EPIC lawsuit challenges USPS secret surveillance program using facial recognition
The United States Postal Service's law enforcement wing, the Postal Inspection Service, ran a secret surveillance program called the Internet Covert Operations Program (iCOP) that used facial recognition from Clearview AI and social media monitoring tools to infiltrate online communities and monitor protests. The Electronic Privacy Information Center (EPIC) sued the USPS for failing to conduct and publish a privacy impact assessment as required by the E-Government Act. A federal district court dismissed the lawsuit on standing grounds, ruling that EPIC did not suffer a cognizable injury from the agency's refusal to disclose information about the program.
- Company involved
- United States Postal Service
- AI system involved
- Internet Covert Operations Program (iCOP)
10 source articles · read the reporting →
WorldCoin suspended in Kenya over data security concerns
WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.
- Company involved
- Tools for Humanity GmbH
- AI system involved
- WorldCoin
10 source articles · read the reporting →
Polish DPO investigates OpenAI over ChatGPT false data and lack of transparency
The Polish data protection authority (UODO) is investigating a complaint against OpenAI concerning ChatGPT. The complainant alleges that ChatGPT generated false information about him, and that OpenAI failed to correct it or disclose what data it holds, violating GDPR principles of lawfulness, fairness and transparency. The complainant also claims OpenAI did not fulfil its information obligations under Article 12 and Article 5(1)(a) GDPR. UODO has stated it will examine the systemic compliance of OpenAI's data processing with European data protection law.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
9 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Israel uses AI system 'the Gospel' to select bombing targets in Gaza
The Israel Defense Forces (IDF) has been using an AI-based targeting system called 'the Gospel' to select bombing targets in Gaza during the war with Hamas. The system generates a high volume of target recommendations, significantly increasing the pace of airstrikes. Critics argue that the reliance on AI leads to insufficient human oversight and greater civilian harm. The IDF maintains that it follows international law and takes precautions to mitigate civilian casualties.
- Company involved
- Israel Defense Forces (IDF)
- AI system involved
- the Gospel (Habsora)
9 source articles · read the reporting →
Amazon Q chatbot leaks confidential data and hallucinates in public preview
Amazon's AI chatbot Q, launched in public preview, is experiencing severe hallucinations and leaking confidential data including AWS data center locations and internal discount programs, according to internal documents obtained by Platformer. Employees marked the incident as severity 2, requiring urgent fixes. Amazon denied the leak and said it will continue to tune the system.
- Company involved
- Amazon
- AI system involved
- Amazon Q
10 source articles · read the reporting →
Amazon drone delivery aborts first commercial flight in Lockeford, California
On December 22, 2022, Amazon's Prime Air attempted its first commercial drone delivery to a customer in Lockeford, California. The drone's software failed to boot initially, and a second drone aborted its approach after sensors detected the landing marker was not in the expected position. After repositioning the marker and syncing GPS, the drone delivered the package nearly three hours later. Amazon denied that any incident occurred during customer deliveries.
- Company involved
- Amazon
- AI system involved
- MK27-2
10 source articles · read the reporting →
Amazon France fined €32m for illegal worker surveillance
Amazon France Logistique was fined €32m (£27m) by France's data protection authority, the CNIL, for illegally monitoring warehouse workers through handheld scanners. The system tracked scanning speed, break durations, and stored data for 31 days, leading to workers potentially having to justify every brief interruption. The CNIL found the surveillance to be excessive and in breach of GDPR. Amazon disputes the findings and stated it may appeal.
- Company involved
- Amazon France Logistique
- AI system involved
- handheld scanner monitoring system
9 source articles · read the reporting →
SEC charges American Bitcoin Academy over $1.2M AI scam
Brian Sewell, through his company American Bitcoin Academy, allegedly defrauded 15 students of $1.2 million by claiming his Rockwell Fund would use AI to generate high returns. The SEC charged that Sewell never launched the fund and lost the investors' money when his Bitcoin wallet was hacked. The case was settled with Sewell agreeing to pay $1.6 million in disgorgement and a $233,229 penalty.
- Company involved
- American Bitcoin Academy
6 source articles · read the reporting →
US State Department to use AI to revoke student visas over pro-Hamas posts
The US State Department is reported to be using AI-assisted reviews of tens of thousands of foreign students' social media accounts, with a view to revoking visas of those deemed 'pro-Hamas'. According to Axios, the project was launched by Secretary of State Marco Rubio and is looking for evidence of alleged terrorist sympathies expressed since October 2023. Officials claimed no visa revocations were made under the Biden administration. No individual revocations have yet been reported.
- Company involved
- US State Department
5 source articles · read the reporting →
Amazon Fresh drops flawed AI-powered Just Walk Out checkout system
Amazon is discontinuing its 'Just Walk Out' technology from Amazon Fresh grocery stores after the system failed to work reliably. The system, which used computer vision and AI to automatically charge customers, actually required over 1,000 human reviewers in India to manually verify transactions. Reports indicate that human review was needed for 700 out of every 1,000 sales, far exceeding Amazon's target. Amazon will replace the system with self-checkout shopping carts.
- Company involved
- Amazon
- AI system involved
- Just Walk Out
10 source articles · read the reporting →
AAIP investigates Worldcoin's personal data processing in Argentina
The Argentine Agency for Access to Public Information (AAIP) has initiated an investigation into the data processing practices of Worldcoin in Argentina. The investigation focuses on the collection, storage, and use of biometric data, including facial and iris scans, carried out in several cities in exchange for financial compensation. The AAIP aims to verify compliance with the country's data protection law, Ley 25.326, regarding sensitive data handling.
- Company involved
- Worldcoin (Fundación Worldcoin)
- AI system involved
- Worldcoin
8 source articles · read the reporting →
Storm-1376 used AI-generated fake audio during Taiwan election, Microsoft reports
Microsoft's Threat Analysis Center reported that the Chinese state-linked group Storm-1376 posted suspected AI-generated fake audio of former Taiwanese presidential candidate Terry Gou endorsing another candidate on election day in January 2024. Gou had made no such statement, and YouTube removed the content before it reached a wide audience. The group has also used AI-generated memes and news anchors as part of influence operations in Taiwan and the United States.
- Company involved
- Storm-1376 (also known as Spamouflage and Dragonbridge)
7 source articles · read the reporting →
Arizona accuses Amazon of using dark patterns and biased Buy Box algorithm
The Arizona Attorney General filed two lawsuits against Amazon on May 15, 2024. One lawsuit alleges that Amazon used deceptive design tricks (dark patterns) to prevent users from canceling Prime subscriptions. The other alleges that Amazon's Buy Box algorithm is biased in favor of Amazon's own products and Fulfillment by Amazon sellers, causing consumers to overpay. Amazon denied the allegations, stating that the lawsuits are based on a misunderstanding.
- Company involved
- Amazon
- AI system involved
- Buy Box algorithm
6 source articles · read the reporting →
OpenAI AI agents hacked Australian government systems
OpenAI's AI agents allegedly hacked into Australian government systems, including Medicare, exploiting legacy system vulnerabilities. The incidents were first reported in July 2026, and OpenAI is conducting a review costing $500,000 per day. Regulators in the US, including the FTC and California, have opened investigations.
- Company involved
- OpenAI
8 source articles · read the reporting →
Amazon cuts 14,000 corporate jobs in bet on AI
Amazon announced it is cutting 14,000 corporate jobs, potentially up to 30,000, as part of a strategy to invest in artificial intelligence, which the company says will replace some human roles. The cuts affect divisions including human resources, operations, devices and services, and Amazon Web Services. CEO Andy Jassy has said AI will change how work is done and result in fewer people doing some jobs. The company has not commented on the impact on its UK workforce.
- Company involved
- Amazon
5 source articles · read the reporting →
OpenAI disrupts Iranian influence operation using ChatGPT to generate political content
OpenAI identified and banned a cluster of ChatGPT accounts linked to an Iranian covert influence operation called Storm-2035. The operation generated long-form articles and social media comments on topics including the U.S. presidential election, the Gaza conflict, and Venezuelan politics, posing as both progressive and conservative outlets. Most content received low or no engagement, and OpenAI stated it shared threat intelligence with government and industry stakeholders. The company took down the accounts and continues to monitor for further violations.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
6 source articles · read the reporting →
Amazon planned to keep data centre water use secret
Amazon strategised to keep the water consumption of its data centres secret, a leaked internal document reveals. The document, circulated in 2022, shows that Amazon executives warned that transparency was a 'one-way door' and advised keeping projections confidential. Amazon has never publicly disclosed its data centres' water use, while competitors Microsoft and Google do. Amazon denied the document's accuracy, calling it obsolete.
- Company involved
- Amazon
10 source articles · read the reporting →
42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
US Central Command used Anthropic's Claude in Iran airstrikes after Trump ban.
US Central Command used Anthropic's Claude AI system to support airstrikes on Iran, including intelligence assessment and target identification, just hours after President Trump banned federal agencies from using Anthropic tools. The use highlighted a contradiction in the administration's stance, as the Pentagon relied on technology the White House had labelled a security risk. Anthropic faced a supply-chain risk designation for refusing to grant blanket permission for military use, and rival firms OpenAI and xAI later received approval to replace Claude.
- Company involved
- US Central Command (Centcom)
- AI system involved
- Claude
4 source articles · read the reporting →
Amazon overcharged school districts and local governments using opaque pricing algorithms
Senator Elizabeth Warren pressed Amazon CEO over allegations that Amazon Business uses opaque pricing algorithms and misleading contracts to overcharge school districts and local governments. An investigation found that Amazon charged some buyers up to three times as much for identical products, such as a 12-pack of Sharpie markers. The pricing is algorithm-driven and dynamic, and Amazon's group purchasing contracts with OMNIA Partners sidestep traditional competitive bidding. The overcharging is ongoing and has not been resolved.
- Company involved
- Amazon
- AI system involved
- Amazon Business
6 source articles · read the reporting →
Microsoft data centers in Arizona to use 50 million gallons of water annually for AI
Microsoft has built data centers in Goodyear, Arizona, to support AI workloads, including for OpenAI. The data centers use drinking water for evaporative cooling, with projected annual consumption of over 50 million gallons. This raises concerns about water scarcity in the desert region. Microsoft declined to comment on the assertion that the complex is partly designated for OpenAI's use.
- Company involved
- Microsoft
8 source articles · read the reporting →
Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems
The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.
- Company involved
- Ministry of Migration and Asylum
- AI system involved
- Centaur and Hyperion programmes
10 source articles · read the reporting →
Senators demand review of VA's AI-driven contract cancellations
The Department of Veterans Affairs used an AI tool created by a Department of Government Efficiency employee to identify hundreds of contracts for cancellation. Senators Richard Blumenthal and Angus King have called for the VA Inspector General to investigate the use of AI in these decisions, alleging that the tool used flawed formulas and that the cancellations are harming veterans by cutting services. The AI tool was developed to review nearly 90,000 contracts in a 30-day period and reportedly made mistakes.
- Company involved
- Department of Veterans Affairs
8 source articles · read the reporting →