The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

44 incidents closest to “D2L Lumi” · matched on meaning · public reporting

WF-YHDO6D15 Sep 2026ZH-CN

OpenAI's internal Project Lily exposed: Human review of ChatGPT user chat logs

OpenAI内部Lily项目曝光:人工审核ChatGPT用户聊天记录 - 新浪财经

A report by 404 Media revealed that OpenAI uses human reviewers, called prompt reviewers, to assess anonymized ChatGPT conversations under an internal project named Project Lily. Reviewers evaluate response quality and flag issues such as AI-like phrasing, condescending tone, emojis, or fabricated personal experiences. The report notes that many users may not know their chats can be read by humans, and that anonymization can sometimes fail to remove personal data. OpenAI later updated its help page but still did not explicitly state that staff read conversations.

Company involved
OpenAI
AI system involved
ChatGPT

1 source article · read the reporting →

WF-7Q32UP6 Sep 2026Italian

Unimore Racing driverless car collision at Imola

Unimore Racing, scontro in pista per l’auto senza pilota a Imola - Gazzetta di Modena

At Imola's Enzo e Dino Ferrari circuit, the driverless cars of Unimore Racing and Politecnico di Milano battled for the lead in the autonomous racing championship. With two laps remaining, the two cars, running first and second, collided, forcing both to retire.

Company involved
Unimore Racing and PoliMOVE

1 source article · read the reporting →

LAION's AI training dataset found to contain private medical photos without consent

An AI artist discovered her private medical photos from 2013 in the LAION-5B dataset, used to train AI image generators like Stable Diffusion. The photos had been taken by her now-deceased doctor and were apparently uploaded online without authorization before being scraped by LAION. LAION responded that it does not host the images and suggested requesting removal from the hosting website, but provided no direct recourse for the artist. The incident raises concerns about the inclusion of sensitive personal data in AI training sets without consent.

Company involved
LAION
AI system involved
LAION-5B

1 source article · read the reporting →

WF-O1ZO6H6 Sep 2026Italian

Imola: Driverless Cars from Unimore and Politecnico di Milano Collide on Track

Imola, scontro in pista fra le auto senza pilota di Unimore e Politecnico di Milano VIDEO - rainews.it

During the European opening race of the Abu Dhabi Autonomous Racing League at Imola, the driverless cars from Unimore Racing and Politecnico di Milano collided while fighting for the lead. Both vehicles were forced to retire with two laps remaining.

Company involved
Unimore Racing (Università di Modena e Reggio Emilia)
AI system involved
Abu Dhabi Autonomous Racing League

1 source article · read the reporting →

WF-4B4FU612 May 2026

TRT-RS's Galileu AI Detects Prompt Injection Attempt in Legal Petition

The Galileu AI system, developed by the Tribunal Regional do Trabalho da 4ª Região (TRT-RS) and nationalised by the Conselho Superior da Justiça do Trabalho (CSJT), detected a prompt injection attempt in a petition filed at the 3rd Labour Court of Parauapebas, Pará. The system alerted the magistrate, who reviewed the content and made a decision based on human verification, in line with judicial AI supervision requirements. The court reported that the system prevented the malicious content from being processed and highlighted the importance of institutional AI tools with security measures.

Company involved
Tribunal Regional do Trabalho da 4ª Região
AI system involved
Galileu

1 source article · read the reporting →

WF-BABUXF28 Feb 2026

McKinsey's Lilli AI Platform Hacked, Exposing 46 Million Chat Messages

Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.

Company involved
McKinsey & Company
AI system involved
Lilli

1 source article · read the reporting →

LLMjacking Attack Leverages Stolen Credentials to Exploit Cloud LLMs

The Sysdig Threat Research Team observed an attack where stolen cloud credentials were used to access cloud-hosted large language model services. The attackers targeted a vulnerable Laravel system to obtain credentials, then used them to invoke models like Anthropic Claude on AWS Bedrock. They intended to sell LLM access to other cybercriminals, potentially costing victims over $46,000 per day. The attack involved checking credentials against ten AI services and using a reverse proxy to manage access.

AI system involved
Claude (v2/v3) on AWS Bedrock

2 source articles · read the reporting →

WF-MDNFKQ22 Jul 2022

OpenAI's DALL-E 2 covertly adds diversity terms to user prompts

Users of OpenAI's text-to-image tool DALL-E 2 discovered that the system was covertly adding words such as 'black' and 'female' to their prompts. The modification appears to be an attempt to diversify the AI's output and counteract biases inherited from its training data. The changes were made without users' knowledge, raising concerns about transparency.

Company involved
OpenAI
AI system involved
DALL-E 2

3 source articles · read the reporting →

WF-GWKZP614 Jun 2024

LAUSD shelves AI chatbot after vendor AllHere collapses

Los Angeles Unified School District turned off its 'Ed' AI chatbot on June 14, 2024, after the vendor AllHere furloughed most staff due to financial collapse. The chatbot, which cost $3 million, was designed to provide students and parents with academic guidance and school information. A former AllHere employee alleged that student data was improperly shared with third parties and processed overseas, raising privacy concerns. The district stated it will ensure privacy protections and plans to eventually restore the chatbot.

Company involved
Los Angeles Unified School District
AI system involved
Ed

5 source articles · read the reporting →

Claude Code deletes developer's production database and snapshots

Alexey Grigorev used Claude Code to manage infrastructure with Terraform for his websites AI Shipping Labs and DataTalks.Club. Due to a missing state file and over-reliance on the AI agent, Claude executed a destroy command that wiped the production setup, including a database with 2.5 years of records and snapshots. Amazon Business support helped restore the data within a day. Grigorev is now implementing safeguards to prevent recurrence.

Company involved
AI Shipping Labs
AI system involved
Claude Code

2 source articles · read the reporting →

WF-R72X6B10 Jul 2025

APT28 uses LLM-powered malware LAMEHUG against Ukraine's security and defence sector

CERT-UA reports that the threat group UAC-0001 (APT28) distributed phishing emails to Ukrainian executive bodies, impersonating a ministry representative. The emails contained a malicious attachment that deployed LAMEHUG, a Python-based tool which uses the Qwen 2.5-Coder-32B-Instruct large language model via Hugging Face to generate commands for data collection and exfiltration. The malware gathered system information and searched for Microsoft Office, TXT and PDF documents in common user directories, exfiltrating them via SFTP or HTTP POST requests.

Company involved
UAC-0001 (APT28)
AI system involved
LAMEHUG

2 source articles · read the reporting →

WF-3TIT2N11 Mar 2026

Bunce v. Visual Technology Innovations (2) (E.D. Pennsylvania): AI-hallucinated content in court filing, Monetary Sanction, Additional CLE

The AI generated fabricated legal citations in a court filing, misleading the court and opposing counsel.

Company involved
Mr. Rajan

1 source article · read the reporting →

Estée Lauder settles with make-up artists sacked by algorithm

Three MAC make-up artists were dismissed after failing a video interview that was scored by HireVue's algorithm. They appealed but received no clear explanation of how the system assessed them. Estée Lauder Companies settled the resulting legal challenge out of court. HireVue later discontinued the visual analysis component of its video interview platform.

Company involved
Estée Lauder Companies
AI system involved
HireVue

2 source articles · read the reporting →

WF-QZWYPM8 Jan 2018

LG robot Cloi fails repeatedly on stage at CES 2018 debut

At CES 2018, LG's robot Cloi failed to respond to three consecutive voice commands during a live demonstration. The robot was intended to showcase LG's ThinQ AI software for smart home control. The failure was widely mocked on social media and analysts described it as a disastrous debut.

Company involved
LG
AI system involved
Cloi

5 source articles · read the reporting →

Fake Luma Dream Machine AI sites deliver Noodlophile infostealer

Cybercriminals set up Facebook pages impersonating Luma Dream Machine and linked to fake AI video generation websites. Users who uploaded images received an archive containing a malicious executable instead of a video. The executable launched a multi-stage attack that installed Noodlophile, which harvests browser credentials, cookies and cryptocurrency wallet information. Morphisec reported the campaign.

8 source articles · read the reporting →

WF-6UZ2Y611 Apr 2023

Photographer sues LAION e.V. over refusal to remove copyrighted images from AI training dataset

Photographer Robert Kneschke requested that LAION e.V. remove his copyrighted images from its LAION-5B dataset used to train AI image generators. LAION refused, claiming the use was covered by copyright exceptions, and demanded €887.03 in legal costs from Kneschke. Kneschke, through his lawyer, then filed a lawsuit at the Landgericht Hamburg against LAION, alleging copyright infringement and seeking removal and information.

Company involved
LAION e.V.
AI system involved
LAION-5B dataset

10 source articles · read the reporting →

Chinese military researchers used Meta's Llama 2 to develop defense chatbot ChatBIT

Chinese military researchers, including two affiliated with the People's Liberation Army, reportedly used Meta's Llama 2 AI model to develop a defense chatbot called ChatBIT. According to Reuters, the chatbot is designed to gather and process intelligence and offer information for operational decision-making. Meta stated that the use was unauthorized and contrary to its acceptable use policy.

Company involved
People's Liberation Army (PLA)
AI system involved
ChatBIT

6 source articles · read the reporting →

WF-LKR1LN18 Aug 2026

Joann LeDoux v. Outliers, Inc. (2) (W.D. Washington): AI-hallucinated content in court filing, Expert Brief excluded/struck

The AI-generated hallucinated citations in an expert report led to the exclusion of the expert and dismissal of the plaintiff's case.

1 source article · read the reporting →

WF-1FBZ1K11 Jun 2026

Quinteros v. Harbor Distributing, LLC (CA California (1d)): AI-hallucinated content in court filing, Monetary Sanction; Bar referral

AI generated hallucinated legal citations that were filed in court, misleading the court and opposing counsel.

Company involved
Lipeles Law Group

1 source article · read the reporting →

WF-E49EWD9 Sep 2026

Beus Gilbert PLLC v. Brigham Young University et al. (D. Utah): AI-hallucinated content in court filing, Two AI-ethics CLE courses;…

The AI system generated fake legal citations that were included in a court filing, misleading the court and opposing counsel.

1 source article · read the reporting →

WF-F7YECE5 May 2026

Jessica Fuller v. Hyde School, et al. (D. Maine): AI-hallucinated content in court filing, CLE; Firm procedures and certification; Serve…

The AI generated fictitious legal citations that were submitted to the court in a legal filing.

AI system involved
ChatGPT or Claude

1 source article · read the reporting →

WF-AJLVH75 Aug 2026

Southland Homes & Real Estate and Investment, LLC v. Lam (SC California): AI-hallucinated content in court filing, Monetary Sanctions; Bar…

The AI system generated legal briefs containing fabricated case citations, which were filed in court, affecting the court and the opposing party.

1 source article · read the reporting →

WF-3UCXWE1 Jul 2023

Study finds Midjourney, DALL-E 2, Stable Diffusion accept over 85% of fake news prompts

A study by AI startup Logically tested Midjourney, DALL-E 2, and Stable Diffusion and found that they accepted over 85% of prompts seeking to generate fake political news. The systems generated images of ballot stuffing, small boat arrivals, and explosions. Logically warned that the lack of moderation could pose threats to upcoming elections. Stability AI responded by stating its ethical use license and measures to prevent misuse.

Company involved
Midjourney, OpenAI, Stability AI
AI system involved
Midjourney, DALL-E 2, Stable Diffusion

8 source articles · read the reporting →

Answer.AI tests Devin and reports 14 failures in 20 tasks

Answer.AI's team tested Devin, an autonomous AI coding assistant, on 20 real-world tasks over a month. Devin succeeded in only 3 tasks, failed 14, and was inconclusive in 3. The team found Devin often produced overly complex or hallucinated solutions and could not recognize fundamental blockers. They ultimately decided to stick with tools that allow more human control.

AI system involved
Devin

5 source articles · read the reporting →

page 1 of 2Older →