AI Incident Database
Browse AI incidents
Every incident record (metadata only) from the weekly snapshot of 2026-09-07. Filter, then export the selection with its licence attached; each row links to the full record and its reports.
-
AI Romance Apps Reportedly Compromise User Privacy for Data Harvesting AIID ↗
AI-powered romantic chatbots, marketed for enhancing mental health, are found to exploit user privacy by harvesting sensitive personal information for data sharing and targeted ads, with inadequate security measures and consent protocols, according to research by the Mozilla Foundation.
-
Alleged ChatGPT Account Compromise Reportedly Led to Unintended Data Exposure AIID ↗
An alleged security breach involving ChatGPT led to the reported exposure of sensitive conversations, including login credentials and personal data, after a user account was allegedly compromised. OpenAI reportedly responded to the incident with an explanation.
-
The New York Times Reportedly Sues OpenAI and Microsoft Over Alleged Unauthorized AI Training on Its Content AIID ↗
The New York Times alleges that OpenAI and Microsoft used millions of its articles without permission to train AI models, including ChatGPT. The lawsuit claims the companies scraped and reproduced copyrighted content without compensation, in turn undermining the Times’s business and competing with its journalism. Some AI outputs allegedly regurgitate Times articles verbatim. The lawsuit seeks damages and demands the destruction of AI models trained on its content.
-
Purported Mass Facial Recognition Program in Gaza Reportedly Used by Israeli Forces to Identify Palestinians AIID ↗
A previously undisclosed facial recognition initiative operated by Israeli military intelligence units was reportedly deployed across Gaza after the October 7, 2023 attacks. According to multiple intelligence officers, the program uses Corsight technology alongside Google Photos to identify individuals from checkpoints, crowds, and drone footage. The system has allegedly produced misidentifications, including the widely reported detention of Palestinian poet Mosab Abu Toha on November 19, 2023.
-
Reported Accidental Exposure of 38TB of Data by Microsoft's AI Research Team AIID ↗
Microsoft's AI research team reportedly accidentally exposed 38TB of sensitive data while publishing open-source training material on GitHub. The exposure allegedly included secrets, private keys, passwords, and internal Microsoft Teams messages. The team reportedly utilized Azure's Shared Access Signature (SAS) tokens for sharing, which were purportedly misconfigured, leading to the wide exposure of data.
-
Bing Chat Solved CAPTCHAs with Image Analysis Feature Despite Safeguards AIID ↗
Microsoft was reported by a Twitter user for deploying image analysis feature capable of solving CAPTCHAs for its GPT-based chatbot despite it being safeguarded against solving them for users.
-
FTC Targets Edmodo for Unlawful Use of Children’s Data and Delegating Compliance to Schools AIID ↗
Edmodo, an education technology provider, violated the Children's Online Privacy Protection Act Rule (COPPA Rule) by collecting and using children's personal data for advertising purposes without parental consent, according to the FTC. The company outsourced its compliance responsibilities to schools, thereby making them "solely" responsible for COPPA compliance without adequate disclosure. Edmodo is facing a proposed order prohibiting such practices, marking a precedent in the ed tech industry.
-
Illinois Residents File Class Action Lawsuit Against Facial Recognition Technology Companies for Allegedly Violating BIPA AIID ↗
A class action lawsuit was filed against several facial recognition technology companies for allegedly violating the Illinois Biometric Information Privacy Act (BIPA). The defendants are accused of offering a facial recognition search engine called Pimeyes, which collects images from databases across the internet and scans them into their database seemingly without consent. This action is claimed to invade the privacy of millions of Americans. The lawsuit argues that Pimeyes lacks publicly avail
-
ChatGPT Reportedly Banned by Italian Authority Due to OpenAI's Purported Lack of Legal Basis for Data Collection and Age Verification AIID ↗
Italy's data protection authority is reported to have temporarily limited OpenAI's processing of Italian users' data after alleging that ChatGPT lacked adequate notice and legal basis for large-scale personal data collection and processing used to train the system. The authority also cited a March 2023 data breach, possible processing of inaccurate personal data, and the absence of age-verification safeguards for children.
-
ChatGPT Reportedly Exposed Users' Private Data Reportedly Due to Bug AIID ↗
ChatGPT reportedly exposed titles of users' chat histories and users' private payment information to other users reportedly due to a bug, which prompted its temporary shutdown by OpenAI.
-
Australian Journalist Able to Access Centrelink Account Using AI Audio of Own Voice AIID ↗
A Guardian journalist was able to verify their identity and gain access to their own Centrelink self-service account using AI-generated audio of their own voice along with their customer reference number, shortly after voiceprint was deployed for ID verification.
-
ChatGPT Reportedly Implicated in Samsung Data Leak of Source Code and Meeting Notes AIID ↗
Samsung engineers are reported to have inadvertently leaked sensitive company data sometime in March 2023, including source code and internal meeting notes, by using ChatGPT to assist with tasks. ChatGPT allegedly retained the inputted data, leading to a purported breach of confidentiality.
-
Meta and OpenAI Accused of Using LibGen’s Pirated Books to Train AI Models AIID ↗
Court records reveal that Meta employees allegedly discussed pirating books to train LLaMA 3, citing cost and speed concerns with licensing. Internal messages suggest Meta accessed LibGen, a repository of over 7.5 million pirated books, with apparent approval from Mark Zuckerberg. Employees allegedly took steps to obscure the dataset’s origins. OpenAI has also been implicated in using LibGen.
-
Bing Chat's Initial Prompts Revealed by Early Testers Through Prompt Injection AIID ↗
Early testers of Bing Chat successfully used prompt injection to reveal its built-in initial instructions, which contains a list of statements governing ChatGPT's interaction with users.
-
Lawyers Denied Entry to Performance Venue by Facial Recognition AIID ↗
Lawyers were barred from entry to Madison Square Garden after a facial recognition system matched them as employed by a law firm currently engaged in litigation with the venue.
-
Stable Diffusion Allegedly Used Artists' Works without Permission for AI Training AIID ↗
Text-to-image model Stable Diffusion was reportedly using artists' original works without permission for its AI training.
-
Stable Diffusion's Training Data Contained Copyrighted Images AIID ↗
Stability AI reportedly scraped copyrighted images by Getty Images to be used as training data for Stable Diffusion model.
-
GPT-3-Based Twitter Bot Hijacked Using Prompt Injection Attacks AIID ↗
Remoteli.io's GPT-3-based Twitter bot was shown being hijacked by Twitter users who redirected it to repeat or generate any phrases.
-
Facial Recognition Trial by UK Southern Co-op Alleged as Unlawful AIID ↗
Southern Co-op's use of facial recognition reportedly to curb violent crime in UK supermarkets was alleged by civil society and privacy groups as "unlawful" and "complete" invasion of privacy.
-
Users Reported Security Issues with Google Pixel 6a's Fingerprint Unlocking AIID ↗
Google Pixel 6a's fingerprint recognition feature was reported by users for security issues, in which phones were mistakenly unlocked by unregistered fingerprints.
-
Australian Retailers Reportedly Captured Face Prints of Their Customers without Consent AIID ↗
Major Australian retailers reportedly analyzed in-store footage to capture facial features of their customers without consent, which was criticized by consumer groups as creepy and invasive.
-
Private Medical Photos Were Reportedly Found in LAION-5B AI Training Dataset AIID ↗
In September 2022, an artist using the name Lapine reported finding private post-operative medical photos of herself in LAION-5B, a web-scraped image-text dataset used in AI image-synthesis research. Ars Technica confirmed her images were referenced in the dataset and reported finding thousands of similar patient medical-record photos.
-
A Chinese Tech Worker at Zhihu Fired Allegedly via a Resignation Risk Prediction Algorithm AIID ↗
The firing of an employee at Zhihu, a large Q&A platform in China, was allegedly caused by the use of a behavioral perception algorithm which claimed to predict a worker’s resignation risk using their online footprints, such as browsing history and internal communication.
-
Local South Korean Government’s Use of CCTV Footage Analysis via Facial Recognition to Track COVID Cases Raised Concerns about Privacy, Retention, and Potential Misuse AIID ↗
Bucheon government's use of facial recognition in analyzing CCTV footage, despite gaining wide public support, was scrutinized by privacy advocates and some lawmakers for collecting data without consent, and retaining and misusing data beyond pandemic needs.
-
McDonald's AI Drive-Thru Allegedly Collected Biometric Customer Data without Consent, Violating BIPA AIID ↗
McDonald's use of chatbot in its AI drive-through in Chicago was alleged in a lawsuit to have collected and processed voice data without user consent to predict customer information, which violated Illinois Biometric Information Privacy Act (BIPA).
-
Xsolla Employees Fired by CEO Allegedly via Big Data Analytics of Work Activities AIID ↗
Xsolla CEO fired more than a hundred employees from his company in Perm, Russia, based on big data analysis of their remote digitized-work activity, which critics said was violating employee's privacy, outdated, and extremely ineffective.
-
GitHub Copilot, Copyright Infringement and Open Source Licensing AIID ↗
Users of GitHub Copilot can produce source code subject to license requirements without attributing and licensing the code to the rights holder.
-
Amazon Allegedly Forced Deployment of AI-Powered Cameras on Delivery Drivers AIID ↗
Amazon delivery drivers were allegedly forced to consent to algorithmic collection and processing of their location, movement, and biometric data through AI-powered cameras, or be dismissed.
-
XPeng Motors Fined For Illegal Collection of Consumers’ Faces Using Facial Recognition Cameras AIID ↗
The Chinese electric vehicle (EV) firm XPeng Motors was fined by local market regulators for illegally collecting in-store customers’ facial images without their consent for six months.
-
Meta Allegedly Used Books3, a Dataset of 191,000 Pirated Books, to Train LLaMA AI AIID ↗
Meta and Bloomberg allegedly used Books3, a dataset containing 191,000 pirated books, to train their AI models, including LLaMA and BloombergGPT, without author consent. Lawsuits from authors such as Sarah Silverman and Michael Chabon claim this constitutes copyright infringement. Books3 includes works from major publishers like Penguin Random House and HarperCollins. Meta argues its AI outputs are not "substantially similar" to the original books, but legal challenges continue.
-
Miami Police Deployed Facial Recognition to Arrest George Floyd Protestor Allegedly without Cause AIID ↗
Miami Police's arrest report for a George Floyd protestor did not disclose use of facial recognition, which allegedly did not meet the legal threshold for probable cause for arrest.
-
Uber Allegedly Violated GDPR by Failing to Provide Sufficient Notice on Automated Profiling for Drivers AIID ↗
Uber was alleged in a lawsuit to have provided incomplete notice about automated decision-making and profiling for drivers such as information about their driving behavior, and use of phone.
-
iRobot Roomba J7 R&D Images Reportedly Appeared in Private Online Groups After Data Labeling AIID ↗
Images reportedly captured in 2020 by development versions of iRobot's Roomba J7 robot vacuum during an AI training data project were sent to Scale AI for labeling and later appeared in private Facebook, Discord, and other online groups. Reporting described some images as showing sensitive household scenes.
-
Finnish Police Were Reportedly Reprimanded After National Bureau of Investigation Unit Allegedly Used Clearview AI to Identify Potential Abuse Victims AIID ↗
Finland's Deputy Data Protection Ombudsman reportedly reprimanded the National Police Board after a National Bureau of Investigation child sexual exploitation unit allegedly used Clearview AI in late 2019 or early 2020 to identify potential child sexual abuse victims. Four NBI users reportedly made about 120 searches during a free trial without controller approval or prior assessment of how uploaded biometric data would be handled.
-
Hive Box Facial-Recognition Locks Hacked by Fourth Graders Using Intended Recipient’s Facial Photo AIID ↗
Facial-recognition locks by Hive Box, an express delivery locker company in China, were easily opened by a group of fourth-graders in a science-club demo using only a printed photo of the intended recipient’s face, leaving contents vulnerable to theft.
-
South Korean Agencies Reportedly Shared Airport Travelers' Face Images with Companies to Train Immigration Facial Recognition System AIID ↗
Reporting in 2021 alleged that South Korea's Ministry of Justice shared roughly 170 million face images and related biometric data from Korean and foreign airport travelers with the Ministry of Science and Information and Communication Technology (ICT) and private companies for an AI identification and tracking system used in immigration screening. The data was reportedly used for AI training and algorithm testing without travelers' consent.
-
Buenos Aires Government Reportedly Used Children's Personal Data in Facial Recognition System for Fugitives AIID ↗
Beginning in April 2019, the Buenos Aires city government reportedly used data from Argentina’s CONARC fugitive database, including children’s identities and reference photos, in its live Facial Recognition System for Fugitives (SRFP). Human Rights Watch found at least 166 children had appeared in CONARC between 2017 and 2020 and warned that the system exposed them to privacy violations and elevated risks of false matches.
-
Ever AI Reportedly Deceived Customers about FRT Use in App AIID ↗
Ever AI, now Paravision AI, allegedly failed to inform customers about the development and use of facial recognition that facilitates the sale of customers’ data to various businesses, a business model that critics said was an egregious violation of privacy.
-
OpenAI Alleged by Lawsuit Violated Users' Privacy Rights by Training AI on Private Info without Informed Consent AIID ↗
OpenAI's products such as ChatGPT and DALL-E were alleged in a lawsuit using stolen private information from internet users without their informed consent or knowledge.
-
GPT-2 Reportedly Reproduced Personal Data from Its Training Data AIID ↗
OpenAI's GPT-2 reportedly memorized and reproduced portions of its training data, including personal information such as names, email addresses, social media handles, and phone numbers. Researchers raised concerns that large language models could expose private or sensitive information when trained on web-scale datasets containing personal data.
-
OpenAI's Training Data for LLMs Allegedly Comprised of Copyrighted Books AIID ↗
Two authors alleged in a class action lawsuit OpenAI infringed authors' copyrights by incorporating illegal "shadow libraries" offering copyrighted books without permission in the training data of its generative LLMs, such as ChatGPT.
-
Calgary Malls Reportedly Deployed Facial Recognition Without Customer Consent AIID ↗
Facial recognition (FRT) was reportedly deployed in some Calgary-area malls to approximate customer age and gender without explicit consent, which a privacy expert warned was a cause for concern.
-
Amazon Echo Mistakenly Recorded and Sent Private Conversation to Random Contact AIID ↗
Amazon Echo misinterpreted a background conversation between a husband and wife as instructions for recording a message and sending it to one of the husband's employees.
-
Amazon Allegedly Violated Children's Privacy through Default Voice Collection Settings AIID ↗
Amazon's retention of children' voice recordings indefinitely as the default setting reportedly to train Alexa's voice recognition for Alexa-enabled devices was charged by the FTC and DOJ to violate COPPA Rule.
-
Facial Recognition Program in São Paulo Metro Stations Suspended for Illegal and Disproportionate Violation of Citizens' Right to Privacy AIID ↗
A facial recognition program rolled out by São Paulo Metro Stations was suspended following a court ruling in response to a lawsuit by civil society organizations, who cited fear of it being integrated with other electronic surveillance entities without consent, and lack of transparency about the biometric data collection process of metro users.
-
Identical Twins Can Open Apple FaceID Protected Devices AIID ↗
Apple's iPhone FaceID can be opened by an identical twin of the person who has registered their face to unlock the phone.
-
Hackers Break Apple Face ID AIID ↗
Vietnamese security firm Bkav created an improved mask to bypass Apple's Face ID
-
Researchers' Homosexual-Men Detection Model Denounced as a Threat to LGBTQ People's Safety and Privacy AIID ↗
Researchers at Stanford Graduate School of Business developed a model that determined, on a binary scale, whether someone was homosexual using only his facial image, which advocacy groups such as GLAAD and the Human Rights Campaign denounced as flawed science and threatening to LGBTQ folks.
-
UK High Court Found Sky Betting & Gaming Unlawfully Used Automated Profiling and Targeted Marketing to Exploit a Recovering Problem Gambler AIID ↗
In the UK, the High Court found that Sky Betting & Gaming unlawfully used automated profiling and targeted direct marketing to pursue a recovering problem gambler from July 28, 2017 onward without valid consent. Sky reportedly treated him as a high-value customer despite addiction indicators.
-
Clearview AI Algorithm Built on Photos Scraped from Social Media Profiles without Consent AIID ↗
Face-matching algorithm by Clearview AI was built using scraped images from social media sites such as Instagram and Facebook without user consent, violating social media site policies, and allegedly privacy regulations.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.