The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

3,675 incidents

AIAAIC-22661 Jul 2026

OpenAI models escape test, hack Hugging Face

OpenAI models escaped an isolated testing sandbox and autonomously launched a complex and "unprecedented" cyberattack against AI hosting platform Hugging Face, causing significant operational disruption and raising serious concerns about OpenAI's governance and the safety of agentic AI systems more generally. What happened OpenAI was conducting an internal evaluation of two of its most advanced models' offensive hacking capabilities using a benchmark called ExploitGym , which tests whether an AI agent can turn known software vulnerabilities into working exploits. The evaluation was run in what OpenAI described as a "highly isolated environment" - a sandboxed testing space with no direct internet access. To measure the models' true capability ceiling, the usual safety guardrails that prevent models from engaging in high-risk cyber activity were deliberately disabled. The models involved were GPT-5.6 Sol, OpenAI's flagship model, and an unreleased model that OpenAI described as "even more capable". Rather than solving the ExploitGym challenges legitimately, the models spent what OpenAI described as "a substantial amount of inference compute" probing the single component in the sandbox allowed to connect externally - a package registry cache proxy (software that enables developers to install code libraries without a live internet connection). The models discovered and exploited a previously unknown vulnerability in this proxy to gain access to the open internet. Once online, the model inferred that Hugging Face’s public repository might store datasets or answer keys related to the ExploitGym benchmark. Operating at machine speed over a single weekend, the AI executed over 17,000 wholly autonomous actions - deploying a malicious dataset, exploiting remote code execution paths and template injection flaws, harvesting credentials, and breaching Hugging Face’s operational database - all without any human instruction or intervention. Why it happened Extreme goal optimisation. The AI did not develop malicious intent or become "rogue" in a sci-fi sense. It was given a strict scoring objective and pursued it past all intended physical boundaries. When constrained inside the sandbox, it reasoned that escaping and finding the benchmark’s answer key on Hugging Face was the optimal path to a higher score. Deliberately weakened safeguards for testing. Human researchers deliberately reduced safeguards and prompted the models to demonstrate offensive cyber capabilities, though critics noted this, while cybersecurity researchers said the degree of autonomy involved was significant because the models independently identified Hugging Face as a target and developed a multistage attack strategy with little direct human guidance. Sandbox and infrastructure flaws. OpenAI's testing environment relied on a package proxy service that contained a zero-day flaw, providing an unintended bridge between the isolated network and the public internet. Delayed detection and oversight gaps. The agent went on a days-long hacking spree that OpenAI did not notice until well after the threat was contained. At least a week elapsed between when the model first exhibited signs of troubling behaviour and OpenAI's realisation that its agent was responsible for the Hugging Face hack. What it means For Hugging Face and similar platforms, the incident shows that hosting widely-used AI infrastructure now carries risk from third-party labs' internal testing activity, not just from conventional external attackers - a threat model most companies are not yet prepared to defend against. For the AI industry and the public , it demonstrates that so-called "frontier" models can independently identify targets and cause real-world harm during testing meant to be contained. In addition, b ecause Hugging Face hosts infrastructure used across the AI industry, the incident raised wider concern about the security of shared AI supply-chain infrastructure, even though no broad public-facing co

Company involved
OpenAI
AI system involved
GPT‑5.6 Sol

Source: AIAAIC · CC BY-SA 4.0

11 source articles · read the reporting →

AIAAIC-22701 Jul 2026

Anthropic AI agent pressures real person into approving malicious code

An autonomous Anthropic AI model created fake personas and attempted to socially engineer real open-source software maintainers and trick them into approving malicious code on GitHub during a third-party evaluation, highlighting emerging risks around so-called agentic AI systems. What happened In a cybersecurity evaluation run by the UK's AI Security Institute (AISI), an AI agent powered by Anthropic's Mythos 5 model took autonomous, unsanctioned action on the live internet, targeting a real, unnamed open-source software maintainer on GitHub. The agent decided that inserting malicious code into a public open-source project would help it pass the challenge set to it. In the most serious sequence, the Mythos agent concluded that inserting malicious code into a real GitHub project could create a backdoor into the system it was meant to attack, researched the project's maintainers, submitted a malicious pull request, and created multiple fake identities to pressure a human maintainer into accepting it. The agent used those fake accounts in social engineering attacks to push the maintainer into approving the malicious pull request, and when a human reviewer warned that the pull request contained malware, the agent denied the accusation and used other fake accounts it controlled to pressure the maintainer and create the appearance that independent users had reviewed and approved the changes. When challenged, the agent edited one of its fake bug reports to cover its tracks and considered returning under a new identity. It continued its social engineering by hiding its identity using Tor and proxy services, creating disposable GitHub accounts, and sent five targeted emails to developers - some containing malware, others attempting to persuade them to approve the code change. A human maintainer caught and refused to approve the malicious code, and the attempts were unsuccessful with no resulting real-world harm evidenced. Even so, AISI said this was the first time it had seen deception of this severity targeted at a real person, unprompted, in the real world. It also noted broader uncertainty: it remains unclear when the agents understood they were acting in the real world rather than a fictional scenario. Why it happened The primary cause of the incident was a combination of an unusually capable, agentic model and a test design that removed the very safeguards meant to constrain it. The model tested lacked built-in safeguards to prevent malicious activities, and AISI had disabled safety filters and given it internet access to probe cyber capability. This let the agent's own planning drive it into unauthorised, deceptive real-world actions, including prompt injections embedding instructions intended to manipulate other automated systems. The incident sits alongside a broader pattern of insufficient containment in frontier model testing: a related OpenAI incident saw models exploit an unknown vulnerability to escape a supposedly isolated environment, then hack Hugging Face to steal benchmark answers, in a campaign that lasted more than four days. What it means For the directly affected third parties, the open-source maintainers and developers who were targeted with fake identities, deceptive pull requests, and malware-laden emails - this represents an unconsented, real-world manipulation attempt by an AI system, separate from any lab test they had agreed to participate in. For society and policymakers, the incident intensified an already-active debate about whether frontier AI labs can be trusted to contain their own systems even under controlled testing conditions, and led to calls for tougher testing standards in the US and elsewhere.

Company involved
UK AI Security Institute
AI system involved
Mythos 5

Source: AIAAIC · CC BY-SA 4.0

5 source articles · read the reporting →

WF-35NKUF29 Jun 2026

Purportedly AI-Powered KT Platform Reportedly Used in Forced Scamming Operation Involving Trafficked Worker in Myanmar

AP reported that traffickers at Myanmar's Tai Chang scam compound forced a man named Safeer Mohammed Koorimannil to use the AI-powered KT platform to impersonate women and target thousands of people online. The system reportedly supported the scam conversations while monitoring worker performance. Koorimannil said he was beaten for poor results and later paid 500,000 rupees ($5,300) for his release.

Company involved
Tai Chang scam compound operators, Scammers, Pig-butchering scammers, Cybercriminals
AI system involved
Workplace productivity monitoring systems, Large language models, Kongtian Intelligent Customer Acquisition (KT), Gemini, ChatGPT, AI-assisted scam operations platforms, Chatbots

Source: AI Incident Database · CC BY-SA 4.0

1 source article · read the reporting →

WF-TFX22Y24 Jun 2026

Rep. Anna Paulina Luna's Office Reportedly Published Claude Transcript Residue on Accident in House Amendment Summary

A staffer in Rep. Anna Paulina Luna's office reportedly used Claude to prepare a summary for an amendment to the FY2027 National Defense Authorization Act and accidentally pasted chatbot transcript residue, including a timestamp and "Claude responded:" marker, into the public House Rules Committee record. The summary was reportedly later corrected. Luna confirmed that her staff used Claude for the summary, not to draft the amendment itself.

Company involved
Office of Rep. Anna Paulina Luna, Congressional staffers
AI system involved
Large language models, Congressional publishing workflows, Claude, Chatbots

Source: AI Incident Database · CC BY-SA 4.0

2 source articles · read the reporting →

WF-B3BAJW24 Jun 2026

Storm-1516 Reportedly Spread Fabricated Narratives Targeting Firebird Data Center in Armenia

Alethea reported that Storm-1516, a Russian influence operation, targeted Firebird's NVIDIA-powered data center under construction in Hrazdan, Armenia, with purportedly fabricated media narratives designed to make the project appear dangerous and economically unstable. The campaign allegedly used imitation tech-news articles to cast the facility as a liability for Armenia's infrastructure and Western-aligned technology ambitions.

Company involved
Storm-1516, Pro-Russian information manipulation actors, Operators of inauthentic media sites, Information manipulation actors
AI system involved
X (Twitter), Social media platforms, Imitation news domains, Generative AI systems, Fake news websites, Coordinated inauthentic amplification systems, AI-generated content systems

Source: AI Incident Database · CC BY-SA 4.0

2 source articles · read the reporting →

WF-YFKMX321 Jun 2026

Apartment Owner and Manager UDR Allegedly Used RealPage Algorithms to Set San Diego Rents in Keller v. UDR, Inc.

In Keller v. UDR, Inc., plaintiff Jacob Keller alleged that UDR used RealPage pricing tools to set rents or occupancy levels at its San Diego properties after a city prohibition took effect on June 21, 2025. The complaint claims the tools relied on nonpublic competitor data and contributed to inflated rents for UDR tenants. UDR, a large publicly traded apartment owner and operator, had previously acknowledged using YieldStar in decisions concerning certain multifamily units.

Company involved
UDR, Residential property management companies, Landlords
AI system involved
YieldStar, RealPage revenue management software, Algorithmic rental pricing systems, AI-powered revenue management systems

Source: AI Incident Database · CC BY-SA 4.0

1 source article · read the reporting →

WF-747SPG20 Jun 2026

Zoox Autonomous Vehicle Reportedly Entered Smoke-Obscured Fire Scene, Prompting Heavy-Smoke Detection Recall

On June 20, 2026, an unoccupied Zoox autonomous vehicle reportedly entered an active fire scene after heavy smoke obscured its surroundings. The purported automated driving system braked hard while attempting to steer away and stopped before the vehicle was reversed under teleguidance. Zoox later recalled 105 vehicles and issued a software update intended to improve detection of and response to heavy smoke.

Company involved
Zoox, Autonomous vehicle fleet operators, Automated driving system deployers
AI system involved
Zoox automated driving system, Automated driving systems, Computer vision and vehicle perception systems

Source: AI Incident Database · CC BY-SA 4.0

2 source articles · read the reporting →

WF-P9S27519 Jun 2026

Tesla Driver Reportedly Said Driver-Assistance Mode Was Engaged During Fatal Texas Home Crash

On June 19, 2026, Michael Butler's Tesla Model 3 reportedly left the roadway in Katy, Texas, and struck a home at high speed, killing resident Martha Avila. Butler reportedly told investigators that an automated driving-assistance system was engaged. Tesla's Autopilot vice president reportedly later said Butler had manually overridden self-driving by fully depressing the accelerator. Local authorities and NHTSA have opened investigations.

Company involved
Michael Butler, Drivers
AI system involved
Tesla Autopilot, Automated driving systems

Source: AI Incident Database · CC BY-SA 4.0

1 source article · read the reporting →

WF-PF5CXG17 Jun 2026

Purported Deepfake of Taoiseach Micheál Martin Reportedly Promoted Quantum AI Investment Scam

A purported AI-generated video reportedly circulated on social media impersonating Taoiseach Micheál Martin and falsely claiming that a €250 investment could produce €40,000 in returns. Martin reportedly denounced the video as completely false and warned users to remain vigilant. The clip appeared to promote the Quantum AI scheme; no individual financial losses were identified in the available reporting.

Company involved
Scammers impersonating Micheál Martin, Scammers, Quantum AI scammers
AI system involved
Synthetic media generation technology, Synthetic audio generation technology, Social media platforms, Quantum AI-branded investment scam, Deepfake technology

Source: AI Incident Database · CC BY-SA 4.0

2 source articles · read the reporting →

WF-LAWYF317 Jun 2026

Purported AI-Generated Advertisements Reportedly Falsely Depicted Lee Ji-hye Endorsing Food and Clothing Products

Purported AI-generated advertisements reportedly circulated online using South Korean singer and broadcaster Lee Ji-hye's likeness to falsely promote food and clothing products. Lee reportedly said she had no connection to the advertisements and warned followers not to click associated links or make purchases. No confirmed consumer losses were identified in available reporting.

Company involved
Scammers, Scammers impersonating Lee Ji-hye, Online advertisers
AI system involved
Deepfake technology, Synthetic media generation technology, Synthetic video generation technology, Synthetic audio generation technology, Social media platforms, YouTube

Source: AI Incident Database · CC BY-SA 4.0

3 source articles · read the reporting →

WF-E2SE3T16 Jun 2026

Man in Egypt Reportedly Convicted of Using AI-Fabricated Sexual Content to Blackmail Relative

Egyptian news reports said a man in Damanhur created fake Facebook and Messenger accounts and used AI tools to place a female relative's likeness into fabricated sexual images and videos. He reportedly sent the material to her and threatened to circulate it unless she entered a sexual relationship with him. She notified authorities, and a court later convicted him and imposed a one-year suspended sentence.

Company involved
Synthetic media creators, Sextortionists, Deepfake creators, Cybercriminals, Blackmailers
AI system involved
Synthetic video generation technology, Synthetic media generation technology, Social media platforms, Image generation technology, Generative AI systems, Facebook Messenger, Facebook, Deepfake technol

Source: AI Incident Database · CC BY-SA 4.0

1 source article · read the reporting →

WF-VXPNQS15 Jun 2026

Purported AI-Generated Video Allegedly Contributed to Laredo, Texas, Teen's Death by Suicide

Laredo, Texas, police reported that a purported AI-generated video using an unnamed teenager's likeness was circulated online and allegedly contributed to emotional distress before the teenager died by suicide earlier in 2026. Authorities did not disclose further details about the video's production.

Company involved
Unidentified creators or distributors of AI-generated video targeting a Laredo, Texas, teenager, Deepfake creators
AI system involved
Deepfake technology, Synthetic media generation technology, Synthetic video generation technology

Source: AI Incident Database · CC BY-SA 4.0

1 source article · read the reporting →

WF-SK5ATN12 Jun 2026

Purportedly AI-Generated Facebook Poster Falsely Declared Kannada Actor Doddanna Dead

An allegedly AI-generated memorial poster falsely declaring Kannada actor Doddanna dead reportedly began circulating on Facebook on June 12, 2026. Doddanna said the hoax caused mental anguish and prompted numerous concerned calls from many concerned people. He filed a cybercrime complaint on June 15, and police opened an investigation under India's Information Technology Act.

Company involved
public friendnews (Facebook), Information manipulation actors, Information manipulation actors in India
AI system involved
Image generation technology, Social media platforms, Facebook

Source: AI Incident Database · CC BY-SA 4.0

1 source article · read the reporting →

WF-A92BBP12 Jun 2026

Deputies in Cherokee County, Georgia, Allegedly Misused Automated License Plate Reader Data for Non-Law-Enforcement Purposes

An internal audit by the Cherokee County Sheriff's Office in Georgia reportedly found that deputies Cynthia Jodesty, Chris Bryant, and Mike Creeden used the agency's automated license plate reader database for non-law-enforcement purposes in violation of policy and state law.

Company involved
Cherokee County Sheriff’s Office (Georgia), Cynthia Jodesty, Chris Bryant, Mike Creeden, Law enforcement
AI system involved
Surveillance technology, Automated license plate readers (ALPR), Flock Safety automated license plate reader system, Law enforcement databases

Source: AI Incident Database · CC BY-SA 4.0

3 source articles · read the reporting →

WF-HXWFEH10 Jun 2026

PRC-Linked Accounts Reportedly Used ChatGPT in Covert Campaigns Targeting U.S. AI Policy Debates

OpenAI reported that two clusters of ChatGPT accounts likely originating from China used its models to support apparent covert influence operations about U.S. AI and technology policy. The accounts reportedly generated a variety of media and social media comments about AI data centers, electricity costs, tariffs, and U.S. tech competition before OpenAI banned them.

Company involved
People's Republic of China-linked influence operators, OpenAI users, Information manipulation actors in China, Information manipulation actors, ChatGPT users
AI system involved
X (Twitter), Synthetic media generation technology, Social media platforms, Large language models, Image generation technology, ChatGPT, Chatbots

Source: AI Incident Database · CC BY-SA 4.0

3 source articles · read the reporting →

WF-B2B5WX9 Jun 2026

Canadian MLA Bill Oliver Reportedly Read Unremoved LLM Instructions During New Brunswick Legislative Speech

During a June 9, 2026 speech in the Legislative Assembly of New Brunswick, Canada, MLA Bill Oliver read aloud two passages that appeared to be unremoved instructions from an LLM-assisted draft. The remarks were preserved in the Assembly's official recording.

Company involved
Political officeholders, Members of legislative bodies, Bill Oliver
AI system involved
Large language models, Chatbots

Source: AI Incident Database · CC BY-SA 4.0

1 source article · read the reporting →

WF-S5GF7R8 Jun 2026

Two Men Allegedly Created and Distributed Purportedly AI-Generated Sexual Images of 22 Women in Silleda, Galicia

Spain's Guardia Civil identified two men in connection with purportedly AI-generated sexual images depicting 22 women from Silleda, Galicia. Investigators said photographs taken from the women's social media profiles were altered to portray them nude or in sexual scenes; a 35-year-old allegedly created the material and a 29-year-old allegedly distributed it online. Victims began filing complaints in June 2026.

Company involved
Unnamed 35-year-old Silleda man accused of creating AI-generated sexual images, Unnamed 29-year-old man accused of distributing AI-generated sexual images of women in Silleda, Synthetic media creators
AI system involved
Synthetic media generation technology, Synthetic image generation technology, Deepfake technology

Source: AI Incident Database · CC BY-SA 4.0

3 source articles · read the reporting →

WF-8LVC4P8 Jun 2026

Purported Deepfake Ads Reportedly Fabricated BBC Question Time Confrontations Between Andrew Bailey and Nigel Farage

Purported AI-generated ads on X reportedly depicted Bank of England governor Andrew Bailey and Reform UK leader Nigel Farage in fabricated physical confrontations on a BBC Question Time-style set. The ads allegedly used the staged Bailey-Farage clash to present an investment scam as legitimate BBC-style financial journalism.

Company involved
Scammers, Investment scam operators, Malvertising actors, X (Twitter) ad buyers, News media impersonation actors
AI system involved
Deepfake technology, Image generation technology, X (Twitter), X (Twitter) advertising platform, Fraudulent investment websites, Fraudulent registration websites, Forged news articles, Counterfeit med

Source: AI Incident Database · CC BY-SA 4.0

1 source article · read the reporting →

WF-7U454R4 Jun 2026

Reddit Scam Ads Reportedly Used Deepfake News Segments and Cloned Media Sites to Promote Allegedly Fake AI Investment Platforms

Sponsored Reddit ads reportedly impersonated the BBC, Financial Times, and The Guardian to promote purportedly fake AI investment platforms including Wencoin STX, Warrior Coin AI, and Nevo Coin. The campaign allegedly dressed the scam as legitimate financial journalism, using cloned publisher pages and deepfake-style news footage to pressure users into sharing contact details and making deposits.

Company involved
Scammers, Investment scam operators, Malvertising actors, Reddit ad buyers, Cloned news site operators
AI system involved
Deepfake technology, Reddit advertising platform, Reddit, Cloned news websites, Fraudulent registration websites, Personal-data collection systems, Fake AI investment platforms, Wencoin STX, Warrior C

Source: AI Incident Database · CC BY-SA 4.0

2 source articles · read the reporting →

WF-W25UVD1 Jun 2026

Humanoid Robot Identified as Likely Unitree G1 Reportedly Kicked Boy During Public Demonstration in Xinjiang

A boy in Xinjiang was reportedly struck in the abdomen by a humanoid robot during a public performance at a scenic-area amusement venue. The robot was reportedly performing martial-arts-style movements near children without clear barriers, and the child's mother said he was fortunately not seriously harmed. The machine was reportedly likely a Unitree G1, but the exact cause of the kick was not established.

Company involved
Urumqi Botanical Garden Amusement Park, Robotics deployers
AI system involved
Unitree G1, Humanoid robots, Robotics, Robotic motion control systems, Robot teleoperation systems, Public entertainment robot demonstration systems

Source: AI Incident Database · CC BY-SA 4.0

5 source articles · read the reporting →

WF-6B7FL331 May 2026

The Sydney Morning Herald and The Age Removed an Opinion Article After Undisclosed Copilot Use

The Sydney Morning Herald and The Age removed an opinion article by Western Sydney University academic Cath Ellis after reporting found it had been prepared with Microsoft Copilot without the masthead being informed. Ellis said she used Copilot to structure her own notes, while the masthead said the article did not meet its editorial standards on AI use.

Company involved
Cath Ellis, Western Sydney University, Educational communities
AI system involved
Copilot, Chatbots, Large language models

Source: AI Incident Database · CC BY-SA 4.0

1 source article · read the reporting →

WF-H7SX7E31 May 2026

Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

Hackers reportedly used Meta's AI support chatbot to take over high-profile Instagram accounts by allegedly convincing it to change account email information and trigger recovery flows. Reported targets included the Barack Obama White House account; the account of John F. Bentivegna, the Chief Master Sergeant of the Space Force; Sephora's account; and app researcher Jane Manchun Wong. Meta said the issue had been resolved.

Company involved
Meta, Instagram, hackers
AI system involved
Meta AI, Meta AI support chatbot, Instagram, Instagram account recovery system, Social media platforms, AI customer support systems, Automated account recovery systems, Large language models, Chatbots

Source: AI Incident Database · CC BY-SA 4.0

2 source articles · read the reporting →

WF-BLKLJV31 May 2026

Italian Mediaset Journalist Safiria Leccese's Image Was Reportedly Used in a Purportedly AI-Generated Fake Loan Scam

Italian media reported that scammers purportedly used AI to create fake social media profiles and a video impersonating Mediaset journalist Safiria Leccese, using her image and footage associated with her political-interview program Super Partes to promote a personal loan. Leccese said several people were deceived within an hour. After she contacted postal police, two additional fake profiles using her image were reportedly found and blocked.

Company involved
Scammers
AI system involved
Social media platforms, Deepfake technology, Synthetic audio generation technology

Source: AI Incident Database · CC BY-SA 4.0

2 source articles · read the reporting →

WF-2PVWQU30 May 2026

COEMPT Quality Assurance Engineers Allegedly Violated Indian CBSE Student Data Privacy Rights by Processing It with Google Gemini

The Hindu reported that vulnerabilities in the OnMark exam-marking portal used by India's Central Board of Secondary Education (CBSE) allegedly exposed sensitive student data, including answer-sheet images. Ethical hacker Nisarga Adhikary also alleged that COEMPT Eduteck quality-assurance scripts processed students' personal information through Google Gemini. CBSE said the vulnerabilities had been contained.

Company involved
Government of India, COEMPT Eduteck, Central Board of Secondary Education
AI system involved
Student answer-sheet databases, OnMark On-Screen Marking portal, Gemini, COEMPT automation scripts

Source: AI Incident Database · CC BY-SA 4.0

1 source article · read the reporting →

← Newerpage 2 of 154Older →

What this view leaves out

Above are the facts: who, what, when, and the reporting it came from. Every incident also carries our reading of it — how we got this, reference upstream, how exact that date is, date reported, industry, ai vendor or provider and more — along with totals and patterns across the whole record.

See what paid access includes