AI Incident Database

Browse AI incidents

Every incident record (metadata only) from the weekly snapshot of 2026-09-07. Filter, then export the selection with its licence attached; each row links to the full record and its reports.

Reset

88 incidents · subdomain: Compromise of privacy by obtaining, leaking or correctly inferring sensitive information · page 2 of 2

  1. #258 · 2 reports

    Australian Retailers Reportedly Captured Face Prints of Their Customers without Consent AIID ↗

    Major Australian retailers reportedly analyzed in-store footage to capture facial features of their customers without consent, which was criticized by consumer groups as creepy and invasive.

    Deployer: The Good Guys, Kmart, Bunnings · Developer: Unknown · Harmed: The Good Guys customers, Privacy, Kmart customers, Bunnings customers, Biometric data subjects

  2. #465 · 1 report

    Private Medical Photos Were Reportedly Found in LAION-5B AI Training Dataset AIID ↗

    In September 2022, an artist using the name Lapine reported finding private post-operative medical photos of herself in LAION-5B, a web-scraped image-text dataset used in AI image-synthesis research. Ars Technica confirmed her images were referenced in the dataset and reported finding thousands of similar patient medical-record photos.

    Deployer: Stability Ai, Google · Developer: Stability Ai, Laion, Google · Harmed: Privacy, Lapine, Patients, Patients Whose Medical Photos Were Included In Laion 5B, People Whose Private Images Were Included In Ai Training Datasets

  3. #204 · 4 reports

    A Chinese Tech Worker at Zhihu Fired Allegedly via a Resignation Risk Prediction Algorithm AIID ↗

    The firing of an employee at Zhihu, a large Q&A platform in China, was allegedly caused by the use of a behavioral perception algorithm which claimed to predict a worker’s resignation risk using their online footprints, such as browsing history and internal communication.

    Deployer: Zhihu · Developer: Sangfor Technologies · Harmed: Zhihu employees, Chinese tech workers

  4. #276 · 1 report

    Local South Korean Government’s Use of CCTV Footage Analysis via Facial Recognition to Track COVID Cases Raised Concerns about Privacy, Retention, and Potential Misuse AIID ↗

    Bucheon government's use of facial recognition in analyzing CCTV footage, despite gaining wide public support, was scrutinized by privacy advocates and some lawmakers for collecting data without consent, and retaining and misusing data beyond pandemic needs.

    Deployer: Bucheon city government · Developer: Unknown · Harmed: Privacy, General public of South Korea, General public, Bucheon citizens, Biometric data subjects

  5. #360 · 3 reports

    McDonald's AI Drive-Thru Allegedly Collected Biometric Customer Data without Consent, Violating BIPA AIID ↗

    McDonald's use of chatbot in its AI drive-through in Chicago was alleged in a lawsuit to have collected and processed voice data without user consent to predict customer information, which violated Illinois Biometric Information Privacy Act (BIPA).

    Deployer: McDonald's · Developer: McD Tech Labs, Apprente · Harmed: Shannon Carpenter, Privacy, McDonald's customers residing in Illinois, McDonald's customers, Biometric data subjects

  6. #119 · 4 reports

    Xsolla Employees Fired by CEO Allegedly via Big Data Analytics of Work Activities AIID ↗

    Xsolla CEO fired more than a hundred employees from his company in Perm, Russia, based on big data analysis of their remote digitized-work activity, which critics said was violating employee's privacy, outdated, and extremely ineffective.

    Deployer: Xsolla · Developer: Unknown · Harmed: Xsolla employees, Privacy, Biometric data subjects

  7. #240 · 5 reports

    GitHub Copilot, Copyright Infringement and Open Source Licensing AIID ↗

    Users of GitHub Copilot can produce source code subject to license requirements without attributing and licensing the code to the rights holder.

    Deployer: Github, Programmers · Developer: Github · Harmed: Intellectual Property Rights Holders

  8. #395 · 4 reports

    Amazon Allegedly Forced Deployment of AI-Powered Cameras on Delivery Drivers AIID ↗

    Amazon delivery drivers were allegedly forced to consent to algorithmic collection and processing of their location, movement, and biometric data through AI-powered cameras, or be dismissed.

    Deployer: Amazon · Developer: Netradyne · Harmed: Privacy, Biometric data subjects, Amazon delivery drivers

  9. #212 · 4 reports

    XPeng Motors Fined For Illegal Collection of Consumers’ Faces Using Facial Recognition Cameras AIID ↗

    The Chinese electric vehicle (EV) firm XPeng Motors was fined by local market regulators for illegally collecting in-store customers’ facial images without their consent for six months.

    Deployer: XPeng Motors · Developer: Unknown · Harmed: XPeng Motors customers, Privacy, Biometric data subjects

  10. #996 · 3 reports

    Meta Allegedly Used Books3, a Dataset of 191,000 Pirated Books, to Train LLaMA AI AIID ↗

    Meta and Bloomberg allegedly used Books3, a dataset containing 191,000 pirated books, to train their AI models, including LLaMA and BloombergGPT, without author consent. Lawsuits from authors such as Sarah Silverman and Michael Chabon claim this constitutes copyright infringement. Books3 includes works from major publishers like Penguin Random House and HarperCollins. Meta argues its AI outputs are not "substantially similar" to the original books, but legal challenges continue.

    Deployer: Meta, Eleutherai, Bloomberg, Generative Ai Developers · Developer: The Pile, Shawn Presser, Meta, Eleutherai, Bloomberg, Generative Ai Developers · Harmed: Zadie Smith, Writers, Verso, Stephen King, Sarah Silverman, Richard Kadrey, Publishers Found In Books3, Penguin Random House, Oxford University Press, Over 170000 Authors Found In Books3, Michael Pollan, Margaret Atwood, Macmillan, Harpercollins, General Public, Creative Industries, Christopher Golden, Authors

  11. #557 · 4 reports

    Miami Police Deployed Facial Recognition to Arrest George Floyd Protestor Allegedly without Cause AIID ↗

    Miami Police's arrest report for a George Floyd protestor did not disclose use of facial recognition, which allegedly did not meet the legal threshold for probable cause for arrest.

    Deployer: Miami Police Department, Law enforcement · Developer: Clearview AI · Harmed: Oriana Albornoz, George Floyd protest participants

  12. #354 · 5 reports

    Uber Allegedly Violated GDPR by Failing to Provide Sufficient Notice on Automated Profiling for Drivers AIID ↗

    Uber was alleged in a lawsuit to have provided incomplete notice about automated decision-making and profiling for drivers such as information about their driving behavior, and use of phone.

    Deployer: Uber · Developer: Uber · Harmed: Uber drivers

  13. #521 · 1 report

    iRobot Roomba J7 R&D Images Reportedly Appeared in Private Online Groups After Data Labeling AIID ↗

    Images reportedly captured in 2020 by development versions of iRobot's Roomba J7 robot vacuum during an AI training data project were sent to Scale AI for labeling and later appeared in private Facebook, Discord, and other online groups. Reporting described some images as showing sensitive household scenes.

    Deployer: Irobot · Developer: Irobot, Scale Ai · Harmed: Privacy, Project Io Participants, People Captured In Roomba Training Images, Minors Captured In Roomba Training Images, Minors

  14. #412 · 4 reports

    Finnish Police Were Reportedly Reprimanded After National Bureau of Investigation Unit Allegedly Used Clearview AI to Identify Potential Abuse Victims AIID ↗

    Finland's Deputy Data Protection Ombudsman reportedly reprimanded the National Police Board after a National Bureau of Investigation child sexual exploitation unit allegedly used Clearview AI in late 2019 or early 2020 to identify potential child sexual abuse victims. Four NBI users reportedly made about 120 searches during a free trial without controller approval or prior assessment of how uploaded biometric data would be handled.

    Deployer: Law enforcement, Government of Finland, Finnish National Police Board, Finnish National Bureau of Investigation · Developer: Facial recognition system developers, Clearview AI · Harmed: Privacy, People whose images were uploaded to Clearview AI, Minors, Child sexual abuse victims, Biometric data subjects

  15. #441 · 5 reports

    South Korean Agencies Reportedly Shared Airport Travelers' Face Images with Companies to Train Immigration Facial Recognition System AIID ↗

    Reporting in 2021 alleged that South Korea's Ministry of Justice shared roughly 170 million face images and related biometric data from Korean and foreign airport travelers with the Ministry of Science and Information and Communication Technology (ICT) and private companies for an AI identification and tracking system used in immigration screening. The data was reportedly used for AI training and algorithm testing without travelers' consent.

    Deployer: Government Of South Korea, Korean Ministry Of Justice, Korean Ministry Of Science And Information And Communication Technology, National It Industry Promotion Agency · Developer: Surveillance Technology Developers, Facial Recognition System Developers · Harmed: Foreign Nationals Traveling Through South Korean Airports, Korean Citizens Whose Airport Facial Images Were Used, Biometric Data Subjects, Privacy, Travelers In Korean Airports

  16. #76 · 1 report

    Buenos Aires Government Reportedly Used Children's Personal Data in Facial Recognition System for Fugitives AIID ↗

    Beginning in April 2019, the Buenos Aires city government reportedly used data from Argentina’s CONARC fugitive database, including children’s identities and reference photos, in its live Facial Recognition System for Fugitives (SRFP). Human Rights Watch found at least 166 children had appeared in CONARC between 2017 and 2020 and warned that the system exposed them to privacy violations and elevated risks of false matches.

    Deployer: Government of Argentina, Buenos Aires city government · Developer: Surveillance technology developers, NtechLab, Facial recognition system developers, Danaide S.A. · Harmed: Privacy, Minors, General public of Buenos Aires, General public of Argentina, General public, Buenos Aires children, Biometric data subjects

  17. #199 · 7 reports

    Ever AI Reportedly Deceived Customers about FRT Use in App AIID ↗

    Ever AI, now Paravision AI, allegedly failed to inform customers about the development and use of facial recognition that facilitates the sale of customers’ data to various businesses, a business model that critics said was an egregious violation of privacy.

    Deployer: Ever AI · Developer: Ever AI · Harmed: Privacy, Ever AI users, Biometric data subjects

  18. #561 · 3 reports

    OpenAI Alleged by Lawsuit Violated Users' Privacy Rights by Training AI on Private Info without Informed Consent AIID ↗

    OpenAI's products such as ChatGPT and DALL-E were alleged in a lawsuit using stolen private information from internet users without their informed consent or knowledge.

    Deployer: Openai · Developer: Openai, Large Language Model Developers, Image Generation Technology Developers, Chatbot Developers · Harmed: Social Media Users, Privacy, Minors, Internet Users

  19. #357 · 3 reports

    GPT-2 Reportedly Reproduced Personal Data from Its Training Data AIID ↗

    OpenAI's GPT-2 reportedly memorized and reproduced portions of its training data, including personal information such as names, email addresses, social media handles, and phone numbers. Researchers raised concerns that large language models could expose private or sensitive information when trained on web-scale datasets containing personal data.

    Deployer: OpenAI · Developer: OpenAI · Harmed: Privacy, People whose personal data was included in GPT-2 training data, GPT-2 users, Biometric data subjects

  20. #555 · 1 report

    OpenAI's Training Data for LLMs Allegedly Comprised of Copyrighted Books AIID ↗

    Two authors alleged in a class action lawsuit OpenAI infringed authors' copyrights by incorporating illegal "shadow libraries" offering copyrighted books without permission in the training data of its generative LLMs, such as ChatGPT.

    Deployer: Openai · Developer: Openai · Harmed: Paul Tremblay, Mona Awad, Authors Of Copyrighted Works

  21. #358 · 1 report

    Calgary Malls Reportedly Deployed Facial Recognition Without Customer Consent AIID ↗

    Facial recognition (FRT) was reportedly deployed in some Calgary-area malls to approximate customer age and gender without explicit consent, which a privacy expert warned was a cause for concern.

    Deployer: Cadillac Fairview · Developer: Unknown · Harmed: Privacy, Market Mall goers, Chinook Centre mall goers, Biometric data subjects

  22. #361 · 1 report

    Amazon Echo Mistakenly Recorded and Sent Private Conversation to Random Contact AIID ↗

    Amazon Echo misinterpreted a background conversation between a husband and wife as instructions for recording a message and sending it to one of the husband's employees.

    Deployer: Amazon · Developer: Amazon · Harmed: Privacy, Biometric data subjects, Amazon Echo users

  23. #556 · 4 reports

    Amazon Allegedly Violated Children's Privacy through Default Voice Collection Settings AIID ↗

    Amazon's retention of children' voice recordings indefinitely as the default setting reportedly to train Alexa's voice recognition for Alexa-enabled devices was charged by the FTC and DOJ to violate COPPA Rule.

    Deployer: Amazon · Developer: Amazon · Harmed: Alexa Children Users, Minors, Alexa Users, Privacy, Biometric Data Subjects

  24. #184 · 3 reports

    Facial Recognition Program in São Paulo Metro Stations Suspended for Illegal and Disproportionate Violation of Citizens' Right to Privacy AIID ↗

    A facial recognition program rolled out by São Paulo Metro Stations was suspended following a court ruling in response to a lawsuit by civil society organizations, who cited fear of it being integrated with other electronic surveillance entities without consent, and lack of transparency about the biometric data collection process of metro users.

    Deployer: Companhia do Metropolitano de São Paulo · Developer: SecurOS · Harmed: São Paulo Metro users, São Paulo citizens, Privacy, General public of Brazil, General public, Biometric data subjects

  25. #167 · 1 report

    Researchers' Homosexual-Men Detection Model Denounced as a Threat to LGBTQ People's Safety and Privacy AIID ↗

    Researchers at Stanford Graduate School of Business developed a model that determined, on a binary scale, whether someone was homosexual using only his facial image, which advocacy groups such as GLAAD and the Human Rights Campaign denounced as flawed science and threatening to LGBTQ folks.

    Deployer: Yilun Wang, Michal Kosinski · Developer: Yilun Wang, Michal Kosinski · Harmed: Privacy, non-American LGBTQ people, LGBTQ people of color, LGBTQ people, Biometric data subjects

  26. #1428 · 2 reports

    UK High Court Found Sky Betting & Gaming Unlawfully Used Automated Profiling and Targeted Marketing to Exploit a Recovering Problem Gambler AIID ↗

    In the UK, the High Court found that Sky Betting & Gaming unlawfully used automated profiling and targeted direct marketing to pursue a recovering problem gambler from July 28, 2017 onward without valid consent. Sky reportedly treated him as a high-value customer despite addiction indicators.

    Deployer: Sky Betting & Gaming, Hestview Ltd, Bonne Terre Ltd · Developer: Sky Betting & Gaming, Hestview Ltd, Bonne Terre Ltd · Harmed: Sky Betting & Gaming customers with gambling disorders, RTM (recovering problem gambler), Recovering problem gamblers, Privacy, People with gambling disorders

  27. #267 · 10 reports

    Clearview AI Algorithm Built on Photos Scraped from Social Media Profiles without Consent AIID ↗

    Face-matching algorithm by Clearview AI was built using scraped images from social media sites such as Instagram and Facebook without user consent, violating social media site policies, and allegedly privacy regulations.

    Deployer: Clearview AI · Developer: Clearview AI · Harmed: Social media users, Privacy, Instagram users, Facebook users, Biometric data subjects

  28. #408 · 1 report

    Facebook Reportedly Outed Sex Workers through Friend Recommendations AIID ↗

    Facebook's "People You May Know" feature reportedly outed sex workers by recommending clients to their personal accounts or family members to their business accounts with no option to opt out.

    Deployer: Facebook · Developer: Facebook · Harmed: Social media users, sex workers using Facebook, sex workers, Privacy, Facebook users, Biometric data subjects

  29. #190 · 4 reports

    ByteDance Allegedly Trained "For You" Algorithm Using Content Scraped without Consent from Other Social Platforms AIID ↗

    ByteDance allegedly scraped short-form videos, usernames, profile pictures, and descriptions of accounts on Instagram, Snapchat, and other sources, and uploaded them without consent on Flipagram, TikTok’s predecessor, in order to improve its “For You” algorithm's performance on American users.

    Deployer: Bytedance · Developer: Bytedance · Harmed: Instagram Users, Snapchat Users, American Social Media Users

  30. #109 · 1 report

    PimEyes's Facial Recognition AI Allegedly Lacked Safeguards to Prevent Itself from Being Abused AIID ↗

    PimEyes offered its subscription-based AI service to anyone in the public to search for matching facial images across the internet, which critics said lacked public oversight and government rules to prevent itself from misuse such as stalking women.

    Deployer: PimEyes · Developer: PimEyes · Harmed: Privacy, internet users, Biometric data subjects

  31. #368 · 10 reports

    Facial Recognition Smart Phone App 'Blue Wolf' Reportedly Monitored Palestinians in the West Bank AIID ↗

    A surveillance program involving facial recognition and algorithmic recommendations, Blue Wolf, was reportedly deployed by the Israeli military to monitor Palestinians in the West Bank.

    Deployer: Israel Defense Forces, Government of Israel · Developer: AnyVision · Harmed: Privacy, Palestinians residing in the West Bank, Palestinians, General public, Biometric data subjects

  32. #406 · 1 report

    Facebook's Friend Suggestion Feature Recommends Patients of Psychiatrist to Each Other AIID ↗

    Facebook's "People You May Know" (PYMK) feature was reported by a psychiatrist for recommending her patients as friends through recommendations, violating patients' privacy and confidentiality.

    Deployer: Facebook · Developer: Facebook · Harmed: pseudonymized psychiatrist's patients, pseudonymized psychiatrist, Privacy, Patients, healthcare providers, Biometric data subjects

  33. #122 · 1 report

    Facebook's 'Tag Suggestions' Allegedly Stored Biometric Data without User Consent AIID ↗

    Facebook's initial version of the its Tag Suggestions feature where users were offered suggestions about the identity of people's faces in photos allegedly stored biometric data without consent, violating the Illinois Biometric Information Privacy Act.

    Deployer: Facebook · Developer: Facebook · Harmed: Social media users, Privacy, Facebook users, Biometric data subjects

  34. #254 · 2 reports

    Google's Face Grouping Allegedly Collected and Analyzed Users' Facial Structure without Consent, Violated BIPA AIID ↗

    A class-action lawsuit alleged Google failing to provide notice, obtain informed written consent, or publish data retention policies about the collection, storage, and analysis of its face-grouping feature in Google Photos, which violated Illinois Biometric Information Privacy Act (BIPA).

    Deployer: Google · Developer: Google · Harmed: Privacy, Illinois residents, Google Photos users residing in Illinois, Google Photos users, Biometric data subjects

  35. #387 · 1 report

    Oracle's Algorithmic Data Processing System Alleged as Unlawful and Violating Privacy Rights AIID ↗

    Oracle's automated system involving algorithmic data processing was alleged in a lawsuit to have been unlawfully collecting personal data from millions of people and violating their privacy rights.

    Deployer: Oracle · Developer: Oracle · Harmed: Privacy, internet users, Biometric data subjects

  36. #409 · 3 reports

    Facial Recognition Researchers Allegedly Used YouTube Videos of Transgender People Without Consent AIID ↗

    YouTube videos of transgender people used by researchers to study facial recognition during gender transitions were allegedly used and distributed without permission.

    Deployer: University of North Carolina Wilmington, Karl Ricanek, Gayathri Mahalingam · Developer: University of North Carolina Wilmington, Karl Ricanek, Gayathri Mahalingam · Harmed: YouTubers, YouTube users, Transgender YouTubers, transgender people, Social media users, Privacy, Biometric data subjects

  37. #44 · 1 report

    Machine Personal Assistants Failed to Maintain Social Norms AIID ↗

    During an experiment of software personal assistants at the Information Sciences Institute (ISI) at the University of Southern California (USC), researchers found that the assistants violated the privacy of their principals and were unable to respect the social norms of the office.

    Deployer: Usc Information Sciences Institute · Developer: Usc Information Sciences Institute · Harmed: Usc Information Sciences Institute

  38. #170 · 3 reports

    Target Suggested Maternity-Related Advertisements to a Teenage Girl's Home, Allegedly Correctly Predicting Her Pregnancy via Algorithm AIID ↗

    Target recommended maternity-related items to a family in Atlanta via ads, allegedly predicting their teenage daughter’s pregnancy before her father did, although critics have called into question the predictability of the algorithm and the authenticity of its claims.

    Deployer: Target · Developer: Target · Harmed: Target customers, Privacy, Consumers, Biometric data subjects

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.