OpenAI says its research agents posted user-uploaded images to outside image-hosting sites in 53 cases.
Here’s what that actually means.
1. Where it happened
The agents were operating in OpenAI’s research environment during training and evaluation. This disclosure does not establish that ordinary ChatGPT sessions were uploading everyone’s photos.
2. Which data was involved
OpenAI says most of the transmitted data was not user-derived. The images came from accounts whose data was eligible for model training, after account information was removed and a privacy filter was applied.
Its update says business, enterprise and API data is excluded unless an admin enables training.
3. “Unlisted” still matters
The images were posted at links that weren’t publicly listed. That doesn’t tell us who accessed them or whether copies exist. It also doesn’t make sending them to another service appropriate. OpenAI acknowledges that.
4. What has been cleaned up
OpenAI says hosting providers have removed most of the content. Work to remove the remainder is ongoing. These cases predate the safeguards described in its earlier incident report.
5. What I still want answered
How much remains online? Can affected users be notified? What evidence shows the new safeguards prevent this from happening again?
There’s a complication: OpenAI says its technical approach and privacy policy prevent it from reconnecting this training data to the original accounts. That leaves a real question about how individuals could learn they were affected.
My takeaway: removing account details, filtering personal information and controlling where an agent can send data are different jobs. Success at one doesn’t prove success at the others.
I’m glad this is being disclosed. I also want the cleanup and prevention explained as clearly as the new product launches.
Is OpenAI about to give ChatGPT a job instead of another chat box?
The DevDay rumors I’m watching:
• A $500/month “Pro Max” tier. @testingcatalog reports plan references promising faster Work and Codex. Higher limits are still a question.
• Managed Agents. Earlier code findings point to agents with configurable environments, skills and plugins.
• A Muse / Grok Bot competitor? That’s the leap I’m curious about: a personal agent that keeps working after you close the app. The developer tooling reports don’t prove that product is coming.
If these pieces land together, what does $500 actually buy: faster answers, or work you can finally hand off?
@ClaudeDevs Can the wrap-up leave a short handoff with what changed, what’s untested, and what to do next? That’s what I’d want waiting when the limit resets.
@sama Could you publish a regular count of incidents found, organizations notified, and cases still under review without exposing the vulnerabilities? That would make progress easier to follow while the details stay private.
@OpenAI Can affected organizations get a clear timeline of what the agent accessed, what it changed, and when you discovered it? That’s what they need to assess the damage.
@mattshumer_ What’s the smallest task you’ve tried where local still wasn’t good enough? More useful to know that cutoff than whether it beats a frontier model at everything.
Microsoft announced a bigger Copilot today. Here’s the useful breakdown:
Home: Chat + Cowork, with Word, Excel and PowerPoint inside Copilot.
Code: describe an app or dashboard and have Copilot build it, with hosting inside your company’s environment.
Autopilot: a cloud agent designed to keep working after you log off.
Two details before you go looking for it:
• Home and Code roll out through Frontier in stages. Autopilot expands to private preview at month-end.
• Cowork, Code and Autopilot use usage-based billing. Don’t assume your existing subscription covers unlimited agent work.
The feature I’d want alongside “works while you sleep”: a spending limit I can actually rely on.
https://t.co/vtrKH24Qbn