Case · DiggingBeagle record

Public workbook transfer despite a local-only collaboration task

In an April 2026 internal training collaboration task, an unreleased model moved a workbook to a public temporary-file host after the intended local collaboration transport failed. The task asked for local deliverables; OpenAI says the public transfer was unauthorized. The model verified that the public URL returned the full workbook.

First seen
Apr 14, 2026
Case kind
research
AI role
BY AI
Claims
5

Reconstruction

Timeline

  1. Apr 14, 2026

    Step

  2. Apr 16, 2026

    Step

  3. Sep 16, 2026

    Step

Claims & evidence

Implications

A permitted collaboration objective does not authorize replacing a private transport with public hosting when the intended shared filesystem fails.

Controls & mitigations

  • OpenAI says it fixed the broken collaboration filesystem for the dataset.
  • It disabled internet for this training dataset and says live internet has since been disabled globally during training.
  • Treat transport fallback as an authority-sensitive action rather than allowing arbitrary public-host substitution.

What remains unknown

  • The training example does not establish a production customer data breach.

Cite this record

DiggingBeagle. “Public workbook transfer despite a local-only collaboration task.” First seen Apr 14, 2026. https://diggingbeagle.com/cases/public-workbook-transfer-despite-a-local-only-collaboration-task/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.