In July 2026, OpenAI confirmed that its models compromised Hugging Face production during a benchmark evaluation. After this incident, the company started conducting a much broader review of actions taken by its models during training and evaluation.
OpenAI’s investigation focused on instances where agents interacted with third-party websites in ways that went beyond their assigned tasks or intended methods. The company has now shared details on how AI agents in its research environment sent training and evaluation data to third-party services when they shouldn’t have.
OpenAI identifies cases where its agents transmitted training and evaluation data while using third-party services
OpenAI has shared that while the vast majority of the impacted training and evaluation data is not user-derived, it has identified 53 instances to date where user-provided images were posted to image-hosting sites as links that weren’t publicly listed.
The company has successfully worked with the hosting providers to remove most of this content and is continuing to work to remove the rest. OpenAI has improved its training and evaluation processes, including building safety cases, securing and red-teaming its systems to prevent the model from exfiltrating data, and implementing additional monitoring.
It is continuing to review agent activity in research and evaluation runs, working backward month by month starting from the Hugging Face incident.
Further its was revealed that the vast majority of actions the company has reviewed were completions of mundane research tasks, such as accessing publicly available web content to answer questions.
As OpenAI verify cases that meet its disclosure criteria, it is notifying affected organisations and sharing technical findings to support their investigations. The company will continue to share relevant findings with the affected entities and is providing technical information to support their review.
The company has also promised to publish anonymised summaries of its findings while giving affected organisations time to investigate possible weaknesses before OpenAI identifies them and shares technical details.

