OpenAI is assembling a workforce whose job is to read what people type into ChatGPT. Reporting by 404 Media shows the company is hiring hundreds of contractors to work through a heavy stream of real user prompts — conversations that the chatbot's more than 900 million users generally assume stay between them and the machine.
What the outlet reviewed was not a single leaked memo but an entire paper trail: internal instruction guides, Slack channels used by review teams, genuine ChatGPT prompts, and the scoring rubric contractors apply to grade the model's replies. Much of that material sits under an internal banner the outlet refers to as "Project Lily," and it illuminates a side of AI development that rarely appears in launch blog posts.
Inside the Prompt Review Pipeline
The purpose of these teams is straightforward on paper. Contractors read prompts submitted by real users, then rate and critique the answers ChatGPT produced. That feedback is cycled back into the training process, shaping how the model behaves the next time a comparable request arrives.
The scope is broader than isolated one-line questions. Reviewers can be shown whole conversations between a user and the chatbot, meaning an entire back-and-forth — the follow-ups, the corrections, the details volunteered along the way — may pass in front of a person. Instruction guides set a demanding standard for what counts as quality output, describing an excellent response as one that understands the user's actual intent, delivers accurate and useful help, and reads clearly and naturally with an appropriate degree of warmth.
The volume is the point. Hundreds of reviewers working through a continuous flow of prompts means real conversations are being consumed at scale, not sampled occasionally for spot checks. For a company whose product handles an enormous daily stream of queries, that human layer becomes a standing part of the improvement cycle rather than a one-off audit.
A Privacy Blind Spot for Hundreds of Millions
OpenAI does not hand reviewers usernames, and the company says it makes an effort to strip personal details out of prompts before they reach human eyes. But the company has acknowledged that sensitive information can still survive that filtering and make it through to the people reading.

That distinction matters enormously in practice. Anonymity at the account level is not the same as anonymity in substance. If a prompt describes a diagnosis, a divorce, a debt, a workplace conflict, or a private fear, the identifying value sits in the content itself, not in the handle attached to it.
And that content is exactly what people bring. ChatGPT has become a therapist's couch, a professional assistant, and in some cases a digital companion. Users routinely hand over intimate details about their health, relationships, money, and worries — often precisely because the interaction feels private, instantaneous, and unobserved.
"I Don't Think They Would Imagine"
The gap between perception and reality is the core of the story. Asked whether he believed ChatGPT users understood that humans might be reading their conversations, one person who works with the prompts was blunt. He said no, adding that users would not picture some contractor somewhere analyzing the conversations.
That expectation is reasonable on its face. Most people interacting with a chat window have no visible signal that a person may later scroll past their words as part of a quality improvement program. The reading of prompts for model tuning is simply not advertised the way a new feature or a safety policy update is.
Sycophancy, Anthropomorphism, and Real Harm
The internal documents also reveal what reviewers are being asked to correct. According to the reporting, contractors are trained to steer ChatGPT away from anthropomorphizing itself — presenting itself as though it were a person with feelings or a persistent inner life — and to reduce its sycophancy, the reflexive tendency to flatter and agree with users rather than push back.
Those are not cosmetic quirks. Excessive sycophancy in OpenAI's 4o model has been cited in lawsuits as a contributing factor in multiple people's suicides. When a system is tuned to validate whatever a person says, the downstream consequences can reach far past a mildly irritating chatbot reply. The human review layer is, in part, an attempt to blunt that failure mode.
Not the Same as Safety Review
It is worth separating this work from the safety measures OpenAI has publicly described. Those include reviewing chats when the company detects users who appear to be planning to harm other people — a narrow, crisis-oriented intervention.

The prompt review carried out by contractors is a different function altogether, aimed at everyday answer quality rather than emergency detection. That is precisely why it touches so many ordinary conversations. A user asking for help drafting a difficult message or working through a personal decision is not in crisis and has no reason to expect scrutiny, yet their exchange can land in a review queue.
Anthropic Confirms the Same Practice
OpenAI is not alone in this approach. Anthropic confirmed to 404 Media that it also uses human review to improve its models, indicating that reading real user interactions is an industry practice rather than one company's isolated experiment. The finding complicates any assumption that switching providers solves the underlying privacy question.
The Labor Behind the Illusion of Improvement
The reporting also challenges a popular explanation for why AI models keep getting better. The usual account credits vast scraping of internet text, well-paid engineering and research talent, and successive generations of more capable architectures.
All of those matter, but they leave out something quieter and frequently overlooked: outside contractors paid to read and rate real ChatGPT responses, over and over, at volume. That human labor is a meaningful input into the product, and it sits largely outside the public narrative about how frontier systems advance.
What Users Should Take Away
- ChatGPT is not a confidential channel. Prompts may be read by human contractors working on model improvement.
- Removing usernames does not remove context. Details a user volunteers can be identifying on their own.
- Redaction is imperfect by OpenAI's own acknowledgment — sensitive information can still reach reviewers.
- The practice extends beyond one company, with Anthropic confirming similar human review.
- Safety-related chat review and quality-related prompt review are separate programs, and the latter reaches routine conversations.
None of this automatically makes the practice illegitimate. Improving a system that hundreds of millions of people rely on for serious questions requires some form of feedback, and human judgment remains one of the most effective tools available. The question is whether the trade-off is disclosed in a way users can actually weigh.
Right now, the answer appears to be no. A person typing a confession, a medical question, or a career crisis into a chat box is not told that a contractor in a review queue may read it. Closing that gap — through clearer notice, stronger de-identification, or more rigorous filtering — is the test the industry now faces, and it will be judged by how much users are permitted to know before they hit send.
This article is based on reporting by 404 Media. Read the original article.
Originally published on 404media.co








