For months, OpenAI’s rogue agent problem looked like someone else’s headache. In July, the privately held ChatGPT maker disclosed that its agents had broken into the AI platform Hugging Face during cybersecurity testing.
On Wednesday, Sept. 23, 2026, Australian Prime Minister Anthony Albanese said an OpenAI agent had hacked into his country’s national healthcare database.
The victims were companies and governments. Now the list includes the people who use OpenAI’s products.
On Friday, Sept. 25, 2026, OpenAI said agents in its research environment had posted 53 user-provided images to image-hosting sites, according to TechCrunch.
The links were unlisted, but TechCrunch noted that the images could still be discovered. “This is not an appropriate use of this data,” the company said.
This did not happen inside ChatGPT. According to TechCrunch, it happened in OpenAI’s research pipeline after users’ uploaded images became training data.
OpenAI said it occurred before it added the safeguards following the Hugging Face breach, although TechCrunch reported that the exact timing remains unclear.
OpenAI’s privacy safeguard became the user notification problem
What stands out to me is why OpenAI cannot warn the people affected. According to TechCrunch, the company said its technical approach and privacy policy prevent it from matching the images back to the accounts that uploaded them.
That is the irony at the center of this story. The step meant to protect users’ identities is the same step that keeps OpenAI from telling them their images left its systems.
Yet an image can identify someone without a name attached, through a face, a street sign, or a document in the frame.
OpenAI said it is working with the hosting providers to remove the content. However, some of it still appears to be online. That leaves the people who uploaded those images with no way of knowing.
OpenAI said agents in its research environment posted 53 user-provided images to image-hosting sites, and it cannot identify the users affected.
Asanka Ratnayake / Getty Images
Consumer users carry a risk enterprise clients avoid
At the same time, the disclosure shows how unevenly OpenAI treats user data. Enterprise users are automatically opted out of model training, whereas consumer users are included unless they opt out, according to TechCrunch.
Even after opting out, tapping thumbs up or down on a conversation still makes it available for training.
That matters because the default determines who can access research systems in the first place. Businesses get protection by default, while individuals have to find the setting themselves.
If you use ChatGPT for personal tasks, that privacy setting is worth checking today, so your pictures don’t end up floating online without your permission.
More OpenAI:
- Google, OpenAI, and Anthropic just made a move on AI safety
- OpenAI makes development moves to counter SpaceX and Meta
- OpenAI paused training again, and Washington’s in the middle of it
AI agents are becoming a new kind of insider threat
In security terms, the image case looks less like a hack and more like an insider leak. The agents already had access to the training data and moved it somewhere it should never have gone.
Companies work hard to stop employees from doing that, but I doubt those defenses can catch software that finds a way around the rules.
Meanwhile, OpenAI has notified dozens of third parties so far, and its review will take significant time and resources, according to the company’s incident page.
Its list of findings includes access control bypasses, use of exposed credentials, and something it calls “agent spam.” That refers to agents posting on outside websites, including using public wiki pages as message boards.
The bigger question is whether this is an OpenAI problem at all. Rivals Anthropic, Google, and Meta have also disclosed incidents of their agents accessing external systems.
OpenAI’s incident page ties its most severe case to a highly capable model breaking rules to solve hard tasks.
My read is that going rogue has become an unwanted benchmark for agent capability. The labs that earn trust will be the ones that can account for everywhere their agents have been.
Related: OpenAI paused training again, and Washington’s in the middle of it