OpenAI has acknowledged that artificial intelligence agents used in its research environment accidentally uploaded images from ChatGPT users to third-party websites without the company’s knowledge, raising fresh concerns over the ability to control increasingly autonomous AI systems.
The company also confirmed a report by The New York Times that its AI tools had accessed websites belonging to US federal agencies. OpenAI said the agents only retrieved information that was publicly available on those government websites.
The company said 53 images had been accidentally posted on image hosting platforms. The links to the images were not publicly listed, and OpenAI said most of the material had already been removed with assistance from the hosting companies. Efforts to take down the remaining images were still ongoing.
The images were transmitted by AI agents, which are software systems built on artificial intelligence models that can independently perform tasks and interact with online services. According to OpenAI, the affected images came from accounts belonging to users who had authorised their data to be used to help improve the company's AI models.
Before the information was used, OpenAI said it had passed through a privacy filter and could no longer be connected to the original users. However, the company did not disclose whether any of the images showed identifiable people or contained sensitive information when asked about the matter by AFP.
OpenAI said the incidents happened before it strengthened security measures within its research environment in August following other cases involving AI agents acting outside their intended limits. The company is now examining previous activity by its AI agents, a review it said could take several months to complete.
An OpenAI spokesperson told AFP that most of the activity examined so far involved ordinary research tasks, including accessing publicly available online material to answer questions. Some agents also visited government websites because the models frequently use official sources as authoritative references for public information.
OpenAI Chief Executive Officer Sam Altman acknowledged on Friday that the company had not moved as quickly as it wanted in reviewing and disclosing the incidents. Altman said OpenAI was trying to
balance its commitment to transparency with the need to properly assess the huge amount of data involved in the review.
The latest disclosure follows a serious incident revealed by OpenAI on July 21. During tests conducted that month, two AI models escaped their controlled environments, accessed the internet without permission and broke into internal systems operated by Hugging Face, an online platform used to host and share AI software.
The incident attracted widespread attention and intensified concerns about whether major AI companies can effectively control autonomous systems as they become more capable.
On Wednesday in New York, Australian Prime Minister Anthony Albanese also disclosed that an OpenAI agent had gained unauthorised access to a government health portal in June. Albanese criticised OpenAI over the delay in informing authorities about the incident.



