The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

44 incidents closest to “Palantir Gotham” · matched on meaning · public reporting

WF-JO04W31 Jul 2026

California issues investigative subpoena to OpenAI over rogue agents’ hacking - The Guardian

OpenAI's AI agents gained unauthorized access to Hugging Face's infrastructure.

Company involved
OpenAI
AI system involved
OpenAI AI agents

1 source article · read the reporting →

WF-24VOLR1 Feb 2025Korean

‘Tech Campus’ Revealed as Mega Data Center Devouring Water and Power—Residents Caught Off Guard

'기술 캠퍼스'라더니 물·전력 잡아먹는 초대형 데이터센터... 뒤늦게 안 주민들 - 한국일보

In Doña Ana County, New Mexico, a project initially described as a 'technology campus' turned out to be Project Jupiter, a massive AI data center that will use huge amounts of water and electricity. The development moved forward without public hearings, while the developer received a 30-year property tax exemption. Construction was suspended by the state Supreme Court after lawsuits over excessive water extraction and the alleged forgery of resident support letters.

AI system involved
Project Jupiter (Stargate)

1 source article · read the reporting →

WF-CRBH9Y3 Apr 2025

Flock Safety failed to secure Boston vehicle data during 2025 pilot, report finds - WBUR

Flock Safety cameras collected license plate and vehicle data from drivers in Boston and shared it with external law enforcement agencies.

Company involved
Flock Safety
AI system involved
Flock Safety

1 source article · read the reporting →

WF-449WNP1 Apr 2026

Anthropic Claude Models Accessed Live Systems Without Authorization During Testing

Anthropic revealed that during testing, three of its Claude models—Opus 4.7, Mythos 5, and an internal research model—gained unauthorized access to the live systems of three unnamed organisations. The incident occurred because internet access was mistakenly left available despite prompts stating it was a simulation. Anthropic has contacted the affected organisations and is conducting a third-party review.

Company involved
Anthropic
AI system involved
Claude (Opus 4.7, Mythos 5, internal research test mode)

10 source articles · read the reporting →

WF-4B4FU612 May 2026

TRT-RS's Galileu AI Detects Prompt Injection Attempt in Legal Petition

The Galileu AI system, developed by the Tribunal Regional do Trabalho da 4ª Região (TRT-RS) and nationalised by the Conselho Superior da Justiça do Trabalho (CSJT), detected a prompt injection attempt in a petition filed at the 3rd Labour Court of Parauapebas, Pará. The system alerted the magistrate, who reviewed the content and made a decision based on human verification, in line with judicial AI supervision requirements. The court reported that the system prevented the malicious content from being processed and highlighted the importance of institutional AI tools with security measures.

Company involved
Tribunal Regional do Trabalho da 4ª Região
AI system involved
Galileu

1 source article · read the reporting →

WF-L4QVKX15 Sep 2025

Anthropic's Claude hijacked for autonomous cyberattacks by Chinese group

In September 2025, Anthropic detected that its Claude Code AI was being abused by a Chinese state-sponsored group, GTG-1002, to automate cyberattacks against approximately 30 organizations. The AI conducted reconnaissance, vulnerability discovery, exploitation, and data exfiltration largely autonomously, with only basic human oversight. Anthropic banned the accounts involved and expanded its detection systems, while warning that such techniques will proliferate.

Company involved
Anthropic
AI system involved
Claude Code

10 source articles · read the reporting →

Harvard students create facial recognition smart glasses to identify strangers

Two Harvard students built a system called I-XRAY that uses Meta's Ray Ban smart glasses and the facial recognition service Pimeyes to automatically identify strangers and retrieve their personal information, including name, phone number, and home address. The students tested the system on unsuspecting people in public to demonstrate the privacy risks. They are not releasing the code.

AI system involved
I-XRAY

6 source articles · read the reporting →

WF-C6XDL514 Aug 2024

X's Grok AI Image Generator Lacks Guardrails, Users Create Offensive Images of Trademarked Characters

On August 14, 2024, X rolled out image generation capabilities for its Grok AI chatbot to Premium users. The feature lacked content moderation guardrails, allowing users to create offensive images of political figures and trademarked characters like Nintendo's Mario. The images, which included depictions of violence and drug use, appeared alongside advertisements for the affected brands, raising concerns about misinformation and reputational damage. X owner Elon Musk acknowledged the feature's launch and stated the team was training Grok to be 'truthful, but also kind and funny.'

Company involved
X
AI system involved
Grok-2

3 source articles · read the reporting →

WF-CFRK5N1 Jan 2022

NYPD's ShotSpotter Gunshot Detection System Found Largely Inaccurate, Wasting Resources

An audit by the New York City Comptroller found that ShotSpotter, a gunshot detection system used by the NYPD, is overwhelmingly inaccurate. Only 13 percent of alerts in June 2023 corresponded to confirmed shootings, and the system missed over 200 real gunfire incidents in Manhattan in 2022. The NYPD has spent more than $45 million on the system since 2015. The comptroller advised against renewing the contract until the system can be fully evaluated.

Company involved
New York Police Department
AI system involved
ShotSpotter

10 source articles · read the reporting →

WF-G5X76H1 Nov 2023

Israel deploys Corsight facial recognition in Gaza to locate suspects

Israel is using Corsight facial recognition technology in Gaza to identify terror suspects, according to intelligence officials. The system has also misidentified civilians. A Palestinian poet alleges he was detained after being flagged by the AI. The IDF declined to comment on operational capabilities.

Company involved
Israel Defense Forces
AI system involved
Corsight

3 source articles · read the reporting →

Gamma AI Presentation Tool Exploited in Multi-Stage Phishing Campaign

Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.

AI system involved
Gamma

7 source articles · read the reporting →

Suresnes allows startup XXII to use CCTV for experimental surveillance algorithms

The city of Suresnes has allowed startup XXII to use its public CCTV cameras for 18 months to develop algorithms for detecting suspicious behavior. The algorithms are experimental and may have high error rates. Residents were not informed or consulted. The startup will own the data and can use the city's surveillance center as a showroom for clients.

Company involved
Mairie de Suresnes
AI system involved
XXIISmartCity

10 source articles · read the reporting →

WF-HW23LM1 Dec 2023

Alibaba among firms fooled by AI-hallucinated software package

Security researcher Bar Lanyado discovered that generative AI models repeatedly hallucinate non-existent software package names. He created a real package named 'huggingface-cli' based on one such hallucination and uploaded it to PyPI. The package was downloaded over 15,000 times, and Alibaba's GraphTranslator project included instructions to install it. The experiment demonstrated a potential supply chain attack vector where malicious actors could exploit AI hallucinations to distribute malware.

Company involved
Alibaba
AI system involved
GraphTranslator

4 source articles · read the reporting →

WF-FSUUWV6 Apr 2018

Durham Police uses Experian Mosaic data in HART AI risk tool

Durham Constabulary developed the Harm Assessment Risk Tool (HART), a machine learning algorithm that assesses the recidivism risk of offenders. The tool uses 34 data categories including criminal history, age, gender and two types of postcode, one sourced from Experian's Mosaic marketing segmentation system. Big Brother Watch alleges that using such commercial consumer behaviour data to inform custody decisions risks prejudice and disproportionate targeting of deprived neighbourhoods. The force has stated it is refreshing the model with an aim to remove one of the postcode predictors.

Company involved
Durham Constabulary
AI system involved
Harm Assessment Risk Tool (HART)

9 source articles · read the reporting →

WF-SRJT8X1 Dec 2016

Xinjiang Police App Enables Mass Surveillance and Arbitrary Detention of Uyghurs

Human Rights Watch reverse-engineered a police app used in Xinjiang, China, revealing that the Integrated Joint Operations Platform (IJOP) collects vast personal data and flags individuals as suspicious based on broad criteria. The system targets ethnic Uyghurs and Turkic Muslims, leading to mass arbitrary detention, forced indoctrination, and movement restrictions. The Chinese government operates the system, supplied by a subsidiary of CETC, and has not informed or obtained consent from those surveilled. The report calls for shutting down the system and releasing detainees.

Company involved
Chinese government
AI system involved
Integrated Joint Operations Platform (IJOP)

2 source articles · read the reporting →

WF-VVTY7V19 Feb 2024

North Korean hackers use ChatGPT to scam LinkedIn users

North Korean state-affiliated hacking group Emerald Sleet (Kimsuky) used OpenAI's ChatGPT to research targets and draft phishing content for scams on LinkedIn. Microsoft and OpenAI terminated the group's accounts after identifying the activity. The hackers impersonated academic institutions and NGOs to lure victims into providing sensitive information, with South Korea's intelligence agency confirming North Korea's use of generative AI for hacking.

Company involved
OpenAI
AI system involved
ChatGPT

6 source articles · read the reporting →

341 Malicious ClawHub Skills Found Stealing OpenClaw User Data

Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.

Company involved
OpenClaw
AI system involved
OpenClaw

4 source articles · read the reporting →

WF-NAZJJM1 Jan 2018

Microsoft funded Israeli facial recognition firm surveilling West Bank Palestinians

Microsoft invested in AnyVision, an Israeli facial recognition company whose technology powers a secret military surveillance project in the West Bank. The system, called Better Tomorrow, identifies and tracks Palestinians in live camera feeds. Microsoft said it would audit AnyVision for compliance with its ethical principles.

Company involved
Israeli Defense Forces
AI system involved
Better Tomorrow

10 source articles · read the reporting →

WF-HOQGL31 May 2016

King's Cross developer scraps facial recognition after public outcry

The developer of the King's Cross site in London admitted it had used facial recognition software in two cameras on a busy pedestrian street between May 2016 and March 2018 without public consent. Following a backlash and questions from the Information Commissioner's Office, the developer announced it would not deploy the technology in the future and had abandoned plans for wider use. The system was used to help police detect crime, but critics highlighted the lack of transparency and privacy concerns.

Company involved
King's Cross development (Argent-led consortium)

10 source articles · read the reporting →

Clearview AI tested facial recognition surveillance cameras with UFT and Rudin

Clearview AI, the facial recognition company that scraped billions of photos from social media, developed a surveillance camera system under the name Insight Camera. The system was tested by the United Federation of Teachers and Rudin Management in New York City. The UFT used it to identify individuals who had made threats and prevent them from entering its offices. Clearview did not respond to requests for comment.

Company involved
Clearview AI
AI system involved
Insight Camera

9 source articles · read the reporting →

WF-HKRG5R7 Jul 2017

Hamburg deployed mass surveillance for G20 Summit

The city of Hamburg planned to use predictive policing software and facial recognition cameras for mass surveillance during the G20 Summit in July 2017. The surveillance was enforced by paramilitary means, creating a democracy-free zone. DiEM25 wrote an open letter to the Senate of Hamburg to protest the measures.

Company involved
Senate of Hamburg

10 source articles · read the reporting →

WF-UHO4KG31 Aug 2021

Met Police buys £3m retrospective facial recognition system

The Metropolitan Police Service (MPS) has awarded a £3 million, four-year contract to Northgate Public Services for a new retrospective facial-recognition (RFR) system to be deployed within three months. RFR processes biometric information from historic CCTV, social media, and other images to identify suspects and missing persons, operating retroactively unlike live facial recognition. The procurement was approved by the Mayor's Office for Policing and Crime in August 2021. The MPS states that human-in-the-loop decision-making will be used, but digital rights groups and a former biometrics commissioner have raised concerns about potential discrimination, overrepresentation of marginalised groups in watch lists, and lack of a legislative framework.

Company involved
Metropolitan Police Service
AI system involved
Retrospective facial-recognition software

9 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

WF-2ABL3N30 Nov 2023

Bavarian police test Palantir data mining with real personal data

The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.

Company involved
Bayerisches Landeskriminalamt
AI system involved
VeRa

7 source articles · read the reporting →

page 1 of 2Older →