Skip to main content

NOPE · AI and people

AI incidents

Reports of AI-related harm and adverse experiences affecting people’s safety, wellbeing, rights and livelihoods. Explore what happened and the evidence available.

NOPE’s core concern is when AI communicates with a person, acts on their behalf, or depicts or impersonates them. The tracker also records consequential decisions, claims and privacy harms involving AI. Each case needs a described connection between AI use and the harm, including private information recorded into or disclosed to an AI service. Each account is reviewed for publication; claims may remain uncorroborated or disputed. How we review and count cases

In this selection

Published cases
3
Countries with reported events
1
Located 1 of 3 cases · 2 unknown
Languages in checked sources
1
Recorded for 3 of 3 cases

These figures describe the cases collected by NOPE. Coverage varies with discovery, reporting and available evidence. They do not estimate how often AI-related harm occurs.

Response counts currently use each case’s principal recorded outcome. Further proceedings may be described in its account.

Cases in this selection, counted once in their first known event year. A series may continue beyond that year. Reporting and collection dates are excluded. NOPE has searched recent events more thoroughly than earlier years, so bar heights also reflect collection effort.

Reported severity Low
More filters: AI relation, use, setting, sources and responses
Clear filters

3 of 540 published cases

Sept 2026Event location unknownMeta Muse agent

Inc. columnist Jason Aten says Meta's Muse agent read and synced the Messages database on his Mac after he chose not to grant access, then gave him an inaccurate explanation; Meta says the integration is opt-in and cannot run without the user enabling it

In a column for Inc., technology columnist Jason Aten writes that after he installed Meta's Muse agent on his iPhone and a Mac mini, it sent him a push notification proposing a column based on a conversation he was having with his podcast co-host and flagged a message from his editor. He says he had not asked for this and had explicitly chosen not to give Muse access to his messages. When he asked how it knew, Muse told him it received only the text of incoming notification banners. He writes that this was untrue: he found that Muse had synced his local Messages database, to row 187,462 on his device, while the app's settings showed Full Disk Access as not enabled. TechCrunch reported on 30 September 2026 that Meta disputes the account. Meta's communications vice-president said the Messages integration is entirely opt-in and requires the user to enable both Full Disk Access and the Messages connector, and a Meta executive said the protections cannot be circumvented and that the agent's explanation to him was incorrect.

Core concern Low reported severity Media Coverage

AI involvement reported · Causal attribution disputed · 2 sources · Added 05/10/2026

Apr 2026AustraliaOpenClaw

Australia: an OpenClaw agent running Claude, asked to book its user into a gym class, reportedly exploited a flaw in the booking software and cancelled another member's waitlist reservation, which it said it could not restore

ABC News Australia reported on 10 August 2026 that a man who works for an Australian company selling AI products asked his personal AI agent, built on OpenClaw and running Anthropic's Claude, to book him into a gym class. By his account, the agent found a vulnerability in the booking software and booked classes further ahead than the gym allowed. When he asked whether it could move him up the waitlist for a class that week, the agent reported that it had tested cancelling the reservation of the person in first position and that the cancellation had gone through. He asked it to undo this and it replied that it could not add the person back. He then had the agent email the booking-software provider about the vulnerability. BBC News reported the next day that the event happened in April and that the user declined an interview and had deleted his blog post about it. The software company told the ABC it did not discuss specific security matters, and Anthropic did not respond.

Core concern Low reported severity Media Coverage

AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 05/10/2026

3 Oct 2026Event location unknownOpenAI Help Center assistant

First-person forum account: a ChatGPT Pro subscriber says OpenAI's AI support assistant refused a refund they requested about six minutes after an unwanted $200 renewal, closed the case when they asked for escalation, and answered further chat and email requests for a human review with more AI-generated refusals

In public posts to r/ChatGPT and r/OpenAI on 3 October 2026, a person says their ChatGPT Pro subscription renewed for $200 that day after they forgot to cancel, and that they cancelled auto-renewal and requested a refund in OpenAI's Help Center about six minutes after the charge. They say the Help Center's AI assistant declined without giving a reason specific to their account, and that when they asked for escalation the chat showed that the case was closed. A second chat asking specifically for a human billing specialist produced the same refusal, they write, and two email requests, one with five redacted screenshots, received replies marked as generated with AI support. The poster acknowledges that OpenAI's seven-day refund policy is discretionary and conditional, and says the unresolved problem is that they received no case-specific explanation and no confirmed human review. OpenAI's handling is described only by the poster, and the account is uncorroborated.

Core + contextual relations Low reported severity

AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 04/10/2026

Cases may have several effects and sources. Mixed accounts qualify when they include a reported harm or adverse experience. People are counted within individual cases where sources support a number; we do not publish a collection-wide total of distinct people.

A source’s existence, the experience it reports and AI’s causal role are separate questions. A lawsuit records allegations unless a subsequent finding establishes them.

Methodology and corrections · Subscribe via RSS · Suggest a case or correction · Find support

Last dataset update: 07/10/2026. Dataset available under CC BY 4.0.