AI Incident Database

Browse AI incidents

Every incident record (metadata only) from the weekly snapshot of 2026-09-07. Filter, then export the selection with its licence attached; each row links to the full record and its reports.

Reset

88 incidents · subdomain: Compromise of privacy by obtaining, leaking or correctly inferring sensitive information · page 1 of 2

  1. #1418 · 16 reports

    Meta AI Smart Glasses Reportedly Routed Intimate Imagery to Reviewers at Kenyan Contractor Sama Before Meta Ended Contract AIID ↗

    Meta AI smart glasses reportedly sent media and transcripts from AI interactions to Sama contractors in Kenya for human review. Workers said they saw nudity, bathroom use, sex, bank cards, and other private activity, sometimes involving people unaware they were recorded or faces left visible despite filtering. The reports prompted lawsuits and regulatory inquiries before Meta paused the work and ended its Sama contract, affecting 1,108 workers.

    Deployer: Sama, Meta · Developer: Meta, Ai Enabled Smart Glasses Developers · Harmed: Meta Users, Meta Ai Smart Glasses Users, People Recorded By Meta Ai Smart Glasses, Bystanders Recorded By Smart Glasses, Sama Data Annotators In Kenya, Data Annotators, Sama Workers Affected By Meta Contract Termination, Sama, Privacy

  2. #1443 · 1 report

    Grok Reportedly Disclosed Adult Performer Siri Dahl's Legal Name and Birthdate, Allegedly Contributing to Doxxing and Harassment AIID ↗

    Grok is reported to have publicly provided adult performer Siri Dahl's legal name and birthdate without being asked for that information. Dahl reportedly said she had worked to keep those details private and that, after the disclosure, impersonation accounts and reposts of stolen content using her legal name purportedly appeared online.

    Deployer: Xai · Developer: Xai · Harmed: Victims Of Doxxing, Siri Dahl, Privacy

  3. #1386 · 1 report

    NPR Host David Greene Alleged Google's NotebookLM Replicated His Voice Without Consent, Prompting Lawsuit AIID ↗

    NPR's David Greene reportedly sued Google LLC and Alphabet in Santa Clara County, alleging NotebookLM's Audio Overviews uses a synthetic male voice that purportedly mimics his cadence and delivery without consent or compensation. The complaint reportedly cited an independent voice-recognition analysis reporting 53–60% confidence his voice trained the model. Google reportedly called the allegations baseless and said the voice is based on a paid actor.

    Deployer: Google · Developer: Google · Harmed: Voice Actors, David Greene

  4. #1362 · 1 report

    Border Patrol Agent Allegedly Claimed Facial Recognition Identified Minneapolis ICE Observer and Global Entry Was Reportedly Revoked Three Days Later AIID ↗

    On 01/10/2026 near Minneapolis, Minnesota, legal observer Nicole Cleland reportedly stated that a CBP Border Patrol agent stopped her vehicle, addressed her by name, and claimed agents used facial recognition to identify her while recording on body cam. She reportedly had her Global Entry and TSA PreCheck revoked on 01/13/2026, which she alleged was retaliatory intimidation, causing travel burden and chilling effects.

    Deployer: Unnamed United States Border Patrol agent, United States Immigration and Customs Enforcement, United States Department of Homeland Security, United States Customs and Border Protection, United States Border Patrol, National security and intelligence stakeholders, Law enforcement, Facial recognition system deployers · Developer: NEC, Facial recognition system developers · Harmed: Privacy, Nicole Cleland, Legal observers, Immigration enforcement observers, General public of the United States, General public, Biometric data subjects

  5. #1298 · 4 reports

    Perplexity AI Reportedly Accused in Federal Lawsuit of Purported Copyright Infringement and False Attribution of Chicago Tribune Content AIID ↗

    The Chicago Tribune filed a federal lawsuit alleging that Perplexity AI unlawfully reproduced and paraphrased its copyrighted journalism in generative chatbot and search outputs. The complaint claims the AI system produced substitutive answers that bypassed links to the Tribune's website, diverted revenue, and at times hallucinated inaccurate information falsely attributed to the newspaper.

    Deployer: Perplexity Ai · Developer: Perplexity Ai · Harmed: Chicago Tribune, Journalistic Integrity, Epistemic Integrity

  6. #1284 · 2 reports

    Secret Desires AI Platform Reportedly Exposed Nearly Two Million Sensitive Images in Cloud Storage Leak AIID ↗

    The erotic AI chatbot and image-generation platform Secret Desires reportedly left nearly two million sensitive images and videos publicly exposed in misconfigured cloud storage. The leaked files reportedly included personal photos, workplace and university information, and explicit AI-generated deepfakes of women and girls. The content reportedly became inaccessible shortly after journalists contacted the platform.

    Deployer: Secret Desires · Developer: Secret Desires, Chatbot developers · Harmed: Women and girls, Women, People depicted in Secret Desires deepfakes, General public, Epistemic integrity

  7. #1278 · 4 reports

    ChatGPT Reportedly Found to Reproduce Protected German Lyrics in Copyright Case AIID ↗

    A Munich regional court ruled that ChatGPT reportedly reproduced protected German song lyrics and that OpenAI's models were trained on copyrighted texts, including works by musician Herbert Grönemeyer, without authorization. The court reportedly found both memorization of nine songs and lyric output to infringe exploitation rights. OpenAI disputes the ruling and may appeal. Damages were ordered, with implications for AI training on copyrighted works.

    Deployer: Openai · Developer: Openai · Harmed: Songwriters, Publishers, Musicians, Herbert Gronemeyer, German Songwriters, German Publishers, German Musicians, German Artists, Gema, Artists

  8. #1213 · 1 report

    Gaggle AI Monitoring at Lawrence, Kansas High School Reportedly Misflags Student Content and Blocks Emails AIID ↗

    In Lawrence, Kansas, students allege the Gaggle Safety Management AI wrongly flagged benign schoolwork, including art photos and casual messages, as child pornography or threats. The system reportedly deleted content, blocked an email records request, and led to questioning of students. Critics cite chilling effects and privacy risks. A lawsuit filed in August 2025 challenges the district's use of Gaggle as unconstitutional surveillance. Gaggle reportedly denies compromising privacy.

    Deployer: Lawrence Public Schools (Usd 497) · Developer: Gaggle · Harmed: Students, Lawrence Public Schools (Usd 497) Students, Educational Communities, Privacy

  9. #1176 · 2 reports

    Microsoft's Windows Recall Allegedly Stores Passwords and Social Security Numbers in Preview Mode AIID ↗

    Microsoft's Windows Recall, an AI-powered screenshot and retrieval tool for Copilot+ PCs, was allegedly still capturing sensitive information such as passwords, Social Security numbers, and bank details despite a built-in "filter sensitive information" feature. Independent testing reportedly found the filter failed in multiple cases. Microsoft reportedly classified Recall as a preview feature and said improvements were in progress.

    Deployer: Microsoft · Developer: Microsoft · Harmed: Windows Recall users, Windows 11 users, Privacy, Microsoft users

  10. #1186 · 5 reports

    Reported Public Exposure of Over 100,000 LLM Conversations via Share Links Indexed by Search Engines and Archived AIID ↗

    Across 2024 and 2025, the share features in multiple LLM platforms, including ChatGPT, Claude, Copilot, Qwen, Mistral, and Grok, allegedly exposed user conversations marked "discoverable" to search engines and archiving services. Over 100,000 chats were reportedly indexed and later scraped, purportedly revealing API keys, access tokens, personal identifiers, and sensitive business data.

    Deployer: Xai, Openai, Mistral, Microsoft, Anthropic, Alibaba · Developer: Xai, Openai, Mistral, Microsoft, Anthropic, Alibaba · Harmed: Users Of Qwen, Users Of Mistral, Users Of Grok, Users Of Copilot, Users Of Claude, Privacy, General Public, Chatgpt Users

  11. #1360 · 1 report

    CISA Acting Director Reportedly Uploaded Sensitive Government Documents to Public ChatGPT Instance AIID ↗

    Madhu Gottumukkala, acting director of the Cybersecurity and Infrastructure Security Agency (CISA), reportedly uploaded government contracting documents marked "for official use only" into a public version of ChatGPT. The uploads reportedly triggered automated cybersecurity alerts and prompted a Department of Homeland Security review to assess potential exposure of sensitive information.

    Deployer: Madhu Gottumukkala · Developer: Openai · Harmed: United States Department Of Homeland Security, Cybersecurity And Infrastructure Security Agency, United States Government, National Security And Intelligence Stakeholders

  12. #1356 · 3 reports

    Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update AIID ↗

    Security researchers reported that the Urban VPN Proxy browser extension introduced AI conversation–harvesting functionality in version 5.5.0, released July 9, 2025. The extension allegedly intercepted and exfiltrated private conversations from AI platforms including ChatGPT, Claude, Gemini, Grok, and others without a user-facing opt-out. The data, including sensitive personal and financial information, was reportedly shared with affiliated data brokers for commercial analytics.

    Deployer: Urban Cyber Security · Developer: Urban Cyber Security, Biscience · Harmed: Urban Vpn Proxy Users, Privacy, Perplexity Users, Meta Ai Users, Grok Users, General Public, Gemini Users, Deepseek Users, Copilot Users, Claude Users, Chatgpt Users, Chatbot Users, Browser Extension Users, Chatbot Developers, Large Language Model Developers

  13. #1179 · 2 reports

    McDonald's McHire AI Recruitment Platform Reportedly Exposed Data of 64 Million Applicants via Default Login and API Vulnerability AIID ↗

    Researchers Ian Carroll and Sam Curry reported that McDonald's AI-powered hiring tool, McHire (using Paradox.ai's "Olivia" chatbot), could purportedly be accessed via default admin credentials and an insecure direct object reference in an internal API. The flaws allegedly allowed viewing of applicants' personally identifiable information and chat histories. McDonald's and Paradox reportedly patched the issues within a day of disclosure; Paradox stated only five records were accessed.

    Deployer: Paradox.Ai, Mcdonald'S · Developer: Paradox.Ai, Mcdonald'S · Harmed: Privacy, Mcdonald'S Applicants, Job Applicants

  14. #1081 · 6 reports

    Voice Actor Alleges Unconsented Use of AI-Generated Voice on ScotRail Trains AIID ↗

    Scottish voice actor Gayanne Potter alleges her voice was used without proper consent in ScotRail's AI train announcements. She claims she had agreed to limited use of her voice data by ReadSpeaker but was not informed it would be used in a synthetic voice system called "Iona." ScotRail continues to use the voice, stating the dispute is between Potter and ReadSpeaker.

    Deployer: Scotrail · Developer: Readspeaker · Harmed: Gayanne Potter, Voiceover Artists, Individuals Affected By Unauthorized Biometric Data Use

  15. #1075 · 15 reports

    New Orleans Police Reportedly Used Real-Time Facial Recognition Alerts Supplied by Project NOLA Despite Local Ordinance AIID ↗

    New Orleans police reportedly received real-time facial recognition alerts from a privately operated surveillance network run by Project NOLA, reportedly leading to dozens of arrests. This purported use of AI surveillance appears to conflict with a 2022 city ordinance that restricts facial recognition to specific post-incident investigations. Police are alleged to have not consistently disclosed the technology's use.

    Deployer: Project NOLA, New Orleans Police Department, Law enforcement, Facial recognition system deployers · Developer: Facial recognition system developers, Dahua Technology · Harmed: Residents subject to live surveillance in New Orleans, Privacy, People misidentified by facial recognition systems, General public of the United States, General public of New Orleans, General public, Biometric data subjects, Arrested individuals in New Orleans

  16. #1070 · 14 reports

    Serviceaide AI Platform Implicated in Health Data Exposure Affecting 483,000 Catholic Health Patients AIID ↗

    An AI-linked platform operated by Serviceaide exposed sensitive health data from Catholic Health, affecting 483,000 patients. The breach stemmed from a misconfigured Elasticsearch database used in Serviceaide’s agentic AI infrastructure. Exposed information included medical records, insurance details, and login credentials. While no misuse has been confirmed, the nature of the data has prompted regulatory scrutiny and legal investigations.

    Deployer: Serviceaide · Developer: Serviceaide · Harmed: Privacy, Patients Of Catholic Health, Patients, Catholic Health

  17. #1101 · 3 reports

    Meta AI App Reportedly Publishes Personal Chats Without Users Fully Realizing AIID ↗

    Meta launched a stand-alone AI app with a "Discover" feed allowing users to share conversations with its chatbot. Multiple reports indicate that some users may have inadvertently published highly personal interactions, including audio recordings, medical questions, legal concerns, and intimate relationship disclosures. While Meta states that sharing is opt-in, the feature's design and labeling may have led to user confusion about what would be publicly visible.

    Deployer: Meta · Developer: Meta, Large language model developers, Chatbot developers · Harmed: Privacy, Meta users, Meta AI users, Chatbot users, Biometric data subjects

  18. #1020 · 2 reports

    Reportedly Unsafe Deployment of Llama.cpp Reveals Interactive AI-Generated CSAM Roleplay Prompts AIID ↗

    A study by UpGuard reports that misconfigured llama.cpp servers publicly exposed user prompts, including hundreds of interactive roleplay scenarios. Some prompts explicitly described fictional sexual abuse of children aged 7–12. While no real children were involved, the findings demonstrate how open-source LLMs can be exploited to generate AI-enabled child sexual abuse material (CSAM).

    Deployer: Users Of Llama.Cpp Servers · Developer: Meta, Users Of Llama.Cpp Servers · Harmed: General Public, Users Of Llama.Cpp Servers

  19. #1010 · 2 reports

    GenNomis AI Database Reportedly Exposes Nearly 100,000 Deepfake and Nudify Images in Public Breach AIID ↗

    In March 2025, cybersecurity researcher Jeremiah Fowler discovered an unprotected database linked to GenNomis by AI-NOMIS, a South Korean company offering face-swapping and "nudify" AI services. The exposed 47.8GB dataset included nearly 100,000 files. Many depicted explicit deepfake images, some involving minors or celebrities. No personal data was found, but the breach was a serious failure in data security and consent safeguards in AI image-generation platforms.

    Deployer: Gennomis By Ai Nomis, Gennomis · Developer: Gennomis By Ai Nomis, Ai Nomis · Harmed: Public Figures And Celebrities Depicted In Explicit Ai Images, Minors, Individuals Whose Likenesses Were Used Without Consent, General Public, Privacy, Epistemic Integrity

  20. #1228 · 2 reports

    Alleged ChatGPT Misuse by Contractor Leads to Reported Data Exposure in New South Wales Resilient Homes Program AIID ↗

    A former contractor of the New South Wales Reconstruction Authority reportedly uploaded a spreadsheet containing personal and health information of Resilient Homes Program applicants to ChatGPT during a three-day period in March 2025. Up to 3,000 people may have reportedly been affected.

    Deployer: Openai · Developer: Openai · Harmed: Resilient Homes Program Applicants, Resilient Homes Program, Government Of New South Wales, General Public Of New South Wales, General Public Of Australia, General Public, Privacy

  21. #956 · 1 report

    Alleged Inclusion of 12,000 Live API Keys in LLM Training Data Reportedly Poses Security Risks AIID ↗

    A dataset used to train large language models allegedly contained 12,000 live API keys and authentication credentials. Some of these were reportedly still active and allowed unauthorized access. Truffle Security found these secrets in a December 2024 Common Crawl archive, which spans 250 billion web pages. The affected credentials could have been exploited for unauthorized data access, service disruptions, financial fraud, and a variety of other malicious uses.

    Deployer: Microsoft, Openai, Common Crawl, Microsoft Azure Openai Service · Developer: Common Crawl, Openai, Microsoft · Harmed: Aws, Slack, Mailchimp, Microsoft, Google, Intel, Huawei, Paypal, Ibm, Tencent

  22. #1174 · 2 reports

    Microsoft Copilot Reportedly Able to Access Cached Data from Since-Private GitHub Repositories AIID ↗

    Lasso Security reported that Microsoft Copilot could return content from GitHub repositories that had been public briefly but later set to private or deleted. Lasso attributed this to Bing's caching system, which stored "zombie data" from over 20,000 repositories. The cached content allegedly included sensitive information such as access keys, tokens, and internal packages. Microsoft reportedly classified the issue as low severity and applied only partial mitigations.

    Deployer: Microsoft · Developer: Microsoft · Harmed: Github Users, Github Repositories, Github, Privacy

  23. #1069 · 33 reports

    Purported Graphite Spyware Linked to Paragon Solutions Allegedly Deployed Against Journalists and Civil Society Workers AIID ↗

    Researchers at Citizen Lab and Censys reportedly identified spyware infections involving Graphite, a tool attributed to Israeli firm Paragon Solutions. The spyware was allegedly deployed against civil society actors, including journalists and aid workers, through a zero-click WhatsApp exploit. WhatsApp notified over 90 targeted individuals. Evidence reportedly suggests deployments in multiple democratic countries.

    Deployer: York Regional Police Service (Ontario, Canada), Unidentified law enforcement or intelligence entity (Singapore), Unidentified law enforcement or intelligence entity (Israel), Unidentified law enforcement or intelligence entity (Denmark), Unidentified law enforcement or intelligence entity (Cyprus), Unidentified law enforcement or intelligence entity (Australia), Peel Regional Police (Ontario, Canada), Ontario Provincial Police · Developer: REDLattice, Paragon Solutions · Harmed: Refugees in Libya, Privacy, National security and intelligence stakeholders, Mediterranea Saving Humans, Luca Casarini, Journalists, Humanitarian workers, Giuseppe "Beppe" Caccia

  24. #1172 · 2 reports

    Meta AI Bug in Deployed Service Reportedly Allowed Potential Access to Other Users' Prompts and Responses AIID ↗

    A security researcher reported a vulnerability in Meta AI's deployed chatbot service that, under certain conditions, could allow an unauthorized user to view another user's prompts and AI-generated responses. The flaw reportedly involved guessable prompt IDs and insufficient server-side authorization checks. Meta reportedly fixed the issue in January 2025 and found no evidence of malicious exploitation, awarding the researcher a bug bounty.

    Deployer: Meta · Developer: Meta, Large language model developers, Chatbot developers · Harmed: Privacy, Meta users, Meta AI users, General public, Biometric data subjects

  25. #906 · 3 reports

    Alleged AI-Powered Call Center Breach Exposes Over 10 Million Conversations in the Middle East AIID ↗

    An AI-powered call center platform in the Middle East reportedly experienced a significant data breach, allegedly exposing over 10 million conversations between consumers, operators, and AI agents. Attackers allegedly accessed the platform’s management dashboard, stealing sensitive data, including national ID documents. The breach poses reported risks such as phishing, identity theft, and social engineering attacks. The stolen data was reportedly listed for sale on the dark web.

    Deployer: Cybercriminals · Developer: Unnamed Ai Call Center Platform Provider · Harmed: Privacy, Enterprise Clients, End Users Of Undisclosed Middle Eastern Ai Powered Cloud Call Center Platform

  26. #814 · 9 reports

    AI Avatar of Murder Victim Created Without Consent on Character.ai Platform AIID ↗

    A user on the Character.ai platform created an unauthorized AI avatar of Jennifer Ann Crecente, a murder victim from 2006, without her family's consent. The avatar was made publicly available, violating Character.ai's policy against impersonation. After the incident surfaced, Character.ai removed the avatar, acknowledging a policy violation.

    Deployer: Character.Ai · Developer: Character.Ai · Harmed: Jennifer Ann Crecente, Drew Crecente, Crecente Family, Brian Crecente

  27. #811 · 6 reports

    AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions AIID ↗

    AI-powered meeting assistants, such as Otter.ai's OtterPilot and Zoom's AI Companion, have reportedly shared sensitive and private conversations beyond the intended audience. These tools, which are set to automatically record and distribute meeting transcripts, allegedly sent confidential discussions after participants had left the meeting, the consequences of which led to unintended exposure of proprietary information and privacy breaches.

    Deployer: Unnamed Venture Capital Investors, Organizations, Employers, Employees, Companies, Alex Bilzerian · Developer: Zoom, Otter.Ai, Ai Transcription Technology Developers · Harmed: Unnamed Venture Capital Investors, Privacy, Organizations, Employers, Employees, Companies, Alex Bilzerian

  28. #807 · 9 reports

    ChatGPT Reportedly Introduces Errors in Critical Child Protection Court Report AIID ↗

    A child protection worker in Victoria, Australia reportedly used ChatGPT to draft a report submitted to the Children's Court. The purportedly AI-generated report contained inaccuracies and downplayed risks to the child, allegedly resulting in a privacy breach when sensitive information was shared with OpenAI.

    Deployer: Government Of Victoria, Employee Of Department Of Families Fairness And Housing, Department Of Families Fairness And Housing · Developer: Openai · Harmed: Unnamed Family Of Child, Unnamed Child

  29. #781 · 2 reports

    Clearview AI Reportedly Faces $33.7 Million Fine for Violating GDPR with Biometric Data Harvesting AIID ↗

    Clearview AI was reportedly fined $33.7 million by the Dutch data protection authority for allegedly creating an illegal facial recognition database by scraping billions of images from the Internet without consent. The company allegedly used AI to convert these images into biometric data and sold the service to law enforcement. This act was reportedly in violation of privacy laws and the GDPR.

    Deployer: Clearview Ai · Developer: Clearview Ai, Facial Recognition System Developers · Harmed: General Public, General Public Of The Netherlands, Privacy, Biometric Data Subjects

  30. #773 · 1 report

    Chatbot in Workplace Training at Bunbury Prison Reveals Real Names in Sexual Harassment Case AIID ↗

    During workplace training at Bunbury Prison in Western Australia, a trainer used Microsoft's Copilot AI chatbot to generate case study scenarios. The chatbot produced a scenario that included the real name of a former employee involved in a sexual harassment case, revealing sensitive information.

    Deployer: Western Australia Department of Justice, Charlotte Ingham · Developer: Microsoft, Large language model developers, Chatbot developers · Harmed: Western Australia Department of Justice senior staff members, Western Australia Department of Justice, Privacy, Bronwyn Hendry

  31. #743 · 1 report

    Gemini AI Allegedly Reads Google Drive Files Without Explicit User Consent AIID ↗

    Kevin Bankston, a privacy activist, claims that Google's Gemini AI scans private Google Drive PDFs without explicit user consent. Bankston reports that after using Gemini on one document, the AI continues to access similar files automatically. Google disputes these claims, stating that Gemini requires proactive user activation and operates within privacy-preserving settings.

    Deployer: Google, Gemini · Developer: Google, Large Language Model Developers · Harmed: Kevin Bankston, Google Users, Google Drive Users, Privacy

  32. #733 · 2 reports

    Auto Insurers Allegedly Are Surreptitiously Collecting and Scoring Driver Data AIID ↗

    The insurance industry allegedly uses AI and telematics to score drivers based on behaviors tracked by automakers and apps like Life360. Data, often collected without clear consent, may affect insurance rates and raises privacy concerns. Consumers are largely unaware of this surveillance, leading to potential misuse and discrimination based on driving habits or socioeconomic factors.

    Deployer: USAA, Toyota, Progressive, MyRadar, Life360, General Motors, GEICO, CSAA · Developer: MyRadar, Life360, Connected Analytic Services, Arity · Harmed: Privacy-conscious individuals, Privacy, People with poor credit scores, MyRadar users, Lower-income workers, Life360 users, Economically vulnerable people, Drivers unaware of data collection

  33. #688 · 14 reports

    Scarlett Johansson Alleges OpenAI's Sky Imitates Her Voice Without Licensing AIID ↗

    OpenAI unveiled a voice assistant with a voice resembling Scarlett Johansson's, despite her refusal to license her voice. Johansson claimed the assistant, "Sky," sounded "eerily similar" to her voice, leading her to seek legal action. OpenAI suspended Sky, asserting the voice was from a different actress.

    Deployer: Sky Voice Assistant, Sam Altman, Openai · Developer: Sam Altman, Openai · Harmed: Scarlett Johansson

  34. #728 · 1 report

    AI Firm Lovo Reportedly Accused of Illegally Replicating Voice Actors' Voices AIID ↗

    Two voice actors, Paul Skye Lehrman and Linnea Sage, are reportedly suing AI start-up Lovo for allegedly creating and promoting unauthorized clones of their voices. Lovo's synthetic voices were allegedly discovered in various media, including a podcast and promotional videos. The actors claim they were misled into providing voice samples, which were then allegedly used without consent, violating trademark and privacy laws.

    Deployer: Synthetic Media Creators, Lovo · Developer: Voice Cloning Technology Developers, Synthetic Media Generation Technology Developers, Synthetic Audio Generation Technology Developers, Lovo · Harmed: Voice Actors, Targets Of Fraudulent Professional Opportunities, Paul Skye Lehrman, Linnea Sage, Epistemic Integrity

  35. #718 · 1 report

    OpenAI, Google, and Meta Alleged to Have Overstepped Legal Boundaries for Training AI AIID ↗

    In late 2021, OpenAI and other tech giants like Google and Meta reportedly faced data shortages for training AI models. OpenAI is said to have developed a tool called Whisper to transcribe over one million hours of YouTube videos, potentially violating YouTube’s terms of service. Similarly, Google allegedly transcribed YouTube videos, risking copyright infringements. Meta reportedly explored summarizing copyrighted texts without permission and debated acquiring Simon & Schuster for data.

    Deployer: Openai, Meta, Google · Developer: Openai, Meta, Google · Harmed: Youtube Creators, General Public, Content Creators

  36. #636 · 5 reports

    AI Romance Apps Reportedly Compromise User Privacy for Data Harvesting AIID ↗

    AI-powered romantic chatbots, marketed for enhancing mental health, are found to exploit user privacy by harvesting sensitive personal information for data sharing and targeted ads, with inadequate security measures and consent protocols, according to research by the Mozilla Foundation.

    Deployer: Romantic Ai, Replika, Genesia Ai Friend And Partner, Eva Ai Chat Bot And Soulmate, Crushon.Ai, Chai · Developer: Romantic Ai, Replika, Genesia Ai Friend And Partner, Eva Ai Chat Bot And Soulmate, Crushon.Ai, Chai, Chatbot Developers · Harmed: General Public, Chatbot Users, Privacy, Replika Users, Chai Users, Romantic Ai Users, Eva Ai Users, Crushon.Ai Users, Genesia Ai Friend And Partner Users

  37. #657 · 1 report

    Alleged ChatGPT Account Compromise Reportedly Led to Unintended Data Exposure AIID ↗

    An alleged security breach involving ChatGPT led to the reported exposure of sensitive conversations, including login credentials and personal data, after a user account was allegedly compromised. OpenAI reportedly responded to the incident with an explanation.

    Deployer: Openai · Developer: Openai, Large Language Model Developers · Harmed: Chatgpt Users, Chase Whiteside, Privacy

  38. #995 · 2 reports

    The New York Times Reportedly Sues OpenAI and Microsoft Over Alleged Unauthorized AI Training on Its Content AIID ↗

    The New York Times alleges that OpenAI and Microsoft used millions of its articles without permission to train AI models, including ChatGPT. The lawsuit claims the companies scraped and reproduced copyrighted content without compensation, in turn undermining the Times’s business and competing with its journalism. Some AI outputs allegedly regurgitate Times articles verbatim. The lawsuit seeks damages and demands the destruction of AI models trained on its content.

    Deployer: Openai, Microsoft · Developer: Openai, Microsoft · Harmed: Writers, The New York Times, Publishers, Media Organizations, Journalists, Journalistic Integrity, Epistemic Integrity

  39. #659 · 3 reports

    Purported Mass Facial Recognition Program in Gaza Reportedly Used by Israeli Forces to Identify Palestinians AIID ↗

    A previously undisclosed facial recognition initiative operated by Israeli military intelligence units was reportedly deployed across Gaza after the October 7, 2023 attacks. According to multiple intelligence officers, the program uses Corsight technology alongside Google Photos to identify individuals from checkpoints, crowds, and drone footage. The system has allegedly produced misidentifications, including the widely reported detention of Palestinian poet Mosab Abu Toha on November 19, 2023.

    Deployer: Unit 8200, Israeli military intelligence, Israeli government, Israel Defense Forces, Facial recognition system deployers · Developer: Unknown Israeli military integrators, Surveillance technology developers, Google Photos, Facial recognition system developers, Corsight · Harmed: Privacy and data rights of Gaza residents, Privacy, Palestinians traveling through Gaza checkpoints, Palestinians, National security and intelligence stakeholders, Mosab Abu Toha, General public of Gaza, General public

  40. #571 · 1 report

    Reported Accidental Exposure of 38TB of Data by Microsoft's AI Research Team AIID ↗

    Microsoft's AI research team reportedly accidentally exposed 38TB of sensitive data while publishing open-source training material on GitHub. The exposure allegedly included secrets, private keys, passwords, and internal Microsoft Teams messages. The team reportedly utilized Azure's Shared Access Signature (SAS) tokens for sharing, which were purportedly misconfigured, leading to the wide exposure of data.

    Deployer: Microsoft · Developer: Microsoft'S Ai Research Division · Harmed: Microsoft Employees, Microsoft, Privacy, Third Parties Whose Confidential Data Was Exposed

  41. #586 · 1 report

    FTC Targets Edmodo for Unlawful Use of Children’s Data and Delegating Compliance to Schools AIID ↗

    Edmodo, an education technology provider, violated the Children's Online Privacy Protection Act Rule (COPPA Rule) by collecting and using children's personal data for advertising purposes without parental consent, according to the FTC. The company outsourced its compliance responsibilities to schools, thereby making them "solely" responsible for COPPA compliance without adequate disclosure. Edmodo is facing a proposed order prohibiting such practices, marking a precedent in the ed tech industry.

    Deployer: Edmodo · Developer: Edmodo · Harmed: Teachers, Students, Schools And Teachers Who Were Misinformed And Burdened With Coppa Compliance Responsibilities Without Adequate Disclosure, Minors, Educational Communities, Children Whose Data Was Collected And Used For Advertising, Biometric Data Subjects, Privacy

  42. #584 · 1 report

    Illinois Residents File Class Action Lawsuit Against Facial Recognition Technology Companies for Allegedly Violating BIPA AIID ↗

    A class action lawsuit was filed against several facial recognition technology companies for allegedly violating the Illinois Biometric Information Privacy Act (BIPA). The defendants are accused of offering a facial recognition search engine called Pimeyes, which collects images from databases across the internet and scans them into their database seemingly without consent. This action is claimed to invade the privacy of millions of Americans. The lawsuit argues that Pimeyes lacks publicly avail

    Deployer: Transaction Cloud, Public Mirror, Pimeyes, Lukasz Kowalczyk, Giorgi Gobronidze, Face Recognition Solutions, Emea Robotics, Does 125, Denis Tatina, Carribex · Developer: Transaction Cloud, Public Mirror, Pimeyes, Lukasz Kowalczyk, Giorgi Gobronidze, Face Recognition Solutions, Emea Robotics, Does 1 25, Denis Tatina, Carribex, Surveillance Technology Developers, Facial Recognition System Developers · Harmed: Nicholas Clayton, Misty Mcgraw, Manuel Clayton, Illinois Residents, Amy Newton, Amanda Curry, General Public, General Public Of Illinois, Privacy, Biometric Data Subjects

  43. #513 · 5 reports

    ChatGPT Reportedly Banned by Italian Authority Due to OpenAI's Purported Lack of Legal Basis for Data Collection and Age Verification AIID ↗

    Italy's data protection authority is reported to have temporarily limited OpenAI's processing of Italian users' data after alleging that ChatGPT lacked adequate notice and legal basis for large-scale personal data collection and processing used to train the system. The authority also cited a March 2023 data breach, possible processing of inaccurate personal data, and the absence of age-verification safeguards for children.

    Deployer: Openai · Developer: Openai, Large Language Model Developers, Chatbot Developers · Harmed: Privacy, Minors, General Public Of Italy, General Public, Minors In Italy

  44. #516 · 2 reports

    ChatGPT Reportedly Exposed Users' Private Data Reportedly Due to Bug AIID ↗

    ChatGPT reportedly exposed titles of users' chat histories and users' private payment information to other users reportedly due to a bug, which prompted its temporary shutdown by OpenAI.

    Deployer: Openai · Developer: Openai, Chatbot Developers, Large Language Model Developers · Harmed: Chatgpt Users, Privacy

  45. #768 · 1 report

    ChatGPT Reportedly Implicated in Samsung Data Leak of Source Code and Meeting Notes AIID ↗

    Samsung engineers are reported to have inadvertently leaked sensitive company data sometime in March 2023, including source code and internal meeting notes, by using ChatGPT to assist with tasks. ChatGPT allegedly retained the inputted data, leading to a purported breach of confidentiality.

    Deployer: Samsung Engineers, Samsung · Developer: Openai, Large Language Model Developers · Harmed: Samsung, Privacy

  46. #997 · 4 reports

    Meta and OpenAI Accused of Using LibGen’s Pirated Books to Train AI Models AIID ↗

    Court records reveal that Meta employees allegedly discussed pirating books to train LLaMA 3, citing cost and speed concerns with licensing. Internal messages suggest Meta accessed LibGen, a repository of over 7.5 million pirated books, with apparent approval from Mark Zuckerberg. Employees allegedly took steps to obscure the dataset’s origins. OpenAI has also been implicated in using LibGen.

    Deployer: Openai, Meta · Developer: Openai, Meta · Harmed: Writers, Publishers, Journalists, Authors, Academic Researchers

  47. #430 · 21 reports

    Lawyers Denied Entry to Performance Venue by Facial Recognition AIID ↗

    Lawyers were barred from entry to Madison Square Garden after a facial recognition system matched them as employed by a law firm currently engaged in litigation with the venue.

    Deployer: Madison Square Garden Entertainment · Developer: Unknown · Harmed: Kelly Conlon, Alexis Majano

  48. #421 · 12 reports

    Stable Diffusion Allegedly Used Artists' Works without Permission for AI Training AIID ↗

    Text-to-image model Stable Diffusion was reportedly using artists' original works without permission for its AI training.

    Deployer: Stability Ai, Lensa Ai, Midjourney, Deviantart · Developer: Stability Ai, Runway, Lensa Ai, Laion, Eleutherai, Compvis Lmu · Harmed: Digital Artists, Artists Publishing On Social Media, Artists

  49. #451 · 5 reports

    Stable Diffusion's Training Data Contained Copyrighted Images AIID ↗

    Stability AI reportedly scraped copyrighted images by Getty Images to be used as training data for Stable Diffusion model.

    Deployer: Stability Ai · Developer: Runway, Laion, Eleutherai, Compvis Lmu, Stability Ai · Harmed: Getty Images, Getty Images Contributors

  50. #391 · 2 reports

    Facial Recognition Trial by UK Southern Co-op Alleged as Unlawful AIID ↗

    Southern Co-op's use of facial recognition reportedly to curb violent crime in UK supermarkets was alleged by civil society and privacy groups as "unlawful" and "complete" invasion of privacy.

    Deployer: Southern Co Op · Developer: Hikvision · Harmed: Souther Co Op Customers

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.