OpenAI has implemented significant changes to its data retention policies for ChatGPT users following a legal dispute with major news organizations, including The New York Times. The lawsuit alleged that users were leveraging ChatGPT to bypass paywalls, often by using temporary or deleted chat logs, prompting a court order that required OpenAI to preserve these logs indefinitely. OpenAI initially resisted the order, citing user privacy concerns, but ultimately lost the legal battle. By July, news plaintiffs began reviewing the preserved logs, which contained only ChatGPT's outputs, while attempts by some users to intervene in the case were denied due to their status as non-parties. On September 26, OpenAI was permitted to cease the controversial practice of retaining all output log data that would otherwise be deleted, following a joint motion approved by US Magistrate Judge Ona Wang. However, some users' deleted and temporary chats remain subject to monitoring under the agreement. This development marks a shift in OpenAI's approach to user data privacy and legal compliance, as the company balances regulatory demands with user expectations. Concurrently, OpenAI has experienced a dramatic increase in AI bot traffic, particularly after the release of its GPT-5 model on August 5, 2025. According to Akamai, OpenAI's bots—including ChatGPT-User, GPTBot, and OAI-SearchBot—now account for the majority of AI bot traffic across major web applications and APIs, with overall traffic rising nearly 300% year-to-date. The release of GPT-5 led to a surge in activity: OAI-SearchBot traffic increased by 136%, ChatGPT-User by 65%, and GPTBot by 66% during August and September. These changes in bot behavior are attributed both to increased adoption of the improved GPT-5 model and to modifications in how the bots interact with external sources. The period following the legal settlement and the GPT-5 launch has been characterized by unusual and intensified bot activity, impacting organizations that rely on web and API security. OpenAI's evolving platform and policy landscape underscore the complex interplay between technological advancement, user privacy, and legal oversight. Organizations are advised to monitor these developments closely, as changes in OpenAI's data handling and bot operations may have direct implications for data privacy, compliance, and web infrastructure security. The ongoing adjustments to OpenAI's practices reflect broader industry trends in AI governance and the challenges of managing large-scale AI deployments in a rapidly changing regulatory environment. Security teams should remain vigilant for further changes in bot behavior and data retention practices as OpenAI continues to adapt to legal and market pressures. The intersection of legal action, user privacy, and technical innovation at OpenAI provides a case study in the evolving risks and responsibilities associated with AI-driven platforms.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Akamai published analysis describing notable bot behavior changes following GPT-5, indicating a new development in how automated activity was being observed after the model's release. The reference frames this as a post-GPT-5 shift rather than a long-standing condition.
OpenAI stopped being required to retain deleted chats for most ChatGPT users, marking a policy and data-handling change affecting standard users. Some users remained excluded from the change, indicating the update did not apply universally.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.