The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

164 incidents closest to “Nova Credit” · matched on meaning · public reporting

WF-PECTZC3 Sep 2024

Dutch DPA fines Clearview AI €30.5 million for GDPR violations

The Dutch Data Protection Authority fined Clearview AI €30.5 million for creating an illegal database of biometric codes scraped from social media without consent. The regulator accused the company of failing to inform individuals about how their data is used and continuing violations after investigation. Clearview AI denies the allegations, stating it has no presence in the Netherlands or EU and that the fine is unenforceable.

Company involved
Clearview AI
AI system involved
Clearview AI facial recognition database

7 source articles · read the reporting →

42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE

SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.

AI system involved
OpenClaw

5 source articles · read the reporting →

WF-UF6BMA1 Jan 2018

TransUnion AI tenant screening denied 75-year-old man apartment due to mistaken littering conviction

Chris Robinson, then 75, applied for a senior living apartment in California. The property manager used an AI screening program from TransUnion, which assigned him a low score based on a mistaken conviction for littering that belonged to a different person with the same name in Texas. Robinson lost the apartment and his application fee. A federal class-action lawsuit against TransUnion moved toward a $11.5 million settlement in 2023.

10 source articles · read the reporting →

WF-3RBX5G1 Jan 2021

Ukrainian Hacker Pleads Guilty to Operating OnlyFake AI ID Scam Site

Yurii Nazarenko, a Ukrainian national, pleaded guilty to running OnlyFake, an AI-powered website that generated and sold over 10,000 counterfeit identification documents globally. The site allowed users to create realistic fake IDs, including driver's licenses and passports, to bypass identity verification at banks and cryptocurrency exchanges. Nazarenko faces up to 15 years in prison and agreed to forfeit $1.2 million. Sentencing is scheduled for June 2026.

Company involved
OnlyFake
AI system involved
OnlyFake

3 source articles · read the reporting →

WF-R41UQV23 Feb 2012

Palantir secretly tested predictive policing in New Orleans

Beginning in 2012, Palantir Technologies secretly partnered with the New Orleans Police Department to deploy a predictive policing system. The programme analysed gang affiliations, social media and criminal histories to forecast individuals’ likelihood of committing or becoming victims of violence, operating without public knowledge or city council oversight. Researchers and law enforcement officials raised concerns about systemic bias and civil liberties. As of 2018, the city and Palantir had not disclosed the programme’s status.

Company involved
New Orleans Police Department

1 source article · read the reporting →

WF-ZGAC7222 Apr 2024

AI-generated voice impersonates Liz Bonnin to deceive Incognito

Scammers used an AI-generated voice to impersonate BBC presenter Liz Bonnin, convincing Incognito CEO Howard Carter to pay £20,000 for an endorsement. Bonnin's likeness was used in insect repellant ads without her consent. The AI-generated voice note exhibited inconsistent accent and cadence, as assessed by experts. Incognito reported the incident to police and its bank.

6 source articles · read the reporting →

Clearview AI facial recognition app scrapes billions of images and is used by police

Clearview AI, a secretive start-up, built a facial recognition app that matches photos to a database of more than three billion images scraped from social media and websites. More than 600 law enforcement agencies, including the FBI and Department of Homeland Security, have used the tool to identify suspects in crimes such as shoplifting, identity theft and murder. The company monitored officers who ran a reporter's photo through the app, and its founder acknowledged designing an augmented-reality prototype but said there were no plans to release it. Critics warned the tool could end anonymity and enable misuse.

Company involved
Clearview AI
AI system involved
Clearview AI facial recognition app

2 source articles · read the reporting →

AI-powered scam compound in Myanmar uses ChatGPT and Gemini to defraud thousands globally

Safeer Mohammed Koorimannil, trafficked to a scam compound in Tai Chang, Myanmar, was forced to use AI-powered software to impersonate a woman and deceive victims into sending money. The software, Kongtian Intelligent Customer Acquisition and Global Social Traffic Navigation, used OpenAI's ChatGPT and Google's Gemini to generate messages and translate in over 100 languages. Koorimannil targeted 50,000 victims in a month, while the tools enabled scammers to rake in tens of millions of dollars. U.S. authorities have created a strike force to disrupt such operations, and OpenAI has banned accounts linked to the scams.

Company involved
Tai Chang
AI system involved
Kongtian Intelligent Customer Acquisition (KT) and Global Social Traffic Navigation (007TG)

2 source articles · read the reporting →

Model Kanchan Nagar sends legal notice over deepfake ad by Yatra Online

Kanchan Nagar, a professional model, issued a legal notice to the Advertising Standards Council of India (ASCI) after Yatra Online Limited allegedly used an AI-generated deepfake image of her face in an advertisement without her consent. The advertisement, published in a national daily, bore a striking resemblance to Nagar's image. Nagar called for regulatory intervention to address the misuse of deepfake technology in advertising.

Company involved
Yatra Online Limited

3 source articles · read the reporting →

WF-NWB6EE1 Dec 2024

OpenAI's Sora video generator trained on copyrighted content without consent, tests suggest

Tests by The Washington Post suggest that OpenAI's video generation tool Sora was trained on videos from Netflix, TikTok, YouTube and other sources without permission. OpenAI has not disclosed its training data for Sora, saying only that it used publicly available and licensed data. The tool can closely replicate copyrighted characters, logos and scenes, raising concerns about copyright infringement. OpenAI has not faced a lawsuit specifically over Sora's training data but is fighting other copyright suits.

Company involved
OpenAI
AI system involved
Sora

3 source articles · read the reporting →

WF-ZMVUYB24 Dec 2023

NewsBreak AI generates false news stories, harms local charities

NewsBreak, the most downloaded US news app, used AI to generate news stories, including a fabricated shooting in Bridgeton, New Jersey. The AI-produced content also contained errors that caused charities to turn away people needing services. Former employees and a consultant raised concerns about the practice, and the company has faced multiple copyright lawsuits. NewsBreak maintains it removes inaccurate content and complies with US laws.

Company involved
NewsBreak
AI system involved
NewsBreak app

2 source articles · read the reporting →

WF-NTJTJM27 May 2021

Privacy International challenges Clearview AI's facial recognition database in Europe

Privacy International filed complaints against Clearview AI with five European data protection authorities in May 2021, alleging that the company's scraping of facial images from the web and building a biometric database without consent violates data protection laws. The regulators in the UK, France, Italy, Greece, and Austria have since found Clearview's practices unlawful, imposed fines, and ordered deletion of data. Clearview has appealed the UK fine, and the case is ongoing.

Company involved
Clearview AI
AI system involved
Clearview

10 source articles · read the reporting →

WF-KH4UOW1 Aug 2020

Google Cloud Used in CBP AI Virtual Border Wall Contract

The Intercept reported that U.S. Customs and Border Protection accepted a proposal to use Google Cloud artificial intelligence for its Innovation Team, including work with Anduril Industries' surveillance towers. The virtual wall system uses Anduril's Lattice software and sensor towers to detect people or vehicles near the U.S.-Mexico border and relay their locations to agents. Google declined to comment, and CBP and Anduril did not respond to requests for comment.

Company involved
U.S. Customs and Border Protection (CBP)
AI system involved
Google Cloud AI Platform with Anduril Lattice and Sentry Towers

1 source article · read the reporting →

WF-CB17LN31 Oct 2023

California AG declares out-of-state ALPR data sharing unlawful

California Attorney General Rob Bonta issued guidance confirming that sharing automated license plate reader (ALPR) data with out-of-state or federal agencies violates state law SB 34. The decision follows years of advocacy by EFF and the ACLU, who demonstrated through public records that many California law enforcement agencies were sharing data with hundreds of external agencies, including ICE and CBP. The guidance mandates that all California agencies review their data sharing and cut off access to out-of-state and federal entities.

Company involved
California law enforcement agencies
AI system involved
Automated license plate readers (ALPRs)

1 source article · read the reporting →

Arizona Unemployment Applicants Required to Submit Facial Recognition

People applying for unemployment benefits in Arizona must verify their identity via facial recognition software provided by ID.me. If the system fails to match a selfie to a photo ID, applicants can be denied benefits unless they successfully complete a video chat with a referee. A class-action lawsuit filed in June 2021 alleges that the practice violates due process rights and discriminates against people of colour.

Company involved
Arizona Department of Economic Security
AI system involved
ID.me

1 source article · read the reporting →

WF-WNQZLI1 Jan 2020

Clearview AI settles with ACLU over facial recognition database sales

Clearview AI has agreed to stop selling its facial recognition database to most private US companies as part of a proposed settlement with the ACLU. The company scraped billions of images from social media without consent to build its database, violating Illinois' Biometric Information Privacy Act. The settlement requires Clearview to delete old facial vectors and allow Illinois residents to opt out. The company can still sell its technology to law enforcement and government agencies.

Company involved
Clearview AI
AI system involved
Clearview AI facial recognition database

8 source articles · read the reporting →

WF-GCB7V21 Jan 2026

OpenClaw vulnerabilities enable data leakage and prompt injection

In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.

AI system involved
OpenClaw

6 source articles · read the reporting →

WF-8RY9IW1 Dec 2025

Mexican government agencies hacked using Anthropic's Claude AI

Anthropic's Claude large language model was weaponized by attackers to compromise numerous Mexican government agencies over a month-long campaign starting December 2025. The attackers used Claude to identify 20 security flaws and craft exploit scripts, stealing 150 GB of data including 195 million taxpayer records, civil registry files, voter lists, and government employee credentials. Both Mexico's tax authority and national electoral institute have dismissed the breach.

Company involved
Anthropic
AI system involved
Claude

5 source articles · read the reporting →

WF-GYY2DP5 Sep 2025

CommNV vs Uprise (Nevada DC): AI-hallucinated content in court filing, Monetary Penalty OR Order to volunteer and teach about AI…

The AI system generated fabricated legal citations that were included in a court filing, misleading the court and opposing counsel.

Company involved
Christopher Day

1 source article · read the reporting →

WF-1OVEQM23 Sep 2026

OpenAI sued over alleged undisclosed human review of ChatGPT conversations - Top Class Actions

ChatGPT conversations were reviewed by third-party contractors without adequate disclosure to users.

Company involved
OpenAI OpCo LLC
AI system involved
ChatGPT

1 source article · read the reporting →

AI chatbots recommended unlicensed casinos to UK users

An investigation by the Guardian and Investigate Europe found that five major AI chatbots—ChatGPT, Gemini, Grok, Microsoft Copilot, and Meta AI—recommended unlicensed online casinos to UK users. Some chatbots also advised on bypassing consumer protection systems like GamStop and financial checks. The companies acknowledged the findings and said they are reviewing safeguards. Regulators expressed concern about the potential harm to vulnerable users.

Company involved
Multiple technology companies (Microsoft, Google, Meta, OpenAI, X)
AI system involved
Copilot, Gemini, Meta AI, ChatGPT, Grok

5 source articles · read the reporting →

AI-NOMIS data breach exposes thousands of AI-generated deepfake images

Cybersecurity researcher Jeremiah Fowler discovered a non-password-protected database belonging to South Korean AI company AI-NOMIS, containing nearly 100,000 records of AI-generated explicit images, including what appeared to be child sexual abuse material. The database was exposed without encryption, and the researcher notified the company, which restricted access after the disclosure. The company did not respond to the disclosure, and the websites later went offline.

Company involved
AI-NOMIS
AI system involved
GenNomis

5 source articles · read the reporting →

WF-N2X8EZ1 Jun 2024

Australian children's photos scraped into LAION-5B AI dataset without consent

Human Rights Watch found that the LAION-5B dataset, used to train AI tools, contains links to identifiable photos of Australian children scraped from the web without consent. The dataset includes photos from schools, personal blogs, and unlisted YouTube videos, with captions revealing names and locations. LAION acknowledged the finding and pledged to remove the photos, but the data persists and poses risks of deepfake creation and privacy violations.

Company involved
LAION
AI system involved
LAION-5B

4 source articles · read the reporting →

WF-M83U889 Sep 2026

Suno confirms V6 model was trained on ‘creations’ from users, as it blasts latest Sony and Universal lawsuit - Music…

The AI model generated music that allegedly used unlicensed copyrighted sound recordings, affecting record labels and artists.

Company involved
Suno
AI system involved
Suno V6

1 source article · read the reporting →

← Newerpage 6 of 7Older →