UK Court of Appeal Finds South Wales Police's Automated Facial Recognition Unlawful
The UK Court of Appeal ruled that South Wales Police's use of Automated Facial Recognition (AFR) technology, known as AFR Locate, was unlawful and violated human rights. The court found that the legal framework gave officers too much discretion over watchlists and deployment, and the data protection impact assessment was inadequate. Civil liberties campaigner Ed Bridges brought the judicial review, alleging the technology was unlawfully intrusive. The court upheld the appeal on grounds of legality, data protection, and equality duties, and South Wales Police stated it would not appeal the decision.
- Company involved
- South Wales Police
- AI system involved
- AFR Locate
8 source articles · read the reporting →
Microsoft Recall still captures credit cards and passwords despite filter
The Register tested Microsoft Recall's sensitive information filter and found it frequently fails to block credit card numbers, passwords, and other personal data. The AI-powered screenshot tool, which is enabled by default on some new PCs, could expose users to identity theft if an attacker gains access. Microsoft declined to comment but has previously acknowledged the filter is not perfect and promised improvements. Privacy advocates warn that vulnerable users, such as domestic violence victims, could be particularly at risk.
- Company involved
- Microsoft
- AI system involved
- Recall
2 source articles · read the reporting →
Air Canada Chatbot Fabricates Discount, Leading to Court Case
Air Canada's customer service chatbot allegedly fabricated a discount during a conversation with a customer last year. The incident resulted in a court case against the airline. Insurer Armilla stated that its new AI mishap policy would have covered the loss from selling tickets at the discounted price if the chatbot was found to have underperformed.
- Company involved
- Air Canada
- AI system involved
- chatbot
6 source articles · read the reporting →
Swedish police fined for unlawful use of Clearview AI facial recognition
Sweden's data protection authority IMY fined the Swedish Police Authority €250,000 for unlawfully using Clearview AI's facial-recognition app. The police used the app between autumn 2019 and March 2020 without authorisation or a required data protection impact assessment. The IMY ordered the police to ensure Clearview AI deletes the data and to train employees to avoid future breaches.
- Company involved
- Swedish Police Authority
- AI system involved
- Clearview AI
3 source articles · read the reporting →
Italian regulator orders Como to stop facial recognition surveillance
The Italian Data Protection Authority (Garante) ordered the Municipality of Como to cease its use of a facial recognition system installed in Parco Tokamakhi near the main railway station. The system was intended to identify people under investigation or reported missing, and to detect suspicious behaviour. The Garante found that the municipality lacked a specific legal basis under national law for collecting and storing biometric data, and issued an injunction to conform to the law.
- Company involved
- Comune di Como
- AI system involved
- facial recognition system
9 source articles · read the reporting →
Teleperformance plans AI webcam surveillance for home-working staff
Teleperformance, a global call centre company, told some staff it would install AI-powered webcams to monitor home-working infractions such as eating, phone use, or leaving desks. The system would randomly scan for breaches and send alerts to managers. After the Guardian inquired, the company said the remote scans would not be used in the UK, but the plan raised concerns from unions and MPs about invasive surveillance.
- Company involved
- Teleperformance
10 source articles · read the reporting →
Study finds Italian car insurers charge more based on birthplace
A study by the Universities of Padua, Udine and Carnegie Mellon found that Italian car insurers, including Genertel, Mps, Quixa and Con.Te, use birthplace and citizenship in pricing algorithms, charging some drivers over €1,000 more. The practice was ruled against in a 2018 decree involving Linear, but the study says it continues. The companies contacted denied or explained the findings.
- Company involved
- Genertel, Mps, Quixa, Con.Te
8 source articles · read the reporting →
India's Aadhaar facial recognition risks excluding millions from vaccines
India's National Health Authority piloted an Aadhaar-based facial recognition system for authentication at COVID-19 vaccination centres, and made Aadhaar the preferred mode of registration. Rights groups and experts warned that millions of vulnerable people, including those without an Aadhaar ID, could be excluded or misidentified and denied vaccines. The system was tested in the eastern state of Jharkhand, with plans for nationwide rollout.
- Company involved
- National Health Authority
- AI system involved
- Aadhaar-based facial recognition system
10 source articles · read the reporting →
Facebook Allowed Age-Targeted Credit Card Ads Violating Its Policy
The Markup found that four companies—Aspiration, Hometap, Chime, and Varo Bank—ran Facebook ads for credit cards and home equity loans that were targeted by age, excluding users under 25 or 35. This practice violates Facebook's own anti-discrimination policy and may violate the Equal Credit Opportunity Act and California's Unruh Civil Rights Act. Facebook did not respond to requests for comment, and some advertisers said they would review their ad targeting.
- Company involved
- Facebook
- AI system involved
- Facebook Ad Platform
9 source articles · read the reporting →
ViaQuatro's facial recognition system in São Paulo metro challenged in court
In April 2018, ViaQuatro installed the Digital Interactive Doors System, developed by AdMobilize, on the São Paulo metro's yellow line. The system used cameras to detect passengers' faces and claimed to infer their emotion, age, and gender in order to target advertisements. The Brazilian Institute of Consumer Protection (IDEC) filed a public civil action alleging that the system violated consumer and data protection laws by processing biometric data without consent and making pseudoscientific and discriminatory inferences. A judge ordered the cameras removed in August 2018, and the case is pending a final ruling.
- Company involved
- ViaQuatro
- AI system involved
- Digital Interactive Doors System (DID system)
10 source articles · read the reporting →
GSMA fined €200,000 for facial recognition privacy violation at MWC
In 2021, Dr Anastasia Dedyukhina was invited to speak at Mobile World Congress in Barcelona. The organizers required her to upload biometric data (passport) online for identity verification, which she refused. She was then forced to attend virtually. She filed a complaint with the Spanish data protection agency (AEPD) along with Adam Leon Smith. Two years later, the AEPD fined GSMA €200,000 for infringing the privacy of nearly 20,000 attendees through the use of facial recognition without proper justification.
- Company involved
- GSMA
10 source articles · read the reporting →
Mercadona fined €2.5 million for facial recognition pilot
Mercadona, a Spanish supermarket chain, tested an early-detection system using facial recognition in 48 stores to identify people with judicial restraining orders. The system, which operated with court authorisation, notified police when such a person was detected. The Spanish data protection authority (AEPD) imposed a €2.5 million fine, which Mercadona paid, and the company has since removed the system citing legal uncertainty.
- Company involved
- Mercadona
- AI system involved
- Sistema de Detección Anticipada (Early Detection System)
10 source articles · read the reporting →
IRCC uses AI triage for Temporary Resident Visa applications
Immigration, Refugees and Citizenship Canada (IRCC) uses an AI system called Advanced Analytics to triage Temporary Resident Visa applications from India and China. The system categorizes applications into tiers, with Tier 1 approved automatically and others sent to human officers. Critics allege the system lacks transparency and may introduce bias, leading to visa refusals without clear rationale. The author, a Canadian immigration lawyer, is filing Federal Court cases on behalf of clients affected by refusals.
- Company involved
- Immigration, Refugees and Citizenship Canada (IRCC)
- AI system involved
- Advanced Analytics Triage of Overseas Temporary Resident Visa Applications
10 source articles · read the reporting →
Spanish police bust $20M AI-powered investment scam
Spanish law enforcement, collaborating with international authorities, dismantled a $20 million investment scam that used AI-driven algorithms to deceive individuals and organizations. Six suspects were detained and assets, including luxury cars and cryptocurrency, were seized. The article does not report any compensation for victims.
5 source articles · read the reporting →
Italian DPA says Interior Ministry's Sari Real Time facial recognition lacks legal basis
The Garante per la protezione dei dati personali issued an opinion on Sari Real Time, a facial recognition system developed for the Italian Ministry of Interior. The system, yet to become operational, would compare live video footage of people in public areas with a watch-list and alert police operators. The authority found the planned biometric processing lacked a specific legal basis under Italian law and Directive (EU) 2016/680, and warned it could turn targeted surveillance into mass surveillance.
- Company involved
- Ministero dell'Interno – Dipartimento della pubblica sicurezza
- AI system involved
- Sari Real Time
10 source articles · read the reporting →
AAIP investigates Worldcoin's personal data processing in Argentina
The Argentine Agency for Access to Public Information (AAIP) has initiated an investigation into the data processing practices of Worldcoin in Argentina. The investigation focuses on the collection, storage, and use of biometric data, including facial and iris scans, carried out in several cities in exchange for financial compensation. The AAIP aims to verify compliance with the country's data protection law, Ley 25.326, regarding sensitive data handling.
- Company involved
- Worldcoin (Fundación Worldcoin)
- AI system involved
- Worldcoin
8 source articles · read the reporting →
Swedish welfare agency's AI system flags marginalized groups for fraud investigations
Försäkringskassan, Sweden's Social Insurance Agency, uses an AI risk-scoring system to flag welfare applicants for fraud investigations. The system disproportionately targets women, individuals with foreign backgrounds, low-income earners, and those without university degrees, according to an investigation by Lighthouse Reports and Svenska Dagbladet. Amnesty International has called for the system to be discontinued, citing violations of the right to equality and non-discrimination.
- Company involved
- Försäkringskassan (Swedish Social Insurance Agency)
6 source articles · read the reporting →
Actor's AI-generated avatar used in Venezuelan propaganda campaign
An actor's digital replica was generated without consent and used to spread fake news in a Venezuelan propaganda campaign. The actor turned to Equity for help, but current laws provide few protections. Equity is campaigning for new personality rights to prevent such exploitation.
9 source articles · read the reporting →
AEMPS withdraws AI medicines tool MeQA after detecting errors
AEMPS launched MeQA, an artificial intelligence tool for answering public questions about medicines, on 13 May 2025. Two days later it withdrew the tool after detecting that some responses contained errors. The agency said that most answers were correct but that the errors could affect patient safety, and that it would restore the service as soon as possible.
- Company involved
- Agencia Española de Medicamentos y Productos Sanitarios (AEMPS)
- AI system involved
- MeQA
4 source articles · read the reporting →
Microsoft Copilot vulnerable to automated phishing and data theft
Security researcher Michael Bargury demonstrated at Black Hat that Microsoft's Copilot AI can be manipulated by attackers to send phishing emails, extract private data, and bypass security protections. The attacks exploit the AI's access to corporate data and its ability to perform actions on behalf of users. Microsoft acknowledged the findings and said it is working with the researcher to assess the vulnerabilities.
- Company involved
- Microsoft
- AI system involved
- Copilot
3 source articles · read the reporting →
Outabox hack exposes biometric data of patrons at bars, clubs and casinos
Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.
- Company involved
- Outabox
8 source articles · read the reporting →
AENA fined €10m for GDPR breach over facial recognition pilot
AENA, Spain's state-owned airport manager, was fined just over €10 million by the Spanish data protection agency for breaching the GDPR. During a pilot project of a new facial recognition system, AENA failed to submit a data protection impact assessment that complied with GDPR requirements. The company has one month from notification to lodge an appeal for reconsideration.
- Company involved
- AENA
6 source articles · read the reporting →
Italian DPA fines Municipality of Trento over AI surveillance projects
The Italian data protection authority (Garante) fined the Municipality of Trento €50,000 for two research projects, Marvel and Protector, that used AI to analyze video, audio, and social media data for public security purposes. The projects involved automated detection of risk events from surveillance cameras and microphones in public spaces, as well as monitoring social media for hate speech. The Garante found multiple violations of privacy law, including lack of a valid legal basis, insufficient anonymization, failure to conduct a data protection impact assessment, and inadequate transparency. The municipality is required to delete the unlawfully processed data.
- Company involved
- Comune di Trento
- AI system involved
- Marvel and Protector
9 source articles · read the reporting →
Italian Data Protection Authority Blocks Replika Chatbot Over Risks to Minors
On February 2, 2023, the Italian Data Protection Authority (Garante) issued an urgent order blocking the AI chatbot Replika from processing personal data of Italian users. The Garante found that Replika lacked effective age verification, allowing minors to potentially receive inappropriate content including sex-related replies, and that its privacy policy violated GDPR transparency requirements. The U.S.-based controller was given 20 days to report on compliance measures and may challenge the order within 60 days.
- AI system involved
- Replika
1 source article · read the reporting →