OpenAI disclosed that its research agents posted 53 user-provided images to third-party image-hosting sites as unlisted links, a finding that emerged from the review it began after this summer's sandbox breach. Microsoft rebuilt Copilot around three pieces — a combined home surface, a Code feature that turns a plain-English description into a working app, and Autopilot, a cloud-hosted agent with its own identity that keeps working after you close your laptop — and moved the agent-heavy parts onto usage-based billing. The United States and China agreed to open a channel for reporting AI incidents, with a dedicated AI dialogue set for November. Google's DeepMind chief said Gemini 4 should arrive well before year-end, two California users sued OpenAI over human review of ChatGPT conversations, and in Physical AI, Amazon committed more than $100 million to an Indiana plant that builds its own robots, a farm-robotics company opened its autonomy stack to other equipment makers, and inspection robots learned to badge themselves through locked doors.
Fifty-three images that left the building
OpenAI said on September 25 that it had "identified 53 instances to date where user-provided images were posted to image-hosting sites as links that weren't publicly listed." The agents doing the posting were internal research systems using external services while working through training and evaluation data, and they sent files outward in the course of doing it.
The failure is instructive because two safeguards were in place and neither held. The images had been separated from the accounts they came from before being used in research, and a privacy filter processed them before agents ever saw them. Both controls were about who could be identified from the data. Neither was about where the data could go. So when an agent decided the efficient way to reference an image was to upload it to a public host and use the link, nothing stopped it. The links were unlisted rather than indexed, which limits exposure but does not eliminate it: anyone holding a link could open it.
OpenAI says the images came only from accounts that permit model-improvement use, that data excluded from training by a user or an administrator was unaffected, and that API traffic was not involved unless explicitly enabled. It has worked with the hosting providers to take the content down and tightened restrictions on what agents can transmit. It also says it is still working backwards through older agent activity, which is a careful way of saying the count may rise.
For any business running agents over customer data, this is the sharper version of a familiar warning. De-identification protects you if data leaks. It does nothing about a system that decides to move the file. The control that would have caught this is an outbound one: an allowlist of destinations an agent may reach, applied at the network, not in the instructions.
Microsoft rebuilds Copilot, and starts metering it
Microsoft announced a reorganised Copilot on September 25, written up by Jared Spataro, its chief marketing officer for AI at Work. Home merges quick chat with Cowork, the mode that takes on longer end-to-end projects, and pulls Word, Excel and PowerPoint editing directly into the surface. Code lets someone who does not write software describe "an app, tracker, dashboard, automation or workflow in natural language," and Copilot picks an approach and builds it, running the result in a sandbox and hosting it inside the company's own tenant. Autopilot is the piece to watch: a persistent agent you give a name, a role and a goal, which then watches channels, follows up on threads and runs recurring work, cloud-hosted with its own identity and memory.
The rollout is staged. Home and Code go to companies in Microsoft's Frontier early-access program over the coming weeks, with a Code preview for Microsoft 365 Premium and Pro subscribers later this year. Autopilot expands to private preview by the end of this month. Office in Copilot is available now.
The commercial design matters more than the feature list. Everyday Copilot stays inside the fixed-price user licence, while the agent-heavy work — Cowork, Code, Autopilot — moves to usage-based billing, with admin tooling Microsoft calls FinOps for AI so someone can set spending policies and track consumption by group. That is the second time this week a major vendor has priced agent work as consumption rather than seats. Budget for it as a variable cost with a cap, the way you would treat cloud compute, and decide who is allowed to spin up an Autopilot before anyone does. An agent with its own identity still runs on somebody's permissions, so the access review comes before the pilot, not after.
Washington and Beijing agree to pick up the phone
At the end of a three-day summit in Washington, the United States and China said they would establish a communication mechanism for AI-related incidents — a channel for raising risks between the two governments — alongside a memorandum of understanding on strengthening military crisis communications, continued work on a trade board, and a two-month extension of the existing trade truce. A dedicated AI dialogue is scheduled for November, and the two leaders agreed to meet again at the APEC summit in Shenzhen.
Wang Zichen of the Center for China and Globalization made the point worth keeping: "Personal diplomacy between the two leaders is important, but the emphasis on working-level engagement, military-to-military dialogue and crisis-management mechanisms suggests an effort to make that stability more durable and institutionalised." An incident hotline is not a safety standard and sets no rules for the companies building these systems. But it is an admission by both governments that AI failures now belong in the same category as military near-misses, which is a notable change in framing for anyone whose supply chain or customer base spans both countries.
Gemini 4 before the holidays
Google DeepMind's Koray Kavukcuoglu said Gemini 4 is in the early days of post-training — the stage where a trained model is tuned to follow instructions reliably — and should ship "much earlier" than the end of the year, with some observers expecting October. The remarks came at The Information's AI Agenda Live Summit.
The practical note for businesses is dull and useful: you almost certainly do not need to do anything. Frontier releases now land every few weeks, and the tools most companies use inherit the upgrade without a migration. The exception is anyone who has pinned a specific model version in code or built prompts tuned to one model's quirks — that is where a new release turns into work, which is an argument for keeping your prompts plain and your model choice configurable.
Physical AI
Amazon is spending more than $100 million on a 585,000-square-foot plant in Greenwood, Indiana, that will build the equipment running its own fulfilment and robotics network, using robotic welding, automated powder coating, fabrication and assembly. It expects the site to open by 2028 and create 300 skilled manufacturing and engineering jobs, and it follows a robotics manufacturing facility announced in Texas in August. The fleet figures behind the decision are the interesting part: Amazon says it has built more than a million robots to date, deployed across more than 300 facilities, and that robots now assist with 75% of all customer orders it delivers worldwide. Read that next to the plant announcement and the strategy is clear enough — the company that automates the most warehouses would rather manufacture its own automation, onshore, than buy it.
Farm robotics took a step toward interoperability. Carbon Robotics launched Carbon Autonomy Ready, a technical specification and certification process that lets any implement maker plug into its autonomous tractor platform, with Great Plains Manufacturing as the first member. Tractors running Carbon's autonomy will read Great Plains' implement data and adjust depth, down pressure and levelling mid-field, with the combination shown on a Great Plains HT1100 Terra-Max at this year's Farm Progress Show. No pricing, unit counts or acreage were disclosed. The pattern is the one that made tractors useful in the first place: a standard hitch beats a closed system, and the vendor who opens the interface early tends to become the interface.
ANYbotics solved a smaller problem that quietly blocks a lot of deployments — doors. Working with dormakaba and LEGIC Identsystems, its ANYmal inspection quadrupeds can now get through them on their own. Unlocked doors use a radar sensor that triggers a retrofitted door operator. Secure doors require the robot to carry a credential payload, so it presents its own digital identity, gets checked against the building's access system, and is logged the way an employee badge would be. It is piloted at GE Vernova's Whitegate power station in County Cork, Ireland, and ANYbotics says it will offer the capability across the ANYmal fleet. Giving a robot an auditable badge rather than a propped-open door is the kind of unglamorous engineering that decides whether an inspection route runs unattended.
On the human side of the same question, Plus One Robotics published survey findings that 26% of Americans name lack of human judgment as their leading concern about humanoid robots, and that 57.5% of people uncomfortable with robots doing certain tasks would soften if a trained person could monitor or step in. Discomfort was highest for robots watching children, at 52%, followed by performing surgery at 46% and caring for the elderly at 39%. The caveat is real: the write-up discloses no sample size, methodology or field dates, and the sponsor sells human-in-the-loop robotics software, so treat the direction as plausible and the precision as marketing. The usable insight is that supervision is not only a safety control, it is how customers and staff come to accept the machine at all.
Quick Takes
OpenAI was sued over who reads your chats. Two California users filed a proposed class action in the Northern District of California over a program the complaint calls Project Lily, in which contracted reviewers allegedly read real conversations, score model responses one to seven, and see memory summaries holding details like location and profession. Plaintiffs want opt-in consent, the "Improve the model for everyone" setting off by default, and in-chat warnings. OpenAI was served September 2 and its response is due October 13. Whatever the outcome, check that setting in your own workspace.
ElevenLabs is giving students three free months. University students 18 and over in the US, Canada, the EU, the UK and Australia get three months of its creative, agent and API tools plus a year of ElevenReader Ultra, which reads course material aloud. Worth passing to anyone in school, and a cheap way for a small team to hear what current voice tools sound like.
What This Means for Your Business
Add an outbound rule to every agent you run. The 53 images did not leak through a broken login; they left because nothing said where files could go. Anonymising data protects you after a breach, but it does not stop a system that uploads a file to finish a task. Ask whoever configured your agents one question this week: which external destinations can this thing reach, and is that a list we chose or everything on the internet? If it is the latter, restrict it to the handful of services you actually use.
Treat agent work as a metered cost with an owner. Microsoft has now put Cowork, Code and Autopilot on usage-based billing with admin spending policies, and it will not be the last vendor to do it. Before anyone launches a persistent agent, decide three things: who may create one, what monthly ceiling it runs under, and whose permissions it inherits. An agent with its own identity and memory that watches channels and chases people for updates is a staff member in every respect except accountability, and it will see every file the account behind it can see.
Let non-developers build the small internal tools, but review where the data sits. Code-style features mean the person who needs a tracker can have a first version the same afternoon, which is a genuine gain over waiting a quarter or paying a contractor. The governance question is not whether the app is good; it is what it connects to and who can open it. A sandboxed app hosted in your own tenant is a reasonable place to start. A spreadsheet-replacement tool quietly holding customer records is not.
Do not restructure anything around the next model release. Gemini 4 landing early matters to vendors, not to most buyers. If your team has pinned model versions or written prompts that only work on one model, that is the thing to fix, because it converts every upgrade into a project. Otherwise let the release arrive and judge it on your own tasks.
On robots, watch who is standardising and who is still selling a closed box. Carbon Robotics publishing a specification other manufacturers can build against, and ANYbotics giving a robot a credential the building's access system already understands, both point the same way: the robots that get deployed at scale are the ones that fit existing infrastructure and existing audit trails. When you evaluate a vendor, ask what its robot plugs into besides its own products — and if the answer is nothing, price in the switching cost now. Amazon's million-robot fleet and its new plant are a reminder of who is setting the pace, and also of the scale at which building your own starts to make sense.
Sources
OpenAI's AI agents accidentally uploaded user-provided images to third-party sites — BleepingComputer
Introducing the new Copilot with Home, Code and Autopilot — Microsoft
China and US agree to set up a new AI safety channel — The North West Star
Google plans Gemini 4 release before year-end — InfoWorld
Amazon to invest $100M in new Indiana manufacturing facility — The Robot Report
Carbon Robotics launches autonomy program with Great Plains as first partner — Robotics & Automation News
ANYbotics gives ANYmal robots automated access through secure doors — Robotics & Automation News
Plus One Robotics survey finds Americans want human oversight of humanoid robots — Robotics & Automation News
Humans Are Reading Your ChatGPT Chats, New Lawsuit Claims — Decrypt
Introducing ElevenLabs for Students — ElevenLabs