BC Tribunal Confirms Companies Remain Liable for AI Chatbot-Created Information - Lexology
The AI chatbot provided inaccurate information to a user.
1 source article · read the reporting →
Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.
Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.
164 incidents closest to “CCC IX Cloud” · matched on meaning · public reporting
The AI chatbot provided inaccurate information to a user.
1 source article · read the reporting →
Hong Kong's privacy commissioner's office raided six premises linked to Worldcoin, a cryptocurrency company that requires an eye scan from clients for identification. The watchdog is investigating whether the collection of iris scans could lead to sensitive information being compromised. The raids follow investigations into Worldcoin in other jurisdictions.
5 source articles · read the reporting →
Two law firms submitted a supplemental brief containing fake legal citations generated by AI systems including Google Gemini and Westlaw's CoCounsel. Judge Michael Wilner imposed $31,000 in sanctions after discovering the citations were fabricated. The lawyers admitted using AI without proper review or disclosure.
5 source articles · read the reporting →
The Guangzhou Internet Court ruled on 8 February 2024 that an unnamed AI company infringed the copyright and adaptation rights of the plaintiff, the exclusive licensee of the Ultraman series images in China. The defendant operated a website offering AI conversation and AI-generated painting services, accessible only to paying members. The plaintiff alleged that the defendant used its Ultraman images without authorisation to train its model and generate substantially similar images. The court ordered the defendant to pay 10,000 yuan ($1,389) in compensation.
9 source articles · read the reporting →
Microsoft's Threat Analysis Center reported that the Chinese state-linked group Storm-1376 posted suspected AI-generated fake audio of former Taiwanese presidential candidate Terry Gou endorsing another candidate on election day in January 2024. Gou had made no such statement, and YouTube removed the content before it reached a wide audience. The group has also used AI-generated memes and news anchors as part of influence operations in Taiwan and the United States.
7 source articles · read the reporting →
A Chinese dubbing artist, Yin, discovered that his voice was being used without permission in a text-to-speech AI product. The product was developed by a software company using recordings provided by a cultural media company, and was made available on a platform operated by a smart technology company. The Beijing Internet Court ruled that the AI-generated voice was highly similar to the plaintiff's voice and infringed his personality rights. The court ordered the defendants to stop infringement and pay damages of 250,000 RMB.
5 source articles · read the reporting →
A customer was refused a mobile phone contract because of an automated credit assessment by Dun & Bradstreet Austria. The customer took the case to court, which found that Dun & Bradstreet had infringed the GDPR by failing to provide meaningful information about the logic involved. The CJEU ruled that data controllers must explain automated decisions and that trade secrets cannot automatically override the right of access.
7 source articles · read the reporting →
The UK Information Commissioner's Office (ICO) has issued a statement on 22 May 2024 regarding Microsoft's Recall feature. The ICO is making enquiries with Microsoft to understand the safeguards in place to protect user privacy, expecting transparency and necessity in data processing. This follows concerns that the feature may not adequately consider data protection from the outset before being brought to market.
10 source articles · read the reporting →
The Center for Investigative Reporting, publisher of Mother Jones and Reveal, has filed a lawsuit against OpenAI and Microsoft in federal court, alleging the companies used its copyrighted articles without permission or compensation to train their AI products. The nonprofit argues that the AI-generated summaries of its stories threaten journalism and violate the Copyright Act and the Digital Millennium Copyright Act. The case is pending in the U.S. District Court for the Southern District of New York.
6 source articles · read the reporting →
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
3 source articles · read the reporting →
Chelmer Valley High School was issued a reprimand by the ICO for failing to complete a Data Protection Impact Assessment before introducing facial recognition technology for cashless catering. The reprimand was issued on 22 July 2024.
7 source articles · read the reporting →
A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.
1 source article · read the reporting →
The Oversight Board's policy advisory opinion on Meta's cross-check program found that the system grants certain users, such as business partners and celebrities, additional human review before removing violating content, while ordinary users face immediate removal. This unequal treatment allows potentially harmful content to remain on the platform for days, and Meta has failed to track whether the program improves accuracy. The Board made 32 recommendations to address these flaws.
10 source articles · read the reporting →
Eticas conducted an adversarial audit of RisCanvi, an AI risk assessment tool used in Catalonia's criminal justice system. The audit uncovered biases in risk classifications against specific demographics and significant reliability issues. The findings call for fairer practices in criminal justice AI.
4 source articles · read the reporting →
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
5 source articles · read the reporting →
US Central Command used Anthropic's Claude AI system to support airstrikes on Iran, including intelligence assessment and target identification, just hours after President Trump banned federal agencies from using Anthropic tools. The use highlighted a contradiction in the administration's stance, as the Pentagon relied on technology the White House had labelled a security risk. Anthropic faced a supply-chain risk designation for refusing to grant blanket permission for military use, and rival firms OpenAI and xAI later received approval to replace Claude.
4 source articles · read the reporting →
The Italian data protection authority (Garante) fined the Municipality of Trento €50,000 for two research projects, Marvel and Protector, that used AI to analyze video, audio, and social media data for public security purposes. The projects involved automated detection of risk events from surveillance cameras and microphones in public spaces, as well as monitoring social media for hate speech. The Garante found multiple violations of privacy law, including lack of a valid legal basis, insufficient anonymization, failure to conduct a data protection impact assessment, and inadequate transparency. The municipality is required to delete the unlawfully processed data.
9 source articles · read the reporting →
The Cyberspace Administration of China fined Didi Global Inc. for violating data protection laws. The investigation found that Didi had over-collected personal data from passengers and drivers, including facial recognition, location, and clipboard information, totaling billions of records. The violations began in 2015 and continued until the investigation in 2021. Didi was ordered to pay a penalty and correct its practices.
8 source articles · read the reporting →
Recorded and transmitted private footage of users and bystanders to overseas AI workers
1 source article · read the reporting →
The Xuhui District branch of the Shanghai Municipal Bureau of Public Security is expanding its Intelligent Image Recognition System, adding 2,500 facial recognition cameras and increased computing capacity to build profiles of residents and flag deviations. The project, contracted to US-sanctioned FiberHome, is designed to match each face to files on more than 50 million people. Officials say the system will analyse behaviour patterns and trigger early warnings.
3 source articles · read the reporting →
The Ninth Circuit sanctioned immigration attorneys from Sethi Law Group after they filed briefs containing AI-generated false cases and quotations. The court imposed monetary sanctions, a six-month suspension from Ninth Circuit practice, and referred the matter to the California State Bar. The court also required future filings to disclose AI use and certify that all citations were verified. The case is Lnu v. Blanche.
2 source articles · read the reporting →
In Withers v. City of Aberdeen, a contract dispute, both sides' attorneys submitted briefs containing fabricated case citations generated by AI tools. The court identified six non-existent citations and sanctioned all four attorneys, revoking pro hac vice admissions, imposing fines, and referring them to state bars. The drafting attorneys had used AI research and drafting tools without verifying outputs, while local counsel signed filings without review. The ruling emphasises that attorneys cannot delegate verification duties to AI and that ignorance of AI risks is no defence.
2 source articles · read the reporting →
The Intercept reported that U.S. Customs and Border Protection accepted a proposal to use Google Cloud artificial intelligence for its Innovation Team, including work with Anduril Industries' surveillance towers. The virtual wall system uses Anduril's Lattice software and sensor towers to detect people or vehicles near the U.S.-Mexico border and relay their locations to agents. Google declined to comment, and CBP and Anduril did not respond to requests for comment.
1 source article · read the reporting →
Clearview AI has agreed to stop selling its facial recognition database to most private US companies as part of a proposed settlement with the ACLU. The company scraped billions of images from social media without consent to build its database, violating Illinois' Biometric Information Privacy Act. The settlement requires Clearview to delete old facial vectors and allow Illinois residents to opt out. The company can still sell its technology to law enforcement and government agencies.
8 source articles · read the reporting →