17 Apr 2026 to 31 May 2026Event location unknownMeta AI support assistant
Meta announced the rollout of its AI support assistant on Facebook and Instagram on 19 March 2026. Meta's filing with the Maine Attorney General (notice dated 5 June 2026) says unauthorized third parties exploited a vulnerability in its AI-assisted Instagram account recovery tool (High Touch Support) to receive password reset links for accounts they did not own, and the listing gives 17 April 2026 as the breach date and 31 May 2026 as the discovery date. Videos that attackers posted, as described by TechCrunch, 404 Media and Krebs on Security, show attackers asking the assistant in a chat to link a new email address to a target username. Reported victims include the security researcher Jane Manchun Wong, who posted that her password was changed without her knowledge, the Instagram account of the U.S. Space Force's Chief Master Sergeant, and the accounts of Sephora and a dormant Obama White House page (TechCrunch marks the last as disputed by Meta). Krebs and the BBC report pro-Iran defacement of some accounts, and TechCrunch reports that some victims were locked out and that short handles were offered for resale. The filing gives 20225 persons affected in total and 30 in Maine, and the notice calls the Maine figure an upper bound. Meta says the tool worked as intended, that a bug in a separate code path failed to check the email address, and (through a spokesperson to Gizmodo) that the failure was not due to the AI agent itself. Meta says it disabled the tool on 31 May 2026, the day it discovered the exploitation.
Contextual tracker case Low reported severity
AI involvement supported · Causal attribution disputed · 12 sources, 2 underlying accounts · Added 29/09/2026
1 Mar 2026IndiaAI roommate kitchen monitor (reported)
On 1 March 2026 a Bengaluru-based technology professional posted on X that he had deployed a home "AI roommate" (a kitchen camera with an AI vision model, which he said was Claude Haiku 4.5) that monitored his cook while she cooked, alerted him when she took anything and sent weekly reports. The post said the system "caught her red handed", that he "caught her twice this week" and that he had "just fired" her. Screenshots quoted by Hindustan Times show the bot listing apples and a banana as gone, reporting the cook eating blueberries, and giving hand-washing and cleaning observations. All coverage derives from the employer's post: the post carries no video, the cook's account is not reported and the alleged taking is unverified.
Contextual tracker case Medium reported severity
AI involvement reported · Causal attribution alleged · 4 sources, 1 underlying account · Added 29/09/2026
Mar 2025United StatesJewish Onliner (suspected)
In March 2025 Yale placed a Yale Law School scholar, who was deputy director of a Yale Law School project, on administrative leave and barred the scholar from campus. The New York Times reports the decision came three days after a news site described as powered at least in part by artificial intelligence published a story on the scholar's connections to Samidoun, a group on a US sanctions list. Inside Higher Ed and Middle East Eye identify the site as Jewish Onliner. The scholar's lawyer says Yale's general counsel named the article as the trigger of the investigation. The scholar told the Times of not being a member of any organization that would violate US law, and the lawyer says the scholar is not a member of Samidoun. A Yale Law School representative told The National that placing an employee on temporary administrative leave while a review is conducted is the appropriate process and that the scholar's short-term position was due to expire the following month. The site says humans fact-check and that AI tools play a significant role in its work. The inspected sources do not show that AI produced the article.
Contextual tracker case Medium reported severity
AI involvement suspected · Causal attribution alleged · 6 sources, 4 underlying accounts · Added 29/09/2026
2025United StatesUnidentified image tool (suspected)
The Guardian reported on 2 August 2025 that a London-based academic who rented a Manhattan apartment through Airbnb in 2025 was accused by the host of more than 12,000 pounds of damage, supported by photos including a cracked coffee table. She says differences between two photos of the table show they were digitally manipulated or AI-generated. Airbnb first told her to reimburse 5,314 pounds after reviewing the photos, then, five days after Guardian Money asked about the case, accepted her appeal, credited 500 pounds and, after she refused an 854-pound offer, refunded her booking cost of 4,269 pounds, and the host's negative review of her was taken down. Airbnb apologised. Airbnb told the host it could not verify the images he submitted and warned him. The host did not respond to the Guardian. No source establishes that AI was used.
Contextual tracker case Low reported severity
AI involvement suspected · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026
12 Mar 2025 to 3 Apr 2025United StatesChatGPT
In March and early April 2025 (the opinion gives no date for the ChatGPT step), a DOGE staff member working with the National Endowment for the Humanities (NEH) submitted short grant descriptions to ChatGPT with a prompt asking whether each project related at all to DEI, and the answers were combined with NEH staff ratings into lists of grants to terminate. More than 1,400 NEH grants (over $100 million) were terminated in notices sent 1 to 3 April 2025. A federal district court found the mass termination unlawful in May 2026 and described the ChatGPT step in its findings. Seven individual grantees who sued report lost or interrupted funding for their research and writing projects. The opinion does not state whether ChatGPT reviewed those seven grants.
Contextual tracker case Medium reported severity
AI involvement supported · Causal attribution unclear · 4 sources, 2 underlying accounts · Added 29/09/2026
Event date unknownEvent location unknownChatGPT
Barnevakten, a Norwegian child-safety organisation, reported on 23 September 2026 that one of its staff members was suddenly told by ChatGPT that their account was now in teen mode. ChatGPT's own pages, as described by Barnevakten, say the system turns the filter on when a user's behaviour indicates an age under 18, reducing sensitive or potentially harmful content (graphic violence, viral challenges, sexual or violent role-play, extreme beauty ideals) and offering parental controls and a study mode. Because there is no age check at sign-up, the system estimates age afterwards from conversation topics and times of use, and Barnevakten notes that such guesses can be wrong. An adult who wants out of teen mode can go through an age check run by the company Persona, which depending on the country asks for a real-time selfie and a government ID; Barnevakten questions whether that process is privacy-safe (Persona's terms mention retention of up to three years) and advises using only age checks one trusts. The account's own experience is limited to the unexpected switch and the verification route; no further consequence is described.
Core + contextual relations Low reported severity Media Coverage
AI involvement supported · Causal attribution supported · 1 source · Added 24/09/2026
Aug 2017United StatesDraftKings and FanDuel apps
Christopher Evans (Philadelphia; complaint filed 24 July 2026 in the Philadelphia Court of Common Pleas) and Michael Santos (Coatesville, Chester County; complaint filed 29 July 2026 in the Chester County Court of Common Pleas) sued DraftKings and its Pennsylvania affiliate; Santos also sued FanDuel and its parents. Both product-liability complaints, filed by the same law firm, allege that the defendants' sports-betting, daily-fantasy and casino apps are designed to addict, and that the companies 'utilize the combination of advanced technology and artificial intelligence paired with the tracking of personalized user data to intentionally addict users', operating 'AI-powered engagement platforms' (pleaded on information and belief) and, per DraftKings' 10-K as quoted, 'data science and machine learning' recommendation engines. Evans pleads that since about August 2017 he wagered over US$2.1 million with net losses of about US$81,000, received constant targeted promotions and personalised push notifications and a VIP account manager, developed depression and anxiety and was formally diagnosed with depression in 2020, stopped going outside, fell into debt, had his vehicle repossessed and separated from his wife. Santos pleads over US$1.164 million wagered on DraftKings with net losses of about US$58,000 plus small FanDuel losses, targeted advertising and a VIP manager who kept offering bonus bets after he said he wanted to stop, maxed-out credit cards, the forced sale of his house, diagnoses of depression and anxiety, suicidal ideation, and self-exclusion with the Pennsylvania Gaming Control Board in 2023. Both cases were removed to the U.S. District Court for the Eastern District of Pennsylvania on 16 September 2026 (2:26-cv-07168 and 2:26-cv-07176). The allegations are untested.
Contextual tracker case High reported severity Lawsuit Ongoing
AI involvement reported · Causal attribution alleged · 4 sources · Added 20/09/2026