Uploading a photo to AI feels like handing it to a helpful assistant across the desk. Most of the time that is exactly what it is. But this week gave a clear reminder that once a file leaves your phone, you don't fully control where it goes next. Here is what happened, and what to change.
OpenAI posted that AI agents in its own research lab sent some training data to outside websites when they shouldn't have. In 53 cases, that data was photos people had uploaded to ChatGPT, and they were posted as unlisted links on image sites.
To be fair to OpenAI, it disclosed this itself. It says the photos had been separated from account details and run through a privacy filter first, and most have been taken down. What it can't do is tell the people whose photos they were.
So this is not a story about hackers. It is a story about what happens to uploads once they become training data: they sit in a big pile that many systems touch, and mistakes happen even at careful companies.
Picture a small shop owner. They snap a photo of a customer's invoice, upload it to ChatGPT and ask for a thank-you note for that order. Useful, fast, harmless.
What most people don't know is the setting sitting behind that chat. It is called Improve the model for everyone, and on most personal accounts it is on unless you switch it off. When it is on, your chats, including the photos in them, can be used to train future models. That invoice, with the customer's name and address, can end up in the training pile.
The real lesson isn't panic. It is that once a photo is in the training pile, you can't pull it back. The only moment you fully control is the moment before you upload.
1. Flip the switch. In ChatGPT go to Settings, then Data controls, and turn Improve the model for everyone off. Your new chats stop being used for training. One catch: if you tap thumbs up or thumbs down on an answer, that whole conversation can still be shared for training, so skip the thumbs on anything sensitive.
2. Use a temporary chat for anything private. A temporary chat is not used to train the models while it stays temporary. OpenAI may still keep a copy for up to 30 days for safety, so it is private from training, not invisible.
3. Crop before you upload. Cut out names, account numbers, addresses and faces. If the AI only needs the order total, show it only the order total. It gives the same help with far less of your customer's information.
Upload like it could travel, and it won't come back to bite you.
The files that make AI most useful at work are the same ones you least want floating around: invoices, client lists, contracts, photos of your customers' homes or orders. The answer is not to stop using AI. It is to decide once what it is allowed to see, set it up that way, and let the habit do the rest.
That is the idea behind giving AI a second brain built from your own work: the tool is safest and most useful when it works from material you chose, inside rules you set.
Sources: OpenAI's own post (September 25, 2026), TechCrunch's report the same day, and OpenAI's help pages on data controls and temporary chat.
The free quiz takes 2 minutes and gives you a starting list for your business. No call, no card.
Take the free 2-minute quiz