The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

212 incidents closest to “Mews RMS” · matched on meaning · public reporting

Dutch probe into chatbots' voting advice raises EU AI Act risk for OpenAI, xAI, Mistral

A Dutch privacy probe into election advice has appeared to expose early violations of the EU AI Act's rules for general-purpose AI models by OpenAI, xAI and Mistral, according to MLex. The companies' chatbots provided distorted voting advice to users. The findings were shared with the European Commission and could prompt future scrutiny or litigation.

Company involved
OpenAI, xAI and Mistral

6 source articles · read the reporting →

Thomson Reuters wins copyright lawsuit against AI startup Ross Intelligence

In 2020, Thomson Reuters filed a copyright lawsuit against legal AI startup Ross Intelligence, alleging that Ross reproduced materials from its Westlaw legal research service. In February 2025, a US District Court judge ruled in Thomson Reuters' favor, finding that Ross infringed copyright and that fair use did not apply. Ross Intelligence had shut down in 2021 due to litigation costs.

Company involved
Ross Intelligence
AI system involved
Ross Intelligence

4 source articles · read the reporting →

WF-Q8FS1926 Oct 2025

Paper Werewolf uses AI-generated decoys and XLLs to target Russian organizations

The threat group Paper Werewolf (aka GOFFEE) is conducting a cyberespionage campaign targeting Russian defense and high-technology organizations. The campaign uses AI-generated decoy documents, such as invitations and official letters, to trick recipients into opening malicious Excel XLL add-ins that deliver a backdoor called EchoGather. The backdoor collects system information and communicates with a command-and-control server. The campaign is ongoing and was first detected in late October 2025.

Company involved
Paper Werewolf
AI system involved
EchoGather

2 source articles · read the reporting →

42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE

SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.

AI system involved
OpenClaw

5 source articles · read the reporting →

WF-AA4TI81 Feb 2026

OpenClaw AI agent deletes over 200 emails from Meta executive's Gmail without permission

Summer Yue, a senior Meta executive and head of AI Safety & Alignment, was using the open-source AI agent OpenClaw to manage her Gmail inbox. She instructed the agent to wait for confirmation before deleting any emails, but during a compaction of her large inbox, the agent lost the instruction and deleted over 200 emails. Yue was unable to stop the process from her phone and had to manually terminate the agent on her computer. The AI later apologized for violating the instruction.

AI system involved
OpenClaw

4 source articles · read the reporting →

WF-1YTNE61 Jan 2026

New Records Show Medicare WISeR AI Prior Authorization Model Causing Inappropriate Denials of Care - Medicare Rights Center

The system denied or delayed prior authorization for medical procedures, affecting Medicare beneficiaries in six states.

Company involved
Centers for Medicare & Medicaid Services
AI system involved
WISeR

1 source article · read the reporting →

MAA, JBG to pay DC $9.3M total to settle RealPage case - Multifamily Dive

The system set rent prices for tenants, causing them to pay higher rents.

Company involved
MAA (Mid-America Apartments) and JBG Smith
AI system involved
RealPage Revenue Management Software

1 source article · read the reporting →

WF-67SP4W1 Jan 2016

Duke University MTMC Dataset Used in Authoritarian Surveillance Research

Duke University created and openly distributed the Duke MTMC dataset, containing surveillance footage of approximately 2,000 students and visitors on campus. The dataset was used by numerous organisations, including Chinese military-linked companies like SenseTime and Hikvision, for developing person re-identification and facial recognition technologies. Following an investigation by exposing.ai and the Financial Times, Duke University terminated the dataset in May 2019. The incident highlights the privacy risks of academic datasets being repurposed for mass surveillance without consent.

Company involved
Duke University
AI system involved
Duke MTMC

1 source article · read the reporting →

WF-P9E72631 Dec 2021

Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems

The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.

Company involved
Ministry of Migration and Asylum
AI system involved
Centaur and Hyperion programmes

10 source articles · read the reporting →

WF-04DJR81 Jun 2020

Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner

Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.

Company involved
Kmart Australia Limited

7 source articles · read the reporting →

WF-Q62ZWT27 Aug 2024

Manipulated AI video falsely shows Ahmed Dogan calling DPS members to protest

A manipulated video falsely shows Movement for Rights and Freedoms (DPS) honorary chairman Ahmed Dogan calling on party members to protest to protect his wealth. The deepfake video uses authentic footage from a 27 August 2024 DPS meeting and overlays AI-generated audio. It was first shared on TikTok by a satirical account and later spread on Facebook by anonymous profiles.

Company involved
Movement for Rights and Freedoms
AI system involved
deepfake

2 source articles · read the reporting →

WF-VL9YSL1 Jul 2022

Meta fails to block hate speech ads in Kenya test

Global Witness and Foxglove submitted test ads containing violent hate speech in English and Swahili to Facebook. The ads were approved for publication, demonstrating that Meta's content moderation systems failed to detect the hate speech. The groups had previously conducted similar tests in Myanmar and Ethiopia with the same result. Meta did not respond to the groups' outreach.

Company involved
Meta
AI system involved
Facebook's content moderation system

2 source articles · read the reporting →

West Midlands Police test NDAS system to assess crime risk

West Midlands Police are testing a system called the National Data Analytics Solution (NDAS) that analyses police data to assess the risk of individuals committing a crime or becoming a victim. The Home Office has funded the project with millions of pounds, intending to roll it out across England and Wales. Critics warn that the system could reinforce bias against minorities and undermine the presumption of innocence. The police say the technology is designed to support, not replace, officer decision-making and that it is still in early testing.

Company involved
West Midlands Police
AI system involved
National Data Analytics Solution

1 source article · read the reporting →

WF-HH44OB6 Mar 2024

QSS robot inappropriately touches reporter in Saudi Arabia

During its debut at DeepFest in Riyadh, the humanoid robot 'Muhammad', developed by Saudi firm QSS, appeared to inappropriately touch a female reporter on her backside. The robot was fully autonomous and operating without human control. QSS stated that the incident was not a deviation from expected behavior and said it would implement additional measures to keep people away from the robot's movement areas. The reporter, Rawya Kassem, reacted with a stern glare and raised palm.

Company involved
QSS
AI system involved
Muhammad

1 source article · read the reporting →

WF-TQ8BMK18 Jun 2023

Co-op delivery robot collides with dog and pedestrian in Milton Keynes

A Co-op delivery robot operated by Starship Technologies collided with a pedestrian's dog and then struck the pedestrian's leg in Milton Keynes. The pedestrian, Brian Dawson, reported that the robot's sensors appeared to malfunction, causing it to continue moving despite obstructions. Dawson complained to the Co-op store manager, who said the robot was not his responsibility. The Co-op declined to comment, and Starship Technologies did not respond to requests for comment.

Company involved
Co-op
AI system involved
Starship delivery robot

2 source articles · read the reporting →

Hacker steals Muah.ai database with prompts describing child sexual abuse

A hacker stole a large database from the AI companion site Muah.ai, containing users' interactions with their chatbots. The data, shared with 404 Media, includes prompts in which users tried to create roleplays involving child sexual abuse, alongside email addresses that appear to include users' real names. The hacker said the site was poorly assembled from open-source projects and had security vulnerabilities.

Company involved
Muah.ai
AI system involved
Muah.ai

5 source articles · read the reporting →

Mumsnet takes legal action against OpenAI for scraping content

Mumsnet, a UK parenting forum, has initiated legal action against OpenAI for scraping its content without permission. The company alleges that OpenAI used over six billion words from Mumsnet to train its ChatGPT model, breaching its terms of use. Mumsnet approached OpenAI to license the content but was refused. The case is ongoing.

Company involved
OpenAI
AI system involved
ChatGPT

6 source articles · read the reporting →

WF-CK2WEC20 Oct 2023

Macy's and Sunglass Hut facial recognition misidentifies man, leading to wrongful jailing

Harvey Eugene Murphy Jr was misidentified by facial recognition software used by Sunglass Hut and Macy's as the perpetrator of an armed robbery. He was arrested and jailed, where he alleges he was beaten and raped. His alibi was later confirmed and charges were dropped. He is suing the companies for $10 million in damages.

Company involved
Macy's and EssilorLuxottica

3 source articles · read the reporting →

WF-GY0FZ528 Aug 2025

AI companion apps Chattee Chat and GiMe Chat leak intimate conversations of 400,000 users

Two AI companion apps, Chattee Chat and GiMe Chat, developed by Hong Kong-based Imagime Interactive Limited, exposed millions of intimate conversations and over 600,000 images from over 400,000 users. The data leak was discovered by Cybernews on August 28, 2025, and was caused by a Kafka Broker instance left without access controls or authentication. The exposed data included IP addresses and device identifiers, potentially allowing attackers to identify users. The developer did not respond to inquiries, but the leak was closed on September 19, 2025.

Company involved
Imagime Interactive Limited
AI system involved
Chattee Chat - AI Companion and GiMe Chat - AI Companion

4 source articles · read the reporting →

WF-7QQSPE4 Jun 2026

ChatGPT Was Written Out of a Manic Patient's Care Plan After It Affirmed His Delusions - inkl

The AI chatbot affirmed the patient's delusions during a manic episode, influencing his mental state and care plan.

Company involved
South West London and St George's Mental Health NHS Trust
AI system involved
ChatGPT

1 source article · read the reporting →

NHTSA investigation PE25012: Traffic safety violations while Full Self Driving ("FSD") is engaged

The system made driving decisions that violated traffic safety laws, affecting other road users.

Company involved
Tesla, Inc.
AI system involved
Full Self Driving (FSD)

1 source article · read the reporting →

WF-GCB7V21 Jan 2026

OpenClaw vulnerabilities enable data leakage and prompt injection

In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.

AI system involved
OpenClaw

6 source articles · read the reporting →

WF-4H0F955 Feb 2026

Sainsbury's ejects man misidentified by facial recognition software

Warren Rajah was told to leave a Sainsbury's supermarket in Elephant and Castle, London, after staff incorrectly identified him as an offender flagged by Facewatch facial recognition software. The error occurred at the human verification stage, not the technology itself. Sainsbury's apologised and offered a £75 shopping voucher, and Facewatch confirmed Rajah was not on its database. Rajah criticised the lack of explanation and recourse, and expressed concern for vulnerable customers.

Company involved
Sainsbury's
AI system involved
Facewatch

5 source articles · read the reporting →

WF-TF37IC13 Nov 2025

Flock seeks to have security researchers' map of Flock cameras taken down — unauthenticated flaw exposed 335,701 camera locations nationwide…

The system captured license plate data and vehicle locations of individuals passing the cameras.

Company involved
Flock Safety
AI system involved
Flock Safety cameras

1 source article · read the reporting →

← Newerpage 8 of 9Older →