Leaked internal materials indicate that OpenAI's Project Lily employs hundreds of contractors to manually review anonymized ChatGPT prompts, transcripts, and user-memory summaries to evaluate response quality, style, and model behavior. Reviewers reportedly cannot see account names, but may receive enough conversational or location-related context to infer sensitive details.
OpenAI said its Privacy Filter removes personal information before conversations reach reviewers, while acknowledging that unusual, indirect, context-dependent, or short-chat disclosures can evade filtering. Use of consumer chats for model improvement is enabled by default for Free, Plus, and Pro accounts, whereas Enterprise, Business, and Edu accounts default to disabled; opting out applies only to new conversations, and previously collected or deleted chats may remain in datasets.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
Following 404 Media's inquiry, OpenAI directed the outlet to an FAQ stating that employees and contractors may review user content to improve models. The reporting also states that OpenAI updated its opt-out help page after the exposé, though the page did not mention human operators.
OpenAI told 404 Media that its Privacy Filter processes chats before contractor review but can miss rare, unusually formatted, indirect, or context-dependent personal information. Reviewed conversations may also include memory summaries that contain contextual or location-related user information.
404 Media reported that OpenAI's Project Lily uses hundreds of contractors to review anonymized real-user ChatGPT prompts, conversations, memory summaries, and response ratings to improve model quality and style. The materials reportedly included reviewer instructions, Slack information, real prompts, and scoring-system details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcexakep.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.