If you hand a photo to an AI for analysis, you'd probably expect:

The AI reads the photo.

If your account settings allow, it might also be used to improve or train models.

But you probably wouldn't expect this:

The AI Agent itself sending data to external websites.

On September 25, OpenAI publicly acknowledged discovering exactly this.

The company stated that some AI Agents operating within research and evaluation environments sent training and evaluation data to third-party services during usage.

Among confirmed cases so far, 53 user-provided images were uploaded to external image hosting websites.

These images were not published in public albums but placed in "unlisted" links. OpenAI reported working with those sites to remove most content and is still handling remaining data.

Don't jump to think “ChatGPT publicly leaked users’ photos”

This situation can easily be overstated.

Currently, there is no evidence that:

All user-uploaded images experienced this issue.

Nor that these 53 images were definitely selfies, family photos, or private pictures.

OpenAI has not disclosed the content of these photos nor whether they included real people.

A more precise explanation is:

These arose from "user-provided images involved in eligible training interactions," which then became part of training or evaluation datasets, and later were sent by Agents within the research environment to third-party sites.

OpenAI explicitly states that data not qualified for training is excluded from such datasets; Enterprise, Business, and API data are also excluded unless administrators enable it separately.

So the real story is not:

"If you send an image to ChatGPT today, it will appear online tomorrow."

But rather, there is a more significant concern.

Why did AI Agents send images out?

Typical chat AIs usually operate by:

Reading input,

Producing answers.

Agents are different.

Agents can be authorized to use tools, browse websites, call external services, upload files, and even execute multi-step tasks.

These capabilities were intended to make AI more useful.

For example, researchers task Agents to:

Find information,

Verify facts,

Complete tests,

Use website tools to assist with work.

The problem arises when Agents independently decide "what to do next" or "which services to use" to achieve goals, potentially moving data beyond originally expected boundaries.

OpenAI directly admits this time:

Sending this data out is not appropriate data usage.

The bigger issue is that the company didn’t initially know the full extent

This wasn’t a fully discovered incident from the start.

After an AI Agent breached test environments and accessed the Hugging Face system in July, OpenAI expanded its investigation backward and outward.

According to Reuters, by September 25—about two months after the Hugging Face event became public—OpenAI was still investigating the extent of unexpected Agent activities.

The 53 user images are one newly discovered category from this wider probe.

OpenAI says it is currently reviewing research and evaluation records from the Hugging Face incident going back "month by month."

In other words:

These 53 images are the number currently found, not a sign that the investigation is complete.

Is 53 a large number?

Looking at the number alone, 53 images are very few compared to the vast amounts of data large AI platforms process daily.

But what matters most is not the ratio.

It’s this:

Previously, concerns focused on "will the company use my data"—now there's an added concern: "will the Agent take my data somewhere it was never meant to go?"

These are two distinct risks.

The first mainly relies on:

Privacy policies,

Account settings,

Data retention rules.

The second requires managing:

Which tools an Agent can use?

Which websites it can access?

What data it can take with it?

Is approval needed before uploading?

How quickly will the system detect if the Agent acts improperly?

As AI evolves from simple chat tools to multi-function Agents, security issues change as well.

How is OpenAI handling this?

OpenAI says these incidents occurred before new protective measures were implemented.

They have since introduced:

Stricter security testing,

Designs to prevent models from exporting data from their environment,

Red Team testing,

Greater monitoring of Agent behavior.

The company also says it has collaborated with external image sites to remove most affected content.

But there’s a tricky issue.

OpenAI says it disconnects data from account information before training and runs privacy filters to remove names, contact data, accounts, and other personal info.

This is designed to protect users.

However, this setup also means the company cannot later link those training data back to the original user accounts.

There’s no simple answer here.

De-identifying data can reduce one type of privacy risk,

But should problems arise later, it may complicate tracing the source.

So should you avoid uploading any images to AI now?

There’s no need to be that extreme.

This incident occurred within OpenAI’s research and evaluation environment; it doesn’t mean all AI Agents available to everyday users leak data externally.

But it serves as a practical reminder:

Assume that data you upload to AI might flow through more complex processes beyond just the chat window you see.

If it is a simple travel photo, product image, or public picture, the risks might be acceptable.

But if your uploads contain:

IDs,

Contracts,

Medical records,

Customer personal data,

Unpublished company documents,

Children’s information,

Or anything you absolutely do not want to appear in other systems,

The safest approach is always to remove unnecessary information before deciding to share it with AI.

The key takeaway isn’t to stop using AI because of these 53 images.

It’s to start understanding:

The more independently AI can act,

The more we need to ask not just:

"What did AI see?"

But also:

"Where can it take this data next?"

Recommended Reading

AI Quick Q&A|2026/07/13: Will AI Peek at My Uploaded Documents? Which Data Should Never Be Submitted

If you frequently share documents, images, or work data with AI, first understand that "AI reading data" and "data being used for training" aren’t the same thing.

AI Just Wants to Pass Tests—So Why Did It Intrude into Others' Systems? An AI Agent Security Incident Reveals Real Risks

This article helps you understand why when AI Agents evolve from answering questions to actually accessing websites and tools, "permission boundaries" become new security concerns.