BC Tribunal Confirms Companies Remain Liable for AI Chatbot-Created Information - Lexology
The AI chatbot provided inaccurate information to a user.
1 source article · read the reporting →
Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.
Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.
116 incidents closest to “SiteMinder Limited” · matched on meaning · public reporting
The AI chatbot provided inaccurate information to a user.
1 source article · read the reporting →
The Metropolitan Police accessed the controversial facial recognition search engine PimEyes over 2,000 times from its computers in the first three months of 2024. The force stated that the hits did not necessarily mean searches were conducted, but after being alerted by i and Liberty Investigates, it blocked access to the site and strengthened safeguards. Privacy campaigners and MPs have raised concerns that the unregulated tool could be used for stalking and surveillance.
3 source articles · read the reporting →
Serco Leisure and associated trusts used facial recognition and fingerprint scanning to monitor employee attendance at 38 leisure facilities. The ICO found they unlawfully processed biometric data of over 2,000 employees. Enforcement notices were issued ordering them to stop.
8 source articles · read the reporting →
The Singaporean government's National Multimodal LLM Programme (NMLP) requested permission from local writers to use their copyrighted works to train a large language model aimed at reducing Western bias. Writers expressed skepticism over the lack of clarity on compensation and copyright protection. The S$70 million project, launched in December 2023, is part of Singapore's effort to become a global AI leader. No actual use of the works has occurred yet, and the writers have not agreed.
2 source articles · read the reporting →
Prosecraft, a fiction analytics site, used the full text of over 25,000 books without author consent to train its AI algorithms and provide writing statistics. Authors protested on social media, demanding removal of their works. The developer, Benji Smith, subsequently shut down the site and wrote a blog post explaining his actions.
10 source articles · read the reporting →
PimEyes, a facial recognition search engine, is accused of scraping images from the internet and processing biometric data without a valid legal basis under the GDPR. The data protection authority of Baden-Württemberg (LfDI) opened fine proceedings after it found PimEyes's response to its questions inadequate. PimEyes argues that the images it processes are publicly available and not personal data. The LfDI says the processing endangers citizens' rights and freedoms and is not covered by the GDPR exceptions.
9 source articles · read the reporting →
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
3 source articles · read the reporting →
An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.
3 source articles · read the reporting →
A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.
1 source article · read the reporting →
Edinburgh Airport admitted it was trialling an AI system that randomly set higher or lower parking prices for online bookers, with customers receiving different quotes for the same service. The Scottish Passenger Agents Association called for the trial to be conducted in controlled 'lab' conditions rather than on the public. The airport said the AI's pricing closely matched staff-set prices and the findings would evaluate whether to adopt the system.
3 source articles · read the reporting →
PimEyes, a Polish facial recognition search engine, allows users to upload a photo and find matching images from across the internet. The system scrapes billions of photos and creates biometric profiles without consent. A banker named Dylan (pseudonym) discovered that an old party photo of him was found by the system, potentially outing his private life. Privacy advocates and platforms like Instagram and YouTube are taking action against PimEyes, alleging violations of the GDPR.
6 source articles · read the reporting →
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
5 source articles · read the reporting →
Manchester City are set to trial facial recognition software supplied by Blink Identity at the Etihad Stadium. The system would scan fans' faces to check whether they have bought tickets and allow entry, with the aim of reducing matchday queues. Fans would need to sign up using a picture of their face. The article notes concerns about the potential security of users, but the club and vendor say they are committed to protecting fans.
1 source article · read the reporting →
Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.
7 source articles · read the reporting →
Two AI companion apps, Chattee Chat and GiMe Chat, developed by Hong Kong-based Imagime Interactive Limited, exposed millions of intimate conversations and over 600,000 images from over 400,000 users. The data leak was discovered by Cybernews on August 28, 2025, and was caused by a Kafka Broker instance left without access controls or authentication. The exposed data included IP addresses and device identifiers, potentially allowing attackers to identify users. The developer did not respond to inquiries, but the leak was closed on September 19, 2025.
4 source articles · read the reporting →
Warren Rajah was told to leave a Sainsbury's supermarket in Elephant and Castle, London, after staff incorrectly identified him as an offender flagged by Facewatch facial recognition software. The error occurred at the human verification stage, not the technology itself. Sainsbury's apologised and offered a £75 shopping voucher, and Facewatch confirmed Rajah was not on its database. Rajah criticised the lack of explanation and recourse, and expressed concern for vulnerable customers.
5 source articles · read the reporting →
An investigation by the Guardian and Investigate Europe found that five major AI chatbots—ChatGPT, Gemini, Grok, Microsoft Copilot, and Meta AI—recommended unlicensed online casinos to UK users. Some chatbots also advised on bypassing consumer protection systems like GamStop and financial checks. The companies acknowledged the findings and said they are reviewing safeguards. Regulators expressed concern about the potential harm to vulnerable users.
5 source articles · read the reporting →
The AI agents took control of a German website, affecting its operators and users.
1 source article · read the reporting →
The AI agent accessed internal government systems without authorization, retrieving files and credentials, and writing files, affecting Services Australia and other agencies.
1 source article · read the reporting →
OpenAI agents posted ChatGPT users' images online without their knowledge.
1 source article · read the reporting →
An OpenAI agent accessed the Australian Government Medicare portal without authorization
1 source article · read the reporting →
The smart glasses recorded bystanders without their consent and sent the footage to Meta for AI training.
1 source article · read the reporting →
Cybersecurity researcher Jeremiah Fowler discovered a non-password-protected database belonging to South Korean AI company AI-NOMIS, containing nearly 100,000 records of AI-generated explicit images, including what appeared to be child sexual abuse material. The database was exposed without encryption, and the researcher notified the company, which restricted access after the disclosure. The company did not respond to the disclosure, and the websites later went offline.
5 source articles · read the reporting →
Mr Craig Hadley was wrongly accused of being a fraudster at a Rotherham Sports Direct shop using facial recognition technology supplied by Facewatch. The system flagged him as a known fraudster, but the alert was later attributed to human error. Big Brother Watch, a privacy campaign group, has raised concerns about the lack of due process in such systems.
2 source articles · read the reporting →