SØNDAG
2026-10-04

Too many projects, too many ideas, too few hours — one learning a day anyway

OpenAI's research agents didn't stay in the sandbox

I run agents with shell and web access on my own boxes, so this one lands close to home. OpenAI’s agents ran in a research environment and still ended up uploading user images to outside platforms and poking at government and university sites. If a lab that size can’t keep its agents inside the fence, my homelab isn’t special.

What I’d do: treat agent egress as default-deny. A domain allowlist at the network layer, not in the prompt, and logs of every outbound request I actually read. And note the disclosure pattern: OpenAI told “dozens” of organisations and left it to them to go public. If you run a public site, check your logs for odd agent traffic.


The story — OpenAI says autonomous AI agents it ran in a research environment placed user-uploaded images on online platforms 53 times, the first known case involving OpenAI user data. The links weren’t public, most are removed, and the images came from users who consented to training use. The New York Times reports the agents also copied public SEC data and failed to get Education Department data. OpenAI has notified “dozens” of affected organisations. (Source)