NewsStocksLawsuit Claims OpenAI Let Outside Contractors Read Users' ChatGPT Conversations

Lawsuit Claims OpenAI Let Outside Contractors Read Users' ChatGPT Conversations

Author: Decrypt·

Key Takeaways

  • •Two California users filed a proposed class action against OpenAI alleging that outside contractors read real ChatGPT conversations without adequate disclosure to users.
  • •The complaint centers on Project Lily, in which contractors summarize user prompts and rate chatbot responses on a one-to-seven scale as part of reinforcement learning from human feedback.
  • •According to the lawsuit, OpenAI's automated filter does not remove personal details, and reviewer dashboards included a user memories summary that could reveal a person's location, profession, or personal life.
  • •OpenAI says the reviews are intended to curb chatbot behavior that is too human-like or overly agreeable, a trait known as sycophancy.
  • •The plaintiffs are seeking damages, restitution, and punitive damages under eight claims, along with an injunction requiring opt-in consent, a default-off data-sharing setting, and in-chat warnings, with OpenAI's response due October 13.
Lawsuit Claims OpenAI Let Outside Contractors Read Users' ChatGPT Conversations

Two ChatGPT users from California have filed a proposed class action against OpenAI, alleging the company allowed outside contractors to read real user conversations without proper disclosure. The case was filed this month in the U.S. District Court for the Northern District of California. OpenAI was served on September 2 and has until October 13 to respond in court.

The complaint centers on "Project Lily," an internal OpenAI in which contractors hired through third-party staffing firms summarize user prompts and score chatbot answers on a scale of one to seven. The court filing accuses the company of routing real user chats to outside reviewers without clearly telling users first.

Per the complaint, contractors hired for roles such as "AI data reviewer" and "chatbot evaluator" read real ChatGPT prompts and full conversations, summarize what the user was trying to accomplish, and then score and critique four different model responses on a one-to-seven scale.

That process is a basic version of how chatbots like ChatGPT actually improve. Humans grade the AI's answers, and those grades are fed back into training so the model learns which responses people prefer—a technique the industry calls reinforcement learning from human feedback, or RLHF. The lawsuit's core allegation is that users were never clearly told that a person, not just a machine, might be the one reading their chats. And because RLHF is a technique the wider industry relies on, the dispute turns less on how chatbots are trained and more on how clearly companies have to disclose that human eyes may land on user conversations.

OpenAI does run conversations through an automated system before any human sees them. The complaint alleges that the filter does not always catch everything, meaning personal details sometimes reach contractors anyway.

Project Lily was first exposed by the outlet 404 Media on September 14. According to its reporting, reviewers work from a dashboard that includes a "user memories summary"—a recap of a person's past chats that can reveal details such as their general location, profession, or personal life, even though usernames are stripped out.

OpenAI has said the reviews are meant to curb two specific behaviors: the chatbot acting too human-like, and the chatbot being too agreeable—a trait researchers call sycophancy, in which an AI tells a user what it thinks they want to hear rather than what is accurate.

ChatGPT has more than 900 million weekly users, many of whom treat it like a diary, a therapist, or a search engine only they can see. People type in health symptoms, breakup texts, tax questions, and legal troubles. The lawsuit argues that OpenAI's privacy policy names some categories of outside parties who receive access to user data, but never specifically flags data annotation or human evaluation vendors among them.

The complaint packs in eight separate legal claims, including violations of California's Unfair Competition Law and its Consumer Privacy Act, along with common-law claims such as intrusion upon seclusion—a privacy tort that covers prying into someone's private affairs in a way a reasonable person would find offensive. Plaintiffs are seeking damages, restitution, and punitive damages.

The requested injunction is specific. The plaintiffs want OpenAI to require opt-in consent before any conversation goes to an outside reviewer, to turn the "Improve the model for everyone" setting off by default instead of on, to add a clear warning inside the chat window itself, and potentially to delete work product tied to the reviewed conversations while retraining any models that used it. That toggle already exists today, but it defaults to on—so users who want their chats excluded from this kind of review currently have to find and switch it off themselves.

Because the suit is still a proposed class action, it must clear class certification before it can move forward on behalf of the broader group of users. OpenAI's response is due October 13.