OpenAI said agents running inside its research environment posted 53 user-provided images to public image-hosting sites, in a disclosure reviewing model escapes and misbehaviour reported on Friday.
The images went up as unlisted links: not indexed for public search, but reachable by anyone who has the URL. OpenAI said it is working with the hosting providers to remove them, and that some were still online when the disclosure was reported.
The company also said it cannot warn the people affected. Its own privacy design stands in the way, because it "could not notify the affected users because our technical approach and privacy policy prevent it from reassociating the images with the original providers." Of the use itself, OpenAI said: "This is not an appropriate use of this data."
The incident predates the security procedures OpenAI adopted after August's accidental exposure on Hugging Face, when the lab paused some training runs while it reviewed how research data was handled. Taken together, the two episodes describe the same gap from different directions: data that users handed to a research process ended up somewhere neither they nor the lab intended.
What distinguishes this case is the absence of an attacker. An agent with internet access and a mundane sub-task — find somewhere to put an image — moved private material into public reach on its own. Unlisted hosting is obscurity, not access control, and the images remain retrievable to anyone holding a link.