OpenAI says its AI agents posted user images online
OpenAI on Friday said that its artificial intelligence (AI) tools had posted images from ChatGPT users to online sites without the company’s knowledge, the latest example of AI agents operating outside their bounds.
The company also confirmed a New York Times report that its tools had accessed Web sites of US federal agencies, saying they retrieved only publicly available information.
Links to the 53 uploaded images were not publicly listed, and were accidentally posted on image-hosting sites, OpenAI said.
OpenAI chief executive officer Sam Altman listens to a speaker at the UN Security Council during the 81st UN General Assembly in New York on Wednesday.
Photo: Reuters
Most have been removed with the help of the hosting providers involved, and removal of the remaining images is under way, the San Francisco-based tech giant said.
“We’ve shared details on how AI agents in our research environment sent training and evaluation data to third-party services when they shouldn’t have,” the company said in a social media post.
Dissemination of the images was caused by AI agents — software built on AI models and capable of acting autonomously. The images in question came from the accounts of users who had authorized the use of the data to improve OpenAI’s models. The data had been run through a privacy filter before use and could no longer be linked to the original user, the company said.
OpenAI did not specify whether the images depicted identifiable people or contained sensitive data.
OpenAI said agents that it uses for its research transmitted the training data to external platforms.
The incidents occurred before OpenAI strengthened the security protocols of its research environment last month following other rogue actions by AI agents.
The company said it is scrutinizing the activity of its AI agents, work that “will take months to complete.”
“Most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public Web content to answer questions. Some involved government Web sites, because our models often turn to them as authoritative sources of public information,” an OpenAI spokesperson said.
OpenAI chief executive officer Sam Altman on Friday acknowledged on social media that “we have not been as fast as we would have liked” in reviewing and disclosing the incidents.
However, it was important to “balance our desire for transparency” with assessing the massive volume of data to be analyzed, he said.
On July 21, OpenAI revealed that during tests it ran that month, two of its models escaped their closed environments, got onto the Internet on their own and broke into the internal systems of Hugging Face, an online library for AI software.
The episode drew wide attention and fed worries that the biggest AI companies cannot keep their own models under control.
Altman on Friday said that the Hugging Face hack “is still the most severe event we’ve seen.”
That discovery was followed by revelations of several similar incidents at OpenAI and its rivals, such as Anthropic and Meta.
On Wednesday in New York, Australian Prime Minister Anthony Albanese said an OpenAI agent had gained unauthorized access to a government health portal in June, and he accused the company of delaying its notification to the authorities.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.