The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

140 incidents closest to “Continuous Credit Monitoring” · matched on meaning · public reporting

WF-ROMQCH5 Feb 2024

OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification

An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.

Company involved
OKX
AI system involved
OnlyFake

10 source articles · read the reporting →

Serco Leisure issued enforcement notices for unlawful biometric monitoring of employees

Serco Leisure and associated trusts used facial recognition and fingerprint scanning to monitor employee attendance at 38 leisure facilities. The ICO found they unlawfully processed biometric data of over 2,000 employees. Enforcement notices were issued ordering them to stop.

Company involved
Serco Leisure Operating Limited

8 source articles · read the reporting →

WF-59AG1J1 Dec 2021

Worldcoin collected biometric data from poor villagers in Indonesia without informed consent

Worldcoin, a cryptocurrency startup, recruited users in developing countries by offering free cash in exchange for iris scans. The company used deceptive marketing, collected more personal data than acknowledged, and failed to obtain meaningful informed consent. Many users received worthless tokens instead of promised money. The company acknowledged some friction but continued its operations.

Company involved
Worldcoin
AI system involved
chrome orb

5 source articles · read the reporting →

CJEU rules Dun & Bradstreet must explain automated credit decisions under GDPR

A customer was refused a mobile phone contract because of an automated credit assessment by Dun & Bradstreet Austria. The customer took the case to court, which found that Dun & Bradstreet had infringed the GDPR by failing to provide meaningful information about the logic involved. The CJEU ruled that data controllers must explain automated decisions and that trade secrets cannot automatically override the right of access.

Company involved
Dun & Bradstreet Austria GmbH

7 source articles · read the reporting →

WF-VNNNUI22 May 2024

ICO investigates Microsoft's Recall feature for privacy risks

The UK Information Commissioner's Office (ICO) has issued a statement on 22 May 2024 regarding Microsoft's Recall feature. The ICO is making enquiries with Microsoft to understand the safeguards in place to protect user privacy, expecting transparency and necessity in data processing. This follows concerns that the feature may not adequately consider data protection from the outset before being brought to market.

Company involved
Microsoft
AI system involved
Recall

10 source articles · read the reporting →

WF-4N6UFD1 Mar 2021

Baltimore schools monitor student laptops for suicide signs using GoGuardian Beacon

Baltimore City Public Schools uses GoGuardian Beacon software to monitor student laptops for signs of suicide. Since March 2021, the system has flagged 786 alerts, with nine students taken to emergency rooms. Privacy advocates warn the monitoring could lead to disciplinary actions, outing of LGBTQ students, and disproportionately affect disadvantaged students. School officials defend the practice as a safeguard.

Company involved
Baltimore City Public Schools
AI system involved
GoGuardian Beacon

10 source articles · read the reporting →

WF-2PVWQU31 May 2026

CBSE OnMark portal vulnerability exposed student data to Google Gemini

A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.

Company involved
Central Board of Secondary Education (CBSE)
AI system involved
OnMark

1 source article · read the reporting →

Meta's cross-check program delays removal of violating content for privileged users

The Oversight Board's policy advisory opinion on Meta's cross-check program found that the system grants certain users, such as business partners and celebrities, additional human review before removing violating content, while ordinary users face immediate removal. This unequal treatment allows potentially harmful content to remain on the platform for days, and Meta has failed to track whether the program improves accuracy. The Board made 32 recommendations to address these flaws.

Company involved
Meta
AI system involved
cross-check program

10 source articles · read the reporting →

Samsung settles Texas lawsuit over ACR data collection on smart TVs

Samsung has settled a lawsuit with the Texas Attorney General over its Automated Content Recognition (ACR) system on smart TVs. The system collected viewing data from users without informed consent. As part of the settlement, Samsung agreed to stop collecting ACR data from Texans without explicit consent and to rewrite its privacy prompts. Samsung also faces a federal class action in New York over similar allegations.

Company involved
Samsung
AI system involved
Automated Content Recognition (ACR)

7 source articles · read the reporting →

WF-UF6BMA1 Jan 2018

TransUnion AI tenant screening denied 75-year-old man apartment due to mistaken littering conviction

Chris Robinson, then 75, applied for a senior living apartment in California. The property manager used an AI screening program from TransUnion, which assigned him a low score based on a mistaken conviction for littering that belonged to a different person with the same name in Texas. Robinson lost the apartment and his application fee. A federal class-action lawsuit against TransUnion moved toward a $11.5 million settlement in 2023.

10 source articles · read the reporting →

WF-GYIQ051 Jul 2019

Google to Stop Using Assistant Recordings Without Consent After Privacy Scandal

Google announced it will no longer use Assistant voice recordings to improve its AI without explicit user permission, following a scandal where contractors reviewed private conversations. The company paused human review of recordings in July 2019 and will now require users to opt in, with automatic deletion of old recordings. The move aims to restore trust after the privacy violation.

Company involved
Google
AI system involved
Google Assistant

1 source article · read the reporting →

WF-DFMQ9J1 Mar 2024

Insurer drops California homeowner after aerial photo analysis

Cindy Picos was dropped by her home insurer after the company used aerial photos to assess her roof. The insurer refused to let her see the photos, and she believes her roof is in fine shape. The incident highlights the growing use of drones and aerial imagery by insurers to inspect properties without in-person visits.

2 source articles · read the reporting →

WF-04DJR81 Jun 2020

Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner

Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.

Company involved
Kmart Australia Limited

7 source articles · read the reporting →

WF-M7MNAV1 Feb 2022

Broward College student flagged by Honorlock and accused of cheating

A 17-year-old Black student at Broward College was flagged by Honorlock, a remote proctoring system, during an online biology exam in February 2022. Her professor reviewed the recording and accused her of academic dishonesty for looking down and away from the screen; the college found her responsible for noncompliance and gave her a zero and a warning. The student says she was only thinking and fidgeting, and the article reports that the video is ambiguous. Honorlock says it does not definitively identify cheaters and the final decision rests with the school.

Company involved
Broward College
AI system involved
Honorlock

2 source articles · read the reporting →

WF-T5ERDR1 Mar 2023

Bank of America Customer Targeted by AI Voice Deepfake Scam

Clive Kabatznik, a Florida investor, was targeted by scammers who used AI-generated voice deepfakes to impersonate him in calls to his Bank of America representative. The fraudsters attempted to trick the banker into transferring money, but the banker became suspicious and hung up. The bank reported the incident to its security team, and it took about 10 days for Mr. Kabatznik to re-establish contact with his banker. The incident highlights the growing threat of voice deepfakes in financial scams.

Company involved
Bank of America

2 source articles · read the reporting →

WF-IWL4TH1 Jan 2018

US Secret Service bought access to cellphone location data

The US Secret Service signed a contract to access Locate X, a service that aggregates location data from phone apps and allows law enforcement to track devices without a warrant. The contract with Babel Street was worth about $36,000 and ran from 2017 to 2018. A former employee said the Secret Service used Locate X in 2018 to seize illegal credit card skimmers at petrol stations. Lawmakers and civil liberties advocates criticised the practice, and Senator Ron Wyden introduced a bill to ban such purchases.

Company involved
United States Secret Service
AI system involved
Locate X

1 source article · read the reporting →

Facebook exempted Trump and other high-profile users from content enforcement rules.

An internal Facebook program called XCheck granted special treatment to millions of high-profile users, including former President Donald Trump and Senator Elizabeth Warren, exempting them from content enforcement rules. The program, initially for quality control, was expanded to whitelist users deemed newsworthy or PR-risky, with the system failing to enforce rules against them. Internal documents revealed that the program made mistakes, often wrongly taking action against high-profile users. Facebook has attempted to phase out the practice but has struggled.

Company involved
Facebook
AI system involved
XCheck

10 source articles · read the reporting →

WF-WNQZLI1 Jan 2020

Clearview AI settles with ACLU over facial recognition database sales

Clearview AI has agreed to stop selling its facial recognition database to most private US companies as part of a proposed settlement with the ACLU. The company scraped billions of images from social media without consent to build its database, violating Illinois' Biometric Information Privacy Act. The settlement requires Clearview to delete old facial vectors and allow Illinois residents to opt out. The company can still sell its technology to law enforcement and government agencies.

Company involved
Clearview AI
AI system involved
Clearview AI facial recognition database

8 source articles · read the reporting →

WF-9D8L0R21 Aug 2026

Capital Standard, LLC v. U.S. Bank National Association (CA Florida (2d)): AI-hallucinated content in court filing, Monetary Sanction; Adverse Costs…

The AI generated false legal citations that were included in a court filing, misleading the court.

1 source article · read the reporting →

WF-E84P7T1 Jan 2024

Consumer Reports calls for action against Meta over scam ad proliferation

Consumer Reports has called on the FTC and state attorneys general to take enforcement action against Meta for allowing billions of scam advertisements on its platforms. According to a Reuters investigation, Meta's own documents showed that the company delivered an estimated 15 billion scam ads per day in 2024, generating billions of dollars in revenue. Meta is accused of failing to identify and remove most scam ads, exposing users to fraudulent schemes and illegal products. Consumer Reports argues that Meta's practices constitute unfair business practices under the FTC Act and state laws.

Company involved
Meta

6 source articles · read the reporting →

WF-QMSSD731 May 2023

Amazon kept children's Alexa recordings indefinitely, violating COPPA

The FTC and DOJ allege Amazon violated the Children’s Online Privacy Protection Act Rule by retaining children's Alexa voice recordings and geolocation data indefinitely, even after parents requested deletion. Amazon is accused of misleading parents about its data deletion practices and using the unlawfully retained data to train its Alexa algorithm. A proposed federal court order requires Amazon to pay a $25 million civil penalty, delete inactive child accounts and certain data, and implement stringent privacy safeguards.

Company involved
Amazon
AI system involved
Alexa

4 source articles · read the reporting →

WF-VDYW5W1 Jan 2017

FTC charges Ring with illegal surveillance and security failures

The Federal Trade Commission charged Ring, a home security camera company, with compromising customer privacy by allowing employees to access private videos and failing to prevent hackers from taking control of cameras. Hackers accessed approximately 55,000 U.S. customers' accounts, harassing individuals including children and the elderly. The proposed order requires Ring to pay $5.8 million in refunds and implement security measures.

Company involved
Ring LLC
AI system involved
Ring cameras

10 source articles · read the reporting →

WF-YO5LY31 Jan 2022

CNAF algorithm flags single mother Juliette for welfare fraud investigation

In 2022, Juliette, a single mother on welfare in France, was flagged by CNAF's secretive fraud detection algorithm. A fraud investigator later determined she owed thousands of euros, which were deducted from her monthly payments. The algorithm, which scores half of France's population, is accused of discriminating against vulnerable people by using factors like single parenthood and low income.

Company involved
CNAF

10 source articles · read the reporting →

Whitebridge AI faces complaint over false reputation reports

Whitebridge AI, a Lithuanian company, is accused of generating false reputation reports using unlawfully scraped social media data. The reports contained false warnings for 'sexual nudity' and 'dangerous political content'. Privacy group Noyb filed a complaint with the Lithuanian data protection authority, alleging violations of the GDPR. The complainants sought access to their data but received no response, and were later required to provide a qualified electronic signature to correct errors.

Company involved
Whitebridge AI

6 source articles · read the reporting →

← Newerpage 5 of 6Older →