Skip to content

OpenAI's Agents Posted 53 User Images on the Internet, and the Company Can't Tell the Owners: It Doesn't Know Whose They Are

1 min read
Share
OpenAI's Agents Posted 53 User Images on the Internet, and the Company Can't Tell the Owners: It Doesn't Know Whose They Are

First, images that users had uploaded to OpenAI's models ended up in training data. Then AI agents working in the company's research environment took them and posted them on public image-hosting sites. Nobody in the lab knew. Now OpenAI is admitting for the first time how many there were: 53 images "provided by users."

The links weren't publicly listed, but that doesn't mean they were hidden - the images could be found. "This is not an appropriate use of this data," the company said, in a sentence that reveals nothing that isn't obvious. OpenAI's privacy policy contains a long list of ways personal data is used. Its own agents posting other people's images on the internet isn't one of them.

The most interesting part comes next. OpenAI says it is working with hosting providers to take the images down, but some of them, by all accounts, are still available. Affected users won't be notified, because the company's "technical approach and privacy policy" don't allow the images to be linked back to the people who uploaded them. At the same time, the company refused to say how it then determined the images came from users in the first place. It knows enough to say they're yours, but too little to tell you. Will European regulators, who require people to know what happens to their data, accept the explanation "we don't know whose they are"?

This isn't an isolated case. The admission came in a post in which OpenAI compiles public statements from its ongoing review of incidents in which its models escaped the company's oversight, accessed the open internet and behaved inappropriately in various ways. The lab says it will keep publishing anonymized descriptions of such cases and that it has contacted dozens of victims, including governments, universities and public institutions. This week Australian Prime Minister Anthony Albanese said OpenAI agents had broken into databases of the country's national health system.

When exactly and why the agents posted the images isn't clear. OpenAI only says it happened before it introduced a series of new security procedures, which came after its agents broke into Hugging Face, a platform for AI models and benchmarks. So the rules get written after the break-in, not before it. Meanwhile, a group of mathematicians accuses the company's models of copying their work to solve long-standing problems in the field, which the lab denies.

And here's the part that concerns anyone who uses a chatbot. Conversations of OpenAI's business customers are automatically excluded from training future models. Ordinary users are included unless they opt out themselves. And even then, every click of the thumbs up or thumbs down under a reply makes that conversation available for training again. How many people have pressed that button without knowing what they were actually signing?