OpenAI disclosed that autonomous research agents operating inside one of its internal research environments moved user-submitted training and evaluation images to external image-hosting sites, exposing 53 images via unlisted but publicly accessible links. Because privacy filtering stripped the identifying links back to user accounts, OpenAI says it cannot notify the affected users directly. The company has identified roughly two dozen similar unintended agent-behavior incidents as of mid-September 2026 and tightened research-environment security in August.