US Secret Service bought access to cellphone location data
The US Secret Service signed a contract to access Locate X, a service that aggregates location data from phone apps and allows law enforcement to track devices without a warrant. The contract with Babel Street was worth about $36,000 and ran from 2017 to 2018. A former employee said the Secret Service used Locate X in 2018 to seize illegal credit card skimmers at petrol stations. Lawmakers and civil liberties advocates criticised the practice, and Senator Ron Wyden introduced a bill to ban such purchases.
- Company involved
- United States Secret Service
- AI system involved
- Locate X
1 source article · read the reporting →
Labor unions sue Trump administration over AI social media surveillance
Three labor unions (UAW, CWA, AFT) filed a lawsuit against the U.S. Departments of State and Homeland Security, alleging the Trump administration created a mass surveillance program using AI and automated technologies to monitor the social media accounts of visa holders and lawful permanent residents. The program is accused of targeting constitutionally protected speech based on viewpoint, causing a chilling effect where union members reported refraining from posting, deleting content, and altering offline union activities. The lawsuit, represented by EFF, Muslim Advocates, and MFIA, argues the program violates the First Amendment and the Administrative Procedure Act.
- Company involved
- U.S. Department of State
- AI system involved
- Catch and Revoke
9 source articles · read the reporting →
France uses AI to monitor mask-wearing on public transport
France has deployed AI software from startup DatakaLab in the Paris metro to check if passengers are wearing face masks. The system generates anonymous statistics on mask compliance to help authorities anticipate COVID-19 outbreaks, and the company states it does not identify or punish individuals. The trial is part of measures making masks mandatory on public transport, with fines considered for non-compliance. Privacy advocates have raised concerns about the spread of AI surveillance during the pandemic.
1 source article · read the reporting →
California AG declares out-of-state ALPR data sharing unlawful
California Attorney General Rob Bonta issued guidance confirming that sharing automated license plate reader (ALPR) data with out-of-state or federal agencies violates state law SB 34. The decision follows years of advocacy by EFF and the ACLU, who demonstrated through public records that many California law enforcement agencies were sharing data with hundreds of external agencies, including ICE and CBP. The guidance mandates that all California agencies review their data sharing and cut off access to out-of-state and federal entities.
- Company involved
- California law enforcement agencies
- AI system involved
- Automated license plate readers (ALPRs)
1 source article · read the reporting →
Arizona Unemployment Applicants Required to Submit Facial Recognition
People applying for unemployment benefits in Arizona must verify their identity via facial recognition software provided by ID.me. If the system fails to match a selfie to a photo ID, applicants can be denied benefits unless they successfully complete a video chat with a referee. A class-action lawsuit filed in June 2021 alleges that the practice violates due process rights and discriminates against people of colour.
- Company involved
- Arizona Department of Economic Security
- AI system involved
- ID.me
1 source article · read the reporting →
Clearview AI settles with ACLU over facial recognition database sales
Clearview AI has agreed to stop selling its facial recognition database to most private US companies as part of a proposed settlement with the ACLU. The company scraped billions of images from social media without consent to build its database, violating Illinois' Biometric Information Privacy Act. The settlement requires Clearview to delete old facial vectors and allow Illinois residents to opt out. The company can still sell its technology to law enforcement and government agencies.
- Company involved
- Clearview AI
- AI system involved
- Clearview AI facial recognition database
8 source articles · read the reporting →
Steak 'n Shake sued over facial recognition kiosks under BIPA
A class action lawsuit alleges that Steak 'n Shake illegally collects facial biometrics from customers using PopID-powered self-ordering kiosks without proper consent. Plaintiff Michael Massel claims the restaurant chain failed to provide notice and obtain written consent as required by Illinois' Biometric Information Privacy Act (BIPA). The suit seeks damages of up to $5,000 per violation for anyone whose biometric data was collected in Illinois in the past five years.
- Company involved
- Steak 'n Shake
- AI system involved
- PopID biometric kiosks
6 source articles · read the reporting →
ICE Agents Stored Photos and License Plates of Protest Observers in Palantir-Built Database, Court Filing Reveals - Latin Times
A court filing alleges ICE agents stored photos and license plates of protest observers in a Palantir-built database, labeled some of them as threats, and ran facial recognition searches on them.
- Company involved
- U.S. Immigration and Customs Enforcement (ICE)
- AI system involved
- ICM (Investigative Case Management system)
1 source article · read the reporting →
OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →
AI chatbots recommended unlicensed casinos to UK users
An investigation by the Guardian and Investigate Europe found that five major AI chatbots—ChatGPT, Gemini, Grok, Microsoft Copilot, and Meta AI—recommended unlicensed online casinos to UK users. Some chatbots also advised on bypassing consumer protection systems like GamStop and financial checks. The companies acknowledged the findings and said they are reviewing safeguards. Regulators expressed concern about the potential harm to vulnerable users.
- Company involved
- Multiple technology companies (Microsoft, Google, Meta, OpenAI, X)
- AI system involved
- Copilot, Gemini, Meta AI, ChatGPT, Grok
5 source articles · read the reporting →
Woman Blindly Trusts Driver Assistance, Rear-Ends Lane-Changing Bus on Highway
女子轻信辅助驾驶放任不管 高速上直接追尾变道大巴车 - 驱动之家
On August 28, on the Shanghai-Kunming Expressway, a woman driving an SUV with driver assistance engaged rear-ended a bus that suddenly changed lanes. She assumed the system would brake automatically and took no action. The bus driver was found at fault for the lane change, but police warned against over-reliance on driver assistance.
1 source article · read the reporting →
$30M Equifax hard inquiry dispute class action settlement - Top Class Actions
A class action, settled for $30 million, alleged that Equifax automatically rejected consumers' disputes of hard inquiries on their credit reports, sending a form letter instead of investigating.
- Company involved
- Equifax Information Services LLC
1 source article · read the reporting →
Italian bank (Fideuram / Intesa Sanpaolo) loses about 95 million euro to AI voice-clone scam
The AI-generated voice deceived the chairman into authorizing transfers of about 95 million euros.
1 source article · read the reporting →
Spanish data regulator orders Worldcoin to stop processing biometric data in Spain
The Spanish Data Protection Agency (AEPD) has ordered a precautionary measure against Tools for Humanity Corporation, the company behind Worldcoin, to cease collection and processing of personal data in Spain. The AEPD received complaints alleging insufficient information, collection of data from minors, and inability to withdraw consent. The regulator acted under GDPR Article 66.1 to prevent potentially irreparable harm to individuals' data protection rights.
- Company involved
- Tools for Humanity Corporation
- AI system involved
- Worldcoin
8 source articles · read the reporting →
Portuguese regulator suspends Worldcoin's biometric data collection
Portugal's data protection authority, CNPD, has ordered Worldcoin Foundation to suspend collection of iris, eye and facial biometric data in Portugal for 90 days. The regulator acted after receiving dozens of complaints about the collection of minors' data without parental consent, as well as deficiencies in the information provided to data subjects. More than 300,000 people in Portugal had reportedly provided their biometric data to Worldcoin in exchange for cryptocurrency tokens. The CNPD said the risk to fundamental rights was high and the measure was needed to prevent serious or irreparable harm.
- Company involved
- Worldcoin Foundation
- AI system involved
- Orb
5 source articles · read the reporting →
Airbnb bans users in Australia using trustworthiness algorithm
Airbnb is accused of using an algorithm acquired from Trooly to score users' trustworthiness based on publicly available data, including social media and occupation. Several users in Australia, including a real estate worker and sex workers, report being banned from the platform without explanation or meaningful appeal. The company has not clarified how the algorithm is applied in Australia, and experts have raised concerns about discrimination and lack of transparency.
- Company involved
- Airbnb
- AI system involved
- Trooly
4 source articles · read the reporting →
DFFH breaches privacy by using ChatGPT in child protection report
A child protection worker at the Department of Families, Fairness and Housing (DFFH) used ChatGPT to draft a Protection Application Report for the Children’s Court, entering sensitive personal information about a child. The generated content contained inaccuracies that downplayed risks to the child, and the information was disclosed to OpenAI overseas. An investigation by the Office of the Victorian Information Commissioner found DFFH failed to ensure accuracy and protect personal information, contravening IPPs 3.1 and 4.1. DFFH accepted the findings and must now block the use of ChatGPT by child protection workers under a compliance notice.
- Company involved
- Department of Families, Fairness and Housing
- AI system involved
- ChatGPT
9 source articles · read the reporting →
Solicitors Regulation Authority Ltd v Abhishek Kumar (Solicitors Disciplinary Tribunal): AI-hallucinated content in court filing, Counsel struck off the Register…
AI-generated false legal citations were submitted to the Solicitors Disciplinary Tribunal, misleading the tribunal and the regulator.
1 source article · read the reporting →
Indore Play School Owner Loses Savings in AI Voice Cloning Fraud
A middle-aged woman in Indore, India, lost her entire savings of Rs 97,500 after a fraudster used AI voice cloning to impersonate her cousin, a police officer. The caller claimed a friend needed urgent cardiac surgery and requested money transfers via QR codes. The victim's teenage daughter made four transactions before they realised the money had not been credited. Police are investigating the incident as the first AI-driven voice cloning fraud in Madhya Pradesh.
3 source articles · read the reporting →
Whitebridge AI faces complaint over false reputation reports
Whitebridge AI, a Lithuanian company, is accused of generating false reputation reports using unlawfully scraped social media data. The reports contained false warnings for 'sexual nudity' and 'dangerous political content'. Privacy group Noyb filed a complaint with the Lithuanian data protection authority, alleging violations of the GDPR. The complainants sought access to their data but received no response, and were later required to provide a qualified electronic signature to correct errors.
- Company involved
- Whitebridge AI
6 source articles · read the reporting →
WeChat Pay Facial Recognition Bypassed by Scammers Using Animated GIFs
In July 2020, a woman in Hubei, China, reported that 20,000 yuan ($3,000) was stolen from her WeChat Pay account. Scammers had tricked her 8-year-old son into revealing her password, then used animated GIFs of her face to bypass the facial recognition security. Police arrested three suspects, and the case remains under investigation. The incident highlights vulnerabilities in facial recognition systems that can be fooled by simple animated images.
- Company involved
- WeChat
- AI system involved
- WeChat Pay facial recognition
1 source article · read the reporting →
Pensioner loses $224k to AI deepfake cryptocurrency scam featuring Prime Minister Luxon
A 72-year-old Taranaki grandmother lost $224,000 after being tricked by an AI-generated deepfake video of Prime Minister Christopher Luxon promoting cryptocurrency investment. The scammers used remote access software to transfer her savings and inheritance. TSB declined liability, stating the victim enabled the scam by granting remote access. Police are investigating.
- Company involved
- TSB
2 source articles · read the reporting →
Agricultural Bank of China apologises after 94-year-old lifted for facial recognition
A 94-year-old woman with limited mobility was lifted by relatives to complete facial recognition while activating her social security card at an Agricultural Bank of China branch in Guangshui, Hubei. A video of the incident circulated online and sparked criticism. The bank issued a statement apologising and saying the episode showed that its service awareness and publicity were inadequate.
- Company involved
- Agricultural Bank of China Guangshui Sub-branch
7 source articles · read the reporting →
Dutch Tax Authority discriminated against dual nationality applicants for child care benefits using automated risk system.
The Dutch Data Protection Authority (AP) found that the Benefits Department of the Tax and Customs Administration (Belastingdienst) unlawfully processed the dual nationality of 1.4 million applicants for child care benefits. The data was used as an indicator in an automated risk-scoring system that flagged applications as high-risk, which was unnecessary and discriminatory. The AP concluded that the processing violated the GDPR and was discriminatory. The AP completed its fact-finding and will consider imposing a sanction.
- Company involved
- Belastingdienst
10 source articles · read the reporting →