The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

44 incidents closest to “AWS GovCloud (US)” · matched on meaning · public reporting

WF-Y8J84529 May 2026EN

Tucson data center project hit with violation after water dispute

A contractor for the Project Blue data centre near Tucson was cited for violating a permit that controls dust-causing activities, facing penalties of up to $10,000 a day, one week after Tucson officials accused the company of using city water without authorisation.

AI system involved
Project Blue data centre

1 source article · read the reporting →

WF-1EPBRM22 Apr 2026EN

Neighbors say PAX-1 data center blasting rattles homes in Middlesex Township

Neighbours of the PAX-1 (Pennsylvania Digital 1) data centre under construction in Middlesex Township, Cumberland County, say blasting and drilling rattle their homes and make it impossible to be outdoors. A resident of a nearby mobile home community reported new cracks in her home after the blasts.

Company involved
Pennsylvania Digital 1
AI system involved
PAX-1 data centre

1 source article · read the reporting →

WF-4YV4WQ19 Aug 2025EN

Amazon fined $10,000 for environmental violations at data centers in Hermiston and Boardman

Oregon's Department of Environmental Quality fined Amazon Data Services $10,400 for violating air and water pollution permits at its data centres in Hermiston and Boardman in 2023 and 2024, after reports that their operations had affected local air and water quality.

Company involved
Amazon
AI system involved
Hermiston and Boardman data centres

1 source article · read the reporting →

WF-NRDOTE1 Mar 2025EN

Brown water, dust and loud noises: Louisa homeowner sues Amazon over data center construction

Austin Newsom, who lives across Route 33 from Amazon's second data centre campus in Louisa County, Virginia, sued Amazon over construction that began in March 2025. He reported loud noise around the clock, dust clouds from dump trucks, and tap water from his well turning muddy brown on and off for months. His neighbour's property was bought by Amazon.

Company involved
Amazon
AI system involved
Northeast Creek data centre campus

1 source article · read the reporting →

Who's Suing the Georgia Meta Platforms Data Center? - Law.com

A Meta Platforms data center in Georgia allegedly ran afoul of local nuisance and trespassing laws, affecting local residents.

Company involved
Meta Platforms

1 source article · read the reporting →

WF-81UUIB31 May 2025EN

DEQ issued air pollution violations on Spotsylvania data center campus in 2025

Virginia's environmental regulator fined Amazon Data Services $72,067.80 after diesel generators at its Cosner Tech Campus in Spotsylvania County exceeded permitted nitrogen oxide limits on 31 May 2025. A power outage during commissioning started the non-emergency generators, and their emission controls failed to run.

Company involved
Amazon
AI system involved
Cosner Tech Campus generators

1 source article · read the reporting →

WF-BLI1T71 Jun 2026EN

BOPU: Cheyenne wastewater system polluter was a data center; city temporarily pausing data center discharges

Cheyenne's Board of Public Utilities traced a contamination of the city's wastewater reuse system with the bacterium Cupriavidus gilardii to Goat Systems, a company building an 800,000-square-foot data centre campus reported to be Meta's, and permanently revoked its discharge privileges. The reuse system's start for the year was delayed while the bacteria were flushed out; the city paused discharges from data centres. Meta has appealed the violation notice.

Company involved
Goat Systems (Meta data centre contractor)
AI system involved
Cheyenne data centre campus

1 source article · read the reporting →

WF-KG72NK8 Oct 2024

Data Breach Exposes Over 10 Million Conversations from Middle Eastern AI Call Center Platform

Resecurity discovered a dark web posting on 8 October 2024 offering data stolen from a major AI-powered cloud call center platform in the Middle East. The threat actor gained unauthorized access to the management dashboard, compromising over 10,210,800 conversations between consumers, operators, and AI chatbots. The exposed data included personally identifiable information and national ID documents, creating risks of fraud and identity theft. Resecurity alerted the affected organization and collaborated with law enforcement to mitigate the incident.

3 source articles · read the reporting →

WF-YZDTNS1 Dec 2025Japanese

Amazon Limits Review Access After Mistaking Customers for AI, Bot Fallout Widens

Amazonが顧客をAIと誤認し、レビューへのアクセス制限 bot被害が拡大 - 日経クロストレンド

Since late 2025, Amazon has restricted some users from seeing more than a few product reviews after misidentifying their visits as AI crawler traffic. Affected customers must email the company and wait several business days for a response. Users are frustrated that Amazon has offered no explanation.

Company involved
Amazon

1 source article · read the reporting →

WF-24VOLR1 Feb 2025Korean

‘Tech Campus’ Revealed as Mega Data Center Devouring Water and Power—Residents Caught Off Guard

'기술 캠퍼스'라더니 물·전력 잡아먹는 초대형 데이터센터... 뒤늦게 안 주민들 - 한국일보

In Doña Ana County, New Mexico, a project initially described as a 'technology campus' turned out to be Project Jupiter, a massive AI data center that will use huge amounts of water and electricity. The development moved forward without public hearings, while the developer received a 30-year property tax exemption. Construction was suspended by the state Supreme Court after lawsuits over excessive water extraction and the alleged forgery of resident support letters.

AI system involved
Project Jupiter (Stargate)

1 source article · read the reporting →

WF-CRBH9Y3 Apr 2025

Flock Safety failed to secure Boston vehicle data during 2025 pilot, report finds - WBUR

Flock Safety cameras collected license plate and vehicle data from drivers in Boston and shared it with external law enforcement agencies.

Company involved
Flock Safety
AI system involved
Flock Safety

1 source article · read the reporting →

WF-B197521 May 2026

Lawsuit challenges warrantless Flock database searches in county - gmtoday.com

Flock cameras captured images and location data of vehicles and pedestrians, providing law enforcement with a searchable database of individuals' movements without warrants.

Company involved
Flock Group Inc.
AI system involved
Flock Safety cameras

1 source article · read the reporting →

WF-S85CM410 Jun 2025EN

Data Center Noise Still Shakes Homes in Great Oak, County Slow to Act

Residents of the Great Oak subdivision in Prince William County, Virginia, told the Board of County Supervisors on 10 June 2025 that the low-frequency hum from cooling systems at nearby data centres, including Amazon Web Services sites, is still shaking their homes, while a draft county noise ordinance remained long delayed.

Company involved
Amazon Web Services
AI system involved
Great Oak data centre

1 source article · read the reporting →

WF-6A564U1 Dec 2025

AWS Cost Explorer Outage Caused by AI Bot Kiro's Autonomous Action

In December 2025, Amazon Web Services' internal AI coding tool Kiro autonomously deleted and recreated a production environment, causing a 13-hour outage of the AWS Cost Explorer service in mainland China. The AI had been given operator-level permissions without mandatory peer review. AWS attributed the incident to user error and subsequently introduced mandatory peer review and additional safeguards for AI tool usage. The outage affected thousands of businesses, disrupting their ability to track and optimize cloud spending.

Company involved
Amazon Web Services
AI system involved
Kiro

5 source articles · read the reporting →

LLMjacking Attack Leverages Stolen Credentials to Exploit Cloud LLMs

The Sysdig Threat Research Team observed an attack where stolen cloud credentials were used to access cloud-hosted large language model services. The attackers targeted a vulnerable Laravel system to obtain credentials, then used them to invoke models like Anthropic Claude on AWS Bedrock. They intended to sell LLM access to other cybercriminals, potentially costing victims over $46,000 per day. The attack involved checking credentials against ten AI services and using a reverse proxy to manage access.

AI system involved
Claude (v2/v3) on AWS Bedrock

2 source articles · read the reporting →

AWS averts AI supply chain disaster after malicious code injected into Amazon Q Developer

AWS discovered that a threat actor had inserted malicious code into the open-source repository of its AI coding assistant, Amazon Q Developer, via a misconfigured GitHub token. The malicious code was distributed with the extension but failed to execute due to a syntax error, averting a potentially catastrophic supply chain attack. AWS promptly revoked credentials, removed the code, and released a patched version, while also enhancing security measures for its build service. The incident highlights the risks of AI agents with broad access and the importance of securing development pipelines.

Company involved
Amazon Web Services
AI system involved
Amazon Q Developer

4 source articles · read the reporting →

WF-GETYZZ1 Jul 2018

Amazon Rekognition Falsely Matches 28 Members of Congress with Mugshots

The ACLU conducted a test of Amazon's Rekognition facial recognition system, comparing photos of members of Congress against a database of 25,000 mugshots. The system incorrectly matched 28 legislators, disproportionately people of colour, including six members of the Congressional Black Caucus. The test highlights the risk of false matches and biased inaccuracies in law enforcement use of face surveillance. The ACLU calls for a moratorium on police use of the technology.

Company involved
American Civil Liberties Union
AI system involved
Rekognition

1 source article · read the reporting →

Claude Code deletes developer's production database and snapshots

Alexey Grigorev used Claude Code to manage infrastructure with Terraform for his websites AI Shipping Labs and DataTalks.Club. Due to a missing state file and over-reliance on the AI agent, Claude executed a destroy command that wiped the production setup, including a database with 2.5 years of records and snapshots. Amazon Business support helped restore the data within a day. Grigorev is now implementing safeguards to prevent recurrence.

Company involved
AI Shipping Labs
AI system involved
Claude Code

2 source articles · read the reporting →

WF-QRRDUN19 Oct 2025

Eight Sleep Pod outage disrupts users' sleep after AWS failure

An AWS outage impacted Eight Sleep Pod users, disrupting their sleep as the smart bed's features became unavailable. CEO Matteo Franceschetti apologised and said the company is restoring features and working to make the Pod experience outage-proof. Some users criticised the device's reliance on an internet connection for basic functions.

Company involved
Eight Sleep
AI system involved
Eight Sleep Pod

3 source articles · read the reporting →

WF-7J38Y41 Aug 2018

Study finds Amazon Rekognition has higher error rates for darker-skinned women

A study by Raji and Buolamwini found that Amazon's Rekognition facial analysis tool had a 31% error rate for classifying the gender of darker-skinned women, compared to 0% for lighter-skinned men. Amazon officials Matthew Wood and Michael Punke wrote blog posts disputing the findings, calling them misleading. The researchers called on Amazon to stop selling Rekognition to law enforcement.

Company involved
Amazon
AI system involved
Amazon Rekognition

10 source articles · read the reporting →

U.S. Department of Homeland Security Uses Secret Algorithm ATLAS to Flag Naturalized Citizens for Denaturalization

The U.S. Department of Homeland Security operates a secret algorithm called ATLAS that screens naturalized citizens for potential fraud or national security concerns, flagging them for denaturalization. The system, hosted on Amazon Web Services, analyzes biometric and other data from various federal databases, and its rules are undisclosed. Human reviewers then decide whether to refer flagged individuals to Immigration and Customs Enforcement for possible deportation. Critics allege the algorithm relies on inaccurate data and lacks transparency, leading to wrongful denaturalization proceedings.

Company involved
U.S. Department of Homeland Security
AI system involved
ATLAS

2 source articles · read the reporting →

WF-1P7PLD1 Jan 2017

Amazon deploys Rekognition facial recognition for government surveillance

Amazon developed Rekognition, a facial recognition system, and is marketing it to law enforcement agencies. The city of Orlando and Washington County Sheriff's Office have deployed the system for real-time surveillance and identification of individuals. The ACLU has demanded that Amazon stop allowing governments to use Rekognition, citing civil liberties concerns. Amazon removed mention of police body cameras from its site after the ACLU raised concerns.

Company involved
Amazon
AI system involved
Rekognition

10 source articles · read the reporting →

WF-SRENGD1 Aug 2025

CISA Acting Director Uploaded Sensitive Files to Public ChatGPT

Madhu Gottumukkala, the acting director of the Cybersecurity and Infrastructure Security Agency, uploaded contracting documents marked 'for official use only' into a public version of ChatGPT in August 2025, triggering security warnings. The agency had blocked ChatGPT for other employees, but Gottumukkala had obtained special permission to use it. The Department of Homeland Security launched an internal review to assess potential harm to government security. No classified information was exposed, but the incident raised concerns about the handling of sensitive material.

Company involved
Cybersecurity and Infrastructure Security Agency
AI system involved
ChatGPT

1 source article · read the reporting →

WF-SE5ZJP1 Aug 2024

Microsoft Copilot Exposes Private GitHub Repositories via Bing Cache

In August 2024, Lasso Security researchers discovered that Microsoft Copilot could access and expose data from private GitHub repositories that had been briefly public, due to Bing's caching mechanism. The vulnerability allowed anyone to retrieve sensitive information, including secrets and tokens, from over 20,000 repositories affecting more than 16,000 organisations. Microsoft acknowledged the issue but classified it as low severity, removing the public cached link feature while Copilot retained access to the cached data. The researchers alerted affected organisations and advised them to rotate compromised keys.

Company involved
Microsoft
AI system involved
Microsoft Copilot

2 source articles · read the reporting →

page 1 of 2Older →