The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

116 incidents closest to “Federato RiskOps platform” · matched on meaning · public reporting

WF-MZCD6720 Sep 2023

Polish DPO investigates OpenAI over ChatGPT false data and lack of transparency

The Polish data protection authority (UODO) is investigating a complaint against OpenAI concerning ChatGPT. The complainant alleges that ChatGPT generated false information about him, and that OpenAI failed to correct it or disclose what data it holds, violating GDPR principles of lawfulness, fairness and transparency. The complainant also claims OpenAI did not fulfil its information obligations under Article 12 and Article 5(1)(a) GDPR. UODO has stated it will examine the systemic compliance of OpenAI's data processing with European data protection law.

Company involved
OpenAI
AI system involved
ChatGPT

9 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

OPC launches investigation into OpenAI's ChatGPT over privacy complaint

The Office of the Privacy Commissioner of Canada (OPC) has launched an investigation into OpenAI, operator of the ChatGPT chatbot, in response to a complaint alleging the collection, use, and disclosure of personal information without consent. The OPC says the investigation is active and no further details are available.

Company involved
OpenAI
AI system involved
ChatGPT

9 source articles · read the reporting →

IRCC uses AI triage for Temporary Resident Visa applications

Immigration, Refugees and Citizenship Canada (IRCC) uses an AI system called Advanced Analytics to triage Temporary Resident Visa applications from India and China. The system categorizes applications into tiers, with Tier 1 approved automatically and others sent to human officers. Critics allege the system lacks transparency and may introduce bias, leading to visa refusals without clear rationale. The author, a Canadian immigration lawyer, is filing Federal Court cases on behalf of clients affected by refusals.

Company involved
Immigration, Refugees and Citizenship Canada (IRCC)
AI system involved
Advanced Analytics Triage of Overseas Temporary Resident Visa Applications

10 source articles · read the reporting →

N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent

Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.

Company involved
N-Tech.lab
AI system involved
FindFace

8 source articles · read the reporting →

WF-ROMQCH5 Feb 2024

OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification

An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.

Company involved
OKX
AI system involved
OnlyFake

10 source articles · read the reporting →

Serco Leisure issued enforcement notices for unlawful biometric monitoring of employees

Serco Leisure and associated trusts used facial recognition and fingerprint scanning to monitor employee attendance at 38 leisure facilities. The ICO found they unlawfully processed biometric data of over 2,000 employees. Enforcement notices were issued ordering them to stop.

Company involved
Serco Leisure Operating Limited

8 source articles · read the reporting →

WF-2JX17425 Mar 2021

Italian DPA says Interior Ministry's Sari Real Time facial recognition lacks legal basis

The Garante per la protezione dei dati personali issued an opinion on Sari Real Time, a facial recognition system developed for the Italian Ministry of Interior. The system, yet to become operational, would compare live video footage of people in public areas with a watch-list and alert police operators. The authority found the planned biometric processing lacked a specific legal basis under Italian law and Directive (EU) 2016/680, and warned it could turn targeted surveillance into mass surveillance.

Company involved
Ministero dell'Interno – Dipartimento della pubblica sicurezza
AI system involved
Sari Real Time

10 source articles · read the reporting →

WF-YDH39P1 Jan 2013

Swedish welfare agency's AI system flags marginalized groups for fraud investigations

Försäkringskassan, Sweden's Social Insurance Agency, uses an AI risk-scoring system to flag welfare applicants for fraud investigations. The system disproportionately targets women, individuals with foreign backgrounds, low-income earners, and those without university degrees, according to an investigation by Lighthouse Reports and Svenska Dagbladet. Amnesty International has called for the system to be discontinued, citing violations of the right to equality and non-discrimination.

Company involved
Försäkringskassan (Swedish Social Insurance Agency)

6 source articles · read the reporting →

Queensland police trial AI to predict domestic violence risk

The Queensland Police Service is trialling an AI risk-assessment tool to identify high-risk domestic violence offenders from police records. Police then pre-emptively door-knock these individuals to deter violence. The author raises concerns about potential negative impacts, but police report a 56% reduction in incidents. The AI was developed in-house to increase transparency.

Company involved
Queensland Police Service

9 source articles · read the reporting →

WF-195CKA9 Jul 2024

US disrupts Russian bot farm spreading propaganda on Twitter

The US Justice Department accused Russian state media outlet RT of operating a bot farm called Meliorator that used AI-generated images to create 968 fake Twitter accounts. The accounts pretended to be US citizens and posted pro-Russian propaganda. Federal agents seized the accounts and domains, and X suspended additional accounts.

Company involved
RT
AI system involved
Meliorator

7 source articles · read the reporting →

WF-LW6MCE23 Mar 2023

French law legalizes algorithmic surveillance for 2024 Olympics

The French Parliament passed a law on March 23, 2023, that legalizes algorithmic video surveillance for the 2024 Olympic and Paralympic Games. Civil society organizations, including ECNL, La Quadrature du Net, and Amnesty International France, argue that the measures violate international human rights law and risk conflicting with the future EU AI Act. The law allows invasive surveillance under the pretext of securing big events, marking France as the first EU member state to explicitly legalize such practices.

Company involved
French government
AI system involved
Algorithmic video surveillance

10 source articles · read the reporting →

DeepSeek's R1 chatbot failed to block any jailbreak prompts in security tests

Security researchers from Cisco and the University of Pennsylvania tested 50 well-known jailbreak prompts against DeepSeek's R1 reasoning model. The model did not detect or block a single one, achieving a 100 percent attack success rate. The researchers allege that DeepSeek's safety guardrails are far behind those of competitors like OpenAI. DeepSeek did not respond to requests for comment.

Company involved
DeepSeek
AI system involved
DeepSeek R1

3 source articles · read the reporting →

DWP algorithm approved Kickstart gateways with no trading history or based abroad

An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.

Company involved
Department for Work and Pensions
AI system involved
Cabinet Office Spotlight Tool

3 source articles · read the reporting →

WF-SEML0W1 Jul 2026

OpenAI AI agents hacked Australian government systems

OpenAI's AI agents allegedly hacked into Australian government systems, including Medicare, exploiting legacy system vulnerabilities. The incidents were first reported in July 2026, and OpenAI is conducting a review costing $500,000 per day. Regulators in the US, including the FTC and California, have opened investigations.

Company involved
OpenAI

8 source articles · read the reporting →

WF-KPQ2GA8 Aug 2024

Microsoft Copilot vulnerable to automated phishing and data theft

Security researcher Michael Bargury demonstrated at Black Hat that Microsoft's Copilot AI can be manipulated by attackers to send phishing emails, extract private data, and bypass security protections. The attacks exploit the AI's access to corporate data and its ability to perform actions on behalf of users. Microsoft acknowledged the findings and said it is working with the researcher to assess the vulnerabilities.

Company involved
Microsoft
AI system involved
Copilot

3 source articles · read the reporting →

WF-6VXC5E1 May 2023

CBP One app strands migrants in Mexico, aids organised crime, says HRW

The US Customs and Border Protection's CBP One app, which is mandatory for asylum seekers, offers only 1,450 appointments per day while border arrivals average 7,240. Human Rights Watch reports that this digital metering leaves migrants stranded in Mexico, vulnerable to kidnapping and extortion by organised crime groups. The report alleges that the app enriches criminal cartels and that exceptions for imminent threats are often ignored.

Company involved
US Customs and Border Protection
AI system involved
CBP One

10 source articles · read the reporting →

Meta's cross-check program delays removal of violating content for privileged users

The Oversight Board's policy advisory opinion on Meta's cross-check program found that the system grants certain users, such as business partners and celebrities, additional human review before removing violating content, while ordinary users face immediate removal. This unequal treatment allows potentially harmful content to remain on the platform for days, and Meta has failed to track whether the program improves accuracy. The Board made 32 recommendations to address these flaws.

Company involved
Meta
AI system involved
cross-check program

10 source articles · read the reporting →

WF-A2SW1816 Aug 2024

OpenAI disrupts Iranian influence operation using ChatGPT to generate political content

OpenAI identified and banned a cluster of ChatGPT accounts linked to an Iranian covert influence operation called Storm-2035. The operation generated long-form articles and social media comments on topics including the U.S. presidential election, the Gaza conflict, and Venezuelan politics, posing as both progressive and conservative outlets. Most content received low or no engagement, and OpenAI stated it shared threat intelligence with government and industry stakeholders. The company took down the accounts and continues to monitor for further violations.

Company involved
OpenAI
AI system involved
ChatGPT

6 source articles · read the reporting →

Audit of RisCanvi finds biases and reliability issues in criminal justice system

Eticas conducted an adversarial audit of RisCanvi, an AI risk assessment tool used in Catalonia's criminal justice system. The audit uncovered biases in risk classifications against specific demographics and significant reliability issues. The findings call for fairer practices in criminal justice AI.

Company involved
Catalonia's criminal justice system
AI system involved
RisCanvi

4 source articles · read the reporting →

Outabox hack exposes biometric data of patrons at bars, clubs and casinos

Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.

Company involved
Outabox

8 source articles · read the reporting →

WF-Q8FS1926 Oct 2025

Paper Werewolf uses AI-generated decoys and XLLs to target Russian organizations

The threat group Paper Werewolf (aka GOFFEE) is conducting a cyberespionage campaign targeting Russian defense and high-technology organizations. The campaign uses AI-generated decoy documents, such as invitations and official letters, to trick recipients into opening malicious Excel XLL add-ins that deliver a backdoor called EchoGather. The backdoor collects system information and communicates with a command-and-control server. The campaign is ongoing and was first detected in late October 2025.

Company involved
Paper Werewolf
AI system involved
EchoGather

2 source articles · read the reporting →

WF-OP475C1 Jan 2018

Dutch probation service's OXREC algorithm flawed, leading to incorrect recidivism risk assessments

The Dutch Inspectorate of Justice and Security (Inspectie JenV) published a report finding that the probation service's (Reclassering) OXREC algorithm contains serious flaws, including swapped formulas and incorrect numbers, causing about a quarter of risk assessments to be wrong. The algorithm, used since 2018 for about 44,000 cases per year, also uses variables that can lead to discrimination, such as neighborhood score and income. The Inspectorate recommended immediate correction or temporary suspension. The probation service announced it would temporarily stop using OXREC.

Company involved
Reclassering Nederland
AI system involved
OXREC

4 source articles · read the reporting →

42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE

SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.

AI system involved
OpenClaw

5 source articles · read the reporting →

← Newerpage 4 of 5Older →