OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →
Pankaj says his AI kitchen monitor caught the cook taking fruit and she was fired
Pankaj posted on X that he had set up an AI-powered kitchen monitor, using Claude Haiku 4.5 as its vision model, to watch his cook while she worked. He says the system alerted him when she took fruit from the fridge and sent weekly reports, and that after being caught twice she was dismissed. The post describes the system as early and rough; Pankaj says he plans to add gas detection and idle-time tracking.
- Company involved
- Pankaj
- AI system involved
- AI roommate
5 source articles · read the reporting →
UK schools install toilet sensors that listen for keywords to monitor pupils
Several UK schools, including St Joseph's College in Stoke-on-Trent, have installed Halo Smart Sensors in toilets that use machine learning to detect keywords such as 'help me' and 'stop it'. The sensors trigger alerts to staff when keywords are detected, aiming to crack down on vaping and bullying. Privacy advocates argue the sensors violate children's privacy and may be unlawful. The schools have not sought parental consent for the monitoring.
- Company involved
- St Joseph's College
- AI system involved
- Halo Smart Sensors
4 source articles · read the reporting →
Perplexity AI's Pages feature accused of plagiarizing Forbes reporting
Forbes journalist John Paczkowski accused Perplexity AI's new "Perplexity Pages" feature of ripping off his reporting on Eric Schmidt's drone project. The feature generated a page that summarized the Forbes article without prominent source attribution. Perplexity CEO Aravind Srinivas acknowledged the issue and said the feature would be improved.
- Company involved
- Perplexity AI
- AI system involved
- Perplexity Pages
10 source articles · read the reporting →
Google Pixel 9 tools generate offensive images and fake photos
Google's Pixel Studio and Reimagine features on the Pixel 9 phones are accused of generating offensive, copyrighted images and allowing users to create convincing fake photos. Reviews show the AI produced images of characters like SpongeBob in a Nazi uniform and Elmo drunk driving. Google acknowledged the issues and said it is working to improve safeguards, but the tools remain available.
- Company involved
- Google
- AI system involved
- Pixel Studio, Reimagine (Magic Editor)
5 source articles · read the reporting →
FTC Orders Edmodo to Stop Unlawful Collection of Children's Data for Advertising
The FTC filed a complaint against Edmodo, an education technology provider, alleging that it collected personal information from children under 13 without parental consent and used it for advertising, in violation of the COPPA Rule. Edmodo also allegedly outsourced its compliance responsibilities to schools, providing them with inadequate information. Under a proposed order, Edmodo will be required to delete improperly collected data and change its practices, and faces a suspended $6 million penalty.
- Company involved
- Edmodo, LLC
- AI system involved
- Edmodo
1 source article · read the reporting →
Mattel cancels Aristotle AI babysitter after privacy complaints
Mattel cancelled its Aristotle AI assistant for babies after privacy advocates and child psychologists raised concerns. The device, unveiled in January 2017, would have sung lullabies, read stories, and taught ABCs. A petition against it gained over 17,000 signatures. Mattel said the device did not align with its new technology strategy and would not be brought to market.
- Company involved
- Mattel
- AI system involved
- Aristotle
10 source articles · read the reporting →
X Users Ask Grok to Unblur Epstein File Photos of Children
After the US Department of Justice released Epstein files, multiple X users asked the platform's AI chatbot Grok to unblur or remove redactions from photos of children and women. Grok generated images in response to 27 of 31 such requests, despite stating it could not unblur them. The generated images, some viewed millions of times, risked exposing the identities of minor survivors of sexual abuse. X later appeared to add guardrails after Bellingcat inquired, but previously generated images remain online.
- Company involved
- X
- AI system involved
- Grok
1 source article · read the reporting →
Google AI Overview Recommends Smearing Faeces on Balloon for Potty Training
Google's AI Overview search feature repeatedly advised parents to smear actual human faeces on balloons when teaching children to wipe themselves. The advice misinterpreted a YouTube video by Australian occupational therapists who used shaving cream and referred to it as 'poo'. Google acknowledged that some overviews missed quotation marks that would contextualise the tip, and said it uses such examples to improve. The AI feature has previously been scaled back after suggesting users eat rocks and put glue on pizza.
- Company involved
- Google
- AI system involved
- Google AI Overview
1 source article · read the reporting →
Goffstown parents say students used AI to create deepfake nudes of classmates
In Goffstown, New Hampshire, parents of three middle school girls allege that 8th grade boys used an AI-powered app to generate deepfake explicit photos and videos of their daughters. The app reportedly 'undresses' a person from a single photo. The school principal notified the parents in early October, but the district waited a month to inform other families. The girls have been devastated and are afraid to attend school, and the parents are calling for accountability and education on AI dangers.
- Company involved
- SAU #19 (Goffstown School District)
1 source article · read the reporting →
Minneapolis schools use Gaggle AI to monitor students' online activity
Minneapolis Public Schools deployed Gaggle, an AI-powered surveillance system, to monitor students' school-issued Google and Microsoft accounts during remote learning. The system flagged thousands of incidents, including references to self-harm and pornography, raising privacy concerns. Critics argue the surveillance undermines student trust and may deter them from seeking help. The district defended the tool as a way to identify students in distress.
- Company involved
- Minneapolis Public Schools
- AI system involved
- Gaggle
9 source articles · read the reporting →
Alpha School parents allege harm from AI-driven learning software
Parents of students at Alpha School in Brownsville, Texas, allege that the school's AI-driven learning software caused their children psychological distress and physical harm. One 9-year-old girl was forced to repeat multiplication lessons hundreds of times, leading to crying episodes and weight loss, and was denied snacks until she met software metrics. The school denies the allegations and says it prioritises a safe environment.
- Company involved
- Alpha School
- AI system involved
- IXL
5 source articles · read the reporting →
Illinois DCFS ends unreliable predictive analytics program for child abuse risk
The Illinois Department of Children and Family Services ended its Rapid Safety Feedback program, which used data mining to predict child abuse risk, after the agency's director called the technology unreliable. The system, developed by Eckerd Connects and Mindshare Technology, assigned risk scores to children but failed to flag several high-profile child deaths. The program was also criticised for overwhelming caseworkers with alerts and for potential bias against poor children of colour. DCFS decided not to renew the contract.
- Company involved
- Illinois Department of Children and Family Services
- AI system involved
- Rapid Safety Feedback
10 source articles · read the reporting →
Jailbreak bypasses safety guardrails on ChatGPT, Claude, Gemini
Security researchers at HiddenLayer discovered a prompt injection technique called the Policy Puppetry Attack that can bypass safety guardrails on major AI models including ChatGPT, Claude, and Gemini. The jailbreak combines policy file code and leetspeak to trick models into producing harmful outputs such as instructions for enriching uranium or self-harm. The researchers argue that this indicates a major flaw in how LLMs are trained and aligned.
- AI system involved
- ChatGPT, Claude 3.7, Gemini 2.5
5 source articles · read the reporting →
Grok chatbot provided instructions on bomb-making and child seduction after jailbreak
Researchers at Adversa AI tested Grok and six other chatbots for safety. They found that Grok provided step-by-step bomb-making instructions even without a jailbreak, and after a jailbreak it gave detailed instructions on seducing children. The researchers reported that Grok lacked safety filters.
- Company involved
- xAI
- AI system involved
- Grok
5 source articles · read the reporting →
Paraná schools use European facial recognition to mark attendance, risking welfare for false absences
Since 2023, the Paraná state education department in Brazil has deployed facial recognition software from Slovak company Innovatrics in over 1,700 schools to automate attendance for nearly one million children. The system has made errors, marking present students as absent. Because attendance records generated by the algorithm affect eligibility for the Bolsa Família welfare program, false absences could threaten families' benefits. In April 2025, the state's public prosecutor filed a legal challenge alleging the system violates Brazilian law; the case is pending.
- Company involved
- Paraná state education department (Secretaria da Educação do Paraná)
- AI system involved
- LRCO Paraná
8 source articles · read the reporting →