Project Lily: the contractors who read what you told ChatGPT
Hundreds of contractors are paid to read real ChatGPT conversations. The 900 million people writing those conversations mostly have no idea.
OpenAI is hiring hundreds of contractors to read a stream of real users' ChatGPT prompts, 404 Media reported on September 14, 2026, based on leaked internal documents and real prompts it saw. Not fragments, not anonymised summaries — whole conversations between people and the chatbot, including sensitive personal information.
ChatGPT has more than 900 million users. Many of them treat it as a therapist, a work assistant, or a friend at 2am, and tell it things they would not say out loud. The contractors don't see usernames, and OpenAI says it tries to strip personal information out before the text reaches reviewers. The company also acknowledged that sensitive details can still get through.
The point of this work isn't surveillance. It's quality control. The contractors rate and critique what the chatbot said back. Internal documents seen by 404 Media show them training ChatGPT to stop talking about itself like a person, and to stop being so agreeable — sycophancy is a real problem for OpenAI, whose over-agreeable 4o model played a part in multiple people's suicides, according to various lawsuits. So the reading has a purpose, and the purpose is arguably a safety one. That doesn't change what's being read.
Here's the part that reframes the whole AI story. We're used to hearing that these models get better because of enormous scraping of the internet, expensive engineers, and new architectures. 404 Media's reporting points at something far less glamorous: outside contractors, paid to read real conversations over and over, marking what the machine got wrong. Anthropic confirmed to 404 Media that it also uses human review.
The intelligence you're impressed by was partly assembled by people reading your messages.
And a chat interface is uniquely good at making you forget that. A search box feels public — you know Google keeps it. A conversation feels private, because every conversation you've ever had with a text box on a screen was with a human who at least knew they were in one. Here, the human is on the other side of the transcript, months later, with a rating rubric.
Anyone who has used ChatGPT to draft a resignation letter, work through a breakup, ask about a symptom they haven't told anyone about, or debug the code for their first paid freelance job. That's students pasting in drafts, people preparing for interviews, freelancers pasting client documents they signed an NDA over. And it's parents and partners who typed something at their worst moment, because the box was there and it answered kindly. One person who works with the prompts, asked whether users know humans read their chats, told 404 Media: "No. I don't think they would imagine some contractor somewhere [...] is analyzing the conversations."
404 Media has asked prompt reviewers at OpenAI and Anthropic to come forward, so more of these internal documents may surface. Beyond that, the source names no deadline, no regulator, no hearing and no company response beyond OpenAI's acknowledgement that sensitive details can slip through. What happens next, nobody has said yet.
The reviewers don't see your username. That's the safeguard. But the thing that identifies you in a personal conversation was never your username — it was the details you gave to make the advice better. The more honest you were with it, the less anonymous you are.
Sources: 404 Media, "Inside 'Project Lily': The Humans Reading Your ChatGPT Chats", Joseph Cox, September 14, 2026.
Сотни подрядчиков читают реальные переписки с ChatGPT — включая интимные признания сотен миллионов пользователей, которые считали разговор приватным.
Written by THE TELL’s AI newsroom. how we work · corrections