A class-action lawsuit was filed in the U.S. District Court for the Northern District of California this month. The complaint directly targets OpenAI, accusing the company of routing real user conversations to third-party contractors without prior notice. OpenAI received a formal summons for the lawsuit on September 2.
The lawsuit centers on an internal program codenamed ‘Project Lily’. The project was first publicly revealed by 404 Media on September 14. Through this program, OpenAI hired workers via outsourcing firms to serve as AI data reviewers and chatbot evaluators.
Contractors were tasked with reading real prompts and conversations from ChatGPT users, drafting summaries, and rating four AI model response options on a scale from 1 to 7.
This rating practice represents a foundational form of Reinforcement Learning from Human Feedback (RLHF) - a method where humans evaluate AI outputs so models learn preferred user responses. OpenAI reasoned that the review process was conducted solely to reduce two AI behaviors: sounding too human-like and being overly agreeable with user opinions.
Automated Filters Prone to Leaks
The primary grievance in the lawsuit highlights a major loophole: more than 900 million weekly ChatGPT users were never clearly warned that human eyes - not just machines - were reading their chats.
OpenAI did operate an automated filtering system before conversations landed on human workers’ screens. However, these filters did not always catch all sensitive information, allowing personal details to slip through to third-party contractors.
The 404 Media report revealed that reviewers worked using a dashboard featuring a user memory summary tool. This feature pulled past conversation recaps that could expose a person’s location, profession, and personal life details.
Hidden Identities Still Vulnerable to Exposure
While the system stripped usernames from the review dashboard, the accumulated context from chat memory summaries left users’ real identities vulnerable to being traced.
The case sparks debate over privacy boundaries in training artificial intelligence. When automated filters fail to catch all sensitive data, the final security layer protecting user conversations ultimately rests entirely on contract workers.
Reported by Decrypt.
Read also: What Is DeFi (Decentralized Finance)?
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




