Your ChatGPT Chats Aren't Private — And the September Model Wave
Two stories dominated AI headlines this week, and if you use AI tools for your creative work — which, if you're here, you probably do — both are worth understanding. One is a privacy wake-up call. The other is a genuinely exciting expansion of the model landscape. Let's dig into both.
Project Lily: The Humans Reading Your ChatGPT Chats
On September 14th, investigative outlet 404 Media published a report that has been making waves ever since. An investigation revealed that OpenAI pays hundreds of contractors over $50 an hour under "Project Lily" to review, summarize, and rate real ChatGPT conversations.
This isn't just a dry corporate data policy story — it has real implications for how you think about what you type into these tools. The news presents a major privacy risk for ChatGPT's users, with people often using ChatGPT as a therapist, professional assistant, or digital friend, and providing it with all sorts of intimate details about their lives.
So what exactly are these contractors doing? Under "Project Lily," reviewers grade model responses, summarize user intent, and flag behaviors such as robotic phrasing or excessive agreement. In other words, the goal is legitimate — making the AI sound less like a machine — but the method involves real people reading real conversations.
OpenAI does have safeguards in place, though they're imperfect. OpenAI scrubs usernames and routes text through an automated tool called Privacy Filter to remove identifying details before conversations reach reviewers, although the system may not catch every rare identifier or ambiguous reference. More troublingly, some Project Lily assignments display a "user memories summary" above the prompt — summaries that can describe what a user has previously used ChatGPT for.
There's also a gap in the opt-out system. OpenAI's current guidance says switching off the "Improve" setting prevents new conversations from being used to train its models — but the result is a difference between conversations that become eligible after a user opts out and those that were already eligible before the setting was changed.
And OpenAI isn't alone here. Anthropic confirmed to 404 Media it is also using human review to improve its models.
What this means for AI creators: If you're generating story ideas, writing scripts, or working through personal creative projects in ChatGPT, treat it the way you'd treat any cloud service — not like a private journal. To opt out of future conversations being used for model training, go to Settings → Data Controls → Improve the model for everyone and toggle it off. It won't retroactively protect past chats, but it limits future exposure.
This is a good reminder that the "magic" of AI improvement doesn't happen in a vacuum. The news dispels the misconception that models are improving only because of mass internet scraping or the power of newer architectures — an important and overlooked part are the outside contractors paid to read and review ChatGPT responses to real prompts over and over again.
The September Model Wave: What Shipped and Why It Matters
Beyond the privacy story, September has been a remarkably busy month for model releases. Twelve new AI models were released in September 2026 so far, from 8 providers. Here are the highlights that matter most for creative practitioners.
GPT-6 Astra and New GPT Image Models
GPT-6 Astra was released by OpenAI on September 3, 2026, followed by GPT Image 2.5 Flare and GPT Image 2.5 Sunburst on September 8, 2026. The new image model variants are particularly interesting for visual creators on platforms like Sunporch — different "Flare" and "Sunburst" variants suggest OpenAI is beginning to differentiate its image generation pipeline the way it has its language models, with different models optimized for different stylistic or technical goals.
DeepSeek V4.1 Flash: Cheap, Fast, and Multimodal
For creators who build or use AI-powered tools, DeepSeek's latest release is hard to ignore on price alone. DeepSeek released DeepSeek-V4.1-Flash on September 10, 2026 under the MIT licence, priced at $0.15 per million input tokens off-peak, with output at $0.60.
What makes it technically interesting is the architecture. The model has a 552 billion parameter backbone but switches on only 8 billion of them for each token it reads, with weights available on Hugging Face under the MIT license and a context window of one million tokens. It also reads images as well as text — making it a capable multimodal tool at a fraction of the cost of frontier closed models.
DeepSeek released V4.1 Flash on September 10 — it is the smallest model in a new architecture family, and it ships with native visual understanding. For independent creators who are self-hosting models or building their own pipelines, the combination of open weights, MIT licensing, and low API prices makes this worth benchmarking against whatever you're currently running.
Sakana AI's Fugu: A Different Kind of Model
One of the more philosophically interesting releases this month comes from Sakana AI. Rather than a traditional foundation model, Sakana AI released Fugu Max and Fugu Ultra v2 — models that route tasks across a pool of AI models rather than functioning as single foundation models.
The two tiers serve different use cases: Fugu Max targets cost, at $2 per million input tokens and $6 per million output tokens — 40 to 60 percent below comparable frontier models on output, Sakana says — and tops six benchmarks including Terminal Bench 2.1 and GPQA Diamond. Meanwhile, Fugu Ultra v2 targets harder reasoning and coding.
The routing approach is worth understanding conceptually: rather than betting everything on one model being best at everything, Fugu dynamically selects among available models for each task. The routing approach lets developers get near-frontier results without locking into one vendor — though it's worth noting that several of the cited benchmarks are Sakana's own and haven't been independently verified yet.
Anthropic and Google Also Shipped
Rounding out the early-September wave, Anthropic shipped Claude Fable 5.1 and Mythos 5.1 on September 1 at an unchanged list price with three breaking API changes — important for any developers with integrations to audit. And Google shipped Gemini 3.8 Flash, including a cybersecurity-focused Cyber variant via a new Fairwind program.
The Bigger Picture
What's striking about September 2026 is how these two storylines connect. The Project Lily revelations remind us that AI improvement is still deeply human — contractors reading prompts, flagging sycophancy, shaping tone. At the same time, the model release wave shows how fast the underlying technology is moving, with open-weight models from DeepSeek and novel orchestration approaches from Sakana challenging the assumption that only the biggest closed labs can deliver frontier capability.
For AI creators, the takeaway is practical: be thoughtful about what you share in any AI chat interface, review your privacy settings, and keep an eye on the open-weight model landscape. The tools available to independent creators in September 2026 are dramatically more powerful — and more affordable — than they were even six months ago.
Sources
- AI News for September 7, 2026 — Daily Edition | AI Weekly
- AI News for September 15, 2026 — Daily Edition | AI Weekly
- AI News for September 2, 2026 — Daily Edition | AI Weekly
- AI News Today, September 16: Top Stories | AI Weekly
- 2026 in artificial intelligence
- The Intelligence Explosion
- Artificial Intelligence News -- ScienceDaily
- AI Updates Today (September 2026) – Latest AI Model Releases
- Xinhua%E2%80%93Sogou AI news anchor
- New AI Model Releases News | September, 2026 (STARTUP EDITION)
- New AI Model Releases — September 2026 Timeline | LLM Gateway
- Apertus (LLM)
- Google Gemini
- Aluminium OS
- Qwen
- Alice AI (AI model family)
- Arena (AI platform)
- AI Model Releases: September 2026 Tracker and Dated Ledger
- Inside ‘Project Lily’: The Humans Reading Your ChatGPT Chats – 404 Media
- OpenAI Hired Contractors To Review ChatGPT Chats but Improve Opt-Out Does Not Remove Earlier Eligible Chats | IBTimes UK
- OpenAI Reportedly Pays Contractors $50+ an Hour to Review ChatGPT Chats
- Hundreds of Contractors Are Reading Real ChatGPT Conversations—Here Is How to Opt Out
- Inside ‘Project Lily’: The Humans Reading Your ChatGPT Chats
- OpenAI paid contractors to read ChatGPT conversations — here's how to protect yourself | Tom's Guide
- ChatGPT
- OpenAI
- AI Weekly: DeepSeek Cuts Prices as Agents Go Hosted
- AI Weekly: DeepSeek Cuts Prices as Agents Go Hosted - DEV Community
- DeepSeek V4: Release Date, Specs, and How to Access It (2026) | Yotta Labs
- DeepSeek-V4.1-Flash: MIT open weights at $0.15 per million
- DeepSeek (chatbot)
- Data Points: DeepSeek-V4.1-Flash’s new architecture
- DeepSeek-V4.1-Flash debuts with $0.003/1M off-peak cached-input rate and benchmarks eclipsing GPT-5.6 Sol, Claude Opus 5 | VentureBeat
- Fugu Ultra v2 vs DeepSeek V4 Pro: the 34x price gap