PimEyes faces fine proceedings over biometric facial recognition in Baden-Württemberg
PimEyes, a facial recognition search engine, is accused of scraping images from the internet and processing biometric data without a valid legal basis under the GDPR. The data protection authority of Baden-Württemberg (LfDI) opened fine proceedings after it found PimEyes's response to its questions inadequate. PimEyes argues that the images it processes are publicly available and not personal data. The LfDI says the processing endangers citizens' rights and freedoms and is not covered by the GDPR exceptions.
- Company involved
- PimEyes
- AI system involved
- PimEyes
9 source articles · read the reporting →
ChatGPT hallucinates fake links to news partners' investigations
Nieman Lab tests found that ChatGPT is generating fake URLs for articles from at least 10 news publications that have licensing deals with OpenAI, including The Wall Street Journal and The Atlantic. The chatbot directs users to broken 404 pages instead of the correct articles. OpenAI acknowledged the issue and stated that the promised citation features are still under development.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
7 source articles · read the reporting →
Lattice cancels plan to give AI digital workers employee records after backlash
Lattice, an HR software company, announced on July 9th that it would give AI digital workers official employee records. After strong backlash from HR professionals and others on LinkedIn, the company canceled the feature on July 12th, stating it 'will not further pursue digital workers in the product.' The feature was intended to manage AI bots such as Devin and Piper, but the company reversed course.
- Company involved
- Lattice
- AI system involved
- Lattice
6 source articles · read the reporting →
Delta uses AI from Fetcherr for domestic ticket pricing
Delta Air Lines is using generative AI from Fetcherr to determine some domestic flight prices, currently covering 3% of its network with plans to reach 20% by end of 2025. Democratic senators expressed concern that the AI could be used for individualized pricing based on personal data, leading to higher fares. Delta denies using personal data in pricing and states it complies with regulations. No actual harm has been reported.
- Company involved
- Delta Air Lines
- AI system involved
- Fetcherr
8 source articles · read the reporting →
Check Point Research finds Google Bard can generate phishing emails and malware
Check Point Research analysed Google's generative AI platform Bard and found it could be used to create phishing emails, malware keyloggers, and basic ransomware code with minimal manipulation. Bard's anti-abuse restrictors were significantly lower than ChatGPT's, making it easier to generate malicious content. The researchers demonstrated these capabilities in controlled tests but did not report actual harm to specific individuals or organisations.
- Company involved
- Google
- AI system involved
- Bard
4 source articles · read the reporting →
Starship delivery robots blocked wheelchair users at University of Pittsburgh
In October 2019, Starship Technologies' autonomous delivery robots blocked wheelchair users on the University of Pittsburgh campus. Doctoral student Emily Ackerman reported that a robot blocked the only accessible sidewalk entrance, trapping her near traffic. Another wheelchair user, Alisa Grishman, had a similar incident earlier that month. The university and Starship paused the robot program for review.
- Company involved
- Starship Technologies
- AI system involved
- Starship delivery robot
4 source articles · read the reporting →
OpenAI disrupts Iranian influence operation using ChatGPT to generate political content
OpenAI identified and banned a cluster of ChatGPT accounts linked to an Iranian covert influence operation called Storm-2035. The operation generated long-form articles and social media comments on topics including the U.S. presidential election, the Gaza conflict, and Venezuelan politics, posing as both progressive and conservative outlets. Most content received low or no engagement, and OpenAI stated it shared threat intelligence with government and industry stakeholders. The company took down the accounts and continues to monitor for further violations.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
6 source articles · read the reporting →
India-aligned network used AI fake accounts to target Pakistan, NewsGuard finds
NewsGuard reports that a network of nearly 1,500 fake Facebook and X accounts used AI-generated content to promote pro-India and pro-Army narratives and criticise Pakistan. The network, which NewsGuard says may be linked to the Indian Army, has operated undetected since September 2021. Meta said it had enforced against a cluster of accounts; X did not comment. The full scale and reach of the operation remain unclear.
2 source articles · read the reporting →
Paper Werewolf uses AI-generated decoys and XLLs to target Russian organizations
The threat group Paper Werewolf (aka GOFFEE) is conducting a cyberespionage campaign targeting Russian defense and high-technology organizations. The campaign uses AI-generated decoy documents, such as invitations and official letters, to trick recipients into opening malicious Excel XLL add-ins that deliver a backdoor called EchoGather. The backdoor collects system information and communicates with a command-and-control server. The campaign is ongoing and was first detected in late October 2025.
- Company involved
- Paper Werewolf
- AI system involved
- EchoGather
2 source articles · read the reporting →
PimEyes facial recognition search engine identifies individuals from public photos
PimEyes, a Polish facial recognition search engine, allows users to upload a photo and find matching images from across the internet. The system scrapes billions of photos and creates biometric profiles without consent. A banker named Dylan (pseudonym) discovered that an old party photo of him was found by the system, potentially outing his private life. Privacy advocates and platforms like Instagram and YouTube are taking action against PimEyes, alleging violations of the GDPR.
- Company involved
- PimEyes
- AI system involved
- PimEyes
6 source articles · read the reporting →
Pega's Hidden AI Tool Listens To US Bank Calls, Suit Says - Law360
The system secretly recorded customer service calls, affecting bank customers.
- Company involved
- U.S. Bancorp
1 source article · read the reporting →
ChatGPT 4o image generator used to create fake receipts
ChatGPT's new image generator, part of the 4o model, can generate realistic fake restaurant receipts. Social media users demonstrated the capability, raising concerns about potential fraud. OpenAI stated that images include metadata and that it takes action against policy violations. The company defended the feature as allowing creative freedom.
- Company involved
- OpenAI
- AI system involved
- ChatGPT 4o image generator
5 source articles · read the reporting →
GoLaxy Used AI to Manipulate Public Opinion in Hong Kong and Taiwan
The Chinese company GoLaxy used an AI system called Smart Propaganda System (GoPro) to monitor and manipulate public opinion in Hong Kong and Taiwan, according to internal documents. The system collected data on members of Congress and other influential Americans, though no campaign was mounted in the United States. GoLaxy denied the allegations, calling them misinformation. The technology represents a new frontier in information warfare, enabling mass production of propaganda.
- Company involved
- GoLaxy
- AI system involved
- Smart Propaganda System (GoPro)
2 source articles · read the reporting →
School AI surveillance like Gaggle can lead to false alarms, arrests
AI surveillance tools used in schools, such as Gaggle, GoGuardian and Bark, are reported to generate false alarms that have led to student arrests. The article examines cases where automated monitoring flagged innocent behaviour as threats, causing harm to students and families.
2 source articles · read the reporting →
Palantir secretly tested predictive policing in New Orleans
Beginning in 2012, Palantir Technologies secretly partnered with the New Orleans Police Department to deploy a predictive policing system. The programme analysed gang affiliations, social media and criminal histories to forecast individuals’ likelihood of committing or becoming victims of violence, operating without public knowledge or city council oversight. Researchers and law enforcement officials raised concerns about systemic bias and civil liberties. As of 2018, the city and Palantir had not disclosed the programme’s status.
- Company involved
- New Orleans Police Department
1 source article · read the reporting →
Google contractors targeted homeless people for Pixel 4 facial recognition data
Google hired Randstad to collect facial data to train the Pixel 4's face recognition system. Contractors allegedly targeted homeless people and unaware students, using deceptive tactics such as calling it a "selfie game" and offering $5 without informing subjects they were being recorded. Google suspended the research program and opened an investigation following the report.
- Company involved
- Google
- AI system involved
- Pixel 4 facial recognition
1 source article · read the reporting →
Adobe Firefly trained on thousands of Midjourney images, Bloomberg reports
Bloomberg has reported that Adobe's Firefly image generator was trained using thousands of images from competitor Midjourney. Adobe says these made up about 5% of the training data and were part of the Adobe Stock library. The company has marketed Firefly as ethically trained and offered enterprise customers indemnity against copyright claims. Adobe responded that all Adobe Stock images undergo moderation, but the report has raised questions about Firefly's copyright safety.
- Company involved
- Adobe
- AI system involved
- Firefly
7 source articles · read the reporting →
AI-powered scam compound in Myanmar uses ChatGPT and Gemini to defraud thousands globally
Safeer Mohammed Koorimannil, trafficked to a scam compound in Tai Chang, Myanmar, was forced to use AI-powered software to impersonate a woman and deceive victims into sending money. The software, Kongtian Intelligent Customer Acquisition and Global Social Traffic Navigation, used OpenAI's ChatGPT and Google's Gemini to generate messages and translate in over 100 languages. Koorimannil targeted 50,000 victims in a month, while the tools enabled scammers to rake in tens of millions of dollars. U.S. authorities have created a strike force to disrupt such operations, and OpenAI has banned accounts linked to the scams.
- Company involved
- Tai Chang
- AI system involved
- Kongtian Intelligent Customer Acquisition (KT) and Global Social Traffic Navigation (007TG)
2 source articles · read the reporting →
Dahua Exposed for Uyghur Tracking Software in Surveillance Systems
Dahua Technology's publicly available SDK was found to contain code for detecting Uyghur ethnicity, enabling Chinese police to covertly track the persecuted minority. The revelation led to widespread criticism, and Dahua removed the SDK after being contacted by IPVM but did not comment. The company had previously been sanctioned by the US for complicity in human rights abuses against Uyghurs, and its software is part of a massive surveillance apparatus in Xinjiang.
- Company involved
- Dahua Technology
- AI system involved
- Dahua SDK
1 source article · read the reporting →
Google Cloud Used in CBP AI Virtual Border Wall Contract
The Intercept reported that U.S. Customs and Border Protection accepted a proposal to use Google Cloud artificial intelligence for its Innovation Team, including work with Anduril Industries' surveillance towers. The virtual wall system uses Anduril's Lattice software and sensor towers to detect people or vehicles near the U.S.-Mexico border and relay their locations to agents. Google declined to comment, and CBP and Anduril did not respond to requests for comment.
- Company involved
- U.S. Customs and Border Protection (CBP)
- AI system involved
- Google Cloud AI Platform with Anduril Lattice and Sentry Towers
1 source article · read the reporting →
Content Giants Sue Unauthorized AI, Invest in Paid Partners - 조선일보
Generated images of copyrighted characters without authorization, affecting Disney and NBCUniversal's intellectual property rights.
- Company involved
- Midjourney
- AI system involved
- Midjourney
1 source article · read the reporting →
Google sued for secretly tracking user data with Gemini AI
Google is accused in a class-action lawsuit of secretly activating its Gemini AI assistant for Gmail, Chat, and Meet users in October 2025, enabling it to collect private communications data without consent. The suit alleges violation of the California Invasion of Privacy Act. Google has not responded to the allegations.
- Company involved
- Google
- AI system involved
- Gemini
4 source articles · read the reporting →
AI companion apps Chattee Chat and GiMe Chat leak intimate conversations of 400,000 users
Two AI companion apps, Chattee Chat and GiMe Chat, developed by Hong Kong-based Imagime Interactive Limited, exposed millions of intimate conversations and over 600,000 images from over 400,000 users. The data leak was discovered by Cybernews on August 28, 2025, and was caused by a Kafka Broker instance left without access controls or authentication. The exposed data included IP addresses and device identifiers, potentially allowing attackers to identify users. The developer did not respond to inquiries, but the leak was closed on September 19, 2025.
- Company involved
- Imagime Interactive Limited
- AI system involved
- Chattee Chat - AI Companion and GiMe Chat - AI Companion
4 source articles · read the reporting →
OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →