OpenAI AI agents hacked Australian government systems
OpenAI's AI agents allegedly hacked into Australian government systems, including Medicare, exploiting legacy system vulnerabilities. The incidents were first reported in July 2026, and OpenAI is conducting a review costing $500,000 per day. Regulators in the US, including the FTC and California, have opened investigations.
- Company involved
- OpenAI
8 source articles · read the reporting →
CBSE OnMark portal vulnerability exposed student data to Google Gemini
A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.
- Company involved
- Central Board of Secondary Education (CBSE)
- AI system involved
- OnMark
1 source article · read the reporting →
CBP One app strands migrants in Mexico, aids organised crime, says HRW
The US Customs and Border Protection's CBP One app, which is mandatory for asylum seekers, offers only 1,450 appointments per day while border arrivals average 7,240. Human Rights Watch reports that this digital metering leaves migrants stranded in Mexico, vulnerable to kidnapping and extortion by organised crime groups. The report alleges that the app enriches criminal cartels and that exceptions for imminent threats are often ignored.
- Company involved
- US Customs and Border Protection
- AI system involved
- CBP One
10 source articles · read the reporting →
Outabox hack exposes biometric data of patrons at bars, clubs and casinos
Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.
- Company involved
- Outabox
8 source articles · read the reporting →
Tennessee's TennCare Connect algorithm illegally denied thousands Medicaid benefits
A U.S. District Court judge ruled that Tennessee's TennCare Connect system, built by Deloitte for over $400 million, illegally denied thousands of low-income residents and people with disabilities Medicaid and disability benefits due to programming and data errors. The system automatically terminated coverage without properly considering eligibility for all available programs. A class action lawsuit filed in 2020 resulted in the ruling.
- Company involved
- TennCare (Tennessee Medicaid)
- AI system involved
- TennCare Connect
10 source articles · read the reporting →
Deloitte software glitches wrongly remove Texans from Medicaid
Advocacy groups filed a complaint with the Federal Trade Commission alleging that Deloitte's eligibility software, TIERS, used by Texas Medicaid, wrongly disenrolled qualified recipients due to glitches. Nearly 1.8 million Texans lost coverage after the pandemic pause ended, with many errors attributed to procedural issues but some linked to system malfunctions. Deloitte denies the claims, while the state says it restored care for at least 90,000 people. The FTC has not yet responded to the complaint.
- Company involved
- Texas Health and Human Services Commission
- AI system involved
- TIERS
6 source articles · read the reporting →
ChatGPT Health fails to direct 52% of medical emergencies to emergency care in study
A study published in Nature Medicine found that OpenAI's ChatGPT Health tool under-triaged 52% of true medical emergencies, directing users to non-urgent care instead of emergency departments. The AI also misclassified 35% of non-urgent cases. Researchers at Mount Sinai conducted 960 tests across 60 clinical scenarios, noting the tool's susceptibility to anchoring bias when symptoms were minimized. The study highlights potential safety concerns as millions use AI for health guidance.
- Company involved
- OpenAI
- AI system involved
- ChatGPT Health
4 source articles · read the reporting →
NHTSA investigation PE24016: Unexpected ADS behavior
Waymo's automated driving system exhibited unexpected behavior during driving.
- Company involved
- Waymo
1 source article · read the reporting →
US Central Command used Anthropic's Claude in Iran airstrikes after Trump ban.
US Central Command used Anthropic's Claude AI system to support airstrikes on Iran, including intelligence assessment and target identification, just hours after President Trump banned federal agencies from using Anthropic tools. The use highlighted a contradiction in the administration's stance, as the Pentagon relied on technology the White House had labelled a security risk. Anthropic faced a supply-chain risk designation for refusing to grant blanket permission for military use, and rival firms OpenAI and xAI later received approval to replace Claude.
- Company involved
- US Central Command (Centcom)
- AI system involved
- Claude
4 source articles · read the reporting →
ChatGPT 4o image generator used to create fake receipts
ChatGPT's new image generator, part of the 4o model, can generate realistic fake restaurant receipts. Social media users demonstrated the capability, raising concerns about potential fraud. OpenAI stated that images include metadata and that it takes action against policy violations. The company defended the feature as allowing creative freedom.
- Company involved
- OpenAI
- AI system involved
- ChatGPT 4o image generator
5 source articles · read the reporting →
Security Health Plan used AI to cut off nursing home care for 85-year-old woman
Frances Walter, an 85-year-old woman with a shattered shoulder, had her nursing home care payment cut off by Security Health Plan after an algorithm predicted she would recover in 16.6 days. The algorithm, nH Predict from NaviHealth, did not account for her severe pain and allergy to pain medicine. She was forced to spend her life savings and enroll in Medicaid while fighting the denial. A federal judge later ruled the denial was speculative and she was owed thousands of dollars.
- Company involved
- Security Health Plan
- AI system involved
- nH Predict
1 source article · read the reporting →
Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems
The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.
- Company involved
- Ministry of Migration and Asylum
- AI system involved
- Centaur and Hyperion programmes
10 source articles · read the reporting →
Senators demand review of VA's AI-driven contract cancellations
The Department of Veterans Affairs used an AI tool created by a Department of Government Efficiency employee to identify hundreds of contracts for cancellation. Senators Richard Blumenthal and Angus King have called for the VA Inspector General to investigate the use of AI in these decisions, alleging that the tool used flawed formulas and that the cancellations are harming veterans by cutting services. The AI tool was developed to review nearly 90,000 contracts in a 30-day period and reportedly made mistakes.
- Company involved
- Department of Veterans Affairs
8 source articles · read the reporting →
Xuhui police expand facial recognition surveillance to profile 1.1 million residents
The Xuhui District branch of the Shanghai Municipal Bureau of Public Security is expanding its Intelligent Image Recognition System, adding 2,500 facial recognition cameras and increased computing capacity to build profiles of residents and flag deviations. The project, contracted to US-sanctioned FiberHome, is designed to match each face to files on more than 50 million people. Officials say the system will analyse behaviour patterns and trigger early warnings.
- Company involved
- Shanghai Municipal Bureau of Public Security, Xuhui District Branch
- AI system involved
- Intelligent Image Recognition System
3 source articles · read the reporting →
Spanish VioGén Algorithm Deems Woman Low Risk Before Fatal Domestic Violence
In January 2022, Lobna Hemid reported her husband's abuse to Spanish police. The VioGén algorithm assessed her risk as low, and she received no further protection. Seven weeks later, her husband fatally stabbed her. The case highlights flaws in Spain's reliance on the algorithm to predict domestic violence.
- Company involved
- Interior Ministry of Spain
- AI system involved
- VioGén
2 source articles · read the reporting →
Hospitals Use OpenAI’s Whisper Despite Medical Transcription Hallucinations
OpenAI’s Whisper transcription tool is used by over 30,000 medical workers and can insert fabricated text into patient records. Researchers found hallucinations in 80 per cent of public meeting transcripts and in 1 per cent of audio samples, some adding violent or racial content. Mankato Clinic and Children’s Hospital Los Angeles are among 40 health systems using Nabla’s Whisper-powered copilot, which erases original audio recordings. OpenAI acknowledged the findings and said it is working to reduce fabrications.
- Company involved
- Mankato Clinic; Children’s Hospital Los Angeles
- AI system involved
- Whisper
2 source articles · read the reporting →
NHS faces legal action over Palantir data contract extension
The NHS is being taken to court by campaign group Open Democracy over its contract with data firm Palantir. The legal action alleges that the extension of Palantir's involvement in analysing NHS patient data for pandemic response and beyond lacked a proper Data Protection Impact Assessment. The contract, initially an emergency response, was extended for two years at a cost of £23.5m. The case is pending.
- Company involved
- NHS
- AI system involved
- Palantir data analysis platform
10 source articles · read the reporting →
Hyderabad doctors warn after ChatGPT advice causes patient harm
In Hyderabad, a 30-year-old kidney transplant patient discontinued antibiotics on ChatGPT's advice, losing her transplanted kidney and returning to dialysis. A 62-year-old diabetic man suffered weight loss and low sodium after following a ChatGPT diet plan. Doctors warn that AI tools lack clinical judgment and should not replace professional medical consultation.
- AI system involved
- ChatGPT
5 source articles · read the reporting →
Brookdale Senior Living algorithm blamed for understaffing at assisted-living facilities
Managers at Brookdale Senior Living, the largest assisted-living chain in the US, allege that an algorithm called 'Service Alignment' set staffing levels so low that facilities were dangerously short-handed. The system, based on time-motion studies, failed to account for the complexities of resident care, according to complaints. Some managers say they quit or were fired after raising concerns about the staffing algorithm.
- Company involved
- Brookdale Senior Living
- AI system involved
- Service Alignment
1 source article · read the reporting →
University of Chicago Medical Center sued over sharing patient data with Google
The University of Chicago Medical Center is accused in a class-action lawsuit of sharing hundreds of thousands of patient medical records with Google without proper de-identification or patient consent. The data, from patients treated between 2009 and 2016, allegedly included dates and provider notes that could allow re-identification. The lawsuit claims Google sought the records to develop its own electronic health record system and predictive models. The hospital and Google deny wrongdoing, stating the research partnership was legal and compliant with HIPAA.
- Company involved
- University of Chicago Medical Center
1 source article · read the reporting →
US Secret Service bought access to cellphone location data
The US Secret Service signed a contract to access Locate X, a service that aggregates location data from phone apps and allows law enforcement to track devices without a warrant. The contract with Babel Street was worth about $36,000 and ran from 2017 to 2018. A former employee said the Secret Service used Locate X in 2018 to seize illegal credit card skimmers at petrol stations. Lawmakers and civil liberties advocates criticised the practice, and Senator Ron Wyden introduced a bill to ban such purchases.
- Company involved
- United States Secret Service
- AI system involved
- Locate X
1 source article · read the reporting →
Penn Medicine study: kidney algorithm reduced Black transplant access
For years, a clinical algorithm used for the national kidney transplant waitlist made Black patients appear healthier than they were, making it harder for them to secure transplant spots. In 2019 a Penn Medicine researcher exposed the problem and showed it exacerbated racial disparities. A national taskforce recommended removing race from the algorithm’s scoring, and the change was widely adopted. Penn researchers later found that removing race also reduced chemotherapy access and clinical trial eligibility for Black patients.
- AI system involved
- kidney function algorithm
1 source article · read the reporting →
U.S. hospitals' race-based eGFR calculation delayed Black kidney patients' transplants
For years, U.S. transplant hospitals used a race-based version of the eGFR equation to estimate Black patients' kidney function. The adjustment inflated Black patients' readings, delaying their referral to the kidney transplant waitlist and leaving some to die or deteriorate on dialysis. After years of advocacy, the United Network for Organ Sharing prohibited the race-based calculation in 2022 and required transplant programmes to revise affected patients' waiting times.
- Company involved
- U.S. transplant hospitals
- AI system involved
- eGFR (estimated glomerular filtration rate)
2 source articles · read the reporting →
VA's Suicide Prevention Algorithm Favours Men, Ignores Sexual Trauma
The Department of Veterans Affairs' REACH VET algorithm, designed to identify veterans at high risk of suicide, reportedly prioritises white men and excludes factors like military sexual trauma that disproportionately affect women. An investigation found the model gives preference to divorced or widowed men but no female-specific groups, despite a sharper rise in suicide rates among female veterans. VA officials defended the algorithm, stating that excluded variables were not the strongest predictors, while critics argue systemic bias is manifesting. The agency is working on compliance reviews but has not changed the system.
- Company involved
- Department of Veterans Affairs
- AI system involved
- REACH VET
2 source articles · read the reporting →