The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

116 incidents closest to “Plaid Protect” · matched on meaning · public reporting

WF-F7YECE5 May 2026

Jessica Fuller v. Hyde School, et al. (D. Maine): AI-hallucinated content in court filing, CLE; Firm procedures and certification; Serve…

The AI generated fictitious legal citations that were submitted to the court in a legal filing.

AI system involved
ChatGPT or Claude

1 source article · read the reporting →

Researchers jailbreak Stable Diffusion and DALL-E 2 to generate disturbing images

Researchers from Johns Hopkins and Duke universities developed a method called SneakyPrompt that uses reinforcement learning to bypass safety filters in text-to-image AI models. The technique allowed them to generate images of nudity and violence from Stable Diffusion and DALL-E 2. OpenAI has since fixed the vulnerability in DALL-E 2, but Stable Diffusion 1.4 remains vulnerable. Stability AI says it is working with the researchers to improve defenses.

AI system involved
Stable Diffusion 1.4 and DALL-E 2

5 source articles · read the reporting →

WF-2ABL3N30 Nov 2023

Bavarian police test Palantir data mining with real personal data

The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.

Company involved
Bayerisches Landeskriminalamt
AI system involved
VeRa

7 source articles · read the reporting →

N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent

Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.

Company involved
N-Tech.lab
AI system involved
FindFace

8 source articles · read the reporting →

Actor's AI-generated avatar used in Venezuelan propaganda campaign

An actor's digital replica was generated without consent and used to spread fake news in a Venezuelan propaganda campaign. The actor turned to Equity for help, but current laws provide few protections. Equity is campaigning for new personality rights to prevent such exploitation.

9 source articles · read the reporting →

WF-KBL3YD15 Oct 2019

Hive Box Facial-Recognition Lockers Hacked by Children Using Photos

Fourth-grade students in Jiaxing, China, demonstrated that Hive Box's facial-recognition smart lockers could be opened with a printed photo. The company, which operates a large network of delivery lockers, acknowledged the flaw and suspended the beta feature. The incident raised concerns about the security of facial recognition technology.

Company involved
Hive Box

1 source article · read the reporting →

Evolv weapon detection system falsely flags Chromebooks as weapons

Evolv's AI-based weapon detection system has been reported to falsely identify certain Chromebook laptops as weapons, causing false alarms at security checkpoints. The system is used in venues such as schools. The article discusses the flaw and user experiences. No official response from Evolv has been mentioned.

Company involved
Evolv
AI system involved
Evolv

5 source articles · read the reporting →

Andrea Bartz and others sue Anthropic PBC over copyright

In August 2024, Andrea Bartz, Kirk Wallace Johnson and Charles Graeber filed a lawsuit against Anthropic PBC in the US District Court for the Northern District of California. The complaint alleges copyright infringement under 17 U.S.C. § 501. Anthropic waived service, and the case was assigned to the court.

Company involved
Anthropic PBC

8 source articles · read the reporting →

Prosecraft shut down after using authors' books without consent for AI analytics

Prosecraft, a fiction analytics site, used the full text of over 25,000 books without author consent to train its AI algorithms and provide writing statistics. Authors protested on social media, demanding removal of their works. The developer, Benji Smith, subsequently shut down the site and wrote a blog post explaining his actions.

Company involved
Prosecraft
AI system involved
Prosecraft

10 source articles · read the reporting →

WF-ATXX7J28 Sep 2026

‘Stop spying on us’: Man announces lawsuit against Simpsonville during Flock camera protest - FOX Carolina News

The Flock cameras captured and stored license plate data of vehicles, affecting residents' privacy.

Company involved
City of Simpsonville
AI system involved
Flock

1 source article · read the reporting →

WF-DB84QL1 Dec 2022

Jacksons Food Stores sued over facial recognition in Portland

Jacksons Food Stores is accused of violating a Portland, Oregon, city ordinance by using facial recognition technology in its stores after the ban took effect. The lawsuit, filed in December 2022, alleges the system, supplied by Blue Line Technology, wrongly identifies people as criminals and disproportionately affects women and people of colour. Customers were required to look at a camera and be scanned before entering. The retailer has not responded to the allegations.

Company involved
Jacksons Food Stores
AI system involved
First Line

10 source articles · read the reporting →

Meta's cross-check program delays removal of violating content for privileged users

The Oversight Board's policy advisory opinion on Meta's cross-check program found that the system grants certain users, such as business partners and celebrities, additional human review before removing violating content, while ordinary users face immediate removal. This unequal treatment allows potentially harmful content to remain on the platform for days, and Meta has failed to track whether the program improves accuracy. The Board made 32 recommendations to address these flaws.

Company involved
Meta
AI system involved
cross-check program

10 source articles · read the reporting →

Outabox hack exposes biometric data of patrons at bars, clubs and casinos

Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.

Company involved
Outabox

8 source articles · read the reporting →

WF-Q8FS1926 Oct 2025

Paper Werewolf uses AI-generated decoys and XLLs to target Russian organizations

The threat group Paper Werewolf (aka GOFFEE) is conducting a cyberespionage campaign targeting Russian defense and high-technology organizations. The campaign uses AI-generated decoy documents, such as invitations and official letters, to trick recipients into opening malicious Excel XLL add-ins that deliver a backdoor called EchoGather. The backdoor collects system information and communicates with a command-and-control server. The campaign is ongoing and was first detected in late October 2025.

Company involved
Paper Werewolf
AI system involved
EchoGather

2 source articles · read the reporting →

42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE

SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.

AI system involved
OpenClaw

5 source articles · read the reporting →

WF-PQ8NMX1 Jan 2022

Stable Diffusion Accused of Stealing Artists' Styles Without Consent

Artists including Greg Rutkowski and Karla Ortiz allege that Stability AI's image generator Stable Diffusion was trained on their work without permission, enabling users to create images mimicking their distinctive styles. The artists express concern that this threatens their livelihoods and identities, as their names become prompts for generating similar art. A tool is being developed to help protect artists from such unauthorised use, but the situation remains unresolved.

Company involved
Stability AI
AI system involved
Stable Diffusion

10 source articles · read the reporting →

WF-R41UQV23 Feb 2012

Palantir secretly tested predictive policing in New Orleans

Beginning in 2012, Palantir Technologies secretly partnered with the New Orleans Police Department to deploy a predictive policing system. The programme analysed gang affiliations, social media and criminal histories to forecast individuals’ likelihood of committing or becoming victims of violence, operating without public knowledge or city council oversight. Researchers and law enforcement officials raised concerns about systemic bias and civil liberties. As of 2018, the city and Palantir had not disclosed the programme’s status.

Company involved
New Orleans Police Department

1 source article · read the reporting →

Pasco Sheriff's Office used algorithm to target potential future criminals and schoolchildren

The Pasco Sheriff's Office operates an intelligence-led policing programme that uses an algorithm to identify people who might break the law based on criminal histories and social networks. Deputies are sent to the homes of those flagged, even without evidence of a crime, and former deputies allege they were ordered to make targets' lives miserable. The agency also keeps a list of more than 400 schoolchildren predicted to 'fall into a life of crime', built from data such as grades and child welfare records, without informing the children or their parents. Civil liberties groups are considering lawsuits and public advocacy campaigns, and experts have called the programmes 'morally repugnant'.

Company involved
Pasco Sheriff's Office

10 source articles · read the reporting →

WF-OK0FGL20 Mar 2025

Lovable security flaw exposed user data from 170 apps

Lovable, a Swedish startup, failed to fix a critical security flaw in its vibe coding service. Researchers found 170 Lovable-created web apps that exposed users' personal data, including names, emails, financial information, and API keys. Lovable acknowledged the issue and implemented a security scan, but the flaw remained unresolved.

Company involved
Lovable
AI system involved
Lovable

5 source articles · read the reporting →

WF-AYLKD31 Dec 2020

NHS faces legal action over Palantir data contract extension

The NHS is being taken to court by campaign group Open Democracy over its contract with data firm Palantir. The legal action alleges that the extension of Palantir's involvement in analysing NHS patient data for pandemic response and beyond lacked a proper Data Protection Impact Assessment. The contract, initially an emergency response, was extended for two years at a cost of £23.5m. The case is pending.

Company involved
NHS
AI system involved
Palantir data analysis platform

10 source articles · read the reporting →

WF-IWL4TH1 Jan 2018

US Secret Service bought access to cellphone location data

The US Secret Service signed a contract to access Locate X, a service that aggregates location data from phone apps and allows law enforcement to track devices without a warrant. The contract with Babel Street was worth about $36,000 and ran from 2017 to 2018. A former employee said the Secret Service used Locate X in 2018 to seize illegal credit card skimmers at petrol stations. Lawmakers and civil liberties advocates criticised the practice, and Senator Ron Wyden introduced a bill to ban such purchases.

Company involved
United States Secret Service
AI system involved
Locate X

1 source article · read the reporting →

WF-85J54330 Mar 2009

San Francisco Police Wrongfully Stop Woman at Gunpoint After License Plate Reader Error

On March 30, 2009, Denise Green, a 47-year-old African-American woman, was driving in San Francisco when an automatic license plate reader misread her plate as stolen. Despite discrepancies between the vehicle description and the stolen plate, officers conducted a felony stop, ordering her out at gunpoint and handcuffing her for nearly 20 minutes. Green filed a civil rights lawsuit alleging Fourth Amendment violations. The Ninth Circuit Court of Appeals reinstated her case, finding that the officers lacked reasonable suspicion for the stop.

Company involved
San Francisco Police Department

1 source article · read the reporting →

WF-CB17LN31 Oct 2023

California AG declares out-of-state ALPR data sharing unlawful

California Attorney General Rob Bonta issued guidance confirming that sharing automated license plate reader (ALPR) data with out-of-state or federal agencies violates state law SB 34. The decision follows years of advocacy by EFF and the ACLU, who demonstrated through public records that many California law enforcement agencies were sharing data with hundreds of external agencies, including ICE and CBP. The guidance mandates that all California agencies review their data sharing and cut off access to out-of-state and federal entities.

Company involved
California law enforcement agencies
AI system involved
Automated license plate readers (ALPRs)

1 source article · read the reporting →

Facebook exempted Trump and other high-profile users from content enforcement rules.

An internal Facebook program called XCheck granted special treatment to millions of high-profile users, including former President Donald Trump and Senator Elizabeth Warren, exempting them from content enforcement rules. The program, initially for quality control, was expanded to whitelist users deemed newsworthy or PR-risky, with the system failing to enforce rules against them. Internal documents revealed that the program made mistakes, often wrongly taking action against high-profile users. Facebook has attempted to phase out the practice but has struggled.

Company involved
Facebook
AI system involved
XCheck

10 source articles · read the reporting →

← Newerpage 4 of 5Older →