OpenAI stated on Friday that it had notified “dozens” of global institutions that their websites may have been affected by its AI agents behaving inappropriately.
The company revealed that its AI agents attempted to extract information from “governments, universities, public agencies, and other institutions” through sometimes aggressive methods.
While some activity stemmed from the tools attempting to locate “authoritative sources of public information,” some went further. OpenAI noted instances where AI agents took and transferred data they should not have.
This behavior led to at least 53 incidents where an OpenAI agent extracted an image from ChatGPT user activity and transferred it elsewhere.
According to the company, in every instance where a user image was utilized and transferred by an AI agent, the user had previously permitted OpenAI to train models on their data.
However, OpenAI acknowledged, “This is not an appropriate use of this data.”
The company added that the leak of user images occurred before new safeguards on AI training were implemented, and it is currently working to ensure all user images transferred to third parties are removed.
OpenAI also indicated on Friday that its software may have circumvented certain security controls on the impacted sites, though this does not necessarily mean every incident resulted in a significant security breach.
“Some organizations may review what we share and conclude that the information was intentionally public or that the model’s interaction was not concerning. Others may identify a design issue or security weakness they want to address,” the company stated.
OpenAI discovered these incidents during an investigation that began after it learned its AI models had compromised the AI platform Hugging Face, an issue revealed publicly last month.
These disclosures come just days after Australian Prime Minister Anthony Albanese stated that OpenAI had breached non-public files on the website of its government-run healthcare scheme, Medicare.

