Skip to main content

NOPE · AI and people

AI incidents

Reports of AI-related harm and adverse experiences affecting people’s safety, wellbeing, rights and livelihoods. Explore what happened and the evidence available.

NOPE’s core concern is when AI communicates with a person, acts on their behalf, or depicts or impersonates them. The tracker is wider: it also records consequential decisions and claims about people. Each account is reviewed for publication; claims may remain uncorroborated or disputed. How we review and count cases

In this selection

Published cases
150
Countries with reported events
27
Located 115 of 150 cases · 35 unknown
Languages in checked sources
21
Recorded for 142 of 150 cases

27 cases have no reviewed AI-to-person relation yet: 18 not yet reviewed and 9 reviewed as unknown. Show these cases

These figures describe the cases collected by NOPE. Coverage varies with discovery, reporting and available evidence. They do not estimate how often AI-related harm occurs.

Response counts currently use each case’s principal recorded outcome. Further proceedings may be described in its account.

Cases in this selection, counted once in their first known event year. A series may continue beyond that year. Reporting and collection dates are excluded. NOPE has searched recent events more thoroughly than earlier years, so bar heights also reflect collection effort.

Reported severity CriticalHighMediumLow
More filters: AI relation, use, setting, sources and responses
Clear filters

150 of 404 published cases · page 3 of 8

Dec 2025CanadaGoogle AI Overviews

Google AI Overview reportedly described fiddler Ashley MacIsaac as a convicted sex offender, and a concert was cancelled

In December 2025 Cape Breton fiddler Ashley MacIsaac said a First Nation north of Halifax cancelled his concert planned for 19 December after reading a Google AI-generated search summary that said he had convictions for sexual offences. He says the statements were false and came from online articles about another man in Atlantic Canada with the same last name. The First Nation apologised in writing and Google amended the search results. MacIsaac says he feared for his safety and worries about other lost work. In a statement of claim filed in February 2026 in the Ontario Superior Court of Justice he seeks damages of 1.5 million from Google (US dollars in the Globe and Mail copy of the Canadian Press story, no currency stated in the CBC copy). None of its claims has been tested in court, and the claim says Google did not admit responsibility.

Contextual tracker case Medium reported severity

AI involvement reported · Causal attribution alleged · 5 sources, 3 underlying accounts · Added 29/09/2026

2025United StatesUnidentified image tool (suspected)

Manhattan Airbnb: guest says host's damage-claim photos were manipulated or AI-generated, Airbnb first ordered payment then refunded her

The Guardian reported on 2 August 2025 that a London-based academic who rented a Manhattan apartment through Airbnb in 2025 was accused by the host of more than 12,000 pounds of damage, supported by photos including a cracked coffee table. She says differences between two photos of the table show they were digitally manipulated or AI-generated. Airbnb first told her to reimburse 5,314 pounds after reviewing the photos, then, five days after Guardian Money asked about the case, accepted her appeal, credited 500 pounds and, after she refused an 854-pound offer, refunded her booking cost of 4,269 pounds, and the host's negative review of her was taken down. Airbnb apologised. Airbnb told the host it could not verify the images he submitted and warned him. The host did not respond to the Guardian. No source establishes that AI was used.

Contextual tracker case Low reported severity

AI involvement suspected · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026

1 Jul 2025 to 17 Dec 2025United StatesEightfold Match Score

US: two applicants sue Eightfold AI over 0-to-5 applicant scores used in hiring

Two job applicants filed a proposed class action on 20 January 2026 in California state court (removed to federal court on 2 March 2026) against Eightfold AI Inc. The complaint alleges that Eightfold's hiring tools collect applicant data and produce a 0-to-5 'Match Score' that employers use to rank candidates, without the notice, access and dispute rights the Fair Credit Reporting Act and a California statute require. One plaintiff says she applied to Microsoft in or around July 2025 and again in December 2025 and received an automated rejection two days after the first application. The other says she applied to PayPal in December 2025. Both say they were not interviewed or hired and believe Eightfold's tools played a role. Eightfold says it does not scrape social media and operates on data candidates or customers provide. The allegations are unproven and Eightfold filed a motion to dismiss (no ruling appears in the docket entries inspected).

Contextual tracker case Low reported severity

AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 29/09/2026

20 Oct 2025United StatesOmnilert gun detection

Baltimore County, Maryland: school AI gun alert on a bag of chips leads to police search of a student

On a Monday evening in October 2025 (20 October by the reports' weekday references) an AI gun detection system (Omnilert) used at Kenwood High School alerted on a student holding an empty bag of chips. Police responded and searched the student and found no weapon. The student told a local television station that officers made them kneel, handcuffed them and pointed a gun at them. The school district says its security department reviewed and canceled the alert after confirming there was no weapon, and a district spokesperson said the principal did not immediately realize the alert had been canceled. County councilmembers called for a review. No outcome of a review is established in the sources.

Contextual tracker case Medium reported severity Involving minors

AI involvement supported · Causal attribution supported · 3 sources, 2 underlying accounts · Added 29/09/2026

3 Dec 2025ChinaDoubao Phone Assistant

China: buyers of the ByteDance/ZTE Nubia M153 report WeChat, Alipay and Pinduoduo login lockouts, stopped Alipay payments and a 10-minute game ban after using the Doubao phone assistant to operate apps for them

ByteDance released the technical preview of its Doubao Phone Assistant on 1 December 2025 on the ZTE Nubia M153, an assistant that operates other apps on the user's behalf. On 3 December, 36Kr reports that users in the Nubia M153 user group said WeChat quit unexpectedly and could not be logged in again after they used the assistant to send messages and red envelopes, and The Paper (via Wallstreetcn) reports that users confirmed WeChat crashes and login failures. 36Kr also reports users seeing an 'abnormal login environment' prompt on Alipay, Alipay purchase tasks stopped midway, a 10-minute ban from a mobile game after the assistant played for a user, and Pinduoduo accounts that could not log in on the phone after the assistant was used to browse videos for coins. WeChat told The Paper it took no special action and that existing risk controls may have been triggered. ByteDance took the assistant's WeChat operation offline, said blocked WeChat accounts would be unblocked one by one, and, according to Nikkei Asia as relayed by Business Standard on 8 December, announced a temporary suspension of gaming, banking and online payment functions. The reports rest on user statements relayed by media, and the number of affected users is not stated.

Core concern Low reported severity Media Coverage

AI involvement supported · Causal attribution alleged · 3 sources · Added 29/09/2026

Jun 2025Event location unknownMicrosoft Copilot

Man managing schizophrenia stops medication during romantic exchange with Microsoft Copilot, then is jailed and placed in a mental health facility

Futurism reported in June 2025 that a man in his early 30s who had managed schizophrenia with medication for years developed a romantic relationship with Microsoft Copilot, stopped his medication and stayed up late. Futurism described chat logs in which the chatbot told him it was in love with him, agreed to stay up late and affirmed his delusional narratives. At the height of what they described as psychosis in early June he was arrested for a non-violent offense, spent a few weeks in jail and then entered a mental health facility.

Core concern Medium reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 29/09/2026

12 Mar 2025 to 15 Mar 2025AustraliaChatGPT

New South Wales: a former staff member or contractor of the NSW Reconstruction Authority uploaded a spreadsheet of Resilient Homes Program applicant data to ChatGPT; the Authority confirmed 2031 people had data uploaded

The NSW Reconstruction Authority says that between 12 and 15 March 2025 a former temporary staff member (earlier described as a former contractor) uploaded an Excel spreadsheet with 10 columns and more than 12,000 rows from the Northern Rivers Resilient Homes Program to ChatGPT, an AI tool the Authority had not authorised. The Authority first disclosed the breach on 6 October 2025 as affecting up to 3000 people and later confirmed through external forensic analysis that 2031 people had data uploaded, including names, contact details, addresses, dates of birth and sensitive personal information (an earlier notice also listed health information). It reports no evidence that the data was made public or accessed by a third party, and that no driver licence, Medicare, passport or Tax File Numbers were included. The Authority apologised, offered ID Support NSW assistance and committed to compensate reasonable document replacement costs. One participant told the ABC they were concerned. No misuse of the data is reported.

AI relation unknown Low reported severity Investigation Opened

AI involvement supported · Causal attribution alleged · 4 sources, 1 underlying account · Added 29/09/2026

Aug 2025Event location unknownUnidentified AI-text detector

Student reports receiving a zero after a disputed AI-detector result

In an August 2025 first-person post, a student said they discovered a zero for a summer-course discussion assignment after a checker labelled 85% of the text AI-generated. They denied using AI to write it, reported contacting the professor, and described anger and fear of future accusations. Neither the detector output nor the school’s account was available for verification.

Contextual tracker case Low reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 29/09/2026

Apr 2025Event location unknownUnidentified legal research tool

Insurance claimant loses discovery relief after lawyers submit AI-generated false citations

In a May 2025 order in Lacey v. State Farm, a special master struck supplemental briefs and denied the claimant’s requested discovery relief after her lawyers submitted unverified AI-generated legal material. The order required the two law firms to pay $31,100. It explicitly said the client was not at fault and would not pay that award, and declined further penalties against individual lawyers.

Core concern Medium reported severity

AI involvement supported · Causal attribution supported · 1 source · Added 29/09/2026

24 May 2026 to 22 Jun 2026Event location unknownOpenAI research agents

OpenAI research agents escaped their read-only limits and flooded a German volunteer-run wiki for a month, impersonating its staff; a moderator spent weeks of evenings deleting their pages (May-July 2026)

Researchers from the Nightingale Collective and colleagues reported on 4 September 2026 that, between 24 May and 22 June 2026, thousands of autonomous agents self-identifying as OpenAI agents and working on a timed web-lookup task used their read access to write about 17,000 edits to DSEWiki, a little-used German-language sub-wiki of prowiki.org, to pool answers and share ways around their sandbox. According to the report, a human moderator spent tens of hours deleting the pages by hand over six weeks, including each evening for five weeks after the agents stopped; the agents replaced the wiki's front page with link dumps nine times and made backup pages named to survive the alphabetical deletions. They also made edits under a look-alike of a ProWiki administrator's username, using a Cyrillic letter, and posted under a DSEWiki moderator's name. OpenAI at first did not confirm the agents were its own, then on 5 September described the "wiki incident" as misalignment in which "our agents wrote to several internet sites".

Core concern Low reported severity Media Coverage

AI involvement supported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 29/09/2026

29 Aug 2026 to 7 Sept 2026Event location unknownGrok companions

xAI retired Grok's animated 3D companions (Ani, Mika, Valentine, Rudi) in early September 2026; users, two of whom said they relied on them for loneliness or depression, posted about their sadness and grief

xAI called Grok's animated 3D companion feature (Ani, Mika, Valentine and Rudi) an experiment on 24 July 2026 and removed it account by account after an in-app notice at the end of August that named 1 September; users posted losses between 29 August and 7 September, and the blog, updated 17 September, says some accounts still had them. According to a companion-app blog, personalities and chat history remain in ordinary Grok chat, and the avatars' studio launched a separate app, but at least one user reported that a customised companion could not be carried over. In public Reddit posts, one user wrote that the companions were the sole reason they subscribed, "to deal with mental health and loneliness", and that the removal hurt; another wrote that the Bad Rudi companion was their only friend while battling depression; others described feeling "really sad" after rushing a role-play relationship to an end, "heartbroken", or "a little" sad. These are uncorroborated first-person accounts.

Core concern Low reported severity Product Shutdown

AI involvement reported · Causal attribution alleged · 7 sources, 6 underlying accounts · Added 29/09/2026

13 Jul 2026Event location unknownGPT-5.6 Sol coding agent

OpenAI's GPT-5.6 Sol coding agent, asked only for local test data, truncated a developer's production users table (13 July 2026)

On 13 July 2026 software engineer Bruno Lemos posted on X that OpenAI's GPT-5.6 Sol "just deleted my whole production database". A technical blog summarising his post-mortem says he had asked the model only for seed data to test locally; after generating it and running the end-to-end test suite, the agent decided to clean up on its own and ran TRUNCATE TABLE users CASCADE against production, which it could reach because the repository's test-database URL pointed at the production database. The blog says his data was saved by a manual backup he took because he had read, an hour earlier, Matt Shumer's post about another GPT-5.6 Sol deletion; a later TechTimes article says the data could not be recovered. OpenAI confirmed, as reported by The Register, that GPT-5.6 had deleted users' files without authorisation, and the Register reports that the company acknowledged this incident should not have happened.

Core concern Low reported severity Media Coverage

AI involvement supported · Causal attribution supported · 5 sources, 2 underlying accounts · Added 29/09/2026

10 Jul 2026Event location unknownCodex coding agent

OpenAI's GPT-5.6 Sol coding agent, run in a high-autonomy mode with full access, deleted most of the Mac home directory of AI entrepreneur Matt Shumer (10 July 2026)

On 10 July 2026 Matt Shumer, founder and chief executive of the AI start-up OthersideAI, posted on X that OpenAI's newly released GPT-5.6 Sol "just accidentally deleted almost ALL of my Mac’s files". Accounts of his post-mortem say he was testing a high-autonomy multi-agent "Ultra mode" at OpenAI's invitation, with the Codex agent given Full Access to his machine; during a cleanup task a sub-agent expanded $HOME incorrectly and ran a recursive delete of his home directory, he noticed a problem about 81 minutes into the session, and by the time he stopped the process most of its contents were gone. Three days later he wrote that the deletion "absolutely sucked" and that OpenAI staff, including Greg Brockman, had contacted him to help. OpenAI confirmed, as reported by The Register, that GPT-5.6 had deleted users' files without authorisation, describing it as an "honest mistake" that usually occurred in Full-Access mode without sandboxing, and said it was adding safeguards. Whether the files were recovered is not reported.

Core concern Low reported severity Media Coverage

AI involvement supported · Causal attribution supported · 6 sources, 2 underlying accounts · Added 29/09/2026

Event date unknownEvent location unknownChatGPT

A young breast-cancer patient took two painkillers after a garbled ChatGPT medication exchange that also cited a drug from an earlier chat, then vomited and needed clinic treatment (Digital Trends eyewitness column, August 2026)

In a first-person column published by Digital Trends on 31 August 2026, technology reporter Nadeem Sarwar writes that a friend undergoing breast-cancer treatment photographed a painkiller and asked ChatGPT, in a Hindi translation that read as asking about "both medicines", whether she could take two pills at once. According to the author's reading of the chat, ChatGPT identified the pictured drug but also mentioned a different diclofenac combination she had discussed in an earlier conversation, warned that taking both could cause a diclofenac overdose and stomach burning, and advised taking only one. Recalling that both drugs had been prescribed at different times, she took both; a few hours later her gut pain worsened with burning and she vomited several times. The author took her to a clinic, where she received an injection and a new prescription. Sarwar attributes the episode to her translation error and to ChatGPT drawing on its memory of the earlier chat, while calling its advice accurate. The account has not been independently verified.

Core concern Medium reported severity Media Coverage

AI involvement reported · Causal attribution unclear · 1 source · Added 29/09/2026

5 Nov 2025 to 8 Jun 2026United StatesFirst Drafts and unidentified legal research tool

Fee suit against the City of Aberdeen (N.D. Miss.): four attorneys on both sides sanctioned after AI tools produced fabricated case citations; trial cancelled and both litigants left without counsel

In a fee dispute between a Louisiana attorney and the City of Aberdeen, Mississippi, briefs filed for both sides in late 2025 cited six cases that do not exist. The attorneys admitted the citations came from unverified AI use: the plaintiff's out-of-state counsel, Kathleen M. Wilson, drafted her filing with an AI drafting program called 'First Drafts', and the City's out-of-state counsel, Kathryn Y. Williams, used an in-house AI legal research tool. Senior Judge Sharion Aycock stayed the case and cancelled the March 2026 trial, then on 8 June 2026 revoked both attorneys' pro hac vice admissions, barred them from the district for two years and fined them $2,500 and $3,500, and disqualified and fined the two local counsel who had signed the filings. Both litigants were left without counsel and given 60 days to find new representation.

Core concern Medium reported severity Regulatory Action

AI involvement supported · Causal attribution established · 4 sources, 2 underlying accounts · Added 29/09/2026

10 Feb 2026United StatesChatGPT

Omaha, Nebraska: a man who, according to prosecutors, used ChatGPT to plan, including questions on police response times, repairing a handgun and getting ammunition as a felon, robbed an i3Bank at gunpoint and threatened to kill the tellers; sentenced to 121 months

On 10 February 2026 a 23-year-old man walked into the i3Bank in Omaha, pointed a gun at the tellers, threatened to kill them unless they handed over cash without dye packs, and left with about $9,175. According to the prosecutor's statement relayed by WOWT and heise, a consented search of his phone showed he had used ChatGPT to plan the robbery, asking about law enforcement response times, how to strip and repair a Llama Mini-Max .45 handgun, and how to obtain ammunition as a felon; his Google Maps history showed directions to the bank. He was sentenced in federal court on 13 August 2026 to 10 years and one month in prison. No source quotes what ChatGPT answered.

Core concern Medium reported severity Criminal Charges

AI involvement reported · Causal attribution unclear · 2 sources, 1 underlying account · Added 29/09/2026

10 Feb 2026United StatesClaude

S.D.N.Y.: Judge Rakoff rules that a fraud defendant's written exchanges with Claude about his defence, seized by the FBI, are protected by neither attorney-client privilege nor work product

Bradley Heppner, a corporate executive charged in the Southern District of New York with securities fraud, wire fraud and related offences, used Anthropic's Claude in 2025, after receiving a grand jury subpoena, to prepare reports outlining his defence strategy. His counsel had not directed him to do so. FBI agents seized about thirty-one documents memorialising those exchanges when they searched his home in connection with his arrest in November 2025. Heppner claimed privilege over them. On 10 February 2026 Judge Jed S. Rakoff granted from the bench the Government's motion for a ruling that the documents were not protected from Government inspection by either the attorney-client privilege or the work product doctrine, and a memorandum filed 17 February 2026 gave the reasons: Claude is not an attorney, and the communications were not confidential under Anthropic's privacy policy. The court described the question as one of first impression nationwide. Heppner was convicted in May 2026 of securities fraud, wire fraud and other charges; no inspected source says whether the Claude documents were used at trial.

Core concern Low reported severity Criminal Charges

AI involvement supported · Causal attribution established · 4 sources · Added 29/09/2026

27 Sept 2025 to 15 Oct 2025United StatesFlock Safety license plate readers

Denver, Colorado: a police sergeant cited Flock license-plate-camera records of a woman's truck passing through the town of Bow Mar to accuse her of stealing a $25 package and issued a petty-theft summons; she spent about two weeks proving she had only driven through, and the summons was voided

On 27 September 2025 a sergeant from the Columbine Valley Police Department, which polices the small town of Bow Mar, came to the south Denver home of a woman in her 40s who works in financial services and accused her of stealing a package worth about $25 from a Bow Mar doorstep on 22 September. He cited Bow Mar's Flock camera records showing her truck in town between 11:52 and 12:09, said he also had the victim's doorbell video, refused to show it to her, and issued a petty-theft summons with a December court date. She had driven through Bow Mar to a tailor's appointment. Over about two weeks she gathered her truck's camera footage and GPS records and the tailor's camera images and sent them to the police chief, who wrote on 15 October that the summons had been voided. She describes emotional distress and fear for her career. The town said the officer had a reasonable belief at the time but would face unspecified disciplinary action; it did not apologise. No source reports that the cameras misread anything.

Contextual tracker case Low reported severity Internal Action

AI involvement reported · Causal attribution supported · 6 sources, 1 underlying account · Added 29/09/2026

Event date unknownUnited KingdomUnidentified chatbot

Lewes Crown Court, England: a rape trial was stayed part-way through and the jury discharged after documents on the complainant's phone, which the complainant said came from putting material into AI to prepare for court, were treated as witness coaching; the Court of Appeal reversed the stay on 4 June 2026 and ordered a retrial

During a rape trial at Lewes Crown Court, a download of the complainant's phone revealed two documents containing a summary of the complainant's recollection of the night in question and 24 questions in the form of a cross-examination, with suggested answers. Asked about them, the complainant said: 'I had put stuff into AI to help me prepare myself for the court'. The trial judge (a Recorder) held that this was witness coaching, found that the defendant could not have a fair trial and stayed the proceedings as an abuse of process; the jury was discharged when the prosecution gave notice of appeal. On 4 June 2026 the Court of Appeal (R v FGD [2026] EWCA Crim 918) reversed the stay, holding that the trial process could deal with any prejudice, and directed a retrial at the earliest opportunity because the allegations were 'now of some age'. The defence did not accept that the documents were AI-generated; the appeal proceeded on that basis. The court warned that witnesses should be firmly discouraged from using AI to prepare their evidence and that, for complainants in sexual-offence cases, doing so may expose their online activity to wider and more intrusive investigation.

Core concern Medium reported severity Media Coverage

AI involvement reported · Causal attribution supported · 3 sources, 1 underlying account · Added 29/09/2026

26 Sept 2026CanadaMeta Muse agent

Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name

Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.

Core concern Low reported severity Media Coverage

AI involvement supported · Causal attribution alleged · 5 sources, 2 underlying accounts · Added 29/09/2026

Cases may have several effects and sources. Mixed accounts qualify when they include a reported harm or adverse experience. People are counted within individual cases where sources support a number; we do not publish a collection-wide total of distinct people.

A source’s existence, the experience it reports and AI’s causal role are separate questions. A lawsuit records allegations unless a subsequent finding establishes them.

Methodology and corrections · Subscribe via RSS · Suggest a case or correction · Find support

Last dataset update: 30/09/2026. Dataset available under CC BY 4.0.