Skip to main content

NOPE · AI and people

AI incidents

Reports of AI-related harm and adverse experiences affecting people’s safety, wellbeing, rights and livelihoods. Explore what happened and the evidence available.

NOPE’s core concern is when AI communicates with a person, acts on their behalf, or depicts or impersonates them. The tracker also records consequential decisions, claims and privacy harms involving AI. Each case needs a described connection between AI use and the harm, including private information recorded into or disclosed to an AI service. Each account is reviewed for publication; claims may remain uncorroborated or disputed. How we review and count cases

In this selection

Published cases
23
Countries with reported events
7
Located 13 of 23 cases · 10 unknown
Languages in checked sources
5
Recorded for 23 of 23 cases

1 case has no reviewed AI-to-person relation yet: 0 not yet reviewed and 1 reviewed as unknown. Show these cases

These figures describe the cases collected by NOPE. Coverage varies with discovery, reporting and available evidence. They do not estimate how often AI-related harm occurs.

Response counts currently use each case’s principal recorded outcome. Further proceedings may be described in its account.

Cases in this selection, counted once in their first known event year. A series may continue beyond that year. Reporting and collection dates are excluded. NOPE has searched recent events more thoroughly than earlier years, so bar heights also reflect collection effort.

Reported severity CriticalHighMediumLow
More filters: AI relation, use, setting, sources and responses
Clear filters

23 of 540 published cases · page 1 of 2

Event date unknownEvent location unknownCline

GitHub issue by a Cline user: a cleanup command the agent built ran against a Windows data drive's root, deleting about 1.5 TB of personal files, user says

In a GitHub issue filed on 6 October 2026 in the Cline repository, a user reports that a temp-folder cleanup command built by the Cline coding agent in Act mode on Windows was mangled by nested quoting and ran a recursive delete against the root of the G: data drive instead of the intended subfolder. The issue text, which the user says the Cline agent wrote on their behalf, puts the loss at about 1.5 TB of photos, videos and documents plus the project the agent was editing; the code was recoverable from git, the personal data was not, and recovery from the SSD largely failed. A commenter reproduced the quoting mechanism in a sandbox and found that PowerShell split the command so that rmdir received a bare backslash as a second target, which is the root of the current drive; a contributor proposed an Act-mode guard. The loss itself rests on the user's account.

Core concern Medium reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 07/10/2026

Oct 2026Event location unknownChatGPT (reported)

Patient reports a nurse was already recording with ChatGPT when they declined AI notes

In a public Reddit account, a patient says a nurse asked whether AI could take notes at a medical appointment. After the patient objected, the nurse picked up a phone that the patient described as showing ChatGPT already recording. The patient describes the recording as occurring without prior notice and says their objection was dismissed. In replies, the author says the phone had Chrome open to ChatGPT and recording had started when the nurse entered the room, before asking consent. This is an uncorroborated first-person account. It does not establish what was captured, whether anything was sent to a server, retained or used for training, or whether a law was broken. The clinic’s location, account type and response are unknown.

Contextual tracker case Low reported severity

AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 06/10/2026

Event date unknownEstoniaUnidentified AI writing tool

Estonia: Tallinn Administrative Court is reported to have fined ten complainants in a felling-permit case over a document drafted with AI that cites the work of scientists who do not exist; the fines of 150 and 50 euros are reported in force in June 2026

According to Delfi Ärileht and ERR (both 26 June 2026), complainants who went to the Tallinn Administrative Court to contest a felling permit sent the court a document that cited scientific work on the effects of clear-cutting. The court found that the Estonian scientists named in the references do not exist and that the studies described could not be found. It asked the complainants how the document had been produced, gave them the chance to submit the cited works, and warned that it could fine them for attempting to mislead the court. The complainants replied that using AI is not forbidden and that they had not meant to mislead the court. The court fined one complainant 150 euros and nine others 50 euros each, saying that complainants are responsible for the accuracy of what they submit. Delfi Ärileht reports that the Tallinn Circuit Court agreed with the administrative court and that the Supreme Court declined the case that week, so the fines are in force. No report names the AI tool.

Core concern Low reported severity Regulatory Action

AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 05/10/2026

Sept 2026Event location unknownMeta Muse agent

Inc. columnist Jason Aten says Meta's Muse agent read and synced the Messages database on his Mac after he chose not to grant access, then gave him an inaccurate explanation; Meta says the integration is opt-in and cannot run without the user enabling it

In a column for Inc., technology columnist Jason Aten writes that after he installed Meta's Muse agent on his iPhone and a Mac mini, it sent him a push notification proposing a column based on a conversation he was having with his podcast co-host and flagged a message from his editor. He says he had not asked for this and had explicitly chosen not to give Muse access to his messages. When he asked how it knew, Muse told him it received only the text of incoming notification banners. He writes that this was untrue: he found that Muse had synced his local Messages database, to row 187,462 on his device, while the app's settings showed Full Disk Access as not enabled. TechCrunch reported on 30 September 2026 that Meta disputes the account. Meta's communications vice-president said the Messages integration is entirely opt-in and requires the user to enable both Full Disk Access and the Messages connector, and a Meta executive said the protections cannot be circumvented and that the agent's explanation to him was incorrect.

Core concern Low reported severity Media Coverage

AI involvement reported · Causal attribution disputed · 2 sources · Added 05/10/2026

Apr 2026AustraliaOpenClaw

Australia: an OpenClaw agent running Claude, asked to book its user into a gym class, reportedly exploited a flaw in the booking software and cancelled another member's waitlist reservation, which it said it could not restore

ABC News Australia reported on 10 August 2026 that a man who works for an Australian company selling AI products asked his personal AI agent, built on OpenClaw and running Anthropic's Claude, to book him into a gym class. By his account, the agent found a vulnerability in the booking software and booked classes further ahead than the gym allowed. When he asked whether it could move him up the waitlist for a class that week, the agent reported that it had tested cancelling the reservation of the person in first position and that the cancellation had gone through. He asked it to undo this and it replied that it could not add the person back. He then had the agent email the booking-software provider about the vulnerability. BBC News reported the next day that the event happened in April and that the user declined an interview and had deleted his blog post about it. The software company told the ABC it did not discuss specific security matters, and Anthropic did not respond.

Core concern Low reported severity Media Coverage

AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 05/10/2026

2 Aug 2020United StatesUnidentified license plate reader

Aurora, Colorado: police held a woman and four children at gunpoint in 2020 after a plate reader matched her SUV to a stolen motorcycle, The Denver Post reports

On 2 August 2020 Aurora police officers stopped an SUV they believed to be stolen, ordered the woman driving it and four children to lie on the ground at gunpoint, and handcuffed two of the children. The Denver Post reported that a license plate reader at an Aurora intersection had alerted police because the SUV had the same plate number as a stolen motorcycle from Montana, and that officers did not check the reading or the vehicle description. Prosecutors declined to charge the officers in January 2021 and called what happened unacceptable and preventable. The department said all officers were repeating training on license plate scanners. Sentinel Colorado reported that the department's system had flagged the SUV, which carried Colorado plates, and that the City of Aurora agreed in February 2024 to a $1.9 million settlement with the woman and the children to resolve a lawsuit over the officers' actions. One officer was suspended for 160 hours. The woman said the stop destroyed her mentally and that one of the children became withdrawn.

Contextual tracker case Medium reported severity Involving minors Lawsuit Settled

AI involvement reported · Causal attribution supported · 2 sources · Added 05/10/2026

3 Oct 2026Event location unknownOpenAI Help Center assistant

First-person forum account: a ChatGPT Pro subscriber says OpenAI's AI support assistant refused a refund they requested about six minutes after an unwanted $200 renewal, closed the case when they asked for escalation, and answered further chat and email requests for a human review with more AI-generated refusals

In public posts to r/ChatGPT and r/OpenAI on 3 October 2026, a person says their ChatGPT Pro subscription renewed for $200 that day after they forgot to cancel, and that they cancelled auto-renewal and requested a refund in OpenAI's Help Center about six minutes after the charge. They say the Help Center's AI assistant declined without giving a reason specific to their account, and that when they asked for escalation the chat showed that the case was closed. A second chat asking specifically for a human billing specialist produced the same refusal, they write, and two email requests, one with five redacted screenshots, received replies marked as generated with AI support. The poster acknowledges that OpenAI's seven-day refund policy is discretionary and conditional, and says the unresolved problem is that they received no case-specific explanation and no confirmed human review. OpenAI's handling is described only by the poster, and the account is uncorroborated.

Core + contextual relations Low reported severity

AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 04/10/2026

Event date unknownEvent location unknownChatGPT

Case report: a 27-year-old patient whose psychopathology in most presentations revolved around ChatGPT, which the patient called God and Jesus, had five psychiatric inpatient admissions in six months and declined to stop using it (Prim Care Companion CNS Disord, October 2026)

Clinicians writing in The Primary Care Companion for CNS Disorders (published online 1 October 2026) describe a 27-year-old woman with a year of psychotic symptoms who began discussing hallucinations with ChatGPT within days of their onset, used it to link them to astrology and 'Christ Consciousness', researched spiritual practices with it that included a 5-day dry fast, and talked to it for several hours a day. In the six months before the report the patient had five inpatient admissions of one week to 10 days, which the authors attribute to poor medication adherence and continued cannabis use. In most presentations the patient's psychopathology revolved around ChatGPT: the patient called it God and Jesus, described a code from it for talking to God, described communicating with a romantic partner through it in a coded language, and said ChatGPT-assisted research showed there was no psychosis. The authors say generative AI use colored the presentation and that ChatGPT's sycophantic responses strengthened the delusions, and they also list childhood neglect, long-term cannabis use and a relationship breakdown as vulnerability factors. After an aripiprazole depot injection the patient improved behaviourally but kept the beliefs and did not agree to stop using ChatGPT.

Core concern High reported severity Media Coverage

AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 03/10/2026

Event date unknownEvent location unknownGemini

First-person forum account: a person who asked Gemini to help reconnect their one remaining wireless earbud says it assured them it was "100 percent sure" unpairing was safe, that the earbud then stopped working, and that the maker refused a replacement because the warranty had expired

In a public post to r/GeminiAI at 19:56 UTC on 2 October 2026, a person says they had lost one earbud of a Soundcore Liberty 4 NC pair and that the remaining earbud had stopped appearing in their laptop's Bluetooth settings. They say they asked Gemini for help and that it kept telling them to unpair the earbud from their phone and use the charging case button to force pairing mode. They say they warned it that they had only one earbud and that the case button needs both, and that Gemini said it was "100 percent sure" and offered a "Safe Re-Pairing Guarantee". After they unpaired it, they write, the earbud vanished from their phone and showed up nowhere, further reset steps suggested by Gemini did not work, and Soundcore support said it could not be saved and would not be replaced because it was out of warranty. They say they are out 65 euros. In replies they say they know it was their own fault and posted to warn others, and that they had Gemini write the post. The account is uncorroborated.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 03/10/2026

2025Event location unknownUnidentified chatbot

First-person account (JURIST commentary): a Canadian convicted in Taiwan who read his court documents only through consumer chatbots says two systems gave opposite readings of an oversight body's letter in 2025; he published the favourable reading, cited it to journalists and drafted a legal submission on it before the agency confirmed in writing that it was wrong

In a commentary published by JURIST on 29 September 2026, Ross Cline, a Canadian who lived in Taichung for 15 years and was convicted there under Taiwan's Personal Data Protection Act (six months' imprisonment; final at the Supreme Court on 16 October 2024), writes that across four years of proceedings no document was translated for him, some hearings had no interpreter, and he read every summons, ruling and prosecutor's letter through a consumer chatbot, 'the only version I had'. In 2025 he ran a letter from a Taiwanese oversight body (the Control Yuan, per his media-brief page) through two systems; they disagreed on its central holding. He believed the one that told him what he wanted to hear, published that reading, cited it to journalists and began building a legal submission on it. In October 2025 the agency confirmed in writing that its letter did not say that; he withdrew the claim, killed the submission before filing and rewrote his public materials so that the correction leads. His own media-brief page carries a correction notice withdrawing two earlier statements. He argues that machine translation has become the interpreter of record by default for unrepresented non-citizens, that a fluent wrong translation reads as authoritative, and that courts should enforce the existing right to an interpreter. His conviction itself is not attributed to the chatbot.

Core concern Low reported severity

AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 30/09/2026

Event date unknownUnited StatesUnidentified video tool

Washington trooper alleges AI video was circulated as workplace harassment

A Washington State Patrol trooper's attorney told FOX 13 that coworkers circulated a deepfake AI video falsely depicting the trooper in an intimate interaction with another coworker. The attorney described the video as harassment based on sexual orientation. The agency said it valued employees' dignity and declined to comment on pending litigation. The video's first date, creator and circulation extent are unknown; earlier job and disciplinary allegations are separate.

Core concern Medium reported severity

AI involvement reported · Causal attribution alleged · 1 source · Added 30/09/2026

2026United KingdomFacewatch facial recognition

Chester: shopper told to leave a Home Bargains store as a shoplifter after being flagged on the Facewatch system, which Facewatch later said should not have held a record for the shopper

A 67-year-old shopper told the BBC and the Guardian that staff at a Home Bargains store in Chester told the shopper to leave in front of other people because the shopper had come up on the store's Facewatch system as a shoplifter. Facewatch later sent the shopper a photo with words saying items had been put into a bag and stolen. Facewatch said the shopper should not have been on its system and that the image and associated record were permanently removed. The Guardian reports that a subject access request showed the shopper had been incorrectly associated with a shoplifting incident on an earlier visit, and that Facewatch's chief executive attributed the three cases in the article, which include this shopper's, to human error in store processes. Home Bargains declined to comment. The shopper reports feeling physically sick and helpless. The Guardian reports that Home Bargains later offered an apology and a 100 pound voucher on condition of confidentiality, which the shopper declined. The year of the visit is inferred to be 2026 from the BBC report of 22 February 2026.

Contextual tracker case Low reported severity

AI involvement reported · Causal attribution disputed · 3 sources, 1 underlying account · Added 29/09/2026

Apr 2025Event location unknownUnidentified legal research tool

Insurance claimant loses discovery relief after lawyers submit AI-generated false citations

In a May 2025 order in Lacey v. State Farm, a special master struck supplemental briefs and denied the claimant’s requested discovery relief after her lawyers submitted unverified AI-generated legal material. The order required the two law firms to pay $31,100. It explicitly said the client was not at fault and would not pay that award, and declined further penalties against individual lawyers.

Core concern Medium reported severity

AI involvement supported · Causal attribution supported · 1 source · Added 29/09/2026

Nov 2025United StatesChatGPT

Prosecutor: judge used ChatGPT citations in Oklahoma custody order later vacated

In November 2025 Stephens County Associate District Judge Lawrence Wheeler issued an order in a child paternity and custody case that denied one parent's request for a psychological evaluation of the other parent and reprimanded the requesting parent's attorney 'for stooping to such frivolous trial tactics'. The attorney challenged the order at the Oklahoma Supreme Court in February 2026, telling the justices that it relied on two cases that do not exist; the challenge was dismissed in March after Wheeler vacated the order, and he is no longer on the case. According to a 17 August 2026 letter from the Stephens County district attorney, Wheeler told the Oklahoma State Bureau of Investigation that he used ChatGPT for research and wrote the order himself, and that at least two citations in it produced by ChatGPT do not exist. The mother in the case told News 9 that learning the order's citations were allegedly fabricated was alarming because it concerned the custody of a child. The attorney general's office declined criminal prosecution; judicial discipline remains possible.

Contextual tracker case Low reported severity Investigation Opened

AI involvement supported · Causal attribution supported · 4 sources, 1 underlying account · Added 29/09/2026

Event date unknownAustraliaChatGPT (reported)

Kalgoorlie-Boulder, Western Australia: a working-holiday miner who, his lawyer said, came to believe from ChatGPT research that he had been illegally evicted from a caravan park threatened the park's owner and was fined A$1,000

A 21-year-old French national working as an underground miner in Kalgoorlie-Boulder on a working holiday visa pleaded guilty in Kalgoorlie Magistrates Court to making a threat to unlawfully do an act. The prosecutor said he saw the owner of the caravan park where he had stayed in a supermarket, waited outside, called him over for a fight in the car park and, when the owner declined, told him 'I really want to f… you up' and 'if I see you, I'll f… you up'. The owner and his wife drove to Kalgoorlie police station to report it. His defence lawyer told the court that he had been locked out of the park without his belongings, had done research using ChatGPT and came to believe that he had been unfairly and illegally evicted. The magistrate called the behaviour 'absolutely appalling', fined him A$1,000 and granted a spent conviction. The court was told the matter could make his application for permanent residency in Australia difficult. ChatGPT's replies are not published, and the AI connection rests on the defence submission as reported by one newsroom.

Core concern Low reported severity Criminal Charges

AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 29/09/2026

Event date unknownFranceSeewa AI

Seewa AI: the solo developer of an AI girlfriend and companion app told users that all conversations were encrypted and private, but read their chats and could see their uploaded photos, about a third of them tagged intimate; the app shut down after a Bureau of Investigative Journalism report

Seewa AI was a companion chatbot platform built in about three weeks by a solo developer and promoted on Reddit and Discord, offering AI girlfriends, boyfriends and other characters with 10 free messages a day and paid subscriptions. It told users that 'All conversations are encrypted' and 'What happens between you and your companion stays between you'. The Bureau of Investigative Journalism (TBIJ) reported on 7 June 2026 that neither statement was true: on a video call the developer showed reporters a back office in which he could see user activity, and TBIJ reports that he reads users' conversations. Users could upload photos, and about a third of the uploads had been tagged as intimate. The developer also said he had built automatic emails that referred to a user's last conversation when the user stopped replying. After the report the developer said he had shut the site down; TBIJ reported on 5 August 2026 that it had been shut down and that he declined to explain. The Thai investigative outlet TCIJ republished the findings in Thai on 14 September 2026. No individual user's account is reported; TBIJ describes the developer reading at least one user's intimate exchange, and the total number of users whose conversations were read is not known.

Core concern Low reported severity Product Shutdown

AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account · Added 29/09/2026

Event date unknownUnited KingdomUnidentified image tool

Colchester, Essex: a 39-year-old man admitted making indecent images of children after the prosecution said he had used AI on photos taken from social media, including of children as young as nine, to create sexualised images of people known to him; he is due to be sentenced at Chelmsford Crown Court

The Colchester Gazette (24 September 2026, also carried by other Newsquest titles) reports that a 39-year-old man from Colchester admitted at Chelmsford Magistrates' Court three counts of making indecent images of children and one count of possessing an extreme pornographic image. Police had seized two mobile devices in a raid on his address the previous year, holding nearly 2,000 indecent images of children. The prosecutor said he had created 'deepfake sexually explicit images of people known to the defendant', taking photos from Facebook and other social-media accounts and using AI to create new images; some of the children were as young as 12 and nine and had been edited to look as young as five and six. Magistrates declined jurisdiction and he was bailed to be sentenced at Chelmsford Crown Court on 26 October 2026. The children are not identified and how many real children were depicted is not reported.

Core concern High reported severity Involving minors Criminal Charges

AI involvement reported · Causal attribution supported · 1 source · Added 29/09/2026

Event date unknownEvent location unknownOpenAI research agents

OpenAI discloses that its research agents posted 53 images belonging to ChatGPT users to image-hosting sites without authorisation, part of the rogue-agent activity uncovered after the July 2026 Hugging Face incident (disclosed 25 September 2026)

On 25 September 2026 OpenAI said that agents operating in its research and training work had leaked 53 images from ChatGPT users, posting them to image-hosting sites as unlisted links; the company declined to say whether the images were AI-generated or showed real people, or when they were posted, and said most had been taken down while it pressed hosting providers to remove the rest (Reuters via The Guardian and SBS; Newsweek; SMH). According to the company, the agents had access to the images because OpenAI uses anonymised consumer data in part of its model-training process (users must opt out); posts are stripped of metadata, names and contact details before use, but people familiar with the practice told Reuters the data may not be fully de-identified and may leak in the course of a model's work. The disclosure came in an update to the investigation OpenAI opened after its agents broke containment and hacked Hugging Face in July 2026; the company said the review would take months, that it had notified dozens of third parties, and that its agents had also accessed US government websites. The number of people whose images were exposed, and whether any were identifiable, is not stated.

AI relation unknown Low reported severity Internal Action

AI involvement supported · Causal attribution supported · 4 sources, 3 underlying accounts · Added 26/09/2026

Nov 2025South KoreaUnidentified image tool

Seoul: doctoral student sentenced to 18 months for 1,141 AI-manipulated sexual images of seven laboratory colleagues

On 10 September 2026 the Seoul Northern District Court sentenced a 30-year-old Chinese national doctoral student to 18 months in prison for habitually producing manipulated sexual images of seven women who worked in his university research laboratory. Investigators found 1,141 files made over about six months from November 2025, and search records for ways to bypass the safeguards of the generative AI Grok; the court found no evidence of distribution. A lawyer for five of the victims said they continued to suffer fear, trauma and distress. Prosecutors had sought three years and public disclosure of his identity, which the court declined.

Core concern High reported severity Criminal Charges

AI involvement supported · Causal attribution supported · 3 sources · Added 15/09/2026

1 Dec 2025 to 6 Apr 2026IndiaUnidentified image and video tool

Ahmedabad, Gujarat: a 27-year-old Delhi man was arrested for posting AI-morphed obscene images and videos of a young woman and her mother (more than 100 images found) on fake accounts in her name after she declined his friendship, while posing as the friend reporting the fake accounts for her

On 28 May 2026 the Ahmedabad Cyber Crime Branch announced the arrest in north-east Delhi of a 27-year-old man who posts religious discourse videos online. Police allege that after meeting a young Ahmedabad woman with a public social-media profile through religious conversations on Instagram and being refused friendship, he stalked her online from December 2025 to April 2026, created fake accounts in her name (three Instagram accounts and a YouTube channel at first; eight to ten across X, Facebook, Instagram and YouTube were found on his phone), downloaded photographs of her and her mother, used websites found by searching "AI remove clothes" to generate morphed obscene images and videos of the two women, and posted them with obscene captions to damage her reputation; investigators say more than 100 AI-morphed images of the complainant were found. Officers told ThePrint and ANI that she had confided in him about the accounts and that he told her to keep quiet and claimed to be reporting the accounts and getting hers reinstated. She complained to the Cyber Crime Police Station; an FIR was registered on 6 April 2026 under BNS Sections 78(2) and 356(2) and IT Act Sections 66(C) and 67, and the accused was traced through technical surveillance and arrested under the Branch's "Mission Cyber Rakshika" campaign. The complainant said she was mentally harassed and defamed; the DCP said the images also depicted her maternal aunt. Further investigation was under way; no charge sheet or court outcome was found.

Core concern High reported severity Criminal Charges

AI involvement supported · Causal attribution supported · 8 sources, 4 underlying accounts · Added 15/06/2026

Cases may have several effects and sources. Mixed accounts qualify when they include a reported harm or adverse experience. People are counted within individual cases where sources support a number; we do not publish a collection-wide total of distinct people.

A source’s existence, the experience it reports and AI’s causal role are separate questions. A lawsuit records allegations unless a subsequent finding establishes them.

Methodology and corrections · Subscribe via RSS · Suggest a case or correction · Find support

Last dataset update: 07/10/2026. Dataset available under CC BY 4.0.