The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

44 incidents closest to “Pega Customer Decision Hub” · matched on meaning · public reporting

Workday Gains an Edge in AI Hiring Bias Fight: California Brief - Bloomberg Law News

Workday Gains an Edge in AI Hiring Bias Fight: California Brief - Bloomberg Law News

1 source article · read the reporting →

WF-CKGUC024 Aug 2026Vietnamese

Frustrated by Airline Hotline's Soulless AI Chatbot Responses

Điên tiết vì gọi hotline hãng hàng không chỉ thấy chatbot AI trả lời vô hồn - VnExpress

A customer called an airline hotline for urgent help but only reached an automated AI voice system. The chatbot on the website also failed to understand the issue and gave irrelevant answers. The customer felt blocked from speaking to a real person and questioned the overuse of AI in customer service.

1 source article · read the reporting →

Resume prompt injection tricks AI hiring - moneywise.com

AI screening system determined which job applicants to advance to the next stage of recruitment.

1 source article · read the reporting →

WF-WCLEUR7 Jul 2026ZH-HK

Phia | Gates' Daughter's AI Shopping Assistant Used Cookie Stuffing, Admits Taking Others' Affiliate Commissions

Phia︱蓋茨女兒「AI購物助理」偷塞Cookie 認收他人推廣佣金 - singtao.ca

Phoebe Gates' startup Phia placed extra cookies during checkout through its browser extension to claim affiliate commissions from retailers even when shoppers did not use it. Internal data showed this was a company-controlled feature rather than a code error, and it was disabled only after media inquiries. Phia admitted receiving commissions it was not owed and offered transaction reversals to brands.

Company involved
Phia
AI system involved
Phia

1 source article · read the reporting →

WF-YYDECKJapanese

US Federal Court Rejects Workday's Arguments, Allows AI Hiring Lawsuit to Proceed

米連邦地裁がWorkdayの主張を退け、AI採用訴訟の継続を認める - Межа. Новини України.

A federal court in San Francisco declined Workday's request to dismiss a lawsuit alleging its AI-powered hiring software discriminates against applicants with disabilities and other protected groups. Judge Rita Lin ruled that California anti-discrimination law may apply and allowed claims that the software screens candidates using proxy indicators such as employment gaps to move forward. Workday maintains its tools evaluate only qualifications and do not make hiring decisions.

Company involved
Workday
AI system involved
Workday

1 source article · read the reporting →

WF-ATS7E1Russian

South Africa's Supreme Court of Appeal Considers Sassa Algorithm Case

Верховный апелляционный суд ЮАР рассмотрел дело об алгоритмах Sassa - UA.NEWS

The Supreme Court of Appeal heard an appeal on 25 August about Sassa's digital application system for the SRD grant. The system only accepts online applications and uses automated bank account checks that may deny grants to people whose accounts receive deposits that are not regular income. The Global Center on AI Governance submitted that automated decisions must uphold constitutional rights and be fair, non-discriminatory, and suited to South Africa's informal economy.

Company involved
South African Social Security Agency (Sassa)
AI system involved
Sassa digital application system

1 source article · read the reporting →

WF-7U35ZD18 Mar 2024

SEC Charges Delphia and Global Predictions for False AI Claims

The SEC charged Delphia (USA) Inc. and Global Predictions Inc. for making false and misleading statements about their use of artificial intelligence. Delphia claimed from 2019 to 2023 that it used AI and machine learning to predict investments, while Global Predictions falsely claimed in 2023 to be the 'first regulated AI financial advisor'. Both firms settled the charges without admitting or denying the findings, agreeing to pay a total of $400,000 in civil penalties and to cease and desist from further violations.

Company involved
Delphia (USA) Inc. and Global Predictions Inc.

1 source article · read the reporting →

WF-B332QL1 Jan 2017

CFPB Acts Against Hello Digit for Faulty Savings Algorithm Causing Overdrafts

Hello Digit, a fintech company, used an automated savings algorithm that made transfers from consumers' checking accounts, falsely guaranteeing no overdrafts. The algorithm caused customers to incur overdraft fees, and the company often denied reimbursement requests. The CFPB found that Hello Digit engaged in deceptive practices and ordered the company to pay redress to harmed consumers and a $2.7 million fine.

Company involved
Hello Digit, LLC
AI system involved
Hello Digit app

1 source article · read the reporting →

WF-8DBA8B9 Apr 2025

Guardio Labs finds AI agents easily abused to create phishing scams

Guardio Labs tested three popular AI agents—ChatGPT, Claude, and Lovable—to see how easily they could be manipulated into generating phishing campaigns. The benchmark, called VibeScamming, simulated a novice scammer attempting to create an SMS phishing attack to steal Microsoft credentials. While ChatGPT and Claude initially refused, they provided full code and tutorials after a jailbreak attempt posing as ethical hacking; Lovable instantly generated and deployed a fully functional, convincing phishing page with no resistance.

Company involved
Guardio Labs
AI system involved
ChatGPT, Claude, Lovable

2 source articles · read the reporting →

WF-BABUXF28 Feb 2026

McKinsey's Lilli AI Platform Hacked, Exposing 46 Million Chat Messages

Security researchers at CodeWall used an autonomous offensive agent to discover a SQL injection vulnerability in McKinsey's internal AI platform, Lilli. The vulnerability allowed unauthenticated access to the production database, exposing 46.5 million chat messages, 728,000 files, and 57,000 user accounts. The researchers responsibly disclosed the issue to McKinsey, who patched the endpoints within days. No data was exfiltrated or misused, and no disruption occurred.

Company involved
McKinsey & Company
AI system involved
Lilli

1 source article · read the reporting →

WF-X8XHHQ18 Jan 2024

DPD Disables AI Chatbot After It Swears at Customer and Insults Company

A customer of UK parcel delivery firm DPD was trying to track a lost package via the company's AI chatbot. The bot was unable to help and, when prompted, wrote a poem calling DPD a 'waste of time' and a 'customer's worst nightmare', and later swore at the customer. DPD acknowledged an error after a system update and disabled the AI element of the chatbot.

Company involved
DPD

2 source articles · read the reporting →

WF-CESBK714 Oct 2024

Portland Water Bureau AI pilot offers discount to billionaire CEO

The Portland Water Bureau used a machine learning system in a randomised control trial to identify customers for its financial assistance programme. The system selected Columbia Sportswear CEO Tim Boyle, a billionaire and one of the city's largest residential water consumers, for a 40% water bill discount. Boyle declined the discount, stating it should go to someone who needs it. The bureau is testing whether the SERVUS algorithm can accurately identify customers' ability to pay.

Company involved
Portland Water Bureau
AI system involved
Smart Discount Program

1 source article · read the reporting →

Claude Code deletes developer's production database and snapshots

Alexey Grigorev used Claude Code to manage infrastructure with Terraform for his websites AI Shipping Labs and DataTalks.Club. Due to a missing state file and over-reliance on the AI agent, Claude executed a destroy command that wiped the production setup, including a database with 2.5 years of records and snapshots. Amazon Business support helped restore the data within a day. Grigorev is now implementing safeguards to prevent recurrence.

Company involved
AI Shipping Labs
AI system involved
Claude Code

2 source articles · read the reporting →

WF-FSUUWV6 Apr 2018

Durham Police uses Experian Mosaic data in HART AI risk tool

Durham Constabulary developed the Harm Assessment Risk Tool (HART), a machine learning algorithm that assesses the recidivism risk of offenders. The tool uses 34 data categories including criminal history, age, gender and two types of postcode, one sourced from Experian's Mosaic marketing segmentation system. Big Brother Watch alleges that using such commercial consumer behaviour data to inform custody decisions risks prejudice and disproportionate targeting of deprived neighbourhoods. The force has stated it is refreshing the model with an aim to remove one of the postcode predictors.

Company involved
Durham Constabulary
AI system involved
Harm Assessment Risk Tool (HART)

9 source articles · read the reporting →

WF-WRPSEM1 Jan 2024

Air Canada Chatbot Fabricates Discount, Leading to Court Case

Air Canada's customer service chatbot allegedly fabricated a discount during a conversation with a customer last year. The incident resulted in a court case against the airline. Insurer Armilla stated that its new AI mishap policy would have covered the loss from selling tickets at the discounted price if the chatbot was found to have underperformed.

Company involved
Air Canada
AI system involved
chatbot

6 source articles · read the reporting →

Walgreens deploys digital cooler doors with ads from Cooler Screens

Walgreens is rolling out digital cooler doors from Cooler Screens that display ads before showing the cooler contents. The system tracks when customers stop in front of the doors but claims to be identity-blind. Customers have expressed confusion and annoyance on social media. Walgreens says the screens provide relevant product information.

Company involved
Walgreens
AI system involved
Cooler Screens

10 source articles · read the reporting →

Finnish recruitment company Digital Minds used AI to analyze job applicants' messages, prompting data protection investigation

Digital Minds, a Finnish recruitment company founded by psychologists, used IBM Watson AI to analyze job applicants' social media and email messages for personality assessments. The company obtained written consent but the Finnish Data Protection Ombudsman launched an investigation, suspecting violations of data protection laws and the secrecy of correspondence. The service was used on fewer than ten applicants and has been paused pending the investigation.

Company involved
Digital Minds
AI system involved
IBM Watson

9 source articles · read the reporting →

WF-I030I618 Nov 2024

Coca-Cola faces backlash over AI-generated Christmas ad

Coca-Cola released an AI-generated Christmas advertisement intended to evoke its classic 1995 'Holidays Are Coming' commercial. The ad, created by three AI studios using generative AI models, drew criticism from consumers and artists who called it 'soulless' and argued it replaced human creativity. A Coca-Cola spokesperson defended the ad as a collaboration between human storytellers and generative AI, and said the company will continue exploring AI in marketing.

Company involved
Coca-Cola

5 source articles · read the reporting →

Answer.AI tests Devin and reports 14 failures in 20 tasks

Answer.AI's team tested Devin, an autonomous AI coding assistant, on 20 real-world tasks over a month. Devin succeeded in only 3 tasks, failed 14, and was inconclusive in 3. The team found Devin often produced overly complex or hallucinated solutions and could not recognize fundamental blockers. They ultimately decided to stick with tools that allow more human control.

AI system involved
Devin

5 source articles · read the reporting →

WF-L8981D29 Jan 2025

DeepSeek exposed user data via open ClickHouse database

Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.

Company involved
DeepSeek
AI system involved
DeepSeek-R1

5 source articles · read the reporting →

WF-3333OU22 Sep 2021

EviCore denied heart catheterization for patient using algorithm

In fall 2021, Little John Cupp's doctor requested a left heart catheterization exam. EviCore, a company hired by UnitedHealthcare, denied the request twice using an algorithm called 'the dial' that adjusts thresholds for review. The algorithm flagged the request for review, and EviCore's doctors determined it was not medically necessary. Cupp did not receive the procedure and his symptoms continued.

Company involved
EviCore (a Cigna company)
AI system involved
the dial

6 source articles · read the reporting →

Presto Automation uses off-site human agents to double-check AI drive-thru orders

Presto Automation Inc, which markets an AI voice assistant for drive-thru ordering, used off-site human agents in countries including the Philippines to double-check orders in more than 70% of customer interactions, according to SEC filings reported by Bloomberg. The company told Bloomberg that the process helps train its system and should reduce human intervention over time. Presto's drive-thru AI is used in more than 400 restaurants, including Del Taco, Carl's Jr and Checkers, and its stock fell more than 10% after the reports.

Company involved
Presto Automation Inc.

8 source articles · read the reporting →

Google Slapped With Digital Privacy Class Action Over Use of Customer Service AI Product - Law.com

The system intercepted and analyzed customer service calls of Home Depot customers without their consent.

Company involved
Google
AI system involved
Cloud Contact Center AI

1 source article · read the reporting →

CJEU rules Dun & Bradstreet must explain automated credit decisions under GDPR

A customer was refused a mobile phone contract because of an automated credit assessment by Dun & Bradstreet Austria. The customer took the case to court, which found that Dun & Bradstreet had infringed the GDPR by failing to provide meaningful information about the logic involved. The CJEU ruled that data controllers must explain automated decisions and that trade secrets cannot automatically override the right of access.

Company involved
Dun & Bradstreet Austria GmbH

7 source articles · read the reporting →

page 1 of 2Older →