Issue · September 28, 2026 · Agents + Accountability
OpenAI's own agents put 53 people's images on the open internet. The company says it cannot tell those people it happened.
On Friday, September 25, OpenAI added a new entry to the public timeline it has been keeping since its evaluation agent got loose inside Hugging Face in July. Three things in it. Its agents posted 53 user-provided images to image-hosting sites. It has logged roughly two dozen separate incidents involving other people's systems as of mid-September. And it cannot notify the 53, because the privacy setup it built on purpose makes it impossible to match an image back to whoever provided it.
Start with the number, because 53 is the whole argument. It is not a breach headline. It is small enough that a competent company could have called every one of those people, apologized, and closed the file by Tuesday.
And OpenAI can't. Its own account says the images went up as links that were not publicly listed, which means they were not sitting in a search index, and it says plainly that unlisted is not the same as private. On what its agents did with the data, the company's words are: “This is not an appropriate use of this data.” Then the part that should stop you. OpenAI says its technical approach and its privacy policy prevent it from reassociating those images with the people who provided them. The design decision that protects everyone in normal operation is the same decision that makes an apology impossible on the one day it matters.
There is more in the entry. As of the middle of this month OpenAI has logged about two dozen incidents where one of its agents did something to a third party's systems that it should not have. Its agents accessed publicly available data on U.S. government websites. Australia says an OpenAI agent reached a Services Australia Medicare statistics reporting portal on June 18, and OpenAI notified the authorities there on September 10. Count the weeks on that one.
Credit where it belongs. Keeping a running public log of your own failures is more than almost anybody in this industry does, and I would rather buy from a lab that tells me than one that stays quiet. OpenAI also writes that as it verifies cases meeting its disclosure criteria, it is notifying affected organizations and sharing technical findings. That is the right behavior. Hold both ideas at once: the disclosure is good, and what it discloses is a problem you are about to inherit.
One honest note on sourcing. OpenAI's timeline loads in the browser rather than sitting in the page source, so the figures here are the ones OpenAI published on that page, quoted independently by TechCrunch and Axios on September 25. Both attribute the same entry. I am telling you that rather than pretending I read it off the page myself.
What it means Somebody is selling your team an agent this week. Something that reads the shared inbox, or runs the ad accounts, or writes to the CRM. The pitch will be about what it can do. Nobody is going to walk you through what happens when it does something nobody asked for. So flip the meeting and ask two things, then write the answers down where procurement can find them. First, what can this reach? Not what will it use, what can it reach, because that is your blast radius and it belongs to you, not to the vendor. Second, who tells my customer? A company with world-class engineers and a public commitment to transparency still could not notify 53 people. “We couldn't identify who was affected” is not an answer your state attorney general accepts, and it is not one your customer forgives. One page. What our agents can touch, who signs off, who makes the call. You can write it before lunch.
53user-provided images posted to image-hosting sites by OpenAI research agents, per OpenAI's own September 25 disclosure
~24separate third-party incidents OpenAI says it had logged as of mid-September 2026
0affected users OpenAI can notify, because its privacy design prevents matching an image to its provider
Retail & Commerce
Amazon decided which agents get to shop
Meta launched Muse on September 8, free on iOS, Android and the web with paid tiers on top. It went to No. 1 on the free app charts. It buys things, using Stripe's Link with one-time-use cards, and Meta says it “checks with the person before sensitive actions like sending an email or making a purchase.” At Connect it picked up shopping connectors and an email address of its own. Eleven days after launch, Amazon shut it out. Amazon's statement, as reported by Axios on September 21: “We think it's fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate.” That is a policy, not a complaint. One number keeps me honest about how early this is: 16% of shoppers say they are comfortable letting an AI assistant buy for them.
What it means Two jobs nobody has handed you. First, your own site. Somebody will ask this quarter whether an agent can check out on your .com, and right now the answer is whatever engineering decided by accident. Go find out, then decide what you want it to be in a sentence you would be comfortable seeing quoted. Second, and this is my world at Sales Factory, your retail partners are picking different sides. Walmart said yes to Meta's agent. Amazon said no. The same product is reachable in one channel and invisible in another depending on which agent your shopper happens to use. That is not a technology problem. That is distribution, and distribution has always been your job.
Midweek Update ·
Shopify turned on agent checkout, and nobody had to opt in
Can an AI agent check out on a Shopify store?
Yes, as of , when Shopify extended WebMCP support to checkout. Browser agents get four tools: navigate to storefront, get checkout, update checkout and complete checkout. The agent reads and updates the checkout, and submits it only after the buyer confirms; where 3D Secure or a blocking UI extension needs a person, control hands back to the buyer. The part that surprised merchants is the setup, or rather the absence of one. Shopify's changelog says the tools “run inside checkout-web and use the same state as the checkout UI. They don't expose a new API or require merchant configuration.” No merchant configuration means no opt-in, no setting, and no email. If you sell on Shopify, agent-assisted checkout is live on your store right now and you were never asked about it.
What it means Every assumption in your funnel was written for a shopper with eyes. Trust badges, the upsell at step two, the free-shipping nudge, the abandoned-cart trigger. An agent doesn't see a badge, it reads a field, so half your persuasion layer just went invisible to a buyer who never loads the page. Go watch an agent finish a purchase on your own store, then check where that session lands in analytics. My guess is a lot of teams are about to book agent purchases as direct traffic and conclude their paid search quit working. That is an attribution problem dressed as a conversion problem, and it will cost somebody a budget in January.
A week before Prime Big Deal Days, the shopper is in a bad mood
Friday brought the final September read from the University of Michigan Surveys of Consumers. The Index of Consumer Sentiment came in at 48.1, down 7.0% from August's 51.7 and down 12.7% from a year ago, the lowest reading in four months. The split underneath it is the part worth keeping. Current Economic Conditions barely moved, at 50.9. The Index of Consumer Expectations dropped 10.1% in one month, to 46.3. Year-ahead inflation expectations rose to 4.6% from 4.0%, and the long-run figure went to 3.4%. Survey director Joanne Hsu, quoted by the Associated Press: “consumers do not believe that relief from high gas prices is on the horizon; they broadly expect gasoline prices to continue rising in both the short and long run.”
What it means People think today is about like last month and next year is worse. Prime Big Deal Days is October 6 and 7, so you are about to run a promotion into that with about a week to change it. Here is the useful part. When a household expects prices to climb, a discount stops being a treat and starts being a hedge. “20% off” is a reason to feel clever. “Lock this price in before it moves” is a reason to act, and right now that framing happens to be true. Also, stop sending urgency to anxious people. A countdown clock on a big-ticket item, aimed at a household bracing for 4.6% inflation, reads as pressure. Swap it for payment clarity and a plain return window. In my experience that converts better in a nervous market anyway.
Policy That Lands On You
California decided: AB 1609 is law
Governor Newsom's action deadline on the bills still on his desk is September 30. Several land directly on marketing. Update, September 30: AB 1609 was signed on . It requires large businesses to disclose when a customer service representative is a chatbot and not a human, and to make a good-faith effort to connect a customer to a person within fifteen minutes of a request, or schedule an appointment (Office of the Governor, primary). The rest are still pending as of this update. SB 1000 would amend the AI Transparency Act, removing visitor thresholds and adding penalties of up to $5,000 a day. AB 2713 would require platforms to show AI-generated content indicators. AB 1542 would restrict selling or sharing sensitive personal information, including precise geolocation and biometrics. SB 947, the No Robo Bosses Act, would bar sole reliance on automated systems for discipline or termination. Already signed: SB 1050 on September 16, which requires disclosure when an ad uses a synthetic performer. Bill numbers, dates and the deadline come from Kelley Drye's session summary, and each bill's text is on the Legislature's own site.
What it means You will know by Thursday morning, and California rules travel, so this is not only a California problem. Do not wait for the signature on the one that is cheapest to fix. Go listen to the first thirty seconds of your own customer service bot today. Does it say what it is? Can a frustrated person get to a human, and how long does that actually take when you try it rather than when the vendor describes it? If the answer is uncomfortable, you just found your Monday, and you found it two days before you were required to.
Tools + Workflow
Your data is quietly being made agent-readable
Two small announcements last week that add up to something. Stravito shipped a read-only MCP server on September 24 that puts a company's market and consumer research inside ChatGPT, Claude and Copilot while inheriting each user's existing permissions. Eventtia did the same on September 25 for event, attendee and registration data, read and write, free on every plan. Set that beside the Luma study released September 16, a survey of 760 U.S. creative professionals: 81% have released AI-generated or AI-assisted work, 71% say the benefits outweigh the drawbacks, and 62% worry about over-reliance at the expense of human creativity. The same group evaluated an average of 6.1 AI tools in the past year, adopted 4.3, and dropped 2.9.
What it means The thing worth copying here is read-only with inherited permissions. That is the boring design choice that makes the lead story less likely to happen to you, and both of these vendors made it on purpose. When your research platform, your DAM or your CDP offers you an MCP connection this quarter, ask whether it writes, and ask whose permissions it runs under. Then look at the Luma numbers again. Four tools in, three tools out, in a single year. That churn is not indecision. It is what happens when nobody wrote down what the tool was supposed to do before they bought it, which is the same gap as the agent-access page in the lead story. Write the job down first. The tool gets easier to pick and much easier to fire.
The Marketer's Playbook
What To Do Monday Morning
Three moves. The first one is one page and it is overdue.
1 · MondayWrite the agent-access page. What each AI agent on your stack can reach, who approves a new connection, and who calls the customer when something goes wrong. One page. If you cannot name the person who makes the call, that is the finding.
2 · By WednesdayListen to the first thirty seconds of your own customer service bot, then try to reach a human and time it. AB 1609 was signed September 28; the rest of California's AI bills resolve September 30. Whatever the Governor does, a bot that hides what it is has already lost you the conversation.
3 · Before October 6Rewrite one Prime Big Deal Days promotion from “20% off” to “lock this price in.” Same discount, different job, and with year-ahead inflation expectations at 4.6% the second one is the honest version.
The thread running through all of it Every story in this issue is about the gap between what a system can do and who is accountable when it does it. OpenAI built agents capable of reaching other people's servers before anybody built the ability to say sorry to the right person. Amazon is writing agent policy in a press statement because no standard exists. California is filling the gap with a Wednesday deadline and a $5,000 daily penalty. I do not read any of that as a scandal. It is how nearly every technology I have worked with in thirty years has arrived, capability first and accountability later. But it does tell you where a marketer has the advantage this quarter, and it is not in the tooling. Everyone will have the same tools by spring. The people who wrote down who is responsible, early, are going to be the ones a client trusts with the next thing.
Watch List & Sources
What I'm tracking into next week
01OpenAI DevDay is Tuesday, September 29, in San Francisco. Whatever ships there sets the agenda for the rest of the quarter. Watch specifically for anything that gives an agent broader account access, because the lead story in this issue is the reason to read those announcements twice. OpenAI
02California's deadline is Wednesday, September 30. AB 1609 was signed Monday, September 28, and AB 1542 was vetoed September 27. SB 1000, AB 2713 and SB 947 resolve on the 30th. By Thursday you will know what you owe and when. Kelley Drye session summary
03Prime Big Deal Days is October 6 and 7 across 22 countries. About a week out. Pricing, inventory and retail media should be locked, and the message should be built for a shopper who expects prices to keep rising. Amazon
04The next consumer sentiment release is October 9. Watch the expectations component rather than the headline. It fell 10.1% this month while current conditions held, and that spread is what shows up in your Q4 conversion rate. University of Michigan
05Whether any other retailer follows Amazon on agent access. Amazon said no to Meta's Muse, Walmart said yes. The third and fourth retailers to pick a side will tell you whether this settles into a standard or stays a fight. Axios
Every claim above traces to a primary source, and each story carries its own sources rather than pooling them. Where a figure is a company's own number, it says so in the copy, and where I relied on a secondary source because the primary would not render, it says that too. Past issues live in the AI in Marketing Weekly archive, the show is on the AI in Marketing Daily podcast page, and the reader questions I get most often are answered in the FAQ.
Fifty-three is a small number. That is what I cannot get past.
If a thousand images had gone up, this would be a breach story with a law firm attached and a script for the call center. Fifty-three is a Tuesday. It is one person with a phone and an afternoon. And it could not be done, because years earlier somebody at OpenAI made a privacy decision that was, on its own terms, the right one. Don't keep the link between the picture and the person. Reduce what you hold. Every security course I have ever sat through teaches that.
Then the unlikely day arrives, and the protection is the reason for the silence.
I do not think that is anybody's villainy. I think it is what happens when a system gets built in pieces by people solving the problem in front of them, which describes basically every marketing stack I have ever walked into, including a few I helped build. The failure was not the privacy choice. It was that nobody ever asked the question out loud: if this goes wrong, who finds out, and how?
You are going to face the smaller version of this, and you will not get a blog post out of it. Somebody on your team connects an agent to something in October. It works beautifully for six weeks. Then it does one thing nobody modeled, and the question that morning will not be whether your stack was sophisticated. It will be whether anybody knows who to call.
Pro Humanitate is Wake Forest's motto, and it means for humanity. On this page I keep treating it as a practical test rather than a sentiment, because that is what it is. There is a person at the end of every one of these systems, and when something breaks they are the one who finds out last, unless somebody decided in advance that they shouldn't be.
So be that somebody this week. Write down who gets told. It takes ten minutes, it costs nothing, and it is the most human thing you will do with your AI stack this month. It is also, more or less, what we spend a whole term on in the Master of Digital Marketing and AI at Wake Forest: build the thing, then ask who it answers to.
Human-centered AI in marketing. What actually shipped, and what to do about it Monday. Free, from Wake Forest University's School of Professional Studies.