The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

116 incidents closest to “Proctorio WebSweep” · matched on meaning · public reporting

WebinarTV secretly records Zoom calls and turns them into AI podcasts

WebinarTV, a company that bills itself as a search engine for webinars, is secretly scanning the internet for Zoom meeting links, recording the calls, and turning them into AI-generated podcasts for profit. People only found out their calls were recorded when WebinarTV contacted them to promote its services. The recordings may put call participants at risk.

Company involved
WebinarTV

4 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

OPC launches investigation into OpenAI's ChatGPT over privacy complaint

The Office of the Privacy Commissioner of Canada (OPC) has launched an investigation into OpenAI, operator of the ChatGPT chatbot, in response to a complaint alleging the collection, use, and disclosure of personal information without consent. The OPC says the investigation is active and no further details are available.

Company involved
OpenAI
AI system involved
ChatGPT

9 source articles · read the reporting →

DeepSeek-R1 censors 85% of sensitive Chinese political prompts in tests

Promptfoo tested DeepSeek-R1 against a dataset of 1,360 politically sensitive prompts and found that about 85% of them were refused. The refusals followed a standard form aligned with Chinese Communist Party policy. The testing also demonstrated that the censorship could be trivially bypassed using simple jailbreak techniques, such as prompt injection or changing the context.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

WF-EA6R453 Jan 2023

New York City Department of Education blocks ChatGPT on school devices

The New York City Department of Education blocked access to the AI chatbot ChatGPT on school devices and networks, citing concerns about negative impacts on student learning and the safety and accuracy of content. The ban applies to all students and teachers on education department devices and internet networks. Individual schools can still request access for studying the technology. The move is the nation's largest school system's response to the arrival of ChatGPT.

Company involved
New York City Department of Education
AI system involved
ChatGPT

9 source articles · read the reporting →

WF-IEKSX31 Jan 2023

PimEyes scraped Ancestry.com for photos of dead people without permission.

PimEyes, a facial recognition search engine, scraped images from Ancestry.com and other websites without authorization, including photos of deceased individuals. The company's algorithms indexed the images to create biometric faceprints, potentially allowing identification of living relatives. Cher Scarlett discovered the scraping after finding photos of her deceased sister on the platform. PimEyes has since blocked Ancestry's domain and is removing the indexes, but privacy concerns remain.

Company involved
PimEyes
AI system involved
PimEyes

7 source articles · read the reporting →

PimEyes facial recognition used to unmask porn actors and Facebook friends

A man used the facial recognition site PimEyes to identify porn actors and women from his Facebook friends by uploading their photos and finding matching images online. The system had no controls to prevent searching for others without consent. The article alleges that this invasion of privacy could lead to discrimination and harassment, and that PimEyes offered a paid service to remove photos but did not prevent the searches.

Company involved
PimEyes
AI system involved
PimEyes

3 source articles · read the reporting →

WF-51NEWF17 Feb 2024

UIUC researchers weaponize GPT-4 to autonomously hack websites

Researchers at the University of Illinois Urbana-Champaign demonstrated that LLM-powered agents, particularly OpenAI's GPT-4, can autonomously hack vulnerable websites. In sandboxed tests, GPT-4 achieved a 73.3% success rate across five attempts on 15 vulnerabilities, while open-source models failed. The researchers used the OpenAI Assistants API, LangChain, and Playwright to enable the agents to interact with websites. The study highlights the potential for AI agents to be used in cyberattacks, with cost estimates suggesting they could be cheaper than human penetration testers.

Company involved
University of Illinois Urbana-Champaign
AI system involved
GPT-4

4 source articles · read the reporting →

Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training

Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.

Company involved
Meta
AI system involved
Model Capability Initiative (MCI)

5 source articles · read the reporting →

WF-TT1WEC30 Sep 2020

UIUC students petition to stop Proctorio exam proctoring over privacy concerns

A petition at the University of Illinois at Urbana-Champaign (UIUC) alleges that Proctorio, an online exam proctoring system, violates student privacy by accessing websites, downloads, screen content, and app settings. The petition claims the terms of service allow monitoring by 'any other means necessary', which students find unsettling. The petition, created on September 30, 2020, gathered 1,087 supporters but does not report any specific incident of harm. It calls on UIUC to discontinue use of Proctorio in favour of alternatives.

Company involved
UIUC
AI system involved
Proctorio

9 source articles · read the reporting →

AI unmasks anonymous chess players, study warns of privacy risks

A study described in Science shows that software can identify people who play chess anonymously, revealing their identities. Researchers, including Alexandra Wood, say the work highlights a growing privacy threat. The article does not name the software or any specific victims.

5 source articles · read the reporting →

Evolv weapon detection system falsely flags Chromebooks as weapons

Evolv's AI-based weapon detection system has been reported to falsely identify certain Chromebook laptops as weapons, causing false alarms at security checkpoints. The system is used in venues such as schools. The article discusses the flaw and user experiences. No official response from Evolv has been mentioned.

Company involved
Evolv
AI system involved
Evolv

5 source articles · read the reporting →

WF-4N6UFD1 Mar 2021

Baltimore schools monitor student laptops for suicide signs using GoGuardian Beacon

Baltimore City Public Schools uses GoGuardian Beacon software to monitor student laptops for signs of suicide. Since March 2021, the system has flagged 786 alerts, with nine students taken to emergency rooms. Privacy advocates warn the monitoring could lead to disciplinary actions, outing of LGBTQ students, and disproportionately affect disadvantaged students. School officials defend the practice as a safeguard.

Company involved
Baltimore City Public Schools
AI system involved
GoGuardian Beacon

10 source articles · read the reporting →

OpenAI and Anthropic ignore robots.txt to scrape web content for training data

OpenAI and Anthropic have been found to be ignoring or circumventing the robots.txt rule that prevents automated scraping of websites, according to a person with knowledge of TollBit's analytics. The AI companies are bypassing blocks to their web crawlers GPTBot and ClaudeBot to retrieve all content from publishers' websites for model training. The practice undermines the long-standing web standard and raises concerns about copyright infringement.

Company involved
OpenAI, Anthropic
AI system involved
ChatGPT, Claude

10 source articles · read the reporting →

Prosecraft shut down after using authors' books without consent for AI analytics

Prosecraft, a fiction analytics site, used the full text of over 25,000 books without author consent to train its AI algorithms and provide writing statistics. Authors protested on social media, demanding removal of their works. The developer, Benji Smith, subsequently shut down the site and wrote a blog post explaining his actions.

Company involved
Prosecraft
AI system involved
Prosecraft

10 source articles · read the reporting →

WF-CQREJ01 Apr 2021

Proctorio anti-cheating software failed to catch student cheaters in study

Researchers at the University of Twente in the Netherlands tested Proctorio, an anti-cheating software, by asking 30 computer science students to sit an exam while six of them cheated. Proctorio did not flag any of the cheaters and flagged some honest students for irregular behaviour. An independent human review caught only one of the six cheaters. Proctorio disputed the study's methodology and cited other research.

Company involved
Proctorio
AI system involved
Proctorio

5 source articles · read the reporting →

WF-NE7SI21 Jan 2012

UCCS professor secretly photographed over 1,700 people for facial recognition research

A University of Colorado Colorado Springs professor, Terrance Boult, led a project that secretly photographed more than 1,700 students, faculty, and passers-by on campus in 2012-2013 to improve facial recognition technology. The photos were published as a public dataset from 2016 until April 2019. University officials defended the research, but a law professor questioned the ethics of the surveillance without consent.

Company involved
University of Colorado Colorado Springs

10 source articles · read the reporting →

WF-OWK2RT30 Jun 2025

Paradox security vulnerability exposed candidate data to researchers

On June 30, 2025, security researchers discovered a vulnerability in Paradox's test account that allowed access to chat interaction records. The researchers viewed five candidates' personal information including names, email addresses, phone numbers, and IP addresses. Paradox fixed the issue within hours and stated that no data was leaked publicly. The company has since implemented new security measures.

Company involved
Paradox
AI system involved
Paradox conversational AI platform

10 source articles · read the reporting →

DeepSeek's R1 chatbot failed to block any jailbreak prompts in security tests

Security researchers from Cisco and the University of Pennsylvania tested 50 well-known jailbreak prompts against DeepSeek's R1 reasoning model. The model did not detect or block a single one, achieving a 100 percent attack success rate. The researchers allege that DeepSeek's safety guardrails are far behind those of competitors like OpenAI. DeepSeek did not respond to requests for comment.

Company involved
DeepSeek
AI system involved
DeepSeek R1

3 source articles · read the reporting →

WF-2PVWQU31 May 2026

CBSE OnMark portal vulnerability exposed student data to Google Gemini

A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.

Company involved
Central Board of Secondary Education (CBSE)
AI system involved
OnMark

1 source article · read the reporting →

WF-KPQ2GA8 Aug 2024

Microsoft Copilot vulnerable to automated phishing and data theft

Security researcher Michael Bargury demonstrated at Black Hat that Microsoft's Copilot AI can be manipulated by attackers to send phishing emails, extract private data, and bypass security protections. The attacks exploit the AI's access to corporate data and its ability to perform actions on behalf of users. Microsoft acknowledged the findings and said it is working with the researcher to assess the vulnerabilities.

Company involved
Microsoft
AI system involved
Copilot

3 source articles · read the reporting →

Meta's cross-check program delays removal of violating content for privileged users

The Oversight Board's policy advisory opinion on Meta's cross-check program found that the system grants certain users, such as business partners and celebrities, additional human review before removing violating content, while ordinary users face immediate removal. This unequal treatment allows potentially harmful content to remain on the platform for days, and Meta has failed to track whether the program improves accuracy. The Board made 32 recommendations to address these flaws.

Company involved
Meta
AI system involved
cross-check program

10 source articles · read the reporting →

WF-5TENXX1 Aug 2023

Vanderbilt, Northwestern and University of Texas stop using Turnitin AI detector over false cheating accusations

Several US universities, including Vanderbilt, Northwestern and the University of Texas, have stopped using Turnitin's AI detection tool over concerns that it falsely marks student essays as written by ChatGPT. Vanderbilt estimated that the tool's 1% false-positive rate could have wrongly labelled about 750 of 75,000 papers submitted last year. A Texas professor came under fire for failing half his class after the software identified their essays as AI-generated. Turnitin said its technology is not meant to replace educators' professional discretion.

Company involved
Multiple universities (Vanderbilt University, Northwestern University, University of Texas)
AI system involved
Turnitin's AI detection tool

9 source articles · read the reporting →

WF-LIDYZZ1 Jan 2025

UK universities detect deepfake applicants in automated interviews

Some UK universities use Enroly's automated online interviews to screen international student applicants. Enroly detected about 30 cases of deepfake attempts out of 20,000 interviews during the January 2025 intake. The deepfakes used AI-generated images and audio to replace applicants' faces and voices. Enroly stated it caught the attempts using real-time detection methods.

Company involved
UK universities
AI system involved
Enroly

5 source articles · read the reporting →

← Newerpage 4 of 5Older →