EPIC lawsuit challenges USPS secret surveillance program using facial recognition
The United States Postal Service's law enforcement wing, the Postal Inspection Service, ran a secret surveillance program called the Internet Covert Operations Program (iCOP) that used facial recognition from Clearview AI and social media monitoring tools to infiltrate online communities and monitor protests. The Electronic Privacy Information Center (EPIC) sued the USPS for failing to conduct and publish a privacy impact assessment as required by the E-Government Act. A federal district court dismissed the lawsuit on standing grounds, ruling that EPIC did not suffer a cognizable injury from the agency's refusal to disclose information about the program.
- Company involved
- United States Postal Service
- AI system involved
- Internet Covert Operations Program (iCOP)
10 source articles · read the reporting →
Australian police trial facial recognition for COVID quarantine compliance
Australian police in New South Wales, Victoria, and Western Australia are trialling facial recognition software from Genvis to monitor people in home quarantine. Individuals are required to take selfies when randomly checked, and the software verifies their location and identity. Privacy advocates and the UN have raised concerns about surveillance overreach and potential human rights violations. The trials are voluntary, but critics warn of inaccuracies and mission creep.
- Company involved
- New South Wales Police Force, Victoria Police, Western Australia Police
- AI system involved
- Genvis facial recognition software
10 source articles · read the reporting →
Google Health's diabetic retinopathy AI faced real-world issues in Thailand clinics
Google Health deployed a deep-learning system to screen for diabetic retinopathy in 11 clinics across Thailand. The AI was highly accurate in lab tests but rejected over a fifth of eye scans in real-world conditions due to poor lighting and slow internet. Patients whose scans were rejected had to visit specialists at other clinics, causing inconvenience and frustration for nurses. Google Health is now working with local staff to improve the system's workflow.
- Company involved
- Google Health
10 source articles · read the reporting →
Spanish Supreme Court orders release of BOSCO algorithm code for social electricity bonus
The Spanish NGO Civio won a Supreme Court case forcing the government to release the source code of BOSCO, the algorithm that decides eligibility for the social electricity bonus (bono social eléctrico). Civio had demonstrated in 2019 that BOSCO contained serious errors that denied the benefit to vulnerable people who met the requirements. The government had refused to disclose the code, citing intellectual property. The Supreme Court ruled that transparency must prevail, setting a precedent for public access to automated decision-making systems.
- Company involved
- Ministerio para la Transición Ecológica (Gobierno de España)
- AI system involved
- BOSCO
10 source articles · read the reporting →
Apple's Enhanced Visual Search raises privacy concerns over default data sharing
Apple's iOS 18 update introduced an 'Enhanced Visual Search' feature that automatically shares encrypted photo data with Apple to identify landmarks. The feature is enabled by default, requiring users to manually opt out, which has sparked privacy concerns. Critics argue it should be opt-in, given Apple's usual privacy standards. The article reports on the feature's design and the resulting debate, not on any specific harm to an individual.
- Company involved
- Apple
- AI system involved
- Enhanced Visual Search
5 source articles · read the reporting →
Study finds Midjourney, DALL-E 2, Stable Diffusion accept over 85% of fake news prompts
A study by AI startup Logically tested Midjourney, DALL-E 2, and Stable Diffusion and found that they accepted over 85% of prompts seeking to generate fake political news. The systems generated images of ballot stuffing, small boat arrivals, and explosions. Logically warned that the lack of moderation could pose threats to upcoming elections. Stability AI responded by stating its ethical use license and measures to prevent misuse.
- Company involved
- Midjourney, OpenAI, Stability AI
- AI system involved
- Midjourney, DALL-E 2, Stable Diffusion
8 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
IRCC uses AI triage for Temporary Resident Visa applications
Immigration, Refugees and Citizenship Canada (IRCC) uses an AI system called Advanced Analytics to triage Temporary Resident Visa applications from India and China. The system categorizes applications into tiers, with Tier 1 approved automatically and others sent to human officers. Critics allege the system lacks transparency and may introduce bias, leading to visa refusals without clear rationale. The author, a Canadian immigration lawyer, is filing Federal Court cases on behalf of clients affected by refusals.
- Company involved
- Immigration, Refugees and Citizenship Canada (IRCC)
- AI system involved
- Advanced Analytics Triage of Overseas Temporary Resident Visa Applications
10 source articles · read the reporting →
Bavarian police test Palantir data mining with real personal data
The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.
- Company involved
- Bayerisches Landeskriminalamt
- AI system involved
- VeRa
7 source articles · read the reporting →
French interior official used Google AI to refuse visas to two asylum seekers
A French interior ministry official used Google's AI to refuse visas to two female asylum seekers. The official boasted about this experiment in a memo presented to the administrative court. The case is now before the court.
- Company involved
- French Ministry of Interior
- AI system involved
- Google AI
3 source articles · read the reporting →
Meta's automated system mistakenly removes Al-Shifa hospital video
Meta's automated content moderation system removed an Instagram video showing the aftermath of a strike on Al-Shifa hospital in Gaza, citing its Violent and Graphic Content policy. The user appealed to the Oversight Board, which found that the removal was incorrect. Meta subsequently restored the content with a warning screen.
- Company involved
- Meta
- AI system involved
- Graphic and Violent Content classifier
10 source articles · read the reporting →
Met Police accessed PimEyes facial recognition site 2,000 times
The Metropolitan Police accessed the controversial facial recognition search engine PimEyes over 2,000 times from its computers in the first three months of 2024. The force stated that the hits did not necessarily mean searches were conducted, but after being alerted by i and Liberty Investigates, it blocked access to the site and strengthened safeguards. Privacy campaigners and MPs have raised concerns that the unregulated tool could be used for stalking and surveillance.
- Company involved
- Metropolitan Police Service
- AI system involved
- PimEyes
3 source articles · read the reporting →
Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training
Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.
- Company involved
- Meta
- AI system involved
- Model Capability Initiative (MCI)
5 source articles · read the reporting →
UIUC students petition to stop Proctorio exam proctoring over privacy concerns
A petition at the University of Illinois at Urbana-Champaign (UIUC) alleges that Proctorio, an online exam proctoring system, violates student privacy by accessing websites, downloads, screen content, and app settings. The petition claims the terms of service allow monitoring by 'any other means necessary', which students find unsettling. The petition, created on September 30, 2020, gathered 1,087 supporters but does not report any specific incident of harm. It calls on UIUC to discontinue use of Proctorio in favour of alternatives.
- Company involved
- UIUC
- AI system involved
- Proctorio
9 source articles · read the reporting →
OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification
An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.
- Company involved
- OKX
- AI system involved
- OnlyFake
10 source articles · read the reporting →
L'Observatoire de l'Europe uses AI to steal Euronews articles
Euronews reports that a site called L'Observatoire de l'Europe uses AI to generate a fake journalist named Jean Delaunay and automatically translate Euronews articles word-for-word, republishing them without permission. The site attributes all articles to the fake journalist. Euronews states that this happens daily and that the site will likely steal this article as well.
- Company involved
- L'Observatoire de l'Europe
6 source articles · read the reporting →
Dutch Ministry of Foreign Affairs used secret algorithm to score visa applicants based on nationality
The Dutch Ministry of Foreign Affairs used a secret algorithm called IOB to score short-stay visa applicants based on nationality, gender, and age. Applicants flagged as high risk were automatically moved to an intensive track with higher rejection rates and delays. The ministry's own data protection officer warned of potential ethnic discrimination, but the system continued to be used. The algorithm has profiled millions of applicants since 2015.
- Company involved
- Ministry of Foreign Affairs
- AI system involved
- IOB
10 source articles · read the reporting →
iBorderCtrl lie detector falsely flagged honest reporter as liar
A journalist testing Europe's iBorderCtrl virtual policeman at the Serbian-Hungarian border gave honest answers but was deemed a liar by the system, scoring 48 out of 100 with four false answers flagged. The Hungarian policeman said the result suggested further checks, though none were carried out. The reporter only learned of the result after filing a data access request under European privacy laws. Experts and transparency activists have criticised the technology as pseudoscientific and potentially discriminatory.
- Company involved
- iBorderCtrl consortium
- AI system involved
- Silent Talker / iBorderCtrl virtual policeman
10 source articles · read the reporting →
Eventbrite algorithm recommended illegal opioid sales to addiction recovery seekers
Eventbrite's recommendation algorithm promoted thousands of listings selling illegal prescription drugs like oxycodone and Xanax alongside addiction recovery events. The listings, which appeared in search results and related events, directed users to unlicensed online pharmacies. Eventbrite acknowledged the issue and removed the listings after WIRED alerted them.
- Company involved
- Eventbrite
- AI system involved
- Eventbrite recommendation algorithm
4 source articles · read the reporting →
Duke University recorded students' faces without proper consent for public dataset
In March 2014, Duke University researchers recorded thousands of students walking to class on campus without their knowledge or proper consent, creating the DukeMTMC dataset of over 2 million image frames. The dataset was placed on a public website and downloaded by academics, security contractors, and military researchers globally, including Chinese companies and military academies linked to surveillance of ethnic minorities. The university took down the public website in April 2019 after an Institutional Review Board investigation found the study deviated significantly from the approved protocol. The lead researcher apologized, stating he took full responsibility for his mistakes.
- Company involved
- Duke University
- AI system involved
- DukeMTMC
10 source articles · read the reporting →
Oxford Town Centre CCTV dataset used without consent for AI research
The Oxford Town Centre dataset is a CCTV video of pedestrians in Oxford, England, captured from a public surveillance camera without the knowledge or consent of the approximately 2,200 people shown. The footage was used in over 60 research projects, including commercial research by Amazon, Disney, and Huawei, for developing facial recognition, sex classification, and social distancing algorithms. The dataset was taken down in June 2020, but no remediation was provided to the individuals depicted.
- Company involved
- University of Oxford
- AI system involved
- Oxford Town Centre dataset
5 source articles · read the reporting →
OpenDream AI art site allowed users to generate child sexual abuse material
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
- Company involved
- CBM Media Pte Ltd
- AI system involved
- OpenDream
3 source articles · read the reporting →
Paradox security vulnerability exposed candidate data to researchers
On June 30, 2025, security researchers discovered a vulnerability in Paradox's test account that allowed access to chat interaction records. The researchers viewed five candidates' personal information including names, email addresses, phone numbers, and IP addresses. Paradox fixed the issue within hours and stated that no data was leaked publicly. The company has since implemented new security measures.
- Company involved
- Paradox
- AI system involved
- Paradox conversational AI platform
10 source articles · read the reporting →
DWP algorithm approved Kickstart gateways with no trading history or based abroad
An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.
- Company involved
- Department for Work and Pensions
- AI system involved
- Cabinet Office Spotlight Tool
3 source articles · read the reporting →