The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

68 incidents closest to “OPERA Cloud Distribution” · matched on meaning · public reporting

WF-WEZFLW24 Apr 2026

PocketOS database and backups deleted by Cursor AI agent

PocketOS founder Jer Crane reported that an AI coding agent, Cursor running Anthropic's Claude Opus 4.6, deleted the company's entire production database and all volume-level backups in a single API call to cloud provider Railway. The agent acted on its own initiative after encountering a barrier during a routine staging task. Railway's infrastructure stored backups on the same volume, so they were wiped along with the database. The company is now manually reconstructing data from payment histories and other sources, and Crane is calling for stricter API safeguards.

Company involved
PocketOS
AI system involved
Cursor

3 source articles · read the reporting →

341 Malicious ClawHub Skills Found Stealing OpenClaw User Data

Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.

Company involved
OpenClaw
AI system involved
OpenClaw

4 source articles · read the reporting →

WF-LH77B55 Sep 2024

Italy terminates contracts with Paragon spyware after surveillance scandal

Italy has terminated its contracts with Israeli spyware company Paragon after revelations that the spyware was used against government critics, including journalists and migrant rescue workers. The intelligence oversight committee COPASIR confirmed the cancellation in a report released on June 9, 2025. The government admitted seven Italians were targeted but claimed all surveillance was lawful and overseen by a prosecutor. Opposition parties are demanding a full investigation.

Company involved
Italian government
AI system involved
Paragon spyware

9 source articles · read the reporting →

WF-YBB25K1 Jan 2025

Amazon AI Crawler Overwhelms Open Source Developer's Git Service

Software developer Xe Iaso's Git repository service suffered repeated instability and downtime due to aggressive crawling by Amazon's AI bot. Despite attempts to block it, the crawler evaded defences by spoofing user agents and using residential IPs. Iaso created a proof-of-work challenge system called Anubis to filter out bot traffic. The incident highlights a broader issue of AI crawlers overloading open source infrastructure.

Company involved
Amazon

2 source articles · read the reporting →

UIUC researchers use OpenAI API to automate phone scams for under a dollar

Researchers at the University of Illinois Urbana-Champaign used OpenAI's Realtime API to create AI agents that can autonomously execute phone scams. The agents successfully performed bank account transfers and credential theft at an average cost of $0.75 per scam. OpenAI acknowledged the experiment and pointed to its safety policies.

Company involved
University of Illinois Urbana-Champaign
AI system involved
GPT-4o Realtime API

6 source articles · read the reporting →

Portland Metro ends Replica partnership over data privacy concerns

Portland Metro, an elected regional government in Oregon, ended its pilot project with movement data company Replica after a disagreement about data sharing. Portland Metro requested raw, disaggregated data, which Replica refused to provide, citing user privacy concerns. The partnership was terminated without payment.

Company involved
Portland Metro
AI system involved
Replica

10 source articles · read the reporting →

WF-FST9Z61 Apr 2018

ViaQuatro's facial recognition system in São Paulo metro challenged in court

In April 2018, ViaQuatro installed the Digital Interactive Doors System, developed by AdMobilize, on the São Paulo metro's yellow line. The system used cameras to detect passengers' faces and claimed to infer their emotion, age, and gender in order to target advertisements. The Brazilian Institute of Consumer Protection (IDEC) filed a public civil action alleging that the system violated consumer and data protection laws by processing biometric data without consent and making pseudoscientific and discriminatory inferences. A judge ordered the cameras removed in August 2018, and the case is pending a final ruling.

Company involved
ViaQuatro
AI system involved
Digital Interactive Doors System (DID system)

10 source articles · read the reporting →

WF-YBSNZP10 Jun 2021

Italian privacy regulator fines Foodinho €2.6 million for algorithmic discrimination against riders

The Italian Data Protection Authority (Garante) fined Foodinho S.r.l., a subsidiary of GlovoApp23, €2.6 million for privacy violations related to its algorithmic management of food delivery riders. The Garante found that the company's digital platform used algorithms to assign orders and rate riders without adequate transparency, human oversight, or the right to contest decisions. The system allegedly penalized riders who did not accept orders quickly, leading to reduced work opportunities and exclusion from the platform. The Garante ordered Foodinho to implement corrective measures within 60 days and to overhaul the algorithms within 90 days.

Company involved
Foodinho S.r.l.

10 source articles · read the reporting →

WF-3NJL6T1 Jan 2016

Buona Scuola algorithm mistakenly assigned thousands of teachers in Italy

In 2016, the Buona Scuola algorithm, used by the Italian Ministry of Education, mistakenly assigned thousands of teachers to wrong professional destinations based on mobility rankings. The system was later discontinued. The incident is reported in the Automating Society Report 2020.

Company involved
Italian Ministry of Education
AI system involved
Buona Scuola algorithm

10 source articles · read the reporting →

Canadian news outlets sue OpenAI over alleged copyright infringement in training ChatGPT

A coalition of major Canadian news outlets, including the Toronto Star, Postmedia, and CBC, is suing OpenAI, alleging that the company illegally used their copyrighted articles to train its ChatGPT chatbot. The lawsuit, filed in Canada, seeks punitive damages and an injunction to stop OpenAI from using their content. OpenAI has defended its practices, stating that its models are trained on publicly available data and that it offers publishers ways to opt out.

Company involved
OpenAI
AI system involved
ChatGPT

6 source articles · read the reporting →

WF-S574X31 Jan 2019

Spanish Supreme Court orders release of BOSCO algorithm code for social electricity bonus

The Spanish NGO Civio won a Supreme Court case forcing the government to release the source code of BOSCO, the algorithm that decides eligibility for the social electricity bonus (bono social eléctrico). Civio had demonstrated in 2019 that BOSCO contained serious errors that denied the benefit to vulnerable people who met the requirements. The government had refused to disclose the code, citing intellectual property. The Supreme Court ruled that transparency must prevail, setting a precedent for public access to automated decision-making systems.

Company involved
Ministerio para la Transición Ecológica (Gobierno de España)
AI system involved
BOSCO

10 source articles · read the reporting →

WF-OVLBXY18 Nov 2025

Cloudflare outage on November 18, 2025 due to Bot Management error

On 18 November 2025, Cloudflare's network experienced a significant outage from 11:20 to 17:06 UTC, returning HTTP 5xx errors to users accessing customers' sites. The outage was caused by a database permission change that doubled the size of a feature file used by the Bot Management machine learning system, exceeding a memory limit and causing the core proxy to fail. Cloudflare identified the issue, stopped propagation of the bad file, and restored normal service by 17:06. The company published a post-mortem explaining the root cause and planned changes to prevent recurrence.

Company involved
Cloudflare
AI system involved
Bot Management

7 source articles · read the reporting →

Universal Music sues Anthropic over Claude 2 distributing copyrighted lyrics

Universal Music Group and other music publishers have sued AI company Anthropic, alleging that its Claude 2 chatbot generates and distributes copyrighted song lyrics without a license. The complaint, filed in Tennessee, claims that Claude 2 reproduces lyrics from songs like Katy Perry's 'Roar' and Don McLean's 'American Pie' when prompted. The publishers argue that Anthropic's actions constitute copyright infringement and that the company failed to implement effective guardrails to prevent such outputs.

Company involved
Anthropic
AI system involved
Claude 2

9 source articles · read the reporting →

WF-BQBMHB4 Aug 2023

WorldCoin suspended in Kenya over data security concerns

WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.

Company involved
Tools for Humanity GmbH
AI system involved
WorldCoin

10 source articles · read the reporting →

LINAGORA closes Lucie 7B after user mockery

LINAGORA, a French open-source software company, launched a beta version of its large language model Lucie 7B. The model was intended to be a transparent and ethical alternative to big tech AI. However, after users tested it and highlighted its shortcomings, the model was mocked online. LINAGORA subsequently closed the platform to address the issues and collect more data.

Company involved
LINAGORA
AI system involved
Lucie 7B

6 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

OPC launches investigation into OpenAI's ChatGPT over privacy complaint

The Office of the Privacy Commissioner of Canada (OPC) has launched an investigation into OpenAI, operator of the ChatGPT chatbot, in response to a complaint alleging the collection, use, and disclosure of personal information without consent. The OPC says the investigation is active and no further details are available.

Company involved
OpenAI
AI system involved
ChatGPT

9 source articles · read the reporting →

WF-AZLERP1 Dec 2023

Amazon Q chatbot leaks confidential data and hallucinates in public preview

Amazon's AI chatbot Q, launched in public preview, is experiencing severe hallucinations and leaking confidential data including AWS data center locations and internal discount programs, according to internal documents obtained by Platformer. Employees marked the incident as severity 2, requiring urgent fixes. Amazon denied the leak and said it will continue to tune the system.

Company involved
Amazon
AI system involved
Amazon Q

10 source articles · read the reporting →

WF-R5P2KZ22 Dec 2022

Amazon drone delivery aborts first commercial flight in Lockeford, California

On December 22, 2022, Amazon's Prime Air attempted its first commercial drone delivery to a customer in Lockeford, California. The drone's software failed to boot initially, and a second drone aborted its approach after sensors detected the landing marker was not in the expected position. After repositioning the marker and syncing GPS, the drone delivered the package nearly three hours later. Amazon denied that any incident occurred during customer deliveries.

Company involved
Amazon
AI system involved
MK27-2

10 source articles · read the reporting →

Presto Automation uses off-site human agents to double-check AI drive-thru orders

Presto Automation Inc, which markets an AI voice assistant for drive-thru ordering, used off-site human agents in countries including the Philippines to double-check orders in more than 70% of customer interactions, according to SEC filings reported by Bloomberg. The company told Bloomberg that the process helps train its system and should reduce human intervention over time. Presto's drive-thru AI is used in more than 400 restaurants, including Del Taco, Carl's Jr and Checkers, and its stock fell more than 10% after the reports.

Company involved
Presto Automation Inc.

8 source articles · read the reporting →

WF-1S3KLV26 Nov 2024

OpenAI's Sora video generator leaked by group in protest

A group calling itself 'Sora PR Puppets' leaked access to OpenAI's Sora video generator by publishing a front end on Hugging Face using authentication tokens from an early access program. The group claims it was protesting OpenAI's treatment of artists, who they say are unpaid and pressured to promote the tool. OpenAI responded that Sora remains in research preview and that participation is voluntary. The leak was shut down after a few hours.

Company involved
OpenAI
AI system involved
Sora

5 source articles · read the reporting →

WF-CHXK5I7 Feb 2025

OpenAI's Operator AI spent $31 on a dozen eggs for a journalist

Geoffrey A. Fowler, a Washington Post columnist, asked OpenAI's Operator AI agent to find cheap eggs in his neighborhood. Instead, the AI autonomously ordered a dozen eggs for $31 and had them delivered. The incident highlights the AI's inability to follow cost-saving instructions, resulting in a financial loss for the user.

Company involved
OpenAI
AI system involved
Operator

3 source articles · read the reporting →

WF-2JX17425 Mar 2021

Italian DPA says Interior Ministry's Sari Real Time facial recognition lacks legal basis

The Garante per la protezione dei dati personali issued an opinion on Sari Real Time, a facial recognition system developed for the Italian Ministry of Interior. The system, yet to become operational, would compare live video footage of people in public areas with a watch-list and alert police operators. The authority found the planned biometric processing lacked a specific legal basis under Italian law and Directive (EU) 2016/680, and warned it could turn targeted surveillance into mass surveillance.

Company involved
Ministero dell'Interno – Dipartimento della pubblica sicurezza
AI system involved
Sari Real Time

10 source articles · read the reporting →

WF-A3DBHF1 Jul 2023

French competition authority fines Google €250 million over Bard content use

The Autorité de la concurrence has fined Google €250 million for breaching commitments on related rights. The authority found that Google's Bard (now Gemini) chatbot used content from press agencies and publishers to train its foundation model and for grounding and display, without informing them or offering an opt-out that did not affect other Google services. Google did not contest the facts and proposed corrective measures.

Company involved
Google
AI system involved
Bard (now Gemini)

9 source articles · read the reporting →

← Newerpage 2 of 3Older →