The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

164 incidents closest to “CCC IX Cloud” · matched on meaning · public reporting

BC Tribunal Confirms Companies Remain Liable for AI Chatbot-Created Information - Lexology

The AI chatbot provided inaccurate information to a user.

1 source article · read the reporting →

WF-2X3B7831 Jan 2024

Hong Kong privacy watchdog raids Worldcoin offices over iris scan data collection

Hong Kong's privacy commissioner's office raided six premises linked to Worldcoin, a cryptocurrency company that requires an eye scan from clients for identification. The watchdog is investigating whether the collection of iris scans could lead to sensitive information being compromised. The raids follow investigations into Worldcoin in other jurisdictions.

Company involved
Worldcoin

5 source articles · read the reporting →

WF-MCOWG76 May 2025

California judge sanctions law firms for using AI to generate fake legal citations

Two law firms submitted a supplemental brief containing fake legal citations generated by AI systems including Google Gemini and Westlaw's CoCounsel. Judge Michael Wilner imposed $31,000 in sanctions after discovering the citations were fabricated. The lawyers admitted using AI without proper review or disclosure.

Company involved
K&L Gates
AI system involved
Google Gemini, Westlaw Precision with CoCounsel

5 source articles · read the reporting →

WF-YQZDB88 Feb 2024

Guangzhou court finds AI company infringed Ultraman copyright

The Guangzhou Internet Court ruled on 8 February 2024 that an unnamed AI company infringed the copyright and adaptation rights of the plaintiff, the exclusive licensee of the Ultraman series images in China. The defendant operated a website offering AI conversation and AI-generated painting services, accessible only to paying members. The plaintiff alleged that the defendant used its Ultraman images without authorisation to train its model and generate substantially similar images. The court ordered the defendant to pay 10,000 yuan ($1,389) in compensation.

Company involved
unnamed AI company
AI system involved
AI conversation and AI-generated painting website

9 source articles · read the reporting →

WF-MXE6CO1 Jan 2024

Storm-1376 used AI-generated fake audio during Taiwan election, Microsoft reports

Microsoft's Threat Analysis Center reported that the Chinese state-linked group Storm-1376 posted suspected AI-generated fake audio of former Taiwanese presidential candidate Terry Gou endorsing another candidate on election day in January 2024. Gou had made no such statement, and YouTube removed the content before it reached a wide audience. The group has also used AI-generated memes and news anchors as part of influence operations in Taiwan and the United States.

Company involved
Storm-1376 (also known as Spamouflage and Dragonbridge)

7 source articles · read the reporting →

Beijing Internet Court rules AI voice cloning infringes personality rights

A Chinese dubbing artist, Yin, discovered that his voice was being used without permission in a text-to-speech AI product. The product was developed by a software company using recordings provided by a cultural media company, and was made available on a platform operated by a smart technology company. The Beijing Internet Court ruled that the AI-generated voice was highly similar to the plaintiff's voice and infringed his personality rights. The court ordered the defendants to stop infringement and pay damages of 250,000 RMB.

5 source articles · read the reporting →

CJEU rules Dun & Bradstreet must explain automated credit decisions under GDPR

A customer was refused a mobile phone contract because of an automated credit assessment by Dun & Bradstreet Austria. The customer took the case to court, which found that Dun & Bradstreet had infringed the GDPR by failing to provide meaningful information about the logic involved. The CJEU ruled that data controllers must explain automated decisions and that trade secrets cannot automatically override the right of access.

Company involved
Dun & Bradstreet Austria GmbH

7 source articles · read the reporting →

WF-VNNNUI22 May 2024

ICO investigates Microsoft's Recall feature for privacy risks

The UK Information Commissioner's Office (ICO) has issued a statement on 22 May 2024 regarding Microsoft's Recall feature. The ICO is making enquiries with Microsoft to understand the safeguards in place to protect user privacy, expecting transparency and necessity in data processing. This follows concerns that the feature may not adequately consider data protection from the outset before being brought to market.

Company involved
Microsoft
AI system involved
Recall

10 source articles · read the reporting →

Center for Investigative Reporting Sues OpenAI, Microsoft Over Copyright

The Center for Investigative Reporting, publisher of Mother Jones and Reveal, has filed a lawsuit against OpenAI and Microsoft in federal court, alleging the companies used its copyrighted articles without permission or compensation to train their AI products. The nonprofit argues that the AI-generated summaries of its stories threaten journalism and violate the Copyright Act and the Digital Millennium Copyright Act. The case is pending in the U.S. District Court for the Southern District of New York.

Company involved
OpenAI and Microsoft

6 source articles · read the reporting →

WF-GEPFGZ1 Dec 2023

OpenDream AI art site allowed users to generate child sexual abuse material

OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.

Company involved
CBM Media Pte Ltd
AI system involved
OpenDream

3 source articles · read the reporting →

Chelmer Valley High School reprimanded for facial recognition DPIA failure

Chelmer Valley High School was issued a reprimand by the ICO for failing to complete a Data Protection Impact Assessment before introducing facial recognition technology for cashless catering. The reprimand was issued on 22 July 2024.

Company involved
Chelmer Valley High School

7 source articles · read the reporting →

WF-2PVWQU31 May 2026

CBSE OnMark portal vulnerability exposed student data to Google Gemini

A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.

Company involved
Central Board of Secondary Education (CBSE)
AI system involved
OnMark

1 source article · read the reporting →

Meta's cross-check program delays removal of violating content for privileged users

The Oversight Board's policy advisory opinion on Meta's cross-check program found that the system grants certain users, such as business partners and celebrities, additional human review before removing violating content, while ordinary users face immediate removal. This unequal treatment allows potentially harmful content to remain on the platform for days, and Meta has failed to track whether the program improves accuracy. The Board made 32 recommendations to address these flaws.

Company involved
Meta
AI system involved
cross-check program

10 source articles · read the reporting →

Audit of RisCanvi finds biases and reliability issues in criminal justice system

Eticas conducted an adversarial audit of RisCanvi, an AI risk assessment tool used in Catalonia's criminal justice system. The audit uncovered biases in risk classifications against specific demographics and significant reliability issues. The findings call for fairer practices in criminal justice AI.

Company involved
Catalonia's criminal justice system
AI system involved
RisCanvi

4 source articles · read the reporting →

42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE

SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.

AI system involved
OpenClaw

5 source articles · read the reporting →

WF-IJU2642 Mar 2026

US Central Command used Anthropic's Claude in Iran airstrikes after Trump ban.

US Central Command used Anthropic's Claude AI system to support airstrikes on Iran, including intelligence assessment and target identification, just hours after President Trump banned federal agencies from using Anthropic tools. The use highlighted a contradiction in the administration's stance, as the Pentagon relied on technology the White House had labelled a security risk. Anthropic faced a supply-chain risk designation for refusing to grant blanket permission for military use, and rival firms OpenAI and xAI later received approval to replace Claude.

Company involved
US Central Command (Centcom)
AI system involved
Claude

4 source articles · read the reporting →

Italian DPA fines Municipality of Trento over AI surveillance projects

The Italian data protection authority (Garante) fined the Municipality of Trento €50,000 for two research projects, Marvel and Protector, that used AI to analyze video, audio, and social media data for public security purposes. The projects involved automated detection of risk events from surveillance cameras and microphones in public spaces, as well as monitoring social media for hate speech. The Garante found multiple violations of privacy law, including lack of a valid legal basis, insufficient anonymization, failure to conduct a data protection impact assessment, and inadequate transparency. The municipality is required to delete the unlawfully processed data.

Company involved
Comune di Trento
AI system involved
Marvel and Protector

9 source articles · read the reporting →

WF-YUFSC71 Jul 2021

Didi fined for over-collecting personal data of users

The Cyberspace Administration of China fined Didi Global Inc. for violating data protection laws. The investigation found that Didi had over-collected personal data from passengers and drivers, including facial recognition, location, and clipboard information, totaling billions of records. The violations began in 2015 and continued until the investigation in 2021. Didi was ordered to pay a penalty and correct its practices.

Company involved
滴滴全球股份有限公司 (Didi Global Inc.)
AI system involved
Didi ride-hailing apps

8 source articles · read the reporting →

Meta Smart Glasses Lawsuit Claims Sex, Bathroom Footage Was Sent to Overseas AI Workers - Law Commentary

Recorded and transmitted private footage of users and bystanders to overseas AI workers

Company involved
Meta
AI system involved
Meta Smart Glasses

1 source article · read the reporting →

WF-HF1YRW1 Sep 2023

Xuhui police expand facial recognition surveillance to profile 1.1 million residents

The Xuhui District branch of the Shanghai Municipal Bureau of Public Security is expanding its Intelligent Image Recognition System, adding 2,500 facial recognition cameras and increased computing capacity to build profiles of residents and flag deviations. The project, contracted to US-sanctioned FiberHome, is designed to match each face to files on more than 50 million people. Officials say the system will analyse behaviour patterns and trigger early warnings.

Company involved
Shanghai Municipal Bureau of Public Security, Xuhui District Branch
AI system involved
Intelligent Image Recognition System

3 source articles · read the reporting →

Ninth Circuit Sanctions Attorneys Over AI-Hallucinated Legal Briefs

The Ninth Circuit sanctioned immigration attorneys from Sethi Law Group after they filed briefs containing AI-generated false cases and quotations. The court imposed monetary sanctions, a six-month suspension from Ninth Circuit practice, and referred the matter to the California State Bar. The court also required future filings to disclose AI use and certify that all citations were verified. The case is Lnu v. Blanche.

Company involved
Sethi Law Group

2 source articles · read the reporting →

WF-MMTM3T1 Nov 2025

Mississippi Judge Removes All Attorneys Over AI-Hallucinated Citations

In Withers v. City of Aberdeen, a contract dispute, both sides' attorneys submitted briefs containing fabricated case citations generated by AI tools. The court identified six non-existent citations and sanctioned all four attorneys, revoking pro hac vice admissions, imposing fines, and referring them to state bars. The drafting attorneys had used AI research and drafting tools without verifying outputs, while local counsel signed filings without review. The ruling emphasises that attorneys cannot delegate verification duties to AI and that ignorance of AI risks is no defence.

AI system involved
First Drafts

2 source articles · read the reporting →

WF-KH4UOW1 Aug 2020

Google Cloud Used in CBP AI Virtual Border Wall Contract

The Intercept reported that U.S. Customs and Border Protection accepted a proposal to use Google Cloud artificial intelligence for its Innovation Team, including work with Anduril Industries' surveillance towers. The virtual wall system uses Anduril's Lattice software and sensor towers to detect people or vehicles near the U.S.-Mexico border and relay their locations to agents. Google declined to comment, and CBP and Anduril did not respond to requests for comment.

Company involved
U.S. Customs and Border Protection (CBP)
AI system involved
Google Cloud AI Platform with Anduril Lattice and Sentry Towers

1 source article · read the reporting →

WF-WNQZLI1 Jan 2020

Clearview AI settles with ACLU over facial recognition database sales

Clearview AI has agreed to stop selling its facial recognition database to most private US companies as part of a proposed settlement with the ACLU. The company scraped billions of images from social media without consent to build its database, violating Illinois' Biometric Information Privacy Act. The settlement requires Clearview to delete old facial vectors and allow Illinois residents to opt out. The company can still sell its technology to law enforcement and government agencies.

Company involved
Clearview AI
AI system involved
Clearview AI facial recognition database

8 source articles · read the reporting →

← Newerpage 6 of 7Older →