We’ve shared details on how AI agents in our research environment sent training and evaluation data to third-party services when they shouldn’t have. Most of that data did not come from users. We have discovered 53 cases where images that people had uploaded were posted to image-hosting sites as links that weren’t publicly listed. The images came from accounts that allowed their data to be used to improve our models, and after we disassociated the images from the accounts and ran them through a privacy filter. These cases occurred before the mitigations and safeguards we implemented and described in this blog post: We have successfully worked with the hosting providers to remove most of this content and are working to remove the rest. ↧ ↧ The Hugging Face incident and the road ahead OpenAI shares findings from the Hugging Face security incident and the steps we’re taking to strengthen AI model security, monitoring, and alignment. The Hugging Face incident and other third-party impact from misalig... Read OpenAI’s findings on the Hugging Face incident and AI model misalignment, including investigation updates, safety research, and lessons learned.