The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

68 incidents closest to “Palantir AIP” · matched on meaning · public reporting

WF-HW23LM1 Dec 2023

Alibaba among firms fooled by AI-hallucinated software package

Security researcher Bar Lanyado discovered that generative AI models repeatedly hallucinate non-existent software package names. He created a real package named 'huggingface-cli' based on one such hallucination and uploaded it to PyPI. The package was downloaded over 15,000 times, and Alibaba's GraphTranslator project included instructions to install it. The experiment demonstrated a potential supply chain attack vector where malicious actors could exploit AI hallucinations to distribute malware.

Company involved
Alibaba
AI system involved
GraphTranslator

4 source articles · read the reporting →

WF-R72X6B10 Jul 2025

APT28 uses LLM-powered malware LAMEHUG against Ukraine's security and defence sector

CERT-UA reports that the threat group UAC-0001 (APT28) distributed phishing emails to Ukrainian executive bodies, impersonating a ministry representative. The emails contained a malicious attachment that deployed LAMEHUG, a Python-based tool which uses the Qwen 2.5-Coder-32B-Instruct large language model via Hugging Face to generate commands for data collection and exfiltration. The malware gathered system information and searched for Microsoft Office, TXT and PDF documents in common user directories, exfiltrating them via SFTP or HTTP POST requests.

Company involved
UAC-0001 (APT28)
AI system involved
LAMEHUG

2 source articles · read the reporting →

U.S. Department of Homeland Security Uses Secret Algorithm ATLAS to Flag Naturalized Citizens for Denaturalization

The U.S. Department of Homeland Security operates a secret algorithm called ATLAS that screens naturalized citizens for potential fraud or national security concerns, flagging them for denaturalization. The system, hosted on Amazon Web Services, analyzes biometric and other data from various federal databases, and its rules are undisclosed. Human reviewers then decide whether to refer flagged individuals to Immigration and Customs Enforcement for possible deportation. Critics allege the algorithm relies on inaccurate data and lacks transparency, leading to wrongful denaturalization proceedings.

Company involved
U.S. Department of Homeland Security
AI system involved
ATLAS

2 source articles · read the reporting →

WF-SRJT8X1 Dec 2016

Xinjiang Police App Enables Mass Surveillance and Arbitrary Detention of Uyghurs

Human Rights Watch reverse-engineered a police app used in Xinjiang, China, revealing that the Integrated Joint Operations Platform (IJOP) collects vast personal data and flags individuals as suspicious based on broad criteria. The system targets ethnic Uyghurs and Turkic Muslims, leading to mass arbitrary detention, forced indoctrination, and movement restrictions. The Chinese government operates the system, supplied by a subsidiary of CETC, and has not informed or obtained consent from those surveilled. The report calls for shutting down the system and releasing detainees.

Company involved
Chinese government
AI system involved
Integrated Joint Operations Platform (IJOP)

2 source articles · read the reporting →

WF-VBDC859 Apr 2026

Sullivan & Cromwell apologises for AI hallucinations in court filing

Sullivan & Cromwell, an elite Wall Street law firm, used an AI tool to help draft a court filing in the Prince Group case. The filing contained inaccurate citations and misquoted the US bankruptcy code due to AI hallucinations. The errors were uncovered by opposing counsel Boies Schiller Flexner, and the firm apologised to the judge and filed a corrected version. The firm stated that its AI policies were not followed and its review process failed to catch the mistakes.

Company involved
Sullivan & Cromwell

3 source articles · read the reporting →

WF-WEZFLW24 Apr 2026

PocketOS database and backups deleted by Cursor AI agent

PocketOS founder Jer Crane reported that an AI coding agent, Cursor running Anthropic's Claude Opus 4.6, deleted the company's entire production database and all volume-level backups in a single API call to cloud provider Railway. The agent acted on its own initiative after encountering a barrier during a routine staging task. Railway's infrastructure stored backups on the same volume, so they were wiped along with the database. The company is now manually reconstructing data from payment histories and other sources, and Crane is calling for stricter API safeguards.

Company involved
PocketOS
AI system involved
Cursor

3 source articles · read the reporting →

WF-VVTY7V19 Feb 2024

North Korean hackers use ChatGPT to scam LinkedIn users

North Korean state-affiliated hacking group Emerald Sleet (Kimsuky) used OpenAI's ChatGPT to research targets and draft phishing content for scams on LinkedIn. Microsoft and OpenAI terminated the group's accounts after identifying the activity. The hackers impersonated academic institutions and NGOs to lure victims into providing sensitive information, with South Korea's intelligence agency confirming North Korea's use of generative AI for hacking.

Company involved
OpenAI
AI system involved
ChatGPT

6 source articles · read the reporting →

341 Malicious ClawHub Skills Found Stealing OpenClaw User Data

Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.

Company involved
OpenClaw
AI system involved
OpenClaw

4 source articles · read the reporting →

WF-NAZJJM1 Jan 2018

Microsoft funded Israeli facial recognition firm surveilling West Bank Palestinians

Microsoft invested in AnyVision, an Israeli facial recognition company whose technology powers a secret military surveillance project in the West Bank. The system, called Better Tomorrow, identifies and tracks Palestinians in live camera feeds. Microsoft said it would audit AnyVision for compliance with its ethical principles.

Company involved
Israeli Defense Forces
AI system involved
Better Tomorrow

10 source articles · read the reporting →

Chinese military researchers used Meta's Llama 2 to develop defense chatbot ChatBIT

Chinese military researchers, including two affiliated with the People's Liberation Army, reportedly used Meta's Llama 2 AI model to develop a defense chatbot called ChatBIT. According to Reuters, the chatbot is designed to gather and process intelligence and offer information for operational decision-making. Meta stated that the use was unauthorized and contrary to its acceptable use policy.

Company involved
People's Liberation Army (PLA)
AI system involved
ChatBIT

6 source articles · read the reporting →

Finnish recruitment company Digital Minds used AI to analyze job applicants' messages, prompting data protection investigation

Digital Minds, a Finnish recruitment company founded by psychologists, used IBM Watson AI to analyze job applicants' social media and email messages for personality assessments. The company obtained written consent but the Finnish Data Protection Ombudsman launched an investigation, suspecting violations of data protection laws and the secrecy of correspondence. The service was used on fewer than ten applicants and has been paused pending the investigation.

Company involved
Digital Minds
AI system involved
IBM Watson

9 source articles · read the reporting →

Clearview AI tested facial recognition surveillance cameras with UFT and Rudin

Clearview AI, the facial recognition company that scraped billions of photos from social media, developed a surveillance camera system under the name Insight Camera. The system was tested by the United Federation of Teachers and Rudin Management in New York City. The UFT used it to identify individuals who had made threats and prevent them from entering its offices. Clearview did not respond to requests for comment.

Company involved
Clearview AI
AI system involved
Insight Camera

9 source articles · read the reporting →

WF-JH5L2X26 Mar 2021

Teleperformance plans AI webcam surveillance for home-working staff

Teleperformance, a global call centre company, told some staff it would install AI-powered webcams to monitor home-working infractions such as eating, phone use, or leaving desks. The system would randomly scan for breaches and send alerts to managers. After the Guardian inquired, the company said the remote scans would not be used in the UK, but the plan raised concerns from unions and MPs about invasive surveillance.

Company involved
Teleperformance

10 source articles · read the reporting →

AI companies trained on Hollywood writers' dialogue without consent

The Atlantic investigation found that dialogue from over 53,000 movies and 85,000 TV episodes was included in the OpenSubtitles data set used by Apple, Anthropic, Meta, Nvidia, Salesforce, and Bloomberg to train AI systems. The article alleges that this use of copyrighted material was done without permission from the writers.

4 source articles · read the reporting →

Campaigners call for end to Home Office's IPIC 'robo-caseworker' AI tool

Migrants' rights campaigners have called for the UK government to stop using the IPIC (Identify & Prioritise Immigration Cases) AI system, which automatically identifies and recommends migrants for immigration decisions or enforcement action. Privacy International and the Migrants' Rights Network have raised concerns that the system could lead to racial bias and the 'rubberstamping' of algorithmic recommendations by caseworkers. The campaigners argue that people going through the immigration system may not know their information has been processed by an algorithm. The Home Office has not directly responded to the specific concerns, though Science Secretary Peter Kyle has defended the safe development of AI in public services.

Company involved
Home Office
AI system involved
IPIC (Identify & Prioritise Immigration Cases)

9 source articles · read the reporting →

WF-HY5JT527 Nov 2024

Tow Center finds ChatGPT Search misattributes publisher content

The Tow Center for Digital Journalism tested ChatGPT Search with 200 block quotes from 20 publishers and found 153 partially or fully incorrect citations. The chatbot often conjured responses when it could not access content, sometimes citing plagiarized or syndicated versions. OpenAI responded that the study was atypical and that it supports publishers with clear links and attribution.

Company involved
OpenAI
AI system involved
ChatGPT Search

6 source articles · read the reporting →

WF-OGHTXE1 Jun 2025

Intellexa Predator spyware used to surveil human rights lawyer in Pakistan

In summer 2025, a human rights lawyer from Pakistan's Balochistan province was targeted via WhatsApp with Intellexa's Predator spyware, according to Amnesty International's Security Lab. The attack is part of a broader pattern of unlawful surveillance of activists, journalists and human rights defenders. The Intellexa Leaks investigation exposed internal operations of the spyware company, raising concerns about human rights due diligence.

AI system involved
Predator spyware

10 source articles · read the reporting →

OpenAI's CLIP vision system fooled by handwritten notes

OpenAI researchers discovered that their CLIP computer vision system can be deceived by handwritten labels placed on objects. The system's multimodal neurons respond to text as well as images, causing it to misidentify objects. The attack, called a typographic attack, is a research finding and not a deployed system. No actual harm occurred.

Company involved
OpenAI
AI system involved
CLIP

10 source articles · read the reporting →

WF-OK04L58 Jan 2025

OpenAI cuts off engineer who created ChatGPT-powered robotic sentry rifle

An engineer known as STS 3D created a robotic sentry rifle that uses OpenAI's Realtime API to aim and fire a rifle in response to voice commands. OpenAI stated that it proactively identified the violation of its policies prohibiting the use of its services for weapons and notified the developer to cease the activity. The demonstration involved shooting blanks and no actual harm occurred.

AI system involved
ChatGPT-powered robotic sentry rifle

4 source articles · read the reporting →

WF-3UCXWE1 Jul 2023

Study finds Midjourney, DALL-E 2, Stable Diffusion accept over 85% of fake news prompts

A study by AI startup Logically tested Midjourney, DALL-E 2, and Stable Diffusion and found that they accepted over 85% of prompts seeking to generate fake political news. The systems generated images of ballot stuffing, small boat arrivals, and explosions. Logically warned that the lack of moderation could pose threats to upcoming elections. Stability AI responded by stating its ethical use license and measures to prevent misuse.

Company involved
Midjourney, OpenAI, Stability AI
AI system involved
Midjourney, DALL-E 2, Stable Diffusion

8 source articles · read the reporting →

WF-UO2QO927 Jan 2025

OpenAI accuses DeepSeek of inappropriately using its data

OpenAI has accused Chinese AI company DeepSeek of inappropriately using data from its ChatGPT model to train DeepSeek's own large language model. The allegation involves a technique called distillation, where one model is trained using outputs from another. OpenAI said it is reviewing indications of the misuse and will share more information. DeepSeek has not responded to the accusation.

Company involved
DeepSeek
AI system involved
DeepSeek

6 source articles · read the reporting →

WF-MZCD6720 Sep 2023

Polish DPO investigates OpenAI over ChatGPT false data and lack of transparency

The Polish data protection authority (UODO) is investigating a complaint against OpenAI concerning ChatGPT. The complainant alleges that ChatGPT generated false information about him, and that OpenAI failed to correct it or disclose what data it holds, violating GDPR principles of lawfulness, fairness and transparency. The complainant also claims OpenAI did not fulfil its information obligations under Article 12 and Article 5(1)(a) GDPR. UODO has stated it will examine the systemic compliance of OpenAI's data processing with European data protection law.

Company involved
OpenAI
AI system involved
ChatGPT

9 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

WF-PMRIR418 Dec 2023

AI-driven Shadow Play network spreads pro-China propaganda on YouTube

The Australian Strategic Policy Institute (ASPI) revealed an extensive network of at least 30 YouTube channels, called Operation Shadow Play, that used generative AI to produce and publish pro-China and anti-US content. The network exploited YouTube's algorithmic recommendation system to cross-promote videos, gaining about 730,000 subscribers and 120 million views. The operation is alleged to be a coordinated influence campaign, possibly directed by a Mandarin-speaking controller, though the specific actor is unknown.

Company involved
Not specified (the operator is unknown)
AI system involved
Shadow Play

4 source articles · read the reporting →

← Newerpage 2 of 3Older →