The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

70 incidents closest to “Palantir Technologies” · matched on meaning · public reporting

WF-C15GZU1 Jun 2026

Another OpenAI hack: AI agent took non-public gov data in Australia - Techlicious

The AI model queried the National Parks and Wildlife Service's Fire History service and gathered non-public summary fire statistics.

Company involved
OpenAI

1 source article · read the reporting →

Gamma AI Presentation Tool Exploited in Multi-Stage Phishing Campaign

Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.

AI system involved
Gamma

7 source articles · read the reporting →

WF-HW23LM1 Dec 2023

Alibaba among firms fooled by AI-hallucinated software package

Security researcher Bar Lanyado discovered that generative AI models repeatedly hallucinate non-existent software package names. He created a real package named 'huggingface-cli' based on one such hallucination and uploaded it to PyPI. The package was downloaded over 15,000 times, and Alibaba's GraphTranslator project included instructions to install it. The experiment demonstrated a potential supply chain attack vector where malicious actors could exploit AI hallucinations to distribute malware.

Company involved
Alibaba
AI system involved
GraphTranslator

4 source articles · read the reporting →

WF-02DLSM24 Jun 2019

Sidewalk Labs releases Toronto waterfront plan amid privacy concerns

Sidewalk Labs, a subsidiary of Alphabet, released a 1,500-page plan for a new development on Toronto's eastern waterfront, including the Quayside site. The plan involves extensive data collection and management, raising privacy concerns from critics and the public. Waterfront Toronto, the overseeing body, is reviewing the plan and has expressed concerns about its scope and data governance. The company has proposed an independent trust to oversee data, but critics remain unsatisfied.

Company involved
Sidewalk Labs
AI system involved
Quayside development

10 source articles · read the reporting →

Ukraine defence ministry uses Clearview AI facial recognition to identify dead and Russian assailants

Ukraine's defence ministry has started using Clearview AI's facial recognition technology to identify Russian assailants and the dead, according to reports. Clearview provided free access to its system, which holds over 10 billion images including from Russian social media. Critics warn that the technology could misidentify people at checkpoints and in battle, potentially harming civilians. Clearview says it should not be used as the sole source of identification.

Company involved
Ukraine's Ministry of Defense
AI system involved
Clearview AI

10 source articles · read the reporting →

WF-U5X4EM1 May 2026

Google sues Chinese gang over AI-powered fraud targeting Americans

Google has filed a lawsuit against a Chinese cybercrime group called Outsider Enterprise, alleging it used Google's Gemini AI to create hundreds of fake websites impersonating companies and government services. The group allegedly sent millions of phishing messages to Android users, defrauding hundreds of thousands of Americans of millions of dollars. Google is coordinating with the FBI and wireless carriers to dismantle the network. The lawsuit, filed in the Southern District of New York, seeks an injunction to take down the operation.

Company involved
Outsider Enterprise
AI system involved
Gemini

3 source articles · read the reporting →

WF-VVTY7V19 Feb 2024

North Korean hackers use ChatGPT to scam LinkedIn users

North Korean state-affiliated hacking group Emerald Sleet (Kimsuky) used OpenAI's ChatGPT to research targets and draft phishing content for scams on LinkedIn. Microsoft and OpenAI terminated the group's accounts after identifying the activity. The hackers impersonated academic institutions and NGOs to lure victims into providing sensitive information, with South Korea's intelligence agency confirming North Korea's use of generative AI for hacking.

Company involved
OpenAI
AI system involved
ChatGPT

6 source articles · read the reporting →

WF-9KY8EL19 Oct 2019

Outback Steakhouse franchise tests Presto Vision to monitor staff and guests

Evergreen Restaurant Group, a franchisee of Outback Steakhouse, has begun testing Presto Vision, a computer vision system that analyses surveillance camera footage to track employee performance and guest behaviour. The system compiles metrics on service, wait times, and customer turnover, which managers receive by email. Employees say they were not informed about the technology, and researchers have raised concerns about workplace stress, job losses, and data sharing with parent companies.

Company involved
Evergreen Restaurant Group
AI system involved
Presto Vision

8 source articles · read the reporting →

WF-LYOLJ61 Jul 2018

SenseNets silent after data leak exposes millions of people's records

SenseNets Technology Ltd., a Shenzhen-based facial recognition company, left a database containing personal information of more than 2.5 million people publicly accessible without password protection for months. Dutch security researcher Victor Gevers and the GDI Foundation discovered the exposure in July and warned the company, which did not respond. The database was secured in February after the leak was reported, and the company is reported to be conducting an internal investigation. SenseNets has declined to comment publicly.

Company involved
SenseNets Technology Ltd.

10 source articles · read the reporting →

WF-LH77B55 Sep 2024

Italy terminates contracts with Paragon spyware after surveillance scandal

Italy has terminated its contracts with Israeli spyware company Paragon after revelations that the spyware was used against government critics, including journalists and migrant rescue workers. The intelligence oversight committee COPASIR confirmed the cancellation in a report released on June 9, 2025. The government admitted seven Italians were targeted but claimed all surveillance was lawful and overseen by a prosecutor. Opposition parties are demanding a full investigation.

Company involved
Italian government
AI system involved
Paragon spyware

9 source articles · read the reporting →

WF-NAZJJM1 Jan 2018

Microsoft funded Israeli facial recognition firm surveilling West Bank Palestinians

Microsoft invested in AnyVision, an Israeli facial recognition company whose technology powers a secret military surveillance project in the West Bank. The system, called Better Tomorrow, identifies and tracks Palestinians in live camera feeds. Microsoft said it would audit AnyVision for compliance with its ethical principles.

Company involved
Israeli Defense Forces
AI system involved
Better Tomorrow

10 source articles · read the reporting →

WF-YK9Q5P10 Feb 2020

Barclays pilot of Sapience monitoring software causes employee stress

Barclays introduced a pilot of employee monitoring software from Sapience in its product control department at Canary Wharf. The system monitors computer activity and admonishes staff if they are not deemed active enough, recording breaks as "unaccounted activity". Employees reported significant stress and worry about taking breaks. Barclays acknowledged the pilot and said it would listen to feedback.

Company involved
Barclays
AI system involved
Sapience employee monitoring software

10 source articles · read the reporting →

Chinese military researchers used Meta's Llama 2 to develop defense chatbot ChatBIT

Chinese military researchers, including two affiliated with the People's Liberation Army, reportedly used Meta's Llama 2 AI model to develop a defense chatbot called ChatBIT. According to Reuters, the chatbot is designed to gather and process intelligence and offer information for operational decision-making. Meta stated that the use was unauthorized and contrary to its acceptable use policy.

Company involved
People's Liberation Army (PLA)
AI system involved
ChatBIT

6 source articles · read the reporting →

PimEyes face search engine found photos of journalists without consent

The New York Times tested PimEyes, a face search engine, by submitting photos of a dozen employees. The system returned photos of the journalists from various sources, including ones they had never seen, even when faces were obscured. The system also misidentified women journalists as possibly being on adult sites. German authorities are currently investigating PimEyes over privacy concerns.

Company involved
PimEyes
AI system involved
PimEyes

2 source articles · read the reporting →

Clearview AI tested facial recognition surveillance cameras with UFT and Rudin

Clearview AI, the facial recognition company that scraped billions of photos from social media, developed a surveillance camera system under the name Insight Camera. The system was tested by the United Federation of Teachers and Rudin Management in New York City. The UFT used it to identify individuals who had made threats and prevent them from entering its offices. Clearview did not respond to requests for comment.

Company involved
Clearview AI
AI system involved
Insight Camera

9 source articles · read the reporting →

Chinese tech companies patented Uyghur detection analytics

IPVM reported that Huawei, Megvii, SenseTime, and other Chinese tech companies filed patents in China for AI systems that can detect Uyghur ethnicity. The patents included Uyghur as a detectable attribute for facial recognition and image retrieval. The companies responded by saying they would amend or withdraw the patents, claiming the references were misunderstood or regrettable, while the technology is used by police for surveillance and targeting of Uyghurs.

10 source articles · read the reporting →

WF-JH5L2X26 Mar 2021

Teleperformance plans AI webcam surveillance for home-working staff

Teleperformance, a global call centre company, told some staff it would install AI-powered webcams to monitor home-working infractions such as eating, phone use, or leaving desks. The system would randomly scan for breaches and send alerts to managers. After the Guardian inquired, the company said the remote scans would not be used in the UK, but the plan raised concerns from unions and MPs about invasive surveillance.

Company involved
Teleperformance

10 source articles · read the reporting →

WF-BWQHCV23 Feb 2021

AnyVision patents drone facial recognition technology

AnyVision, an Israeli private surveillance company, filed a US patent for drone technology that uses facial recognition to identify people on the ground. The patent describes adaptive positioning of drones to find optimal angles for accurate facial recognition. The technology is not yet in production, but the company's CEO stated it will become a reality soon. Potential privacy concerns have been raised.

Company involved
AnyVision
AI system involved
Adaptive positioning of drones for enhanced facial recognition

9 source articles · read the reporting →

PwC develops facial recognition tool to monitor employees working from home

Accounting giant PwC has developed a facial recognition tool that logs when employees are absent from their computer screens while working from home. The tool, intended for financial institutions, requires workers to provide written reasons for any absences, including toilet breaks. Commentators have criticised the tool as a huge invasion of privacy, with concerns about damage to trust and increased stress. PwC stated that the technology is designed to help regulated institutions meet compliance obligations and that voluntary consent of traders is essential.

Company involved
PwC

8 source articles · read the reporting →

WF-OGHTXE1 Jun 2025

Intellexa Predator spyware used to surveil human rights lawyer in Pakistan

In summer 2025, a human rights lawyer from Pakistan's Balochistan province was targeted via WhatsApp with Intellexa's Predator spyware, according to Amnesty International's Security Lab. The attack is part of a broader pattern of unlawful surveillance of activists, journalists and human rights defenders. The Intellexa Leaks investigation exposed internal operations of the spyware company, raising concerns about human rights due diligence.

AI system involved
Predator spyware

10 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

WF-2ABL3N30 Nov 2023

Bavarian police test Palantir data mining with real personal data

The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.

Company involved
Bayerisches Landeskriminalamt
AI system involved
VeRa

7 source articles · read the reporting →

N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent

Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.

Company involved
N-Tech.lab
AI system involved
FindFace

8 source articles · read the reporting →

WF-KPRZVQ1 Jan 2024

Met Police accessed PimEyes facial recognition site 2,000 times

The Metropolitan Police accessed the controversial facial recognition search engine PimEyes over 2,000 times from its computers in the first three months of 2024. The force stated that the hits did not necessarily mean searches were conducted, but after being alerted by i and Liberty Investigates, it blocked access to the site and strengthened safeguards. Privacy campaigners and MPs have raised concerns that the unregulated tool could be used for stalking and surveillance.

Company involved
Metropolitan Police Service
AI system involved
PimEyes

3 source articles · read the reporting →

← Newerpage 2 of 3Older →