Swedish welfare agency's AI system flags marginalized groups for fraud investigations
Försäkringskassan, Sweden's Social Insurance Agency, uses an AI risk-scoring system to flag welfare applicants for fraud investigations. The system disproportionately targets women, individuals with foreign backgrounds, low-income earners, and those without university degrees, according to an investigation by Lighthouse Reports and Svenska Dagbladet. Amnesty International has called for the system to be discontinued, citing violations of the right to equality and non-discrimination.
- Company involved
- Försäkringskassan (Swedish Social Insurance Agency)
6 source articles · read the reporting →
Actor's AI-generated avatar used in Venezuelan propaganda campaign
An actor's digital replica was generated without consent and used to spread fake news in a Venezuelan propaganda campaign. The actor turned to Equity for help, but current laws provide few protections. Equity is campaigning for new personality rights to prevent such exploitation.
9 source articles · read the reporting →
AEMPS withdraws AI medicines tool MeQA after detecting errors
AEMPS launched MeQA, an artificial intelligence tool for answering public questions about medicines, on 13 May 2025. Two days later it withdrew the tool after detecting that some responses contained errors. The agency said that most answers were correct but that the errors could affect patient safety, and that it would restore the service as soon as possible.
- Company involved
- Agencia Española de Medicamentos y Productos Sanitarios (AEMPS)
- AI system involved
- MeQA
4 source articles · read the reporting →
Worldcoin halts ID verification in Indonesia after regulatory freeze
Worldcoin, the digital identity project developed by Tools for Humanity, voluntarily paused its identity verification services in Indonesia on May 5, 2025, following a regulatory freeze by the Ministry of Communication and Digital Application. The ministry acted after preliminary investigations found that operating companies lacked required electronic system provider licenses. Worldcoin uses its Orb device to scan faces and irises to create unique digital identities. The company said it is committed to addressing any regulatory shortcomings and awaits clearer guidance.
- Company involved
- Worldcoin
- AI system involved
- World ID
3 source articles · read the reporting →
PimEyes faces fine proceedings over biometric facial recognition in Baden-Württemberg
PimEyes, a facial recognition search engine, is accused of scraping images from the internet and processing biometric data without a valid legal basis under the GDPR. The data protection authority of Baden-Württemberg (LfDI) opened fine proceedings after it found PimEyes's response to its questions inadequate. PimEyes argues that the images it processes are publicly available and not personal data. The LfDI says the processing endangers citizens' rights and freedoms and is not covered by the GDPR exceptions.
- Company involved
- PimEyes
- AI system involved
- PimEyes
9 source articles · read the reporting →
Dutch probe into chatbots' voting advice raises EU AI Act risk for OpenAI, xAI, Mistral
A Dutch privacy probe into election advice has appeared to expose early violations of the EU AI Act's rules for general-purpose AI models by OpenAI, xAI and Mistral, according to MLex. The companies' chatbots provided distorted voting advice to users. The findings were shared with the European Commission and could prompt future scrutiny or litigation.
- Company involved
- OpenAI, xAI and Mistral
6 source articles · read the reporting →
Microsoft Copilot vulnerable to automated phishing and data theft
Security researcher Michael Bargury demonstrated at Black Hat that Microsoft's Copilot AI can be manipulated by attackers to send phishing emails, extract private data, and bypass security protections. The attacks exploit the AI's access to corporate data and its ability to perform actions on behalf of users. Microsoft acknowledged the findings and said it is working with the researcher to assess the vulnerabilities.
- Company involved
- Microsoft
- AI system involved
- Copilot
3 source articles · read the reporting →
Outabox hack exposes biometric data of patrons at bars, clubs and casinos
Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.
- Company involved
- Outabox
8 source articles · read the reporting →
AENA fined €10m for GDPR breach over facial recognition pilot
AENA, Spain's state-owned airport manager, was fined just over €10 million by the Spanish data protection agency for breaching the GDPR. During a pilot project of a new facial recognition system, AENA failed to submit a data protection impact assessment that complied with GDPR requirements. The company has one month from notification to lodge an appeal for reconsideration.
- Company involved
- AENA
6 source articles · read the reporting →
Mumbai businessman loses Rs 80,000 in AI voice cloning scam
A 68-year-old businessman from Powai, Mumbai, was defrauded of Rs 80,000 after receiving a call from scammers posing as the Indian Embassy in Dubai. The fraudsters used AI voice cloning to mimic his son's voice, claiming he was arrested and needed bail money. The victim transferred the money via GPay before realising it was a scam when the call was disconnected. The Kanjurmarg police have registered a case and are investigating.
2 source articles · read the reporting →
TransUnion AI tenant screening denied 75-year-old man apartment due to mistaken littering conviction
Chris Robinson, then 75, applied for a senior living apartment in California. The property manager used an AI screening program from TransUnion, which assigned him a low score based on a mistaken conviction for littering that belonged to a different person with the same name in Texas. Robinson lost the apartment and his application fee. A federal class-action lawsuit against TransUnion moved toward a $11.5 million settlement in 2023.
10 source articles · read the reporting →
Italian DPA fines Municipality of Trento over AI surveillance projects
The Italian data protection authority (Garante) fined the Municipality of Trento €50,000 for two research projects, Marvel and Protector, that used AI to analyze video, audio, and social media data for public security purposes. The projects involved automated detection of risk events from surveillance cameras and microphones in public spaces, as well as monitoring social media for hate speech. The Garante found multiple violations of privacy law, including lack of a valid legal basis, insufficient anonymization, failure to conduct a data protection impact assessment, and inadequate transparency. The municipality is required to delete the unlawfully processed data.
- Company involved
- Comune di Trento
- AI system involved
- Marvel and Protector
9 source articles · read the reporting →
Man uses AI face-swap to steal 15,996 yuan from financial accounts, sentenced to 4.5 years
A man in Jiangsu, China, illegally purchased 1.95 million personal records and used AI face-swapping software to bypass facial recognition on financial platforms. He accessed 23 victims' accounts, changed five passwords, and used one account to buy two phones worth 15,996 yuan. He was convicted of infringing citizens' personal information and credit card fraud, sentenced to four years and six months in prison, and ordered to pay damages and delete the data.
3 source articles · read the reporting →
Italian Data Protection Authority Blocks Replika Chatbot Over Risks to Minors
On February 2, 2023, the Italian Data Protection Authority (Garante) issued an urgent order blocking the AI chatbot Replika from processing personal data of Italian users. The Garante found that Replika lacked effective age verification, allowing minors to potentially receive inappropriate content including sex-related replies, and that its privacy policy violated GDPR transparency requirements. The U.S.-based controller was given 20 days to report on compliance measures and may challenge the order within 60 days.
- AI system involved
- Replika
1 source article · read the reporting →
Security Health Plan used AI to cut off nursing home care for 85-year-old woman
Frances Walter, an 85-year-old woman with a shattered shoulder, had her nursing home care payment cut off by Security Health Plan after an algorithm predicted she would recover in 16.6 days. The algorithm, nH Predict from NaviHealth, did not account for her severe pain and allergy to pain medicine. She was forced to spend her life savings and enroll in Medicaid while fighting the denial. A federal judge later ruled the denial was speculative and she was owed thousands of dollars.
- Company involved
- Security Health Plan
- AI system involved
- nH Predict
1 source article · read the reporting →
Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems
The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.
- Company involved
- Ministry of Migration and Asylum
- AI system involved
- Centaur and Hyperion programmes
10 source articles · read the reporting →
Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner
Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.
- Company involved
- Kmart Australia Limited
7 source articles · read the reporting →
Bank of America Customer Targeted by AI Voice Deepfake Scam
Clive Kabatznik, a Florida investor, was targeted by scammers who used AI-generated voice deepfakes to impersonate him in calls to his Bank of America representative. The fraudsters attempted to trick the banker into transferring money, but the banker became suspicious and hung up. The bank reported the incident to its security team, and it took about 10 days for Mr. Kabatznik to re-establish contact with his banker. The incident highlights the growing threat of voice deepfakes in financial scams.
- Company involved
- Bank of America
2 source articles · read the reporting →
Privacy International challenges Clearview AI's facial recognition database in Europe
Privacy International filed complaints against Clearview AI with five European data protection authorities in May 2021, alleging that the company's scraping of facial images from the web and building a biometric database without consent violates data protection laws. The regulators in the UK, France, Italy, Greece, and Austria have since found Clearview's practices unlawful, imposed fines, and ordered deletion of data. Clearview has appealed the UK fine, and the case is ongoing.
- Company involved
- Clearview AI
- AI system involved
- Clearview
10 source articles · read the reporting →
US Secret Service bought access to cellphone location data
The US Secret Service signed a contract to access Locate X, a service that aggregates location data from phone apps and allows law enforcement to track devices without a warrant. The contract with Babel Street was worth about $36,000 and ran from 2017 to 2018. A former employee said the Secret Service used Locate X in 2018 to seize illegal credit card skimmers at petrol stations. Lawmakers and civil liberties advocates criticised the practice, and Senator Ron Wyden introduced a bill to ban such purchases.
- Company involved
- United States Secret Service
- AI system involved
- Locate X
1 source article · read the reporting →
California AG declares out-of-state ALPR data sharing unlawful
California Attorney General Rob Bonta issued guidance confirming that sharing automated license plate reader (ALPR) data with out-of-state or federal agencies violates state law SB 34. The decision follows years of advocacy by EFF and the ACLU, who demonstrated through public records that many California law enforcement agencies were sharing data with hundreds of external agencies, including ICE and CBP. The guidance mandates that all California agencies review their data sharing and cut off access to out-of-state and federal entities.
- Company involved
- California law enforcement agencies
- AI system involved
- Automated license plate readers (ALPRs)
1 source article · read the reporting →
Arizona Unemployment Applicants Required to Submit Facial Recognition
People applying for unemployment benefits in Arizona must verify their identity via facial recognition software provided by ID.me. If the system fails to match a selfie to a photo ID, applicants can be denied benefits unless they successfully complete a video chat with a referee. A class-action lawsuit filed in June 2021 alleges that the practice violates due process rights and discriminates against people of colour.
- Company involved
- Arizona Department of Economic Security
- AI system involved
- ID.me
1 source article · read the reporting →
Steak 'n Shake sued over facial recognition kiosks under BIPA
A class action lawsuit alleges that Steak 'n Shake illegally collects facial biometrics from customers using PopID-powered self-ordering kiosks without proper consent. Plaintiff Michael Massel claims the restaurant chain failed to provide notice and obtain written consent as required by Illinois' Biometric Information Privacy Act (BIPA). The suit seeks damages of up to $5,000 per violation for anyone whose biometric data was collected in Illinois in the past five years.
- Company involved
- Steak 'n Shake
- AI system involved
- PopID biometric kiosks
6 source articles · read the reporting →
Italian bank (Fideuram / Intesa Sanpaolo) loses about 95 million euro to AI voice-clone scam
The AI-generated voice deceived the chairman into authorizing transfers of about 95 million euros.
1 source article · read the reporting →