Last Update: 08/01/2026 at 1:00 PM EST

ChatGPT Expands Into Sensitive Data

Coverage from The Record, Startup Fortune, and others

Articles

33

Active Days

428

The Topic

ChatGPT Expands Into Sensitive Data topic image

OpenAI is extending ChatGPT beyond general conversation into financial guidance, medical-record analysis, persistent file storage, and mental-health safety interventions. These features increase the platform’s practical value while also concentrating highly sensitive information and decisions inside a consumer AI service, raising questions about data retention, legal protections, account compromise, consent, and human oversight. A separate Japan-based incident illustrates how ChatGPT-generated code can also support unauthorized activity against online services.

First Article: 05/26/25

Latest Article: 07/27/26

Summary

  • ChatGPT Finance connects accounts from thousands of financial institutions and exposes balances, spending, investments, and payment information to the service.
  • ChatGPT Health can combine medical records, laboratory data, and wearable information, but connected records may not retain the same protections they had with healthcare providers.
  • OpenAI says financial and health data can be disconnected or deleted and that health data is not used for model training or advertising; experts describe some protections as contractual or insufficient.
  • ChatGPT Library stores uploaded and generated files separately from conversations, so deleting a chat does not necessarily delete associated files.
  • Trusted Contact adds optional human review and notifications for suspected serious self-harm situations, creating a tradeoff between intervention and sensitive mental-health privacy.
  • A Japanese investigation alleges that a teenager used ChatGPT-assisted code and rotating IP addresses to disrupt Bandai Channel and compromise user information.

History

07/27/2026

The story is sharpened around specific ChatGPT product rollouts for finance and health, with clearer claims about data protections and a new human-review safety feature for self-harm cases. The cyber incident is also reframed as a Japanese allegation involving a teenager and rotating IPs, rather than a more general disruptive-code example.

07/25/2026

The biggest change is that the story now includes a new safety-intervention dimension: OpenAI is adding human-reviewed alerts for suspected serious self-harm discussions, which raises fresh concerns about sensitive disclosure. The security angle also broadened, with a reported Bandai incident now described more specifically as ChatGPT-assisted code enabling account disruption and IP-blocking evasion.

Full History

Featured

Timeline: 428 Days

2025Jan 1Mar 5May 28Jul 30Oct 22Dec 242026Jan 1Mar 5May 28Jul 30Oct 22Dec 24

Additional Articles

⭐⭐⭐⭐⭐

New York Post05-14-2026
Aurascape researchers in reports describe AI doxxing, where chatbots like Google Gemini disclose personal contact numbers without consent.
BereaOnline / Chad Hembree03-27-2026
United States v. Heppner ties chatbot privacy to retention and linkage, showing that deleted Anthropic Claude chats can still be outside legal confidentiality protections.
LumiChats / Aditya Kumar Jha04-02-2026
A 2026 comparison of AI providers details how ChatGPT, Claude, Gemini, and Grok vary in conversation logging, retention, training opt-out, and employee access.
Forbes07-01-2026
OpenAI and other AI assistant vendors are scrutinized for third-party data handling that can undermine HIPAA suitability and user expectations of chat deletion.
Geeky Gadgets / Julian Horsey05-26-2025
OpenAI faces a court order to retain all output logs in 2024 amid privacy and copyright disputes in the United States.
CNET / Corin Cesaric-Epple05-14-2026
CNET testing compared Grok, ChatGPT, and Gemini responses about real individuals phone numbers and addresses as Cornell research highlighted user-input training and data retention.
TokenDock04-20-2026
AI safety guidance recommends minimizing and de-identifying personal inputs and reviewing retention, training, and memory settings to reduce privacy and account-compromise risks.
The Tech Buzz04-26-2026
OpenAI outlines ChatGPT data export, chat-history toggles, and training opt-out controls, while describing about-30-day retention for monitoring and deletion.
Torkin Manes LLP05-25-2026
OPC and provincial privacy regulators investigated OpenAI ChatGPT practices and cited consent, transparency, accuracy, and retention compliance problems in Canada.
Common Dreams / John D. Marks04-18-2026
An essay links chatbot privilege and retention orders, plus US information-sharing initiatives, to increased interagency access to user chat logs.

⭐⭐⭐

BleepingComputer / Mayank Parmar03-23-2026
OpenAI rolled out ChatGPT Library globally except the EEA, Switzerland, and the United Kingdom, storing uploaded files in account cloud storage until manual deletion and server removal within 30 days.
CBR / Ami Nazru07-12-2026
Tokyo police investigated and arrested a 15-year-old in Saitama after a November 2025 ChatGPT-assisted attack deleted Bandai Channel accounts and compromised personal data.
CNET / Alex Valdes05-08-2026
OpenAI launched Trusted Contact for adult ChatGPT users worldwide, notifying a nominated contact after human-reviewed self-harm safety signals.
CNET / Dashia Milden06-12-2026
Visa partnered with OpenAI in the United States to enable ChatGPT-initiated Visa payments using tokenization and user-set purchasing limits.
Forbes / Kate O'Flaherty02-09-2026
Users upload personal data to AI caricature tools in 2026 on social media platforms and OpenAI services.
CNET / Alex Valdes03-16-2026
OpenAI plans a text-only adult mode for ChatGPT in the 2020s while advisers warn about minor access risks tied to age-prediction errors.
Mashable / Timothy Beck Werth02-13-2026
Mashable reports in 2025 that viral ChatGPT caricature prompts prompted users to delete chat history and opt out of model-training data use with OpenAI in the United States.
Infosecurity Magazine / Danny Palmer03-30-2026
Check Point researchers reported a ChatGPT vulnerability enabling covert exfiltration via malicious prompts; OpenAI patched it on February 20.
Yahoo07-25-2026
Avtar Singh avoided DNA and social-platform data sharing, then used ChatGPT to identify Savinder Kaur, leading to sibling recognition without genetic testing in 2025.
Umich04-07-2026
Stanford-linked researchers and AI developers describe how default training on chatbot conversations and agentic browsing behaviors can weaken user control over personal data.
Windows Forum04-03-2026
Users managing ChatGPT, Google Gemini, Microsoft Copilot, Alexa, and Siri settings must control AI training, retention, and activity deletion to reduce privacy exposure.
Windows Forum04-03-2026
A privacy guide for major AI assistants explains that disabling model improvement or activity features often reduces future use but does not automatically delete previously stored data.
ZDNET / Radhika Rajkumar03-30-2026
ZDNET reported Duck.ai usage reaching 11.1 million visits in February after DuckDuckGo added anonymized voice chat and image generation.
Fox59 / Zach Myers06-16-2026
Trend Micro says AI assistants can profile users from prompts and recommends limiting sensitive sharing and adjusting privacy settings.
inkl04-17-2026
Users seeking relationship, health, and financial advice through AI chats face privacy risks from conversation logging, review, reuse, and potential breach exposure.
Arslandg / Arslan Ahmad07-27-2026
ChatGPT, Claude, and Gemini store and may use prompts for training unless users adjust model-improvement and retention settings, especially for sensitive questions.
Slate / Rich Juzwiak06-27-2026
An advice column highlights consent and data exposure risks when identifiable nude imagery is uploaded to a large language model.

⭐️⭐️

Time / Nikita Ostrovsky03-25-2026
OpenAI published its Model Spec in 2025 to describe ChatGPT behavior rules, including prohibitions on facilitating mass surveillance and higher-priority high-severity harms.
AI Tuition Hub03-31-2026
In the 2020s, AI privacy discussions highlight how tools like ChatGPT process and may store user inputs for monitoring and improvement, subject to privacy settings.