AI Incident Database
Browse AI incidents
Every incident record (metadata only) from the weekly snapshot of 2026-09-07. Filter, then export the selection with its licence attached; each row links to the full record and its reports.
-
Australian Retailers Reportedly Captured Face Prints of Their Customers without Consent AIID ↗
Major Australian retailers reportedly analyzed in-store footage to capture facial features of their customers without consent, which was criticized by consumer groups as creepy and invasive.
-
Private Medical Photos Were Reportedly Found in LAION-5B AI Training Dataset AIID ↗
In September 2022, an artist using the name Lapine reported finding private post-operative medical photos of herself in LAION-5B, a web-scraped image-text dataset used in AI image-synthesis research. Ars Technica confirmed her images were referenced in the dataset and reported finding thousands of similar patient medical-record photos.
-
A Chinese Tech Worker at Zhihu Fired Allegedly via a Resignation Risk Prediction Algorithm AIID ↗
The firing of an employee at Zhihu, a large Q&A platform in China, was allegedly caused by the use of a behavioral perception algorithm which claimed to predict a worker’s resignation risk using their online footprints, such as browsing history and internal communication.
-
Local South Korean Government’s Use of CCTV Footage Analysis via Facial Recognition to Track COVID Cases Raised Concerns about Privacy, Retention, and Potential Misuse AIID ↗
Bucheon government's use of facial recognition in analyzing CCTV footage, despite gaining wide public support, was scrutinized by privacy advocates and some lawmakers for collecting data without consent, and retaining and misusing data beyond pandemic needs.
-
McDonald's AI Drive-Thru Allegedly Collected Biometric Customer Data without Consent, Violating BIPA AIID ↗
McDonald's use of chatbot in its AI drive-through in Chicago was alleged in a lawsuit to have collected and processed voice data without user consent to predict customer information, which violated Illinois Biometric Information Privacy Act (BIPA).
-
Xsolla Employees Fired by CEO Allegedly via Big Data Analytics of Work Activities AIID ↗
Xsolla CEO fired more than a hundred employees from his company in Perm, Russia, based on big data analysis of their remote digitized-work activity, which critics said was violating employee's privacy, outdated, and extremely ineffective.
-
GitHub Copilot, Copyright Infringement and Open Source Licensing AIID ↗
Users of GitHub Copilot can produce source code subject to license requirements without attributing and licensing the code to the rights holder.
-
Amazon Allegedly Forced Deployment of AI-Powered Cameras on Delivery Drivers AIID ↗
Amazon delivery drivers were allegedly forced to consent to algorithmic collection and processing of their location, movement, and biometric data through AI-powered cameras, or be dismissed.
-
XPeng Motors Fined For Illegal Collection of Consumers’ Faces Using Facial Recognition Cameras AIID ↗
The Chinese electric vehicle (EV) firm XPeng Motors was fined by local market regulators for illegally collecting in-store customers’ facial images without their consent for six months.
-
Meta Allegedly Used Books3, a Dataset of 191,000 Pirated Books, to Train LLaMA AI AIID ↗
Meta and Bloomberg allegedly used Books3, a dataset containing 191,000 pirated books, to train their AI models, including LLaMA and BloombergGPT, without author consent. Lawsuits from authors such as Sarah Silverman and Michael Chabon claim this constitutes copyright infringement. Books3 includes works from major publishers like Penguin Random House and HarperCollins. Meta argues its AI outputs are not "substantially similar" to the original books, but legal challenges continue.
-
Miami Police Deployed Facial Recognition to Arrest George Floyd Protestor Allegedly without Cause AIID ↗
Miami Police's arrest report for a George Floyd protestor did not disclose use of facial recognition, which allegedly did not meet the legal threshold for probable cause for arrest.
-
Uber Allegedly Violated GDPR by Failing to Provide Sufficient Notice on Automated Profiling for Drivers AIID ↗
Uber was alleged in a lawsuit to have provided incomplete notice about automated decision-making and profiling for drivers such as information about their driving behavior, and use of phone.
-
iRobot Roomba J7 R&D Images Reportedly Appeared in Private Online Groups After Data Labeling AIID ↗
Images reportedly captured in 2020 by development versions of iRobot's Roomba J7 robot vacuum during an AI training data project were sent to Scale AI for labeling and later appeared in private Facebook, Discord, and other online groups. Reporting described some images as showing sensitive household scenes.
-
Finnish Police Were Reportedly Reprimanded After National Bureau of Investigation Unit Allegedly Used Clearview AI to Identify Potential Abuse Victims AIID ↗
Finland's Deputy Data Protection Ombudsman reportedly reprimanded the National Police Board after a National Bureau of Investigation child sexual exploitation unit allegedly used Clearview AI in late 2019 or early 2020 to identify potential child sexual abuse victims. Four NBI users reportedly made about 120 searches during a free trial without controller approval or prior assessment of how uploaded biometric data would be handled.
-
South Korean Agencies Reportedly Shared Airport Travelers' Face Images with Companies to Train Immigration Facial Recognition System AIID ↗
Reporting in 2021 alleged that South Korea's Ministry of Justice shared roughly 170 million face images and related biometric data from Korean and foreign airport travelers with the Ministry of Science and Information and Communication Technology (ICT) and private companies for an AI identification and tracking system used in immigration screening. The data was reportedly used for AI training and algorithm testing without travelers' consent.
-
Buenos Aires Government Reportedly Used Children's Personal Data in Facial Recognition System for Fugitives AIID ↗
Beginning in April 2019, the Buenos Aires city government reportedly used data from Argentina’s CONARC fugitive database, including children’s identities and reference photos, in its live Facial Recognition System for Fugitives (SRFP). Human Rights Watch found at least 166 children had appeared in CONARC between 2017 and 2020 and warned that the system exposed them to privacy violations and elevated risks of false matches.
-
Ever AI Reportedly Deceived Customers about FRT Use in App AIID ↗
Ever AI, now Paravision AI, allegedly failed to inform customers about the development and use of facial recognition that facilitates the sale of customers’ data to various businesses, a business model that critics said was an egregious violation of privacy.
-
OpenAI Alleged by Lawsuit Violated Users' Privacy Rights by Training AI on Private Info without Informed Consent AIID ↗
OpenAI's products such as ChatGPT and DALL-E were alleged in a lawsuit using stolen private information from internet users without their informed consent or knowledge.
-
GPT-2 Reportedly Reproduced Personal Data from Its Training Data AIID ↗
OpenAI's GPT-2 reportedly memorized and reproduced portions of its training data, including personal information such as names, email addresses, social media handles, and phone numbers. Researchers raised concerns that large language models could expose private or sensitive information when trained on web-scale datasets containing personal data.
-
OpenAI's Training Data for LLMs Allegedly Comprised of Copyrighted Books AIID ↗
Two authors alleged in a class action lawsuit OpenAI infringed authors' copyrights by incorporating illegal "shadow libraries" offering copyrighted books without permission in the training data of its generative LLMs, such as ChatGPT.
-
Calgary Malls Reportedly Deployed Facial Recognition Without Customer Consent AIID ↗
Facial recognition (FRT) was reportedly deployed in some Calgary-area malls to approximate customer age and gender without explicit consent, which a privacy expert warned was a cause for concern.
-
Amazon Echo Mistakenly Recorded and Sent Private Conversation to Random Contact AIID ↗
Amazon Echo misinterpreted a background conversation between a husband and wife as instructions for recording a message and sending it to one of the husband's employees.
-
Amazon Allegedly Violated Children's Privacy through Default Voice Collection Settings AIID ↗
Amazon's retention of children' voice recordings indefinitely as the default setting reportedly to train Alexa's voice recognition for Alexa-enabled devices was charged by the FTC and DOJ to violate COPPA Rule.
-
Facial Recognition Program in São Paulo Metro Stations Suspended for Illegal and Disproportionate Violation of Citizens' Right to Privacy AIID ↗
A facial recognition program rolled out by São Paulo Metro Stations was suspended following a court ruling in response to a lawsuit by civil society organizations, who cited fear of it being integrated with other electronic surveillance entities without consent, and lack of transparency about the biometric data collection process of metro users.
-
Researchers' Homosexual-Men Detection Model Denounced as a Threat to LGBTQ People's Safety and Privacy AIID ↗
Researchers at Stanford Graduate School of Business developed a model that determined, on a binary scale, whether someone was homosexual using only his facial image, which advocacy groups such as GLAAD and the Human Rights Campaign denounced as flawed science and threatening to LGBTQ folks.
-
UK High Court Found Sky Betting & Gaming Unlawfully Used Automated Profiling and Targeted Marketing to Exploit a Recovering Problem Gambler AIID ↗
In the UK, the High Court found that Sky Betting & Gaming unlawfully used automated profiling and targeted direct marketing to pursue a recovering problem gambler from July 28, 2017 onward without valid consent. Sky reportedly treated him as a high-value customer despite addiction indicators.
-
Clearview AI Algorithm Built on Photos Scraped from Social Media Profiles without Consent AIID ↗
Face-matching algorithm by Clearview AI was built using scraped images from social media sites such as Instagram and Facebook without user consent, violating social media site policies, and allegedly privacy regulations.
-
Facebook Reportedly Outed Sex Workers through Friend Recommendations AIID ↗
Facebook's "People You May Know" feature reportedly outed sex workers by recommending clients to their personal accounts or family members to their business accounts with no option to opt out.
-
ByteDance Allegedly Trained "For You" Algorithm Using Content Scraped without Consent from Other Social Platforms AIID ↗
ByteDance allegedly scraped short-form videos, usernames, profile pictures, and descriptions of accounts on Instagram, Snapchat, and other sources, and uploaded them without consent on Flipagram, TikTok’s predecessor, in order to improve its “For You” algorithm's performance on American users.
-
PimEyes's Facial Recognition AI Allegedly Lacked Safeguards to Prevent Itself from Being Abused AIID ↗
PimEyes offered its subscription-based AI service to anyone in the public to search for matching facial images across the internet, which critics said lacked public oversight and government rules to prevent itself from misuse such as stalking women.
-
Facial Recognition Smart Phone App 'Blue Wolf' Reportedly Monitored Palestinians in the West Bank AIID ↗
A surveillance program involving facial recognition and algorithmic recommendations, Blue Wolf, was reportedly deployed by the Israeli military to monitor Palestinians in the West Bank.
-
Facebook's Friend Suggestion Feature Recommends Patients of Psychiatrist to Each Other AIID ↗
Facebook's "People You May Know" (PYMK) feature was reported by a psychiatrist for recommending her patients as friends through recommendations, violating patients' privacy and confidentiality.
-
Facebook's 'Tag Suggestions' Allegedly Stored Biometric Data without User Consent AIID ↗
Facebook's initial version of the its Tag Suggestions feature where users were offered suggestions about the identity of people's faces in photos allegedly stored biometric data without consent, violating the Illinois Biometric Information Privacy Act.
-
Google's Face Grouping Allegedly Collected and Analyzed Users' Facial Structure without Consent, Violated BIPA AIID ↗
A class-action lawsuit alleged Google failing to provide notice, obtain informed written consent, or publish data retention policies about the collection, storage, and analysis of its face-grouping feature in Google Photos, which violated Illinois Biometric Information Privacy Act (BIPA).
-
Oracle's Algorithmic Data Processing System Alleged as Unlawful and Violating Privacy Rights AIID ↗
Oracle's automated system involving algorithmic data processing was alleged in a lawsuit to have been unlawfully collecting personal data from millions of people and violating their privacy rights.
-
Facial Recognition Researchers Allegedly Used YouTube Videos of Transgender People Without Consent AIID ↗
YouTube videos of transgender people used by researchers to study facial recognition during gender transitions were allegedly used and distributed without permission.
-
Machine Personal Assistants Failed to Maintain Social Norms AIID ↗
During an experiment of software personal assistants at the Information Sciences Institute (ISI) at the University of Southern California (USC), researchers found that the assistants violated the privacy of their principals and were unable to respect the social norms of the office.
-
Target Suggested Maternity-Related Advertisements to a Teenage Girl's Home, Allegedly Correctly Predicting Her Pregnancy via Algorithm AIID ↗
Target recommended maternity-related items to a family in Atlanta via ads, allegedly predicting their teenage daughter’s pregnancy before her father did, although critics have called into question the predictability of the algorithm and the authenticity of its claims.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.