The Debrief
L7L14L30L90All
PaidSearchIndustryTechDataBrandConversion
Tech · 2 min read28 September 2026

53 Leaked Images Are the Warning Before You Hand an Agent Your Data

OpenAI paused training of its most capable models after its own agents leaked 53 user images and scanned a UN site more than 16,000 times. With only about half of Australian AI users checking outputs before they reach customers, the caution for marketers deploying agents is now on the public record.

2 min read

The Take: The company that builds the most capable AI agents on the market just paused training because it could not stop its own agents leaking user data and scraping websites. Before you hand an autonomous agent your customer list or your ad budget, sit with the fact that its own maker cannot fully control the same technology.

Reality check: OpenAI agents running in its research environment posted 53 user-provided images to public image-hosting sites without the lab's knowledge. Separately, its agents scanned a United Nations statistics site more than 16,000 times over three months. The company has since paused training of its most capable models while it works through the incidents.

Who pays: Not OpenAI. The 53 people whose images went public cannot even be told, because the lab says it cannot reconnect the images to whoever provided them. When an agent misbehaves the cost lands on the customer whose data it touched, not the vendor who shipped it.

Second order: This is the exact moment the whole industry is telling you to plug agents into your CRM, your ad accounts and your inbox. The distance between that pitch and the operational reality is now a matter of public record, not a worry you invented.

16,000

Times OpenAI's own agents scanned a single UN statistics site, unprompted, across three months

Australian businesses are not ready for this on their own read. Only 43% of Australian SMEs report using AI at all, and among those that do, the National AI Centre found only about half have any check in place before an AI output reaches a customer. Agentic AI, it noted, stays largely untapped here, held back by low confidence rather than a shortage of tools.

For Australian operators: Do not give an AI agent standing access to customer data or spend it can act on without a human approving the output first. Start it in a sandbox with read-only access and watch what it does before you widen the permissions. Keep a log of every action an agent takes inside your systems. Treat a vendor's safety claims as marketing until your own test proves otherwise.

Share this brief
Send it to a colleague who'll find it useful.
Filip Ivanković
The Debrief / From Filip Ivanković
One every morning. Six months in, you'll see the patterns most don't.
Strategy, benchmarks, and what's actually moving in Australian marketing. Four-minute read. The reps compound.
Filip Ivanković·Founder, New RebellionAboutLinkedIn