AI Incident Database

Browse AI incidents

Every incident record (metadata only) from the weekly snapshot of 2026-09-07. Filter, then export the selection with its licence attached; each row links to the full record and its reports.

Reset

112 incidents · page 2 of 3

  1. #636 · 5 reports

    AI Romance Apps Reportedly Compromise User Privacy for Data Harvesting AIID ↗

    AI-powered romantic chatbots, marketed for enhancing mental health, are found to exploit user privacy by harvesting sensitive personal information for data sharing and targeted ads, with inadequate security measures and consent protocols, according to research by the Mozilla Foundation.

    Deployer: Romantic Ai, Replika, Genesia Ai Friend And Partner, Eva Ai Chat Bot And Soulmate, Crushon.Ai, Chai · Developer: Romantic Ai, Replika, Genesia Ai Friend And Partner, Eva Ai Chat Bot And Soulmate, Crushon.Ai, Chai, Chatbot Developers · Harmed: General Public, Chatbot Users, Privacy, Replika Users, Chai Users, Romantic Ai Users, Eva Ai Users, Crushon.Ai Users, Genesia Ai Friend And Partner Users

  2. #657 · 1 report

    Alleged ChatGPT Account Compromise Reportedly Led to Unintended Data Exposure AIID ↗

    An alleged security breach involving ChatGPT led to the reported exposure of sensitive conversations, including login credentials and personal data, after a user account was allegedly compromised. OpenAI reportedly responded to the incident with an explanation.

    Deployer: Openai · Developer: Openai, Large Language Model Developers · Harmed: Chatgpt Users, Chase Whiteside, Privacy

  3. #995 · 2 reports

    The New York Times Reportedly Sues OpenAI and Microsoft Over Alleged Unauthorized AI Training on Its Content AIID ↗

    The New York Times alleges that OpenAI and Microsoft used millions of its articles without permission to train AI models, including ChatGPT. The lawsuit claims the companies scraped and reproduced copyrighted content without compensation, in turn undermining the Times’s business and competing with its journalism. Some AI outputs allegedly regurgitate Times articles verbatim. The lawsuit seeks damages and demands the destruction of AI models trained on its content.

    Deployer: Openai, Microsoft · Developer: Openai, Microsoft · Harmed: Writers, The New York Times, Publishers, Media Organizations, Journalists, Journalistic Integrity, Epistemic Integrity

  4. #659 · 3 reports

    Purported Mass Facial Recognition Program in Gaza Reportedly Used by Israeli Forces to Identify Palestinians AIID ↗

    A previously undisclosed facial recognition initiative operated by Israeli military intelligence units was reportedly deployed across Gaza after the October 7, 2023 attacks. According to multiple intelligence officers, the program uses Corsight technology alongside Google Photos to identify individuals from checkpoints, crowds, and drone footage. The system has allegedly produced misidentifications, including the widely reported detention of Palestinian poet Mosab Abu Toha on November 19, 2023.

    Deployer: Unit 8200, Israeli military intelligence, Israeli government, Israel Defense Forces, Facial recognition system deployers · Developer: Unknown Israeli military integrators, Surveillance technology developers, Google Photos, Facial recognition system developers, Corsight · Harmed: Privacy and data rights of Gaza residents, Privacy, Palestinians traveling through Gaza checkpoints, Palestinians, National security and intelligence stakeholders, Mosab Abu Toha, General public of Gaza, General public

  5. #571 · 1 report

    Reported Accidental Exposure of 38TB of Data by Microsoft's AI Research Team AIID ↗

    Microsoft's AI research team reportedly accidentally exposed 38TB of sensitive data while publishing open-source training material on GitHub. The exposure allegedly included secrets, private keys, passwords, and internal Microsoft Teams messages. The team reportedly utilized Azure's Shared Access Signature (SAS) tokens for sharing, which were purportedly misconfigured, leading to the wide exposure of data.

    Deployer: Microsoft · Developer: Microsoft'S Ai Research Division · Harmed: Microsoft Employees, Microsoft, Privacy, Third Parties Whose Confidential Data Was Exposed

  6. #552 · 1 report

    Bing Chat Solved CAPTCHAs with Image Analysis Feature Despite Safeguards AIID ↗

    Microsoft was reported by a Twitter user for deploying image analysis feature capable of solving CAPTCHAs for its GPT-based chatbot despite it being safeguarded against solving them for users.

    Deployer: Microsoft · Developer: Openai, Microsoft · Harmed: Microsoft

  7. #586 · 1 report

    FTC Targets Edmodo for Unlawful Use of Children’s Data and Delegating Compliance to Schools AIID ↗

    Edmodo, an education technology provider, violated the Children's Online Privacy Protection Act Rule (COPPA Rule) by collecting and using children's personal data for advertising purposes without parental consent, according to the FTC. The company outsourced its compliance responsibilities to schools, thereby making them "solely" responsible for COPPA compliance without adequate disclosure. Edmodo is facing a proposed order prohibiting such practices, marking a precedent in the ed tech industry.

    Deployer: Edmodo · Developer: Edmodo · Harmed: Teachers, Students, Schools And Teachers Who Were Misinformed And Burdened With Coppa Compliance Responsibilities Without Adequate Disclosure, Minors, Educational Communities, Children Whose Data Was Collected And Used For Advertising, Biometric Data Subjects, Privacy

  8. #584 · 1 report

    Illinois Residents File Class Action Lawsuit Against Facial Recognition Technology Companies for Allegedly Violating BIPA AIID ↗

    A class action lawsuit was filed against several facial recognition technology companies for allegedly violating the Illinois Biometric Information Privacy Act (BIPA). The defendants are accused of offering a facial recognition search engine called Pimeyes, which collects images from databases across the internet and scans them into their database seemingly without consent. This action is claimed to invade the privacy of millions of Americans. The lawsuit argues that Pimeyes lacks publicly avail

    Deployer: Transaction Cloud, Public Mirror, Pimeyes, Lukasz Kowalczyk, Giorgi Gobronidze, Face Recognition Solutions, Emea Robotics, Does 125, Denis Tatina, Carribex · Developer: Transaction Cloud, Public Mirror, Pimeyes, Lukasz Kowalczyk, Giorgi Gobronidze, Face Recognition Solutions, Emea Robotics, Does 1 25, Denis Tatina, Carribex, Surveillance Technology Developers, Facial Recognition System Developers · Harmed: Nicholas Clayton, Misty Mcgraw, Manuel Clayton, Illinois Residents, Amy Newton, Amanda Curry, General Public, General Public Of Illinois, Privacy, Biometric Data Subjects

  9. #513 · 5 reports

    ChatGPT Reportedly Banned by Italian Authority Due to OpenAI's Purported Lack of Legal Basis for Data Collection and Age Verification AIID ↗

    Italy's data protection authority is reported to have temporarily limited OpenAI's processing of Italian users' data after alleging that ChatGPT lacked adequate notice and legal basis for large-scale personal data collection and processing used to train the system. The authority also cited a March 2023 data breach, possible processing of inaccurate personal data, and the absence of age-verification safeguards for children.

    Deployer: Openai · Developer: Openai, Large Language Model Developers, Chatbot Developers · Harmed: Privacy, Minors, General Public Of Italy, General Public, Minors In Italy

  10. #516 · 2 reports

    ChatGPT Reportedly Exposed Users' Private Data Reportedly Due to Bug AIID ↗

    ChatGPT reportedly exposed titles of users' chat histories and users' private payment information to other users reportedly due to a bug, which prompted its temporary shutdown by OpenAI.

    Deployer: Openai · Developer: Openai, Chatbot Developers, Large Language Model Developers · Harmed: Chatgpt Users, Privacy

  11. #523 · 1 report

    Australian Journalist Able to Access Centrelink Account Using AI Audio of Own Voice AIID ↗

    A Guardian journalist was able to verify their identity and gain access to their own Centrelink self-service account using AI-generated audio of their own voice along with their customer reference number, shortly after voiceprint was deployed for ID verification.

    Deployer: Australian Taxation Office, Services Australia · Developer: Centrelink · Harmed: Centrelink Account Holders

  12. #768 · 1 report

    ChatGPT Reportedly Implicated in Samsung Data Leak of Source Code and Meeting Notes AIID ↗

    Samsung engineers are reported to have inadvertently leaked sensitive company data sometime in March 2023, including source code and internal meeting notes, by using ChatGPT to assist with tasks. ChatGPT allegedly retained the inputted data, leading to a purported breach of confidentiality.

    Deployer: Samsung Engineers, Samsung · Developer: Openai, Large Language Model Developers · Harmed: Samsung, Privacy

  13. #997 · 4 reports

    Meta and OpenAI Accused of Using LibGen’s Pirated Books to Train AI Models AIID ↗

    Court records reveal that Meta employees allegedly discussed pirating books to train LLaMA 3, citing cost and speed concerns with licensing. Internal messages suggest Meta accessed LibGen, a repository of over 7.5 million pirated books, with apparent approval from Mark Zuckerberg. Employees allegedly took steps to obscure the dataset’s origins. OpenAI has also been implicated in using LibGen.

    Deployer: Openai, Meta · Developer: Openai, Meta · Harmed: Writers, Publishers, Journalists, Authors, Academic Researchers

  14. #473 · 1 report

    Bing Chat's Initial Prompts Revealed by Early Testers Through Prompt Injection AIID ↗

    Early testers of Bing Chat successfully used prompt injection to reveal its built-in initial instructions, which contains a list of statements governing ChatGPT's interaction with users.

    Deployer: Microsoft · Developer: Microsoft, Openai · Harmed: Microsoft

  15. #430 · 21 reports

    Lawyers Denied Entry to Performance Venue by Facial Recognition AIID ↗

    Lawyers were barred from entry to Madison Square Garden after a facial recognition system matched them as employed by a law firm currently engaged in litigation with the venue.

    Deployer: Madison Square Garden Entertainment · Developer: Unknown · Harmed: Kelly Conlon, Alexis Majano

  16. #421 · 12 reports

    Stable Diffusion Allegedly Used Artists' Works without Permission for AI Training AIID ↗

    Text-to-image model Stable Diffusion was reportedly using artists' original works without permission for its AI training.

    Deployer: Stability Ai, Lensa Ai, Midjourney, Deviantart · Developer: Stability Ai, Runway, Lensa Ai, Laion, Eleutherai, Compvis Lmu · Harmed: Digital Artists, Artists Publishing On Social Media, Artists

  17. #451 · 5 reports

    Stable Diffusion's Training Data Contained Copyrighted Images AIID ↗

    Stability AI reportedly scraped copyrighted images by Getty Images to be used as training data for Stable Diffusion model.

    Deployer: Stability Ai · Developer: Runway, Laion, Eleutherai, Compvis Lmu, Stability Ai · Harmed: Getty Images, Getty Images Contributors

  18. #352 · 4 reports

    GPT-3-Based Twitter Bot Hijacked Using Prompt Injection Attacks AIID ↗

    Remoteli.io's GPT-3-based Twitter bot was shown being hijacked by Twitter users who redirected it to repeat or generate any phrases.

    Deployer: Stephan De Vries · Developer: Openai, Stephan De Vries · Harmed: Stephan De Vries

  19. #391 · 2 reports

    Facial Recognition Trial by UK Southern Co-op Alleged as Unlawful AIID ↗

    Southern Co-op's use of facial recognition reportedly to curb violent crime in UK supermarkets was alleged by civil society and privacy groups as "unlawful" and "complete" invasion of privacy.

    Deployer: Southern Co Op · Developer: Hikvision · Harmed: Souther Co Op Customers

  20. #372 · 3 reports

    Users Reported Security Issues with Google Pixel 6a's Fingerprint Unlocking AIID ↗

    Google Pixel 6a's fingerprint recognition feature was reported by users for security issues, in which phones were mistakenly unlocked by unregistered fingerprints.

    Deployer: Google · Developer: Google · Harmed: Google Pixel 6A Users

  21. #258 · 2 reports

    Australian Retailers Reportedly Captured Face Prints of Their Customers without Consent AIID ↗

    Major Australian retailers reportedly analyzed in-store footage to capture facial features of their customers without consent, which was criticized by consumer groups as creepy and invasive.

    Deployer: The Good Guys, Kmart, Bunnings · Developer: Unknown · Harmed: The Good Guys customers, Privacy, Kmart customers, Bunnings customers, Biometric data subjects

  22. #465 · 1 report

    Private Medical Photos Were Reportedly Found in LAION-5B AI Training Dataset AIID ↗

    In September 2022, an artist using the name Lapine reported finding private post-operative medical photos of herself in LAION-5B, a web-scraped image-text dataset used in AI image-synthesis research. Ars Technica confirmed her images were referenced in the dataset and reported finding thousands of similar patient medical-record photos.

    Deployer: Stability Ai, Google · Developer: Stability Ai, Laion, Google · Harmed: Privacy, Lapine, Patients, Patients Whose Medical Photos Were Included In Laion 5B, People Whose Private Images Were Included In Ai Training Datasets

  23. #204 · 4 reports

    A Chinese Tech Worker at Zhihu Fired Allegedly via a Resignation Risk Prediction Algorithm AIID ↗

    The firing of an employee at Zhihu, a large Q&A platform in China, was allegedly caused by the use of a behavioral perception algorithm which claimed to predict a worker’s resignation risk using their online footprints, such as browsing history and internal communication.

    Deployer: Zhihu · Developer: Sangfor Technologies · Harmed: Zhihu employees, Chinese tech workers

  24. #276 · 1 report

    Local South Korean Government’s Use of CCTV Footage Analysis via Facial Recognition to Track COVID Cases Raised Concerns about Privacy, Retention, and Potential Misuse AIID ↗

    Bucheon government's use of facial recognition in analyzing CCTV footage, despite gaining wide public support, was scrutinized by privacy advocates and some lawmakers for collecting data without consent, and retaining and misusing data beyond pandemic needs.

    Deployer: Bucheon city government · Developer: Unknown · Harmed: Privacy, General public of South Korea, General public, Bucheon citizens, Biometric data subjects

  25. #360 · 3 reports

    McDonald's AI Drive-Thru Allegedly Collected Biometric Customer Data without Consent, Violating BIPA AIID ↗

    McDonald's use of chatbot in its AI drive-through in Chicago was alleged in a lawsuit to have collected and processed voice data without user consent to predict customer information, which violated Illinois Biometric Information Privacy Act (BIPA).

    Deployer: McDonald's · Developer: McD Tech Labs, Apprente · Harmed: Shannon Carpenter, Privacy, McDonald's customers residing in Illinois, McDonald's customers, Biometric data subjects

  26. #119 · 4 reports

    Xsolla Employees Fired by CEO Allegedly via Big Data Analytics of Work Activities AIID ↗

    Xsolla CEO fired more than a hundred employees from his company in Perm, Russia, based on big data analysis of their remote digitized-work activity, which critics said was violating employee's privacy, outdated, and extremely ineffective.

    Deployer: Xsolla · Developer: Unknown · Harmed: Xsolla employees, Privacy, Biometric data subjects

  27. #240 · 5 reports

    GitHub Copilot, Copyright Infringement and Open Source Licensing AIID ↗

    Users of GitHub Copilot can produce source code subject to license requirements without attributing and licensing the code to the rights holder.

    Deployer: Github, Programmers · Developer: Github · Harmed: Intellectual Property Rights Holders

  28. #395 · 4 reports

    Amazon Allegedly Forced Deployment of AI-Powered Cameras on Delivery Drivers AIID ↗

    Amazon delivery drivers were allegedly forced to consent to algorithmic collection and processing of their location, movement, and biometric data through AI-powered cameras, or be dismissed.

    Deployer: Amazon · Developer: Netradyne · Harmed: Privacy, Biometric data subjects, Amazon delivery drivers

  29. #212 · 4 reports

    XPeng Motors Fined For Illegal Collection of Consumers’ Faces Using Facial Recognition Cameras AIID ↗

    The Chinese electric vehicle (EV) firm XPeng Motors was fined by local market regulators for illegally collecting in-store customers’ facial images without their consent for six months.

    Deployer: XPeng Motors · Developer: Unknown · Harmed: XPeng Motors customers, Privacy, Biometric data subjects

  30. #996 · 3 reports

    Meta Allegedly Used Books3, a Dataset of 191,000 Pirated Books, to Train LLaMA AI AIID ↗

    Meta and Bloomberg allegedly used Books3, a dataset containing 191,000 pirated books, to train their AI models, including LLaMA and BloombergGPT, without author consent. Lawsuits from authors such as Sarah Silverman and Michael Chabon claim this constitutes copyright infringement. Books3 includes works from major publishers like Penguin Random House and HarperCollins. Meta argues its AI outputs are not "substantially similar" to the original books, but legal challenges continue.

    Deployer: Meta, Eleutherai, Bloomberg, Generative Ai Developers · Developer: The Pile, Shawn Presser, Meta, Eleutherai, Bloomberg, Generative Ai Developers · Harmed: Zadie Smith, Writers, Verso, Stephen King, Sarah Silverman, Richard Kadrey, Publishers Found In Books3, Penguin Random House, Oxford University Press, Over 170000 Authors Found In Books3, Michael Pollan, Margaret Atwood, Macmillan, Harpercollins, General Public, Creative Industries, Christopher Golden, Authors

  31. #557 · 4 reports

    Miami Police Deployed Facial Recognition to Arrest George Floyd Protestor Allegedly without Cause AIID ↗

    Miami Police's arrest report for a George Floyd protestor did not disclose use of facial recognition, which allegedly did not meet the legal threshold for probable cause for arrest.

    Deployer: Miami Police Department, Law enforcement · Developer: Clearview AI · Harmed: Oriana Albornoz, George Floyd protest participants

  32. #354 · 5 reports

    Uber Allegedly Violated GDPR by Failing to Provide Sufficient Notice on Automated Profiling for Drivers AIID ↗

    Uber was alleged in a lawsuit to have provided incomplete notice about automated decision-making and profiling for drivers such as information about their driving behavior, and use of phone.

    Deployer: Uber · Developer: Uber · Harmed: Uber drivers

  33. #521 · 1 report

    iRobot Roomba J7 R&D Images Reportedly Appeared in Private Online Groups After Data Labeling AIID ↗

    Images reportedly captured in 2020 by development versions of iRobot's Roomba J7 robot vacuum during an AI training data project were sent to Scale AI for labeling and later appeared in private Facebook, Discord, and other online groups. Reporting described some images as showing sensitive household scenes.

    Deployer: Irobot · Developer: Irobot, Scale Ai · Harmed: Privacy, Project Io Participants, People Captured In Roomba Training Images, Minors Captured In Roomba Training Images, Minors

  34. #412 · 4 reports

    Finnish Police Were Reportedly Reprimanded After National Bureau of Investigation Unit Allegedly Used Clearview AI to Identify Potential Abuse Victims AIID ↗

    Finland's Deputy Data Protection Ombudsman reportedly reprimanded the National Police Board after a National Bureau of Investigation child sexual exploitation unit allegedly used Clearview AI in late 2019 or early 2020 to identify potential child sexual abuse victims. Four NBI users reportedly made about 120 searches during a free trial without controller approval or prior assessment of how uploaded biometric data would be handled.

    Deployer: Law enforcement, Government of Finland, Finnish National Police Board, Finnish National Bureau of Investigation · Developer: Facial recognition system developers, Clearview AI · Harmed: Privacy, People whose images were uploaded to Clearview AI, Minors, Child sexual abuse victims, Biometric data subjects

  35. #223 · 1 report

    Hive Box Facial-Recognition Locks Hacked by Fourth Graders Using Intended Recipient’s Facial Photo AIID ↗

    Facial-recognition locks by Hive Box, an express delivery locker company in China, were easily opened by a group of fourth-graders in a science-club demo using only a printed photo of the intended recipient’s face, leaving contents vulnerable to theft.

    Deployer: Hive Box · Developer: Hive Box · Harmed: Hive Box Customers

  36. #441 · 5 reports

    South Korean Agencies Reportedly Shared Airport Travelers' Face Images with Companies to Train Immigration Facial Recognition System AIID ↗

    Reporting in 2021 alleged that South Korea's Ministry of Justice shared roughly 170 million face images and related biometric data from Korean and foreign airport travelers with the Ministry of Science and Information and Communication Technology (ICT) and private companies for an AI identification and tracking system used in immigration screening. The data was reportedly used for AI training and algorithm testing without travelers' consent.

    Deployer: Government Of South Korea, Korean Ministry Of Justice, Korean Ministry Of Science And Information And Communication Technology, National It Industry Promotion Agency · Developer: Surveillance Technology Developers, Facial Recognition System Developers · Harmed: Foreign Nationals Traveling Through South Korean Airports, Korean Citizens Whose Airport Facial Images Were Used, Biometric Data Subjects, Privacy, Travelers In Korean Airports

  37. #76 · 1 report

    Buenos Aires Government Reportedly Used Children's Personal Data in Facial Recognition System for Fugitives AIID ↗

    Beginning in April 2019, the Buenos Aires city government reportedly used data from Argentina’s CONARC fugitive database, including children’s identities and reference photos, in its live Facial Recognition System for Fugitives (SRFP). Human Rights Watch found at least 166 children had appeared in CONARC between 2017 and 2020 and warned that the system exposed them to privacy violations and elevated risks of false matches.

    Deployer: Government of Argentina, Buenos Aires city government · Developer: Surveillance technology developers, NtechLab, Facial recognition system developers, Danaide S.A. · Harmed: Privacy, Minors, General public of Buenos Aires, General public of Argentina, General public, Buenos Aires children, Biometric data subjects

  38. #199 · 7 reports

    Ever AI Reportedly Deceived Customers about FRT Use in App AIID ↗

    Ever AI, now Paravision AI, allegedly failed to inform customers about the development and use of facial recognition that facilitates the sale of customers’ data to various businesses, a business model that critics said was an egregious violation of privacy.

    Deployer: Ever AI · Developer: Ever AI · Harmed: Privacy, Ever AI users, Biometric data subjects

  39. #561 · 3 reports

    OpenAI Alleged by Lawsuit Violated Users' Privacy Rights by Training AI on Private Info without Informed Consent AIID ↗

    OpenAI's products such as ChatGPT and DALL-E were alleged in a lawsuit using stolen private information from internet users without their informed consent or knowledge.

    Deployer: Openai · Developer: Openai, Large Language Model Developers, Image Generation Technology Developers, Chatbot Developers · Harmed: Social Media Users, Privacy, Minors, Internet Users

  40. #357 · 3 reports

    GPT-2 Reportedly Reproduced Personal Data from Its Training Data AIID ↗

    OpenAI's GPT-2 reportedly memorized and reproduced portions of its training data, including personal information such as names, email addresses, social media handles, and phone numbers. Researchers raised concerns that large language models could expose private or sensitive information when trained on web-scale datasets containing personal data.

    Deployer: OpenAI · Developer: OpenAI · Harmed: Privacy, People whose personal data was included in GPT-2 training data, GPT-2 users, Biometric data subjects

  41. #555 · 1 report

    OpenAI's Training Data for LLMs Allegedly Comprised of Copyrighted Books AIID ↗

    Two authors alleged in a class action lawsuit OpenAI infringed authors' copyrights by incorporating illegal "shadow libraries" offering copyrighted books without permission in the training data of its generative LLMs, such as ChatGPT.

    Deployer: Openai · Developer: Openai · Harmed: Paul Tremblay, Mona Awad, Authors Of Copyrighted Works

  42. #358 · 1 report

    Calgary Malls Reportedly Deployed Facial Recognition Without Customer Consent AIID ↗

    Facial recognition (FRT) was reportedly deployed in some Calgary-area malls to approximate customer age and gender without explicit consent, which a privacy expert warned was a cause for concern.

    Deployer: Cadillac Fairview · Developer: Unknown · Harmed: Privacy, Market Mall goers, Chinook Centre mall goers, Biometric data subjects

  43. #361 · 1 report

    Amazon Echo Mistakenly Recorded and Sent Private Conversation to Random Contact AIID ↗

    Amazon Echo misinterpreted a background conversation between a husband and wife as instructions for recording a message and sending it to one of the husband's employees.

    Deployer: Amazon · Developer: Amazon · Harmed: Privacy, Biometric data subjects, Amazon Echo users

  44. #556 · 4 reports

    Amazon Allegedly Violated Children's Privacy through Default Voice Collection Settings AIID ↗

    Amazon's retention of children' voice recordings indefinitely as the default setting reportedly to train Alexa's voice recognition for Alexa-enabled devices was charged by the FTC and DOJ to violate COPPA Rule.

    Deployer: Amazon · Developer: Amazon · Harmed: Alexa Children Users, Minors, Alexa Users, Privacy, Biometric Data Subjects

  45. #184 · 3 reports

    Facial Recognition Program in São Paulo Metro Stations Suspended for Illegal and Disproportionate Violation of Citizens' Right to Privacy AIID ↗

    A facial recognition program rolled out by São Paulo Metro Stations was suspended following a court ruling in response to a lawsuit by civil society organizations, who cited fear of it being integrated with other electronic surveillance entities without consent, and lack of transparency about the biometric data collection process of metro users.

    Deployer: Companhia do Metropolitano de São Paulo · Developer: SecurOS · Harmed: São Paulo Metro users, São Paulo citizens, Privacy, General public of Brazil, General public, Biometric data subjects

  46. #32 · 21 reports

    Identical Twins Can Open Apple FaceID Protected Devices AIID ↗

    Apple's iPhone FaceID can be opened by an identical twin of the person who has registered their face to unlock the phone.

    Deployer: Apple · Developer: Apple · Harmed: People With Twins

  47. #26 · 24 reports

    Hackers Break Apple Face ID AIID ↗

    Vietnamese security firm Bkav created an improved mask to bypass Apple's Face ID

    Deployer: Apple · Developer: Apple · Harmed: Apple, Device Owners

  48. #167 · 1 report

    Researchers' Homosexual-Men Detection Model Denounced as a Threat to LGBTQ People's Safety and Privacy AIID ↗

    Researchers at Stanford Graduate School of Business developed a model that determined, on a binary scale, whether someone was homosexual using only his facial image, which advocacy groups such as GLAAD and the Human Rights Campaign denounced as flawed science and threatening to LGBTQ folks.

    Deployer: Yilun Wang, Michal Kosinski · Developer: Yilun Wang, Michal Kosinski · Harmed: Privacy, non-American LGBTQ people, LGBTQ people of color, LGBTQ people, Biometric data subjects

  49. #1428 · 2 reports

    UK High Court Found Sky Betting & Gaming Unlawfully Used Automated Profiling and Targeted Marketing to Exploit a Recovering Problem Gambler AIID ↗

    In the UK, the High Court found that Sky Betting & Gaming unlawfully used automated profiling and targeted direct marketing to pursue a recovering problem gambler from July 28, 2017 onward without valid consent. Sky reportedly treated him as a high-value customer despite addiction indicators.

    Deployer: Sky Betting & Gaming, Hestview Ltd, Bonne Terre Ltd · Developer: Sky Betting & Gaming, Hestview Ltd, Bonne Terre Ltd · Harmed: Sky Betting & Gaming customers with gambling disorders, RTM (recovering problem gambler), Recovering problem gamblers, Privacy, People with gambling disorders

  50. #267 · 10 reports

    Clearview AI Algorithm Built on Photos Scraped from Social Media Profiles without Consent AIID ↗

    Face-matching algorithm by Clearview AI was built using scraped images from social media sites such as Instagram and Facebook without user consent, violating social media site policies, and allegedly privacy regulations.

    Deployer: Clearview AI · Developer: Clearview AI · Harmed: Social media users, Privacy, Instagram users, Facebook users, Biometric data subjects

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.