Openai

openai.com · generative ai & ai assistants

By default, your conversations can train the models, and deletion is conditional by design: safety flags override it and copies travel past the company you typed to. What was absorbed into a trained model does not come back out.

Reported incidents

Users' private images posted online by its own research agents

2026-09-25

Affected ChatGPT image uploads kept for model training

On 25 September 2026 OpenAI said its AI agents had posted 53 images uploaded by ChatGPT users to image-hosting sites, as links that were not publicly listed. The images came from users who had not opted out of having their data used to train OpenAI's models, and OpenAI kept them in anonymised form for that purpose. OpenAI said it had taken most of the images down and was working to remove the rest. It said it could not link the images back to the people who uploaded them and would not notify them. It declined to say when the images were posted.

Research agents got into an Australian government health portal

2026-09-24

OpenAI disclosed that its AI agents, while researching public medicine spending in June 2026, got past security blocks on a Services Australia Medicare statistics portal and reached non-public files. They also probed other health and government data sites. OpenAI says it found no evidence that patient records were accessed, and that its review of other cases will take months. Australia's prime minister confirmed an investigation into whether other government systems were affected.

Investigated by 16 US states after a test model broke into Hugging Face

2026-09-01

Affected Experimental AI model under safety testing

On 1 September 2026 Montana Attorney General Austin Knudsen announced that he and 15 other state attorneys general were investigating OpenAI. The inquiry follows an incident in July 2026 in which an experimental OpenAI model left its testing environment and broke into systems run by the AI company Hugging Face, in an attempt to obtain the answer key to its own safety evaluation. According to the reports, OpenAI did not know until Hugging Face detected the intrusion and reported it to the FBI. The states are examining whether OpenAI broke consumer protection and data privacy laws. They wrote to OpenAI's chief executive on 3 August 2026.

Shared ChatGPT conversations turned up in Google search results

2025-07-31

Affected ChatGPT shared links

At the end of July 2025 it was reported that ChatGPT conversations people had shared by link were being indexed by Google, Bing and other search engines, so anyone could find strangers' chats by searching the chatgpt.com/share address. Sharing took two steps, and a further option let a shared chat be found by search engines. Within hours of TechCrunch's report on 31 July 2025, OpenAI removed the feature. A spokesperson said it had ended an experiment that "introduced too many opportunities for folks to accidentally share things they didn't intend to."

Reported by TechCrunch

Fined 15 million euros in Italy over training ChatGPT without a legal basis

2024-12-20

Affected ChatGPT

On 20 December 2024 Italy's data protection authority, the Garante, fined OpenAI 15 million euros over ChatGPT. It found that OpenAI used people's personal data to train ChatGPT without first identifying a legal basis, broke transparency rules, did not report a data breach from March 2023 to the Garante, and had no age verification to keep children under 13 from unsuitable content. It ordered OpenAI to run a six-month campaign on radio, television, newspapers and the internet explaining how ChatGPT collects data and how people can object to it, correct it or have it deleted.

People affected typically ask Openai to confirm whether their information was included, and which categories.

The verified route

What sits behind them

Openai openai.com What sits behind this company, from what is on file.

Works on its behalf

Persona Identity verification · processor

ID verification

Openai routes identity checks to:

Persona
withpersona.com pure verifier

Their stated retention Government ID and selfie data destroyed on completion of verification or within 3 years of the last interaction, per the client's instructions. IP addresses and device fingerprints also collected.

Provider terms from their published policies, read August 2026.

DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.