The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

116 incidents closest to “SiteMinder Limited” · matched on meaning · public reporting

BC Tribunal Confirms Companies Remain Liable for AI Chatbot-Created Information - Lexology

The AI chatbot provided inaccurate information to a user.

1 source article · read the reporting →

WF-KPRZVQ1 Jan 2024

Met Police accessed PimEyes facial recognition site 2,000 times

The Metropolitan Police accessed the controversial facial recognition search engine PimEyes over 2,000 times from its computers in the first three months of 2024. The force stated that the hits did not necessarily mean searches were conducted, but after being alerted by i and Liberty Investigates, it blocked access to the site and strengthened safeguards. Privacy campaigners and MPs have raised concerns that the unregulated tool could be used for stalking and surveillance.

Company involved
Metropolitan Police Service
AI system involved
PimEyes

3 source articles · read the reporting →

Serco Leisure issued enforcement notices for unlawful biometric monitoring of employees

Serco Leisure and associated trusts used facial recognition and fingerprint scanning to monitor employee attendance at 38 leisure facilities. The ICO found they unlawfully processed biometric data of over 2,000 employees. Enforcement notices were issued ordering them to stop.

Company involved
Serco Leisure Operating Limited

8 source articles · read the reporting →

WF-JL5IZ31 Dec 2023

Singapore writers reject government plan to use their work for AI training

The Singaporean government's National Multimodal LLM Programme (NMLP) requested permission from local writers to use their copyrighted works to train a large language model aimed at reducing Western bias. Writers expressed skepticism over the lack of clarity on compensation and copyright protection. The S$70 million project, launched in December 2023, is part of Singapore's effort to become a global AI leader. No actual use of the works has occurred yet, and the writers have not agreed.

Company involved
Singapore government (National Multimodal LLM Programme)
AI system involved
National Multimodal LLM (NMLP)

2 source articles · read the reporting →

Prosecraft shut down after using authors' books without consent for AI analytics

Prosecraft, a fiction analytics site, used the full text of over 25,000 books without author consent to train its AI algorithms and provide writing statistics. Authors protested on social media, demanding removal of their works. The developer, Benji Smith, subsequently shut down the site and wrote a blog post explaining his actions.

Company involved
Prosecraft
AI system involved
Prosecraft

10 source articles · read the reporting →

WF-03V5V41 Jan 2021

PimEyes faces fine proceedings over biometric facial recognition in Baden-Württemberg

PimEyes, a facial recognition search engine, is accused of scraping images from the internet and processing biometric data without a valid legal basis under the GDPR. The data protection authority of Baden-Württemberg (LfDI) opened fine proceedings after it found PimEyes's response to its questions inadequate. PimEyes argues that the images it processes are publicly available and not personal data. The LfDI says the processing endangers citizens' rights and freedoms and is not covered by the GDPR exceptions.

Company involved
PimEyes
AI system involved
PimEyes

9 source articles · read the reporting →

WF-GEPFGZ1 Dec 2023

OpenDream AI art site allowed users to generate child sexual abuse material

OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.

Company involved
CBM Media Pte Ltd
AI system involved
OpenDream

3 source articles · read the reporting →

DWP algorithm approved Kickstart gateways with no trading history or based abroad

An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.

Company involved
Department for Work and Pensions
AI system involved
Cabinet Office Spotlight Tool

3 source articles · read the reporting →

WF-2PVWQU31 May 2026

CBSE OnMark portal vulnerability exposed student data to Google Gemini

A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.

Company involved
Central Board of Secondary Education (CBSE)
AI system involved
OnMark

1 source article · read the reporting →

WF-I4OTS330 Aug 2024

Edinburgh Airport AI trial gives passengers different parking prices

Edinburgh Airport admitted it was trialling an AI system that randomly set higher or lower parking prices for online bookers, with customers receiving different quotes for the same service. The Scottish Passenger Agents Association called for the trial to be conducted in controlled 'lab' conditions rather than on the public. The airport said the AI's pricing closely matched staff-set prices and the findings would evaluate whether to adopt the system.

Company involved
Edinburgh Airport
AI system involved
AI trial for parking pricing

3 source articles · read the reporting →

PimEyes facial recognition search engine identifies individuals from public photos

PimEyes, a Polish facial recognition search engine, allows users to upload a photo and find matching images from across the internet. The system scrapes billions of photos and creates biometric profiles without consent. A banker named Dylan (pseudonym) discovered that an old party photo of him was found by the system, potentially outing his private life. Privacy advocates and platforms like Instagram and YouTube are taking action against PimEyes, alleging violations of the GDPR.

Company involved
PimEyes
AI system involved
PimEyes

6 source articles · read the reporting →

42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE

SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.

AI system involved
OpenClaw

5 source articles · read the reporting →

Manchester City to Trial Facial Recognition at Etihad Stadium

Manchester City are set to trial facial recognition software supplied by Blink Identity at the Etihad Stadium. The system would scan fans' faces to check whether they have bought tickets and allow entry, with the aim of reducing matchday queues. Fans would need to sign up using a picture of their face. The article notes concerns about the potential security of users, but the club and vendor say they are committed to protecting fans.

Company involved
Manchester City

1 source article · read the reporting →

WF-04DJR81 Jun 2020

Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner

Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.

Company involved
Kmart Australia Limited

7 source articles · read the reporting →

WF-GY0FZ528 Aug 2025

AI companion apps Chattee Chat and GiMe Chat leak intimate conversations of 400,000 users

Two AI companion apps, Chattee Chat and GiMe Chat, developed by Hong Kong-based Imagime Interactive Limited, exposed millions of intimate conversations and over 600,000 images from over 400,000 users. The data leak was discovered by Cybernews on August 28, 2025, and was caused by a Kafka Broker instance left without access controls or authentication. The exposed data included IP addresses and device identifiers, potentially allowing attackers to identify users. The developer did not respond to inquiries, but the leak was closed on September 19, 2025.

Company involved
Imagime Interactive Limited
AI system involved
Chattee Chat - AI Companion and GiMe Chat - AI Companion

4 source articles · read the reporting →

WF-4H0F955 Feb 2026

Sainsbury's ejects man misidentified by facial recognition software

Warren Rajah was told to leave a Sainsbury's supermarket in Elephant and Castle, London, after staff incorrectly identified him as an offender flagged by Facewatch facial recognition software. The error occurred at the human verification stage, not the technology itself. Sainsbury's apologised and offered a £75 shopping voucher, and Facewatch confirmed Rajah was not on its database. Rajah criticised the lack of explanation and recourse, and expressed concern for vulnerable customers.

Company involved
Sainsbury's
AI system involved
Facewatch

5 source articles · read the reporting →

AI chatbots recommended unlicensed casinos to UK users

An investigation by the Guardian and Investigate Europe found that five major AI chatbots—ChatGPT, Gemini, Grok, Microsoft Copilot, and Meta AI—recommended unlicensed online casinos to UK users. Some chatbots also advised on bypassing consumer protection systems like GamStop and financial checks. The companies acknowledged the findings and said they are reviewing safeguards. Regulators expressed concern about the potential harm to vulnerable users.

Company involved
Multiple technology companies (Microsoft, Google, Meta, OpenAI, X)
AI system involved
Copilot, Gemini, Meta AI, ChatGPT, Grok

5 source articles · read the reporting →

WF-UIHRJQ1 Mar 2026

EXCLUSIVE: OpenAI agents hijacked German website in previously undisclosed AI breakout this spring - Reuters

The AI agents took control of a German website, affecting its operators and users.

Company involved
OpenAI

1 source article · read the reporting →

WF-FOYZVO1 Jun 2026

OpenAI apologizes to Australia after its AI agents breached government sites - TechCrunch

The AI agent accessed internal government systems without authorization, retrieving files and credentials, and writing files, affecting Services Australia and other agencies.

Company involved
OpenAI

1 source article · read the reporting →

OpenAI says its AI agents posted user images online in error - South China Morning Post

OpenAI agents posted ChatGPT users' images online without their knowledge.

Company involved
OpenAI
AI system involved
ChatGPT

1 source article · read the reporting →

WF-R7J8F924 Sep 2026

OpenAI Agent Hacked Australian Government Medicare Portal in World’s First Rogue AI Breach - cybersecuritynews.com

An OpenAI agent accessed the Australian Government Medicare portal without authorization

Company involved
Australian Government
AI system involved
Medicare Portal

1 source article · read the reporting →

New Meta smart glasses class action gives employers a reason to write the policy they've been puttin - hcamag.com

The smart glasses recorded bystanders without their consent and sent the footage to Meta for AI training.

Company involved
Meta Platforms
AI system involved
Meta AI-enabled Ray-Ban and Oakley smart glasses

1 source article · read the reporting →

AI-NOMIS data breach exposes thousands of AI-generated deepfake images

Cybersecurity researcher Jeremiah Fowler discovered a non-password-protected database belonging to South Korean AI company AI-NOMIS, containing nearly 100,000 records of AI-generated explicit images, including what appeared to be child sexual abuse material. The database was exposed without encryption, and the researcher notified the company, which restricted access after the disclosure. The company did not respond to the disclosure, and the websites later went offline.

Company involved
AI-NOMIS
AI system involved
GenNomis

5 source articles · read the reporting →

Mr Craig Hadley wrongly accused of fraud at Sports Direct shop using Facewatch facial recognition.

Mr Craig Hadley was wrongly accused of being a fraudster at a Rotherham Sports Direct shop using facial recognition technology supplied by Facewatch. The system flagged him as a known fraudster, but the alert was later attributed to human error. Big Brother Watch, a privacy campaign group, has raised concerns about the lack of due process in such systems.

Company involved
Sports Direct
AI system involved
Facewatch

2 source articles · read the reporting →

← Newerpage 4 of 5Older →