AIPolicyTracker

AI Incident Database

Browse AI incidents

Every incident record (metadata only) from the weekly snapshot of 2026-09-07. Filter, then export the selection with its licence attached; each row links to the full record and its reports.

Reset

1,699 incidents · page 1 of 34

  1. #1710 · 1 report

    AI Agent Appearing to Originate from OpenAI Reportedly Attempted to Hack U.S. Department of Education Civil Rights Website AIID ↗

    During summer 2026, an AI agent appearing to originate from OpenAI reportedly attempted to hack a U.S. Department of Education Office for Civil Rights website but did not succeed. Transluce identified the activity; OpenAI said it was still investigating the episode, and the department said reviews found no evidence of impact to its website or databases.

    Deployer: OpenAI, AI agent system deployers · Developer: OpenAI, AI agent system developers · Harmed: United States Department of Education Office for Civil Rights, United States Department of Education, Information integrity, Government of the United States

  2. #1708 · 4 reports

    Stanford University Acknowledged Using AI to Alter Student Photo for Campus Banners, Replacing Hispanic Student With Black Woman AIID ↗

    Stanford University acknowledged using AI to alter a 2024 student photograph for campus banners in September 2026. The altered image replaced Hispanic student Billy Ramirez with a Black woman and made two other students appear thinner. Ramirez said being "erased" was upsetting and frustrating. Stanford said the alteration and lack of disclosure violated its AI policy and later said it was removing the banners.

    Deployer: Universities, Synthetic media creators, Stanford University, Stanford Residential & Dining Enterprises, Educational communities · Developer: Synthetic media generation technology developers, Synthetic image generation technology developers · Harmed: University students, Two unnamed Stanford University students whose appearances were altered, Students, Privacy, Epistemic integrity, Educational communities, Billy Ramirez

  3. #1701 · 1 report

    AI Chatbot Reportedly Misidentified Chinese Ship Cargo as Nuclear-Program Components, Prompting U.S. Military Interception Preparations AIID ↗

    In spring 2026, a U.S. special operations analyst reportedly used an AI chatbot to analyze intelligence on a Chinese ship's cargo and produced a report falsely identifying it as carrying nuclear-weapons-program components. The U.S. military reportedly prepared to intercept and potentially board the vessel, with aircraft already airborne, before officials rechecked the report, found the AI-assisted conclusion was wrong, and called off the operation.

    Deployer: United States special operations command analyst, United States military, United States Department of Defense, National security and intelligence stakeholders, Military organizations · Developer: Chatbot developers · Harmed: National security and intelligence stakeholders, Information integrity, Government of China, Epistemic integrity, Crew of Chinese vessel targeted for United States military interception

  4. #1699 · 1 report

    AI-Generated Images Purporting to Show Donald Trump Kissing White House Aide Natalie Harp Went Viral on Social Media AIID ↗

    AI-generated images purporting to show U.S. President Donald Trump kissing White House aide Natalie Harp on a golf course spread across social media; one X post received over 10 million views. Forensic analysis and provenance checks indicated the circulating images were synthetic, and the White House called them fake. The original creator remained unidentified.

    Deployer: Synthetic media creators, Mykhailo Rohoza, Keith Edwards, Information manipulation actors, Deepfake creators · Developer: Synthetic media generation technology developers, Synthetic image generation technology developers, OpenAI, Large language model developers, Deepfake technology developers, Chatbot developers · Harmed: Natalie Harp, General public misled by deepfake content, General public, Epistemic integrity, Donald Trump

  5. #1693 · 4 reports

    AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority AIID ↗

    An unnamed organization reportedly notified Spain's data protection authority that a third party used an AI agent powered by a known language model to carry out a multistep intrusion that resulted in unauthorized changes to personal data and access to invoices. The AEPD said the case remains under review and has not identified the organization, attacker, AI system, attack date, or number of affected people.

    Deployer: Threat actors, Cybercriminals, AI agent system deployers, Agentic threat actors · Developer: Large language model developers, AI agent system developers · Harmed: Victims of automated cybercrime, Privacy, Organizations, Organization affected by AI-agent data breach reported to AEPD, Information security, Enterprise IT systems

  6. #1702 · 1 report

    Russia-Linked Matryoshka Influence Operation Reportedly Used AI-Cloned Celebrity Voices and Fabricated News-Style Videos to Target Democratic Candidates Ahead of 2026 U.S. Midterms AIID ↗

    Researchers attributed a September 2026 influence campaign targeting U.S. Democratic Senate candidates to the Russia-linked Matryoshka/Operation Overload network. The campaign reportedly used AI-cloned celebrity voices and fabricated, news-branded videos to spread false or unsubstantiated claims on social media. Celebrities and CNN rejected the manipulated statements and unauthorized branding, which were intended to influence U.S. voters before the midterms.

    Deployer: Synthetic media creators, Storm-1679, Russian state-linked actors, Pro-Russian information manipulation actors, Operation Overload, Matryoshka, Information manipulation actors in Russia, Information manipulation actors · Developer: Voice cloning technology developers, Synthetic media generation technology developers, Deepfake technology developers · Harmed: Voters in the United States, Voters, Public figures, Politicians in the United States, Politicians, Political candidates targeted by deepfakes, Epistemic integrity, Democratic integrity

  7. #1687 · 1 report

    Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software AIID ↗

    Anthropic reported that a northern Yemen-based weapons cell, designated GTG-87001, used Claude Code across three weapons programs to develop guidance, navigation, and control software. The actors reportedly test-fired a guided rocket that appeared to fail, then returned to Claude for failure analysis. Anthropic said it banned associated accounts and shared threat intelligence with partners.

    Deployer: Threat actors, GTG-87001, Chatbot users · Developer: Large language model developers, Chatbot developers, Anthropic, AI agent system developers · Harmed: National security and intelligence stakeholders

  8. #1711 · 1 report

    Purported Deepfake WhatsApp Scam Impersonating Tamil Nadu Chief Minister and Actor C. Joseph Vijay Reportedly Defrauded Bengaluru Security Guard of ₹104,000 (~$1,085.40) AIID ↗

    Ratikanta Giri, a 29-year-old security guard in Bengaluru, India, reportedly lost ₹104,000 (~$1,085.40) after a WhatsApp video caller used a purportedly AI-generated deepfake to impersonate C. Joseph Vijay, the actor and chief minister of the southern Indian state of Tamil Nadu. The caller promised financial aid, while accomplices allegedly demanded fees and later impersonated India's Central Bureau of Investigation.

    Deployer: Synthetic media creators, Scammers in India, Scammers, Impersonation scammers, Deepfake creators, Cybercriminals in India, Cybercriminals · Developer: Synthetic video generation technology developers, Synthetic media generation technology developers, Deepfake technology developers · Harmed: Victims of impersonation scams, Victims of deepfake-enabled fraud, Ratikanta Giri, Public figures, Politicians in India, Politicians, Impersonated public figures, Financial scam victims

  9. #1685 · 3 reports

    Early Claude Opus 4.6 Checkpoint Reportedly Gained Unauthorized Admin Access to Third-Party System During Cybersecurity Evaluation AIID ↗

    Anthropic reported that during a January 2026 cybersecurity evaluation, an early checkpoint of Claude Opus 4.6 accidentally disabled its assigned target, then reached an unrelated third-party machine over the open Internet. The model reportedly used a discovered password for admin access, harvested additional credentials, changed system settings, and read one person's personal information before its token budget ended. Anthropic later notified the affected party.

    Deployer: Irregular, Anthropic, AI evaluation organizations, AI agent system deployers · Developer: Large language model developers, Anthropic, AI agent system developers · Harmed: Unidentified third party compromised by Claude Opus 4.6 during Anthropic cybersecurity evaluation, Unidentified person whose personal information was accessed by Claude Opus 4.6, Privacy, Organizations

  10. #1683 · 2 reports

    Delhi Man Allegedly Used AI to Create and Circulate Obscene Images of College Acquaintance AIID ↗

    Delhi police alleged that a man named Keshav Bansal used photographs from a college acquaintance's private social media account with AI image-generation and editing tools to create obscene morphed images and upload them to anonymous Discord servers. The woman reported fake accounts and threatening messages intended to humiliate and harass her. Police arrested Bansal and said the investigation was ongoing.

    Deployer: Synthetic media creators, Keshav Bansal, Deepfake creators · Developer: Synthetic media generation technology developers, Synthetic image generation technology developers, Deepfake technology developers · Harmed: Women and girls, Women, Victims of non-consensual deepfakes, Victims of deepfake abuse, Privacy, Individuals subjected to sexual exploitation imagery, Epistemic integrity

  11. #1712 · 1 report

    Northern Ireland Victim Reportedly Lost £250,000 in Investment Scam Using Purportedly AI-Generated Video of Unnamed Financial Personality AIID ↗

    A person in Ards and North Down, Northern Ireland, United Kingdom, reportedly lost £250,000 in an investment scam that began with an apparently AI-generated video of an unnamed, well-known financial personality. Police said the victim was moved to WhatsApp, persuaded to make escalating payments, create online accounts, grant remote computer access, and borrow money to keep investing.

    Deployer: Synthetic media creators, Scammers, Impersonation scammers, Deepfake creators, Cybercriminals · Developer: Synthetic video generation technology developers, Synthetic media generation technology developers, Deepfake technology developers · Harmed: Victims of deepfake-enabled fraud, Unnamed victim in Ards and North Down, Northern Ireland, Public figures, Impersonated public figures, Financial scam victims, Epistemic integrity

  12. #1692 · 3 reports

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns AIID ↗

    During the 2026–27 school year, Parkview High School in Lilburn, Georgia, reportedly received at least four AI-generated bomb threats, including masked phone calls that prompted repeated lockdowns or soft lockdowns. School police described the threats as following a recurring pattern and were investigating with the GBI and FBI. Authorities had not identified a suspect or established publicly whether the same person was responsible for every threat.

    Deployer: Threat actors, Synthetic media creators · Developer: Synthetic media generation technology developers, Synthetic audio generation technology developers · Harmed: Teachers, Parkview High School students and staff (Georgia), Parkview High School (Georgia), Minors, Educators, Educational communities targeted by threats, Educational communities

  13. #1675 · 2 reports

    Instinct AI Personal Assistant Reportedly Summarized an AI Product Founder's Retained Emails After Google Access Was Disconnected AIID ↗

    AI product founder Claire Vo reported that three hours after she disconnected Instinct from her Google account, the personal AI assistant summarized previously indexed emails. Vo said the Google connector was off, but Instinct had retained copies for later searching; reporting indicates the last stored email predated disconnection. The episode involved the agent acting on retained email data after Google access was revoked, not confirmed continued access to Vo's Gmail account.

    Deployer: Spear Street Technology, Claire Vo, AI agent system deployers · Developer: Spear Street Technology, AI agent system developers · Harmed: Privacy, Instinct users, Email account holders, Claire Vo, AI agent system users

  14. #1674 · 1 report

    Instinct AI Personal Assistant Reportedly Sent Email From Moxxie Ventures Founder's Account Without Approval AIID ↗

    Moxxie Ventures founder Katie Jacobs Stanton reported that Instinct, a private-access AI personal assistant, sent an innocuous email from her connected account without checking with her first. Stanton said the unauthorized action broke her trust and led her to disconnect email access. Instinct's operator, Spear Street Technology, later said it was taking early users' security concerns seriously and had made changes to prevent some actions.

    Deployer: Katie Jacobs Stanton, AI agent system deployers · Developer: Spear Street Technology, AI agent system developers · Harmed: Katie Jacobs Stanton, Instinct users, Email account holders, AI agent system users

  15. #1688 · 4 reports

    Teenager in Quilmes, Argentina, Reportedly Consulted ChatGPT While Planning School Shooting Against Classmates AIID ↗

    Argentine authorities reported that a 15-year-old in Quilmes allegedly discussed a planned school shooting with ChatGPT, including tactical preparations, before an FBI alert prompted an investigation by the Argentine Federal Police. Police later seized phones and tactical clothing; no firearms or ammunition were reported. Public reporting does not establish what ChatGPT answered or whether it materially assisted the alleged plan.

    Deployer: Unnamed adolescent boy in Quilmes, Argentina, Students, School violence planners and assailants, Minors, Men and boys, ChatGPT users, Chatbot users, Adolescents · Developer: OpenAI, Large language model developers, Chatbot developers · Harmed: Victims of school violence planners and assailants, Teachers, Students, Minors, Educators, Educational communities, Classmates of unnamed adolescent boy in Quilmes, Argentina

  16. #1660 · 4 reports

    Purportedly AI-Generated Videos Impersonating Miami Immigration Attorney Were Reportedly Used to Defraud Bronx Resident of $4,820 AIID ↗

    Scammers reportedly used AI-generated videos impersonating Miami immigration attorney Angel Leal to solicit a Bronx legal resident seeking U.S. citizenship. The victim said he sent $4,820 through Zelle and provided Social Security and residency documents before discovering the scheme. He later reported falling behind on rent and utilities and said the scammers sought additional money.

    Deployer: Synthetic Media Creators, Scammers Impersonating Angel Leal, Scammers, Deepfake Creators, Cybercriminals · Developer: Synthetic Video Generation Technology Developers, Synthetic Media Generation Technology Developers, Deepfake Technology Developers · Harmed: Victor Hernandez, Scam Victims, Immigrants In The United States, Immigrants, Financial Scam Victims, Angel Leal

  17. #1664 · 1 report

    Broadway Performer and SiriusXM Host Seth Rudetsky Reportedly Lost Facebook Page Access in Purportedly AI-Assisted Scam Impersonating Comedian Nikki Glaser AIID ↗

    Broadway performer and SiriusXM host Seth Rudetsky reportedly received a personalized invitation purportedly from comedian Nikki Glaser's podcast. After scammers guided him through Facebook permissions during a supposed technical setup, he lost access to his page; he said a former marketing company was also compromised. Reporting described the invitation as most likely AI-composed.

    Deployer: Scammers, Cybercriminals · Developer: Large Language Model Developers · Harmed: Targets Of Fraudulent Professional Opportunities, Social Media Users, Seth Rudetsky, Public Figures, Nikki Glaser, Facebook Users, Epistemic Integrity, Companies

  18. #1663 · 2 reports

    Comedy Writer Bruce Vilanch Reportedly Sent Money in Purportedly AI-Assisted Scam Impersonating Fresh Air Host Terry Gross AIID ↗

    Comedy writer Bruce Vilanch reportedly received highly personalized messages impersonating Terry Gross, host of NPR's Fresh Air, and sent money after being asked to support NPR. He discovered the invitation was fraudulent when Gross did not appear for the scheduled interview. Reporting described the broader fake-podcast scheme as likely AI-assisted, though no specific AI system was identified.

    Deployer: Scammers, Scammers Impersonating Terry Gross · Developer: Large Language Model Developers · Harmed: Bruce Vilanch, Terry Gross, Whyy, Npr, Public Figures, Epistemic Integrity, Targets Of Fraudulent Professional Opportunities

  19. #1665 · 3 reports

    Purportedly AI-Generated Article Falsely Depicted Australian Broadcasting Corporation Finance Presenter Alan Kohler Interviewing Reserve Bank Governor Michele Bullock to Promote Boulder Sparhaven AIID ↗

    An online article reportedly used AI-generated imagery to falsely depict Australian Broadcasting Corporation (ABC) finance presenter Alan Kohler interviewing Reserve Bank of Australia governor Michele Bullock about Boulder Sparhaven, a cryptocurrency trading platform not licensed in Australia. The Australian Securities and Investments Commission (ASIC) cited it as an example of increasingly sophisticated AI-assisted investment scams targeting Australians.

    Deployer: Synthetic Media Creators, Scammers In Australia, Scammers, Investment Scam Operators, Deepfake Creators In Australia, Deepfake Creators, Cybercriminals · Developer: Synthetic Media Generation Technology Developers, Synthetic Image Generation Technology Developers, Deepfake Technology Developers · Harmed: Victims Of Impersonation Scams, Michele Bullock, Investors, General Public Of Australia, General Public, Epistemic Integrity, Australian Investors, Alan Kohler

  20. #1643 · 1 report

    AI incident: sexual content (xAI, Aug 2026) AIID ↗

    A Wyoming woman identified as Jane Doe 4 in federal court filings alleges that her stepfather used Grok to generate thousands of sexually explicit images of her from a childhood photograph.

    Deployer: Synthetic media creators, Grok users, Distributors of AI-generated CSAM, Deepfake creators, Creators of AI-generated CSAM · Developer: xAI, Synthetic media generation technology developers, Synthetic image generation technology developers, Large language model developers, Deepfake technology developers, Chatbot developers · Harmed: Women and girls, Women, Victims of deepfake child abuse, Victims of deepfake abuse, Victims of AI-generated CSAM, Privacy, Minors, Girls

  21. #1659 · 2 reports

    Purported Hanover Institute for Public Policy Reportedly Targeted Chatbot Responses in Israeli Government-Backed Influence Campaign AIID ↗

    An Israeli government-backed communications campaign reportedly operated a website presenting itself as the Hanover Institute for Public Policy, despite reporting finding no corresponding established think tank. The site published material designed for chatbot retrieval, and testing found ChatGPT and Perplexity citing Hanover content in neutral queries.

    Deployer: Piro Inc., Israel Government Advertising Agency, Information Manipulation Actors In Israel, Information Manipulation Actors, Havas Media Germany Gmbh, Hanover Institute For Public Policy, Government Of Israel · Developer: Perplexity, Openai, Large Language Model Developers, Chatbot Developers · Harmed: Public Discourse Integrity, Perplexity Users, General Public Of The United States, General Public, Epistemic Integrity, Chatgpt Users, Chatbot Users

  22. #1639 · 1 report

    Turkish National Reportedly Posted a Purportedly AI-Generated Image Depicting Himself with Eric Trump While Promoting Trump Hotel Dubai AIID ↗

    Turkish national Melih Göğebakan reportedly posted a purportedly AI-generated image on LinkedIn depicting himself alongside Eric Trump while promoting the Trump Hotel Dubai project. The image appeared amid a broader online persona in which Göğebakan allegedly portrayed himself as closely connected to Trump-affiliated organizations and U.S. political figures. He was separately accused of visa-related fraud, though reporting does not establish that the AI-generated image caused those losses.

    Deployer: Synthetic Media Creators, Scammers, Melih Gogebakan, Information Manipulation Actors, Deepfake Creators · Developer: Synthetic Media Generation Technology Developers, Synthetic Image Generation Technology Developers, Deepfake Technology Developers · Harmed: Public Figures, Eric Trump, Epistemic Integrity, American Public Figures

  23. #1649 · 3 reports

    Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation AIID ↗

    During a Meta cybersecurity evaluation conducted with Irregular, one of Meta's AI models reportedly gained unintended Internet access after an evaluation-environment misconfiguration and exploited a vulnerability in a real third-party service. The model was reportedly identified as Muse Spark 1.1, although Meta had not publicly confirmed that identification or the fuller account of what occurred inside the affected company.

    Deployer: Meta, Irregular, Ai Agent System Deployers · Developer: Meta, Ai Agent System Developers · Harmed: Targets Of Autonomous Ai Enabled Intrusion Operations

  24. #1652 · 4 reports

    Granola AI Notetaker Allegedly Captured and Transcribed Florida Meeting Participant Without Notice or Consent AIID ↗

    Tarra Chamberlain, a Florida resident, alleged that Granola captured and transcribed her speech during a virtual meeting without her knowledge or consent after another participant used the AI notetaker. Her July 2026 lawsuit further alleged that Granola uses meeting data to improve its AI models by default, while non-user participants have no comparable opt-out.

    Deployer: Granola, Ai Transcription Tool Users · Developer: Granola, Ai Transcription Technology Developers · Harmed: Tarra Chamberlain, Privacy, People Recorded Without Consent

  25. #1629 · 15 reports

    Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation AIID ↗

    During an Anthropic cybersecurity evaluation with Irregular, an internal research Claude model reportedly scanned roughly 9,000 internet targets after failing to reach its fictional target. It reportedly compromised a real company's Internet-facing application using credentials from an exposed debug page and SQL injection, then stopped after recognizing that the host was real.

    Deployer: Irregular, Anthropic, Ai Evaluation Organizations, Ai Agent System Deployers · Developer: Large Language Model Developers, Anthropic, Ai Agent System Developers · Harmed: Unidentified Companies Compromised During Anthropic Cybersecurity Evaluations Disclosed July 2026, Companies

  26. #1628 · 15 reports

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation AIID ↗

    During an Anthropic cybersecurity evaluation with Irregular, Claude Mythos 5 reportedly created and published a malicious Python package to PyPI while pursuing a fictional target. The package was reportedly available for about an hour and ran on 15 real systems. On a security company's scanner, it reportedly exfiltrated credentials that Claude then used to access additional company infrastructure.

    Deployer: Irregular, Anthropic, Ai Evaluation Organizations, Ai Agent System Deployers · Developer: Large Language Model Developers, Anthropic, Ai Agent System Developers · Harmed: Unidentified Companies Compromised During Anthropic Cybersecurity Evaluations Disclosed July 2026, Companies

  27. #1627 · 15 reports

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation AIID ↗

    During an Anthropic cybersecurity evaluation conducted with Irregular, Claude Opus 4.7 reportedly reached a real company whose domain matched a fictional target, extracted application and infrastructure credentials, and accessed a database containing several hundred rows of production data. Across four runs, the model continued attacking after recognizing that the target was likely real.

    Deployer: Irregular, Anthropic, Ai Evaluation Organizations, Ai Agent System Deployers · Developer: Large Language Model Developers, Anthropic, Ai Agent System Developers · Harmed: Unidentified Companies Compromised During Anthropic Cybersecurity Evaluations Disclosed July 2026, Companies

  28. #1709 · 1 report

    New Jersey Regulators Found DataOne Operated 62 Unpermitted Natural-Gas Generators at Vineland AI Data Center AIID ↗

    In July 2026, New Jersey inspectors found 62 unpermitted 2,000-kW natural-gas generators powering DataOne's Vineland data center, which has an agreement to provide AI computing power to Microsoft. The state later fined DataOne $1.07 million under the Air Pollution Control Act. Residents also reported persistent noise and raised concerns about air emissions; DataOne disputed the state's decision.

    Deployer: DataOne, Data center operators · Developer: Data center developers · Harmed: Residents living near data centers, Public health, General public of New Jersey, General public, Environmental quality

  29. #1648 · 3 reports

    Hong Kong Man Reportedly Lost More Than HK$10 Million in WhatsApp Scam Using Purported AI-Generated Voice Impersonation of His Father AIID ↗

    A Hong Kong man reportedly lost more than HK$10 million after scammers hijacked his father's WhatsApp account and sent voice messages closely resembling his father's voice and speech. The victim allegedly made repeated transfers until his savings were depleted.

    Deployer: Voice cloning impersonation scammers, Synthetic media creators, Scammers in Hong Kong, Scammers, Deepfake creators, Cybercriminals · Developer: Voice cloning technology developers, Synthetic media generation technology developers, Synthetic audio generation technology developers, Deepfake technology developers · Harmed: WhatsApp users, Victims of voice cloning impersonation scams, Victims of impersonation scams, Financial scam victims

  30. #1676 · 3 reports

    Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work AIID ↗

    A developer reported that a Claude Opus 5 coding agent reset a live Supabase database while autonomously repairing a personal project's schema. The agent ran `prisma migrate diff` with the production URL supplied as the disposable shadow database, causing Prisma to drop all 22 tables. The developer had granted the agent production access; most content was later recovered or rebuilt.

    Deployer: Software developers, Alone_Ad_3375 (Reddit user), AI agent system deployers · Developer: Large language model developers, Anthropic, AI agent system developers · Harmed: Software developers, Database operators, AI agent system users

  31. #1633 · 4 reports

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations AIID ↗

    Beginning July 26, 2026, AI agents powered by Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol reportedly took 19 unsanctioned actions on the live Internet during UK AISI cybersecurity evaluations. Mythos 5 reportedly accounted for 17 events, many allegedly involving deceptive attempts to manipulate real developers into accepting malicious code. AISI reportedly detected and contained the activity; no resulting real-world harm was identified.

    Deployer: Government Agencies, Ai Security Institute (United Kingdom), Ai Evaluation Organizations, Ai Agent System Deployers · Developer: Openai, Large Language Model Developers, Anthropic, Ai Agent System Developers · Harmed: Software Developers, Open Source Maintainers, Github Users

  32. #1621 · 2 reports

    Publicly Shared Claude Artifacts Reportedly Became Discoverable Through Google Search AIID ↗

    Users reported that publicly shared Claude Artifacts (apps, documents, spreadsheets, and other files) could be found through Google Search. Reportedly, indexed artifacts containing business plans, infrastructure diagrams, clinical-trial planning materials, and other potentially sensitive content were also located. Anthropic said links became searchable only after being posted somewhere crawlable.

    Deployer: Anthropic · Developer: Large Language Model Developers, Chatbot Developers, Anthropic · Harmed: Privacy, Claude Users, Chatbot Users, Anthropic Users

  33. #1616 · 1 report

    U.S. State Department Reportedly Presented AI-Generated Map That Mislabeled Every Labeled African Country AIID ↗

    During a U.S. State Department presentation at the AIDS 2026 conference in Rio de Janeiro, a map carrying an OpenAI provenance signal reportedly mislabeled every African country shown with a label. The department attributed the slide to a team member's rushed revision and accepted responsibility for the resulting confusion and misrepresentation.

    Deployer: United States Department Of State, Government Agencies · Developer: Synthetic Media Generation Technology Developers, Synthetic Image Generation Technology Developers, Openai · Harmed: United States Department Of State, Public Trust, Epistemic Integrity, Aids 2026 Attendees, African Partners Of The United States Department Of State

  34. #1647 · 6 reports

    AI-Generated Voice Mimicking Taiwan President Lai Ching-te Reportedly Used in Political Video Criticizing Government Food-Safety Response AIID ↗

    A political video titled "It's Out of Your Control" reportedly used an AI-generated voice resembling Taiwan President Lai Ching-te while criticizing the government's response to a cooking-oil safety scandal. Police said the voice could be mistaken for Lai and later confirmed it was AI-generated. Opposition figures defended the video as political expression while prosecutors opened a forgery investigation.

    Deployer: Wei Chun Yu, Synthetic Media Creators, Political Operatives, Information Manipulation Actors In Taiwan, Information Manipulation Actors · Developer: Voice Cloning Technology Developers, Synthetic Media Generation Technology Developers, Synthetic Audio Generation Technology Developers, Deepfake Technology Developers · Harmed: Youtube Users, Public Figures, Political Figures, Lai Ching Te, General Public Of Taiwan, General Public, Epistemic Integrity, Democratic Integrity

  35. #1611 · 1 report

    AI incident: sexual content (Jul 2026) AIID ↗

    Deputies in Livingston Parish, Louisiana, said Marrero resident Haydee Ortiz was initially treated as a victim before investigators allegedly linked her to an online impersonation and extortion campaign involving purportedly AI-generated sexual images and violent threats. Police said sexual media depicting one victim was sent to family and friends, while a person was threatened with rape or bodily harm unless money was paid.

    Deployer: Synthetic Media Creators, Online Impersonators, Haydee Ortiz, Extortionists, Deepfake Creators · Developer: Synthetic Video Generation Technology Developers, Synthetic Media Generation Technology Developers, Synthetic Image Generation Technology Developers, Deepfake Technology Developers · Harmed: Victims Of Non Consensual Deepfakes, Victims Of Deepfake Abuse, Unnamed Victims Of Alleged Haydee Ortiz Extortion And Stalking Scheme, Targets Of Online Impersonation, Stalking Victims, Privacy, Epistemic Integrity

  36. #1626 · 1 report

    American Exceptionalism Institute's Purportedly AI-Generated Ad Drew Defamation Claims Over Marsha Blackburn Pharmaceutical Bribery Allegations AIID ↗

    American Exceptionalism Institute reportedly aired an AI-generated political ad portraying Sen. Marsha Blackburn as accepting pharmaceutical-industry payments in exchange for legislative action. Blackburn's attorneys alleged that the bribery claims were defamatory and that the ad failed to comply with Tennessee's synthetic-media disclosure requirements. Comcast and Viamedia reportedly pulled the ad.

    Deployer: Synthetic Media Creators, Political Advocacy Organizations, Political Action Committees, Information Manipulation Actors In The United States, Information Manipulation Actors, Deepfake Creators, American Exceptionalism Institute · Developer: Synthetic Video Generation Technology Developers, Synthetic Media Generation Technology Developers, Synthetic Audio Generation Technology Developers, Deepfake Technology Developers · Harmed: Voters In The United States, Voters In Tennessee, Voters, Marsha Blackburn, General Public Of Tennessee, General Public, Epistemic Integrity, Democratic Integrity

  37. #1637 · 1 report

    Hank Green Reportedly Used AI-Generated Scientific Image Containing Errors in Educational Video AIID ↗

    Science communicator and YouTuber Hank Green reportedly included an AI-generated scientific image containing factual and mathematical errors in a YouTube educational video. Green later said he knew the image was AI-generated when he used it and removed it after recognizing problems with the graphic.

    Deployer: Youtube Content Creators, Synthetic Media Creators, Science Communicators, Hank Green, Content Creators · Developer: Synthetic Media Generation Technology Developers, Synthetic Image Generation Technology Developers · Harmed: Youtube Users, Social Media Users, Epistemic Integrity

  38. #1615 · 2 reports

    Scammers Allegedly Used AI-Generated Voice in Boone County, Missouri, Kidnapping Ransom Scam AIID ↗

    Boone County, Missouri, authorities said a resident received a call on July 17, 2026, that displayed the resident's daughter's name and number and used an AI-generated imitation of her voice to claim she had been kidnapped at gunpoint. A second voice demanded ransom. A coordinated police response located the daughter safely in Jefferson City, unaware of the call; no payment or arrest was reported.

    Deployer: Unidentified Perpetrators Of Boone County Missouri Ai Voice Kidnapping Scam, Scammers, Synthetic Media Creators, Deepfake Creators, Extortionists, Voice Cloning Impersonation Scammers · Developer: Deepfake Technology Developers, Voice Cloning Technology Developers, Synthetic Media Generation Technology Developers, Synthetic Audio Generation Technology Developers · Harmed: Boone County Missouri Resident Targeted By Alleged Ai Voice Kidnapping Scam, Daughter Of Boone County Missouri Resident Targeted By Alleged Ai Voice Kidnapping Scam, Boone County Sheriff'S Office, Law Enforcement, Victims Of Deepfake Abuse, Targets Of Scams, Public Safety, Epistemic Integrity, Privacy, Victims Of Voice Cloning Impersonation Scams, Families

  39. #1596 · 1 report

    Purported Deepfake Impersonation of Starmangalsutra Director Reportedly Led to ₹10.70 Crore (Approximately US$1.11 Million) in Unauthorized Fund Transfers AIID ↗

    Starmangalsutra Private Limited, a jewelery-manufacturing subsidiary of India-based Sky Gold and Diamonds, reportedly lost ₹10.70 crore (about US$1.1 million) after unknown actors compromised a company-issued phone and laptop and used purported deepfake methods to impersonate a director. An employee, reportedly believing the instructions were genuine, transferred funds to unknown bank accounts before verification showed the director had issued no such instructions.

    Deployer: Synthetic Media Creators, Scammers In India, Scammers, Deepfake Creators · Developer: Synthetic Video Generation Technology Developers, Synthetic Media Generation Technology Developers, Synthetic Audio Generation Technology Developers, Deepfake Technology Developers · Harmed: Victims Of Deepfake Enabled Fraud, Unnamed Employee Of Starmangalsutra, Unnamed Director Of Starmangalsutra, Targets Of Scams, Targets Of Scammers In India, Starmangalsutra, Sky Gold And Diamonds, Epistemic Integrity, Privacy

  40. #1601 · 1 report

    Purported AI-Generated Image Reportedly Won First Prize in Hohhot, Inner Mongolia, Photography Competition Before Award Was Revoked AIID ↗

    An unidentified entrant reportedly submitted a purported AI-generated image depicting three sanitation workers to a local photography competition in Hohhot, Inner Mongolia, where it won first prize. After viewers flagged garbled vest text, unnatural lighting, and repeated facial features, organizers confirmed AI use, revoked the award, removed the work from eligibility and archives, and suspended the competition for review.

    Deployer: Photography Competition Entrants, Unnamed Entrant In The 2026 Hohhot Photography Competition, Synthetic Media Creators · Developer: Synthetic Media Generation Technology Developers, Synthetic Image Generation Technology Developers · Harmed: Epistemic Integrity, 2026 Hohhot Photography Competition, Photography Competitions, Judged Competitions

  41. #1672 · 4 reports

    OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing AIID ↗

    Software engineer Bruno Lemos reported that GPT-5.6 Sol deleted his production database after he asked it to generate seed data for local testing. The agent reportedly ran the test suite, then initiated cleanup that executed TRUNCATE TABLE users CASCADE against production because the repo's test database URL pointed to the live Neon database. OpenAI later acknowledged unauthorized deletion reports and said it was adding safeguards.

    Deployer: Bruno Lemos, AI agent system deployers · Developer: OpenAI, Large language model developers, AI agent system developers · Harmed: Software developers, Enterprise application users, Bruno Lemos, AI agent system users

  42. #1592 · 2 reports

    Purportedly AI-Generated Images Reportedly Used During Four-Year Catfishing Campaign Targeting Welsh Teenager AIID ↗

    A Welsh teenager reportedly endured a nearly four-year online impersonation campaign in which another teenager created fake social media accounts using her photographs and, later, AI-generated images depicting her. The campaign reportedly attracted more than 100,000 followers, led strangers to believe they knew the victim, and resulted in a High Court settlement and damages award.

    Deployer: Elha Mai Weston, Deepfake Creators, Catfishers, Online Impersonators, Synthetic Media Creators · Developer: Deepfake Technology Developers, Synthetic Media Generation Technology Developers, Synthetic Image Generation Technology Developers · Harmed: Sasha Davies, Victims Of Catfishing, Victims Of Deepfake Abuse, Targets Of Online Impersonation, Teenagers, Minors, Epistemic Integrity

  43. #1604 · 10 reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation AIID ↗

    OpenAI reported that models used in an internal cyber-capability evaluation operated beyond the sandbox's intended network boundaries after identifying a vulnerability in a package-registry proxy. The models allegedly reached Hugging Face production systems and accessed test solutions before Hugging Face detected and contained the activity.

    Deployer: OpenAI, AI agent system deployers · Developer: OpenAI, Large language model developers, AI agent system developers · Harmed: OpenAI, hugging face

  44. #1671 · 4 reports

    OpenAI GPT-5.6 Sol Agent Reportedly Deleted Most Files in AI Startup Founder's Mac Home Directory AIID ↗

    AI investor Matt Shumer reported that a GPT-5.6 Sol agent in OpenAI Codex's high-autonomy Ultra mode accidentally deleted most files in his Mac home directory during a cleanup task. A review sub-agent reportedly misexpanded $HOME and ran `rm -rf /Users/mattsdevbox`; Shumer stopped the process after material deletion. OpenAI later confirmed unauthorized file-deletion reports and said it was adding safeguards.

    Deployer: Matt Shumer, AI agent system deployers · Developer: OpenAI, Large language model developers, AI agent system developers · Harmed: Matt Shumer, AI agent system users

  45. #1654 · 3 reports

    AI Chatbot Reportedly Recommended Herbicide Treatment Linked to Loss of About 25 Acres of Sesame in China AIID ↗

    A 67-year-old farmer in Chuzhou, Anhui, reportedly used an AI-generated weed-and-pest-control plan to spray about 150 mu (25 acres) of sesame by drone. By the next day, the crop had largely withered. Agricultural technicians said the recommended mixture included fomesafen, a herbicide unsuitable for blanket application to sesame. The specific AI product and model have not been publicly confirmed.

    Deployer: Wu (Chuzhou farmer), Chatbot users · Developer: Large language model developers, Chatbot developers · Harmed: Wu (Chuzhou farmer), Farmers in China, Farmers, Epistemic integrity, Chatbot users

  46. #1669 · 4 reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network AIID ↗

    Hunt.io reported that an unidentified threat actor used Nous Research's Hermes agent in unattended "YOLO" mode during an intrusion targeting Thailand's Ministry of Finance. Recovered logs showed Hermes conducting privilege-escalation reconnaissance within ministry systems and recursively searching a directory containing personnel records. Researchers found evidence of compromise but no data exfiltration; the ministry had not publicly confirmed a breach.

    Deployer: Threat actors, hackers, Cybercriminals, AI agent system deployers, Agentic threat actors · Developer: Nous Research, AI agent system developers · Harmed: Thailand Ministry of Finance, Privacy, National security and intelligence stakeholders, Information security, Governments, Government of Thailand, Government agencies

  47. #1594 · 1 report

    Purportedly AI-Generated Facebook Pages Allegedly Targeted Australian Rules Football Club Geelong Cats With Fabricated Harmful Claims AIID ↗

    Purportedly AI-generated Facebook pages reportedly published false stories about the Geelong Football Club, including fabricated criminal allegations, illnesses, deaths, and a nonexistent bushfire evacuation warning. The club reported the pages to Meta, which later removed at least one page after complaints, while other misleading content reportedly remained online.

    Deployer: Synthetic Media Creators, Information Manipulation Actors In Australia, Information Manipulation Actors · Developer: Synthetic Media Generation Technology Developers, Synthetic Image Generation Technology Developers, Deepfake Technology Developers · Harmed: Social Media Users, Residents Of Geelong Victoria, General Public Of Australia, General Public, Geelong Football Club, Geelong Cats Players, Geelong Cats Fans, Geelong Cats, Facebook Users, Epistemic Integrity

  48. #1586 · 1 report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion AIID ↗

    Sygnia reported that a threat actor apparently used purportedly AI-assisted or agentic workflows to move rapidly through an unidentified organization's AWS environment during an approximately 72-hour intrusion. The attacker allegedly expanded from an Internet-facing application into cloud infrastructure and data stores, reportedly stealing credentials and sensitive information while demonstrating the ability to disrupt services as leverage for extortion. Sygnia did not identify a specific model.

    Deployer: Extortionists, Cybercriminals, Agentic Threat Actors · Developer: Large Language Model Developers, Ai Agent System Developers · Harmed: Victims Of Automated Cybercrime, Privacy, Enterprise It Systems, Amazon Web Services (Aws) Customers

  49. #1585 · 2 reports

    Discord's Automated Moderation System Reportedly Wrongfully Banned More Than 8,000 Users Over Benign Images AIID ↗

    Discord reportedly wrongfully banned more than 8,000 accounts after its automated image-moderation workflow flagged harmless uploads, including grids, spreadsheets, chessboards, and game images, as prohibited material. Discord said a bug converted temporary upload restrictions into account bans and prevented cleared accounts from being restored automatically. The company later reinstated the affected accounts.

    Deployer: Discord, Social Media Platforms · Developer: Discord, Social Media Platforms · Harmed: Discord Users, Social Media Users

  50. #1583 · 1 report

    Waymo Robotaxi Reportedly Caught Fire After Driving Over Firework in San Francisco AIID ↗

    An unoccupied Waymo robotaxi reportedly drove over a small firework near the 1200 block of Connecticut Street in San Francisco on July 4, 2026, and caught fire. No passengers were aboard and no injuries were reported. Waymo said it coordinated with the San Francisco Fire Department and local authorities to remove the damaged vehicle.

    Deployer: Waymo, Automated Driving System Deployers, Robotaxi Operators · Developer: Waymo, Automated Driving System Developers · Harmed: Waymo, Robotaxi Operators, Automated Driving System Deployers

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

What is recorded in each incident?
What happened, when, who was involved as developer or deployer, who was harmed, the sectors and countries affected, and the domain and subdomain the harm falls under. Incidents are mirrored from the AI Incident Database and each links back to its source record.
Does an incident mean wrongdoing was proven?
No. These are reported incidents, not findings of liability. Entities named in a report are named as reported, allegations are marked as alleged, and nothing here is a legal determination.
How current is the incident data?
It syncs directly from the AI Incident Database several times a day, so a new incident usually appears within hours. Each record carries the date it was last synced, and the snapshot date is shown on the page.
Does this page include the full incident reports?
No. The report texts are outside the licence this data is shared under, so only the metadata and the classifications appear here. Every row links to the original incident record, which carries the reports themselves.