The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

188 incidents closest to “Visa A2A Protect” · matched on meaning · public reporting

WF-7PPBNA4 Mar 2022

Spanish VioGén Algorithm Deems Woman Low Risk Before Fatal Domestic Violence

In January 2022, Lobna Hemid reported her husband's abuse to Spanish police. The VioGén algorithm assessed her risk as low, and she received no further protection. Seven weeks later, her husband fatally stabbed her. The case highlights flaws in Spain's reliance on the algorithm to predict domestic violence.

Company involved
Interior Ministry of Spain
AI system involved
VioGén

2 source articles · read the reporting →

WF-04DJR81 Jun 2020

Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner

Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.

Company involved
Kmart Australia Limited

7 source articles · read the reporting →

WF-T5ERDR1 Mar 2023

Bank of America Customer Targeted by AI Voice Deepfake Scam

Clive Kabatznik, a Florida investor, was targeted by scammers who used AI-generated voice deepfakes to impersonate him in calls to his Bank of America representative. The fraudsters attempted to trick the banker into transferring money, but the banker became suspicious and hung up. The bank reported the incident to its security team, and it took about 10 days for Mr. Kabatznik to re-establish contact with his banker. The incident highlights the growing threat of voice deepfakes in financial scams.

Company involved
Bank of America

2 source articles · read the reporting →

WF-NTJTJM27 May 2021

Privacy International challenges Clearview AI's facial recognition database in Europe

Privacy International filed complaints against Clearview AI with five European data protection authorities in May 2021, alleging that the company's scraping of facial images from the web and building a biometric database without consent violates data protection laws. The regulators in the UK, France, Italy, Greece, and Austria have since found Clearview's practices unlawful, imposed fines, and ordered deletion of data. Clearview has appealed the UK fine, and the case is ongoing.

Company involved
Clearview AI
AI system involved
Clearview

10 source articles · read the reporting →

WF-IWL4TH1 Jan 2018

US Secret Service bought access to cellphone location data

The US Secret Service signed a contract to access Locate X, a service that aggregates location data from phone apps and allows law enforcement to track devices without a warrant. The contract with Babel Street was worth about $36,000 and ran from 2017 to 2018. A former employee said the Secret Service used Locate X in 2018 to seize illegal credit card skimmers at petrol stations. Lawmakers and civil liberties advocates criticised the practice, and Senator Ron Wyden introduced a bill to ban such purchases.

Company involved
United States Secret Service
AI system involved
Locate X

1 source article · read the reporting →

WF-5MY45D4 May 2020

France uses AI to monitor mask-wearing on public transport

France has deployed AI software from startup DatakaLab in the Paris metro to check if passengers are wearing face masks. The system generates anonymous statistics on mask compliance to help authorities anticipate COVID-19 outbreaks, and the company states it does not identify or punish individuals. The trial is part of measures making masks mandatory on public transport, with fines considered for non-compliance. Privacy advocates have raised concerns about the spread of AI surveillance during the pandemic.

1 source article · read the reporting →

WF-CB17LN31 Oct 2023

California AG declares out-of-state ALPR data sharing unlawful

California Attorney General Rob Bonta issued guidance confirming that sharing automated license plate reader (ALPR) data with out-of-state or federal agencies violates state law SB 34. The decision follows years of advocacy by EFF and the ACLU, who demonstrated through public records that many California law enforcement agencies were sharing data with hundreds of external agencies, including ICE and CBP. The guidance mandates that all California agencies review their data sharing and cut off access to out-of-state and federal entities.

Company involved
California law enforcement agencies
AI system involved
Automated license plate readers (ALPRs)

1 source article · read the reporting →

Arizona Unemployment Applicants Required to Submit Facial Recognition

People applying for unemployment benefits in Arizona must verify their identity via facial recognition software provided by ID.me. If the system fails to match a selfie to a photo ID, applicants can be denied benefits unless they successfully complete a video chat with a referee. A class-action lawsuit filed in June 2021 alleges that the practice violates due process rights and discriminates against people of colour.

Company involved
Arizona Department of Economic Security
AI system involved
ID.me

1 source article · read the reporting →

WF-WNQZLI1 Jan 2020

Clearview AI settles with ACLU over facial recognition database sales

Clearview AI has agreed to stop selling its facial recognition database to most private US companies as part of a proposed settlement with the ACLU. The company scraped billions of images from social media without consent to build its database, violating Illinois' Biometric Information Privacy Act. The settlement requires Clearview to delete old facial vectors and allow Illinois residents to opt out. The company can still sell its technology to law enforcement and government agencies.

Company involved
Clearview AI
AI system involved
Clearview AI facial recognition database

8 source articles · read the reporting →

WF-452L9H1 Jan 2024

Steak 'n Shake sued over facial recognition kiosks under BIPA

A class action lawsuit alleges that Steak 'n Shake illegally collects facial biometrics from customers using PopID-powered self-ordering kiosks without proper consent. Plaintiff Michael Massel claims the restaurant chain failed to provide notice and obtain written consent as required by Illinois' Biometric Information Privacy Act (BIPA). The suit seeks damages of up to $5,000 per violation for anyone whose biometric data was collected in Illinois in the past five years.

Company involved
Steak 'n Shake
AI system involved
PopID biometric kiosks

6 source articles · read the reporting →

WF-AFVQNO1 Jan 2026

ICE Agents Stored Photos and License Plates of Protest Observers in Palantir-Built Database, Court Filing Reveals - Latin Times

A court filing alleges ICE agents stored photos and license plates of protest observers in a Palantir-built database, labeled some of them as threats, and ran facial recognition searches on them.

Company involved
U.S. Immigration and Customs Enforcement (ICE)
AI system involved
ICM (Investigative Case Management system)

1 source article · read the reporting →

WF-GCB7V21 Jan 2026

OpenClaw vulnerabilities enable data leakage and prompt injection

In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.

AI system involved
OpenClaw

6 source articles · read the reporting →

AI chatbots recommended unlicensed casinos to UK users

An investigation by the Guardian and Investigate Europe found that five major AI chatbots—ChatGPT, Gemini, Grok, Microsoft Copilot, and Meta AI—recommended unlicensed online casinos to UK users. Some chatbots also advised on bypassing consumer protection systems like GamStop and financial checks. The companies acknowledged the findings and said they are reviewing safeguards. Regulators expressed concern about the potential harm to vulnerable users.

Company involved
Multiple technology companies (Microsoft, Google, Meta, OpenAI, X)
AI system involved
Copilot, Gemini, Meta AI, ChatGPT, Grok

5 source articles · read the reporting →

WF-XMO8SI28 Aug 2026ZH-CN

Woman Blindly Trusts Driver Assistance, Rear-Ends Lane-Changing Bus on Highway

女子轻信辅助驾驶放任不管 高速上直接追尾变道大巴车 - 驱动之家

On August 28, on the Shanghai-Kunming Expressway, a woman driving an SUV with driver assistance engaged rear-ended a bus that suddenly changed lanes. She assumed the system would brake automatically and took no action. The bus driver was found at fault for the lane change, but police warned against over-reliance on driver assistance.

1 source article · read the reporting →

WF-0ZQI8S4 Oct 2016

$30M Equifax hard inquiry dispute class action settlement - Top Class Actions

A class action, settled for $30 million, alleged that Equifax automatically rejected consumers' disputes of hard inquiries on their credit reports, sending a form letter instead of investigating.

Company involved
Equifax Information Services LLC

1 source article · read the reporting →

WF-ART4FW1 Feb 2026

Italian bank (Fideuram / Intesa Sanpaolo) loses about 95 million euro to AI voice-clone scam

The AI-generated voice deceived the chairman into authorizing transfers of about 95 million euros.

1 source article · read the reporting →

WF-S9GZ006 Mar 2024

Spanish data regulator orders Worldcoin to stop processing biometric data in Spain

The Spanish Data Protection Agency (AEPD) has ordered a precautionary measure against Tools for Humanity Corporation, the company behind Worldcoin, to cease collection and processing of personal data in Spain. The AEPD received complaints alleging insufficient information, collection of data from minors, and inability to withdraw consent. The regulator acted under GDPR Article 66.1 to prevent potentially irreparable harm to individuals' data protection rights.

Company involved
Tools for Humanity Corporation
AI system involved
Worldcoin

8 source articles · read the reporting →

WF-3KD9ZW25 Mar 2024

Portuguese regulator suspends Worldcoin's biometric data collection

Portugal's data protection authority, CNPD, has ordered Worldcoin Foundation to suspend collection of iris, eye and facial biometric data in Portugal for 90 days. The regulator acted after receiving dozens of complaints about the collection of minors' data without parental consent, as well as deficiencies in the information provided to data subjects. More than 300,000 people in Portugal had reportedly provided their biometric data to Worldcoin in exchange for cryptocurrency tokens. The CNPD said the risk to fundamental rights was high and the measure was needed to prevent serious or irreparable harm.

Company involved
Worldcoin Foundation
AI system involved
Orb

5 source articles · read the reporting →

WF-EEFSL81 Oct 2021

Airbnb bans users in Australia using trustworthiness algorithm

Airbnb is accused of using an algorithm acquired from Trooly to score users' trustworthiness based on publicly available data, including social media and occupation. Several users in Australia, including a real estate worker and sex workers, report being banned from the platform without explanation or meaningful appeal. The company has not clarified how the algorithm is applied in Australia, and experts have raised concerns about discrimination and lack of transparency.

Company involved
Airbnb
AI system involved
Trooly

4 source articles · read the reporting →

DFFH breaches privacy by using ChatGPT in child protection report

A child protection worker at the Department of Families, Fairness and Housing (DFFH) used ChatGPT to draft a Protection Application Report for the Children’s Court, entering sensitive personal information about a child. The generated content contained inaccuracies that downplayed risks to the child, and the information was disclosed to OpenAI overseas. An investigation by the Office of the Victorian Information Commissioner found DFFH failed to ensure accuracy and protect personal information, contravening IPPs 3.1 and 4.1. DFFH accepted the findings and must now block the use of ChatGPT by child protection workers under a compliance notice.

Company involved
Department of Families, Fairness and Housing
AI system involved
ChatGPT

9 source articles · read the reporting →

Whitebridge AI faces complaint over false reputation reports

Whitebridge AI, a Lithuanian company, is accused of generating false reputation reports using unlawfully scraped social media data. The reports contained false warnings for 'sexual nudity' and 'dangerous political content'. Privacy group Noyb filed a complaint with the Lithuanian data protection authority, alleging violations of the GDPR. The complainants sought access to their data but received no response, and were later required to provide a qualified electronic signature to correct errors.

Company involved
Whitebridge AI

6 source articles · read the reporting →

WF-Y8JJVE1 Jul 2020

WeChat Pay Facial Recognition Bypassed by Scammers Using Animated GIFs

In July 2020, a woman in Hubei, China, reported that 20,000 yuan ($3,000) was stolen from her WeChat Pay account. Scammers had tricked her 8-year-old son into revealing her password, then used animated GIFs of her face to bypass the facial recognition security. Police arrested three suspects, and the case remains under investigation. The incident highlights vulnerabilities in facial recognition systems that can be fooled by simple animated images.

Company involved
WeChat
AI system involved
WeChat Pay facial recognition

1 source article · read the reporting →

WF-VD173U1 Jul 2024

Pensioner loses $224k to AI deepfake cryptocurrency scam featuring Prime Minister Luxon

A 72-year-old Taranaki grandmother lost $224,000 after being tricked by an AI-generated deepfake video of Prime Minister Christopher Luxon promoting cryptocurrency investment. The scammers used remote access software to transfer her savings and inheritance. TSB declined liability, stating the victim enabled the scam by granting remote access. Police are investigating.

Company involved
TSB

2 source articles · read the reporting →

WF-XHZEMH21 Nov 2020

Agricultural Bank of China apologises after 94-year-old lifted for facial recognition

A 94-year-old woman with limited mobility was lifted by relatives to complete facial recognition while activating her social security card at an Agricultural Bank of China branch in Guangshui, Hubei. A video of the incident circulated online and sparked criticism. The bank issued a statement apologising and saying the episode showed that its service awareness and publicity were inadequate.

Company involved
Agricultural Bank of China Guangshui Sub-branch

7 source articles · read the reporting →

← Newerpage 7 of 8Older →