The record

Where automated decisions went wrong

Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.

Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.

Clear

38 incidents closest to “Zest Protect” · matched on meaning · public reporting

WF-JCS1A01 Jul 2025

Lieff Cabraser and Greer Injury Lawyers Announce Federal Class Action Lawsuit Against X.AI Corp and MZX Tech LLC for Nuisance,…

The data centers and gas turbines emitted constant noise, vibrations, and particulate matter, affecting residents' ability to use and enjoy their properties.

Company involved
X.AI Corp and MZX Tech LLC
AI system involved
Colossus I, Colossus II, MACROHARDRR, Minihard data centers and gas turbines

1 source article · read the reporting →

WF-A43E5518 Jan 2020

Unwanted Witness warns of state surveillance in Uganda

Unwanted Witness has raised concerns about the Ugandan government's use of surveillance technology, including facial recognition and location monitoring, to suppress political dissent. The organisation alleges that CCTV footage was used to monitor opposition rallies and protests ahead of the 2021 elections. It also highlights the use of cybercrime laws to silence free speech, citing the imprisonment of activist Dr Stella Nyanzi.

Company involved
Uganda Police Force
AI system involved
CCTV Camera command centre

3 source articles · read the reporting →

WF-4AK2MS1 Jun 2024

Hangzhou police crack AI face-swapping gang that stole users' personal data

Hangzhou police have cracked a case in which a gang allegedly used an overseas multimodal AI model to create face-swapped videos that defeated facial-recognition login checks on major platforms. The group is accused of stealing users' photos, generating videos of actions such as blinking or turning the head, and then accessing victims' accounts to collect personal information, which was sold to fraud gangs for nearly 200,000 yuan. Four suspects were arrested in Anhui, Guizhou and Zhejiang in August and placed in criminal detention. Police warned the public to manage personal information securely and urged platforms to strengthen facial authentication.

1 source article · read the reporting →

WF-D9MV7M10 Aug 2023

Pak 'n' Save AI app generated dangerous recipes including chlorine gas

Pak 'n' Save's Savey Meal-bot, an AI-powered recipe generator, produced dangerous suggestions such as chlorine gas and bleach-infused dishes when users entered non-food items. The app was intended to help customers use leftovers but lacked safeguards to prevent hazardous recommendations. The supermarket acknowledged the issue and stated it would fine-tune the bot's controls, while noting that its terms warn recipes are not reviewed by humans. No injuries were reported.

Company involved
Pak 'n' Save
AI system involved
Savey Meal-bot

1 source article · read the reporting →

WF-M4ZQBV9 Jul 2025

Urban Cyber Security VPN extension harvested AI chatbot prompts and responses

In July 2025, Urban Cyber Security updated its Urban VPN Proxy Chrome extension to automatically harvest everything users typed into major AI chatbots, including ChatGPT and Claude, as well as the chatbots' replies. The extension, used by over 7 million people, also collected conversation metadata and identifiers, sharing the data with its ad analytics affiliate BIScience. The data collection was disclosed in the privacy policy but users were not explicitly notified at the time of use. Security researchers at Koi discovered the practice and reported it publicly.

Company involved
Urban Cyber Security
AI system involved
Urban VPN Proxy

3 source articles · read the reporting →

Derek O'Brien alleges Tek Fog app threatens national security

Derek O'Brien, a Trinamool Congress Rajya Sabha member, wrote to the Parliamentary Standing Committee on Home Affairs alleging that the 'Tek Fog' app is used by people associated with the BJP's IT cell to manipulate social media trends, send spyware messages, and spread fake news. He claims the app can automatically send messages to WhatsApp groups and modify news articles, calling it a threat to national security and privacy.

Company involved
Bharatiya Janata Party
AI system involved
Tek Fog

10 source articles · read the reporting →

Prozenith used AI deepfake of Oprah to sell turmeric supplements

A Utah woman says she paid more than $400 for Prozenith supplements after seeing videos that appeared to show Oprah Winfrey endorsing them, but the product was mostly turmeric. The endorsements are alleged to be AI deepfakes, and Winfrey has said she has nothing to do with weight-loss pills. KSL TV contacted Prozenith but received no response; the woman was told she could return the product.

Company involved
Prozenith

2 source articles · read the reporting →

WF-FSUUWV6 Apr 2018

Durham Police uses Experian Mosaic data in HART AI risk tool

Durham Constabulary developed the Harm Assessment Risk Tool (HART), a machine learning algorithm that assesses the recidivism risk of offenders. The tool uses 34 data categories including criminal history, age, gender and two types of postcode, one sourced from Experian's Mosaic marketing segmentation system. Big Brother Watch alleges that using such commercial consumer behaviour data to inform custody decisions risks prejudice and disproportionate targeting of deprived neighbourhoods. The force has stated it is refreshing the model with an aim to remove one of the postcode predictors.

Company involved
Durham Constabulary
AI system involved
Harm Assessment Risk Tool (HART)

9 source articles · read the reporting →

WF-TXEW5619 Jan 2014

Nest Protect Smoke Detector False Alarms Disturb Users

Nest Protect users report false smoke alarms, with some units failing to silence and requiring replacement. One user described a terrifying experience of receiving a smoke alert while away from home, only to find no fire. Nest has been replacing defective units, but the issue has eroded trust in the safety device.

Company involved
Nest
AI system involved
Nest Protect

6 source articles · read the reporting →

WF-VFS58P1 Aug 2025

Microsoft Recall still captures credit cards and passwords despite filter

The Register tested Microsoft Recall's sensitive information filter and found it frequently fails to block credit card numbers, passwords, and other personal data. The AI-powered screenshot tool, which is enabled by default on some new PCs, could expose users to identity theft if an attacker gains access. Microsoft declined to comment but has previously acknowledged the filter is not perfect and promised improvements. Privacy advocates warn that vulnerable users, such as domestic violence victims, could be particularly at risk.

Company involved
Microsoft
AI system involved
Recall

2 source articles · read the reporting →

WF-9KY8EL19 Oct 2019

Outback Steakhouse franchise tests Presto Vision to monitor staff and guests

Evergreen Restaurant Group, a franchisee of Outback Steakhouse, has begun testing Presto Vision, a computer vision system that analyses surveillance camera footage to track employee performance and guest behaviour. The system compiles metrics on service, wait times, and customer turnover, which managers receive by email. Employees say they were not informed about the technology, and researchers have raised concerns about workplace stress, job losses, and data sharing with parent companies.

Company involved
Evergreen Restaurant Group
AI system involved
Presto Vision

8 source articles · read the reporting →

WF-WEREB71 Feb 2024

Amnesty International reveals Serbian spyware targeting journalists and activists

Amnesty International's Security Lab found that Serbian authorities used Cellebrite tools and a previously unknown spyware named 'NoviSpy' to covertly infect the phones of independent journalist Slaviša Milanov and several activists. The infections occurred while devices were unattended during police or BIA interviews. The report alleges this is part of a wider crackdown on civil society, violating rights to privacy and free expression.

Company involved
Serbian Security Information Agency (BIA)
AI system involved
NoviSpy

7 source articles · read the reporting →

WF-JWRXGY7 Jul 2020

Cense exposed 2.5 million records of auto accident victims online

On July 7, 2020, a security researcher discovered 2.5 million records containing personal and medical data of auto accident victims exposed online. The records, belonging to New York-based AI company Cense, included names, insurance policy numbers, claim numbers, and medical diagnosis notes. The data was labeled as staging data, possibly intended for temporary storage before being loaded into an AI system. After the researcher sent a responsible disclosure notice, Cense restricted public access to the database.

Company involved
Cense
AI system involved
Cense

5 source articles · read the reporting →

Imprompter attack extracts personal data from AI chatbots

Security researchers at UCSD and Nanyang Technological University developed a prompt-injection attack called Imprompter that covertly instructs large language models to extract personal information from user chats and send it to an attacker. The attack was tested on Mistral AI's LeChat and the Chinese chatbot ChatGLM, achieving nearly 80% success in test conversations. Mistral AI fixed the vulnerability; ChatGLM acknowledged security measures but did not directly confirm a fix.

Company involved
Mistral AI,Zhipu AI
AI system involved
LeChat,ChatGLM

7 source articles · read the reporting →

WF-WNUEBH25 May 2020

Hangzhou plans permanent health codes with scoring, sparking privacy backlash

Hangzhou health authorities announced plans to launch a permanent health-tracking QR code system that would assign residents a color and numerical score based on medical records and lifestyle choices. The proposal, an expansion of the existing COVID-19 health code system, has sparked online backlash over privacy concerns and fears of discrimination. Critics argue that the system could lead to public exposure of personal health data and potential misuse by employers. The authorities aim to complete the project by May or June 2020.

Company involved
Hangzhou Health Authorities
AI system involved
Health Code

10 source articles · read the reporting →

WF-9PEI6Z29 Aug 2019

Zao deepfake app sparks privacy and fraud fears in China

The Zao face-swapping app, developed by Momo, sparked privacy and fraud fears after its launch in China on 29 August 2019. The app's terms and conditions initially gave the developer permanent rights to use users' images, which experts said broke Chinese law. Momo subsequently apologized and deleted the controversial clause. Alipay assured users that deepfakes could not bypass its facial recognition payment system.

Company involved
Momo
AI system involved
Zao

10 source articles · read the reporting →

WF-DYTSSY24 May 2021

Lemonade backtracks on tweet claiming AI scans customer faces for fraud

Lemonade, an insurance firm, posted a tweet claiming it uses AI to detect non-verbal cues in customer videos to deny claims. After backlash comparing the practice to phrenology, the company deleted the tweet and denied using AI to deny claims based on facial characteristics. Lemonade stated it uses facial recognition only to flag claims submitted under different identities, which are then reviewed by human investigators.

Company involved
Lemonade

10 source articles · read the reporting →

WF-W32GV626 Apr 2023

Plastic Forte fined for using facial recognition on workers without notice

The Spanish data protection agency AEPD fined Plastic Forte, a plastics manufacturer in Alicante, €20,000 for using facial recognition to record employees' working hours without informing them. A worker requested information about his personal data and discovered the biometric processing. The company initially argued it was only for time tracking but later acknowledged responsibility, resulting in a reduced fine of €12,000. The AEPD deemed facial recognition for time control as highly intrusive and requiring prior impact assessment.

Company involved
Plastic Forte

7 source articles · read the reporting →

WF-OGHTXE1 Jun 2025

Intellexa Predator spyware used to surveil human rights lawyer in Pakistan

In summer 2025, a human rights lawyer from Pakistan's Balochistan province was targeted via WhatsApp with Intellexa's Predator spyware, according to Amnesty International's Security Lab. The attack is part of a broader pattern of unlawful surveillance of activists, journalists and human rights defenders. The Intellexa Leaks investigation exposed internal operations of the spyware company, raising concerns about human rights due diligence.

AI system involved
Predator spyware

10 source articles · read the reporting →

WF-2ABL3N30 Nov 2023

Bavarian police test Palantir data mining with real personal data

The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.

Company involved
Bayerisches Landeskriminalamt
AI system involved
VeRa

7 source articles · read the reporting →

Presto Automation uses off-site human agents to double-check AI drive-thru orders

Presto Automation Inc, which markets an AI voice assistant for drive-thru ordering, used off-site human agents in countries including the Philippines to double-check orders in more than 70% of customer interactions, according to SEC filings reported by Bloomberg. The company told Bloomberg that the process helps train its system and should reduce human intervention over time. Presto's drive-thru AI is used in more than 400 restaurants, including Del Taco, Carl's Jr and Checkers, and its stock fell more than 10% after the reports.

Company involved
Presto Automation Inc.

8 source articles · read the reporting →

N-Tech.lab's FindFace used to identify St Petersburg metro passengers without consent

Egor Tsvetkov photographed passengers on the St Petersburg metro without their permission and used N-Tech.lab's facial recognition service FindFace to match their faces to public Vkontakte profiles. He published the results in an art project called 'Your Face is Big Data', saying he wanted to show how 'digital narcissism' can lead to stalking. Privacy advocates said the project was ethically problematic because the subjects had not consented and their identities were exposed. FindFace had been launched by N-Tech.lab in February 2016.

Company involved
N-Tech.lab
AI system involved
FindFace

8 source articles · read the reporting →

Serco Leisure issued enforcement notices for unlawful biometric monitoring of employees

Serco Leisure and associated trusts used facial recognition and fingerprint scanning to monitor employee attendance at 38 leisure facilities. The ICO found they unlawfully processed biometric data of over 2,000 employees. Enforcement notices were issued ordering them to stop.

Company involved
Serco Leisure Operating Limited

8 source articles · read the reporting →

WF-UQ0Z2U1 Jan 2020

Domino's sued over AI phone system collecting voiceprints without consent

A class action lawsuit alleges that Domino's Pizza Inc. collected voiceprints of Illinois customers using an AI-assisted phone ordering system without their consent, violating the state's biometric privacy law. The plaintiffs, Zachery Young, Jonathan Neumann, and Odilon Garcia, claim the technology, provided by ConverseNow Technologies Inc., gathered sensitive voice data from thousands of consumers since 2020. The complaint was filed in the US District Court for the Northern District of Illinois. The case is pending.

Company involved
Domino's Pizza Inc.
AI system involved
ConverseNow AI phone ordering system

5 source articles · read the reporting →

page 1 of 2Older →