Esc
EthicsEmerging

Lawsuit alleges contractors reviewed private ChatGPT conversations

Is this a scandal?

Not yet — an early signal. Noise 53/100, holding steady, across 3 sources.

SCAND-260784as of Methodology
Cite this incident"Lawsuit alleges contractors reviewed private ChatGPT conversations." SCAND.Ai incident SCAND-260784, noise 53/100 as of September 25, 2026. https://scand.ai/scandal/lawsuit-alleges-contractors-reviewed-chatgpt-chats
FORECASTForecast, not fact

Courts will likely examine whether OpenAI's disclosures met reasonable notice standards because similar tech privacy cases often settle based on transparency adequacy rather than absolute prohibitions.

Confidence: Likely (~70%)

Next to watch: Filing of a motion for preliminary approval of a class action settlement in the relevant federal district court.

How we reached this call
53

Noise 53/100 — louder than 99% of tracked AI controversies.

AI-assisted analysis · How we work

Why it matters

This case tests whether AI firms must explicitly disclose human review in privacy policies, potentially redefining consent standards for model training and user trust.

Key points

  1. Proposed class action alleges OpenAI failed to disclose third-party contractor review of ChatGPT conversations.
  2. Complaint identifies an internal program named Project Lily for routing real user chats to external reviewers.
  3. OpenAI confirms authorized humans and service providers can access user content under certain circumstances.
  4. Lawsuit focuses on inadequate notice rather than unauthorized access or data security breaches.
  5. Case challenges sufficiency of current AI privacy disclosures regarding human-in-the-loop training processes.

The story

A proposed class action lawsuit filed September 25, 2026, accuses OpenAI of failing to adequately disclose that third-party contractors reviewed real ChatGPT conversations through a program allegedly called Project Lily. The complaint claims users were not properly notified that outside workers could read, summarize, and evaluate their private chats to improve model performance. OpenAI confirmed that authorized personnel and service providers may access user content in specific circumstances but did not address the specific allegations regarding Project Lily. The suit centers on transparency obligations rather than data breaches, arguing that existing privacy notices insufficiently informed users about human involvement in processing sensitive inputs. Legal experts suggest this case could establish new precedents for how AI companies communicate data handling practices. The litigation arrives amid growing scrutiny of AI labor practices and user privacy expectations in generative AI services.

Who's involved

Critic
Plaintiff Class

Alleges OpenAI failed to disclose human review of private chats, violating privacy laws and user trust.

Defender
OpenAI

Confirms authorized access occurs per terms of service but does not admit wrongdoing regarding specific allegations.

Most contested claim

OpenAI 'quietly' routed private chats to contractors without telling users and violated privacy laws.

Read the full story

How we got here

This litigation reflects a recurring pattern in the AI industry where data annotation and reinforcement learning from human feedback (RLHF) workflows collide with consumer privacy expectations. Historically, technology firms have relied on broad terms of service to authorize human quality assurance, but regulators and plaintiffs are increasingly testing whether such boilerplate language satisfies informed consent standards when sensitive personal data is involved. Previous disputes in the tech sector have established that 'access' and 'review' can be legally distinct concepts; users often consent to automated processing but may not reasonably anticipate human inspection of private communications. This case continues a trend of scrutinizing the 'human-in-the-loop' supply chain, where third-party contractors perform essential model alignment tasks that are operationally necessary but reputationally and legally sensitive. The precedent being tested here concerns the specificity of disclosure: whether general references to 'service providers' suffice when the service involves subjective human evaluation of private content, or if explicit, granular notice is now required to maintain valid user consent in the generative AI era.

The full story

On September 25, 2026, a proposed class action lawsuit was filed against OpenAI, alleging that the company failed to adequately disclose that third-party contractors were reviewing, summarizing, and evaluating private ChatGPT conversations. According to the complaint cited by Decrypt and Top Class Actions, this human review process occurred through an internal initiative referred to as 'Project Lily,' which purportedly routed real user chats to outside vendors for the purpose of model improvement and grading without providing clear notice to users. The plaintiffs argue that this practice violates privacy laws and breaches user trust by omitting material information regarding human access to personal data.

OpenAI has responded to these allegations by acknowledging that authorized personnel and service providers may access user content under specific circumstances, as outlined in their terms of service. However, the company has not admitted wrongdoing regarding the specific claims of undisclosed review or the existence of Project Lily as described in the suit. Multiple sources, including KuCoin News and Class Action Lawsuits, confirm that the core legal theory rests on the adequacy of disclosure rather than the mere fact of access; the plaintiffs contend that while terms of service may mention data use, they do not sufficiently inform users that human beings are actively reading and processing their specific conversations for training purposes.

The sequence of events highlights a growing tension between AI development workflows and consumer privacy expectations. The lawsuit, first reported widely on September 25, 2026, asserts that users operated under the assumption of automated processing, whereas the reality involved human intervention. Decrypt reports that the accusation specifically targets the 'quiet' routing of conversations, suggesting a systemic lack of transparency. Conversely, OpenAI’s confirmation of authorized access policies indicates that the company believes its existing disclosures cover these operational necessities, setting up a legal dispute over the interpretation of consent and the granularity required in privacy notices for generative AI services.

What's confirmed, what's disputed

  • ConfirmedA proposed class action accuses OpenAI of routing real conversations to outside contractors through a program called Project Lily without telling users.
  • ConfirmedPlaintiffs allege OpenAI failed to adequately disclose that third-party contractors may read, summarize and evaluate users' ChatGPT conversations.
  • ConfirmedOpenAI confirms that authorized humans and service providers can access user content in certain circumstances.
  • ConfirmedThe lawsuit alleges outside contractors reviewed real chats to help improve OpenAI's models.
  • ConfirmedThe core allegation is that OpenAI did not adequately disclose to users that outside contractors might review, summarize, and evaluate their conversations.

The strongest case each way

Critic's case

Users cannot provide meaningful consent to human review of private data if that review is buried in generic terms or conducted through undisclosed programs like Project Lily; the sensitivity of conversational AI demands explicit, affirmative notice distinct from standard automated processing disclosures.

Defender's case

Human review is a standard, necessary component of AI safety and model improvement that is explicitly covered by existing terms of service authorizing service provider access; redefining 'adequate disclosure' to require itemized notification for every backend QA workflow would make safe AI development operationally impossible.

Times this happened before

  • BetterHelp FTC Settlement · 2023Company paid $7.8M for sharing health data with third parties despite vague privacy promises; established that 'service provider' disclosures must be specific about data recipients and purposes.
  • Meta Biometric Privacy Litigation · 2024Settlements reinforced that technical compliance with terms does not shield against claims of inadequate notice for sensitive data processing.

What's at stake

The primary parties at risk are OpenAI and the proposed class of ChatGPT users who allege their private conversations were reviewed without adequate consent. The magnitude of potential liability depends on class certification and statutory damages under applicable privacy laws, which are currently unquantified in available sources. Beyond direct financial exposure, the stakes include operational disruption to OpenAI’s model improvement pipelines if human review processes must be paused or restructured to meet new disclosure standards. For the broader industry, the case establishes a potential benchmark for privacy policy granularity; a plaintiff victory could necessitate costly retroactive compliance measures across all firms utilizing third-party annotators for sensitive data. Users face the risk of continued uncertainty regarding data handling, while OpenAI risks reputational damage and precedent-setting legal findings on the sufficiency of current AI industry disclosure norms.

Join the Discussion

Discuss this story

Community comments coming in a future update

Be the first to share your perspective. Subscribe to comment.

Noise Level

Buzz53?Noise Score (0–100): how loud a controversy is. Composite of reach, engagement, star power, cross-platform spread, polarity, duration, and industry impact — with 7-day decay.
Decay: 99%
Reach
45
Engagement
88
Star Power
35
Duration
6
Cross-Platform
50
Polarity
72
Industry Impact
68

The timeline

  1. Lawsuit filed alleging human review of ChatGPT logs

    Complaint claims contractors accessed private conversations; OpenAI acknowledges authorized access policies exist.

The full record

Sources & methodology

The records from this story's original coverage were pruned, so items marked located later were found by searching for it afterwards. The summary above has since been rewritten to take them into account — it is not the text first published. How we score →

Where the sources disagree

In dispute OpenAI 'quietly' routed private chats to contractors without telling users and violated privacy laws.

Established A lawsuit has been filed making these allegations; OpenAI acknowledges authorized human access policies exist but disputes the characterization of non-disclosure.

What's being under-reported

Missing perspective from the third-party contracting firms performing the actual review work; their operational protocols, NDAs, and training materials would clarify whether 'review' constituted systematic reading or sampled auditing. Also absent is technical documentation distinguishing Project Lily from standard RLHF pipelines, which would determine if the program was exceptional or routine. Without contractor testimony or internal workflow diagrams, the case hinges entirely on plaintiff characterization versus OpenAI's general policy acknowledgments.

Who changed their mind, and why
  • Plaintiff ClassFormalized allegations into a class action complaint focusing specifically on the 'Project Lily' program and adequacy of disclosure. (was: General user concern regarding privacy and data usage.)
  • OpenAIAcknowledged authorized access policies in response to filing but maintained position that disclosures are sufficient. (was: Standard terms of service permitting service provider access.)

The forecast, in full

How we reached this call

Forecast, not fact · Confidence: Likely (~70%) · an editorial estimate we score when this resolves.

The reasoning

  1. Class action lawsuits against major tech firms over human review of voice or text data historically resolve via settlements that include financial payouts and policy updates, rather than full trials on the merits.
  2. The base rate for settlement in tech privacy class actions concerning data annotation and RLHF workflows is high, driven by the corporate desire to avoid discovery risks, negative PR, and the high cost of litigation.
  3. OpenAI's reliance on broad Terms of Service for 'Project Lily' faces strict scrutiny under modern informed consent standards; however, proving actual damages or wiretap violations is difficult for plaintiffs, pushing both sides toward a negotiated settlement with updated opt-in disclosures.
  4. Therefore, the most likely outcome is a settlement where OpenAI updates its privacy notices to explicitly address human review without admitting liability, while a minority of cases escalate into regulatory probes or face early dismissal if the court finds the existing ToS legally sufficient.

What's pushing the call

  • Public and regulatory scrutiny of AI data supply chains
  • Judicial skepticism of boilerplate privacy policies in AI training
  • Cost and reputational risk of prolonged discovery in class actions

Three ways this could go

Base60%

OpenAI reaches a financial settlement with the plaintiff class and implements a mandatory, explicit opt-in mechanism for human review of ChatGPT logs, without admitting liability. This mirrors historical resolutions in tech privacy disputes where companies update disclosures to avoid protracted litigation.

Watch for: Filing of a motion for preliminary approval of a class action settlement in the relevant federal district court.

Escalation25%

The lawsuit survives early motions, and discovery reveals internal communications showing deliberate obfuscation of the human review initiative, prompting the FTC or state attorneys general to open parallel investigations into OpenAI's privacy practices.

Watch for: Issuance of a Civil Investigative Demand (CID) or subpoena by the FTC or a State Attorney General to OpenAI regarding human review practices.

Resolution10%

The court dismisses the lawsuit or grants summary judgment for OpenAI, ruling that the existing Terms of Service and Privacy Policy provided legally sufficient notice of service provider access under the applicable privacy statutes.

Watch for: Court scheduling a hearing specifically on OpenAI's motion to dismiss based on the sufficiency of the Terms of Service.

≈5% — something else entirely. A forecast should leave room for the unforeseen.

You're up to date

That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.

Follow this story

We keep this page current — no need to check back. We'll send the next real change to your inbox, nothing else.

Tracking this story since September 25, 2026.