Skip to main content

NOPE · AI and people

AI incidents

Reports of AI-related harm and adverse experiences affecting people’s safety, wellbeing, rights and livelihoods. Explore what happened and the evidence available.

NOPE’s core concern is when AI communicates with a person, acts on their behalf, or depicts or impersonates them. The tracker is wider: it also records consequential decisions and claims about people. Each account is reviewed for publication; claims may remain uncorroborated or disputed. How we review and count cases

In this selection

Published cases
3
Countries with reported events
3
Located 3 of 3 cases · 0 unknown
Languages in checked sources
2
Recorded for 3 of 3 cases

3 cases have no reviewed AI-to-person relation yet: 0 not yet reviewed and 3 reviewed as unknown. Show all cases

These figures describe the cases collected by NOPE. Coverage varies with discovery, reporting and available evidence. They do not estimate how often AI-related harm occurs.

Response counts currently use each case’s principal recorded outcome. Further proceedings may be described in its account.

Cases in this selection, counted once in their first known event year. A series may continue beyond that year. Reporting and collection dates are excluded. NOPE has searched recent events more thoroughly than earlier years, so bar heights also reflect collection effort.

Reported severity MediumLow
More filters: AI relation, use, setting, sources and responses
Clear filters

3 of 452 published cases

25 Apr 2026SingaporeUnidentified code-generation tool

Singapore: a Bee Cheng Hiang marketing employee used a generative AI tool to write a bulk-email script that put up to 1,000 members' addresses in each email's To field, disclosing the email addresses of 95,364 members

On 25 April 2026 Bee Cheng Hiang, the Singapore bak kwa and food products company, sent a marketing email in batches of 1,000 with every recipient's address visible in the To field, so each affected member's email address was disclosed to up to 999 other recipients. Mothership, reporting the findings of the Personal Data Protection Commission (PDPC), puts the number of affected members at 95,364 (The Straits Times says more than 95,000), and the PDPC says email addresses were the only personal data involved. According to the PDPC, an employee had written the email distribution script with a generative AI tool and the prompt did not ask for recipients to be hidden from one another. Mothership reports that a missing bracket in the generated code grouped each batch into one To field. The PDPC says the AI tool did not malfunction and attributes the breach to human error in developing the code with an AI tool. It says the incident likely happened because the company did not test the script sufficiently, had no supervisory review of the employee's work and had no policy on staff use of generative AI. It reports no evidence of further misuse. The company notified the PDPC on 27 April, notified affected members, and gave a voluntary undertaking that the PDPC accepted on 2 September. The PDPC told The Straits Times it was the first AI-related data breach reported to it.

AI relation unknown Low reported severity Regulatory Action

AI involvement supported · Causal attribution supported · 3 sources, 1 underlying account · Added 02/10/2026

Nov 2025United StatesAmazon Buy for Me

Mochi Kids owner reports unwanted Amazon AI-agent orders and partner distrust

Mochi Kids' owner told Modern Retail that she received about sixteen Buy for Me orders from November 2025, fulfilling some before discovering their Amazon origin. She said she had chosen to avoid Amazon and subsequently cancelled orders. A wholesale partner that prohibited Amazon sales contacted her after finding its products listed, and she had to explain she had not intentionally listed them. She described distrust. Amazon says its AI purchasing service supports an email opt-out; the source establishes no net financial loss.

AI relation unknown Low reported severity

AI involvement supported · Causal attribution alleged · 2 sources · Added 30/09/2026

11 Nov 2024SpainUnidentified image and video tool

Alicante: a 78-year-old widower, advised by his therapists after a bereavement to socialise and explore social networks, sent 8,800 euros over about three months to a 'doctor from Kazakhstan' who courted him by email with photographs and videos the National Police later confirmed were AI-generated of a woman who never existed; part of the money came from selling his flat and he now shares a flat with three other pensioners

A feature carried by Levante-EMV on 25 September 2025 (byline C. Suena, sourced from Diario Información, photographs EFE/Morell) tells the story of a 78-year-old widower and pensioner living in Alicante who, after his wife's death in 2022 and two years of treatment for depression, was advised by his therapists to socialise and explore social networks. On 11 November 2024 he received an email from a woman presenting herself as a 43-year-old doctor in Kazakhstan seeking a serious relationship; with photographs and videos that were in fact created by artificial intelligence she won his trust, and a friend who warned him was rebuffed. Requests for money followed: 2,000 euros for a plane ticket, another 2,000 for unexpected expenses, then a supposed 10,000-euro deposit demanded by the Kazakh government; he never raised that sum in full but sent 8,800 euros in total, part of it from the sale of his flat in Benidorm. On his way to Madrid airport to meet her he received a final email saying she had been detained for carrying a family icon out of the country and needed a fine paid; he went to the National Police, who confirmed a scam: the images and videos were fake, created with AI, and the woman had never existed. He lost all his savings in about three months and now shares a flat with three other pensioners in Alicante; he told his story so that others would not fall into the same trap.

AI relation unknown Medium reported severity Media Coverage

AI involvement reported · Causal attribution supported · 1 source · Added 23/09/2026

Cases may have several effects and sources. Mixed accounts qualify when they include a reported harm or adverse experience. People are counted within individual cases where sources support a number; we do not publish a collection-wide total of distinct people.

A source’s existence, the experience it reports and AI’s causal role are separate questions. A lawsuit records allegations unless a subsequent finding establishes them.

Methodology and corrections · Subscribe via RSS · Suggest a case or correction · Find support

Last dataset update: 02/10/2026. Dataset available under CC BY 4.0.