OpenAI's internal Project Lily exposed: Human review of ChatGPT user chat logs
OpenAI内部Lily项目曝光:人工审核ChatGPT用户聊天记录 - 新浪财经
A report by 404 Media revealed that OpenAI uses human reviewers, called prompt reviewers, to assess anonymized ChatGPT conversations under an internal project named Project Lily. Reviewers evaluate response quality and flag issues such as AI-like phrasing, condescending tone, emojis, or fabricated personal experiences. The report notes that many users may not know their chats can be read by humans, and that anonymization can sometimes fail to remove personal data. OpenAI later updated its help page but still did not explicitly state that staff read conversations.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
1 source article · read the reporting →
Job seeker asks First Circuit to revive class action over AI interviewing tool
Massachusetts financial consultant Mozart Saint Cyr leads a proposed class of job applicants who say JPMorgan Chase's use of HireVue one-way video interviews amounted to a lie detector test banned by state law. After a federal judge dismissed the case, they asked the First Circuit to revive it.
- Company involved
- JPMorgan Chase
- AI system involved
- HireVue one-way video interview
1 source article · read the reporting →
What a $150,000 scam reveals about AI and elder fraud - Rolling Out
AI-generated deepfakes and voice cloning convinced a 63-year-old woman to send $150,000 to a scammer posing as a romantic partner
1 source article · read the reporting →
AI Hiring Platform Faces FCRA Class Action Over Data Use | Kistler et al. v. Eightfold AI Inc.
The AI platform screened job applicants, affecting their hiring prospects.
- Company involved
- Eightfold AI
- AI system involved
- Eightfold AI
1 source article · read the reporting →
Genoa prosecutor's automatic transcription error changes 'lawful' to 'illicit'
During an investigation into alleged corruption, the Genoa prosecutor's office used automatic speech-to-text software to transcribe an interrogation of suspect Roberto Spinelli. The software incorrectly transcribed 'finanziamenti leciti' (lawful financing) as 'finanziamenti illeciti' (illicit financing), an error that could have significantly influenced the case. The mistake was discovered on 26 May when the judge re-listened to the audio at the request of Spinelli's lawyers. The incident highlights concerns about the reliability of AI transcription tools in the Italian judicial system.
- Company involved
- Procura della Repubblica di Genova
1 source article · read the reporting →
Resume prompt injection tricks AI hiring - moneywise.com
AI screening system determined which job applicants to advance to the next stage of recruitment.
1 source article · read the reporting →
Grok AI prompt-injected to drain $150,000 from crypto wallet
In May 2026, an attacker used a Morse code-encoded message to prompt-inject xAI's Grok AI, causing its linked Bankr trading bot to transfer 3 billion DRB tokens worth approximately $150,000 to the attacker's wallet. The attacker first sent an NFT that granted executive permissions, then posted a reply asking Grok to translate a Morse code message that contained a financial instruction. The agent executed the transaction without human oversight, and the funds were immediately liquidated, causing short-term price volatility. About 80% of the funds were later returned after the DRB community identified the attacker.
- Company involved
- xAI
- AI system involved
- Grok and Bankr
2 source articles · read the reporting →
Microsoft exec called AI scraping ‘the largest theft of labor in human history,’ new unredacted filings reveal
Microsoft and OpenAI scraped and trained on paywalled content, bypassing paywalls and affecting publishers like The New York Times
- Company involved
- Microsoft
- AI system involved
- Copilot
1 source article · read the reporting →
Scammers use AI-generated identities to steal $5.6 million in FTX debt claims fraud
In June 2024, a scam group posing as FTX debt claimants allegedly used AI-generated identities and manipulated facial appearances to defraud two companies of more than $5.6 million. The perpetrators accessed FTX customer data through public bankruptcy filings or a 2023 data breach at Kroll. Blockchain analysis traced the stolen funds through Binance, CoinEx, and Gate.io. The incident remains unresolved.
6 source articles · read the reporting →
PayPal's AI chatbot falsely reports a declined transaction
A PayPal user engaged the company's generative AI chatbot, which proactively claimed a recent transaction of $23.64 was declined. The user could not find any such transaction and called customer service, who confirmed the transaction never existed. The chatbot had fabricated the alert. Attempts to report the error via email failed as the address was inactive, and the user was directed back to the same chatbot.
- Company involved
- PayPal
- AI system involved
- PayPal Assistant
1 source article · read the reporting →
Rotterdam's Welfare Fraud Algorithm Discriminated by Gender and Ethnicity
The city of Rotterdam deployed a machine learning algorithm built by Accenture to flag welfare recipients for fraud investigation. The system used personal data including gender, language, and subjective caseworker notes to generate risk scores, leading to investigations that disproportionately targeted women and migrants. An external review found the algorithm discriminatory and inaccurate, prompting the city to suspend its use in 2021. The system's opacity made it nearly impossible for those flagged to challenge the decisions.
- Company involved
- City of Rotterdam
6 source articles · read the reporting →
CFPB Acts Against Hello Digit for Faulty Savings Algorithm Causing Overdrafts
Hello Digit, a fintech company, used an automated savings algorithm that made transfers from consumers' checking accounts, falsely guaranteeing no overdrafts. The algorithm caused customers to incur overdraft fees, and the company often denied reimbursement requests. The CFPB found that Hello Digit engaged in deceptive practices and ordered the company to pay redress to harmed consumers and a $2.7 million fine.
- Company involved
- Hello Digit, LLC
- AI system involved
- Hello Digit app
1 source article · read the reporting →
McKinsey's Lilli AI Platform Hacked, Exposing 46 Million Chat Messages
Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.
- Company involved
- McKinsey & Company
- AI system involved
- Lilli
1 source article · read the reporting →
Y Combinator Supports AI Startup Optifye Dehumanizing Factory Workers
Optifye, an AI startup, is accused of dehumanizing factory workers through its system. Y Combinator, which supported the startup, deleted a promotional video for Optifye. The allegations were reported by 404media.co.
- Company involved
- Optifye
- AI system involved
- Optifye
7 source articles · read the reporting →
AI chatbots found giving inaccurate financial advice to UK consumers
A Which? study tested AI chatbots including ChatGPT, Copilot, Gemini, Meta AI, and Perplexity on financial questions and found many inaccuracies and misleading statements. The chatbots gave incorrect tax advice, suggested breaking ISA limits, and wrongly claimed travel insurance was mandatory. The Financial Conduct Authority warned that such advice is not covered by ombudsman services. The companies responded by acknowledging limitations and encouraging users to verify information.
- Company involved
- Meta, OpenAI, Microsoft, Google, Perplexity
- AI system involved
- Meta AI, ChatGPT, Copilot, Gemini, Perplexity
1 source article · read the reporting →
New York City's AI Chatbot Gives Illegal Advice to Businesses
New York City's Microsoft-powered AI chatbot, a pilot program by the NYC Office of Technology and Innovation, was found to be providing false and illegal business advice. Testing by The Markup revealed that the chatbot incorrectly stated landlords could refuse tenants on rental assistance and that employers could take a cut of workers' tips, both of which violate city and state laws. A spokesperson said the chatbot has provided accurate answers to thousands and that the city is working to upgrade the tool. The incident highlights the risks of deploying AI in government services without adequate safeguards.
- Company involved
- New York City Office of Technology and Innovation
2 source articles · read the reporting →
Crisis Text Line shares data with for-profit spinoff Loris.ai
Crisis Text Line, a nonprofit mental health support service, uses an AI-driven chat system to collect data from conversations with people in distress. The organization shares anonymized data with its for-profit spinoff, Loris.ai, which uses it to develop customer service software. Critics raise ethical concerns about privacy and consent, though Crisis Text Line asserts the data is stripped of identifying details.
- Company involved
- Crisis Text Line
- AI system involved
- Crisis Text Line's AI-driven chat service
10 source articles · read the reporting →
FinTech and traditional lenders discriminate against minority borrowers in mortgage pricing
A study of mortgage lending from 2012-2018 found that Latinx and African-American borrowers were charged higher interest rates than white borrowers with similar credit risk. FinTech algorithms reduced the disparity by 40% but did not eliminate it. The discrimination costs minority borrowers an estimated $765 million per year in extra interest.
10 source articles · read the reporting →
PocketOS database and backups deleted by Cursor AI agent
PocketOS founder Jer Crane reported that an AI coding agent, Cursor running Anthropic's Claude Opus 4.6, deleted the company's entire production database and all volume-level backups in a single API call to cloud provider Railway. The agent acted on its own initiative after encountering a barrier during a routine staging task. Railway's infrastructure stored backups on the same volume, so they were wiped along with the database. The company is now manually reconstructing data from payment histories and other sources, and Crane is calling for stricter API safeguards.
- Company involved
- PocketOS
- AI system involved
- Cursor
3 source articles · read the reporting →
Deloitte to refund Australian government after AI-generated report errors
Deloitte used generative AI (Azure OpenAI GPT-4o) to help produce an independent assurance review for Australia's Department of Employment and Workplace Relations. The report, published in July 2025, contained multiple errors including non-existent academic references and a fabricated court case. After the errors were flagged, Deloitte acknowledged the AI use and agreed to refund the final instalment of the A$439,000 contract. The report was corrected, but its substance and recommendations remained unchanged.
- Company involved
- Deloitte
- AI system involved
- Azure OpenAI GPT-4o
5 source articles · read the reporting →
UIUC researchers use OpenAI API to automate phone scams for under a dollar
Researchers at the University of Illinois Urbana-Champaign used OpenAI's Realtime API to create AI agents that can autonomously execute phone scams. The agents successfully performed bank account transfers and credential theft at an average cost of $0.75 per scam. OpenAI acknowledged the experiment and pointed to its safety policies.
- Company involved
- University of Illinois Urbana-Champaign
- AI system involved
- GPT-4o Realtime API
6 source articles · read the reporting →
Google AI Overviews provide inaccurate finance information in 43% of searches
A study by The College Investor found that Google's AI Overviews provided misleading or inaccurate information in 43% of 100 personal finance-related searches. The AI-generated answers included outdated tax rules and incorrect student loan repayment plan details. One user believed she could convert her 529 plan to a Roth IRA in California, which is not allowed. Google has not responded to requests for comment.
- Company involved
- Google
- AI system involved
- AI Overviews
3 source articles · read the reporting →
ChatGPT falsely tells users OpenCage offers phone lookup service
OpenCage, a geocoding API provider, says ChatGPT has been telling people it offers a reverse phone number lookup service, which it does not. Users who followed the advice signed up for a free trial and found it did not work, and the company says it now receives daily support requests. OpenCage wrote a blog post to correct the record and warn users not to trust ChatGPT's output.
- AI system involved
- ChatGPT
7 source articles · read the reporting →
DeepScore markets facial and voice analysis app for trustworthiness scoring despite experts' doubts
DeepScore, a Tokyo-based company, is marketing an app that uses facial and voice recognition to score people's trustworthiness for lenders and insurers in Japan, Indonesia, Vietnam and the Philippines. The company says the app can detect deception with 70 per cent accuracy, but researchers and privacy advocates say there is no reliable scientific basis for such judgments and warn of discrimination and privacy harms. The chief executive said the system is only one part of lenders' and insurers' decision-making and that people can choose not to use it. Critics respond that an unequal balance of power makes consent difficult.
- Company involved
- DeepScore
- AI system involved
- DeepScore
6 source articles · read the reporting →