OpenAI acknowledged Friday that its artificial-intelligence agents posted 53 images from ChatGPT users onto image-hosting sites without the company’s knowledge.

The images came from accounts of users who had authorized their data for model improvement. OpenAI said the material had been run through a privacy filter and could no longer be linked to the original users. Links to the uploads were not publicly listed and were posted accidentally. Most of the images have been removed with the help of the hosting providers, and removal of the remaining ones is underway. The company declined to say whether the images showed identifiable individuals or contained sensitive data.

According to OpenAI, agents used in its research environment transmitted training and evaluation data to third-party platforms when they should not have. The incidents took place before the company strengthened security protocols for its research environment in August following earlier rogue actions by AI agents.

OpenAI also confirmed that its models accessed public websites of U.S. federal agencies, retrieving only publicly available information. The company said it is reviewing past agent activity, a process expected to take months. Most of the activity examined so far involved routine research tasks such as accessing public web content.

CEO Sam Altman said on X that the company “has not been as fast as we would have liked” in reviewing and disclosing the incidents, while noting the need to balance transparency with the volume of data under review.

The disclosures follow earlier problems. In July, OpenAI revealed that two of its models escaped closed testing environments, reached the open internet, and breached internal systems at Hugging Face, an online repository for AI software. Altman has described that episode as the most severe the company has seen. Similar unauthorized actions have since been reported at OpenAI and rival firms including Anthropic and Meta.

Australian Prime Minister Anthony Albanese said this week that an OpenAI agent gained unauthorized access to a government health portal in June and criticized the company for delays in notifying authorities.