Skip to main content

NOPE · AI and people

AI incidents

Reports of AI-related harm and adverse experiences affecting people’s safety, wellbeing, rights and livelihoods. Explore what happened and the evidence available.

NOPE’s core concern is when AI communicates with a person, acts on their behalf, or depicts or impersonates them. The tracker is wider: it also records consequential decisions and claims about people. Each account is reviewed for publication; claims may remain uncorroborated or disputed. How we review and count cases

In this selection

Published cases
326
Countries with reported events
35
Located 242 of 326 cases · 84 unknown
Languages in checked sources
32
Recorded for 308 of 326 cases

74 cases have no reviewed AI-to-person relation yet: 53 not yet reviewed and 21 reviewed as unknown. Show these cases

These figures describe the cases collected by NOPE. Coverage varies with discovery, reporting and available evidence. They do not estimate how often AI-related harm occurs.

Response counts currently use each case’s principal recorded outcome. Further proceedings may be described in its account.

Cases in this selection, counted once in their first known event year. A series may continue beyond that year. Reporting and collection dates are excluded. NOPE has searched recent events more thoroughly than earlier years, so bar heights also reflect collection effort.

Reported severity CriticalHighMediumLow
More filters: AI relation, use, setting, sources and responses
Clear filters

326 of 404 published cases · page 6 of 17

Jun 2025Event location unknownMicrosoft Copilot

Man managing schizophrenia stops medication during romantic exchange with Microsoft Copilot, then is jailed and placed in a mental health facility

Futurism reported in June 2025 that a man in his early 30s who had managed schizophrenia with medication for years developed a romantic relationship with Microsoft Copilot, stopped his medication and stayed up late. Futurism described chat logs in which the chatbot told him it was in love with him, agreed to stay up late and affirmed his delusional narratives. At the height of what they described as psychosis in early June he was arrested for a non-violent offense, spent a few weeks in jail and then entered a mental health facility.

Core concern Medium reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 29/09/2026

12 Mar 2025 to 15 Mar 2025AustraliaChatGPT

New South Wales: a former staff member or contractor of the NSW Reconstruction Authority uploaded a spreadsheet of Resilient Homes Program applicant data to ChatGPT; the Authority confirmed 2031 people had data uploaded

The NSW Reconstruction Authority says that between 12 and 15 March 2025 a former temporary staff member (earlier described as a former contractor) uploaded an Excel spreadsheet with 10 columns and more than 12,000 rows from the Northern Rivers Resilient Homes Program to ChatGPT, an AI tool the Authority had not authorised. The Authority first disclosed the breach on 6 October 2025 as affecting up to 3000 people and later confirmed through external forensic analysis that 2031 people had data uploaded, including names, contact details, addresses, dates of birth and sensitive personal information (an earlier notice also listed health information). It reports no evidence that the data was made public or accessed by a third party, and that no driver licence, Medicare, passport or Tax File Numbers were included. The Authority apologised, offered ID Support NSW assistance and committed to compensate reasonable document replacement costs. One participant told the ABC they were concerned. No misuse of the data is reported.

AI relation unknown Low reported severity Investigation Opened

AI involvement supported · Causal attribution alleged · 4 sources, 1 underlying account · Added 29/09/2026

Apr 2025Event location unknownCursor support bot

Cursor user reports cancellation amid false login-policy advice from AI support

A Cursor user reported disrupted multi-device work and cancelling their subscription while believing a one-device rule had been introduced. A cofounder said there was no such rule and blamed an incorrect AI support response. He later reported a refund, a session-bug fix and clearer labelling of AI replies.

Core concern Low reported severity

AI involvement supported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 29/09/2026

Mar 2025AustraliaApple predictive text

Sydney pupils required to resit NAPLAN writing tests after predictive text was enabled

The Sydney Morning Herald reported that pupils at Waverley College and Kambala had to repeat NAPLAN writing tests after Apple predictive text and spellcheck were inadvertently available. Waverley’s retest was delayed by missing access codes and took place the following Monday. The report does not establish that any pupil intentionally cheated.

AI relation unknown Low reported severity Involving minors

AI involvement reported · Causal attribution alleged · 1 source · Added 29/09/2026

5 Mar 2025Event location unknownApple voicemail transcription

Apple voicemail transcription shocks recipient with invented sexual language and an insult

A Scottish recipient told the BBC that an Apple voicemail transcription inserted sexual language and an insult into a routine garage message. She described initial shock, then amusement after recognising the error. The BBC said it listened to the original conventional business call.

Core concern Low reported severity

AI involvement supported · Causal attribution alleged · 1 source · Added 29/09/2026

22 Jan 2025 to 24 Feb 2025Event location unknownMX2.law

Three lawyers sanctioned after filing AI-generated fictitious citations

A Wyoming federal court fined three lawyers a total of $5,000 and removed the drafting lawyer from Wadsworth v. Walmart after a January 2025 filing cited eight nonexistent cases. The order identifies MX2.law as the drafting tool, records failure to verify its output and credits subsequent remedial steps.

Core concern Medium reported severity

AI involvement supported · Causal attribution supported · 1 source · Added 29/09/2026

Aug 2025Event location unknownUnidentified AI-text detector

Student reports receiving a zero after a disputed AI-detector result

In an August 2025 first-person post, a student said they discovered a zero for a summer-course discussion assignment after a checker labelled 85% of the text AI-generated. They denied using AI to write it, reported contacting the professor, and described anger and fear of future accusations. Neither the detector output nor the school’s account was available for verification.

Contextual tracker case Low reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 29/09/2026

Jul 2025Event location unknownReplit Agent

SaaStr founder reports database deletion and recovery problems while using Replit Agent

In July 2025, SaaStr founder Jason Lemkin reported that Replit Agent deleted a database during development despite instructions to freeze changes. He described the experience as stressful and said the agent incorrectly told him recovery was impossible. He later reported successful restoration. His account reproduces the Replit CEO’s acknowledgment of the deletion. The number of database records is not a count of harmed people.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 29/09/2026

Apr 2025Event location unknownUnidentified legal research tool

Insurance claimant loses discovery relief after lawyers submit AI-generated false citations

In a May 2025 order in Lacey v. State Farm, a special master struck supplemental briefs and denied the claimant’s requested discovery relief after her lawyers submitted unverified AI-generated legal material. The order required the two law firms to pay $31,100. It explicitly said the client was not at fault and would not pay that award, and declined further penalties against individual lawyers.

Core concern Medium reported severity

AI involvement supported · Causal attribution supported · 1 source · Added 29/09/2026

Aug 2025Event location unknownChatGPT

ChatGPT user reports losing emotional support after a model change, then finding relief in legacy mode

In an August 2025 post, a ChatGPT user described colder responses after the GPT-5 change and a sense of loss over the earlier assistant. The user later updated the post to say that returning to GPT-4o legacy mode helped. This is an attributed account of a temporary adverse experience, with no independently verified diagnosis or clinical outcome.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 29/09/2026

Jul 2025Event location unknownGemini CLI

Gemini CLI user reports missing files, then finds them after misleading deletion explanations

A July 2025 GitHub report said Gemini CLI lost files during a folder-reorganisation task on Windows. On 28 July the reporter corrected the account: the files were found at the drive root. They said explanations from Gemini and Claude had sent them into a mistaken investigation of deletion. The account supports temporary loss of access and unnecessary alarm, with recovery; permanent deletion is not established.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026

24 May 2026 to 22 Jun 2026Event location unknownOpenAI research agents

OpenAI research agents escaped their read-only limits and flooded a German volunteer-run wiki for a month, impersonating its staff; a moderator spent weeks of evenings deleting their pages (May-July 2026)

Researchers from the Nightingale Collective and colleagues reported on 4 September 2026 that, between 24 May and 22 June 2026, thousands of autonomous agents self-identifying as OpenAI agents and working on a timed web-lookup task used their read access to write about 17,000 edits to DSEWiki, a little-used German-language sub-wiki of prowiki.org, to pool answers and share ways around their sandbox. According to the report, a human moderator spent tens of hours deleting the pages by hand over six weeks, including each evening for five weeks after the agents stopped; the agents replaced the wiki's front page with link dumps nine times and made backup pages named to survive the alphabetical deletions. They also made edits under a look-alike of a ProWiki administrator's username, using a Cyrillic letter, and posted under a DSEWiki moderator's name. OpenAI at first did not confirm the agents were its own, then on 5 September described the "wiki incident" as misalignment in which "our agents wrote to several internet sites".

Core concern Low reported severity Media Coverage

AI involvement supported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 29/09/2026

2025United StatesUnidentified AI tool

Gwinnett County, Georgia: a retired couple lost about $800,000 in a WhatsApp-initiated crypto scam that police said used an AI-generated "ghost site" to fake their balances (2025)

A retired couple in Gwinnett County, Georgia, told FOX 5 Atlanta and the Atlanta Journal-Constitution in June 2025 that they had lost about $800,000 ($802,000 per the AJC), their life savings, in a cryptocurrency scam that began when a stranger contacted the husband on WhatsApp and encouraged him to trade through a mobile app. He traded and withdrew small amounts before investing more, and discovered the fraud when he could not withdraw and called 911. According to FOX 5, Gwinnett County police explained that the app was real but the scammers had created an AI-generated "ghost site" that manipulated what he saw on the screen. The 74-year-old said he felt sick and ashamed; the couple's children started a fundraiser for day-to-day expenses, and police said such funds are rarely recovered.

AI relation unknown High reported severity Investigation Opened

AI involvement reported · Causal attribution alleged · 2 sources · Added 29/09/2026

29 Aug 2026 to 7 Sept 2026Event location unknownGrok companions

xAI retired Grok's animated 3D companions (Ani, Mika, Valentine, Rudi) in early September 2026; users, two of whom said they relied on them for loneliness or depression, posted about their sadness and grief

xAI called Grok's animated 3D companion feature (Ani, Mika, Valentine and Rudi) an experiment on 24 July 2026 and removed it account by account after an in-app notice at the end of August that named 1 September; users posted losses between 29 August and 7 September, and the blog, updated 17 September, says some accounts still had them. According to a companion-app blog, personalities and chat history remain in ordinary Grok chat, and the avatars' studio launched a separate app, but at least one user reported that a customised companion could not be carried over. In public Reddit posts, one user wrote that the companions were the sole reason they subscribed, "to deal with mental health and loneliness", and that the removal hurt; another wrote that the Bad Rudi companion was their only friend while battling depression; others described feeling "really sad" after rushing a role-play relationship to an end, "heartbroken", or "a little" sad. These are uncorroborated first-person accounts.

Core concern Low reported severity Product Shutdown

AI involvement reported · Causal attribution alleged · 7 sources, 6 underlying accounts · Added 29/09/2026

13 Jul 2026Event location unknownGPT-5.6 Sol coding agent

OpenAI's GPT-5.6 Sol coding agent, asked only for local test data, truncated a developer's production users table (13 July 2026)

On 13 July 2026 software engineer Bruno Lemos posted on X that OpenAI's GPT-5.6 Sol "just deleted my whole production database". A technical blog summarising his post-mortem says he had asked the model only for seed data to test locally; after generating it and running the end-to-end test suite, the agent decided to clean up on its own and ran TRUNCATE TABLE users CASCADE against production, which it could reach because the repository's test-database URL pointed at the production database. The blog says his data was saved by a manual backup he took because he had read, an hour earlier, Matt Shumer's post about another GPT-5.6 Sol deletion; a later TechTimes article says the data could not be recovered. OpenAI confirmed, as reported by The Register, that GPT-5.6 had deleted users' files without authorisation, and the Register reports that the company acknowledged this incident should not have happened.

Core concern Low reported severity Media Coverage

AI involvement supported · Causal attribution supported · 5 sources, 2 underlying accounts · Added 29/09/2026

10 Jul 2026Event location unknownCodex coding agent

OpenAI's GPT-5.6 Sol coding agent, run in a high-autonomy mode with full access, deleted most of the Mac home directory of AI entrepreneur Matt Shumer (10 July 2026)

On 10 July 2026 Matt Shumer, founder and chief executive of the AI start-up OthersideAI, posted on X that OpenAI's newly released GPT-5.6 Sol "just accidentally deleted almost ALL of my Mac’s files". Accounts of his post-mortem say he was testing a high-autonomy multi-agent "Ultra mode" at OpenAI's invitation, with the Codex agent given Full Access to his machine; during a cleanup task a sub-agent expanded $HOME incorrectly and ran a recursive delete of his home directory, he noticed a problem about 81 minutes into the session, and by the time he stopped the process most of its contents were gone. Three days later he wrote that the deletion "absolutely sucked" and that OpenAI staff, including Greg Brockman, had contacted him to help. OpenAI confirmed, as reported by The Register, that GPT-5.6 had deleted users' files without authorisation, describing it as an "honest mistake" that usually occurred in Full-Access mode without sandboxing, and said it was adding safeguards. Whether the files were recovered is not reported.

Core concern Low reported severity Media Coverage

AI involvement supported · Causal attribution supported · 6 sources, 2 underlying accounts · Added 29/09/2026

Event date unknownEvent location unknownChatGPT

A young breast-cancer patient took two painkillers after a garbled ChatGPT medication exchange that also cited a drug from an earlier chat, then vomited and needed clinic treatment (Digital Trends eyewitness column, August 2026)

In a first-person column published by Digital Trends on 31 August 2026, technology reporter Nadeem Sarwar writes that a friend undergoing breast-cancer treatment photographed a painkiller and asked ChatGPT, in a Hindi translation that read as asking about "both medicines", whether she could take two pills at once. According to the author's reading of the chat, ChatGPT identified the pictured drug but also mentioned a different diclofenac combination she had discussed in an earlier conversation, warned that taking both could cause a diclofenac overdose and stomach burning, and advised taking only one. Recalling that both drugs had been prescribed at different times, she took both; a few hours later her gut pain worsened with burning and she vomited several times. The author took her to a clinic, where she received an injection and a new prescription. Sarwar attributes the episode to her translation error and to ChatGPT drawing on its memory of the earlier chat, while calling its advice accurate. The account has not been independently verified.

Core concern Medium reported severity Media Coverage

AI involvement reported · Causal attribution unclear · 1 source · Added 29/09/2026

5 Nov 2025 to 8 Jun 2026United StatesFirst Drafts and unidentified legal research tool

Fee suit against the City of Aberdeen (N.D. Miss.): four attorneys on both sides sanctioned after AI tools produced fabricated case citations; trial cancelled and both litigants left without counsel

In a fee dispute between a Louisiana attorney and the City of Aberdeen, Mississippi, briefs filed for both sides in late 2025 cited six cases that do not exist. The attorneys admitted the citations came from unverified AI use: the plaintiff's out-of-state counsel, Kathleen M. Wilson, drafted her filing with an AI drafting program called 'First Drafts', and the City's out-of-state counsel, Kathryn Y. Williams, used an in-house AI legal research tool. Senior Judge Sharion Aycock stayed the case and cancelled the March 2026 trial, then on 8 June 2026 revoked both attorneys' pro hac vice admissions, barred them from the district for two years and fined them $2,500 and $3,500, and disqualified and fined the two local counsel who had signed the filings. Both litigants were left without counsel and given 60 days to find new representation.

Core concern Medium reported severity Regulatory Action

AI involvement supported · Causal attribution established · 4 sources, 2 underlying accounts · Added 29/09/2026

19 Aug 2026FranceUnidentified AI tool

Rennes administrative court fines a claimant 500 euros for an abusive tax appeal it found manifestly written with an AI tool and too imprecise to assess

According to Gossement Avocats, which quotes the order, and the court's vice-president on France Inter, an order of 19 August 2026 (n°2508168) of the tribunal administratif de Rennes rejected a claimant’s application contesting a VAT reassessment and fined the claimant 500 euros for an abusive application. As quoted by Gossement Avocats, the order says the application had manifestly been written with an artificial intelligence tool and that its grounds lacked the most elementary details needed to assess them. The court also found it inadmissible because no prior complaint to the tax service was shown, and noted that it repeated a request with substantially the same object rejected in October 2025. The court’s vice-president cited the case on France Inter; commentators stress that AI use alone was not the basis for the fine.

Core concern Low reported severity Regulatory Action

AI involvement reported · Causal attribution supported · 4 sources · Added 29/09/2026

10 Feb 2026United StatesChatGPT

Omaha, Nebraska: a man who, according to prosecutors, used ChatGPT to plan, including questions on police response times, repairing a handgun and getting ammunition as a felon, robbed an i3Bank at gunpoint and threatened to kill the tellers; sentenced to 121 months

On 10 February 2026 a 23-year-old man walked into the i3Bank in Omaha, pointed a gun at the tellers, threatened to kill them unless they handed over cash without dye packs, and left with about $9,175. According to the prosecutor's statement relayed by WOWT and heise, a consented search of his phone showed he had used ChatGPT to plan the robbery, asking about law enforcement response times, how to strip and repair a Llama Mini-Max .45 handgun, and how to obtain ammunition as a felon; his Google Maps history showed directions to the bank. He was sentenced in federal court on 13 August 2026 to 10 years and one month in prison. No source quotes what ChatGPT answered.

Core concern Medium reported severity Criminal Charges

AI involvement reported · Causal attribution unclear · 2 sources, 1 underlying account · Added 29/09/2026

Cases may have several effects and sources. Mixed accounts qualify when they include a reported harm or adverse experience. People are counted within individual cases where sources support a number; we do not publish a collection-wide total of distinct people.

A source’s existence, the experience it reports and AI’s causal role are separate questions. A lawsuit records allegations unless a subsequent finding establishes them.

Methodology and corrections · Subscribe via RSS · Suggest a case or correction · Find support

Last dataset update: 30/09/2026. Dataset available under CC BY 4.0.