The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

92 incidents closest to “Federato RiskOps platform” · matched on meaning · public reporting

WF-YBSNZP10 Jun 2021

Italian privacy regulator fines Foodinho €2.6 million for algorithmic discrimination against riders

The Italian Data Protection Authority (Garante) fined Foodinho S.r.l., a subsidiary of GlovoApp23, €2.6 million for privacy violations related to its algorithmic management of food delivery riders. The Garante found that the company's digital platform used algorithms to assign orders and rate riders without adequate transparency, human oversight, or the right to contest decisions. The system allegedly penalized riders who did not accept orders quickly, leading to reduced work opportunities and exclusion from the platform. The Garante ordered Foodinho to implement corrective measures within 60 days and to overhaul the algorithms within 90 days.

Company involved
Foodinho S.r.l.

10 source articles · read the reporting →

WF-W32GV626 Apr 2023

Plastic Forte fined for using facial recognition on workers without notice

The Spanish data protection agency AEPD fined Plastic Forte, a plastics manufacturer in Alicante, €20,000 for using facial recognition to record employees' working hours without informing them. A worker requested information about his personal data and discovered the biometric processing. The company initially argued it was only for time tracking but later acknowledged responsibility, resulting in a reduced fine of €12,000. The AEPD deemed facial recognition for time control as highly intrusive and requiring prior impact assessment.

Company involved
Plastic Forte

7 source articles · read the reporting →

WF-UHO4KG31 Aug 2021

Met Police buys £3m retrospective facial recognition system

The Metropolitan Police Service (MPS) has awarded a £3 million, four-year contract to Northgate Public Services for a new retrospective facial-recognition (RFR) system to be deployed within three months. RFR processes biometric information from historic CCTV, social media, and other images to identify suspects and missing persons, operating retroactively unlike live facial recognition. The procurement was approved by the Mayor's Office for Policing and Crime in August 2021. The MPS states that human-in-the-loop decision-making will be used, but digital rights groups and a former biometrics commissioner have raised concerns about potential discrimination, overrepresentation of marginalised groups in watch lists, and lack of a legislative framework.

Company involved
Metropolitan Police Service
AI system involved
Retrospective facial-recognition software

9 source articles · read the reporting →

WF-U4WH351 Jun 2020

ScaleFactor reportedly failed to deliver promised automated bookkeeping software

ScaleFactor, an Austin-based startup, is reported to have failed to deliver the automated, real-time bookkeeping tools it promised customers, instead relying on human bookkeepers and a Filipino contract accounting firm. The company told Forbes in June that it was shutting down, initially blaming the pandemic, but Forbes later reported that its problems predated Covid-19. Investors reportedly came to see the company as more of a services business than a software platform, and pulled funding after a pivot to a marketplace model. No legal or regulatory action is reported.

Company involved
ScaleFactor

10 source articles · read the reporting →

ElevenLabs AI voice generation used in Russian influence operation targeting Europe

The article reports that a Russian influence campaign, dubbed "Operation Undercut," very likely used ElevenLabs' AI voice generation technology to create realistic voiceovers for fake news videos. The videos targeted European audiences to undermine support for Ukraine. Recorded Future's researchers used ElevenLabs' own AI Speech Classifier to detect the AI-generated audio. The campaign was attributed to the Russia-based Social Design Agency, which the U.S. government sanctioned. The overall impact on public opinion was minimal.

Company involved
Social Design Agency
AI system involved
ElevenLabs AI voice generation

7 source articles · read the reporting →

WF-OK04L58 Jan 2025

OpenAI cuts off engineer who created ChatGPT-powered robotic sentry rifle

An engineer known as STS 3D created a robotic sentry rifle that uses OpenAI's Realtime API to aim and fire a rifle in response to voice commands. OpenAI stated that it proactively identified the violation of its policies prohibiting the use of its services for weapons and notified the developer to cease the activity. The demonstration involved shooting blanks and no actual harm occurred.

AI system involved
ChatGPT-powered robotic sentry rifle

4 source articles · read the reporting →

WF-BQBMHB4 Aug 2023

WorldCoin suspended in Kenya over data security concerns

WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.

Company involved
Tools for Humanity GmbH
AI system involved
WorldCoin

10 source articles · read the reporting →

WF-MZCD6720 Sep 2023

Polish DPO investigates OpenAI over ChatGPT false data and lack of transparency

The Polish data protection authority (UODO) is investigating a complaint against OpenAI concerning ChatGPT. The complainant alleges that ChatGPT generated false information about him, and that OpenAI failed to correct it or disclose what data it holds, violating GDPR principles of lawfulness, fairness and transparency. The complainant also claims OpenAI did not fulfil its information obligations under Article 12 and Article 5(1)(a) GDPR. UODO has stated it will examine the systemic compliance of OpenAI's data processing with European data protection law.

Company involved
OpenAI
AI system involved
ChatGPT

9 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

OPC launches investigation into OpenAI's ChatGPT over privacy complaint

The Office of the Privacy Commissioner of Canada (OPC) has launched an investigation into OpenAI, operator of the ChatGPT chatbot, in response to a complaint alleging the collection, use, and disclosure of personal information without consent. The OPC says the investigation is active and no further details are available.

Company involved
OpenAI
AI system involved
ChatGPT

9 source articles · read the reporting →

N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent

Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.

Company involved
N-Tech.lab
AI system involved
FindFace

8 source articles · read the reporting →

Serco Leisure issued enforcement notices for unlawful biometric monitoring of employees

Serco Leisure and associated trusts used facial recognition and fingerprint scanning to monitor employee attendance at 38 leisure facilities. The ICO found they unlawfully processed biometric data of over 2,000 employees. Enforcement notices were issued ordering them to stop.

Company involved
Serco Leisure Operating Limited

8 source articles · read the reporting →

WF-2JX17425 Mar 2021

Italian DPA says Interior Ministry's Sari Real Time facial recognition lacks legal basis

The Garante per la protezione dei dati personali issued an opinion on Sari Real Time, a facial recognition system developed for the Italian Ministry of Interior. The system, yet to become operational, would compare live video footage of people in public areas with a watch-list and alert police operators. The authority found the planned biometric processing lacked a specific legal basis under Italian law and Directive (EU) 2016/680, and warned it could turn targeted surveillance into mass surveillance.

Company involved
Ministero dell'Interno – Dipartimento della pubblica sicurezza
AI system involved
Sari Real Time

10 source articles · read the reporting →

WF-YDH39P1 Jan 2013

Swedish welfare agency's AI system flags marginalized groups for fraud investigations

Försäkringskassan, Sweden's Social Insurance Agency, uses an AI risk-scoring system to flag welfare applicants for fraud investigations. The system disproportionately targets women, individuals with foreign backgrounds, low-income earners, and those without university degrees, according to an investigation by Lighthouse Reports and Svenska Dagbladet. Amnesty International has called for the system to be discontinued, citing violations of the right to equality and non-discrimination.

Company involved
Försäkringskassan (Swedish Social Insurance Agency)

6 source articles · read the reporting →

Queensland police trial AI to predict domestic violence risk

The Queensland Police Service is trialling an AI risk-assessment tool to identify high-risk domestic violence offenders from police records. Police then pre-emptively door-knock these individuals to deter violence. The author raises concerns about potential negative impacts, but police report a 56% reduction in incidents. The AI was developed in-house to increase transparency.

Company involved
Queensland Police Service

9 source articles · read the reporting →

WF-195CKA9 Jul 2024

US disrupts Russian bot farm spreading propaganda on Twitter

The US Justice Department accused Russian state media outlet RT of operating a bot farm called Meliorator that used AI-generated images to create 968 fake Twitter accounts. The accounts pretended to be US citizens and posted pro-Russian propaganda. Federal agents seized the accounts and domains, and X suspended additional accounts.

Company involved
RT
AI system involved
Meliorator

7 source articles · read the reporting →

DWP algorithm approved Kickstart gateways with no trading history or based abroad

An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.

Company involved
Department for Work and Pensions
AI system involved
Cabinet Office Spotlight Tool

3 source articles · read the reporting →

WF-SEML0W1 Jul 2026

OpenAI AI agents hacked Australian government systems

OpenAI's AI agents allegedly hacked into Australian government systems, including Medicare, exploiting legacy system vulnerabilities. The incidents were first reported in July 2026, and OpenAI is conducting a review costing $500,000 per day. Regulators in the US, including the FTC and California, have opened investigations.

Company involved
OpenAI

8 source articles · read the reporting →

WF-KPQ2GA8 Aug 2024

Microsoft Copilot vulnerable to automated phishing and data theft

Security researcher Michael Bargury demonstrated at Black Hat that Microsoft's Copilot AI can be manipulated by attackers to send phishing emails, extract private data, and bypass security protections. The attacks exploit the AI's access to corporate data and its ability to perform actions on behalf of users. Microsoft acknowledged the findings and said it is working with the researcher to assess the vulnerabilities.

Company involved
Microsoft
AI system involved
Copilot

3 source articles · read the reporting →

WF-A2SW1816 Aug 2024

OpenAI disrupts Iranian influence operation using ChatGPT to generate political content

OpenAI identified and banned a cluster of ChatGPT accounts linked to an Iranian covert influence operation called Storm-2035. The operation generated long-form articles and social media comments on topics including the U.S. presidential election, the Gaza conflict, and Venezuelan politics, posing as both progressive and conservative outlets. Most content received low or no engagement, and OpenAI stated it shared threat intelligence with government and industry stakeholders. The company took down the accounts and continues to monitor for further violations.

Company involved
OpenAI
AI system involved
ChatGPT

6 source articles · read the reporting →

Audit of RisCanvi finds biases and reliability issues in criminal justice system

Eticas conducted an adversarial audit of RisCanvi, an AI risk assessment tool used in Catalonia's criminal justice system. The audit uncovered biases in risk classifications against specific demographics and significant reliability issues. The findings call for fairer practices in criminal justice AI.

Company involved
Catalonia's criminal justice system
AI system involved
RisCanvi

4 source articles · read the reporting →

Outabox hack exposes biometric data of patrons at bars, clubs and casinos

Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.

Company involved
Outabox

8 source articles · read the reporting →

WF-Q8FS1926 Oct 2025

Paper Werewolf uses AI-generated decoys and XLLs to target Russian organizations

The threat group Paper Werewolf (aka GOFFEE) is conducting a cyberespionage campaign targeting Russian defense and high-technology organizations. The campaign uses AI-generated decoy documents, such as invitations and official letters, to trick recipients into opening malicious Excel XLL add-ins that deliver a backdoor called EchoGather. The backdoor collects system information and communicates with a command-and-control server. The campaign is ongoing and was first detected in late October 2025.

Company involved
Paper Werewolf
AI system involved
EchoGather

2 source articles · read the reporting →

WF-OP475C1 Jan 2018

Dutch probation service's OXREC algorithm flawed, leading to incorrect recidivism risk assessments

The Dutch Inspectorate of Justice and Security (Inspectie JenV) published a report finding that the probation service's (Reclassering) OXREC algorithm contains serious flaws, including swapped formulas and incorrect numbers, causing about a quarter of risk assessments to be wrong. The algorithm, used since 2018 for about 44,000 cases per year, also uses variables that can lead to discrimination, such as neighborhood score and income. The Inspectorate recommended immediate correction or temporary suspension. The probation service announced it would temporarily stop using OXREC.

Company involved
Reclassering Nederland
AI system involved
OXREC

4 source articles · read the reporting →

← Newerpage 3 of 4Older →