Finnish recruitment company Digital Minds used AI to analyze job applicants' messages, prompting data protection investigation
Digital Minds, a Finnish recruitment company founded by psychologists, used IBM Watson AI to analyze job applicants' social media and email messages for personality assessments. The company obtained written consent but the Finnish Data Protection Ombudsman launched an investigation, suspecting violations of data protection laws and the secrecy of correspondence. The service was used on fewer than ten applicants and has been paused pending the investigation.
- Company involved
- Digital Minds
- AI system involved
- IBM Watson
9 source articles · read the reporting →
Momus Analytics' jury-selection algorithm criticised for racial bias
Momus Analytics, a legal technology company, uses machine learning to rank potential jurors for attorneys. Experts and researchers who reviewed the company's patent application say the algorithm relies on demographic characteristics such as race, which may violate constitutional prohibitions against discriminatory jury selection. The company claims its software has helped secure verdicts worth over $940 million, but did not respond to requests for comment.
- Company involved
- Momus Analytics
- AI system involved
- Momus
9 source articles · read the reporting →
Europol cracks down on network using deepfake ads for crypto fraud
Europol and national authorities in Belgium, Bulgaria, Germany, and Israel arrested two people in November as part of a crackdown on a criminal network that used fraudulent online ads and AI-generated deepfake videos to lure victims into fake cryptocurrency investment platforms. The network allegedly laundered 700 million euros ($816 million) through the scheme, which Europol described as operating on an 'industrial' scale. The arrests were the second phase of an operation that had already led to nine arrests in October. The article does not name the suspects or firms targeted.
4 source articles · read the reporting →
Chinese tech companies patented Uyghur detection analytics
IPVM reported that Huawei, Megvii, SenseTime, and other Chinese tech companies filed patents in China for AI systems that can detect Uyghur ethnicity. The patents included Uyghur as a detectable attribute for facial recognition and image retrieval. The companies responded by saying they would amend or withdraw the patents, claiming the references were misunderstood or regrettable, while the technology is used by police for surveillance and targeting of Uyghurs.
10 source articles · read the reporting →
Teleperformance plans AI webcam surveillance for home-working staff
Teleperformance, a global call centre company, told some staff it would install AI-powered webcams to monitor home-working infractions such as eating, phone use, or leaving desks. The system would randomly scan for breaches and send alerts to managers. After the Guardian inquired, the company said the remote scans would not be used in the UK, but the plan raised concerns from unions and MPs about invasive surveillance.
- Company involved
- Teleperformance
10 source articles · read the reporting →
Study finds Italian car insurers charge more based on birthplace
A study by the Universities of Padua, Udine and Carnegie Mellon found that Italian car insurers, including Genertel, Mps, Quixa and Con.Te, use birthplace and citizenship in pricing algorithms, charging some drivers over €1,000 more. The practice was ruled against in a 2018 decree involving Linear, but the study says it continues. The companies contacted denied or explained the findings.
- Company involved
- Genertel, Mps, Quixa, Con.Te
8 source articles · read the reporting →
DeepScore markets facial and voice analysis app for trustworthiness scoring despite experts' doubts
DeepScore, a Tokyo-based company, is marketing an app that uses facial and voice recognition to score people's trustworthiness for lenders and insurers in Japan, Indonesia, Vietnam and the Philippines. The company says the app can detect deception with 70 per cent accuracy, but researchers and privacy advocates say there is no reliable scientific basis for such judgments and warn of discrimination and privacy harms. The chief executive said the system is only one part of lenders' and insurers' decision-making and that people can choose not to use it. Critics respond that an unequal balance of power makes consent difficult.
- Company involved
- DeepScore
- AI system involved
- DeepScore
6 source articles · read the reporting →
Huawei and Megvii tested Uyghur alarm facial recognition system
Huawei and Megvii conducted an interoperability test in 2018 that verified a 'Uyghur alarm' function in Megvii's facial recognition system, according to a confidential report found by IPVM. The system could identify Uyghur minorities and alert police. Huawei denied real-world application and deleted the report after IPVM inquired. Megvii denied targeting ethnic groups. The test report was publicly accessible on Huawei's European website.
- Company involved
- Huawei
- AI system involved
- Megvii Dynamic Face Recognition
10 source articles · read the reporting →
Denmark's Udbetaling Danmark welfare algorithm illegally surveilled millions
Udbetaling Danmark (UDK), Denmark's centralized welfare payment agency, used automated algorithms to check eligibility and detect fraud. The system collected personal data on millions of beneficiaries and their relatives, including non-beneficiaries, in what a think-tank called 'systematic surveillance'. A complaint to the Danish Data Protection Authority led to a ruling that the data collection violated GDPR, and UDK eventually deleted the illegally obtained data. The system also caused erroneous payments, including underpaying 300,000 pensioners by 94 million euros annually.
- Company involved
- Udbetaling Danmark
10 source articles · read the reporting →
Plastic Forte fined for using facial recognition on workers without notice
The Spanish data protection agency AEPD fined Plastic Forte, a plastics manufacturer in Alicante, €20,000 for using facial recognition to record employees' working hours without informing them. A worker requested information about his personal data and discovered the biometric processing. The company initially argued it was only for time tracking but later acknowledged responsibility, resulting in a reduced fine of €12,000. The AEPD deemed facial recognition for time control as highly intrusive and requiring prior impact assessment.
- Company involved
- Plastic Forte
7 source articles · read the reporting →
California regulator accuses Maxpread Technologies of using AI-generated fake CEO to scam investors
Maxpread Technologies allegedly used an AI-generated avatar to pose as its CEO in a YouTube video to deceive investors. The California DFPI issued cease and desist letters to Maxpread and four other companies for offering unqualified securities and making false promises. The regulator claims the companies promised high daily returns using AI trading, but these claims were false. Maxpread did not respond to requests for comment.
- Company involved
- Maxpread Technologies
8 source articles · read the reporting →
Intellexa Predator spyware used to surveil human rights lawyer in Pakistan
In summer 2025, a human rights lawyer from Pakistan's Balochistan province was targeted via WhatsApp with Intellexa's Predator spyware, according to Amnesty International's Security Lab. The attack is part of a broader pattern of unlawful surveillance of activists, journalists and human rights defenders. The Intellexa Leaks investigation exposed internal operations of the spyware company, raising concerns about human rights due diligence.
- AI system involved
- Predator spyware
10 source articles · read the reporting →
ScaleFactor reportedly failed to deliver promised automated bookkeeping software
ScaleFactor, an Austin-based startup, is reported to have failed to deliver the automated, real-time bookkeeping tools it promised customers, instead relying on human bookkeepers and a Filipino contract accounting firm. The company told Forbes in June that it was shutting down, initially blaming the pandemic, but Forbes later reported that its problems predated Covid-19. Investors reportedly came to see the company as more of a services business than a software platform, and pulled funding after a pivot to a marketplace model. No legal or regulatory action is reported.
- Company involved
- ScaleFactor
10 source articles · read the reporting →
ElevenLabs AI voice generation used in Russian influence operation targeting Europe
The article reports that a Russian influence campaign, dubbed "Operation Undercut," very likely used ElevenLabs' AI voice generation technology to create realistic voiceovers for fake news videos. The videos targeted European audiences to undermine support for Ukraine. Recorded Future's researchers used ElevenLabs' own AI Speech Classifier to detect the AI-generated audio. The campaign was attributed to the Russia-based Social Design Agency, which the U.S. government sanctioned. The overall impact on public opinion was minimal.
- Company involved
- Social Design Agency
- AI system involved
- ElevenLabs AI voice generation
7 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Bavarian police test Palantir data mining with real personal data
The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.
- Company involved
- Bayerisches Landeskriminalamt
- AI system involved
- VeRa
7 source articles · read the reporting →
N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent
Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.
- Company involved
- N-Tech.lab
- AI system involved
- FindFace
8 source articles · read the reporting →
BC Tribunal Confirms Companies Remain Liable for AI Chatbot-Created Information - Lexology
The AI chatbot provided inaccurate information to a user.
1 source article · read the reporting →
Teleperformance deploys AI to neutralise Indian call centre agents' accents
Teleperformance, the world's largest call centre operator, has announced it is using AI from Sanas to modify the accents of its Indian employees in real time. The technology, called accent translation, aims to make agents sound more neutral to native English speakers. The company invested $13 million in Sanas and gained exclusive rights. No specific incident of harm has been reported.
- Company involved
- Teleperformance
- AI system involved
- Sanas AI
6 source articles · read the reporting →
Spanish police bust $20M AI-powered investment scam
Spanish law enforcement, collaborating with international authorities, dismantled a $20 million investment scam that used AI-driven algorithms to deceive individuals and organizations. Six suspects were detained and assets, including luxury cars and cryptocurrency, were seized. The article does not report any compensation for victims.
5 source articles · read the reporting →
OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification
An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.
- Company involved
- OKX
- AI system involved
- OnlyFake
10 source articles · read the reporting →
Paradox security vulnerability exposed candidate data to researchers
On June 30, 2025, security researchers discovered a vulnerability in Paradox's test account that allowed access to chat interaction records. The researchers viewed five candidates' personal information including names, email addresses, phone numbers, and IP addresses. Paradox fixed the issue within hours and stated that no data was leaked publicly. The company has since implemented new security measures.
- Company involved
- Paradox
- AI system involved
- Paradox conversational AI platform
10 source articles · read the reporting →
Dutch probe into chatbots' voting advice raises EU AI Act risk for OpenAI, xAI, Mistral
A Dutch privacy probe into election advice has appeared to expose early violations of the EU AI Act's rules for general-purpose AI models by OpenAI, xAI and Mistral, according to MLex. The companies' chatbots provided distorted voting advice to users. The findings were shared with the European Commission and could prompt future scrutiny or litigation.
- Company involved
- OpenAI, xAI and Mistral
6 source articles · read the reporting →
Dutch DPA fines Clearview AI €30.5 million for GDPR violations
The Dutch Data Protection Authority fined Clearview AI €30.5 million for creating an illegal database of biometric codes scraped from social media without consent. The regulator accused the company of failing to inform individuals about how their data is used and continuing violations after investigation. Clearview AI denies the allegations, stating it has no presence in the Netherlands or EU and that the fine is unenforceable.
- Company involved
- Clearview AI
- AI system involved
- Clearview AI facial recognition database
7 source articles · read the reporting →