Skip to main content

NOPE · AI and people

AI incidents

Reports of AI-related harm and adverse experiences affecting people’s safety, wellbeing, rights and livelihoods. Explore what happened and the evidence available.

NOPE’s core concern is when AI communicates with a person, acts on their behalf, or depicts or impersonates them. The tracker is wider: it also records consequential decisions and claims about people. Each account is reviewed for publication; claims may remain uncorroborated or disputed. How we review and count cases

In this selection

Published cases
1
Countries with reported events
1
Located 1 of 1 cases · 0 unknown
Languages in checked sources
1
Recorded for 1 of 1 cases

1 case has no reviewed AI-to-person relation yet: 0 not yet reviewed and 1 reviewed as unknown. Show all cases

These figures describe the cases collected by NOPE. Coverage varies with discovery, reporting and available evidence. They do not estimate how often AI-related harm occurs.

Response counts currently use each case’s principal recorded outcome. Further proceedings may be described in its account.

Cases in this selection, counted once in their first known event year. A series may continue beyond that year. Reporting and collection dates are excluded. NOPE has searched recent events more thoroughly than earlier years, so bar heights also reflect collection effort.

Reported severity Low
More filters: AI relation, use, setting, sources and responses
Clear filters

1 of 452 published cases

25 Apr 2026SingaporeUnidentified code-generation tool

Singapore: a Bee Cheng Hiang marketing employee used a generative AI tool to write a bulk-email script that put up to 1,000 members' addresses in each email's To field, disclosing the email addresses of 95,364 members

On 25 April 2026 Bee Cheng Hiang, the Singapore bak kwa and food products company, sent a marketing email in batches of 1,000 with every recipient's address visible in the To field, so each affected member's email address was disclosed to up to 999 other recipients. Mothership, reporting the findings of the Personal Data Protection Commission (PDPC), puts the number of affected members at 95,364 (The Straits Times says more than 95,000), and the PDPC says email addresses were the only personal data involved. According to the PDPC, an employee had written the email distribution script with a generative AI tool and the prompt did not ask for recipients to be hidden from one another. Mothership reports that a missing bracket in the generated code grouped each batch into one To field. The PDPC says the AI tool did not malfunction and attributes the breach to human error in developing the code with an AI tool. It says the incident likely happened because the company did not test the script sufficiently, had no supervisory review of the employee's work and had no policy on staff use of generative AI. It reports no evidence of further misuse. The company notified the PDPC on 27 April, notified affected members, and gave a voluntary undertaking that the PDPC accepted on 2 September. The PDPC told The Straits Times it was the first AI-related data breach reported to it.

AI relation unknown Low reported severity Regulatory Action

AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account · Added 02/10/2026

Cases may have several effects and sources. Mixed accounts qualify when they include a reported harm or adverse experience. People are counted within individual cases where sources support a number; we do not publish a collection-wide total of distinct people.

A source’s existence, the experience it reports and AI’s causal role are separate questions. A lawsuit records allegations unless a subsequent finding establishes them.

Methodology and corrections · Subscribe via RSS · Suggest a case or correction · Find support

Last dataset update: 02/10/2026. Dataset available under CC BY 4.0.