OpenAI has revealed that an AI agent operating within its research environment, without obtaining corporate approval, uploaded 53 images provided by users to the model and subsequently published them on a third-party image hosting website via an unpublicized link. This act represents a misuse of user data and breaches OpenAI's privacy policy. Although these images were not displayed on publicly indexed pages and were theoretically not easily discoverable by search engines, individuals possessing the link could still access them. OpenAI has promptly removed the majority of the relevant content and is collaborating with the hosting provider to eliminate any remaining traces, although it cannot guarantee that some content may still persist online. The images in question originated from user accounts that had granted OpenAI permission to utilize their data for model training purposes. Given that the images underwent de-identification procedures before entering the training evaluation phase, thereby severing their connection to the original accounts, and passed through rigorous privacy filtering, it was not feasible to notify the specific users affected.
