{"attribution":{"source":"AI Incident Database (Responsible AI Collaborative)","license":"CC BY-SA 4.0","license_url":"https://creativecommons.org/licenses/by-sa/4.0/","citation":"McGregor, S. (2021). Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. Proceedings of the AAAI Conference on Artificial Intelligence (IAAI-21).","snapshot_date":"2026-09-07"},"exported_at":"2026-09-12"}
{"rows":[{"incident_id":1507,"occurred_on":"2026-05-30","title":"COEMPT Quality Assurance Engineers Allegedly Violated Indian CBSE Student Data Privacy Rights by Processing It with Google Gemini","description":"The Hindu reported that vulnerabilities in the OnMark exam-marking portal used by India's Central Board of Secondary Education (CBSE) allegedly exposed sensitive student data, including answer-sheet images. Ethical hacker Nisarga Adhikary also alleged that COEMPT Eduteck quality-assurance scripts processed students' personal information through Google Gemini. CBSE said the vulnerabilities had been contained.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Government Of India, Coempt Eduteck, Central Board Of Secondary Education"],"developers":["Large Language Model Developers, Google"],"harmed":["Students In India, Students, Privacy, Minors In India, Minors, Educational Communities, Central Board Of Secondary Education Students"],"report_count":1},{"incident_id":1497,"occurred_on":"2026-05-13","title":"Hidden Prompt Injection in Brazilian Labor-Court Petition Reportedly Tried to Manipulate Galileu","description":"Galileu, an AI tool used by Brazil's labor courts, reportedly detected hidden instructions embedded in an initial petition before the 3rd Labor Court of Parauapebas. The text allegedly told the AI to contest the petition superficially and not challenge documents. Galileu reportedly alerted the judge and blocked the hidden content from processing; the judge then reviewed the material before imposing any procedural consequences.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Conselho Superior Da Justica Do Trabalho, Tribunal Regional Do Trabalho Da 8A Regiao, 3A Vara Do Trabalho De Parauapebas, Judicial System Of Brazil, Brazilian Labor Courts"],"developers":["Tribunal Regional Do Trabalho Da 4A Regiao, Conselho Superior Da Justica Do Trabalho"],"harmed":["Epistemic Integrity, Judicial Integrity, Judicial System Of Brazil, Brazilian Labor Courts, Defendants In Brazilian Labor Cases"],"report_count":1},{"incident_id":1471,"occurred_on":"2026-03-18","title":"Meta Internal AI Agent Reportedly Gave Advice That Allegedly Exposed Sensitive Data to Unauthorized Employees","description":"Reporting alleged that a Meta internal AI agent, purportedly similar to OpenClaw, posted inaccurate technical advice to an internal forum without approval. An employee reportedly followed the advice, allegedly causing an SEV1 incident in which sensitive company and user data became accessible to unauthorized employees for nearly two hours.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Meta"],"developers":["Meta"],"harmed":["Privacy, Meta Users, Meta"],"report_count":2},{"incident_id":1412,"occurred_on":"2026-02-28","title":"CodeWall's Autonomous Agent Reportedly Obtained Unauthorized Access to McKinsey's Lilli AI Platform Database","description":"CodeWall reported that its autonomous agent exploited vulnerabilities in McKinsey's Lilli AI platform and obtained unauthorized read and write access to production systems, allegedly exposing internal chat messages, files, user accounts, and prompts. McKinsey confirmed the vulnerability and said it fixed the issue within hours, but said it found no evidence that client data or client confidential information were accessed.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Mckinsey And Company, Codewall"],"developers":["Mckinsey And Company, Codewall"],"harmed":["Privacy, Mckinsey And Company Employees, Mckinsey And Company Consultants, Mckinsey And Company, Lilli Users"],"report_count":1},{"incident_id":1418,"occurred_on":"2026-02-27","title":"Meta AI Smart Glasses Reportedly Routed Intimate Imagery to Reviewers at Kenyan Contractor Sama Before Meta Ended Contract","description":"Meta AI smart glasses reportedly sent media and transcripts from AI interactions to Sama contractors in Kenya for human review. Workers said they saw nudity, bathroom use, sex, bank cards, and other private activity, sometimes involving people unaware they were recorded or faces left visible despite filtering. The reports prompted lawsuits and regulatory inquiries before Meta paused the work and ended its Sama contract, affecting 1,108 workers.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Sama, Meta"],"developers":["Meta, Ai Enabled Smart Glasses Developers"],"harmed":["Meta Users, Meta Ai Smart Glasses Users, People Recorded By Meta Ai Smart Glasses, Bystanders Recorded By Smart Glasses, Sama Data Annotators In Kenya, Data Annotators, Sama Workers Affected By Meta Contract Termination, Sama, Privacy"],"report_count":16},{"incident_id":1395,"occurred_on":"2026-02-23","title":"Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale","description":"Anthropic said it identified large-scale campaigns that used fraudulent accounts and proxy services to generate high volumes of Claude interactions to extract model capabilities for competitor training (\"distillation\"). Anthropic attributed the activity to DeepSeek, Moonshot, and MiniMax and said it involved millions of exchanges across thousands of accounts, violating its terms and access restrictions. Anthropic described detection measures, account controls, and indicator-sharing in response.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Deepseek, Moonshot Ai, Minimax, Proxy Reseller Services"],"developers":["Anthropic"],"harmed":["Anthropic, Claude Users, Anthropic Customers, National Security And Intelligence Stakeholders"],"report_count":4},{"incident_id":1443,"occurred_on":"2026-02-19","title":"Grok Reportedly Disclosed Adult Performer Siri Dahl's Legal Name and Birthdate, Allegedly Contributing to Doxxing and Harassment","description":"Grok is reported to have publicly provided adult performer Siri Dahl's legal name and birthdate without being asked for that information. Dahl reportedly said she had worked to keep those details private and that, after the disclosure, impersonation accounts and reposts of stolen content using her legal name purportedly appeared online.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Xai"],"developers":["Xai"],"harmed":["Victims Of Doxxing, Siri Dahl, Privacy"],"report_count":1},{"incident_id":1389,"occurred_on":"2026-02-08","title":"DJI Romo Cloud Authorization Bug Reportedly Exposed Camera, Microphone, and Home-Mapping Data From Nearly 7,000 Robot Vacuums","description":"A software engineer reportedly used an AI coding assistant while attempting to reverse-engineer his DJI robot vacuum so he could control it with a video game controller. In the course of that work, he reportedly said he discovered that credentials used to communicate with DJI's cloud servers could also grant access to data associated with nearly 7,000 other vacuums across 24 countries, including live camera feeds, microphone audio, maps, and status information.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Dji"],"developers":["Dji"],"harmed":["Dji Romo Owners, Privacy"],"report_count":1},{"incident_id":1364,"occurred_on":"2026-01-31","title":"Moltbook Database Exposure Allegedly Revealed Users' Private Communications and API Authentication Tokens","description":"Wiz researchers reported accessing an exposed Moltbook database in under three minutes, allegedly obtaining ~35,000 email addresses, thousands of private DMs, and ~1.5 million API authentication tokens. The exposure was described as enabling read/write access and potential impersonation or manipulation of \"AI agent\" accounts. Wiz said it disclosed the issue to Moltbook, which reportedly secured the database within hours and deleted accessed data.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Moltbook Platform Operators, Moltbook"],"developers":["Moltbook"],"harmed":["Moltbook Users, Moltbook Account Holders, Privacy"],"report_count":1},{"incident_id":1386,"occurred_on":"2026-01-23","title":"NPR Host David Greene Alleged Google's NotebookLM Replicated His Voice Without Consent, Prompting Lawsuit","description":"NPR's David Greene reportedly sued Google LLC and Alphabet in Santa Clara County, alleging NotebookLM's Audio Overviews uses a synthetic male voice that purportedly mimics his cadence and delivery without consent or compensation. The complaint reportedly cited an independent voice-recognition analysis reporting 53–60% confidence his voice trained the model. Google reportedly called the allegations baseless and said the voice is based on a paid actor.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Other","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Google"],"developers":["Google"],"harmed":["Voice Actors, David Greene"],"report_count":1},{"incident_id":1362,"occurred_on":"2026-01-10","title":"Border Patrol Agent Allegedly Claimed Facial Recognition Identified Minneapolis ICE Observer and Global Entry Was Reportedly Revoked Three Days Later","description":"On 01/10/2026 near Minneapolis, Minnesota, legal observer Nicole Cleland reportedly stated that a CBP Border Patrol agent stopped her vehicle, addressed her by name, and claimed agents used facial recognition to identify her while recording on body cam. She reportedly had her Global Entry and TSA PreCheck revoked on 01/13/2026, which she alleged was retaliatory intimidation, causing travel burden and chilling effects.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Unnamed United States Border Patrol agent","United States Immigration and Customs Enforcement","United States Department of Homeland Security","United States Customs and Border Protection","United States Border Patrol","National security and intelligence stakeholders","Law enforcement","Facial recognition system deployers"],"developers":["NEC","Facial recognition system developers"],"harmed":["Privacy","Nicole Cleland","Legal observers","Immigration enforcement observers","General public of the United States","General public","Biometric data subjects"],"report_count":1},{"incident_id":1298,"occurred_on":"2025-12-04","title":"Perplexity AI Reportedly Accused in Federal Lawsuit of Purported Copyright Infringement and False Attribution of Chicago Tribune Content","description":"The Chicago Tribune filed a federal lawsuit alleging that Perplexity AI unlawfully reproduced and paraphrased its copyrighted journalism in generative chatbot and search outputs. The complaint claims the AI system produced substitutive answers that bypassed links to the Tribune's website, diverted revenue, and at times hallucinated inaccurate information falsely attributed to the newspaper.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Perplexity Ai"],"developers":["Perplexity Ai"],"harmed":["Chicago Tribune, Journalistic Integrity, Epistemic Integrity"],"report_count":4},{"incident_id":1284,"occurred_on":"2025-11-19","title":"Secret Desires AI Platform Reportedly Exposed Nearly Two Million Sensitive Images in Cloud Storage Leak","description":"The erotic AI chatbot and image-generation platform Secret Desires reportedly left nearly two million sensitive images and videos publicly exposed in misconfigured cloud storage. The leaked files reportedly included personal photos, workplace and university information, and explicit AI-generated deepfakes of women and girls. The content reportedly became inaccessible shortly after journalists contacted the platform.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Secret Desires"],"developers":["Secret Desires","Chatbot developers"],"harmed":["Women and girls","Women","People depicted in Secret Desires deepfakes","General public","Epistemic integrity"],"report_count":2},{"incident_id":1278,"occurred_on":"2025-11-11","title":"ChatGPT Reportedly Found to Reproduce Protected German Lyrics in Copyright Case","description":"A Munich regional court ruled that ChatGPT reportedly reproduced protected German song lyrics and that OpenAI's models were trained on copyrighted texts, including works by musician Herbert Grönemeyer, without authorization. The court reportedly found both memorization of nine songs and lyric output to infringe exploitation rights. OpenAI disputes the ruling and may appeal. Damages were ordered, with implications for AI training on copyrighted works.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai"],"developers":["Openai"],"harmed":["Songwriters, Publishers, Musicians, Herbert Gronemeyer, German Songwriters, German Publishers, German Musicians, German Artists, Gema, Artists"],"report_count":4},{"incident_id":1210,"occurred_on":"2025-08-21","title":"Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration","description":"Malicious versions of the popular Nx monorepo tool and plugins were reportedly published to npm after attackers compromised its CI workflow. The malware's postinstall script reportedly harvested credentials and exfiltrated data, reportedly weaponizing local AI coding agents such as Claude Code, Gemini, and Amazon q. By invoking unsafe flags, it allegedly coerced the tools into scanning developer machines for sensitive files, marking one of the first known AI-assisted supply chain attacks.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Malicious Actors Compromising Nx'S Cicd Pipeline And Publishing Tainted Npm Packages"],"developers":["Anthropic, Google, Amazon"],"harmed":["Nx Users And Organizations Installing Compromised Npm Packages"],"report_count":2},{"incident_id":1176,"occurred_on":"2025-08-01","title":"Microsoft's Windows Recall Allegedly Stores Passwords and Social Security Numbers in Preview Mode","description":"Microsoft's Windows Recall, an AI-powered screenshot and retrieval tool for Copilot+ PCs, was allegedly still capturing sensitive information such as passwords, Social Security numbers, and bank details despite a built-in \"filter sensitive information\" feature. Independent testing reportedly found the filter failed in multiple cases. Microsoft reportedly classified Recall as a preview feature and said improvements were in progress.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Microsoft"],"developers":["Microsoft"],"harmed":["Windows Recall users","Windows 11 users","Privacy","Microsoft users"],"report_count":2},{"incident_id":1213,"occurred_on":"2025-08-01","title":"Gaggle AI Monitoring at Lawrence, Kansas High School Reportedly Misflags Student Content and Blocks Emails","description":"In Lawrence, Kansas, students allege the Gaggle Safety Management AI wrongly flagged benign schoolwork, including art photos and casual messages, as child pornography or threats. The system reportedly deleted content, blocked an email records request, and led to questioning of students. Critics cite chilling effects and privacy risks. A lawsuit filed in August 2025 challenges the district's use of Gaggle as unconstitutional surveillance. Gaggle reportedly denies compromising privacy.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Lawrence Public Schools (Usd 497)"],"developers":["Gaggle"],"harmed":["Students, Lawrence Public Schools (Usd 497) Students, Educational Communities, Privacy"],"report_count":1},{"incident_id":1186,"occurred_on":"2025-07-31","title":"Reported Public Exposure of Over 100,000 LLM Conversations via Share Links Indexed by Search Engines and Archived","description":"Across 2024 and 2025, the share features in multiple LLM platforms, including ChatGPT, Claude, Copilot, Qwen, Mistral, and Grok, allegedly exposed user conversations marked \"discoverable\" to search engines and archiving services. Over 100,000 chats were reportedly indexed and later scraped, purportedly revealing API keys, access tokens, personal identifiers, and sensitive business data.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Xai, Openai, Mistral, Microsoft, Anthropic, Alibaba"],"developers":["Xai, Openai, Mistral, Microsoft, Anthropic, Alibaba"],"harmed":["Users Of Qwen, Users Of Mistral, Users Of Grok, Users Of Copilot, Users Of Claude, Privacy, General Public, Chatgpt Users"],"report_count":5},{"incident_id":1171,"occurred_on":"2025-07-25","title":"Reported Hack of Tea Dating App Compromises Data from Purportedly AI-Supported Identity and Image Checks","description":"In July 2025, the Tea dating advice app, which purportedly uses AI-assisted tools for user verification and reverse image search, reportedly suffered a breach of a legacy storage system. Hackers allegedly accessed about 72,000 images, including selfies, photo IDs, and other content, which were purportedly circulated on 4chan. The incident reportedly exposed sensitive data of users who signed up before February 2024.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Other","intent":"Other","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Tea Dating Advice"],"developers":["Tea Dating Advice"],"harmed":["Women and girls","Women","Users of the Tea app","Users of Tea Dating Advice","Privacy","General public"],"report_count":2},{"incident_id":1158,"occurred_on":"2025-07-17","title":"Alleged Malicious Wiping Command Found in Amazon Q AI Assistant","description":"A reported compromise of Amazon's AI coding assistant \"Q\" allegedly involved the insertion of commands that, if executed, could have wiped local files and potentially affected cloud resources. The altered code was reportedly incorporated into a public release before being detected and removed.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Aws, Amazon Web Services, Amazon"],"developers":["Aws, Amazon Web Services, Amazon"],"harmed":["Aws Toolkit Users, Amazon Web Services (Aws) Customers, Amazon Q Users"],"report_count":4},{"incident_id":1360,"occurred_on":"2025-07-15","title":"CISA Acting Director Reportedly Uploaded Sensitive Government Documents to Public ChatGPT Instance","description":"Madhu Gottumukkala, acting director of the Cybersecurity and Infrastructure Security Agency (CISA), reportedly uploaded government contracting documents marked \"for official use only\" into a public version of ChatGPT. The uploads reportedly triggered automated cybersecurity alerts and prompted a Department of Homeland Security review to assess potential exposure of sensitive information.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Madhu Gottumukkala"],"developers":["Openai"],"harmed":["United States Department Of Homeland Security, Cybersecurity And Infrastructure Security Agency, United States Government, National Security And Intelligence Stakeholders"],"report_count":1},{"incident_id":1356,"occurred_on":"2025-07-09","title":"Urban VPN Proxy Browser Extension Reportedly Harvested and Sold Private AI Chatbot Conversations via Silent Update","description":"Security researchers reported that the Urban VPN Proxy browser extension introduced AI conversation–harvesting functionality in version 5.5.0, released July 9, 2025. The extension allegedly intercepted and exfiltrated private conversations from AI platforms including ChatGPT, Claude, Gemini, Grok, and others without a user-facing opt-out. The data, including sensitive personal and financial information, was reportedly shared with affiliated data brokers for commercial analytics.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Urban Cyber Security"],"developers":["Urban Cyber Security, Biscience"],"harmed":["Urban Vpn Proxy Users, Privacy, Perplexity Users, Meta Ai Users, Grok Users, General Public, Gemini Users, Deepseek Users, Copilot Users, Claude Users, Chatgpt Users, Chatbot Users, Browser Extension Users, Chatbot Developers, Large Language Model Developers"],"report_count":3},{"incident_id":1218,"occurred_on":"2025-07-04","title":"Microsoft 365 Copilot Vulnerability Allegedly Allowed File Access Without Audit Log Entry","description":"A vulnerability in Microsoft 365 Copilot reportedly allowed users to access and summarize files without generating audit log entries, allegedly undermining traceability and compliance. Security researcher Zack Korman disclosed the issue to Microsoft, which reportedly classified it as \"important\" and fixed it on August 17, 2025, but reportedly chose not to notify customers or assign a CVE.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Microsoft"],"developers":["Microsoft"],"harmed":["Organizations Relying On Audit Logs For Compliance And Security, Microsoft 365 Copilot Enterprise Customers"],"report_count":1},{"incident_id":1179,"occurred_on":"2025-06-30","title":"McDonald's McHire AI Recruitment Platform Reportedly Exposed Data of 64 Million Applicants via Default Login and API Vulnerability","description":"Researchers Ian Carroll and Sam Curry reported that McDonald's AI-powered hiring tool, McHire (using Paradox.ai's \"Olivia\" chatbot), could purportedly be accessed via default admin credentials and an insecure direct object reference in an internal API. The flaws allegedly allowed viewing of applicants' personally identifiable information and chat histories. McDonald's and Paradox reportedly patched the issues within a day of disclosure; Paradox stated only five records were accessed.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Paradox.Ai, Mcdonald'S"],"developers":["Paradox.Ai, Mcdonald'S"],"harmed":["Privacy, Mcdonald'S Applicants, Job Applicants"],"report_count":2},{"incident_id":1081,"occurred_on":"2025-05-27","title":"Voice Actor Alleges Unconsented Use of AI-Generated Voice on ScotRail Trains","description":"Scottish voice actor Gayanne Potter alleges her voice was used without proper consent in ScotRail's AI train announcements. She claims she had agreed to limited use of her voice data by ReadSpeaker but was not informed it would be used in a synthetic voice system called \"Iona.\" ScotRail continues to use the voice, stating the dispute is between Potter and ReadSpeaker. ","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Scotrail"],"developers":["Readspeaker"],"harmed":["Gayanne Potter, Voiceover Artists, Individuals Affected By Unauthorized Biometric Data Use"],"report_count":6},{"incident_id":1075,"occurred_on":"2025-05-19","title":"New Orleans Police Reportedly Used Real-Time Facial Recognition Alerts Supplied by Project NOLA Despite Local Ordinance","description":"New Orleans police reportedly received real-time facial recognition alerts from a privately operated surveillance network run by Project NOLA, reportedly leading to dozens of arrests. This purported use of AI surveillance appears to conflict with a 2022 city ordinance that restricts facial recognition to specific post-incident investigations. Police are alleged to have not consistently disclosed the technology's use.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Project NOLA","New Orleans Police Department","Law enforcement","Facial recognition system deployers"],"developers":["Facial recognition system developers","Dahua Technology"],"harmed":["Residents subject to live surveillance in New Orleans","Privacy","People misidentified by facial recognition systems","General public of the United States","General public of New Orleans","General public","Biometric data subjects","Arrested individuals in New Orleans"],"report_count":15},{"incident_id":1070,"occurred_on":"2025-05-09","title":"Serviceaide AI Platform Implicated in Health Data Exposure Affecting 483,000 Catholic Health Patients","description":"An AI-linked platform operated by Serviceaide exposed sensitive health data from Catholic Health, affecting 483,000 patients. The breach stemmed from a misconfigured Elasticsearch database used in Serviceaide’s agentic AI infrastructure. Exposed information included medical records, insurance details, and login credentials. While no misuse has been confirmed, the nature of the data has prompted regulatory scrutiny and legal investigations.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Serviceaide"],"developers":["Serviceaide"],"harmed":["Privacy, Patients Of Catholic Health, Patients, Catholic Health"],"report_count":14},{"incident_id":1101,"occurred_on":"2025-04-29","title":"Meta AI App Reportedly Publishes Personal Chats Without Users Fully Realizing","description":"Meta launched a stand-alone AI app with a \"Discover\" feed allowing users to share conversations with its chatbot. Multiple reports indicate that some users may have inadvertently published highly personal interactions, including audio recordings, medical questions, legal concerns, and intimate relationship disclosures. While Meta states that sharing is opt-in, the feature's design and labeling may have led to user confusion about what would be publicly visible.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Meta"],"developers":["Meta","Large language model developers","Chatbot developers"],"harmed":["Privacy","Meta users","Meta AI users","Chatbot users","Biometric data subjects"],"report_count":3},{"incident_id":1020,"occurred_on":"2025-04-11","title":"Reportedly Unsafe Deployment of Llama.cpp Reveals Interactive AI-Generated CSAM Roleplay Prompts","description":"A study by UpGuard reports that misconfigured llama.cpp servers publicly exposed user prompts, including hundreds of interactive roleplay scenarios. Some prompts explicitly described fictional sexual abuse of children aged 7–12. While no real children were involved, the findings demonstrate how open-source LLMs can be exploited to generate AI-enabled child sexual abuse material (CSAM).","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Users Of Llama.Cpp Servers"],"developers":["Meta, Users Of Llama.Cpp Servers"],"harmed":["General Public, Users Of Llama.Cpp Servers"],"report_count":2},{"incident_id":1010,"occurred_on":"2025-03-31","title":"GenNomis AI Database Reportedly Exposes Nearly 100,000 Deepfake and Nudify Images in Public Breach","description":"In March 2025, cybersecurity researcher Jeremiah Fowler discovered an unprotected database linked to GenNomis by AI-NOMIS, a South Korean company offering face-swapping and \"nudify\" AI services. The exposed 47.8GB dataset included nearly 100,000 files. Many depicted explicit deepfake images, some involving minors or celebrities. No personal data was found, but the breach was a serious failure in data security and consent safeguards in AI image-generation platforms.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Gennomis By Ai Nomis, Gennomis"],"developers":["Gennomis By Ai Nomis, Ai Nomis"],"harmed":["Public Figures And Celebrities Depicted In Explicit Ai Images, Minors, Individuals Whose Likenesses Were Used Without Consent, General Public, Privacy, Epistemic Integrity"],"report_count":2},{"incident_id":1003,"occurred_on":"2025-03-18","title":"Alleged Fraudulent Prompts via AIXBT Dashboard Led Purported AI Trading Agent to Transfer 55.5 ETH from Simulacrum Wallet","description":"A reported hacker attack allegedly compromised the autonomous AI crypto bot AIXBT, purportedly resulting in the theft of 55.5 ETH (approximately $106,200). The attacker is reported to have infiltrated the secure dashboard of the AIXBT autonomous system at 2:00 AM UTC on March 18, 2025, and allegedly queued two fraudulent prompts that instructed the AI agent to transfer funds from its simulacrum wallet.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["0Xhungusman"],"developers":["Rxbt"],"harmed":["Aixbt Users, Aixbt System, Aixbt Investors"],"report_count":1},{"incident_id":1228,"occurred_on":"2025-03-12","title":"Alleged ChatGPT Misuse by Contractor Leads to Reported Data Exposure in New South Wales Resilient Homes Program","description":"A former contractor of the New South Wales Reconstruction Authority reportedly uploaded a spreadsheet containing personal and health information of Resilient Homes Program applicants to ChatGPT during a three-day period in March 2025. Up to 3,000 people may have reportedly been affected.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai"],"developers":["Openai"],"harmed":["Resilient Homes Program Applicants, Resilient Homes Program, Government Of New South Wales, General Public Of New South Wales, General Public Of Australia, General Public, Privacy"],"report_count":2},{"incident_id":956,"occurred_on":"2025-02-28","title":"Alleged Inclusion of 12,000 Live API Keys in LLM Training Data Reportedly Poses Security Risks","description":"A dataset used to train large language models allegedly contained 12,000 live API keys and authentication credentials. Some of these were reportedly still active and allowed unauthorized access. Truffle Security found these secrets in a December 2024 Common Crawl archive, which spans 250 billion web pages. The affected credentials could have been exploited for unauthorized data access, service disruptions, financial fraud, and a variety of other malicious uses.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Pre-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Microsoft, Openai, Common Crawl, Microsoft Azure Openai Service"],"developers":["Common Crawl, Openai, Microsoft"],"harmed":["Aws, Slack, Mailchimp, Microsoft, Google, Intel, Huawei, Paypal, Ibm, Tencent"],"report_count":1},{"incident_id":1174,"occurred_on":"2025-02-26","title":"Microsoft Copilot Reportedly Able to Access Cached Data from Since-Private GitHub Repositories","description":"Lasso Security reported that Microsoft Copilot could return content from GitHub repositories that had been public briefly but later set to private or deleted. Lasso attributed this to Bing's caching system, which stored \"zombie data\" from over 20,000 repositories. The cached content allegedly included sensitive information such as access keys, tokens, and internal packages. Microsoft reportedly classified the issue as low severity and applied only partial mitigations.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Microsoft"],"developers":["Microsoft"],"harmed":["Github Users, Github Repositories, Github, Privacy"],"report_count":2},{"incident_id":1069,"occurred_on":"2025-01-31","title":"Purported Graphite Spyware Linked to Paragon Solutions Allegedly Deployed Against Journalists and Civil Society Workers","description":"Researchers at Citizen Lab and Censys reportedly identified spyware infections involving Graphite, a tool attributed to Israeli firm Paragon Solutions. The spyware was allegedly deployed against civil society actors, including journalists and aid workers, through a zero-click WhatsApp exploit. WhatsApp notified over 90 targeted individuals. Evidence reportedly suggests deployments in multiple democratic countries.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["York Regional Police Service (Ontario, Canada)","Unidentified law enforcement or intelligence entity (Singapore)","Unidentified law enforcement or intelligence entity (Israel)","Unidentified law enforcement or intelligence entity (Denmark)","Unidentified law enforcement or intelligence entity (Cyprus)","Unidentified law enforcement or intelligence entity (Australia)","Peel Regional Police (Ontario, Canada)","Ontario Provincial Police"],"developers":["REDLattice","Paragon Solutions"],"harmed":["Refugees in Libya","Privacy","National security and intelligence stakeholders","Mediterranea Saving Humans","Luca Casarini","Journalists","Humanitarian workers","Giuseppe \"Beppe\" Caccia"],"report_count":33},{"incident_id":1172,"occurred_on":"2024-12-26","title":"Meta AI Bug in Deployed Service Reportedly Allowed Potential Access to Other Users' Prompts and Responses","description":"A security researcher reported a vulnerability in Meta AI's deployed chatbot service that, under certain conditions, could allow an unauthorized user to view another user's prompts and AI-generated responses. The flaw reportedly involved guessable prompt IDs and insufficient server-side authorization checks. Meta reportedly fixed the issue in January 2025 and found no evidence of malicious exploitation, awarding the researcher a bug bounty.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Meta"],"developers":["Meta","Large language model developers","Chatbot developers"],"harmed":["Privacy","Meta users","Meta AI users","General public","Biometric data subjects"],"report_count":2},{"incident_id":906,"occurred_on":"2024-10-08","title":"Alleged AI-Powered Call Center Breach Exposes Over 10 Million Conversations in the Middle East","description":"An AI-powered call center platform in the Middle East reportedly experienced a significant data breach, allegedly exposing over 10 million conversations between consumers, operators, and AI agents. Attackers allegedly accessed the platform’s management dashboard, stealing sensitive data, including national ID documents. The breach poses reported risks such as phishing, identity theft, and social engineering attacks. The stolen data was reportedly listed for sale on the dark web.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Cybercriminals"],"developers":["Unnamed Ai Call Center Platform Provider"],"harmed":["Privacy, Enterprise Clients, End Users Of Undisclosed Middle Eastern Ai Powered Cloud Call Center Platform"],"report_count":3},{"incident_id":814,"occurred_on":"2024-10-02","title":"AI Avatar of Murder Victim Created Without Consent on Character.ai Platform","description":"A user on the Character.ai platform created an unauthorized AI avatar of Jennifer Ann Crecente, a murder victim from 2006, without her family's consent. The avatar was made publicly available, violating Character.ai's policy against impersonation. After the incident surfaced, Character.ai removed the avatar, acknowledging a policy violation. ","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Other","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Character.Ai"],"developers":["Character.Ai"],"harmed":["Jennifer Ann Crecente, Drew Crecente, Crecente Family, Brian Crecente"],"report_count":9},{"incident_id":811,"occurred_on":"2024-10-02","title":"AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions","description":"AI-powered meeting assistants, such as Otter.ai's OtterPilot and Zoom's AI Companion, have reportedly shared sensitive and private conversations beyond the intended audience. These tools, which are set to automatically record and distribute meeting transcripts, allegedly sent confidential discussions after participants had left the meeting, the consequences of which led to unintended exposure of proprietary information and privacy breaches.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Unnamed Venture Capital Investors, Organizations, Employers, Employees, Companies, Alex Bilzerian"],"developers":["Zoom, Otter.Ai, Ai Transcription Technology Developers"],"harmed":["Unnamed Venture Capital Investors, Privacy, Organizations, Employers, Employees, Companies, Alex Bilzerian"],"report_count":6},{"incident_id":807,"occurred_on":"2024-09-25","title":"ChatGPT Reportedly Introduces Errors in Critical Child Protection Court Report","description":"A child protection worker in Victoria, Australia reportedly used ChatGPT to draft a report submitted to the Children's Court. The purportedly AI-generated report contained inaccuracies and downplayed risks to the child, allegedly resulting in a privacy breach when sensitive information was shared with OpenAI. ","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Government Of Victoria, Employee Of Department Of Families Fairness And Housing, Department Of Families Fairness And Housing"],"developers":["Openai"],"harmed":["Unnamed Family Of Child, Unnamed Child"],"report_count":9},{"incident_id":781,"occurred_on":"2024-09-03","title":"Clearview AI Reportedly Faces $33.7 Million Fine for Violating GDPR with Biometric Data Harvesting","description":"Clearview AI was reportedly fined $33.7 million by the Dutch data protection authority for allegedly creating an illegal facial recognition database by scraping billions of images from the Internet without consent. The company allegedly used AI to convert these images into biometric data and sold the service to law enforcement. This act was reportedly in violation of privacy laws and the GDPR.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Clearview Ai"],"developers":["Clearview Ai, Facial Recognition System Developers"],"harmed":["General Public, General Public Of The Netherlands, Privacy, Biometric Data Subjects"],"report_count":2},{"incident_id":773,"occurred_on":"2024-08-20","title":"Chatbot in Workplace Training at Bunbury Prison Reveals Real Names in Sexual Harassment Case","description":"During workplace training at Bunbury Prison in Western Australia, a trainer used Microsoft's Copilot AI chatbot to generate case study scenarios. The chatbot produced a scenario that included the real name of a former employee involved in a sexual harassment case, revealing sensitive information.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Western Australia Department of Justice","Charlotte Ingham"],"developers":["Microsoft","Large language model developers","Chatbot developers"],"harmed":["Western Australia Department of Justice senior staff members","Western Australia Department of Justice","Privacy","Bronwyn Hendry"],"report_count":1},{"incident_id":743,"occurred_on":"2024-07-16","title":"Gemini AI Allegedly Reads Google Drive Files Without Explicit User Consent","description":"Kevin Bankston, a privacy activist, claims that Google's Gemini AI scans private Google Drive PDFs without explicit user consent. Bankston reports that after using Gemini on one document, the AI continues to access similar files automatically. Google disputes these claims, stating that Gemini requires proactive user activation and operates within privacy-preserving settings.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Google, Gemini"],"developers":["Google, Large Language Model Developers"],"harmed":["Kevin Bankston, Google Users, Google Drive Users, Privacy"],"report_count":1},{"incident_id":950,"occurred_on":"2024-07-11","title":"NullBulge's AI-Powered Malware Allegedly Compromises Disney Employee and Internal Data","description":"A Disney employee, Matthew Van Andel, reportedly downloaded AI-powered malware allegedly developed by the cybercriminal group NullBulge, resulting in a major cybersecurity breach. Hackers purportedly accessed Disney's Slack system, exposing 44 million internal messages, employee and customer data, and financial records. NullBulge also reportedly leaked Van Andel’s personal financial information, leading to identity theft and his eventual termination.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Nullbulge"],"developers":["Nullbulge"],"harmed":["Matthew Van Andel, Disney Employees, Disney"],"report_count":2},{"incident_id":757,"occurred_on":"2024-07-01","title":"OpenAI's ChatGPT Mac App Stored User Data in Unencrypted Text Files","description":"OpenAI's ChatGPT macOS app stored user conversations in plain text. If accessed by a malicious actor, these conversations could have been easily read. The critical security flaw was demonstrated by a third party and ultimately resolved after OpenAI released an update to encrypt the stored data.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai"],"developers":["Openai"],"harmed":["Chatgpt"],"report_count":1},{"incident_id":733,"occurred_on":"2024-06-09","title":"Auto Insurers Allegedly Are Surreptitiously Collecting and Scoring Driver Data","description":"The insurance industry allegedly uses AI and telematics to score drivers based on behaviors tracked by automakers and apps like Life360. Data, often collected without clear consent, may affect insurance rates and raises privacy concerns. Consumers are largely unaware of this surveillance, leading to potential misuse and discrimination based on driving habits or socioeconomic factors.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["USAA","Toyota","Progressive","MyRadar","Life360","General Motors","GEICO","CSAA"],"developers":["MyRadar","Life360","Connected Analytic Services","Arity"],"harmed":["Privacy-conscious individuals","Privacy","People with poor credit scores","MyRadar users","Lower-income workers","Life360 users","Economically vulnerable people","Drivers unaware of data collection"],"report_count":2},{"incident_id":842,"occurred_on":"2024-05-24","title":"Reportedly Hacked AI-Powered Robot Vacuums Allegedly Used for Surveillance and Harassment","description":"Hackers reportedly exploited a vulnerability in Ecovacs’s Deebot X2 robot vacuums, gaining unauthorized access to camera and microphone controls. Users reported privacy invasions and offensive language broadcasted through the devices. Although Ecovacs claimed to have resolved the security flaw, researchers suggest vulnerabilities remain that could potentially leave users exposed to surveillance and harassment through their AI-enabled devices.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Ecovacs Deebot X2, Ecovacs"],"developers":["Ecovacs"],"harmed":["Ecovacs Deebot X2 Users, Ecovacs Customers, Daniel Swenson, Privacy"],"report_count":16},{"incident_id":688,"occurred_on":"2024-05-20","title":"Scarlett Johansson Alleges OpenAI's Sky Imitates Her Voice Without Licensing","description":"OpenAI unveiled a voice assistant with a voice resembling Scarlett Johansson's, despite her refusal to license her voice. Johansson claimed the assistant, \"Sky,\" sounded \"eerily similar\" to her voice, leading her to seek legal action. OpenAI suspended Sky, asserting the voice was from a different actress.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Sky Voice Assistant, Sam Altman, Openai"],"developers":["Sam Altman, Openai"],"harmed":["Scarlett Johansson"],"report_count":14},{"incident_id":728,"occurred_on":"2024-05-16","title":"AI Firm Lovo Reportedly Accused of Illegally Replicating Voice Actors' Voices","description":"Two voice actors, Paul Skye Lehrman and Linnea Sage, are reportedly suing AI start-up Lovo for allegedly creating and promoting unauthorized clones of their voices. Lovo's synthetic voices were allegedly discovered in various media, including a podcast and promotional videos. The actors claim they were misled into providing voice samples, which were then allegedly used without consent, violating trademark and privacy laws. ","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Synthetic Media Creators, Lovo"],"developers":["Voice Cloning Technology Developers, Synthetic Media Generation Technology Developers, Synthetic Audio Generation Technology Developers, Lovo"],"harmed":["Voice Actors, Targets Of Fraudulent Professional Opportunities, Paul Skye Lehrman, Linnea Sage, Epistemic Integrity"],"report_count":1},{"incident_id":718,"occurred_on":"2024-04-06","title":"OpenAI, Google, and Meta Alleged to Have Overstepped Legal Boundaries for Training AI","description":"In late 2021, OpenAI and other tech giants like Google and Meta reportedly faced data shortages for training AI models. OpenAI is said to have developed a tool called Whisper to transcribe over one million hours of YouTube videos, potentially violating YouTube’s terms of service. Similarly, Google allegedly transcribed YouTube videos, risking copyright infringements. Meta reportedly explored summarizing copyrighted texts without permission and debated acquiring Simon & Schuster for data.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Pre-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai, Meta, Google"],"developers":["Openai, Meta, Google"],"harmed":["Youtube Creators, General Public, Content Creators"],"report_count":1},{"incident_id":636,"occurred_on":"2024-02-14","title":"AI Romance Apps Reportedly Compromise User Privacy for Data Harvesting","description":"AI-powered romantic chatbots, marketed for enhancing mental health, are found to exploit user privacy by harvesting sensitive personal information for data sharing and targeted ads, with inadequate security measures and consent protocols, according to research by the Mozilla Foundation.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Romantic Ai, Replika, Genesia Ai Friend And Partner, Eva Ai Chat Bot And Soulmate, Crushon.Ai, Chai"],"developers":["Romantic Ai, Replika, Genesia Ai Friend And Partner, Eva Ai Chat Bot And Soulmate, Crushon.Ai, Chai, Chatbot Developers"],"harmed":["General Public, Chatbot Users, Privacy, Replika Users, Chai Users, Romantic Ai Users, Eva Ai Users, Crushon.Ai Users, Genesia Ai Friend And Partner Users"],"report_count":5},{"incident_id":657,"occurred_on":"2024-01-30","title":"Alleged ChatGPT Account Compromise Reportedly Led to Unintended Data Exposure","description":"An alleged security breach involving ChatGPT led to the reported exposure of sensitive conversations, including login credentials and personal data, after a user account was allegedly compromised. OpenAI reportedly responded to the incident with an explanation.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Other","intent":"Other","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai"],"developers":["Openai, Large Language Model Developers"],"harmed":["Chatgpt Users, Chase Whiteside, Privacy"],"report_count":1},{"incident_id":995,"occurred_on":"2023-12-27","title":"The New York Times Reportedly Sues OpenAI and Microsoft Over Alleged Unauthorized AI Training on Its Content","description":"The New York Times alleges that OpenAI and Microsoft used millions of its articles without permission to train AI models, including ChatGPT. The lawsuit claims the companies scraped and reproduced copyrighted content without compensation, in turn undermining the Times’s business and competing with its journalism. Some AI outputs allegedly regurgitate Times articles verbatim. The lawsuit seeks damages and demands the destruction of AI models trained on its content.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai, Microsoft"],"developers":["Openai, Microsoft"],"harmed":["Writers, The New York Times, Publishers, Media Organizations, Journalists, Journalistic Integrity, Epistemic Integrity"],"report_count":2},{"incident_id":659,"occurred_on":"2023-10-07","title":"Purported Mass Facial Recognition Program in Gaza Reportedly Used by Israeli Forces to Identify Palestinians","description":"A previously undisclosed facial recognition initiative operated by Israeli military intelligence units was reportedly deployed across Gaza after the October 7, 2023 attacks. According to multiple intelligence officers, the program uses Corsight technology alongside Google Photos to identify individuals from checkpoints, crowds, and drone footage. The system has allegedly produced misidentifications, including the widely reported detention of Palestinian poet Mosab Abu Toha on November 19, 2023.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Unit 8200","Israeli military intelligence","Israeli government","Israel Defense Forces","Facial recognition system deployers"],"developers":["Unknown Israeli military integrators","Surveillance technology developers","Google Photos","Facial recognition system developers","Corsight"],"harmed":["Privacy and data rights of Gaza residents","Privacy","Palestinians traveling through Gaza checkpoints","Palestinians","National security and intelligence stakeholders","Mosab Abu Toha","General public of Gaza","General public"],"report_count":3},{"incident_id":571,"occurred_on":"2023-06-22","title":"Reported Accidental Exposure of 38TB of Data by Microsoft's AI Research Team","description":"Microsoft's AI research team reportedly accidentally exposed 38TB of sensitive data while publishing open-source training material on GitHub. The exposure allegedly included secrets, private keys, passwords, and internal Microsoft Teams messages. The team reportedly utilized Azure's Shared Access Signature (SAS) tokens for sharing, which were purportedly misconfigured, leading to the wide exposure of data.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Microsoft"],"developers":["Microsoft'S Ai Research Division"],"harmed":["Microsoft Employees, Microsoft, Privacy, Third Parties Whose Confidential Data Was Exposed"],"report_count":1},{"incident_id":552,"occurred_on":"2023-06-22","title":"Bing Chat Solved CAPTCHAs with Image Analysis Feature Despite Safeguards","description":"Microsoft was reported by a Twitter user for deploying image analysis feature capable of solving CAPTCHAs for its GPT-based chatbot despite it being safeguarded against solving them for users.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Microsoft"],"developers":["Openai, Microsoft"],"harmed":["Microsoft"],"report_count":1},{"incident_id":586,"occurred_on":"2023-05-22","title":"FTC Targets Edmodo for Unlawful Use of Children’s Data and Delegating Compliance to Schools","description":"Edmodo, an education technology provider, violated the Children's Online Privacy Protection Act Rule (COPPA Rule) by collecting and using children's personal data for advertising purposes without parental consent, according to the FTC. The company outsourced its compliance responsibilities to schools, thereby making them \"solely\" responsible for COPPA compliance without adequate disclosure. Edmodo is facing a proposed order prohibiting such practices, marking a precedent in the ed tech industry.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Edmodo"],"developers":["Edmodo"],"harmed":["Teachers, Students, Schools And Teachers Who Were Misinformed And Burdened With Coppa Compliance Responsibilities Without Adequate Disclosure, Minors, Educational Communities, Children Whose Data Was Collected And Used For Advertising, Biometric Data Subjects, Privacy"],"report_count":1},{"incident_id":584,"occurred_on":"2023-05-18","title":"Illinois Residents File Class Action Lawsuit Against Facial Recognition Technology Companies for Allegedly Violating BIPA","description":"A class action lawsuit was filed against several facial recognition technology companies for allegedly violating the Illinois Biometric Information Privacy Act (BIPA). The defendants are accused of offering a facial recognition search engine called Pimeyes, which collects images from databases across the internet and scans them into their database seemingly without consent. This action is claimed to invade the privacy of millions of Americans. The lawsuit argues that Pimeyes lacks publicly avail","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Transaction Cloud, Public Mirror, Pimeyes, Lukasz Kowalczyk, Giorgi Gobronidze, Face Recognition Solutions, Emea Robotics, Does 125, Denis Tatina, Carribex"],"developers":["Transaction Cloud, Public Mirror, Pimeyes, Lukasz Kowalczyk, Giorgi Gobronidze, Face Recognition Solutions, Emea Robotics, Does 1 25, Denis Tatina, Carribex, Surveillance Technology Developers, Facial Recognition System Developers"],"harmed":["Nicholas Clayton, Misty Mcgraw, Manuel Clayton, Illinois Residents, Amy Newton, Amanda Curry, General Public, General Public Of Illinois, Privacy, Biometric Data Subjects"],"report_count":1},{"incident_id":513,"occurred_on":"2023-03-31","title":"ChatGPT Reportedly Banned by Italian Authority Due to OpenAI's Purported Lack of Legal Basis for Data Collection and Age Verification","description":"Italy's data protection authority is reported to have temporarily limited OpenAI's processing of Italian users' data after alleging that ChatGPT lacked adequate notice and legal basis for large-scale personal data collection and processing used to train the system. The authority also cited a March 2023 data breach, possible processing of inaccurate personal data, and the absence of age-verification safeguards for children.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai"],"developers":["Openai, Large Language Model Developers, Chatbot Developers"],"harmed":["Privacy, Minors, General Public Of Italy, General Public, Minors In Italy"],"report_count":5},{"incident_id":516,"occurred_on":"2023-03-20","title":"ChatGPT Reportedly Exposed Users' Private Data Reportedly Due to Bug","description":"ChatGPT reportedly exposed titles of users' chat histories and users' private payment information to other users reportedly due to a bug, which prompted its temporary shutdown by OpenAI.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai"],"developers":["Openai, Chatbot Developers, Large Language Model Developers"],"harmed":["Chatgpt Users, Privacy"],"report_count":2},{"incident_id":523,"occurred_on":"2023-03-15","title":"Australian Journalist Able to Access Centrelink Account Using AI Audio of Own Voice","description":"A Guardian journalist was able to verify their identity and gain access to their own Centrelink self-service account using AI-generated audio of their own voice along with their customer reference number, shortly after voiceprint was deployed for ID verification.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Australian Taxation Office, Services Australia"],"developers":["Centrelink"],"harmed":["Centrelink Account Holders"],"report_count":1},{"incident_id":768,"occurred_on":"2023-03-11","title":"ChatGPT Reportedly Implicated in Samsung Data Leak of Source Code and Meeting Notes","description":"Samsung engineers are reported to have inadvertently leaked sensitive company data sometime in March 2023, including source code and internal meeting notes, by using ChatGPT to assist with tasks. ChatGPT allegedly retained the inputted data, leading to a purported breach of confidentiality.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Samsung Engineers, Samsung"],"developers":["Openai, Large Language Model Developers"],"harmed":["Samsung, Privacy"],"report_count":1},{"incident_id":997,"occurred_on":"2023-02-28","title":"Meta and OpenAI Accused of Using LibGen’s Pirated Books to Train AI Models","description":"Court records reveal that Meta employees allegedly discussed pirating books to train LLaMA 3, citing cost and speed concerns with licensing. Internal messages suggest Meta accessed LibGen, a repository of over 7.5 million pirated books, with apparent approval from Mark Zuckerberg. Employees allegedly took steps to obscure the dataset’s origins. OpenAI has also been implicated in using LibGen.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Pre-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai, Meta"],"developers":["Openai, Meta"],"harmed":["Writers, Publishers, Journalists, Authors, Academic Researchers"],"report_count":4},{"incident_id":473,"occurred_on":"2023-02-08","title":"Bing Chat's Initial Prompts Revealed by Early Testers Through Prompt Injection","description":"Early testers of Bing Chat successfully used prompt injection to reveal its built-in initial instructions, which contains a list of statements governing ChatGPT's interaction with users.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Microsoft"],"developers":["Microsoft, Openai"],"harmed":["Microsoft"],"report_count":1},{"incident_id":430,"occurred_on":"2022-12-19","title":"Lawyers Denied Entry to Performance Venue by Facial Recognition","description":"Lawyers were barred from entry to Madison Square Garden after a facial recognition system matched them as employed by a law firm currently engaged in litigation with the venue.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Madison Square Garden Entertainment"],"developers":["Unknown"],"harmed":["Kelly Conlon, Alexis Majano"],"report_count":21},{"incident_id":421,"occurred_on":"2022-11-20","title":"Stable Diffusion Allegedly Used Artists' Works without Permission for AI Training","description":"Text-to-image model Stable Diffusion was reportedly using artists' original works without permission for its AI training.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Stability Ai, Lensa Ai, Midjourney, Deviantart"],"developers":["Stability Ai, Runway, Lensa Ai, Laion, Eleutherai, Compvis Lmu"],"harmed":["Digital Artists, Artists Publishing On Social Media, Artists"],"report_count":12},{"incident_id":451,"occurred_on":"2022-10-16","title":"Stable Diffusion's Training Data Contained Copyrighted Images","description":"Stability AI reportedly scraped copyrighted images by Getty Images to be used as training data for Stable Diffusion model.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Stability Ai"],"developers":["Runway, Laion, Eleutherai, Compvis Lmu, Stability Ai"],"harmed":["Getty Images, Getty Images Contributors"],"report_count":5},{"incident_id":352,"occurred_on":"2022-09-15","title":"GPT-3-Based Twitter Bot Hijacked Using Prompt Injection Attacks","description":"Remoteli.io's GPT-3-based Twitter bot was shown being hijacked by Twitter users who redirected it to repeat or generate any phrases.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Stephan De Vries"],"developers":["Openai, Stephan De Vries"],"harmed":["Stephan De Vries"],"report_count":4},{"incident_id":391,"occurred_on":"2022-07-26","title":"Facial Recognition Trial by UK Southern Co-op Alleged as Unlawful","description":"Southern Co-op's use of facial recognition reportedly to curb violent crime in UK supermarkets was alleged by civil society and privacy groups as \"unlawful\" and \"complete\" invasion of privacy.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Southern Co Op"],"developers":["Hikvision"],"harmed":["Souther Co Op Customers"],"report_count":2},{"incident_id":372,"occurred_on":"2022-07-22","title":"Users Reported Security Issues with Google Pixel 6a's Fingerprint Unlocking","description":"Google Pixel 6a's fingerprint recognition feature was reported by users for security issues, in which phones were mistakenly unlocked by unregistered fingerprints.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Google"],"developers":["Google"],"harmed":["Google Pixel 6A Users"],"report_count":3},{"incident_id":258,"occurred_on":"2022-05-13","title":"Australian Retailers Reportedly Captured Face Prints of Their Customers without Consent","description":"Major Australian retailers reportedly analyzed in-store footage to capture facial features of their customers without consent, which was criticized by consumer groups as creepy and invasive.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["The Good Guys","Kmart","Bunnings"],"developers":["Unknown"],"harmed":["The Good Guys customers","Privacy","Kmart customers","Bunnings customers","Biometric data subjects"],"report_count":2},{"incident_id":465,"occurred_on":"2022-03-03","title":"Private Medical Photos Were Reportedly Found in LAION-5B AI Training Dataset","description":"In September 2022, an artist using the name Lapine reported finding private post-operative medical photos of herself in LAION-5B, a web-scraped image-text dataset used in AI image-synthesis research. Ars Technica confirmed her images were referenced in the dataset and reported finding thousands of similar patient medical-record photos.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Stability Ai, Google"],"developers":["Stability Ai, Laion, Google"],"harmed":["Privacy, Lapine, Patients, Patients Whose Medical Photos Were Included In Laion 5B, People Whose Private Images Were Included In Ai Training Datasets"],"report_count":1},{"incident_id":204,"occurred_on":"2022-02-11","title":"A Chinese Tech Worker at Zhihu Fired Allegedly via a Resignation Risk Prediction Algorithm","description":"The firing of an employee at Zhihu, a large Q&A platform in China, was allegedly caused by the use of a behavioral perception algorithm which claimed to predict a worker’s resignation risk using their online footprints, such as browsing history and internal communication.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Zhihu"],"developers":["Sangfor Technologies"],"harmed":["Zhihu employees","Chinese tech workers"],"report_count":4},{"incident_id":276,"occurred_on":"2022-01-01","title":"Local South Korean Government’s Use of CCTV Footage Analysis via Facial Recognition to Track COVID Cases Raised Concerns about Privacy, Retention, and Potential Misuse","description":"Bucheon government's use of facial recognition in analyzing CCTV footage, despite gaining wide public support, was scrutinized by privacy advocates and some lawmakers for collecting data without consent, and retaining and misusing data beyond pandemic needs.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Bucheon city government"],"developers":["Unknown"],"harmed":["Privacy","General public of South Korea","General public","Bucheon citizens","Biometric data subjects"],"report_count":1},{"incident_id":360,"occurred_on":"2021-10-15","title":"McDonald's AI Drive-Thru Allegedly Collected Biometric Customer Data without Consent, Violating BIPA","description":"McDonald's use of chatbot in its AI drive-through in Chicago was alleged in a lawsuit to have collected and processed voice data without user consent to predict customer information, which violated Illinois Biometric Information Privacy Act (BIPA).","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":"none","sectors":["accommodation and food service activities"],"countries":["US"],"deployers":["McDonald's"],"developers":["McD Tech Labs","Apprente"],"harmed":["Shannon Carpenter","Privacy","McDonald's customers residing in Illinois","McDonald's customers","Biometric data subjects"],"report_count":3},{"incident_id":119,"occurred_on":"2021-08-03","title":"Xsolla Employees Fired by CEO Allegedly via Big Data Analytics of Work Activities","description":"Xsolla CEO fired more than a hundred employees from his company in Perm, Russia, based on big data analysis of their remote digitized-work activity, which critics said was violating employee's privacy, outdated, and extremely ineffective.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":"none","sectors":["administrative and support service activities"],"countries":["RU"],"deployers":["Xsolla"],"developers":["Unknown"],"harmed":["Xsolla employees","Privacy","Biometric data subjects"],"report_count":4},{"incident_id":240,"occurred_on":"2021-06-29","title":"GitHub Copilot, Copyright Infringement and Open Source Licensing","description":"Users of GitHub Copilot can produce source code subject to license requirements without attributing and licensing the code to the rights holder.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Github, Programmers"],"developers":["Github"],"harmed":["Intellectual Property Rights Holders"],"report_count":5},{"incident_id":395,"occurred_on":"2021-03-02","title":"Amazon Allegedly Forced Deployment of AI-Powered Cameras on Delivery Drivers","description":"Amazon delivery drivers were allegedly forced to consent to algorithmic collection and processing of their location, movement, and biometric data through AI-powered cameras, or be dismissed.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Amazon"],"developers":["Netradyne"],"harmed":["Privacy","Biometric data subjects","Amazon delivery drivers"],"report_count":4},{"incident_id":212,"occurred_on":"2021-01-01","title":"XPeng Motors Fined For Illegal Collection of Consumers’ Faces Using Facial Recognition Cameras","description":"The Chinese electric vehicle (EV) firm XPeng Motors was fined by local market regulators for illegally collecting in-store customers’ facial images without their consent for six months.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["XPeng Motors"],"developers":["Unknown"],"harmed":["XPeng Motors customers","Privacy","Biometric data subjects"],"report_count":4},{"incident_id":996,"occurred_on":"2020-10-25","title":"Meta Allegedly Used Books3, a Dataset of 191,000 Pirated Books, to Train LLaMA AI","description":"Meta and Bloomberg allegedly used Books3, a dataset containing 191,000 pirated books, to train their AI models, including LLaMA and BloombergGPT, without author consent. Lawsuits from authors such as Sarah Silverman and Michael Chabon claim this constitutes copyright infringement. Books3 includes works from major publishers like Penguin Random House and HarperCollins. Meta argues its AI outputs are not \"substantially similar\" to the original books, but legal challenges continue.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Pre-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Meta, Eleutherai, Bloomberg, Generative Ai Developers"],"developers":["The Pile, Shawn Presser, Meta, Eleutherai, Bloomberg, Generative Ai Developers"],"harmed":["Zadie Smith, Writers, Verso, Stephen King, Sarah Silverman, Richard Kadrey, Publishers Found In Books3, Penguin Random House, Oxford University Press, Over 170000 Authors Found In Books3, Michael Pollan, Margaret Atwood, Macmillan, Harpercollins, General Public, Creative Industries, Christopher Golden, Authors"],"report_count":3},{"incident_id":557,"occurred_on":"2020-06-24","title":"Miami Police Deployed Facial Recognition to Arrest George Floyd Protestor Allegedly without Cause","description":"Miami Police's arrest report for a George Floyd protestor did not disclose use of facial recognition, which allegedly did not meet the legal threshold for probable cause for arrest.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Miami Police Department","Law enforcement"],"developers":["Clearview AI"],"harmed":["Oriana Albornoz","George Floyd protest participants"],"report_count":4},{"incident_id":354,"occurred_on":"2020-06-20","title":"Uber Allegedly Violated GDPR by Failing to Provide Sufficient Notice on Automated Profiling for Drivers","description":"Uber was alleged in a lawsuit to have provided incomplete notice about automated decision-making and profiling for drivers such as information about their driving behavior, and use of phone.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":"AI tangible harm event","sectors":["transportation and storage"],"countries":[],"deployers":["Uber"],"developers":["Uber"],"harmed":["Uber drivers"],"report_count":5},{"incident_id":521,"occurred_on":"2020-06-10","title":"iRobot Roomba J7 R&D Images Reportedly Appeared in Private Online Groups After Data Labeling","description":"Images reportedly captured in 2020 by development versions of iRobot's Roomba J7 robot vacuum during an AI training data project were sent to Scale AI for labeling and later appeared in private Facebook, Discord, and other online groups. Reporting described some images as showing sensitive household scenes.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Irobot"],"developers":["Irobot, Scale Ai"],"harmed":["Privacy, Project Io Participants, People Captured In Roomba Training Images, Minors Captured In Roomba Training Images, Minors"],"report_count":1},{"incident_id":412,"occurred_on":"2020-01-15","title":"Finnish Police Were Reportedly Reprimanded After National Bureau of Investigation Unit Allegedly Used Clearview AI to Identify Potential Abuse Victims","description":"Finland's Deputy Data Protection Ombudsman reportedly reprimanded the National Police Board after a National Bureau of Investigation child sexual exploitation unit allegedly used Clearview AI in late 2019 or early 2020 to identify potential child sexual abuse victims. Four NBI users reportedly made about 120 searches during a free trial without controller approval or prior assessment of how uploaded biometric data would be handled.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":"none","sectors":["law enforcement","information and communication"],"countries":[],"deployers":["Law enforcement","Government of Finland","Finnish National Police Board","Finnish National Bureau of Investigation"],"developers":["Facial recognition system developers","Clearview AI"],"harmed":["Privacy","People whose images were uploaded to Clearview AI","Minors","Child sexual abuse victims","Biometric data subjects"],"report_count":4},{"incident_id":223,"occurred_on":"2019-10-09","title":"Hive Box Facial-Recognition Locks Hacked by Fourth Graders Using Intended Recipient’s Facial Photo","description":"Facial-recognition locks by Hive Box, an express delivery locker company in China, were easily opened by a group of fourth-graders in a science-club demo using only a printed photo of the intended recipient’s face, leaving contents vulnerable to theft.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Hive Box"],"developers":["Hive Box"],"harmed":["Hive Box Customers"],"report_count":1},{"incident_id":441,"occurred_on":"2019-06-01","title":"South Korean Agencies Reportedly Shared Airport Travelers' Face Images with Companies to Train Immigration Facial Recognition System","description":"Reporting in 2021 alleged that South Korea's Ministry of Justice shared roughly 170 million face images and related biometric data from Korean and foreign airport travelers with the Ministry of Science and Information and Communication Technology (ICT) and private companies for an AI identification and tracking system used in immigration screening. The data was reportedly used for AI training and algorithm testing without travelers' consent.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Government Of South Korea, Korean Ministry Of Justice, Korean Ministry Of Science And Information And Communication Technology, National It Industry Promotion Agency"],"developers":["Surveillance Technology Developers, Facial Recognition System Developers"],"harmed":["Foreign Nationals Traveling Through South Korean Airports, Korean Citizens Whose Airport Facial Images Were Used, Biometric Data Subjects, Privacy, Travelers In Korean Airports"],"report_count":5},{"incident_id":76,"occurred_on":"2019-04-24","title":"Buenos Aires Government Reportedly Used Children's Personal Data in Facial Recognition System for Fugitives","description":"Beginning in April 2019, the Buenos Aires city government reportedly used data from Argentina’s CONARC fugitive database, including children’s identities and reference photos, in its live Facial Recognition System for Fugitives (SRFP). Human Rights Watch found at least 166 children had appeared in CONARC between 2017 and 2020 and warned that the system exposed them to privacy violations and elevated risks of false matches.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":"AI tangible harm event","sectors":["law enforcement","public administration"],"countries":["AR"],"deployers":["Government of Argentina","Buenos Aires city government"],"developers":["Surveillance technology developers","NtechLab","Facial recognition system developers","Danaide S.A."],"harmed":["Privacy","Minors","General public of Buenos Aires","General public of Argentina","General public","Buenos Aires children","Biometric data subjects"],"report_count":1},{"incident_id":199,"occurred_on":"2019-04-01","title":"Ever AI Reportedly Deceived Customers about FRT Use in App","description":"Ever AI, now Paravision AI, allegedly failed to inform customers about the development and use of facial recognition that facilitates the sale of customers’ data to various businesses, a business model that critics said was an egregious violation of privacy.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Ever AI"],"developers":["Ever AI"],"harmed":["Privacy","Ever AI users","Biometric data subjects"],"report_count":7},{"incident_id":561,"occurred_on":"2019-03-11","title":"OpenAI Alleged by Lawsuit Violated Users' Privacy Rights by Training AI on Private Info without Informed Consent","description":"OpenAI's products such as ChatGPT and DALL-E were alleged in a lawsuit using  stolen private information from internet users without their informed consent or knowledge.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Pre-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai"],"developers":["Openai, Large Language Model Developers, Image Generation Technology Developers, Chatbot Developers"],"harmed":["Social Media Users, Privacy, Minors, Internet Users"],"report_count":3},{"incident_id":357,"occurred_on":"2019-02-14","title":"GPT-2 Reportedly Reproduced Personal Data from Its Training Data","description":"OpenAI's GPT-2 reportedly memorized and reproduced portions of its training data, including personal information such as names, email addresses, social media handles, and phone numbers. Researchers raised concerns that large language models could expose private or sensitive information when trained on web-scale datasets containing personal data.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["OpenAI"],"developers":["OpenAI"],"harmed":["Privacy","People whose personal data was included in GPT-2 training data","GPT-2 users","Biometric data subjects"],"report_count":3},{"incident_id":555,"occurred_on":"2018-06-11","title":"OpenAI's Training Data for LLMs Allegedly Comprised of Copyrighted Books","description":"Two authors alleged in a class action lawsuit OpenAI infringed authors' copyrights by incorporating illegal \"shadow libraries\" offering copyrighted books without permission in the training data of its generative LLMs, such as ChatGPT.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Pre-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai"],"developers":["Openai"],"harmed":["Paul Tremblay, Mona Awad, Authors Of Copyrighted Works"],"report_count":1},{"incident_id":358,"occurred_on":"2018-06-01","title":"Calgary Malls Reportedly Deployed Facial Recognition Without Customer Consent","description":"Facial recognition (FRT) was reportedly deployed in some Calgary-area malls to approximate customer age and gender without explicit consent, which a privacy expert warned was a cause for concern.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Cadillac Fairview"],"developers":["Unknown"],"harmed":["Privacy","Market Mall goers","Chinook Centre mall goers","Biometric data subjects"],"report_count":1},{"incident_id":361,"occurred_on":"2018-05-11","title":"Amazon Echo Mistakenly Recorded and Sent Private Conversation to Random Contact","description":"Amazon Echo misinterpreted a background conversation between a husband and wife as instructions for recording a message and sending it to one of the husband's employees.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Amazon"],"developers":["Amazon"],"harmed":["Privacy","Biometric data subjects","Amazon Echo users"],"report_count":1},{"incident_id":556,"occurred_on":"2018-05-10","title":"Amazon Allegedly Violated Children's Privacy through Default Voice Collection Settings","description":"Amazon's retention of children' voice recordings indefinitely as the default setting reportedly to train Alexa's voice recognition for Alexa-enabled devices was charged by the FTC and DOJ to violate COPPA Rule.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Amazon"],"developers":["Amazon"],"harmed":["Alexa Children Users, Minors, Alexa Users, Privacy, Biometric Data Subjects"],"report_count":4},{"incident_id":184,"occurred_on":"2018-04-12","title":"Facial Recognition Program in São Paulo Metro Stations Suspended for Illegal and Disproportionate Violation of Citizens' Right to Privacy","description":" A facial recognition program rolled out by São Paulo Metro Stations was suspended following a court ruling in response to a lawsuit by civil society organizations, who cited fear of it being integrated with other electronic surveillance entities without consent, and lack of transparency about the biometric data collection process of metro users.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Companhia do Metropolitano de São Paulo"],"developers":["SecurOS"],"harmed":["São Paulo Metro users","São Paulo citizens","Privacy","General public of Brazil","General public","Biometric data subjects"],"report_count":3},{"incident_id":32,"occurred_on":"2017-09-13","title":"Identical Twins Can Open Apple FaceID Protected Devices","description":"Apple's iPhone FaceID can be opened by an identical twin of the person who has registered their face to unlock the phone.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":"none","sectors":["information and communication"],"countries":["US"],"deployers":["Apple"],"developers":["Apple"],"harmed":["People With Twins"],"report_count":21},{"incident_id":26,"occurred_on":"2017-09-13","title":"Hackers Break Apple Face ID","description":"Vietnamese security firm Bkav created an improved mask to bypass Apple's Face ID","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":"none","sectors":["information and communication"],"countries":["VN"],"deployers":["Apple"],"developers":["Apple"],"harmed":["Apple, Device Owners"],"report_count":24},{"incident_id":167,"occurred_on":"2017-09-07","title":"Researchers' Homosexual-Men Detection Model Denounced as a Threat to LGBTQ People's Safety and Privacy","description":"Researchers at Stanford Graduate School of Business developed a model that determined, on a binary scale, whether someone was homosexual using only his facial image, which advocacy groups such as GLAAD and the Human Rights Campaign denounced as flawed science and threatening to LGBTQ folks.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Yilun Wang","Michal Kosinski"],"developers":["Yilun Wang","Michal Kosinski"],"harmed":["Privacy","non-American LGBTQ people","LGBTQ people of color","LGBTQ people","Biometric data subjects"],"report_count":1},{"incident_id":1428,"occurred_on":"2017-07-28","title":"UK High Court Found Sky Betting & Gaming Unlawfully Used Automated Profiling and Targeted Marketing to Exploit a Recovering Problem Gambler","description":"In the UK, the High Court found that Sky Betting & Gaming unlawfully used automated profiling and targeted direct marketing to pursue a recovering problem gambler from July 28, 2017 onward without valid consent. Sky reportedly treated him as a high-value customer despite addiction indicators.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Sky Betting & Gaming","Hestview Ltd","Bonne Terre Ltd"],"developers":["Sky Betting & Gaming","Hestview Ltd","Bonne Terre Ltd"],"harmed":["Sky Betting & Gaming customers with gambling disorders","RTM (recovering problem gambler)","Recovering problem gamblers","Privacy","People with gambling disorders"],"report_count":2},{"incident_id":267,"occurred_on":"2017-06-15","title":"Clearview AI Algorithm Built on Photos Scraped from Social Media Profiles without Consent","description":"Face-matching algorithm by Clearview AI was built using scraped images from social media sites such as Instagram and Facebook without user consent, violating social media site policies, and allegedly privacy regulations.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Clearview AI"],"developers":["Clearview AI"],"harmed":["Social media users","Privacy","Instagram users","Facebook users","Biometric data subjects"],"report_count":10},{"incident_id":428,"occurred_on":"2017-05-19","title":"BBC Reporter's Twin Brother Cracked HSBC's Voice ID Authentication","description":"HSBC’s voice recognition authentication system was fooled after seven repeated attempts  by a BBC reporter's twin brother who mimicked his voice to access his bank account.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Hsbc Uk"],"developers":["Nuance Communications"],"harmed":["Hsbc Uk Customers, Dan Simmons"],"report_count":3},{"incident_id":408,"occurred_on":"2017-04-15","title":"Facebook Reportedly Outed Sex Workers through Friend Recommendations","description":"Facebook's \"People You May Know\" feature reportedly outed sex workers by recommending clients to their personal accounts or family members to their business accounts with no option to opt out.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Facebook"],"developers":["Facebook"],"harmed":["Social media users","sex workers using Facebook","sex workers","Privacy","Facebook users","Biometric data subjects"],"report_count":1},{"incident_id":190,"occurred_on":"2017-01-15","title":"ByteDance Allegedly Trained \"For You\" Algorithm Using Content Scraped without Consent from Other Social Platforms","description":" ByteDance allegedly scraped short-form videos, usernames, profile pictures, and descriptions of accounts on Instagram, Snapchat, and other sources, and uploaded them without consent on Flipagram, TikTok’s predecessor, in order to improve its “For You” algorithm's performance on American users.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Bytedance"],"developers":["Bytedance"],"harmed":["Instagram Users, Snapchat Users, American Social Media Users"],"report_count":4},{"incident_id":109,"occurred_on":"2017-01-01","title":"PimEyes's Facial Recognition AI Allegedly Lacked Safeguards to Prevent Itself from Being Abused","description":"PimEyes offered its subscription-based AI service to anyone in the public to search for matching facial images across the internet, which critics said lacked public oversight and government rules to prevent itself from misuse such as stalking women.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":"unclear","sectors":["information and communication","arts, entertainment and recreation"],"countries":[],"deployers":["PimEyes"],"developers":["PimEyes"],"harmed":["Privacy","internet users","Biometric data subjects"],"report_count":1},{"incident_id":368,"occurred_on":"2016-06-01","title":"Facial Recognition Smart Phone App 'Blue Wolf' Reportedly Monitored Palestinians in the West Bank","description":"A surveillance program involving facial recognition and algorithmic recommendations, Blue Wolf, was reportedly deployed by the Israeli military to monitor Palestinians in the West Bank.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Israel Defense Forces","Government of Israel"],"developers":["AnyVision"],"harmed":["Privacy","Palestinians residing in the West Bank","Palestinians","General public","Biometric data subjects"],"report_count":10},{"incident_id":406,"occurred_on":"2015-07-15","title":"Facebook's Friend Suggestion Feature Recommends Patients of Psychiatrist to Each Other","description":"Facebook's \"People You May Know\" (PYMK) feature was reported by a psychiatrist for recommending her patients as friends through recommendations, violating patients' privacy and confidentiality.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Facebook"],"developers":["Facebook"],"harmed":["pseudonymized psychiatrist's patients","pseudonymized psychiatrist","Privacy","Patients","healthcare providers","Biometric data subjects"],"report_count":1},{"incident_id":122,"occurred_on":"2015-06-14","title":"Facebook's 'Tag Suggestions' Allegedly Stored Biometric Data without User Consent","description":"Facebook's initial version of the its Tag Suggestions feature where users were offered suggestions about the identity of people's faces in photos allegedly stored biometric data without consent, violating the Illinois Biometric Information Privacy Act.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":"AI tangible harm event","sectors":["arts, entertainment and recreation","information and communication"],"countries":["US"],"deployers":["Facebook"],"developers":["Facebook"],"harmed":["Social media users","Privacy","Facebook users","Biometric data subjects"],"report_count":1},{"incident_id":254,"occurred_on":"2015-05-01","title":"Google's Face Grouping Allegedly Collected and Analyzed Users' Facial Structure without Consent, Violated BIPA","description":"A class-action lawsuit alleged Google failing to provide notice, obtain informed written consent, or publish data retention policies about the collection, storage, and analysis of its face-grouping feature in Google Photos, which violated Illinois Biometric Information Privacy Act (BIPA).","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":"AI tangible harm event","sectors":["information and communication"],"countries":["US"],"deployers":["Google"],"developers":["Google"],"harmed":["Privacy","Illinois residents","Google Photos users residing in Illinois","Google Photos users","Biometric data subjects"],"report_count":2},{"incident_id":387,"occurred_on":"2014-12-22","title":"Oracle's Algorithmic Data Processing System Alleged as Unlawful and Violating Privacy Rights","description":"Oracle's automated system involving algorithmic data processing was alleged in a lawsuit to have been unlawfully collecting personal data from millions of people and violating their privacy rights.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":"none","sectors":["information and communication"],"countries":["US"],"deployers":["Oracle"],"developers":["Oracle"],"harmed":["Privacy","internet users","Biometric data subjects"],"report_count":1},{"incident_id":409,"occurred_on":"2013-09-13","title":"Facial Recognition Researchers Allegedly Used YouTube Videos of Transgender People Without Consent","description":"YouTube videos of transgender people used by researchers to study facial recognition during gender transitions were allegedly used and distributed without permission.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":"none","sectors":["professional, scientific and technical activities"],"countries":[],"deployers":["University of North Carolina Wilmington","Karl Ricanek","Gayathri Mahalingam"],"developers":["University of North Carolina Wilmington","Karl Ricanek","Gayathri Mahalingam"],"harmed":["YouTubers","YouTube users","Transgender YouTubers","transgender people","Social media users","Privacy","Biometric data subjects"],"report_count":3},{"incident_id":44,"occurred_on":"2008-07-01","title":"Machine Personal Assistants Failed to Maintain Social Norms","description":"During an experiment of software personal assistants at the Information Sciences Institute (ISI) at the University of Southern California (USC), researchers found that the assistants violated the privacy of their principals and were unable to respect the social norms of the office.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":"none","sectors":["administrative and support service activities"],"countries":["US"],"deployers":["Usc Information Sciences Institute"],"developers":["Usc Information Sciences Institute"],"harmed":["Usc Information Sciences Institute"],"report_count":1},{"incident_id":170,"occurred_on":"2003-06-01","title":"Target Suggested Maternity-Related Advertisements to a Teenage Girl's Home, Allegedly Correctly Predicting Her Pregnancy via Algorithm","description":"Target recommended maternity-related items to a family in Atlanta via ads, allegedly predicting their teenage daughter’s pregnancy before her father did, although critics have called into question the predictability of the algorithm and the authenticity of its claims.","mit_domain":"Privacy & Security","mit_subdomain":"Compromise of privacy by obtaining, leaking or correctly inferring sensitive information","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Target"],"developers":["Target"],"harmed":["Target customers","Privacy","Consumers","Biometric data subjects"],"report_count":3}]}