OpenAI has engaged hundreds of external contractors to analyze real conversations from ChatGPT users, according to a report by 404 Media.
Documents related to an internal initiative known as Project Lily have come to light, revealing reviewer instructions, Slack communications, response evaluation systems, and user inquiries.
These contractors reviewed dialogues, summarizing user intentions and assessing the chatbot's responses to enhance the quality of ChatGPT's replies.
Reviewers evaluated complete conversations rather than isolated messages, some of which contained sensitive personal information, as noted by 404 Media.
A source from the publication, who deals with inquiries, expressed doubt that users are aware of this review process, stating, "I don’t think they realize that some contractor is analyzing these conversations somewhere."
This internal review process differs from the checks OpenAI has publicly acknowledged, which involve monitoring chats when there is suspicion of potential threats to others. Project Lily is a separate endeavor, the journalists emphasized.
How the Review Process Works
Contractors accessed tasks through a panel, where clicking on a task would reveal a real user inquiry. 404 Media observed several such requests but refrained from disclosing them verbatim to protect sources.
Each reviewer followed a three-step process: reading the request, briefly describing the user's intent, and evaluating a set of generated responses. An example provided in the instructions involved a user seeking help to rephrase a work message in Slack to make it more inviting and conducive to discussion.
Next, the contractor examined four response variants from ChatGPT, highlighting segments that met or failed to meet the training model's requirements. They were required to identify at least three segments and justify their selections.
The final step involved rating the responses on a scale of 1 to 7, where 1 indicated an unusable response and 7 represented a near-perfect answer. Even content-rich responses could receive low scores if they were overly lengthy or convoluted. Justifications ranged from a few sentences to an entire paragraph.
The specific model being trained was not detailed in the documents, nor was it clear whether it pertained to an existing model or a future release.
What ChatGPT Was Trained On
One guideline described an acceptable response as one that captures the user’s intent while providing accurate and helpful assistance in a clear, natural, and moderately warm tone.
Another document marked as “Confidential” instructed the model to adapt to the user’s tone, albeit in a more subdued manner:
"It should remain natural, restrained, and professional, without implying that it is human or experiencing emotions."
Reviewers were tasked with identifying obsequiousness, forced mimicry of style, engaging endings, provocation of irritation, and condescending assumptions—all factors that could detract from the naturalness and authenticity of the response. Instead, responses should be helpful, honest, supportive, and intelligent, but without any condescension.
Additionally, reviewers focused on eliminating "AI-speak" and inappropriate emoji usage. A checklist in the instructions labeled certain usages of emoji as inappropriate.
Context was considered; for example, mentioning a tree in a text about Arbor Day was deemed appropriate, while discussing skulls in a conversation about death or airplanes in an aviation disaster summary was not.
Responses were also prohibited from referencing personal experiences, such as "as a chef, I love..." or "I know how it feels." However, first-person phrases like "I will check" were allowed in service-oriented contexts.
Fact-checking was not part of the reviewers’ responsibilities. The FAQ stated that they were not required to verify information against external sources, as content verification was handled by other project teams. Nevertheless, reviewers flagged factual inaccuracies they observed, and responses to medical, legal, or financial inquiries that lacked citations were rated lower.
What Contractors Knew
User inquiries were anonymized, meaning the account name was not displayed on the panel. However, personal information still came to the reviewers' attention.
Sometimes, a user memories summary block appeared alongside the inquiry, allowing reviewers to glean information about the user's previous interactions with the chatbot, their location, and other life circumstances known to the model.
Instructions mandated that contractors escalate tasks if they encountered personal data or potential safety risks.
OpenAI stated that conversations are processed through a version of the model called the Privacy Filter, designed to identify and remove personal information. The company acknowledged the filter's limitations, noting that it sometimes fails to catch rare identifiers and ambiguous references, and can excessively or insufficiently delete data in short segments or lacking context.
Some requests reviewed by journalists indicated that users did not expect external scrutiny, as they asked ChatGPT to keep their conversations private.
What OpenAI Communicates to Users
404 Media inquired with OpenAI representatives whether they explicitly informed users that their requests could be reviewed by others for the purpose of improving responses, and where such notifications were published. Journalists did not receive a response.
OpenAI’s website mentions that flagged content may be reviewed by humans, but this pertains to service violations and security threats. The privacy policy allows for the use of personal data to enhance models.
Deleted conversations are promised to be wiped from systems within 30 days, except for already anonymized data dissociated from accounts under the consent for model improvement.
After the publication of the article, OpenAI directed the publication to a help section stating that humans may review content to enhance the model's performance.
Conversations are included in training through a setting labeled improve the model for everyone. This setting is enabled by default for Free, Plus, and Pro users, who must manually opt out. However, opting out only applies to new dialogues and does not affect past interactions. For Enterprise, Business, and Edu plans, this setting is initially disabled.
Source: 404 Media.Following inquiries from journalists, the company updated the help page regarding this setting and provided a more detailed explanation of the opt-out procedure. However, there remains no acknowledgment of user requests being read by humans in that information.
Who the Contractors Are
One source for 404 Media, residing in North America, reported earning over $50 per hour for reviewing ChatGPT user conversations. They found the job through a recruitment firm called Crossing Hurdles.
This firm describes itself on its website as a mediator between specialists and clients in the AI training sector.
On Reddit, several individuals reported receiving unsolicited emails from Crossing Hurdles and speculated whether it was a scam.
At the time of 404 Media's publication, the firm's LinkedIn page listed open positions for AI data reviewers, annotators, and "chatbot evaluators."
While OpenAI and ChatGPT were not mentioned in the job descriptions, responsibilities included evaluating AI responses and comparing them. The firm is also involved in projects like filming videos of individuals performing household tasks, which are used to train robots.
The reviewer described their work as somewhat mechanical, noting that while reading requests can be amusing at times, the overall task is quite repetitive. They mentioned that the project often lacks consistency, with rules frequently changing and sometimes contradicting one another.
Anthropic confirmed to 404 Media that it also employs human reviewers to improve its models, including future responses from Claude. This applies to users who have enabled the setting Help improve our AI models.
Before review, the company anonymizes conversations and removes account identifiers, including email addresses.
Google Gemini has a disclaimer indicating that some saved chats are reviewed by humans.
Expert Evaluations
Michal Luria, a senior fellow at the Center for Democracy & Technology, deemed human review necessary for safety but pointed out the deceptive feelings it can create.
"Current chatbot interfaces automatically create a false sense of intimacy and privacy," she noted.
She contrasted this with moderation on social media, where content publication inherently involves both platform review and public visibility.
UCLA professor Sarah T. Roberts, author of the book Behind the Screen on content moderation, compared the revelation to the plot of The Wizard of Oz, where characters discover a person pulling the levers behind the magical kingdom:
"They require constant, ongoing human intervention."
The hourly rate exceeding $50 significantly surpasses what social media moderators and AI annotators typically earn, especially those often hired abroad. Roberts speculated that such pay might be temporary, suggesting that human labor, which is essential for product functionality, is often the least valued and poorly compensated.
It is worth noting that in April 2026, OpenAI released the Privacy Filter, a free tool with 1.5 billion parameters designed to cleanse confidential information from conversations with ChatGPT.
