The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

140 incidents closest to “Pagaya Technologies” · matched on meaning · public reporting

N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent

Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.

Company involved
N-Tech.lab
AI system involved
FindFace

8 source articles · read the reporting →

WF-51NEWF17 Feb 2024

UIUC researchers weaponize GPT-4 to autonomously hack websites

Researchers at the University of Illinois Urbana-Champaign demonstrated that LLM-powered agents, particularly OpenAI's GPT-4, can autonomously hack vulnerable websites. In sandboxed tests, GPT-4 achieved a 73.3% success rate across five attempts on 15 vulnerabilities, while open-source models failed. The researchers used the OpenAI Assistants API, LangChain, and Playwright to enable the agents to interact with websites. The study highlights the potential for AI agents to be used in cyberattacks, with cost estimates suggesting they could be cheaper than human penetration testers.

Company involved
University of Illinois Urbana-Champaign
AI system involved
GPT-4

4 source articles · read the reporting →

WF-CP9OZK22 Jan 2024

OpenAI suspends developer of bot mimicking Dean Phillips

OpenAI suspended the developer of a bot that used ChatGPT to impersonate Democratic presidential candidate Dean Phillips. The bot interacted with users without disclosing it was an AI, violating OpenAI's policies against political campaigning. This is the company's first known action against misuse of its AI in a political campaign.

5 source articles · read the reporting →

WF-MXE6CO1 Jan 2024

Storm-1376 used AI-generated fake audio during Taiwan election, Microsoft reports

Microsoft's Threat Analysis Center reported that the Chinese state-linked group Storm-1376 posted suspected AI-generated fake audio of former Taiwanese presidential candidate Terry Gou endorsing another candidate on election day in January 2024. Gou had made no such statement, and YouTube removed the content before it reached a wide audience. The group has also used AI-generated memes and news anchors as part of influence operations in Taiwan and the United States.

Company involved
Storm-1376 (also known as Spamouflage and Dragonbridge)

7 source articles · read the reporting →

WildBrain disputes Kartoon Studios' Gadget A.I. trademark use

Kartoon Studios announced its Gadget A.I. toolkit, which aggregates AI tools for animation production. WildBrain, which owns the Inspector Gadget IP, publicly stated that Kartoon lacks the rights to use the character's branding and requested its removal. Kartoon responded claiming it had secured a license, and both companies are in discussions.

Company involved
Kartoon Studios
AI system involved
Gadget A.I.

2 source articles · read the reporting →

Geologists raise censorship and bias concerns over IUGS-backed GeoGPT chatbot

Geologists, particularly in developing countries, have raised concerns that GeoGPT, an AI chatbot backed by the International Union of Geological Sciences (IUGS) and developed under the Deep-time Digital Earth programme, may censor or bias geological information. Tests with its underlying AI, Qwen, developed by Alibaba, reportedly produced evasive or inadequate answers to sensitive questions. The IUGS and DDE deny state influence, saying the information is purely geoscientific, and have said the database will be made public once governance is ensured.

Company involved
International Union of Geological Sciences (IUGS) and Deep-time Digital Earth (DDE) program
AI system involved
GeoGPT (underlying AI: Qwen)

6 source articles · read the reporting →

WF-03V5V41 Jan 2021

PimEyes faces fine proceedings over biometric facial recognition in Baden-Württemberg

PimEyes, a facial recognition search engine, is accused of scraping images from the internet and processing biometric data without a valid legal basis under the GDPR. The data protection authority of Baden-Württemberg (LfDI) opened fine proceedings after it found PimEyes's response to its questions inadequate. PimEyes argues that the images it processes are publicly available and not personal data. The LfDI says the processing endangers citizens' rights and freedoms and is not covered by the GDPR exceptions.

Company involved
PimEyes
AI system involved
PimEyes

9 source articles · read the reporting →

Delta uses AI from Fetcherr for domestic ticket pricing

Delta Air Lines is using generative AI from Fetcherr to determine some domestic flight prices, currently covering 3% of its network with plans to reach 20% by end of 2025. Democratic senators expressed concern that the AI could be used for individualized pricing based on personal data, leading to higher fares. Delta denies using personal data in pricing and states it complies with regulations. No actual harm has been reported.

Company involved
Delta Air Lines
AI system involved
Fetcherr

8 source articles · read the reporting →

WF-AZK2NL11 Jul 2023

Check Point Research finds Google Bard can generate phishing emails and malware

Check Point Research analysed Google's generative AI platform Bard and found it could be used to create phishing emails, malware keyloggers, and basic ransomware code with minimal manipulation. Bard's anti-abuse restrictors were significantly lower than ChatGPT's, making it easier to generate malicious content. The researchers demonstrated these capabilities in controlled tests but did not report actual harm to specific individuals or organisations.

Company involved
Google
AI system involved
Bard

4 source articles · read the reporting →

WF-A2SW1816 Aug 2024

OpenAI disrupts Iranian influence operation using ChatGPT to generate political content

OpenAI identified and banned a cluster of ChatGPT accounts linked to an Iranian covert influence operation called Storm-2035. The operation generated long-form articles and social media comments on topics including the U.S. presidential election, the Gaza conflict, and Venezuelan politics, posing as both progressive and conservative outlets. Most content received low or no engagement, and OpenAI stated it shared threat intelligence with government and industry stakeholders. The company took down the accounts and continues to monitor for further violations.

Company involved
OpenAI
AI system involved
ChatGPT

6 source articles · read the reporting →

WF-DHKEO71 Sep 2021

India-aligned network used AI fake accounts to target Pakistan, NewsGuard finds

NewsGuard reports that a network of nearly 1,500 fake Facebook and X accounts used AI-generated content to promote pro-India and pro-Army narratives and criticise Pakistan. The network, which NewsGuard says may be linked to the Indian Army, has operated undetected since September 2021. Meta said it had enforced against a cluster of accounts; X did not comment. The full scale and reach of the operation remain unclear.

2 source articles · read the reporting →

WF-Q8FS1926 Oct 2025

Paper Werewolf uses AI-generated decoys and XLLs to target Russian organizations

The threat group Paper Werewolf (aka GOFFEE) is conducting a cyberespionage campaign targeting Russian defense and high-technology organizations. The campaign uses AI-generated decoy documents, such as invitations and official letters, to trick recipients into opening malicious Excel XLL add-ins that deliver a backdoor called EchoGather. The backdoor collects system information and communicates with a command-and-control server. The campaign is ongoing and was first detected in late October 2025.

Company involved
Paper Werewolf
AI system involved
EchoGather

2 source articles · read the reporting →

PimEyes facial recognition search engine identifies individuals from public photos

PimEyes, a Polish facial recognition search engine, allows users to upload a photo and find matching images from across the internet. The system scrapes billions of photos and creates biometric profiles without consent. A banker named Dylan (pseudonym) discovered that an old party photo of him was found by the system, potentially outing his private life. Privacy advocates and platforms like Instagram and YouTube are taking action against PimEyes, alleging violations of the GDPR.

Company involved
PimEyes
AI system involved
PimEyes

6 source articles · read the reporting →

ChatGPT 4o image generator used to create fake receipts

ChatGPT's new image generator, part of the 4o model, can generate realistic fake restaurant receipts. Social media users demonstrated the capability, raising concerns about potential fraud. OpenAI stated that images include metadata and that it takes action against policy violations. The company defended the feature as allowing creative freedom.

Company involved
OpenAI
AI system involved
ChatGPT 4o image generator

5 source articles · read the reporting →

WF-H3NHGW1 Jan 2020

GoLaxy Used AI to Manipulate Public Opinion in Hong Kong and Taiwan

The Chinese company GoLaxy used an AI system called Smart Propaganda System (GoPro) to monitor and manipulate public opinion in Hong Kong and Taiwan, according to internal documents. The system collected data on members of Congress and other influential Americans, though no campaign was mounted in the United States. GoLaxy denied the allegations, calling them misinformation. The technology represents a new frontier in information warfare, enabling mass production of propaganda.

Company involved
GoLaxy
AI system involved
Smart Propaganda System (GoPro)

2 source articles · read the reporting →

School AI surveillance like Gaggle can lead to false alarms, arrests

AI surveillance tools used in schools, such as Gaggle, GoGuardian and Bark, are reported to generate false alarms that have led to student arrests. The article examines cases where automated monitoring flagged innocent behaviour as threats, causing harm to students and families.

2 source articles · read the reporting →

WF-R41UQV23 Feb 2012

Palantir secretly tested predictive policing in New Orleans

Beginning in 2012, Palantir Technologies secretly partnered with the New Orleans Police Department to deploy a predictive policing system. The programme analysed gang affiliations, social media and criminal histories to forecast individuals’ likelihood of committing or becoming victims of violence, operating without public knowledge or city council oversight. Researchers and law enforcement officials raised concerns about systemic bias and civil liberties. As of 2018, the city and Palantir had not disclosed the programme’s status.

Company involved
New Orleans Police Department

1 source article · read the reporting →

WF-30XEUN1 Jul 2019

Google contractors targeted homeless people for Pixel 4 facial recognition data

Google hired Randstad to collect facial data to train the Pixel 4's face recognition system. Contractors allegedly targeted homeless people and unaware students, using deceptive tactics such as calling it a "selfie game" and offering $5 without informing subjects they were being recorded. Google suspended the research program and opened an investigation following the report.

Company involved
Google
AI system involved
Pixel 4 facial recognition

1 source article · read the reporting →

Adobe Firefly trained on thousands of Midjourney images, Bloomberg reports

Bloomberg has reported that Adobe's Firefly image generator was trained using thousands of images from competitor Midjourney. Adobe says these made up about 5% of the training data and were part of the Adobe Stock library. The company has marketed Firefly as ethically trained and offered enterprise customers indemnity against copyright claims. Adobe responded that all Adobe Stock images undergo moderation, but the report has raised questions about Firefly's copyright safety.

Company involved
Adobe
AI system involved
Firefly

7 source articles · read the reporting →

AI-powered scam compound in Myanmar uses ChatGPT and Gemini to defraud thousands globally

Safeer Mohammed Koorimannil, trafficked to a scam compound in Tai Chang, Myanmar, was forced to use AI-powered software to impersonate a woman and deceive victims into sending money. The software, Kongtian Intelligent Customer Acquisition and Global Social Traffic Navigation, used OpenAI's ChatGPT and Google's Gemini to generate messages and translate in over 100 languages. Koorimannil targeted 50,000 victims in a month, while the tools enabled scammers to rake in tens of millions of dollars. U.S. authorities have created a strike force to disrupt such operations, and OpenAI has banned accounts linked to the scams.

Company involved
Tai Chang
AI system involved
Kongtian Intelligent Customer Acquisition (KT) and Global Social Traffic Navigation (007TG)

2 source articles · read the reporting →

WF-1MQMSR21 Apr 2020

Dahua Exposed for Uyghur Tracking Software in Surveillance Systems

Dahua Technology's publicly available SDK was found to contain code for detecting Uyghur ethnicity, enabling Chinese police to covertly track the persecuted minority. The revelation led to widespread criticism, and Dahua removed the SDK after being contacted by IPVM but did not comment. The company had previously been sanctioned by the US for complicity in human rights abuses against Uyghurs, and its software is part of a massive surveillance apparatus in Xinjiang.

Company involved
Dahua Technology
AI system involved
Dahua SDK

1 source article · read the reporting →

WF-KH4UOW1 Aug 2020

Google Cloud Used in CBP AI Virtual Border Wall Contract

The Intercept reported that U.S. Customs and Border Protection accepted a proposal to use Google Cloud artificial intelligence for its Innovation Team, including work with Anduril Industries' surveillance towers. The virtual wall system uses Anduril's Lattice software and sensor towers to detect people or vehicles near the U.S.-Mexico border and relay their locations to agents. Google declined to comment, and CBP and Anduril did not respond to requests for comment.

Company involved
U.S. Customs and Border Protection (CBP)
AI system involved
Google Cloud AI Platform with Anduril Lattice and Sentry Towers

1 source article · read the reporting →

WF-8RFVVY1 Oct 2025

Google sued for secretly tracking user data with Gemini AI

Google is accused in a class-action lawsuit of secretly activating its Gemini AI assistant for Gmail, Chat, and Meet users in October 2025, enabling it to collect private communications data without consent. The suit alleges violation of the California Invasion of Privacy Act. Google has not responded to the allegations.

Company involved
Google
AI system involved
Gemini

4 source articles · read the reporting →

WF-GY0FZ528 Aug 2025

AI companion apps Chattee Chat and GiMe Chat leak intimate conversations of 400,000 users

Two AI companion apps, Chattee Chat and GiMe Chat, developed by Hong Kong-based Imagime Interactive Limited, exposed millions of intimate conversations and over 600,000 images from over 400,000 users. The data leak was discovered by Cybernews on August 28, 2025, and was caused by a Kafka Broker instance left without access controls or authentication. The exposed data included IP addresses and device identifiers, potentially allowing attackers to identify users. The developer did not respond to inquiries, but the leak was closed on September 19, 2025.

Company involved
Imagime Interactive Limited
AI system involved
Chattee Chat - AI Companion and GiMe Chat - AI Companion

4 source articles · read the reporting →

← Newerpage 5 of 6Older →