The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

214 incidents closest to “Rekor Systems” · matched on meaning · public reporting

Audit of RisCanvi finds biases and reliability issues in criminal justice system

Eticas conducted an adversarial audit of RisCanvi, an AI risk assessment tool used in Catalonia's criminal justice system. The audit uncovered biases in risk classifications against specific demographics and significant reliability issues. The findings call for fairer practices in criminal justice AI.

Company involved
Catalonia's criminal justice system
AI system involved
RisCanvi

4 source articles · read the reporting →

Outabox hack exposes biometric data of patrons at bars, clubs and casinos

Hackers claiming to be former employees published a website allowing searches of Outabox's facial recognition database, exposing biometric and other sensitive data of patrons used for age verification at bars, clubs and casinos. The Surveillance Technology Oversight Project warns that the breach demonstrates the danger of facial recognition for age verification. S.T.O.P. has launched a campaign to ban facial recognition in public accommodations.

Company involved
Outabox

8 source articles · read the reporting →

Thomson Reuters wins copyright lawsuit against AI startup Ross Intelligence

In 2020, Thomson Reuters filed a copyright lawsuit against legal AI startup Ross Intelligence, alleging that Ross reproduced materials from its Westlaw legal research service. In February 2025, a US District Court judge ruled in Thomson Reuters' favor, finding that Ross infringed copyright and that fair use did not apply. Ross Intelligence had shut down in 2021 due to litigation costs.

Company involved
Ross Intelligence
AI system involved
Ross Intelligence

4 source articles · read the reporting →

WF-1UJHJB1 Jan 2019

Tennessee's TennCare Connect algorithm illegally denied thousands Medicaid benefits

A U.S. District Court judge ruled that Tennessee's TennCare Connect system, built by Deloitte for over $400 million, illegally denied thousands of low-income residents and people with disabilities Medicaid and disability benefits due to programming and data errors. The system automatically terminated coverage without properly considering eligibility for all available programs. A class action lawsuit filed in 2020 resulted in the ruling.

Company involved
TennCare (Tennessee Medicaid)
AI system involved
TennCare Connect

10 source articles · read the reporting →

Publishers sue AI startup Cohere over alleged copyright infringement

A consortium of 14 publishers including Condé Nast, The Atlantic, and Forbes filed a lawsuit against Cohere, alleging that the generative AI startup engaged in massive, systematic copyright infringement by using at least 4,000 copyrighted works to train its AI models and display large portions of articles, harming referral traffic. Cohere denied the allegations, calling the lawsuit misguided and frivolous.

Company involved
Cohere
AI system involved
Cohere's AI models

8 source articles · read the reporting →

WF-15KEYQ1 Apr 2023

Deloitte software glitches wrongly remove Texans from Medicaid

Advocacy groups filed a complaint with the Federal Trade Commission alleging that Deloitte's eligibility software, TIERS, used by Texas Medicaid, wrongly disenrolled qualified recipients due to glitches. Nearly 1.8 million Texans lost coverage after the pandemic pause ended, with many errors attributed to procedural issues but some linked to system malfunctions. Deloitte denies the claims, while the state says it restored care for at least 90,000 people. The FTC has not yet responded to the complaint.

Company involved
Texas Health and Human Services Commission
AI system involved
TIERS

6 source articles · read the reporting →

WF-OP475C1 Jan 2018

Dutch probation service's OXREC algorithm flawed, leading to incorrect recidivism risk assessments

The Dutch Inspectorate of Justice and Security (Inspectie JenV) published a report finding that the probation service's (Reclassering) OXREC algorithm contains serious flaws, including swapped formulas and incorrect numbers, causing about a quarter of risk assessments to be wrong. The algorithm, used since 2018 for about 44,000 cases per year, also uses variables that can lead to discrimination, such as neighborhood score and income. The Inspectorate recommended immediate correction or temporary suspension. The probation service announced it would temporarily stop using OXREC.

Company involved
Reclassering Nederland
AI system involved
OXREC

4 source articles · read the reporting →

42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE

SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.

AI system involved
OpenClaw

5 source articles · read the reporting →

WF-4NBY2U13 May 2024

NHTSA investigation PE24016: Unexpected ADS behavior

Waymo's automated driving system exhibited unexpected behavior during driving.

Company involved
Waymo

1 source article · read the reporting →

Samsung settles Texas lawsuit over ACR data collection on smart TVs

Samsung has settled a lawsuit with the Texas Attorney General over its Automated Content Recognition (ACR) system on smart TVs. The system collected viewing data from users without informed consent. As part of the settlement, Samsung agreed to stop collecting ACR data from Texans without explicit consent and to rewrite its privacy prompts. Samsung also faces a federal class action in New York over similar allegations.

Company involved
Samsung
AI system involved
Automated Content Recognition (ACR)

7 source articles · read the reporting →

WF-1YTNE61 Jan 2026

New Records Show Medicare WISeR AI Prior Authorization Model Causing Inappropriate Denials of Care - Medicare Rights Center

The system denied or delayed prior authorization for medical procedures, affecting Medicare beneficiaries in six states.

Company involved
Centers for Medicare & Medicaid Services
AI system involved
WISeR

1 source article · read the reporting →

WF-2LAYJ824 Apr 2019

Buenos Aires city government uses live facial recognition to track minors in criminal database

The Buenos Aires city government deployed a live facial recognition system in April 2019 that scans subway passengers and matches them against CONARC, a national database of alleged offenders. Human Rights Watch found that the database includes at least 166 children, some as young as one to three years old, and that the system has led to numerous false arrests. The system was implemented without public consultation, and there is no mechanism to correct mistakes. A civil rights organization filed a lawsuit, and the government is pushing a bill to legalize the technology.

Company involved
Buenos Aires city government

1 source article · read the reporting →

Bahia Facial Recognition System Misidentifies Black Man as Wanted Criminal

Davi, a black administrative assistant, was tracked across 15 metro stations and approached by police after Bahia's facial recognition system falsely matched him to a wanted person. He was released after officers verified his identity. The system, supplied by Iecisa and Huawei, has a low accuracy rate and disproportionately affects black people. The government plans to expand it despite concerns over racial bias and errors.

Company involved
Secretaria de Segurança Pública da Bahia

2 source articles · read the reporting →

Manchester City to Trial Facial Recognition at Etihad Stadium

Manchester City are set to trial facial recognition software supplied by Blink Identity at the Etihad Stadium. The system would scan fans' faces to check whether they have bought tickets and allow entry, with the aim of reducing matchday queues. Fans would need to sign up using a picture of their face. The article notes concerns about the potential security of users, but the club and vendor say they are committed to protecting fans.

Company involved
Manchester City

1 source article · read the reporting →

WF-04DJR81 Jun 2020

Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner

Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.

Company involved
Kmart Australia Limited

7 source articles · read the reporting →

WF-IWL4TH1 Jan 2018

US Secret Service bought access to cellphone location data

The US Secret Service signed a contract to access Locate X, a service that aggregates location data from phone apps and allows law enforcement to track devices without a warrant. The contract with Babel Street was worth about $36,000 and ran from 2017 to 2018. A former employee said the Secret Service used Locate X in 2018 to seize illegal credit card skimmers at petrol stations. Lawmakers and civil liberties advocates criticised the practice, and Senator Ron Wyden introduced a bill to ban such purchases.

Company involved
United States Secret Service
AI system involved
Locate X

1 source article · read the reporting →

WF-452L9H1 Jan 2024

Steak 'n Shake sued over facial recognition kiosks under BIPA

A class action lawsuit alleges that Steak 'n Shake illegally collects facial biometrics from customers using PopID-powered self-ordering kiosks without proper consent. Plaintiff Michael Massel claims the restaurant chain failed to provide notice and obtain written consent as required by Illinois' Biometric Information Privacy Act (BIPA). The suit seeks damages of up to $5,000 per violation for anyone whose biometric data was collected in Illinois in the past five years.

Company involved
Steak 'n Shake
AI system involved
PopID biometric kiosks

6 source articles · read the reporting →

WF-CK2WEC20 Oct 2023

Macy's and Sunglass Hut facial recognition misidentifies man, leading to wrongful jailing

Harvey Eugene Murphy Jr was misidentified by facial recognition software used by Sunglass Hut and Macy's as the perpetrator of an armed robbery. He was arrested and jailed, where he alleges he was beaten and raped. His alibi was later confirmed and charges were dropped. He is suing the companies for $10 million in damages.

Company involved
Macy's and EssilorLuxottica

3 source articles · read the reporting →

NHTSA investigation PE25012: Traffic safety violations while Full Self Driving ("FSD") is engaged

The system made driving decisions that violated traffic safety laws, affecting other road users.

Company involved
Tesla, Inc.
AI system involved
Full Self Driving (FSD)

1 source article · read the reporting →

WF-GCB7V21 Jan 2026

OpenClaw vulnerabilities enable data leakage and prompt injection

In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.

AI system involved
OpenClaw

6 source articles · read the reporting →

WF-74CS0825 Nov 2025

Thailand halts iris-scan crypto scheme and deletes 1.2m biometric records

The Ministry of Digital Economy and Society (DES) and the Personal Data Protection Committee (PDPC) ordered a company to stop collecting iris data and delete 1.2 million citizen records. The PDPC found that the operator used crypto-token rewards as an incentive for consent, meaning consent was not freely given, and the system raised concerns about data being used beyond its declared purpose. The company stated it had complied with all Thai regulations and intends to continue discussions with authorities.

Company involved
The company behind the iris-scan system (not named)
AI system involved
Iris-scan system

4 source articles · read the reporting →

WF-WWQVJ130 Sep 2026

Two Florida deputies arrested for Flock, ALPR abuse after TCPalm query - Yahoo

The Flock ALPR system was used by deputies to track the locations of a woman and a teenage girl for personal, non-law-enforcement purposes.

Company involved
Pinellas County Sheriff's Office
AI system involved
Flock Safety ALPR

1 source article · read the reporting →

Hackers Extract Encryption Keys from Flock Surveillance Cameras, Revealing Person Detection Alongside Vehicle Tracking - finance.biggo.com

The system detected and recorded images of vehicles and people, affecting individuals in public spaces.

Company involved
Flock Safety
AI system involved
Flock Safety ALPR cameras

1 source article · read the reporting →

New Meta smart glasses class action gives employers a reason to write the policy they've been puttin - hcamag.com

The smart glasses recorded bystanders without their consent and sent the footage to Meta for AI training.

Company involved
Meta Platforms
AI system involved
Meta AI-enabled Ray-Ban and Oakley smart glasses

1 source article · read the reporting →

← Newerpage 8 of 9Older →