:

OPENAI EMPLOYS HUNDREDS TO READ YOUR CHATGPT CHATS

AI DESK2 MIN READ
MON, SEP 14, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

OpenAI has hundreds of contract workers reviewing real ChatGPT conversations and rating them to improve the model. The practice is enabled by default, requiring users to manually opt out.

OpenAI uses hundreds of contract workers to read and evaluate actual ChatGPT conversations, according to 404 Media. These workers rate exchanges on a scale of one to seven, focusing on reducing flattery and overly human-like behavior in the AI's responses. While OpenAI anonymizes the prompts before human review, the conversations can still contain sensitive information. Users have limited visibility into what data reviewers see or how long it's retained. The Opt-Out Problem The review process is enabled through the "Improve the model for everyone" setting, which is turned on by default. Users who want to prevent humans from reading their conversations must manually disable this feature in their account settings. This approach puts the burden of privacy protection on individual users rather than making human review an opt-in feature. What This Means The revelation adds another layer to ongoing debates about data privacy and AI training practices. Major AI companies routinely use human feedback to refine their models, but the scale and default nature of OpenAI's program highlights questions about consent and data handling. Users unaware of the setting may have assumed their conversations were private or only processed by automated systems. The anonymization process may also be insufficient—anonymized data can sometimes be re-identified through context and writing patterns. OpenAI has previously stated that it uses conversations to improve safety and model performance. However, the company has faced criticism for its approach to data governance and transparency around how user information is used. Users who wish to opt out can access the setting directly in their ChatGPT account preferences, though the default status means many may never discover this option.

■ SOURCES

The Decoder

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

OpenAI's web-crawling bots were aware of a significant caching vulnerability in RubyGems before public disclosure, raising questions about vulnerability discovery and responsible disclosure practices.

JUST NOWAI Desk

Attackers compromised HBO Max's official Reddit account to distribute malicious ads using ClickFix exploits. The campaign targeted Windows and macOS users with information-stealing malware.

JUST NOWSecurity Desk

The Manhattan District Attorney's Office has seized 12 websites that created non-consensual deepfake content of celebrities, marking the largest legal action against harmful deepfake platforms to date. The sites collectively victimized approximately 1,200 people.

2H AGOIndustry Desk

A widespread scanning campaign is targeting internet-exposed Vite development servers to steal AWS and Azure credentials. The attack aims to compromise cloud infrastructure through unprotected development environments.

2H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.