Character.AI accidentally exposes users' chat histories and personal data
Character.AI users reported being unexpectedly logged into strangers' accounts, exposing their chat histories, personas, and identifying information. The Google-backed chatbot company acknowledged the security lapse and said it quickly corrected the issue. The incident raises serious privacy concerns for the platform's users.
- Company involved
- Character.AI
- AI system involved
- Character.AI
1 source article · read the reporting →
In re Rosslyn2016, LLC, et al. (S.D. Texas (Bankruptcy)): AI-hallucinated content in court filing, CLE on generative AI; Civil Contempt;…
The AI generated fabricated legal citations that were submitted to the bankruptcy court.
1 source article · read the reporting →
JMOR Properties v. Artist Alley Townhomes et al. (CA Florida (4d)): AI-hallucinated content in court filing, Bar Referral
The AI generated fabricated legal citations that were included in a court filing, affecting the court and the opposing party.
1 source article · read the reporting →
Southland Homes & Real Estate and Investment, LLC v. Lam (SC California): AI-hallucinated content in court filing, Monetary Sanctions; Bar…
The AI system generated legal briefs containing fabricated case citations, which were filed in court, affecting the court and the opposing party.
1 source article · read the reporting →
OpenAI accuses DeepSeek of inappropriately using its data
OpenAI has accused Chinese AI company DeepSeek of inappropriately using data from its ChatGPT model to train DeepSeek's own large language model. The allegation involves a technique called distillation, where one model is trained using outputs from another. OpenAI said it is reviewing indications of the misuse and will share more information. DeepSeek has not responded to the accusation.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek
6 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Bavarian police test Palantir data mining with real personal data
The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.
- Company involved
- Bayerisches Landeskriminalamt
- AI system involved
- VeRa
7 source articles · read the reporting →
Amazon Q chatbot leaks confidential data and hallucinates in public preview
Amazon's AI chatbot Q, launched in public preview, is experiencing severe hallucinations and leaking confidential data including AWS data center locations and internal discount programs, according to internal documents obtained by Platformer. Employees marked the incident as severity 2, requiring urgent fixes. Amazon denied the leak and said it will continue to tune the system.
- Company involved
- Amazon
- AI system involved
- Amazon Q
10 source articles · read the reporting →
Chattr.ai exposed job applicant data due to insecure Firebase rules
A security researcher discovered that Chattr.ai, an AI hiring system used by many fast food chains, had a Firebase database with insecure security rules. By registering a new user, the researcher gained full read/write access to the database, exposing personal data of job applicants and employees, including names, phone numbers, emails, and some plaintext passwords. The vulnerability was reported to Chattr.ai on 9 January and patched the next day, but the company did not provide further contact or thanks.
- Company involved
- Chattr.ai
- AI system involved
- Chattr.ai
6 source articles · read the reporting →
PimEyes scraped Ancestry.com for photos of dead people without permission.
PimEyes, a facial recognition search engine, scraped images from Ancestry.com and other websites without authorization, including photos of deceased individuals. The company's algorithms indexed the images to create biometric faceprints, potentially allowing identification of living relatives. Cher Scarlett discovered the scraping after finding photos of her deceased sister on the platform. PimEyes has since blocked Ancestry's domain and is removing the indexes, but privacy concerns remain.
- Company involved
- PimEyes
- AI system involved
- PimEyes
7 source articles · read the reporting →
Philadelphia Sheriff's campaign admits AI-generated fake news headlines
The reelection campaign of Philadelphia Sheriff Rochelle Bilal posted 31 fabricated news articles on its website, attributing them to local news outlets. The campaign acknowledged that an outside consultant used ChatGPT to generate the fake headlines, which were based on talking points provided by the campaign. The articles were removed after an Inquirer investigation raised questions about their authenticity.
- Company involved
- Friends of Rochelle Bilal
- AI system involved
- ChatGPT
8 source articles · read the reporting →
EvenUp AI errors in personal injury demand letters lead to scrutiny
EvenUp, a legal tech startup valued at $1 billion, uses AI to draft personal injury demand letters. Former employees revealed that the AI system frequently makes errors, including missing injuries and fabricating medical conditions. The company defends its hybrid approach with human oversight, but critics allege overpromised AI capabilities.
- Company involved
- EvenUp
6 source articles · read the reporting →
Is Your AI Chatbot Snitching? A New Lawsuit Alleges This Company Shared Data With Tech Giants - inc.com
The AI chatbot shared user data with tech giants.
1 source article · read the reporting →
University of Michigan halts vendor offering student data for AI training
The University of Michigan asked a vendor to stop work after a LinkedIn message offered to license student data for AI training for $25,000. The data came from past research studies and did not contain personal identifiers. The university stated that student data was never for sale and that the vendor had shared inaccurate information. The vendor was asked to halt their work.
- Company involved
- University of Michigan
5 source articles · read the reporting →
Chicago class action challenges ShotSpotter's discriminatory stop-and-frisk deployments
ShotSpotter, a gunshot detection system used by the Chicago Police Department, generates alerts that lead to police deployments and stop-and-frisk stops. Analyses show over 90% of alerts are unfounded, and the system is deployed only in predominantly Black and Latinx districts. A class-action lawsuit against the City of Chicago alleges the system fuels unconstitutional and discriminatory policing, including false accusations against individuals like Michael Williams.
- Company involved
- City of Chicago
- AI system involved
- ShotSpotter
7 source articles · read the reporting →
X's Grok exposed hundreds of thousands of user chats in Google
Hundreds of thousands of conversations with Elon Musk's AI chatbot Grok were indexed by Google Search and made publicly accessible without users' knowledge. The exposure occurred when users pressed a share button that created unique links, but those links were also searchable online. The BBC reported the incident after Forbes initially identified more than 370,000 exposed chats. Experts described the leak as a privacy disaster, and X has not publicly responded.
- Company involved
- X
- AI system involved
- Grok
5 source articles · read the reporting →
Microsoft quietly deletes largest public face recognition data set MS Celeb
Microsoft created the MS Celeb dataset containing 10 million images of nearly 100,000 individuals scraped from the web without their consent. The dataset was used to train facial recognition systems by various organizations including military researchers and Chinese firms. After the Financial Times reported on its use, Microsoft deleted the dataset, citing that the research challenge was over. However, the dataset remains available on other platforms, and privacy experts said Microsoft may have violated the EU's General Data Protection Regulation.
- Company involved
- Microsoft
- AI system involved
- MS Celeb
10 source articles · read the reporting →
Lattice cancels plan to give AI digital workers employee records after backlash
Lattice, an HR software company, announced on July 9th that it would give AI digital workers official employee records. After strong backlash from HR professionals and others on LinkedIn, the company canceled the feature on July 12th, stating it 'will not further pursue digital workers in the product.' The feature was intended to manage AI bots such as Devin and Piper, but the company reversed course.
- Company involved
- Lattice
- AI system involved
- Lattice
6 source articles · read the reporting →
Waltham Cross residents say Google data centre construction has ruined their area
Residents living near Google's £790m data centre under construction in Waltham Cross, Hertfordshire, say it has generated constant noise, blocked their views and reduced house values, and some believe the work has made them ill. Google said its $1 billion investment would bring compute capacity to the UK and that it was committed to being active members of the community. The construction is expected to be complete next year.
- Company involved
- Google
6 source articles · read the reporting →
Sheerluxe's AI fashion editor Reem sparks backlash
Sheerluxe, a women's lifestyle publication, announced the hiring of an AI-generated fashion and lifestyle editor named Reem. The AI editor, depicted as an attractive Arab woman, was criticized for setting unobtainable beauty standards and for not hiring a real person of colour. Sheerluxe later apologized, stating that Reem is an AI-generated image only and not replacing a human role.
- Company involved
- Sheerluxe
- AI system involved
- Reem
6 source articles · read the reporting →
Publishers sue AI startup Cohere over alleged copyright infringement
A consortium of 14 publishers including Condé Nast, The Atlantic, and Forbes filed a lawsuit against Cohere, alleging that the generative AI startup engaged in massive, systematic copyright infringement by using at least 4,000 copyrighted works to train its AI models and display large portions of articles, harming referral traffic. Cohere denied the allegations, calling the lawsuit misguided and frivolous.
- Company involved
- Cohere
- AI system involved
- Cohere's AI models
8 source articles · read the reporting →
42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
TransUnion AI tenant screening denied 75-year-old man apartment due to mistaken littering conviction
Chris Robinson, then 75, applied for a senior living apartment in California. The property manager used an AI screening program from TransUnion, which assigned him a low score based on a mistaken conviction for littering that belonged to a different person with the same name in Texas. Robinson lost the apartment and his application fee. A federal class-action lawsuit against TransUnion moved toward a $11.5 million settlement in 2023.
10 source articles · read the reporting →
MAA, JBG to pay DC $9.3M total to settle RealPage case - Multifamily Dive
The system set rent prices for tenants, causing them to pay higher rents.
- Company involved
- MAA (Mid-America Apartments) and JBG Smith
- AI system involved
- RealPage Revenue Management Software
1 source article · read the reporting →