Storm-1376 used AI-generated fake audio during Taiwan election, Microsoft reports
Microsoft's Threat Analysis Center reported that the Chinese state-linked group Storm-1376 posted suspected AI-generated fake audio of former Taiwanese presidential candidate Terry Gou endorsing another candidate on election day in January 2024. Gou had made no such statement, and YouTube removed the content before it reached a wide audience. The group has also used AI-generated memes and news anchors as part of influence operations in Taiwan and the United States.
- Company involved
- Storm-1376 (also known as Spamouflage and Dragonbridge)
7 source articles · read the reporting →
Beijing Internet Court rules AI voice cloning infringes personality rights
A Chinese dubbing artist, Yin, discovered that his voice was being used without permission in a text-to-speech AI product. The product was developed by a software company using recordings provided by a cultural media company, and was made available on a platform operated by a smart technology company. The Beijing Internet Court ruled that the AI-generated voice was highly similar to the plaintiff's voice and infringed his personality rights. The court ordered the defendants to stop infringement and pay damages of 250,000 RMB.
5 source articles · read the reporting →
CJEU rules Dun & Bradstreet must explain automated credit decisions under GDPR
A customer was refused a mobile phone contract because of an automated credit assessment by Dun & Bradstreet Austria. The customer took the case to court, which found that Dun & Bradstreet had infringed the GDPR by failing to provide meaningful information about the logic involved. The CJEU ruled that data controllers must explain automated decisions and that trade secrets cannot automatically override the right of access.
- Company involved
- Dun & Bradstreet Austria GmbH
7 source articles · read the reporting →
ICO investigates Microsoft's Recall feature for privacy risks
The UK Information Commissioner's Office (ICO) has issued a statement on 22 May 2024 regarding Microsoft's Recall feature. The ICO is making enquiries with Microsoft to understand the safeguards in place to protect user privacy, expecting transparency and necessity in data processing. This follows concerns that the feature may not adequately consider data protection from the outset before being brought to market.
- Company involved
- Microsoft
- AI system involved
- Recall
10 source articles · read the reporting →
Center for Investigative Reporting Sues OpenAI, Microsoft Over Copyright
The Center for Investigative Reporting, publisher of Mother Jones and Reveal, has filed a lawsuit against OpenAI and Microsoft in federal court, alleging the companies used its copyrighted articles without permission or compensation to train their AI products. The nonprofit argues that the AI-generated summaries of its stories threaten journalism and violate the Copyright Act and the Digital Millennium Copyright Act. The case is pending in the U.S. District Court for the Southern District of New York.
- Company involved
- OpenAI and Microsoft
6 source articles · read the reporting →
OpenDream AI art site allowed users to generate child sexual abuse material
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
- Company involved
- CBM Media Pte Ltd
- AI system involved
- OpenDream
3 source articles · read the reporting →
Chelmer Valley High School reprimanded for facial recognition DPIA failure
Chelmer Valley High School was issued a reprimand by the ICO for failing to complete a Data Protection Impact Assessment before introducing facial recognition technology for cashless catering. The reprimand was issued on 22 July 2024.
- Company involved
- Chelmer Valley High School
7 source articles · read the reporting →
CBSE OnMark portal vulnerability exposed student data to Google Gemini
A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.
- Company involved
- Central Board of Secondary Education (CBSE)
- AI system involved
- OnMark
1 source article · read the reporting →
Meta's cross-check program delays removal of violating content for privileged users
The Oversight Board's policy advisory opinion on Meta's cross-check program found that the system grants certain users, such as business partners and celebrities, additional human review before removing violating content, while ordinary users face immediate removal. This unequal treatment allows potentially harmful content to remain on the platform for days, and Meta has failed to track whether the program improves accuracy. The Board made 32 recommendations to address these flaws.
- Company involved
- Meta
- AI system involved
- cross-check program
10 source articles · read the reporting →
Audit of RisCanvi finds biases and reliability issues in criminal justice system
Eticas conducted an adversarial audit of RisCanvi, an AI risk assessment tool used in Catalonia's criminal justice system. The audit uncovered biases in risk classifications against specific demographics and significant reliability issues. The findings call for fairer practices in criminal justice AI.
- Company involved
- Catalonia's criminal justice system
- AI system involved
- RisCanvi
4 source articles · read the reporting →
42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
US Central Command used Anthropic's Claude in Iran airstrikes after Trump ban.
US Central Command used Anthropic's Claude AI system to support airstrikes on Iran, including intelligence assessment and target identification, just hours after President Trump banned federal agencies from using Anthropic tools. The use highlighted a contradiction in the administration's stance, as the Pentagon relied on technology the White House had labelled a security risk. Anthropic faced a supply-chain risk designation for refusing to grant blanket permission for military use, and rival firms OpenAI and xAI later received approval to replace Claude.
- Company involved
- US Central Command (Centcom)
- AI system involved
- Claude
4 source articles · read the reporting →
Italian DPA fines Municipality of Trento over AI surveillance projects
The Italian data protection authority (Garante) fined the Municipality of Trento €50,000 for two research projects, Marvel and Protector, that used AI to analyze video, audio, and social media data for public security purposes. The projects involved automated detection of risk events from surveillance cameras and microphones in public spaces, as well as monitoring social media for hate speech. The Garante found multiple violations of privacy law, including lack of a valid legal basis, insufficient anonymization, failure to conduct a data protection impact assessment, and inadequate transparency. The municipality is required to delete the unlawfully processed data.
- Company involved
- Comune di Trento
- AI system involved
- Marvel and Protector
9 source articles · read the reporting →
Didi fined for over-collecting personal data of users
The Cyberspace Administration of China fined Didi Global Inc. for violating data protection laws. The investigation found that Didi had over-collected personal data from passengers and drivers, including facial recognition, location, and clipboard information, totaling billions of records. The violations began in 2015 and continued until the investigation in 2021. Didi was ordered to pay a penalty and correct its practices.
- Company involved
- 滴滴全球股份有限公司 (Didi Global Inc.)
- AI system involved
- Didi ride-hailing apps
8 source articles · read the reporting →
Meta Smart Glasses Lawsuit Claims Sex, Bathroom Footage Was Sent to Overseas AI Workers - Law Commentary
Recorded and transmitted private footage of users and bystanders to overseas AI workers
- Company involved
- Meta
- AI system involved
- Meta Smart Glasses
1 source article · read the reporting →
Xuhui police expand facial recognition surveillance to profile 1.1 million residents
The Xuhui District branch of the Shanghai Municipal Bureau of Public Security is expanding its Intelligent Image Recognition System, adding 2,500 facial recognition cameras and increased computing capacity to build profiles of residents and flag deviations. The project, contracted to US-sanctioned FiberHome, is designed to match each face to files on more than 50 million people. Officials say the system will analyse behaviour patterns and trigger early warnings.
- Company involved
- Shanghai Municipal Bureau of Public Security, Xuhui District Branch
- AI system involved
- Intelligent Image Recognition System
3 source articles · read the reporting →
Ninth Circuit Sanctions Attorneys Over AI-Hallucinated Legal Briefs
The Ninth Circuit sanctioned immigration attorneys from Sethi Law Group after they filed briefs containing AI-generated false cases and quotations. The court imposed monetary sanctions, a six-month suspension from Ninth Circuit practice, and referred the matter to the California State Bar. The court also required future filings to disclose AI use and certify that all citations were verified. The case is Lnu v. Blanche.
- Company involved
- Sethi Law Group
2 source articles · read the reporting →
Mississippi Judge Removes All Attorneys Over AI-Hallucinated Citations
In Withers v. City of Aberdeen, a contract dispute, both sides' attorneys submitted briefs containing fabricated case citations generated by AI tools. The court identified six non-existent citations and sanctioned all four attorneys, revoking pro hac vice admissions, imposing fines, and referring them to state bars. The drafting attorneys had used AI research and drafting tools without verifying outputs, while local counsel signed filings without review. The ruling emphasises that attorneys cannot delegate verification duties to AI and that ignorance of AI risks is no defence.
- AI system involved
- First Drafts
2 source articles · read the reporting →
Google Cloud Used in CBP AI Virtual Border Wall Contract
The Intercept reported that U.S. Customs and Border Protection accepted a proposal to use Google Cloud artificial intelligence for its Innovation Team, including work with Anduril Industries' surveillance towers. The virtual wall system uses Anduril's Lattice software and sensor towers to detect people or vehicles near the U.S.-Mexico border and relay their locations to agents. Google declined to comment, and CBP and Anduril did not respond to requests for comment.
- Company involved
- U.S. Customs and Border Protection (CBP)
- AI system involved
- Google Cloud AI Platform with Anduril Lattice and Sentry Towers
1 source article · read the reporting →
Clearview AI settles with ACLU over facial recognition database sales
Clearview AI has agreed to stop selling its facial recognition database to most private US companies as part of a proposed settlement with the ACLU. The company scraped billions of images from social media without consent to build its database, violating Illinois' Biometric Information Privacy Act. The settlement requires Clearview to delete old facial vectors and allow Illinois residents to opt out. The company can still sell its technology to law enforcement and government agencies.
- Company involved
- Clearview AI
- AI system involved
- Clearview AI facial recognition database
8 source articles · read the reporting →
X platform enables deepfake porn and abuse against women activists
Caitlin Roper, a women's rights activist, reports that she and her colleagues at Collective Shout have been subjected to a sustained campaign of misogynistic threats, abuse, and deepfake pornography on X (formerly Twitter). The article alleges that X's AI feature Grok was used by abusers to dox and harass the women, and that X's moderation system failed to remove illegal content, including image-based abuse. Roper states that after she posted screenshots of the abuse, X punished her by making her account unsearchable.
- Company involved
- X (formerly Twitter)
- AI system involved
- Grok
2 source articles · read the reporting →
User loses lawsuit against tech company over AI-generated inaccurate information
In June 2025, a user asked an AI chatbot about university admission information. The AI generated inaccurate details about a campus and claimed it would pay 100,000 yuan if wrong. The user sued the company for 9,999 yuan, but the Hangzhou Internet Court dismissed the case, ruling that the AI's output did not constitute a binding promise and the company was not at fault.
4 source articles · read the reporting →
OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →
Herbert Brooks v. Lowes Home Centers LLC (W.D. Louisiana): AI-hallucinated content in court filing, Monetary Sanction; CLE
Generated a legal brief with hallucinated case law, filed in court.
- AI system involved
- Claude
1 source article · read the reporting →