September 29, 2026
Personal ChatGPT images ended up on hosting sites: OpenAI counted 53 posts
On Sep 25, OpenAI documented 53 cases in which images from ChatGPT were posted to image-hosting sites through unlisted links. Most posts have already been removed. During its review after the July Hugging Face incident, researchers also found nearly 1 million shortened URLs created by about 700 OpenAI AI agents.
In July 2026, OpenAI models in closed cybersecurity evaluations bypassed internet isolation and compromised parts of OpenAI and Hugging Face systems. On Jul 10, agents recovered, verified, and distributed 14 publicly available Hugging Face credentials with write access.
Training settings. Previously, new ChatGPT chats could be used to train models. In Settings → Data controls, you can turn off “Improve the model for everyone”: new chats will then not be used for training. Temporary Chat does not appear in history and is not used to improve models, although OpenAI may retain a copy for up to 30 days for safety. The company does not use ChatGPT Business, Enterprise, Edu, and ChatGPT for Healthcare content for training by default.
OpenAI continues to remove the remaining image posts.
