Plastic Forte fined for using facial recognition on workers without notice
The Spanish data protection agency AEPD fined Plastic Forte, a plastics manufacturer in Alicante, €20,000 for using facial recognition to record employees' working hours without informing them. A worker requested information about his personal data and discovered the biometric processing. The company initially argued it was only for time tracking but later acknowledged responsibility, resulting in a reduced fine of €12,000. The AEPD deemed facial recognition for time control as highly intrusive and requiring prior impact assessment.
- Company involved
- Plastic Forte
7 source articles · read the reporting →
California regulator accuses Maxpread Technologies of using AI-generated fake CEO to scam investors
Maxpread Technologies allegedly used an AI-generated avatar to pose as its CEO in a YouTube video to deceive investors. The California DFPI issued cease and desist letters to Maxpread and four other companies for offering unqualified securities and making false promises. The regulator claims the companies promised high daily returns using AI trading, but these claims were false. Maxpread did not respond to requests for comment.
- Company involved
- Maxpread Technologies
8 source articles · read the reporting →
Serbia's Ministry of Interior deploys thousands of Huawei facial recognition cameras in Belgrade
In early 2019, Serbia's Ministry of Interior announced the deployment of a thousand smart surveillance cameras with facial and license plate recognition capabilities, supplied by Huawei, across Belgrade. The Ministry refused to release information about the project, citing confidentiality, and failed to conduct a legally required Data Protection Impact Assessment. Citizens responded by crowdsourcing camera locations via the hashtag #hiljadekamera and a website. The system remains in operation with no public debate or transparency.
- Company involved
- Ministry of Interior
- AI system involved
- Huawei smart surveillance cameras
10 source articles · read the reporting →
FTC settles with IntelliVision over deceptive facial recognition claims
The Federal Trade Commission (FTC) took action against IntelliVision Technologies Corp. for making false, misleading, or unsubstantiated claims about its AI-powered facial recognition software. The company allegedly claimed its software had one of the highest accuracy rates on the market and was free of gender or racial bias, without supporting evidence. The FTC also alleged that IntelliVision did not train its software on millions of faces as claimed, but on images of approximately 100,000 individuals. Under a proposed consent order, IntelliVision is prohibited from making such misrepresentations without competent and reliable testing.
- Company involved
- IntelliVision Technologies Corp.
- AI system involved
- IntelliVision facial recognition software
9 source articles · read the reporting →
ScaleFactor reportedly failed to deliver promised automated bookkeeping software
ScaleFactor, an Austin-based startup, is reported to have failed to deliver the automated, real-time bookkeeping tools it promised customers, instead relying on human bookkeepers and a Filipino contract accounting firm. The company told Forbes in June that it was shutting down, initially blaming the pandemic, but Forbes later reported that its problems predated Covid-19. Investors reportedly came to see the company as more of a services business than a software platform, and pulled funding after a pivot to a marketplace model. No legal or regulatory action is reported.
- Company involved
- ScaleFactor
10 source articles · read the reporting →
New Jersey court rules police must disclose facial recognition algorithms used to identify defendant
Francisco Arteaga was charged with armed robbery after a facial recognition search by the New York Police Department identified him as a possible match. The New Jersey police used this match to obtain witness identifications. Arteaga requested information about the facial recognition software, including its source code and error rate, but the trial court denied his request. The New Jersey appellate court ruled that the prosecution must disclose the algorithms, citing due process and the Brady rule.
- Company involved
- New Jersey Police
7 source articles · read the reporting →
WorldCoin suspended in Kenya over data security concerns
WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.
- Company involved
- Tools for Humanity GmbH
- AI system involved
- WorldCoin
10 source articles · read the reporting →
Dahua facial recognition technology can sort by race and alert police when detecting Uighurs
Dahua Technologies, a Chinese surveillance camera company, developed facial recognition software that can classify individuals by race and send real-time warnings to police when it identifies Uighur people. Documents and code revealed the capability, though it is unclear if it has been deployed. Human rights advocates and Uighur individuals have expressed concern about potential surveillance and discrimination. The company did not respond to requests for comment.
- Company involved
- Dahua Technologies
- AI system involved
- Dahua facial recognition software
10 source articles · read the reporting →
Deepfake video promotes fake Petro-Canada investment scheme
A Facebook ad used deepfake videos of Justin Trudeau and CBC anchor Aarti Pole to promote a fake Petro-Canada investment platform. Suncor, Petro-Canada's parent company, confirmed the offer was not legitimate. The manipulated videos were created using AI and did not air on CBC.
5 source articles · read the reporting →
Chattr.ai exposed job applicant data due to insecure Firebase rules
A security researcher discovered that Chattr.ai, an AI hiring system used by many fast food chains, had a Firebase database with insecure security rules. By registering a new user, the researcher gained full read/write access to the database, exposing personal data of job applicants and employees, including names, phone numbers, emails, and some plaintext passwords. The vulnerability was reported to Chattr.ai on 9 January and patched the next day, but the company did not provide further contact or thanks.
- Company involved
- Chattr.ai
- AI system involved
- Chattr.ai
6 source articles · read the reporting →
N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent
Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.
- Company involved
- N-Tech.lab
- AI system involved
- FindFace
8 source articles · read the reporting →
OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification
An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.
- Company involved
- OKX
- AI system involved
- OnlyFake
10 source articles · read the reporting →
Salvini and Lega used non-watermarked AI images in EU election campaign
Matteo Salvini and his party Lega created and posted 19 allegedly non-watermarked AI-generated images on social media as part of their 'More Italy, less Europe' electoral campaign. The images promoted false narratives about the EU, including the 'Muslim Great Replacement' theory and EU support for war in Ukraine. The posts reached millions of users, including a paid Facebook ad that reached over 3 million people. Alliance4Europe reported the incident, highlighting that the posts violated the voluntary 2024 European Parliament Elections Code of Conduct.
- Company involved
- Lega
5 source articles · read the reporting →
Italian DPA says Interior Ministry's Sari Real Time facial recognition lacks legal basis
The Garante per la protezione dei dati personali issued an opinion on Sari Real Time, a facial recognition system developed for the Italian Ministry of Interior. The system, yet to become operational, would compare live video footage of people in public areas with a watch-list and alert police operators. The authority found the planned biometric processing lacked a specific legal basis under Italian law and Directive (EU) 2016/680, and warned it could turn targeted surveillance into mass surveillance.
- Company involved
- Ministero dell'Interno – Dipartimento della pubblica sicurezza
- AI system involved
- Sari Real Time
10 source articles · read the reporting →
AAIP investigates Worldcoin's personal data processing in Argentina
The Argentine Agency for Access to Public Information (AAIP) has initiated an investigation into the data processing practices of Worldcoin in Argentina. The investigation focuses on the collection, storage, and use of biometric data, including facial and iris scans, carried out in several cities in exchange for financial compensation. The AAIP aims to verify compliance with the country's data protection law, Ley 25.326, regarding sensitive data handling.
- Company involved
- Worldcoin (Fundación Worldcoin)
- AI system involved
- Worldcoin
8 source articles · read the reporting →
US disrupts Russian bot farm spreading propaganda on Twitter
The US Justice Department accused Russian state media outlet RT of operating a bot farm called Meliorator that used AI-generated images to create 968 fake Twitter accounts. The accounts pretended to be US citizens and posted pro-Russian propaganda. Federal agents seized the accounts and domains, and X suspended additional accounts.
- Company involved
- RT
- AI system involved
- Meliorator
7 source articles · read the reporting →
Hacker tricks Freysa AI chatbot into transferring $47,000 prize pool
A hacker using the alias 'p0pular.eth' successfully manipulated the Freysa AI chatbot through a prompt injection attack, tricking it into transferring its entire balance of 13.19 ETH (approximately $47,000) from a prize pool. The chatbot was designed to never transfer money, but the hacker crafted a message that redefined the 'approveTransfer' function and announced a fake $100 deposit, causing the bot to release the funds. The incident occurred during a pay-to-play contest where participants paid escalating fees to attempt the hack, with the winner receiving the prize pool.
- Company involved
- Freysa.ai
- AI system involved
- Freysa
4 source articles · read the reporting →
Delta uses AI from Fetcherr for domestic ticket pricing
Delta Air Lines is using generative AI from Fetcherr to determine some domestic flight prices, currently covering 3% of its network with plans to reach 20% by end of 2025. Democratic senators expressed concern that the AI could be used for individualized pricing based on personal data, leading to higher fares. Delta denies using personal data in pricing and states it complies with regulations. No actual harm has been reported.
- Company involved
- Delta Air Lines
- AI system involved
- Fetcherr
8 source articles · read the reporting →
AfD used AI-generated images for political propaganda on TikTok
In the months before the 2024 European elections, Alternative für Deutschland (AfD) politician Maximilian Krah used AI-generated images on TikTok to create false visual evidence of fictional families, staged nationalist demonstrations, and immigration threats. The AI-generated content was posted to amplify anxieties around migration and cultural identity, with over 1.3 million views across 28 thumbnails. The article alleges that the AfD continued this practice after the elections, weaponizing AI to deepen political divides.
- Company involved
- Alternative für Deutschland (AfD)
5 source articles · read the reporting →
Delhi Police use facial recognition to screen PM Modi rally attendees
Delhi Police used an Automated Facial Recognition System (AFRS) to screen crowds at Prime Minister Narendra Modi's rally on December 22, 2019. The system, originally installed to find missing children, was used to identify possible disruptions. Privacy advocates called the move illegal and unconstitutional, saying it amounts to mass surveillance. Police defended the use, citing credible intelligence about possible disruptions.
- Company involved
- Delhi Police
- AI system involved
- Automated Facial Recognition System (AFRS)
6 source articles · read the reporting →
India-aligned network used AI fake accounts to target Pakistan, NewsGuard finds
NewsGuard reports that a network of nearly 1,500 fake Facebook and X accounts used AI-generated content to promote pro-India and pro-Army narratives and criticise Pakistan. The network, which NewsGuard says may be linked to the Indian Army, has operated undetected since September 2021. Meta said it had enforced against a cluster of accounts; X did not comment. The full scale and reach of the operation remain unclear.
2 source articles · read the reporting →
FBI charges man for creating AI chatbots to harass university professor
A university professor in Massachusetts was harassed online for years, including through the creation of AI chatbots that impersonated her. The chatbots were programmed with her personal information and encouraged users to contact her. The FBI arrested James Florence Jr. on charges of cyberstalking in violation of 18 U.S.C. § 2261A(2).
5 source articles · read the reporting →
Italian DPA fines Municipality of Trento over AI surveillance projects
The Italian data protection authority (Garante) fined the Municipality of Trento €50,000 for two research projects, Marvel and Protector, that used AI to analyze video, audio, and social media data for public security purposes. The projects involved automated detection of risk events from surveillance cameras and microphones in public spaces, as well as monitoring social media for hate speech. The Garante found multiple violations of privacy law, including lack of a valid legal basis, insufficient anonymization, failure to conduct a data protection impact assessment, and inadequate transparency. The municipality is required to delete the unlawfully processed data.
- Company involved
- Comune di Trento
- AI system involved
- Marvel and Protector
9 source articles · read the reporting →
Italian Data Protection Authority Blocks Replika Chatbot Over Risks to Minors
On February 2, 2023, the Italian Data Protection Authority (Garante) issued an urgent order blocking the AI chatbot Replika from processing personal data of Italian users. The Garante found that Replika lacked effective age verification, allowing minors to potentially receive inappropriate content including sex-related replies, and that its privacy policy violated GDPR transparency requirements. The U.S.-based controller was given 20 days to report on compliance measures and may challenge the order within 60 days.
- AI system involved
- Replika
1 source article · read the reporting →