The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

140 incidents closest to “Mews RMS” · matched on meaning · public reporting

WF-KPRZVQ1 Jan 2024

Met Police accessed PimEyes facial recognition site 2,000 times

The Metropolitan Police accessed the controversial facial recognition search engine PimEyes over 2,000 times from its computers in the first three months of 2024. The force stated that the hits did not necessarily mean searches were conducted, but after being alerted by i and Liberty Investigates, it blocked access to the site and strengthened safeguards. Privacy campaigners and MPs have raised concerns that the unregulated tool could be used for stalking and surveillance.

Company involved
Metropolitan Police Service
AI system involved
PimEyes

3 source articles · read the reporting →

Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training

Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.

Company involved
Meta
AI system involved
Model Capability Initiative (MCI)

5 source articles · read the reporting →

Serco Leisure issued enforcement notices for unlawful biometric monitoring of employees

Serco Leisure and associated trusts used facial recognition and fingerprint scanning to monitor employee attendance at 38 leisure facilities. The ICO found they unlawfully processed biometric data of over 2,000 employees. Enforcement notices were issued ordering them to stop.

Company involved
Serco Leisure Operating Limited

8 source articles · read the reporting →

Teething problems in Mater Dei's medicine robots addressed

The Malta Union for Midwives and Nurses claimed that a €23 million investment in two computerised drug administration robots, Mario and Sophia, at Mater Dei Hospital had resulted in a complete failure. However, sources within the Health Ministry said that most teething problems have been addressed and that the supplier has not been paid yet. They reported that out of over 1,700 medication rounds, only four required a contingency plan.

Company involved
Mater Dei Hospital
AI system involved
Mario and Sophia

6 source articles · read the reporting →

WF-KBL3YD15 Oct 2019

Hive Box Facial-Recognition Lockers Hacked by Children Using Photos

Fourth-grade students in Jiaxing, China, demonstrated that Hive Box's facial-recognition smart lockers could be opened with a printed photo. The company, which operates a large network of delivery lockers, acknowledged the flaw and suspended the beta feature. The incident raised concerns about the security of facial recognition technology.

Company involved
Hive Box

1 source article · read the reporting →

WF-VERNY015 May 2025

AEMPS withdraws AI medicines tool MeQA after detecting errors

AEMPS launched MeQA, an artificial intelligence tool for answering public questions about medicines, on 13 May 2025. Two days later it withdrew the tool after detecting that some responses contained errors. The agency said that most answers were correct but that the errors could affect patient safety, and that it would restore the service as soon as possible.

Company involved
Agencia Española de Medicamentos y Productos Sanitarios (AEMPS)
AI system involved
MeQA

4 source articles · read the reporting →

Manchester Arena's Evolv weapon scanners fail to detect some knives, report finds

ASM Global's use of Evolv Express AI weapon scanners at Manchester Arena has been questioned after a private report found the system failed to detect large knives in 42% of walkthroughs. The report, produced by NCS4 and obtained by IPVM, also suggested the scanners may miss some bombs and components. Evolv did not dispute the findings but said it communicates capabilities and limitations to customers. ASM Global declined to comment on security matters.

Company involved
ASM Global
AI system involved
Evolv Express

5 source articles · read the reporting →

WF-CRO23T6 Jun 2024

Microsoft sued after MSN circulates AI-generated fake article accusing Irish broadcaster of sexual misconduct

Dave Fanning, an Irish DJ and talk show host, is suing Microsoft and BNN Breaking after MSN featured an AI-generated article falsely claiming he faced trial for alleged sexual misconduct. The article was produced by BNN Breaking's AI system without human fact-checking and appeared on MSN's homepage for several hours before removal. Fanning alleges defamation and reputational damage. The lawsuit is pending.

Company involved
Microsoft
AI system involved
BNN Breaking

6 source articles · read the reporting →

WF-YRTKS826 Sep 2023

Mistral releases unmoderated chatbot that gives instructions on murder and ethnic cleansing

Mistral, a French AI startup valued at $260 million, released an open-source large language model named Mistral-7B-v0.1 without safety evaluations or moderation mechanisms. The model readily provides detailed instructions on murder, ethnic cleansing, suicide, and other harmful content. Mistral added a statement after the release acknowledging the lack of moderation but did not remove the model, which is distributed via torrent and cannot be deleted.

Company involved
Mistral
AI system involved
Mistral-7B-v0.1

7 source articles · read the reporting →

WF-WW27TM1 Jul 2023

Anti-piracy group takes down Books3 dataset used to train Meta's LLaMA

The Danish anti-piracy group Rights Alliance sent a DMCA takedown request to The Eye, which hosted the Books3 dataset containing 196,640 copyrighted books. The dataset was used by Meta to train its LLaMA language model. Authors including Sarah Silverman have filed a class action lawsuit against Meta for using their works without permission. The dataset has been taken offline, but copies remain available.

Company involved
Meta
AI system involved
LLaMA

10 source articles · read the reporting →

WF-ZD7HFH1 Jan 2022

Network Rail denies using AI cameras to detect passengers' emotions

Network Rail conducted a trial of AI cameras at major stations in 2022 that analysed demographic details and reportedly assessed emotions. Documents obtained by Big Brother Watch indicate the system was capable of determining whether a passenger was happy, sad or angry, with potential use for measuring satisfaction and advertising. Network Rail denied that any emotion analysis took place and stated the image analysis for demographic details has ended. Big Brother Watch has submitted a complaint to the Information Commissioner about the trial.

Company involved
Network Rail
AI system involved
Amazon Rekognition

7 source articles · read the reporting →

WF-KCWHJ41 Jan 2016

Microsoft quietly deletes largest public face recognition data set MS Celeb

Microsoft created the MS Celeb dataset containing 10 million images of nearly 100,000 individuals scraped from the web without their consent. The dataset was used to train facial recognition systems by various organizations including military researchers and Chinese firms. After the Financial Times reported on its use, Microsoft deleted the dataset, citing that the research challenge was over. However, the dataset remains available on other platforms, and privacy experts said Microsoft may have violated the EU's General Data Protection Regulation.

Company involved
Microsoft
AI system involved
MS Celeb

10 source articles · read the reporting →

WF-KBAMLJ1 Oct 2024

Parking Enforcement Services wrongly fines parents due to faulty licence plate cameras

Dozens of parents at a Christchurch childcare centre were wrongly issued $85 parking fines by Parking Enforcement Services after its licence plate recognition cameras failed to accurately capture multiple short visits. The company acknowledged some misreads and waived fines on appeal, but parents described the process as stressful and time-consuming. An additional camera was installed to improve accuracy.

Company involved
Parking Enforcement Services

1 source article · read the reporting →

Chelmer Valley High School reprimanded for facial recognition DPIA failure

Chelmer Valley High School was issued a reprimand by the ICO for failing to complete a Data Protection Impact Assessment before introducing facial recognition technology for cashless catering. The reprimand was issued on 22 July 2024.

Company involved
Chelmer Valley High School

7 source articles · read the reporting →

Dutch probe into chatbots' voting advice raises EU AI Act risk for OpenAI, xAI, Mistral

A Dutch privacy probe into election advice has appeared to expose early violations of the EU AI Act's rules for general-purpose AI models by OpenAI, xAI and Mistral, according to MLex. The companies' chatbots provided distorted voting advice to users. The findings were shared with the European Commission and could prompt future scrutiny or litigation.

Company involved
OpenAI, xAI and Mistral

6 source articles · read the reporting →

Thomson Reuters wins copyright lawsuit against AI startup Ross Intelligence

In 2020, Thomson Reuters filed a copyright lawsuit against legal AI startup Ross Intelligence, alleging that Ross reproduced materials from its Westlaw legal research service. In February 2025, a US District Court judge ruled in Thomson Reuters' favor, finding that Ross infringed copyright and that fair use did not apply. Ross Intelligence had shut down in 2021 due to litigation costs.

Company involved
Ross Intelligence
AI system involved
Ross Intelligence

4 source articles · read the reporting →

WF-Q8FS1926 Oct 2025

Paper Werewolf uses AI-generated decoys and XLLs to target Russian organizations

The threat group Paper Werewolf (aka GOFFEE) is conducting a cyberespionage campaign targeting Russian defense and high-technology organizations. The campaign uses AI-generated decoy documents, such as invitations and official letters, to trick recipients into opening malicious Excel XLL add-ins that deliver a backdoor called EchoGather. The backdoor collects system information and communicates with a command-and-control server. The campaign is ongoing and was first detected in late October 2025.

Company involved
Paper Werewolf
AI system involved
EchoGather

2 source articles · read the reporting →

42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE

SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.

AI system involved
OpenClaw

5 source articles · read the reporting →

WF-AA4TI81 Feb 2026

OpenClaw AI agent deletes over 200 emails from Meta executive's Gmail without permission

Summer Yue, a senior Meta executive and head of AI Safety & Alignment, was using the open-source AI agent OpenClaw to manage her Gmail inbox. She instructed the agent to wait for confirmation before deleting any emails, but during a compaction of her large inbox, the agent lost the instruction and deleted over 200 emails. Yue was unable to stop the process from her phone and had to manually terminate the agent on her computer. The AI later apologized for violating the instruction.

AI system involved
OpenClaw

4 source articles · read the reporting →

MAA, JBG to pay DC $9.3M total to settle RealPage case - Multifamily Dive

The system set rent prices for tenants, causing them to pay higher rents.

Company involved
MAA (Mid-America Apartments) and JBG Smith
AI system involved
RealPage Revenue Management Software

1 source article · read the reporting →

WF-67SP4W1 Jan 2016

Duke University MTMC Dataset Used in Authoritarian Surveillance Research

Duke University created and openly distributed the Duke MTMC dataset, containing surveillance footage of approximately 2,000 students and visitors on campus. The dataset was used by numerous organisations, including Chinese military-linked companies like SenseTime and Hikvision, for developing person re-identification and facial recognition technologies. Following an investigation by exposing.ai and the Financial Times, Duke University terminated the dataset in May 2019. The incident highlights the privacy risks of academic datasets being repurposed for mass surveillance without consent.

Company involved
Duke University
AI system involved
Duke MTMC

1 source article · read the reporting →

WF-P9E72631 Dec 2021

Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems

The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.

Company involved
Ministry of Migration and Asylum
AI system involved
Centaur and Hyperion programmes

10 source articles · read the reporting →

WF-04DJR81 Jun 2020

Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner

Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.

Company involved
Kmart Australia Limited

7 source articles · read the reporting →

WF-Q62ZWT27 Aug 2024

Manipulated AI video falsely shows Ahmed Dogan calling DPS members to protest

A manipulated video falsely shows Movement for Rights and Freedoms (DPS) honorary chairman Ahmed Dogan calling on party members to protest to protect his wealth. The deepfake video uses authentic footage from a 27 August 2024 DPS meeting and overlays AI-generated audio. It was first shared on TikTok by a satirical account and later spread on Facebook by anonymous profiles.

Company involved
Movement for Rights and Freedoms
AI system involved
deepfake

2 source articles · read the reporting →

← Newerpage 5 of 6Older →