The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

140 incidents closest to “HCC Capture” · matched on meaning · public reporting

Serco Leisure issued enforcement notices for unlawful biometric monitoring of employees

Serco Leisure and associated trusts used facial recognition and fingerprint scanning to monitor employee attendance at 38 leisure facilities. The ICO found they unlawfully processed biometric data of over 2,000 employees. Enforcement notices were issued ordering them to stop.

Company involved
Serco Leisure Operating Limited

8 source articles · read the reporting →

WF-3OJOAW6 Mar 2024

AI image generators produce misleading election images, study finds

A study by the Center for Countering Digital Hate found that leading AI image generators, including Midjourney, DreamStudio, ChatGPT Plus, and Microsoft Image Creator, could be manipulated to create misleading election-related images. The researchers used jailbreaking techniques to bypass safety measures, producing photorealistic images of candidates in compromising situations or of voting fraud. The companies responded by stating they are updating policies and implementing safeguards, but the study suggests existing protections are inadequate.

Company involved
Midjourney, Stability AI, OpenAI, Microsoft
AI system involved
Midjourney, DreamStudio, ChatGPT Plus, Microsoft Image Creator

8 source articles · read the reporting →

WF-BMI81A1 Jan 2020

UNOS liver allocation policy reduces transplants in poorer states

The United Network for Organ Sharing (UNOS) implemented a new liver allocation policy in 2020 called the acuity circles system, which prioritizes the sickest patients regardless of location. An analysis by The Markup and The Washington Post found that the policy led to sharp declines in liver transplants in several Southern and Midwestern states and Puerto Rico, while increasing transplants in New York and California. Patients in affected states allege the system disadvantages poorer regions, and hospitals have sued to overturn the policy.

Company involved
United Network for Organ Sharing (UNOS)
AI system involved
Acuity circles liver allocation policy

10 source articles · read the reporting →

WF-2X3B7831 Jan 2024

Hong Kong privacy watchdog raids Worldcoin offices over iris scan data collection

Hong Kong's privacy commissioner's office raided six premises linked to Worldcoin, a cryptocurrency company that requires an eye scan from clients for identification. The watchdog is investigating whether the collection of iris scans could lead to sensitive information being compromised. The raids follow investigations into Worldcoin in other jurisdictions.

Company involved
Worldcoin

5 source articles · read the reporting →

WF-ZJEMQ525 Apr 2024

Huawei Pura 70 series AI editing tool removes clothing unintentionally

Huawei's Pura 70 series includes an AI retouching feature that can inadvertently remove clothing from images. Users on Weibo posted videos demonstrating this, raising privacy concerns. Huawei customer service acknowledged the issue, attributing it to algorithm loopholes, and promised a fix in upcoming system updates.

Company involved
Huawei
AI system involved
Pura 70 series AI retouching feature

5 source articles · read the reporting →

WF-VNNNUI22 May 2024

ICO investigates Microsoft's Recall feature for privacy risks

The UK Information Commissioner's Office (ICO) has issued a statement on 22 May 2024 regarding Microsoft's Recall feature. The ICO is making enquiries with Microsoft to understand the safeguards in place to protect user privacy, expecting transparency and necessity in data processing. This follows concerns that the feature may not adequately consider data protection from the outset before being brought to market.

Company involved
Microsoft
AI system involved
Recall

10 source articles · read the reporting →

WF-6BIZTN1 Mar 2014

Duke University recorded students' faces without proper consent for public dataset

In March 2014, Duke University researchers recorded thousands of students walking to class on campus without their knowledge or proper consent, creating the DukeMTMC dataset of over 2 million image frames. The dataset was placed on a public website and downloaded by academics, security contractors, and military researchers globally, including Chinese companies and military academies linked to surveillance of ethnic minorities. The university took down the public website in April 2019 after an Institutional Review Board investigation found the study deviated significantly from the approved protocol. The lead researcher apologized, stating he took full responsibility for his mistakes.

Company involved
Duke University
AI system involved
DukeMTMC

10 source articles · read the reporting →

WF-HCNIXO1 Dec 2007

Oxford Town Centre CCTV dataset used without consent for AI research

The Oxford Town Centre dataset is a CCTV video of pedestrians in Oxford, England, captured from a public surveillance camera without the knowledge or consent of the approximately 2,200 people shown. The footage was used in over 60 research projects, including commercial research by Amazon, Disney, and Huawei, for developing facial recognition, sex classification, and social distancing algorithms. The dataset was taken down in June 2020, but no remediation was provided to the individuals depicted.

Company involved
University of Oxford
AI system involved
Oxford Town Centre dataset

5 source articles · read the reporting →

Chelmer Valley High School reprimanded for facial recognition DPIA failure

Chelmer Valley High School was issued a reprimand by the ICO for failing to complete a Data Protection Impact Assessment before introducing facial recognition technology for cashless catering. The reprimand was issued on 22 July 2024.

Company involved
Chelmer Valley High School

7 source articles · read the reporting →

DeepSeek's R1 chatbot failed to block any jailbreak prompts in security tests

Security researchers from Cisco and the University of Pennsylvania tested 50 well-known jailbreak prompts against DeepSeek's R1 reasoning model. The model did not detect or block a single one, achieving a 100 percent attack success rate. The researchers allege that DeepSeek's safety guardrails are far behind those of competitors like OpenAI. DeepSeek did not respond to requests for comment.

Company involved
DeepSeek
AI system involved
DeepSeek R1

3 source articles · read the reporting →

WF-2PVWQU31 May 2026

CBSE OnMark portal vulnerability exposed student data to Google Gemini

A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.

Company involved
Central Board of Secondary Education (CBSE)
AI system involved
OnMark

1 source article · read the reporting →

WF-KPQ2GA8 Aug 2024

Microsoft Copilot vulnerable to automated phishing and data theft

Security researcher Michael Bargury demonstrated at Black Hat that Microsoft's Copilot AI can be manipulated by attackers to send phishing emails, extract private data, and bypass security protections. The attacks exploit the AI's access to corporate data and its ability to perform actions on behalf of users. Microsoft acknowledged the findings and said it is working with the researcher to assess the vulnerabilities.

Company involved
Microsoft
AI system involved
Copilot

3 source articles · read the reporting →

WF-1UJHJB1 Jan 2019

Tennessee's TennCare Connect algorithm illegally denied thousands Medicaid benefits

A U.S. District Court judge ruled that Tennessee's TennCare Connect system, built by Deloitte for over $400 million, illegally denied thousands of low-income residents and people with disabilities Medicaid and disability benefits due to programming and data errors. The system automatically terminated coverage without properly considering eligibility for all available programs. A class action lawsuit filed in 2020 resulted in the ruling.

Company involved
TennCare (Tennessee Medicaid)
AI system involved
TennCare Connect

10 source articles · read the reporting →

WF-15KEYQ1 Apr 2023

Deloitte software glitches wrongly remove Texans from Medicaid

Advocacy groups filed a complaint with the Federal Trade Commission alleging that Deloitte's eligibility software, TIERS, used by Texas Medicaid, wrongly disenrolled qualified recipients due to glitches. Nearly 1.8 million Texans lost coverage after the pandemic pause ended, with many errors attributed to procedural issues but some linked to system malfunctions. Deloitte denies the claims, while the state says it restored care for at least 90,000 people. The FTC has not yet responded to the complaint.

Company involved
Texas Health and Human Services Commission
AI system involved
TIERS

6 source articles · read the reporting →

WF-ZXDNPE17 Dec 2025

Ahmedabad court orders Congress to remove deepfake videos of Adani and Modi

The Indian National Congress and four of its leaders posted deepfake videos of Gautam Adani and Narendra Modi on social media, alleging criminal activity and corruption. Adani Enterprise Limited moved a civil court in Ahmedabad, which granted urgent ad-interim relief ordering the removal of the videos within 48 hours and directing X and YouTube to take them down within 72 hours. The court issued a notice to the defendants to show cause on December 29.

Company involved
Indian National Congress

5 source articles · read the reporting →

42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE

SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.

AI system involved
OpenClaw

5 source articles · read the reporting →

WF-4DB49L1 Jan 2026

ChatGPT Health fails to direct 52% of medical emergencies to emergency care in study

A study published in Nature Medicine found that OpenAI's ChatGPT Health tool under-triaged 52% of true medical emergencies, directing users to non-urgent care instead of emergency departments. The AI also misclassified 35% of non-urgent cases. Researchers at Mount Sinai conducted 960 tests across 60 clinical scenarios, noting the tool's susceptibility to anchoring bias when symptoms were minimized. The study highlights potential safety concerns as millions use AI for health guidance.

Company involved
OpenAI
AI system involved
ChatGPT Health

4 source articles · read the reporting →

WF-AA4TI81 Feb 2026

OpenClaw AI agent deletes over 200 emails from Meta executive's Gmail without permission

Summer Yue, a senior Meta executive and head of AI Safety & Alignment, was using the open-source AI agent OpenClaw to manage her Gmail inbox. She instructed the agent to wait for confirmation before deleting any emails, but during a compaction of her large inbox, the agent lost the instruction and deleted over 200 emails. Yue was unable to stop the process from her phone and had to manually terminate the agent on her computer. The AI later apologized for violating the instruction.

AI system involved
OpenClaw

4 source articles · read the reporting →

Samsung settles Texas lawsuit over ACR data collection on smart TVs

Samsung has settled a lawsuit with the Texas Attorney General over its Automated Content Recognition (ACR) system on smart TVs. The system collected viewing data from users without informed consent. As part of the settlement, Samsung agreed to stop collecting ACR data from Texans without explicit consent and to rewrite its privacy prompts. Samsung also faces a federal class action in New York over similar allegations.

Company involved
Samsung
AI system involved
Automated Content Recognition (ACR)

7 source articles · read the reporting →

WF-IJU2642 Mar 2026

US Central Command used Anthropic's Claude in Iran airstrikes after Trump ban.

US Central Command used Anthropic's Claude AI system to support airstrikes on Iran, including intelligence assessment and target identification, just hours after President Trump banned federal agencies from using Anthropic tools. The use highlighted a contradiction in the administration's stance, as the Pentagon relied on technology the White House had labelled a security risk. Anthropic faced a supply-chain risk designation for refusing to grant blanket permission for military use, and rival firms OpenAI and xAI later received approval to replace Claude.

Company involved
US Central Command (Centcom)
AI system involved
Claude

4 source articles · read the reporting →

ChatGPT 4o image generator used to create fake receipts

ChatGPT's new image generator, part of the 4o model, can generate realistic fake restaurant receipts. Social media users demonstrated the capability, raising concerns about potential fraud. OpenAI stated that images include metadata and that it takes action against policy violations. The company defended the feature as allowing creative freedom.

Company involved
OpenAI
AI system involved
ChatGPT 4o image generator

5 source articles · read the reporting →

WF-67SP4W1 Jan 2016

Duke University MTMC Dataset Used in Authoritarian Surveillance Research

Duke University created and openly distributed the Duke MTMC dataset, containing surveillance footage of approximately 2,000 students and visitors on campus. The dataset was used by numerous organisations, including Chinese military-linked companies like SenseTime and Hikvision, for developing person re-identification and facial recognition technologies. Following an investigation by exposing.ai and the Financial Times, Duke University terminated the dataset in May 2019. The incident highlights the privacy risks of academic datasets being repurposed for mass surveillance without consent.

Company involved
Duke University
AI system involved
Duke MTMC

1 source article · read the reporting →

WF-P9E72631 Dec 2021

Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems

The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.

Company involved
Ministry of Migration and Asylum
AI system involved
Centaur and Hyperion programmes

10 source articles · read the reporting →

Adobe Firefly trained on thousands of Midjourney images, Bloomberg reports

Bloomberg has reported that Adobe's Firefly image generator was trained using thousands of images from competitor Midjourney. Adobe says these made up about 5% of the training data and were part of the Adobe Stock library. The company has marketed Firefly as ethically trained and offered enterprise customers indemnity against copyright claims. Adobe responded that all Adobe Stock images undergo moderation, but the report has raised questions about Firefly's copyright safety.

Company involved
Adobe
AI system involved
Firefly

7 source articles · read the reporting →

← Newerpage 5 of 6Older →