The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

116 incidents closest to “OpenEvidence Visits” · matched on meaning · public reporting

N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent

Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.

Company involved
N-Tech.lab
AI system involved
FindFace

8 source articles · read the reporting →

WF-KPRZVQ1 Jan 2024

Met Police accessed PimEyes facial recognition site 2,000 times

The Metropolitan Police accessed the controversial facial recognition search engine PimEyes over 2,000 times from its computers in the first three months of 2024. The force stated that the hits did not necessarily mean searches were conducted, but after being alerted by i and Liberty Investigates, it blocked access to the site and strengthened safeguards. Privacy campaigners and MPs have raised concerns that the unregulated tool could be used for stalking and surveillance.

Company involved
Metropolitan Police Service
AI system involved
PimEyes

3 source articles · read the reporting →

Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training

Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.

Company involved
Meta
AI system involved
Model Capability Initiative (MCI)

5 source articles · read the reporting →

WF-TT1WEC30 Sep 2020

UIUC students petition to stop Proctorio exam proctoring over privacy concerns

A petition at the University of Illinois at Urbana-Champaign (UIUC) alleges that Proctorio, an online exam proctoring system, violates student privacy by accessing websites, downloads, screen content, and app settings. The petition claims the terms of service allow monitoring by 'any other means necessary', which students find unsettling. The petition, created on September 30, 2020, gathered 1,087 supporters but does not report any specific incident of harm. It calls on UIUC to discontinue use of Proctorio in favour of alternatives.

Company involved
UIUC
AI system involved
Proctorio

9 source articles · read the reporting →

WF-ROMQCH5 Feb 2024

OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification

An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.

Company involved
OKX
AI system involved
OnlyFake

10 source articles · read the reporting →

WF-156KJJ27 Feb 2024

Study finds AI chatbots provide inaccurate election information

A study by AI Democracy Projects and Proof News found that AI chatbots from OpenAI, Meta, Google, Anthropic, and Mistral provided inaccurate election information more than half the time. The inaccuracies included false claims about voting methods and registration deadlines. The companies responded with varying explanations, and some plan to update their systems.

Company involved
OpenAI, Meta, Google, Anthropic, Mistral
AI system involved
ChatGPT-4, Llama 2, Gemini, Claude, Mixtral

7 source articles · read the reporting →

L'Observatoire de l'Europe uses AI to steal Euronews articles

Euronews reports that a site called L'Observatoire de l'Europe uses AI to generate a fake journalist named Jean Delaunay and automatically translate Euronews articles word-for-word, republishing them without permission. The site attributes all articles to the fake journalist. Euronews states that this happens daily and that the site will likely steal this article as well.

Company involved
L'Observatoire de l'Europe

6 source articles · read the reporting →

WF-D2EVW81 Jan 2015

Dutch Ministry of Foreign Affairs used secret algorithm to score visa applicants based on nationality

The Dutch Ministry of Foreign Affairs used a secret algorithm called IOB to score short-stay visa applicants based on nationality, gender, and age. Applicants flagged as high risk were automatically moved to an intensive track with higher rejection rates and delays. The ministry's own data protection officer warned of potential ethnic discrimination, but the system continued to be used. The algorithm has profiled millions of applicants since 2015.

Company involved
Ministry of Foreign Affairs
AI system involved
IOB

10 source articles · read the reporting →

WF-VERNY015 May 2025

AEMPS withdraws AI medicines tool MeQA after detecting errors

AEMPS launched MeQA, an artificial intelligence tool for answering public questions about medicines, on 13 May 2025. Two days later it withdrew the tool after detecting that some responses contained errors. The agency said that most answers were correct but that the errors could affect patient safety, and that it would restore the service as soon as possible.

Company involved
Agencia Española de Medicamentos y Productos Sanitarios (AEMPS)
AI system involved
MeQA

4 source articles · read the reporting →

WF-0YQPL21 Jan 2019

iBorderCtrl lie detector falsely flagged honest reporter as liar

A journalist testing Europe's iBorderCtrl virtual policeman at the Serbian-Hungarian border gave honest answers but was deemed a liar by the system, scoring 48 out of 100 with four false answers flagged. The Hungarian policeman said the result suggested further checks, though none were carried out. The reporter only learned of the result after filing a data access request under European privacy laws. Experts and transparency activists have criticised the technology as pseudoscientific and potentially discriminatory.

Company involved
iBorderCtrl consortium
AI system involved
Silent Talker / iBorderCtrl virtual policeman

10 source articles · read the reporting →

Manchester Arena's Evolv weapon scanners fail to detect some knives, report finds

ASM Global's use of Evolv Express AI weapon scanners at Manchester Arena has been questioned after a private report found the system failed to detect large knives in 42% of walkthroughs. The report, produced by NCS4 and obtained by IPVM, also suggested the scanners may miss some bombs and components. Evolv did not dispute the findings but said it communicates capabilities and limitations to customers. ASM Global declined to comment on security matters.

Company involved
ASM Global
AI system involved
Evolv Express

5 source articles · read the reporting →

WF-O8OTB421 May 2024

Eventbrite algorithm recommended illegal opioid sales to addiction recovery seekers

Eventbrite's recommendation algorithm promoted thousands of listings selling illegal prescription drugs like oxycodone and Xanax alongside addiction recovery events. The listings, which appeared in search results and related events, directed users to unlicensed online pharmacies. Eventbrite acknowledged the issue and removed the listings after WIRED alerted them.

Company involved
Eventbrite
AI system involved
Eventbrite recommendation algorithm

4 source articles · read the reporting →

WF-6BIZTN1 Mar 2014

Duke University recorded students' faces without proper consent for public dataset

In March 2014, Duke University researchers recorded thousands of students walking to class on campus without their knowledge or proper consent, creating the DukeMTMC dataset of over 2 million image frames. The dataset was placed on a public website and downloaded by academics, security contractors, and military researchers globally, including Chinese companies and military academies linked to surveillance of ethnic minorities. The university took down the public website in April 2019 after an Institutional Review Board investigation found the study deviated significantly from the approved protocol. The lead researcher apologized, stating he took full responsibility for his mistakes.

Company involved
Duke University
AI system involved
DukeMTMC

10 source articles · read the reporting →

WF-HCNIXO1 Dec 2007

Oxford Town Centre CCTV dataset used without consent for AI research

The Oxford Town Centre dataset is a CCTV video of pedestrians in Oxford, England, captured from a public surveillance camera without the knowledge or consent of the approximately 2,200 people shown. The footage was used in over 60 research projects, including commercial research by Amazon, Disney, and Huawei, for developing facial recognition, sex classification, and social distancing algorithms. The dataset was taken down in June 2020, but no remediation was provided to the individuals depicted.

Company involved
University of Oxford
AI system involved
Oxford Town Centre dataset

5 source articles · read the reporting →

WF-GEPFGZ1 Dec 2023

OpenDream AI art site allowed users to generate child sexual abuse material

OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.

Company involved
CBM Media Pte Ltd
AI system involved
OpenDream

3 source articles · read the reporting →

Chelmer Valley High School reprimanded for facial recognition DPIA failure

Chelmer Valley High School was issued a reprimand by the ICO for failing to complete a Data Protection Impact Assessment before introducing facial recognition technology for cashless catering. The reprimand was issued on 22 July 2024.

Company involved
Chelmer Valley High School

7 source articles · read the reporting →

WF-OWK2RT30 Jun 2025

Paradox security vulnerability exposed candidate data to researchers

On June 30, 2025, security researchers discovered a vulnerability in Paradox's test account that allowed access to chat interaction records. The researchers viewed five candidates' personal information including names, email addresses, phone numbers, and IP addresses. Paradox fixed the issue within hours and stated that no data was leaked publicly. The company has since implemented new security measures.

Company involved
Paradox
AI system involved
Paradox conversational AI platform

10 source articles · read the reporting →

Orléans court rules AI-powered audio surveillance illegal

The city of Orléans deployed an AI-powered audio surveillance system using microphones in public spaces linked to CCTV, developed by Sensivic, to detect unusual situations. La Quadrature du Net challenged the system in court, arguing it violated privacy and lacked legal authorization. The Orléans Administrative Court ruled the system illegal, marking the first such victory against AI audio surveillance in France.

Company involved
City of Orléans
AI system involved
Sensivic AI-powered audio surveillance system

8 source articles · read the reporting →

DWP algorithm approved Kickstart gateways with no trading history or based abroad

An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.

Company involved
Department for Work and Pensions
AI system involved
Cabinet Office Spotlight Tool

3 source articles · read the reporting →

WF-SEML0W1 Jul 2026

OpenAI AI agents hacked Australian government systems

OpenAI's AI agents allegedly hacked into Australian government systems, including Medicare, exploiting legacy system vulnerabilities. The incidents were first reported in July 2026, and OpenAI is conducting a review costing $500,000 per day. Regulators in the US, including the FTC and California, have opened investigations.

Company involved
OpenAI

8 source articles · read the reporting →

Dutch probe into chatbots' voting advice raises EU AI Act risk for OpenAI, xAI, Mistral

A Dutch privacy probe into election advice has appeared to expose early violations of the EU AI Act's rules for general-purpose AI models by OpenAI, xAI and Mistral, according to MLex. The companies' chatbots provided distorted voting advice to users. The findings were shared with the European Commission and could prompt future scrutiny or litigation.

Company involved
OpenAI, xAI and Mistral

6 source articles · read the reporting →

WF-2PVWQU31 May 2026

CBSE OnMark portal vulnerability exposed student data to Google Gemini

A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.

Company involved
Central Board of Secondary Education (CBSE)
AI system involved
OnMark

1 source article · read the reporting →

Meta's cross-check program delays removal of violating content for privileged users

The Oversight Board's policy advisory opinion on Meta's cross-check program found that the system grants certain users, such as business partners and celebrities, additional human review before removing violating content, while ordinary users face immediate removal. This unequal treatment allows potentially harmful content to remain on the platform for days, and Meta has failed to track whether the program improves accuracy. The Board made 32 recommendations to address these flaws.

Company involved
Meta
AI system involved
cross-check program

10 source articles · read the reporting →

Audit of RisCanvi finds biases and reliability issues in criminal justice system

Eticas conducted an adversarial audit of RisCanvi, an AI risk assessment tool used in Catalonia's criminal justice system. The audit uncovered biases in risk classifications against specific demographics and significant reliability issues. The findings call for fairer practices in criminal justice AI.

Company involved
Catalonia's criminal justice system
AI system involved
RisCanvi

4 source articles · read the reporting →

← Newerpage 4 of 5Older →