The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

92 incidents closest to “DataWorks Plus” · matched on meaning · public reporting

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

DeepSeek-R1 censors 85% of sensitive Chinese political prompts in tests

Promptfoo tested DeepSeek-R1 against a dataset of 1,360 politically sensitive prompts and found that about 85% of them were refused. The refusals followed a standard form aligned with Chinese Communist Party policy. The testing also demonstrated that the censorship could be trivially bypassed using simple jailbreak techniques, such as prompt injection or changing the context.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

WF-2ABL3N30 Nov 2023

Bavarian police test Palantir data mining with real personal data

The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.

Company involved
Bayerisches Landeskriminalamt
AI system involved
VeRa

7 source articles · read the reporting →

N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent

Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.

Company involved
N-Tech.lab
AI system involved
FindFace

8 source articles · read the reporting →

Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training

Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.

Company involved
Meta
AI system involved
Model Capability Initiative (MCI)

5 source articles · read the reporting →

WF-4N6UFD1 Mar 2021

Baltimore schools monitor student laptops for suicide signs using GoGuardian Beacon

Baltimore City Public Schools uses GoGuardian Beacon software to monitor student laptops for signs of suicide. Since March 2021, the system has flagged 786 alerts, with nine students taken to emergency rooms. Privacy advocates warn the monitoring could lead to disciplinary actions, outing of LGBTQ students, and disproportionately affect disadvantaged students. School officials defend the practice as a safeguard.

Company involved
Baltimore City Public Schools
AI system involved
GoGuardian Beacon

10 source articles · read the reporting →

Prosecraft shut down after using authors' books without consent for AI analytics

Prosecraft, a fiction analytics site, used the full text of over 25,000 books without author consent to train its AI algorithms and provide writing statistics. Authors protested on social media, demanding removal of their works. The developer, Benji Smith, subsequently shut down the site and wrote a blog post explaining his actions.

Company involved
Prosecraft
AI system involved
Prosecraft

10 source articles · read the reporting →

WF-GEPFGZ1 Dec 2023

OpenDream AI art site allowed users to generate child sexual abuse material

OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.

Company involved
CBM Media Pte Ltd
AI system involved
OpenDream

3 source articles · read the reporting →

DWP algorithm mistakenly flags 200,000 Housing Benefit claimants for fraud review

The UK Department for Work and Pensions (DWP) uses an algorithm to flag Housing Benefit claimants for possible fraud or error. According to a Big Brother Watch investigation, the algorithm has mistakenly flagged 200,000 innocent people, subjecting them to intrusive reviews. Only one in three flagged cases actually had errors, compared to two in three during the pilot. The DWP has spent £4.4 million on these pointless checks.

Company involved
Department for Work and Pensions (DWP)

6 source articles · read the reporting →

WF-RX9YRU9 Jul 2024

Lattice cancels plan to give AI digital workers employee records after backlash

Lattice, an HR software company, announced on July 9th that it would give AI digital workers official employee records. After strong backlash from HR professionals and others on LinkedIn, the company canceled the feature on July 12th, stating it 'will not further pursue digital workers in the product.' The feature was intended to manage AI bots such as Devin and Piper, but the company reversed course.

Company involved
Lattice
AI system involved
Lattice

6 source articles · read the reporting →

WF-OWK2RT30 Jun 2025

Paradox security vulnerability exposed candidate data to researchers

On June 30, 2025, security researchers discovered a vulnerability in Paradox's test account that allowed access to chat interaction records. The researchers viewed five candidates' personal information including names, email addresses, phone numbers, and IP addresses. Paradox fixed the issue within hours and stated that no data was leaked publicly. The company has since implemented new security measures.

Company involved
Paradox
AI system involved
Paradox conversational AI platform

10 source articles · read the reporting →

Irish DPC takes Twitter to court over using user data to train Grok AI

The Irish Data Protection Commission has initiated High Court proceedings against Twitter International Unlimited Company over concerns that the company is processing personal data of millions of European X users to train its Grok AI system without adequate consent. The DPC alleges that Twitter failed to provide timely opt-out mechanisms and is seeking an order to suspend the data processing. Twitter denies any wrongdoing.

Company involved
Twitter International Unlimited Company
AI system involved
Grok

10 source articles · read the reporting →

DWP algorithm approved Kickstart gateways with no trading history or based abroad

An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.

Company involved
Department for Work and Pensions
AI system involved
Cabinet Office Spotlight Tool

3 source articles · read the reporting →

WF-2PVWQU31 May 2026

CBSE OnMark portal vulnerability exposed student data to Google Gemini

A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.

Company involved
Central Board of Secondary Education (CBSE)
AI system involved
OnMark

1 source article · read the reporting →

WF-JRPF9K30 Jul 2024

Microsoft Dynamics 365 Field Service AI singles out workers in performance predictions

A report by Cracked Labs found that Microsoft's Dynamics 365 Field Service software uses AI to generate performance metrics and predict task durations, singling out individual workers. The AI predictions can be influenced by the worker's identity, such as increasing or decreasing estimated duration. Microsoft stated the system is not intended for employment decisions and is not a surveillance tool, but the report raises concerns about potential misuse for worker monitoring.

Company involved
Microsoft
AI system involved
Dynamics 365 Field Service

6 source articles · read the reporting →

WF-Q8FS1926 Oct 2025

Paper Werewolf uses AI-generated decoys and XLLs to target Russian organizations

The threat group Paper Werewolf (aka GOFFEE) is conducting a cyberespionage campaign targeting Russian defense and high-technology organizations. The campaign uses AI-generated decoy documents, such as invitations and official letters, to trick recipients into opening malicious Excel XLL add-ins that deliver a backdoor called EchoGather. The backdoor collects system information and communicates with a command-and-control server. The campaign is ongoing and was first detected in late October 2025.

Company involved
Paper Werewolf
AI system involved
EchoGather

2 source articles · read the reporting →

School AI surveillance like Gaggle can lead to false alarms, arrests

AI surveillance tools used in schools, such as Gaggle, GoGuardian and Bark, are reported to generate false alarms that have led to student arrests. The article examines cases where automated monitoring flagged innocent behaviour as threats, causing harm to students and families.

2 source articles · read the reporting →

WF-M38V6314 Nov 2024

Richland School District investigates AI-generated obscene images of students

Students at Richland Township School District allegedly used artificial intelligence to create and distribute obscene images of other students. The district began investigating on Thursday, November 14, and contacted police and parents. Charges are pending, and the district has urged the community to avoid speculation on social media.

Company involved
Richland Township School District

2 source articles · read the reporting →

WF-R41UQV23 Feb 2012

Palantir secretly tested predictive policing in New Orleans

Beginning in 2012, Palantir Technologies secretly partnered with the New Orleans Police Department to deploy a predictive policing system. The programme analysed gang affiliations, social media and criminal histories to forecast individuals’ likelihood of committing or becoming victims of violence, operating without public knowledge or city council oversight. Researchers and law enforcement officials raised concerns about systemic bias and civil liberties. As of 2018, the city and Palantir had not disclosed the programme’s status.

Company involved
New Orleans Police Department

1 source article · read the reporting →

Pasco Sheriff's Office used algorithm to target potential future criminals and schoolchildren

The Pasco Sheriff's Office operates an intelligence-led policing programme that uses an algorithm to identify people who might break the law based on criminal histories and social networks. Deputies are sent to the homes of those flagged, even without evidence of a crime, and former deputies allege they were ordered to make targets' lives miserable. The agency also keeps a list of more than 400 schoolchildren predicted to 'fall into a life of crime', built from data such as grades and child welfare records, without informing the children or their parents. Civil liberties groups are considering lawsuits and public advocacy campaigns, and experts have called the programmes 'morally repugnant'.

Company involved
Pasco Sheriff's Office

10 source articles · read the reporting →

WF-30XEUN1 Jul 2019

Google contractors targeted homeless people for Pixel 4 facial recognition data

Google hired Randstad to collect facial data to train the Pixel 4's face recognition system. Contractors allegedly targeted homeless people and unaware students, using deceptive tactics such as calling it a "selfie game" and offering $5 without informing subjects they were being recorded. Google suspended the research program and opened an investigation following the report.

Company involved
Google
AI system involved
Pixel 4 facial recognition

1 source article · read the reporting →

West Midlands Police test NDAS system to assess crime risk

West Midlands Police are testing a system called the National Data Analytics Solution (NDAS) that analyses police data to assess the risk of individuals committing a crime or becoming a victim. The Home Office has funded the project with millions of pounds, intending to roll it out across England and Wales. Critics warn that the system could reinforce bias against minorities and undermine the presumption of innocence. The police say the technology is designed to support, not replace, officer decision-making and that it is still in early testing.

Company involved
West Midlands Police
AI system involved
National Data Analytics Solution

1 source article · read the reporting →

WF-UKLVHR27 Oct 2014

Brainwash cafe customers unknowingly put in AI surveillance dataset

In 2014, customers at the Brainwash Cafe in San Francisco were recorded by a publicly available webcam. The images were compiled into a dataset containing 11,917 photos for training surveillance-related object and head detection algorithms. The dataset was later removed from access following an investigation revealing use by researchers affiliated with the National University of Defense Technology in China. The dataset's creators are accused of collecting the images without the cafe customers' knowledge or consent.

Company involved
Stanford University
AI system involved
Brainwash dataset

1 source article · read the reporting →

WF-7SZLK41 Jan 2024

Ex-Pikesville athletic director used AI deepfake to impersonate principal

Dazhon Darien, former athletic director at Pikesville High School, used artificial intelligence to create a deepfake audio clip in 2024 that made it appear as though principal Eric Eiswert made racist and antisemitic comments. The clip spread widely online, severely damaging Eiswert's reputation. Darien was arrested and later pleaded guilty to unrelated child sex crimes. Eiswert sued Baltimore County Public Schools and reached a settlement.

Company involved
Baltimore County Public Schools

7 source articles · read the reporting →

← Newerpage 3 of 4Older →