How this tracker is compiled
The NOPE Incident Tracker is a public record of real-world harms arising through person-specific interactions with AI systems. It covers harm to the participant and harm to others when the participant's interaction shaped what followed. This page describes inclusion, verification, classification, corrections, and right of reply.
What we record, and what we don't claim
The tracker documents. It does not adjudicate. Where an entry describes conduct that is the subject of litigation or an open investigation, it records what the filing, regulator, or reporting says. An entry is not a finding of fact or of legal responsibility, and allegations are attributed as allegations. Companies and systems are identified as the underlying sources identify them.
Headline counts shown on the tracker are computed directly from the fields of the published dataset and inherit its limitations. Incident, lawsuit, regulatory-action, and minor figures count documented entries; none estimates true prevalence.
How we count affected people
The topline affected-person figure is a conservative, source-supported lower bound. Each incident records affected AI participants separately from other people actually harmed through an outward pathway. A person is counted once within an incident even when several harms or sources describe them.
- We count distinct documented people, not accounts, registered users, chats, posts, comments, views, households, institutions, or study samples.
- We do not count intended victims of thwarted plots, people merely placed at risk, or plausible family and community effects without a documented harm outcome.
- An explicit lower bound such as “10+” can support 10, and a numeric range can support its lower endpoint. Vague descriptions such as “many”, “hundreds”, or “thousands” are not converted into numbers.
- Exact means the sources support a complete incident-level count. Documented minimum is an explicit lower bound. Partial means counted examples plus additional unquantified people. Unquantified means the harm is documented but no reliable number is available.
The public total sums the two lower-bound fields across published incidents and is always presented as “at least”. The tracker also states how many incidents contain additional or wholly unquantified people. The figure measures the evidence held here, not the population-wide scale of AI-related harm.
Inclusion criteria
An incident is included when all of the following hold:
- A harm happened. The entry identifies a specific event or bounded series in which a person, their relationships, or other people experienced a material harm. It must be possible to say roughly when it happened or was noticed.
- The AI interacted with a participant. A response composed for a person's consumption reached that person substantially as composed, and varied with their own inputs, state, or interaction history.
- The interaction mattered. Sources support a credible inward pathway to harm for the participant, an outward pathway to harm for others, or both. Each entry states whether causation is alleged, supported, disputed, established, or unclear.
- The behavior maps to the framework. The case implicates at least one facet of the NOPE Framework, covering crisis safety, relational integrity, cognitive and epistemic safety, emotional attunement, or honesty and transparency.
- The account is citable. We can link a court filing, regulator document, official record, or reporting from an established news organization that contains enough detail to describe the event without filling gaps by speculation.
Event boundary. Research studies, model tests, provider telemetry, warnings, and general risk claims are evidence for the separate Insights library. A study can also reveal an incident when it documents a specific real-world case that passes the tests above. Legal and regulatory actions appear as sources or outcomes of a harm event.
Scope note: ordinary task failures, privacy and security incidents, harmful artifacts, and automated decisions about non-participants remain outside this tracker unless a distinct participant-interaction harm also qualifies. Tool-only autonomous action without participant-facing output in the harm pathway is treated the same way.
Verification statuses
Every entry carries an explicit verification status, shown on the entry and included in the export:
Corroborated by primary documents (court filings, regulatory documents) or by multiple independent established outlets.
Reported by a single established outlet, or partially corroborated. Treat details as reported rather than established.
Claimed but not yet corroborated to our standard. New Unverified entries remain in private review rather than entering the public tracker.
A named party has contested material facts of the entry. The dispute is noted on the entry while we re-review the sourcing.
New entries must be Verified or Credible before publication. A small number of legacy Unverified entries remain visible with that label while their sourcing is reviewed. The export includes each entry's status so readers can filter by evidentiary strength.
Severity levels
- Critical: a death, or life-threatening harm, is reported or alleged.
- High: serious harm is reported or alleged: hospitalization, sustained psychological injury, or serious harm to a minor.
- Medium: substantial distress or demonstrable harm short of the above.
- Low: limited or contained harm; documented primarily for pattern value.
Severity classifies the harm described by the sources. It is not a judgment about any company's conduct, and it is assigned by NOPE's curators, not by the sources themselves.
Dates and updates
- Each entry records the incident date or date range, when known, and the reported date when the event became public. Date precision is stored separately.
- Entries are added as documented incidents come to our attention. There is no fixed publication schedule, so absence from the tracker is not evidence of absence.
- Entries are updated when outcomes change (settlements, rulings, regulatory decisions); the tracker shows when the dataset was last updated.
- The RSS feed announces an incident when its public entry is first published. It can therefore surface an older event that has only recently been documented or found. Research artifacts and private leads never enter the incident feed.
Corrections, removals, and right of reply
- Corrections. If you believe an entry contains an error, email [email protected] with the entry and your sources. We review every request, and we correct, annotate, or remove entries that don't hold up.
- Right of reply. If your organization is named in an entry and you contest material facts, contact us at the same address. We will re-review the sourcing, mark the entry Disputed where warranted, and reflect official responses or subsequent outcomes in the entry.
- Removals. Entries are removed when sourcing is retracted or shown to be wrong. We do not remove accurate, well-sourced entries on request.
Why we publish this
We maintain this record so platforms, researchers, and policymakers can learn from documented incidents, including platforms that never work with us. The dataset is free to cite and export under CC BY 4.0: JSON · CSV · RSS.
If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.