← All research

OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

2026-09-29 · OrangeStealth Security

Giving an AI agent access to a file is not the same as keeping that file inside the tool you trusted. When an agent can browse websites, call services and complete tasks on its own, information may cross a boundary that neither the user nor the organization expected.

BleepingComputer reported that OpenAI identified cases in which agents in a research environment transmitted training and evaluation data while using third-party services. The company found 53 instances involving user-provided images that were posted to image-hosting sites as links that were not publicly listed. OpenAI said most users were not affected and that the vast majority of the impacted data was not derived from users.

B
BleepingComputer@bleepincomputer

OpenAI's AI agents accidentally uploaded user-provided images to third-party siteshttps://t.co/Y1QA5ieKOMhttps://t.co/Y1QA5ieKOM

September 26, 2026 · Read original

The distinction between an unlisted link and a deliberately public post matters, but it does not make the exposure harmless. An unlisted file can still be available to anyone who obtains its address. The hosting provider also receives the file and associated service data. Depending on the image, that could create privacy, confidentiality, contractual or retention concerns.

We have successfully worked with the hosting providers to remove most of this content and are continuing to work to remove the rest.

BleepingComputer

OpenAI said data that was not eligible for training was not involved. According to the report, this excluded data controlled out of training by users or enterprise administrators. Enterprise, business and API data was also excluded unless an administrator had enabled its use. OpenAI further said eligible data is disassociated from account information and filtered to redact personal details before entering training datasets.

Those safeguards narrow the reported incident, but the larger lesson applies well beyond one provider. Agent security is not only about what a model can read. It is also about where the model can send information, which external tools it can use, and whether those actions remain visible to the people responsible for the data.

If this is your domain

  1. Inventory every external destination available to agents. Document browser access, file-upload functions, connectors, code execution environments, image hosts, collaboration tools and other services. Do not rely on a list of approved AI products alone. The important question is which destinations become reachable after the agent starts working.

    0
    0xbadhash@0xbadhash

    OpenAI: agents in its research environment sent training and eval data to third-party services. 53 user-uploaded images landed on image hosts as unlisted links, after

    September 27, 2026 · Excerpt; read original

  2. Separate data access from outbound permission. An agent that needs to inspect an image does not automatically need permission to upload it elsewhere. Apply destination allowlists, block unnecessary upload services, restrict connector scopes and require approval for actions that transmit files outside the organization’s controlled environment.

  3. Test with realistic sensitive content. Use synthetic records that resemble the documents employees actually handle, including screenshots, identification images, contracts and customer attachments. Confirm whether the agent uploads, republishes or converts that material into externally accessible links. A configuration gap is not proof of compromise, but it is a reason to reduce access before real data is involved.

  4. Keep useful records of agent actions. Logs should show which tool acted, what destination it contacted, when the transfer occurred and whether a human approved it. Protect the logs themselves and avoid recording full sensitive payloads when metadata or a secure reference will support the investigation.

  5. Prepare a removal and notification path. Know who can disable an agent, revoke a connector, contact a hosting provider, preserve evidence and determine whether legal or customer notification is required. Deleting an internal task history does not necessarily remove a file from an outside service.

Hypothetical example: A property management employee asks an agent to summarize photos attached to a maintenance complaint. One image includes a resident’s name, apartment number and a visible access code. The agent uploads the photo to an outside image host so another tool can process it, then returns an unlisted link. Nothing in that scenario proves the link was discovered or abused. The problem is that the organization lost control of where the image was stored, how long it remained there and which provider handled it.

A passive, external-only External Security Posture Assessment can identify exposed services, risky public configurations and other internet-visible gaps around an organization’s AI footprint. It cannot see every internal agent decision, so it should complement internal access reviews, vendor checks and outbound logging rather than replace them.

OpenAI said it strengthened its training and evaluation processes with additional safeguards and monitoring, and that it is continuing to review older agent activity month by month. For other organizations, the immediate task is simpler: choose one agent workflow involving files, trace every place those files can travel, and remove any destination that the workflow does not genuinely need.