The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

92 incidents closest to “Vigilant ClientPortal” · matched on meaning · public reporting

WF-JH5L2X26 Mar 2021

Teleperformance plans AI webcam surveillance for home-working staff

Teleperformance, a global call centre company, told some staff it would install AI-powered webcams to monitor home-working infractions such as eating, phone use, or leaving desks. The system would randomly scan for breaches and send alerts to managers. After the Guardian inquired, the company said the remote scans would not be used in the UK, but the plan raised concerns from unions and MPs about invasive surveillance.

Company involved
Teleperformance

10 source articles · read the reporting →

WF-TX7ZJM8 Mar 2021

Verkada security breach exposes customer video and data

In March 2021, attackers compromised Verkada's platform and accessed video and image data from 97 customer organisations. The attackers used a misconfigured customer support server to gain access and viewed live video, accessed badge credentials for eight customers, and downloaded user lists. Verkada cut off access within hours and notified affected customers. The attacker, Tillie Kottmann, was later indicted by the U.S. Department of Justice.

Company involved
Verkada
AI system involved
Verkada Command platform with People Analytics

10 source articles · read the reporting →

WF-D2VR7O13 May 2025

Ramirez v. Humala (E.D. New York): AI-hallucinated content in court filing, Monetary sanction jointly imposed on counsel and firm; order…

The AI generated nonexistent case citations that were filed in court, misleading the court and opposing counsel.

1 source article · read the reporting →

WF-ROOO6W1 Apr 2019

Amazon coaches police on obtaining Ring footage without warrant

Amazon's Ring division provided police departments with templates and advice on how to request surveillance footage from Ring camera owners without a warrant. The company coached officers on using the Law Enforcement Neighborhood Portal and the Neighbors app to increase the number of residents who share footage. Critics argue this creates a dragnet surveillance system without proper oversight.

Company involved
Amazon (Ring)
AI system involved
Ring Law Enforcement Neighborhood Portal and Neighbors app

10 source articles · read the reporting →

WF-AAQNX125 Sep 2026

Aguilar v. The Crawford Group, Inc. (D. Massachusetts): AI-hallucinated content in court filing, Adverse Costs Order; Pro hac vice status…

The AI generated fake legal citations that were included in a court filing, misleading the court and opposing counsel.

Company involved
Lindemann Law Firm

1 source article · read the reporting →

WF-FST9Z61 Apr 2018

ViaQuatro's facial recognition system in São Paulo metro challenged in court

In April 2018, ViaQuatro installed the Digital Interactive Doors System, developed by AdMobilize, on the São Paulo metro's yellow line. The system used cameras to detect passengers' faces and claimed to infer their emotion, age, and gender in order to target advertisements. The Brazilian Institute of Consumer Protection (IDEC) filed a public civil action alleging that the system violated consumer and data protection laws by processing biometric data without consent and making pseudoscientific and discriminatory inferences. A judge ordered the cameras removed in August 2018, and the case is pending a final ruling.

Company involved
ViaQuatro
AI system involved
Digital Interactive Doors System (DID system)

10 source articles · read the reporting →

PwC develops facial recognition tool to monitor employees working from home

Accounting giant PwC has developed a facial recognition tool that logs when employees are absent from their computer screens while working from home. The tool, intended for financial institutions, requires workers to provide written reasons for any absences, including toilet breaks. Commentators have criticised the tool as a huge invasion of privacy, with concerns about damage to trust and increased stress. PwC stated that the technology is designed to help regulated institutions meet compliance obligations and that voluntary consent of traders is essential.

Company involved
PwC

8 source articles · read the reporting →

EPIC lawsuit challenges USPS secret surveillance program using facial recognition

The United States Postal Service's law enforcement wing, the Postal Inspection Service, ran a secret surveillance program called the Internet Covert Operations Program (iCOP) that used facial recognition from Clearview AI and social media monitoring tools to infiltrate online communities and monitor protests. The Electronic Privacy Information Center (EPIC) sued the USPS for failing to conduct and publish a privacy impact assessment as required by the E-Government Act. A federal district court dismissed the lawsuit on standing grounds, ruling that EPIC did not suffer a cognizable injury from the agency's refusal to disclose information about the program.

Company involved
United States Postal Service
AI system involved
Internet Covert Operations Program (iCOP)

10 source articles · read the reporting →

WF-4HFVHY13 Dec 2024

Character.AI accidentally exposes users' chat histories and personal data

Character.AI users reported being unexpectedly logged into strangers' accounts, exposing their chat histories, personas, and identifying information. The Google-backed chatbot company acknowledged the security lapse and said it quickly corrected the issue. The incident raises serious privacy concerns for the platform's users.

Company involved
Character.AI
AI system involved
Character.AI

1 source article · read the reporting →

WF-BQBMHB4 Aug 2023

WorldCoin suspended in Kenya over data security concerns

WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.

Company involved
Tools for Humanity GmbH
AI system involved
WorldCoin

10 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

WF-LEN91Y1 May 2021

US CBP deploys CBP One app using facial recognition for asylum seekers amid privacy concerns

The article reports that U.S. Customs and Border Protection quietly deployed the CBP One mobile app at the Mexico border. The app uses facial recognition and geolocation to collect and verify information on asylum seekers before they enter the United States. Privacy experts warn that the app poses risks of persistent surveillance and that the facial recognition algorithm is unreliable for people of colour. A previous CBP facial recognition pilot was hacked, exposing images. CBP says the app is voluntary and data is secure.

Company involved
U.S. Customs and Border Protection
AI system involved
CBP One

8 source articles · read the reporting →

WF-KPRZVQ1 Jan 2024

Met Police accessed PimEyes facial recognition site 2,000 times

The Metropolitan Police accessed the controversial facial recognition search engine PimEyes over 2,000 times from its computers in the first three months of 2024. The force stated that the hits did not necessarily mean searches were conducted, but after being alerted by i and Liberty Investigates, it blocked access to the site and strengthened safeguards. Privacy campaigners and MPs have raised concerns that the unregulated tool could be used for stalking and surveillance.

Company involved
Metropolitan Police Service
AI system involved
PimEyes

3 source articles · read the reporting →

AAIP investigates Worldcoin's personal data processing in Argentina

The Argentine Agency for Access to Public Information (AAIP) has initiated an investigation into the data processing practices of Worldcoin in Argentina. The investigation focuses on the collection, storage, and use of biometric data, including facial and iris scans, carried out in several cities in exchange for financial compensation. The AAIP aims to verify compliance with the country's data protection law, Ley 25.326, regarding sensitive data handling.

Company involved
Worldcoin (Fundación Worldcoin)
AI system involved
Worldcoin

8 source articles · read the reporting →

WF-2X3B7831 Jan 2024

Hong Kong privacy watchdog raids Worldcoin offices over iris scan data collection

Hong Kong's privacy commissioner's office raided six premises linked to Worldcoin, a cryptocurrency company that requires an eye scan from clients for identification. The watchdog is investigating whether the collection of iris scans could lead to sensitive information being compromised. The raids follow investigations into Worldcoin in other jurisdictions.

Company involved
Worldcoin

5 source articles · read the reporting →

WF-4N6UFD1 Mar 2021

Baltimore schools monitor student laptops for suicide signs using GoGuardian Beacon

Baltimore City Public Schools uses GoGuardian Beacon software to monitor student laptops for signs of suicide. Since March 2021, the system has flagged 786 alerts, with nine students taken to emergency rooms. Privacy advocates warn the monitoring could lead to disciplinary actions, outing of LGBTQ students, and disproportionately affect disadvantaged students. School officials defend the practice as a safeguard.

Company involved
Baltimore City Public Schools
AI system involved
GoGuardian Beacon

10 source articles · read the reporting →

WF-OWK2RT30 Jun 2025

Paradox security vulnerability exposed candidate data to researchers

On June 30, 2025, security researchers discovered a vulnerability in Paradox's test account that allowed access to chat interaction records. The researchers viewed five candidates' personal information including names, email addresses, phone numbers, and IP addresses. Paradox fixed the issue within hours and stated that no data was leaked publicly. The company has since implemented new security measures.

Company involved
Paradox
AI system involved
Paradox conversational AI platform

10 source articles · read the reporting →

DWP algorithm approved Kickstart gateways with no trading history or based abroad

An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.

Company involved
Department for Work and Pensions
AI system involved
Cabinet Office Spotlight Tool

3 source articles · read the reporting →

WF-KPQ2GA8 Aug 2024

Microsoft Copilot vulnerable to automated phishing and data theft

Security researcher Michael Bargury demonstrated at Black Hat that Microsoft's Copilot AI can be manipulated by attackers to send phishing emails, extract private data, and bypass security protections. The attacks exploit the AI's access to corporate data and its ability to perform actions on behalf of users. Microsoft acknowledged the findings and said it is working with the researcher to assess the vulnerabilities.

Company involved
Microsoft
AI system involved
Copilot

3 source articles · read the reporting →

Outabox hack exposes biometric data of patrons at bars, clubs and casinos

Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.

Company involved
Outabox

8 source articles · read the reporting →

WF-PQKZOM1 Jan 2016

Vumacam's AI CCTV system flagged 28 black people as suspicious in Johannesburg suburbs

In Johannesburg suburbs, Vumacam's AI-powered CCTV network using iSentry software flagged 28 black individuals as 'suspicious' in a shift report, according to a 2019 article. The system, deployed by private security firms, uses video analytics to detect abnormal behavior and alerts security guards. The article alleges that the system disproportionately targets people of color, reflecting racial bias in a racially divided country.

Company involved
Vumacam
AI system involved
iSentry

6 source articles · read the reporting →

42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE

SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.

AI system involved
OpenClaw

5 source articles · read the reporting →

School AI surveillance like Gaggle can lead to false alarms, arrests

AI surveillance tools used in schools, such as Gaggle, GoGuardian and Bark, are reported to generate false alarms that have led to student arrests. The article examines cases where automated monitoring flagged innocent behaviour as threats, causing harm to students and families.

2 source articles · read the reporting →

WF-OK0FGL20 Mar 2025

Lovable security flaw exposed user data from 170 apps

Lovable, a Swedish startup, failed to fix a critical security flaw in its vibe coding service. Researchers found 170 Lovable-created web apps that exposed users' personal data, including names, emails, financial information, and API keys. Lovable acknowledged the issue and implemented a security scan, but the flaw remained unresolved.

Company involved
Lovable
AI system involved
Lovable

5 source articles · read the reporting →

← Newerpage 3 of 4Older →