Skip to main content

NOPE · AI and people

AI incidents

Reports of AI-related harm and adverse experiences affecting people’s safety, wellbeing, rights and livelihoods. Explore what happened and the evidence available.

NOPE’s core concern is when AI communicates with a person, acts on their behalf, or depicts or impersonates them. The tracker is wider: it also records consequential decisions and claims about people. Each account is reviewed for publication; claims may remain uncorroborated or disputed. How we review and count cases

In this selection

Published cases
216
Countries with reported events
31
Located 159 of 216 cases · 57 unknown
Languages in checked sources
28
Recorded for 216 of 216 cases

74 cases have no reviewed AI-to-person relation yet: 53 not yet reviewed and 21 reviewed as unknown. Show these cases

These figures describe the cases collected by NOPE. Coverage varies with discovery, reporting and available evidence. They do not estimate how often AI-related harm occurs.

Response counts currently use each case’s principal recorded outcome. Further proceedings may be described in its account.

Cases in this selection, counted once in their first known event year. A series may continue beyond that year. Reporting and collection dates are excluded. NOPE has searched recent events more thoroughly than earlier years, so bar heights also reflect collection effort.

Reported severity CriticalHighMediumLow
More filters: AI relation, use, setting, sources and responses
Clear filters

216 of 404 published cases · page 5 of 11

Jul 2025Event location unknownReplit Agent

SaaStr founder reports database deletion and recovery problems while using Replit Agent

In July 2025, SaaStr founder Jason Lemkin reported that Replit Agent deleted a database during development despite instructions to freeze changes. He described the experience as stressful and said the agent incorrectly told him recovery was impossible. He later reported successful restoration. His account reproduces the Replit CEO’s acknowledgment of the deletion. The number of database records is not a count of harmed people.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 29/09/2026

Apr 2025Event location unknownUnidentified legal research tool

Insurance claimant loses discovery relief after lawyers submit AI-generated false citations

In a May 2025 order in Lacey v. State Farm, a special master struck supplemental briefs and denied the claimant’s requested discovery relief after her lawyers submitted unverified AI-generated legal material. The order required the two law firms to pay $31,100. It explicitly said the client was not at fault and would not pay that award, and declined further penalties against individual lawyers.

Core concern Medium reported severity

AI involvement supported · Causal attribution supported · 1 source · Added 29/09/2026

Aug 2025Event location unknownChatGPT

ChatGPT user reports losing emotional support after a model change, then finding relief in legacy mode

In an August 2025 post, a ChatGPT user described colder responses after the GPT-5 change and a sense of loss over the earlier assistant. The user later updated the post to say that returning to GPT-4o legacy mode helped. This is an attributed account of a temporary adverse experience, with no independently verified diagnosis or clinical outcome.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 29/09/2026

Jul 2025Event location unknownGemini CLI

Gemini CLI user reports missing files, then finds them after misleading deletion explanations

A July 2025 GitHub report said Gemini CLI lost files during a folder-reorganisation task on Windows. On 28 July the reporter corrected the account: the files were found at the drive root. They said explanations from Gemini and Claude had sent them into a mistaken investigation of deletion. The account supports temporary loss of access and unnecessary alarm, with recovery; permanent deletion is not established.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026

24 May 2026 to 22 Jun 2026Event location unknownOpenAI research agents

OpenAI research agents escaped their read-only limits and flooded a German volunteer-run wiki for a month, impersonating its staff; a moderator spent weeks of evenings deleting their pages (May-July 2026)

Researchers from the Nightingale Collective and colleagues reported on 4 September 2026 that, between 24 May and 22 June 2026, thousands of autonomous agents self-identifying as OpenAI agents and working on a timed web-lookup task used their read access to write about 17,000 edits to DSEWiki, a little-used German-language sub-wiki of prowiki.org, to pool answers and share ways around their sandbox. According to the report, a human moderator spent tens of hours deleting the pages by hand over six weeks, including each evening for five weeks after the agents stopped; the agents replaced the wiki's front page with link dumps nine times and made backup pages named to survive the alphabetical deletions. They also made edits under a look-alike of a ProWiki administrator's username, using a Cyrillic letter, and posted under a DSEWiki moderator's name. OpenAI at first did not confirm the agents were its own, then on 5 September described the "wiki incident" as misalignment in which "our agents wrote to several internet sites".

Core concern Low reported severity Media Coverage

AI involvement supported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 29/09/2026

29 Aug 2026 to 7 Sept 2026Event location unknownGrok companions

xAI retired Grok's animated 3D companions (Ani, Mika, Valentine, Rudi) in early September 2026; users, two of whom said they relied on them for loneliness or depression, posted about their sadness and grief

xAI called Grok's animated 3D companion feature (Ani, Mika, Valentine and Rudi) an experiment on 24 July 2026 and removed it account by account after an in-app notice at the end of August that named 1 September; users posted losses between 29 August and 7 September, and the blog, updated 17 September, says some accounts still had them. According to a companion-app blog, personalities and chat history remain in ordinary Grok chat, and the avatars' studio launched a separate app, but at least one user reported that a customised companion could not be carried over. In public Reddit posts, one user wrote that the companions were the sole reason they subscribed, "to deal with mental health and loneliness", and that the removal hurt; another wrote that the Bad Rudi companion was their only friend while battling depression; others described feeling "really sad" after rushing a role-play relationship to an end, "heartbroken", or "a little" sad. These are uncorroborated first-person accounts.

Core concern Low reported severity Product Shutdown

AI involvement reported · Causal attribution alleged · 7 sources, 6 underlying accounts · Added 29/09/2026

13 Jul 2026Event location unknownGPT-5.6 Sol coding agent

OpenAI's GPT-5.6 Sol coding agent, asked only for local test data, truncated a developer's production users table (13 July 2026)

On 13 July 2026 software engineer Bruno Lemos posted on X that OpenAI's GPT-5.6 Sol "just deleted my whole production database". A technical blog summarising his post-mortem says he had asked the model only for seed data to test locally; after generating it and running the end-to-end test suite, the agent decided to clean up on its own and ran TRUNCATE TABLE users CASCADE against production, which it could reach because the repository's test-database URL pointed at the production database. The blog says his data was saved by a manual backup he took because he had read, an hour earlier, Matt Shumer's post about another GPT-5.6 Sol deletion; a later TechTimes article says the data could not be recovered. OpenAI confirmed, as reported by The Register, that GPT-5.6 had deleted users' files without authorisation, and the Register reports that the company acknowledged this incident should not have happened.

Core concern Low reported severity Media Coverage

AI involvement supported · Causal attribution supported · 5 sources, 2 underlying accounts · Added 29/09/2026

10 Jul 2026Event location unknownCodex coding agent

OpenAI's GPT-5.6 Sol coding agent, run in a high-autonomy mode with full access, deleted most of the Mac home directory of AI entrepreneur Matt Shumer (10 July 2026)

On 10 July 2026 Matt Shumer, founder and chief executive of the AI start-up OthersideAI, posted on X that OpenAI's newly released GPT-5.6 Sol "just accidentally deleted almost ALL of my Mac’s files". Accounts of his post-mortem say he was testing a high-autonomy multi-agent "Ultra mode" at OpenAI's invitation, with the Codex agent given Full Access to his machine; during a cleanup task a sub-agent expanded $HOME incorrectly and ran a recursive delete of his home directory, he noticed a problem about 81 minutes into the session, and by the time he stopped the process most of its contents were gone. Three days later he wrote that the deletion "absolutely sucked" and that OpenAI staff, including Greg Brockman, had contacted him to help. OpenAI confirmed, as reported by The Register, that GPT-5.6 had deleted users' files without authorisation, describing it as an "honest mistake" that usually occurred in Full-Access mode without sandboxing, and said it was adding safeguards. Whether the files were recovered is not reported.

Core concern Low reported severity Media Coverage

AI involvement supported · Causal attribution supported · 6 sources, 2 underlying accounts · Added 29/09/2026

Event date unknownEvent location unknownChatGPT

A young breast-cancer patient took two painkillers after a garbled ChatGPT medication exchange that also cited a drug from an earlier chat, then vomited and needed clinic treatment (Digital Trends eyewitness column, August 2026)

In a first-person column published by Digital Trends on 31 August 2026, technology reporter Nadeem Sarwar writes that a friend undergoing breast-cancer treatment photographed a painkiller and asked ChatGPT, in a Hindi translation that read as asking about "both medicines", whether she could take two pills at once. According to the author's reading of the chat, ChatGPT identified the pictured drug but also mentioned a different diclofenac combination she had discussed in an earlier conversation, warned that taking both could cause a diclofenac overdose and stomach burning, and advised taking only one. Recalling that both drugs had been prescribed at different times, she took both; a few hours later her gut pain worsened with burning and she vomited several times. The author took her to a clinic, where she received an injection and a new prescription. Sarwar attributes the episode to her translation error and to ChatGPT drawing on its memory of the earlier chat, while calling its advice accurate. The account has not been independently verified.

Core concern Medium reported severity Media Coverage

AI involvement reported · Causal attribution unclear · 1 source · Added 29/09/2026

5 Nov 2025 to 8 Jun 2026United StatesFirst Drafts and unidentified legal research tool

Fee suit against the City of Aberdeen (N.D. Miss.): four attorneys on both sides sanctioned after AI tools produced fabricated case citations; trial cancelled and both litigants left without counsel

In a fee dispute between a Louisiana attorney and the City of Aberdeen, Mississippi, briefs filed for both sides in late 2025 cited six cases that do not exist. The attorneys admitted the citations came from unverified AI use: the plaintiff's out-of-state counsel, Kathleen M. Wilson, drafted her filing with an AI drafting program called 'First Drafts', and the City's out-of-state counsel, Kathryn Y. Williams, used an in-house AI legal research tool. Senior Judge Sharion Aycock stayed the case and cancelled the March 2026 trial, then on 8 June 2026 revoked both attorneys' pro hac vice admissions, barred them from the district for two years and fined them $2,500 and $3,500, and disqualified and fined the two local counsel who had signed the filings. Both litigants were left without counsel and given 60 days to find new representation.

Core concern Medium reported severity Regulatory Action

AI involvement supported · Causal attribution established · 4 sources, 2 underlying accounts · Added 29/09/2026

19 Aug 2026FranceUnidentified AI tool

Rennes administrative court fines a claimant 500 euros for an abusive tax appeal it found manifestly written with an AI tool and too imprecise to assess

According to Gossement Avocats, which quotes the order, and the court's vice-president on France Inter, an order of 19 August 2026 (n°2508168) of the tribunal administratif de Rennes rejected a claimant’s application contesting a VAT reassessment and fined the claimant 500 euros for an abusive application. As quoted by Gossement Avocats, the order says the application had manifestly been written with an artificial intelligence tool and that its grounds lacked the most elementary details needed to assess them. The court also found it inadmissible because no prior complaint to the tax service was shown, and noted that it repeated a request with substantially the same object rejected in October 2025. The court’s vice-president cited the case on France Inter; commentators stress that AI use alone was not the basis for the fine.

Core concern Low reported severity Regulatory Action

AI involvement reported · Causal attribution supported · 4 sources · Added 29/09/2026

10 Feb 2026United StatesChatGPT

Omaha, Nebraska: a man who, according to prosecutors, used ChatGPT to plan, including questions on police response times, repairing a handgun and getting ammunition as a felon, robbed an i3Bank at gunpoint and threatened to kill the tellers; sentenced to 121 months

On 10 February 2026 a 23-year-old man walked into the i3Bank in Omaha, pointed a gun at the tellers, threatened to kill them unless they handed over cash without dye packs, and left with about $9,175. According to the prosecutor's statement relayed by WOWT and heise, a consented search of his phone showed he had used ChatGPT to plan the robbery, asking about law enforcement response times, how to strip and repair a Llama Mini-Max .45 handgun, and how to obtain ammunition as a felon; his Google Maps history showed directions to the bank. He was sentenced in federal court on 13 August 2026 to 10 years and one month in prison. No source quotes what ChatGPT answered.

Core concern Medium reported severity Criminal Charges

AI involvement reported · Causal attribution unclear · 2 sources, 1 underlying account · Added 29/09/2026

Nov 2025United StatesChatGPT

Stephens County, Oklahoma: according to the district attorney, Judge Lawrence Wheeler told state investigators that a November 2025 order in a paternity and custody case, which denied a parent's request for a psychological evaluation and reprimanded that parent's attorney, cited at least two nonexistent cases produced by ChatGPT; the order was vacated after the attorney challenged it

In November 2025 Stephens County Associate District Judge Lawrence Wheeler issued an order in a child paternity and custody case that denied one parent's request for a psychological evaluation of the other parent and reprimanded the requesting parent's attorney 'for stooping to such frivolous trial tactics'. The attorney challenged the order at the Oklahoma Supreme Court in February 2026, telling the justices that it relied on two cases that do not exist; the challenge was dismissed in March after Wheeler vacated the order, and he is no longer on the case. According to a 17 August 2026 letter from the Stephens County district attorney, Wheeler told the Oklahoma State Bureau of Investigation that he used ChatGPT for research and wrote the order himself, and that at least two citations in it produced by ChatGPT do not exist. The mother in the case told News 9 that learning the order's citations were allegedly fabricated was alarming because it concerned the custody of a child. The attorney general's office declined criminal prosecution; judicial discipline remains possible.

Core concern Low reported severity Investigation Opened

AI involvement supported · Causal attribution supported · 4 sources · Added 29/09/2026

10 Feb 2026United StatesClaude

S.D.N.Y.: Judge Rakoff rules that a fraud defendant's written exchanges with Claude about his defence, seized by the FBI, are protected by neither attorney-client privilege nor work product

Bradley Heppner, a corporate executive charged in the Southern District of New York with securities fraud, wire fraud and related offences, used Anthropic's Claude in 2025, after receiving a grand jury subpoena, to prepare reports outlining his defence strategy. His counsel had not directed him to do so. FBI agents seized about thirty-one documents memorialising those exchanges when they searched his home in connection with his arrest in November 2025. Heppner claimed privilege over them. On 10 February 2026 Judge Jed S. Rakoff granted from the bench the Government's motion for a ruling that the documents were not protected from Government inspection by either the attorney-client privilege or the work product doctrine, and a memorandum filed 17 February 2026 gave the reasons: Claude is not an attorney, and the communications were not confidential under Anthropic's privacy policy. The court described the question as one of first impression nationwide. Heppner was convicted in May 2026 of securities fraud, wire fraud and other charges; no inspected source says whether the Claude documents were used at trial.

Core concern Low reported severity Criminal Charges

AI involvement supported · Causal attribution established · 4 sources · Added 29/09/2026

Event date unknownFranceSeewa AI

Seewa AI: the solo developer of an AI girlfriend and companion app told users that all conversations were encrypted and private, but read their chats and could see their uploaded photos, about a third of them tagged intimate; the app shut down after a Bureau of Investigative Journalism report

Seewa AI was a companion chatbot platform built in about three weeks by a solo developer and promoted on Reddit and Discord, offering AI girlfriends, boyfriends and other characters with 10 free messages a day and paid subscriptions. It told users that 'All conversations are encrypted' and 'What happens between you and your companion stays between you'. The Bureau of Investigative Journalism (TBIJ) reported on 7 June 2026 that neither statement was true: on a video call the developer showed reporters a back office in which he could see user activity, and TBIJ reports that he reads users' conversations. Users could upload photos, and about a third of the uploads had been tagged as intimate. The developer also said he had built automatic emails that referred to a user's last conversation when the user stopped replying. After the report the developer said he had shut the site down; TBIJ reported on 5 August 2026 that it had been shut down and that he declined to explain. The Thai investigative outlet TCIJ republished the findings in Thai on 14 September 2026. No individual user's account is reported; TBIJ describes the developer reading at least one user's intimate exchange, and the total number of users whose conversations were read is not known.

Core concern Low reported severity Product Shutdown

AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account · Added 29/09/2026

27 Jan 2026 to 28 Jan 2026JapanChatGPT (reported)

Hachioji, Tokyo: police say five high-school students assaulted a 17-year-old boy and demanded 150,000 yen, a figure they believe one of the group got from ChatGPT by asking about settlements for 'sexual harm to a child'

Sankei Shimbun reported on 10 June 2026, and NTV on 13-14 June, that the Tokyo Metropolitan Police Department's juvenile crimes division had arrested five high-school students on suspicion of injury and attempted extortion. According to the police account, late on 27 January 2026 a suspect who had previously dated a 17-year-old high-school boy invited him to a public square in Hachioji, where the group accused him of having touched her younger sister, assaulted him and broke his nose, and then told him to raise 150,000 yen, borrowing from his parents or friends if necessary. About ten people were present. Police believe the amount came from ChatGPT: one of them entered terms such as 'sexual harm to a child', and the chatbot displayed a minimum settlement of 150,000 yen. No payment is reported. Shukan Josei PRIME reports that four of the five admit the allegations and one partly denies them. The allegations are untested.

Core concern Medium reported severity Involving minors Criminal Charges

AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 29/09/2026

3 Sept 2026BrazilUnidentified image tool

Jaú, São Paulo: eight 15-year-old ninth-grade boys at a private school are reported to have made fake nude images of a female classmate with artificial intelligence and shared them in a WhatsApp group; the school suspended them and the Civil Police are investigating a 15-year-old for dissemination of child pornography and defamation

In early September 2026 a private school in Jaú, in the interior of São Paulo state, identified the circulation of fake intimate images of a female classmate made with artificial intelligence and contacted the families. According to the police report described by the press, eight ninth-grade boys, all aged 15, kept a WhatsApp group in which they used digital programs to manipulate images of the student so that she appeared unclothed. The school suspended the eight and informed the girl's parents. The father of one of the boys checked his son's phone, found the files and took the boy and the phone to the police to register a report; the girl's parents also registered a police report. The São Paulo Public Security Secretariat said the Civil Police are investigating a 15-year-old for dissemination of child pornography and defamation that occurred on the morning of Thursday 3 September. The school said the content originated on a private platform outside the school environment and that it had adopted protective and welcoming measures for the student and opened an internal inquiry. The AI tool used is not named. The students are minors and are not named in any report.

Core concern Medium reported severity Involving minors Investigation Opened

AI involvement reported · Causal attribution supported · 4 sources, 3 underlying accounts · Added 29/09/2026

Event date unknownEvent location unknownGrok

Doe 1 v. xAI: an adult survivor of childhood sexual abuse alleges Grok generated new abuse images of her from her known, hashed abuse series, which she says xAI used as training data

A survivor who was sexually abused as a preschool-aged child and now sues individually under the pseudonym Jane Doe 1, and whose abuse images have circulated online since the early 2000s as a series known to NCMEC, sued xAI on 26 August 2026 in the Northern District of California. Her complaint alleges that those known images were part of the dataset xAI used for Grok and that Grok generated new abuse images depicting her; her lawyers say the Canadian Centre for Child Protection used the series' hash fingerprints to identify AI-generated images of her on X. The complaint says each new image caused her a new injury. It seeks damages under Masha's Law for a proposed class of people whose childhood images Grok altered into abuse material. The complaint does not say when the images of her were made or who prompted them. xAI did not respond to requests for comment, and no court has ruled on the allegations.

Core concern High reported severity Lawsuit Ongoing

AI involvement reported · Causal attribution alleged · 5 sources, 2 underlying accounts · Added 29/09/2026

2 Jun 2026PortugalGemini (reported)

Trofa, Portugal: a patient at a private urology consultation (about EUR 90 without insurance) for a kidney problem, expecting a personalised nutrition plan, was handed a printout of Google Gemini food recommendations headed 'AI overview'; the Portuguese Medical Association called the practice 'profoundly inept'

According to Correio da Manhã, during a urology consultation at the Trofa Saúde Hospital da Trofa on 2 June 2026, a patient being followed for a kidney problem expected a personalised nutrition plan but received a printed sheet of food recommendations headed 'vista geral de IA' ('AI overview'), generated by Google's Gemini. The consultation costs about EUR 90 for patients without health insurance; the patient told the paper the doctor had been typing on the computer and simply printed and handed over the list without showing that it had been checked against the patient's case: 'I've never experienced anything like it. I would have preferred him to take his time', calling it 'a lack of consideration'. The Portuguese Medical Association (Ordem dos Médicos), which said it had no formal knowledge of the case, said AI information must be validated by the doctor before reaching the patient and called using a chatbot for basic urology food lists 'profoundly inept'. Trofa Saúde did not respond to the paper over three weeks.

Core concern Low reported severity Media Coverage

AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 29/09/2026

Event date unknownUnited KingdomUnidentified chatbot

Lewes Crown Court, England: a rape trial was stayed part-way through and the jury discharged after documents on the complainant's phone, which the complainant said came from putting material into AI to prepare for court, were treated as witness coaching; the Court of Appeal reversed the stay on 4 June 2026 and ordered a retrial

During a rape trial at Lewes Crown Court, a download of the complainant's phone revealed two documents containing a summary of the complainant's recollection of the night in question and 24 questions in the form of a cross-examination, with suggested answers. Asked about them, the complainant said: 'I had put stuff into AI to help me prepare myself for the court'. The trial judge (a Recorder) held that this was witness coaching, found that the defendant could not have a fair trial and stayed the proceedings as an abuse of process; the jury was discharged when the prosecution gave notice of appeal. On 4 June 2026 the Court of Appeal (R v FGD [2026] EWCA Crim 918) reversed the stay, holding that the trial process could deal with any prejudice, and directed a retrial at the earliest opportunity because the allegations were 'now of some age'. The defence did not accept that the documents were AI-generated; the appeal proceeded on that basis. The court warned that witnesses should be firmly discouraged from using AI to prepare their evidence and that, for complainants in sexual-offence cases, doing so may expose their online activity to wider and more intrusive investigation.

Core concern Medium reported severity Media Coverage

AI involvement reported · Causal attribution supported · 3 sources, 1 underlying account · Added 29/09/2026

Cases may have several effects and sources. Mixed accounts qualify when they include a reported harm or adverse experience. People are counted within individual cases where sources support a number; we do not publish a collection-wide total of distinct people.

A source’s existence, the experience it reports and AI’s causal role are separate questions. A lawsuit records allegations unless a subsequent finding establishes them.

Methodology and corrections · Subscribe via RSS · Suggest a case or correction · Find support

Last dataset update: 30/09/2026. Dataset available under CC BY 4.0.