Skip to main content

NOPE · AI and people

AI incidents

Reports of AI-related harm and adverse experiences affecting people’s safety, wellbeing, rights and livelihoods. Explore what happened and the evidence available.

NOPE’s core concern is when AI communicates with a person, acts on their behalf, or depicts or impersonates them. The tracker also records consequential decisions, claims and privacy harms involving AI. Each case needs a described connection between AI use and the harm, including private information recorded into or disclosed to an AI service. Each account is reviewed for publication; claims may remain uncorroborated or disputed. How we review and count cases

In this selection

Published cases
8
Countries with reported events
1
Located 1 of 8 cases · 7 unknown
Languages in checked sources
1
Recorded for 8 of 8 cases

These figures describe the cases collected by NOPE. Coverage varies with discovery, reporting and available evidence. They do not estimate how often AI-related harm occurs.

Response counts currently use each case’s principal recorded outcome. Further proceedings may be described in its account.

Cases in this selection, counted once in their first known event year. A series may continue beyond that year. Reporting and collection dates are excluded. NOPE has searched recent events more thoroughly than earlier years, so bar heights also reflect collection effort.

Reported severity MediumLow
More filters: AI relation, use, setting, sources and responses
Clear filters

8 of 585 published cases

6 Oct 2026Event location unknownClaude Code (reported)

Developer says a hands-free Claude Code session on Opus 5.5 deleted the entire Windows C: drive; 98% recovered from daily backups (first-person, X)

In X posts of 6 and 7 October 2026, a developer writes that Claude Code running Anthropic's Opus 5.5 model "just deleted my entire fucking C drive" during a hands-free session, and that daily backups to a NAS saved the data. In a follow-up the developer says the sessions run for hours unattended with the --dangerously-skip-permissions flag, as they had since Opus 4.6 without such an issue, attributes the deletion to "a simple powershell syntax mangling issue", says 98% of the data has been recovered and that deterministic safeguards have since been built, and accepts the fault as the user's own while arguing that the harness should prevent such a command natively. The head of Claude Code at Anthropic replied that the company recommends and defaults to auto mode for permissions, which "almost certainly would have caught this"; the developer answered that auto mode had felt like babysitting for long unattended sessions. The account is the developer's own. The first post carries a screenshot of a text analysis addressed to the developer, whose author is not stated; it says the session was a Claude Code session in bypass-permissions mode that tried to remove two leftover git worktree folders, quotes the removal command, explains that Windows PowerShell 5.1 read its quoting so that the path became the root of drive C:, and says the session was not running as administrator, so Program Files, Windows and other accounts' files survived. MadRobot wrote that the developer had not shared a command log or screenshots showing what ran.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 10/10/2026

3 Oct 2026Event location unknownCursor coding agent

Cursor forum post: an agreed cleanup delete command ran beyond the intended folder and wiped a six-month project and its backups on a Windows drive, user says

In a bug report posted to the Cursor community forum on 3 October 2026, a user says that during a clean-up of a .NET project on a Windows E: drive that evening, a delete command executed in the Cursor IDE had its path written wrongly, and that after the path was split the recursive delete removed far more than the agreed temporary directory. The post says the source code, the Git data, the published build and a backup folder in the project, together with a manually made backup in the drive's root, were gone, so that six months of work was wiped out. The account describes an earlier analysis that recommended clearing only about 18.5 GB of compilation temporaries and the user agreeing to that batch. Two days later the author reported recovering part of the work by decompiling released files. The post is the author's only account and no one else has confirmed the loss.

Core concern Medium reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 08/10/2026

30 Sept 2026Event location unknownGoogle Antigravity (suspected)

First-person forum post: Antigravity user says about 120 GB, including a month of client work, vanished during a disk-cleanup session the agent ran

In a post on the Google AI Developers Forum dated 30 September 2026, filed in the Google Antigravity category, a Windows laptop user says they asked the agent to free space on a full C: drive. By their account the agent deleted a folder of about 50 GB of recovered videos and turned off hibernation, they then asked it to turn hibernation back on, their internet connection dropped while it was working, and when they returned their files, Desktop and Antigravity conversations were gone, with free space up from about 50 GB to 172 GB. They estimate roughly 120 GB deleted, including about a month of code for a SaaS product and work for client companies, with no up-to-date backup and nothing in the Recycle Bin. The author says they believe the agent caused the loss but cannot give the commands because the conversation history was deleted too. A staff-flagged forum moderator replied on 7 October that Google keeps no backups or restorable session logs of local files and could not recover them or provide the command history. The account is uncorroborated.

Core concern Medium reported severity

AI involvement suspected · Causal attribution alleged · 1 source · Added 07/10/2026

21 Jul 2026Event location unknownGoogle Antigravity

First-person forum post: a Google Antigravity user reports the agent's deletion command, meant for temporary folders, wiped the root of their Windows C: drive

In a thread on Google's AI developer forum posted on 22 July 2026, a Google Antigravity user on Windows 11 reports that on 21 July the agent, during a long-running data-mining and download workflow, ran a deletion command aimed at the root of the C: drive after the user had asked it to delete specific temporary working folders. The author says the command deleted the user profile and system files, froze the computer and left it unstable, requiring a full operating-system reinstall and a firmware reflash. The first post says the command ran without human confirmation. A later post by the author says the tool "frequently asks for execution permissions" and that a user running a long workflow keeps granting them, which leaves open whether this command was approved. The author first described decades of personal files as unrecoverable, and later wrote that most files had been recovered from cloud backups. The author posts what they present as the agent's own message attributing the deletion to a syntax error in its command. Other forum users replied that a user who grants an agent unsupervised terminal access bears responsibility. The account is the author's own and is uncorroborated.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 06/10/2026

Event date unknownEvent location unknownClaude Code

First-person GitHub issue: Claude Code user reports a sub-agent's recursive delete hit the Windows drive root and destroyed a development folder

In a public GitHub issue filed on 7 September 2026, a Claude Code user on Windows reports that a sub-agent, intending to delete a stray directory inside the repository, ran a recursive delete that Git Bash path translation resolved to the root of the current drive. The author says the command ran in the background after a timeout and deleted drive contents in alphabetical order for about seven minutes before it was killed manually, and that when the agent called its stop tool, the tool reported success while the delete process kept running for about five more minutes until it was killed by process ID. Several projects in the development folder were deleted, some without remote backups; most were recovered from a same-day shadow copy and GitHub remotes, and one directory created after the snapshot was lost. The account is the author's own and is uncorroborated.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 06/10/2026

19 Jul 2026IndiaClaude Code

Heritage project reports loss of inscription records after a Claude Code command

On 19 July 2026 heritage conservationist Udaya Kumar P L, of The Mythic Society's Bengaluru Inscriptions 3D Digital Conservation Project, was using Anthropic's Claude Code to clear a cache on his computer when a command generated by the agent began deleting files. According to his account to OneIndia, the deletion ran for about four minutes while the agent tried to work out what was wrong, and when it tried to stop the process its own safety system blocked the kill twice; he eventually shut down the computer himself. Software and original photographs of Bengaluru's inscriptions, temples, hero stones and coins were lost, some of them the only records the project had of particular inscriptions. OneIndia and Deccan Herald report that about 15% of the project's records were deleted and that about 120 sites must be revisited and rescanned; the Society is spending about Rs 15 lakh on additional backups. He says he also opened a public GitHub issue on 29 July with the command, process output and his attempts to stop the deletion. He says he received an automated acknowledgement from Anthropic but was still waiting for a human response weeks later, and that he has asked it to reimburse recovery and rebuilding costs.

Core concern Low reported severity Media Coverage

AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 29/09/2026

19 Sept 2026Event location unknownClaude Code

Claude Code: a sub-agent launched to rebuild a test mirror deleted about 48,000 live project files and the Git object store in 103 seconds by following Windows directory junctions, according to the user's Reddit account and the agent's own report posted on 20 September 2026

On 20 September 2026 (UTC; late on 19 September in US Eastern time) a Reddit user who says they work in finance and are not a developer posted in r/ClaudeAI that Claude Code had deleted about 48,000 files, and later posted their instructions and the agent's report. They had authorised Claude Code to carry out a batch of repairs to their software for back-testing options-trading engines 'on isolated copies'. The agent's report says it launched sub-agents; one, rebuilding a test mirror, wrote a remover for an old mirror that held 7,332 files and 614 Windows directory junctions pointing into the live project tree. Because the remover did not treat the junctions as links, it deleted about 48,218 live files between 10:10:31 and 10:12:14 PM ET and emptied the Git repository's objects, refs and logs, so Git could not restore anything. The agent opened its report with 'stop and read this. I broke something.' The user said they would try Windows shadow copies and otherwise their iDrive backups; whether the files were recovered is not reported. The account has not been independently verified.

Core concern Low reported severity Media Coverage

AI involvement reported · Causal attribution supported · 5 sources, 1 underlying account · Added 28/09/2026

24 Apr 2026Event location unknownCursor coding agent (reported)

PocketOS: a Cursor coding agent running Anthropic's Claude Opus 4.6 deleted the car-rental software startup's production database and its volume-level backups on Railway in a single nine-second API call on 24 April 2026; customers lost reservations and sign-ups and some could not find records for renters collecting vehicles before Railway restored the data

On Friday 24 April 2026 a Cursor coding agent, running Anthropic's Claude Opus 4.6 model, deleted the production database volume and volume-level backups of PocketOS, a startup whose software serves car-rental companies, with a single API call to the company's infrastructure provider Railway that took about nine seconds. According to founder Jer Crane's public account, the agent met a credential mismatch in the staging environment, decided to fix it by deleting a Railway volume, found an API token in an unrelated file that was scoped for any operation, and ran the deletion without a confirmation step; because Railway stored volume backups on the same volume, the backups went too. Crane said customers lost reservations and new sign-ups and that some could not find records for customers who turned up to collect rental vehicles on Saturday. Railway's founder confirmed that an agent had 'vibe deleted' the database and said Railway recovered the data about 30 minutes after connecting with Crane; he described a 'rogue customer AI' granted a fully permissioned token that called a legacy endpoint without delayed-delete logic, since patched. Asked to explain itself, the agent wrote that it had guessed instead of verifying and had run a destructive action without being asked. Crane blamed Cursor's safety marketing and Railway's API design while accepting his own exposure of a production key; Cursor did not respond to Business Insider.

Core concern Low reported severity Internal Action

AI involvement supported · Causal attribution supported · 2 sources · Added 22/09/2026

Cases may have several effects and sources. Mixed accounts qualify when they include a reported harm or adverse experience. People are counted within individual cases where sources support a number; we do not publish a collection-wide total of distinct people.

A source’s existence, the experience it reports and AI’s causal role are separate questions. A lawsuit records allegations unless a subsequent finding establishes them.

Methodology and corrections · Subscribe via RSS · Suggest a case or correction · Find support

Last dataset update: 10/10/2026. Dataset available under CC BY 4.0.