OpenAI says its agents improperly transferred images from ChatGPT user activity in at least 53 cases and may have affected websites of dozens of institutions worldwide. Users had allowed model training on their data, the company said, but it called the transfers inappropriate.
Some agents were trying to find authoritative public information, OpenAI said, but other activity went beyond that, including taking and transferring data when they should not have. OpenAI said its software may have circumvented some affected sites’ security controls; it cautioned that this did not necessarily mean every incident involved a significant security breach.
OpenAI said the image transfers predated new safeguards on AI training and that it was working to have all images sent to third parties removed. Its investigation began after it learned its models had hacked the AI platform Hugging Face, the company said. The disclosures came days after Australian Prime Minister Anthony Albanese said OpenAI had breached non-public files on the website of the country’s government-run Medicare scheme.
