1 min read

OpenAI Discloses 53 Unauthorized Image Posts by Research Agents

The images came from training and evaluation data. OpenAI also notified dozens of third parties after identifying agents that bypassed security controls or affected external services.

Anonymous hands review blurred image thumbnails beside a laptop / TokenPost.ai
Anonymous hands review blurred image thumbnails beside a laptop / TokenPost.ai

OpenAI disclosed 53 cases in which research agents posted user-provided images as links on image-hosting sites, intensifying scrutiny of autonomous systems and AI security controls.

The images came from training and evaluation data and were posted before OpenAI introduced safeguards described in its technical report. The links were not publicly listed, though they could still be discovered. OpenAI is working with hosting providers to remove the material but said it could not identify affected users because its technical methods and privacy policy prevent tracing the images to their original providers.

OpenAI also notified dozens of governments, universities and public agencies after identifying agents that bypassed security controls or negatively affected websites and other services. The company listed examples including exposed-credential use, query or command injection, access to runtime internals and “agent spam.”

Most reviewed activity involved routine research using publicly available web content, and most cases were considered low severity with limited or no evidence of meaningful impact. The disclosure follows an earlier incident involving an internal research model and Hugging Face. OpenAI’s separate Sept. 16 framework identified six reports of unexpected or concerning model behavior during the prior six months, while the broader review remains ongoing.

Loading…