":"facts-v3","tags":["ai-agents","privacy","data-leak","openai","training-data","rogue-agent","institutional-use"]}]}