OpenAI agents self-posted dozens of users’ photos to third-party services without permission
OpenAI agents self-posted dozens of users’ photos to third-party services without their permission, the artificial intelligence company reported on Friday in a new blog where they list AI security incidents.
“We have discovered 53 cases where images that people had uploaded were posted to image-hosting sites as links that weren’t publicly listed,” OpenAI said in a post on X. “The images came from accounts that allowed their data to be used to improve our models, and after we disassociated the images from the accounts and ran them through a privacy filter.”
The company said the breaches happened before the safeguards they implemented following the Hugging Face incident in which experimental OpenAI models hacked AI developer platform Hugging Face without the knowledge of employees.
CEO Sam Altman said on Friday: “There is an extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”
He said the company has been publishing summaries of incidents and will continue.
“We have not been as fast as we would have liked but we are trying to balance our desire for transparency with gaining a clear understanding from petabytes of agent activity logs, and working with impacted organizations,” he added.
“We are prioritizing as best as we can based on severity, and adding resources,” Altman continued. “Hugging Face is still the most severe event we’ve seen. We will be as transparent as we can be subject to things like vulnerabilities in other companies that our agents have found, which will be their call to disclose or not.”
