The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

92 incidents closest to “HCC Capture” · matched on meaning · public reporting

Hospitals use Epic AI to predict Covid-19 decline without validation

Dozens of hospitals across the US are using Epic's deterioration index AI system to predict which Covid-19 patients will become critically ill, despite the tool not being validated for the new disease. The rapid deployment during the pandemic bypassed normal testing and validation processes.

AI system involved
Deterioration index

9 source articles · read the reporting →

WF-OD83P526 May 2021

Google and HCA Healthcare partner to analyze 32 million patient records

Google Cloud has announced a partnership with HCA Healthcare to analyze around 32 million patient records. The anonymized data will be used to develop algorithms that could advise doctors on treatment options. Privacy advocates have raised concerns about the data sharing and the potential for AI to re-identify patients. HCA insists that patient-identifiable information will be stripped and that access will be tightly controlled.

Company involved
HCA Healthcare
AI system involved
Google Cloud

9 source articles · read the reporting →

WF-YWUJN81 Oct 2024

Company fires HR team after ATS auto-rejects manager's CV due to filtering error

A company's applicant tracking system (ATS) auto-rejected qualified candidates' resumes for three months because it was filtering for the outdated framework AngularJS instead of the required Angular framework. The manager discovered the flaw by submitting his own CV under a pseudonym and found it was rejected within seconds. After the manager reported the issue to upper management, the company investigated and dismissed half of its HR team. No legal action or regulatory involvement is reported.

4 source articles · read the reporting →

Face recognition bypass used to register shell companies for tax fraud in Shanghai

In a major tax fraud case in Shanghai, criminals used face recognition cracking techniques to register shell companies on government platforms. They purchased high-resolution photos and used apps to create fake videos, then used modified phones to bypass face recognition authentication. The scheme resulted in fraudulent invoices totaling over 500 million yuan. The case was prosecuted by the Shanghai procuratorate.

7 source articles · read the reporting →

WF-XHWUDY14 Jun 2022

Zhengzhou officials punished for red health codes on depositors

Five officials in Zhengzhou were punished for ordering red health codes to be assigned to 1,317 depositors of four village banks, restricting their movement and preventing them from withdrawing savings. The officials acted without authorization, and the codes were later turned green after media coverage. Legal experts say the liability for privacy invasion remains unresolved, and the banks may face breach of contract claims.

Company involved
Zhengzhou municipal government
AI system involved
Health code system

10 source articles · read the reporting →

WF-BQBMHB4 Aug 2023

WorldCoin suspended in Kenya over data security concerns

WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.

Company involved
Tools for Humanity GmbH
AI system involved
WorldCoin

10 source articles · read the reporting →

Perth hospital group bans ChatGPT after doctor used it for a patient discharge summary

South Metropolitan Health Service, which runs five hospitals in Perth, ordered staff to stop using ChatGPT for work involving patient information after an email said some staff had used the AI chatbot to write medical notes. The service later clarified that only one doctor had used the tool to generate a patient discharge summary and that no confidential patient information had been breached. The Australian Medical Association has called for national regulations to ensure a human is involved in AI-assisted health decisions.

Company involved
South Metropolitan Health Service
AI system involved
ChatGPT

6 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

DeepSeek-R1 censors 85% of sensitive Chinese political prompts in tests

Promptfoo tested DeepSeek-R1 against a dataset of 1,360 politically sensitive prompts and found that about 85% of them were refused. The refusals followed a standard form aligned with Chinese Communist Party policy. The testing also demonstrated that the censorship could be trivially bypassed using simple jailbreak techniques, such as prompt injection or changing the context.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

Researchers extract training data from ChatGPT using repeat prompt

Researchers from Google DeepMind and other institutions developed an attack that extracts verbatim training data from OpenAI's ChatGPT. By prompting the model to repeat a word forever, they caused it to output memorized personal information, including email addresses and phone numbers. The attack demonstrates that alignment techniques can be circumvented, and the researchers estimate that a gigabyte of training data could be extracted.

Company involved
OpenAI
AI system involved
ChatGPT

8 source articles · read the reporting →

WF-3333OU22 Sep 2021

EviCore denied heart catheterization for patient using algorithm

In fall 2021, Little John Cupp's doctor requested a left heart catheterization exam. EviCore, a company hired by UnitedHealthcare, denied the request twice using an algorithm called 'the dial' that adjusts thresholds for review. The algorithm flagged the request for review, and EviCore's doctors determined it was not medically necessary. Cupp did not receive the procedure and his symptoms continued.

Company involved
EviCore (a Cigna company)
AI system involved
the dial

6 source articles · read the reporting →

IRCC uses AI triage for Temporary Resident Visa applications

Immigration, Refugees and Citizenship Canada (IRCC) uses an AI system called Advanced Analytics to triage Temporary Resident Visa applications from India and China. The system categorizes applications into tiers, with Tier 1 approved automatically and others sent to human officers. Critics allege the system lacks transparency and may introduce bias, leading to visa refusals without clear rationale. The author, a Canadian immigration lawyer, is filing Federal Court cases on behalf of clients affected by refusals.

Company involved
Immigration, Refugees and Citizenship Canada (IRCC)
AI system involved
Advanced Analytics Triage of Overseas Temporary Resident Visa Applications

10 source articles · read the reporting →

WF-RTW1XZ25 Aug 2023

ChatGPT generates error-filled cancer treatment plans, study finds

A study by researchers at Brigham and Women's Hospital found that ChatGPT, developed by OpenAI, generated cancer treatment plans with errors. One-third of the chatbot's responses contained incorrect information, and 12.5% were hallucinated. The study was published in JAMA Oncology and reported by Bloomberg.

Company involved
OpenAI
AI system involved
ChatGPT

10 source articles · read the reporting →

WF-1XANCK10 Nov 2023

Meta's automated system mistakenly removes Al-Shifa hospital video

Meta's automated content moderation system removed an Instagram video showing the aftermath of a strike on Al-Shifa hospital in Gaza, citing its Violent and Graphic Content policy. The user appealed to the Oversight Board, which found that the removal was incorrect. Meta subsequently restored the content with a warning screen.

Company involved
Meta
AI system involved
Graphic and Violent Content classifier

10 source articles · read the reporting →

Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training

Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.

Company involved
Meta
AI system involved
Model Capability Initiative (MCI)

5 source articles · read the reporting →

WF-3OJOAW6 Mar 2024

AI image generators produce misleading election images, study finds

A study by the Center for Countering Digital Hate found that leading AI image generators, including Midjourney, DreamStudio, ChatGPT Plus, and Microsoft Image Creator, could be manipulated to create misleading election-related images. The researchers used jailbreaking techniques to bypass safety measures, producing photorealistic images of candidates in compromising situations or of voting fraud. The companies responded by stating they are updating policies and implementing safeguards, but the study suggests existing protections are inadequate.

Company involved
Midjourney, Stability AI, OpenAI, Microsoft
AI system involved
Midjourney, DreamStudio, ChatGPT Plus, Microsoft Image Creator

8 source articles · read the reporting →

WF-BMI81A1 Jan 2020

UNOS liver allocation policy reduces transplants in poorer states

The United Network for Organ Sharing (UNOS) implemented a new liver allocation policy in 2020 called the acuity circles system, which prioritizes the sickest patients regardless of location. An analysis by The Markup and The Washington Post found that the policy led to sharp declines in liver transplants in several Southern and Midwestern states and Puerto Rico, while increasing transplants in New York and California. Patients in affected states allege the system disadvantages poorer regions, and hospitals have sued to overturn the policy.

Company involved
United Network for Organ Sharing (UNOS)
AI system involved
Acuity circles liver allocation policy

10 source articles · read the reporting →

WF-2X3B7831 Jan 2024

Hong Kong privacy watchdog raids Worldcoin offices over iris scan data collection

Hong Kong's privacy commissioner's office raided six premises linked to Worldcoin, a cryptocurrency company that requires an eye scan from clients for identification. The watchdog is investigating whether the collection of iris scans could lead to sensitive information being compromised. The raids follow investigations into Worldcoin in other jurisdictions.

Company involved
Worldcoin

5 source articles · read the reporting →

WF-ZJEMQ525 Apr 2024

Huawei Pura 70 series AI editing tool removes clothing unintentionally

Huawei's Pura 70 series includes an AI retouching feature that can inadvertently remove clothing from images. Users on Weibo posted videos demonstrating this, raising privacy concerns. Huawei customer service acknowledged the issue, attributing it to algorithm loopholes, and promised a fix in upcoming system updates.

Company involved
Huawei
AI system involved
Pura 70 series AI retouching feature

5 source articles · read the reporting →

WF-VNNNUI22 May 2024

ICO investigates Microsoft's Recall feature for privacy risks

The UK Information Commissioner's Office (ICO) has issued a statement on 22 May 2024 regarding Microsoft's Recall feature. The ICO is making enquiries with Microsoft to understand the safeguards in place to protect user privacy, expecting transparency and necessity in data processing. This follows concerns that the feature may not adequately consider data protection from the outset before being brought to market.

Company involved
Microsoft
AI system involved
Recall

10 source articles · read the reporting →

WF-HCNIXO1 Dec 2007

Oxford Town Centre CCTV dataset used without consent for AI research

The Oxford Town Centre dataset is a CCTV video of pedestrians in Oxford, England, captured from a public surveillance camera without the knowledge or consent of the approximately 2,200 people shown. The footage was used in over 60 research projects, including commercial research by Amazon, Disney, and Huawei, for developing facial recognition, sex classification, and social distancing algorithms. The dataset was taken down in June 2020, but no remediation was provided to the individuals depicted.

Company involved
University of Oxford
AI system involved
Oxford Town Centre dataset

5 source articles · read the reporting →

WF-KPQ2GA8 Aug 2024

Microsoft Copilot vulnerable to automated phishing and data theft

Security researcher Michael Bargury demonstrated at Black Hat that Microsoft's Copilot AI can be manipulated by attackers to send phishing emails, extract private data, and bypass security protections. The attacks exploit the AI's access to corporate data and its ability to perform actions on behalf of users. Microsoft acknowledged the findings and said it is working with the researcher to assess the vulnerabilities.

Company involved
Microsoft
AI system involved
Copilot

3 source articles · read the reporting →

WF-1UJHJB1 Jan 2019

Tennessee's TennCare Connect algorithm illegally denied thousands Medicaid benefits

A U.S. District Court judge ruled that Tennessee's TennCare Connect system, built by Deloitte for over $400 million, illegally denied thousands of low-income residents and people with disabilities Medicaid and disability benefits due to programming and data errors. The system automatically terminated coverage without properly considering eligibility for all available programs. A class action lawsuit filed in 2020 resulted in the ruling.

Company involved
TennCare (Tennessee Medicaid)
AI system involved
TennCare Connect

10 source articles · read the reporting →

WF-15KEYQ1 Apr 2023

Deloitte software glitches wrongly remove Texans from Medicaid

Advocacy groups filed a complaint with the Federal Trade Commission alleging that Deloitte's eligibility software, TIERS, used by Texas Medicaid, wrongly disenrolled qualified recipients due to glitches. Nearly 1.8 million Texans lost coverage after the pandemic pause ended, with many errors attributed to procedural issues but some linked to system malfunctions. Deloitte denies the claims, while the state says it restored care for at least 90,000 people. The FTC has not yet responded to the complaint.

Company involved
Texas Health and Human Services Commission
AI system involved
TIERS

6 source articles · read the reporting →

← Newerpage 3 of 4Older →