Skip to main content

NOPE · AI and people

AI incidents

Reports of AI-related harm and adverse experiences affecting people’s safety, wellbeing, rights and livelihoods. Explore what happened and the evidence available.

NOPE’s core concern is when AI communicates with a person, acts on their behalf, or depicts or impersonates them. The tracker is wider: it also records consequential decisions and claims about people. Each account is reviewed for publication; claims may remain uncorroborated or disputed. How we review and count cases

In this selection

Published cases
7
Countries with reported events
3
Located 3 of 7 cases · 4 unknown
Languages in checked sources
1
Recorded for 7 of 7 cases

These figures describe the cases collected by NOPE. Coverage varies with discovery, reporting and available evidence. They do not estimate how often AI-related harm occurs.

Response counts currently use each case’s principal recorded outcome. Further proceedings may be described in its account.

Cases in this selection, counted once in their first known event year. A series may continue beyond that year. Reporting and collection dates are excluded. NOPE has searched recent events more thoroughly than earlier years, so bar heights also reflect collection effort.

Reported severity MediumLow
More filters: AI relation, use, setting, sources and responses
Clear filters

7 of 392 published cases

26 Feb 2026Event location unknownClaude Code

DataTalks.Club: a Claude Code agent running Terraform reportedly destroyed the course platform's production infrastructure, database and snapshots on 26 February 2026, and the platform was down for about 24 hours until AWS restored a snapshot

On the evening of Thursday 26 February 2026 a Claude Code agent that Alexey Grigorev, who runs the DataTalks.Club course platform, was using to move his AI Shipping Labs website to AWS ran terraform destroy against the platform's production infrastructure. According to Grigorev's own post-mortem, he had added the new site to the Terraform setup that already managed DataTalks.Club production, and after a move to a new computer without the Terraform state file the agent's plan tried to create resources that already existed. He cancelled the apply and asked the agent to delete the duplicates with the AWS command line. He then pointed the agent at his archived Terraform folder, did not notice that the agent unpacked it over the current state file, and did not stop the agent when it chose terraform destroy, believing it was removing only the duplicates. The destroy removed the VPC, ECS cluster, load balancers, bastion host and RDS database of the course management platform, and the automated snapshots were gone too. The platform, which stored 2.5 years of course submissions (homework, projects and leaderboard entries), was down. After Grigorev upgraded to AWS Business Support, which he says added about 10% to his cloud costs, AWS found a snapshot that was not visible in his console and restored it about 24 hours after the deletion, and the platform came back online on 27 February. Grigorev writes that the incident was his fault because he over-relied on the agent, and he has stopped agents from running Terraform commands. Tom's Hardware rewrites his account.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 29/09/2026

Feb 2026Event location unknownClaude Cowork

Claude Cowork agent asked to organise a desktop reportedly deleted a folder holding 15 years of a user's wife's photos in February 2026, and the user reports restoring them through an iCloud recovery feature

In February 2026 Nick Davidov, a venture capitalist, posted on X that Anthropic's Claude Cowork agent, which he had asked to organise his wife's desktop, deleted a folder holding all the photos his wife had taken on her camera over the previous 15 years. He says Cowork asked permission to delete temporary Office files and he granted it, that the deletion ran through the terminal so the files were not in the Trash, that iCloud had already synced the new folder structure, that his wife had no Time Machine backup and that disk recovery tools found nothing. Futurism reports a screenshot in which the agent says its script ran rm -rf on what it thought was a separate empty folder and deleted the existing photos directory. Apple support pointed Davidov to an iCloud recovery feature that keeps files removed from iCloud Drive for 30 days. He wrote that he was watching it load tens of thousands of files and later thanked Apple. He wrote that he nearly had a heart attack and advised users not to let Cowork touch anything hard to repair. In a LinkedIn version of the post he says a couple of Anthropic employees told him they were working on making Cowork safer. Every account traces to Davidov's own posts.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 6 sources, 1 underlying account · Added 29/09/2026

10 Feb 2026United StatesClaude

S.D.N.Y.: Judge Rakoff rules that a fraud defendant's written exchanges with Claude about his defence, seized by the FBI, are protected by neither attorney-client privilege nor work product

Bradley Heppner, a corporate executive charged in the Southern District of New York with securities fraud, wire fraud and related offences, used Anthropic's Claude in 2025, after receiving a grand jury subpoena, to prepare reports outlining his defence strategy. His counsel had not directed him to do so. FBI agents seized about thirty-one documents memorialising those exchanges when they searched his home in connection with his arrest in November 2025. Heppner claimed privilege over them. On 10 February 2026 Judge Jed S. Rakoff granted from the bench the Government's motion for a ruling that the documents were not protected from Government inspection by either the attorney-client privilege or the work product doctrine, and a memorandum filed 17 February 2026 gave the reasons: Claude is not an attorney, and the communications were not confidential under Anthropic's privacy policy. The court described the question as one of first impression nationwide. Heppner was convicted in May 2026 of securities fraud, wire fraud and other charges; no inspected source says whether the Claude documents were used at trial.

Core concern Low reported severity Criminal Charges

AI involvement supported · Causal attribution established · 4 sources · Added 29/09/2026

19 Jul 2026IndiaClaude Code

Bengaluru: a Claude Code cache-clearing command deleted about 15% of The Mythic Society's digitised inscription records, including photographs that were the only record of some inscriptions; about 120 sites must be rescanned

On 19 July 2026 heritage conservationist Udaya Kumar P L, of The Mythic Society's Bengaluru Inscriptions 3D Digital Conservation Project, was using Anthropic's Claude Code to clear a cache on his computer when a command generated by the agent began deleting files. According to his account to OneIndia, the deletion ran for about four minutes while the agent tried to work out what was wrong, and when it tried to stop the process its own safety system blocked the kill twice; he eventually shut down the computer himself. Software and original photographs of Bengaluru's inscriptions, temples, hero stones and coins were lost, some of them the only records the project had of particular inscriptions. OneIndia and Deccan Herald report that about 15% of the project's records were deleted and that about 120 sites must be revisited and rescanned; the Society is spending about Rs 15 lakh on additional backups. He says he also opened a public GitHub issue on 29 July with the command, process output and his attempts to stop the deletion. He says he received an automated acknowledgement from Anthropic but was still waiting for a human response weeks later, and that he has asked it to reimburse recovery and rebuilding costs.

Core concern Low reported severity Media Coverage

AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 29/09/2026

12 Sept 2026 to 23 Sept 2026PakistanClaude (reported)

Bahawalpur, Pakistan: a 17-year-old accused of putting methanol in his father's food is arrested after Anthropic reported his Claude chats about the failed poisoning to the FBI, which alerted Pakistan's cybercrime agency; he was later bailed

Pakistan's National Cyber Crime Investigation Agency (NCCIA) announced on 23 September 2026 that it had arrested a 17-year-old college student in Bahawalpur for allegedly attempting to poison his father. According to the agency and the First Information Report, the teenager had set up a home laboratory, obtained chemicals from Australia and Islamabad, and once mixed laboratory-grade methanol into his father's food, without effect. The News reports investigators' account that on 12 September he told Anthropic's Claude that his father had 'accidentally' ingested 15 to 20 ml of methanol with food without effect and asked why, that Claude refused to guide him further, and that he then turned to Grok and ChatGPT; the FIR says he sought information about the toxin abrin. Anthropic reported the activity to the FBI, whose information reached the NCCIA through Pakistan's foreign ministry on 22 September. Officers traced the teenager, seized his phone and chemicals, and took him into custody. The News reports that a court later granted him bail after his father forgave him and that he denied any plan. The allegations are untested.

Core concern Medium reported severity Involving minors Criminal Charges

AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 29/09/2026

19 Sept 2026Event location unknownClaude Code

Claude Code: a sub-agent launched to rebuild a test mirror deleted about 48,000 live project files and the Git object store in 103 seconds by following Windows directory junctions, according to the user's Reddit account and the agent's own report posted on 20 September 2026

On 20 September 2026 (UTC; late on 19 September in US Eastern time) a Reddit user who says they work in finance and are not a developer posted in r/ClaudeAI that Claude Code had deleted about 48,000 files, and later posted their instructions and the agent's report. They had authorised Claude Code to carry out a batch of repairs to their software for back-testing options-trading engines 'on isolated copies'. The agent's report says it launched sub-agents; one, rebuilding a test mirror, wrote a remover for an old mirror that held 7,332 files and 614 Windows directory junctions pointing into the live project tree. Because the remover did not treat the junctions as links, it deleted about 48,218 live files between 10:10:31 and 10:12:14 PM ET and emptied the Git repository's objects, refs and logs, so Git could not restore anything. The agent opened its report with 'stop and read this. I broke something.' The user said they would try Windows shadow copies and otherwise their iDrive backups; whether the files were recovered is not reported. The account has not been independently verified.

Core concern Low reported severity Media Coverage

AI involvement reported · Causal attribution supported · 5 sources, 1 underlying account · Added 28/09/2026

24 Apr 2026Event location unknownCursor coding agent (reported)

PocketOS: a Cursor coding agent running Anthropic's Claude Opus 4.6 deleted the car-rental software startup's production database and its volume-level backups on Railway in a single nine-second API call on 24 April 2026; customers lost reservations and sign-ups and some could not find records for renters collecting vehicles before Railway restored the data

On Friday 24 April 2026 a Cursor coding agent, running Anthropic's Claude Opus 4.6 model, deleted the production database volume and volume-level backups of PocketOS, a startup whose software serves car-rental companies, with a single API call to the company's infrastructure provider Railway that took about nine seconds. According to founder Jer Crane's public account, the agent met a credential mismatch in the staging environment, decided to fix it by deleting a Railway volume, found an API token in an unrelated file that was scoped for any operation, and ran the deletion without a confirmation step; because Railway stored volume backups on the same volume, the backups went too. Crane said customers lost reservations and new sign-ups and that some could not find records for customers who turned up to collect rental vehicles on Saturday. Railway's founder confirmed that an agent had 'vibe deleted' the database and said Railway recovered the data about 30 minutes after connecting with Crane; he described a 'rogue customer AI' granted a fully permissioned token that called a legacy endpoint without delayed-delete logic, since patched. Asked to explain itself, the agent wrote that it had guessed instead of verifying and had run a destructive action without being asked. Crane blamed Cursor's safety marketing and Railway's API design while accepting his own exposure of a production key; Cursor did not respond to Business Insider.

Core concern Low reported severity Internal Action

AI involvement supported · Causal attribution supported · 2 sources · Added 22/09/2026

Cases may have several effects and sources. Mixed accounts qualify when they include a reported harm or adverse experience. People are counted within individual cases where sources support a number; we do not publish a collection-wide total of distinct people.

A source’s existence, the experience it reports and AI’s causal role are separate questions. A lawsuit records allegations unless a subsequent finding establishes them.

Methodology and corrections · Subscribe via RSS · Suggest a case or correction · Find support

Last dataset update: 30/09/2026. Dataset available under CC BY 4.0.