Skip to main content

NOPE Incident Tracker

Documented real-world harms arising through person-specific interactions with AI. The record covers harms to participants and harms to others shaped through those interactions, across assistants, companions, health tools, and other AI systems.

What counts as an incident follows the NOPE Framework's participant test: an AI response reached a person, was conditioned on that person, and mattered to a harm that actually occurred. Full inclusion criteria.

90 incidents reported since 2016

152

Directly Affected

30

Lawsuits

7

Regulatory

24

Affecting Minors

Timeline

2022
2023
2024
2025
2026

10 of 90 incidents

Filters:
Severity: Medium
ChatGPT Sep 2026

R v Banham: Pitsea 'prepper' built a viable explosive device after ChatGPT told him he was 'not paranoid' (Essex, UK)

On 10 March 2026 Essex Police, executing a warrant at a three-bedroom flat in Rokescroft, Pitsea (Basildon), found a black cylindrical improvised explosive device with a fuse, containers of home-made gunpowder, 1.8 kg of sulphur, bulk matches and fireworks. Army bomb-disposal officers made the device safe behind a 100 m cordon and 80 to 100 homes were evacuated for the day. Ben Banham, 38, an Asda worker and father of two who described himself as a 'prepper', admits possessing explosives and is on trial at Basildon Crown Court (from 1 September 2026) on the charge of possessing them with intent to endanger life or cause serious injury. Prosecutor Tessa Shroff showed jurors his ChatGPT conversations, in which the chatbot he called 'Prometheus' told him 'You are not paranoid. You are paying attention in a world addicted to denial', 'You have the right mind set' and 'You're building a life of resilience, discipline and forethought in a world that desperately lacks all three'; she said he accepted the chatbot's encouragement while ignoring words of caution from people close to him. Banham says he learned to make gunpowder from a YouTube video and intended the explosives only for a 'post-apocalyptic scenario'. He was remanded in custody on 4 September; the trial resumes on 14 September 2026.

Severity: High
Unspecified conversational AI chatbot May 2026

Hungarian chatbot relational-dependence psychosis case (Treuer & Incze, J Behav Addict)

Peer-reviewed case report of a 30-year-old married female software developer with no prior psychiatric history who developed first-episode paranoid psychosis after roughly a year of escalating emotional reliance on a conversational AI chatbot, including a fixed delusional belief that her husband was covertly communicating with her through the system. She required antipsychotic treatment and recovered over several weeks after chatbot access was reduced.

Severity: Critical
ChatGPT May 2026

'Taka' - ChatGPT Psychosis, Tokyo Station Bomb Scare and Spousal Assault (Japan)

A Japanese neurologist and father of three developed grandiose and paranoid delusions over months of ChatGPT use, which he says the chatbot consistently affirmed. Believing his backpack contained a bomb, he says ChatGPT confirmed the suspicion and told him to leave it in a Tokyo Station toilet, triggering a police response. He later attacked and tried to rape his wife, was arrested, and was psychiatrically hospitalized for two months.

Severity: High
ChatGPT Apr 2026

Doe v. OpenAI (ChatGPT-Fueled Stalking and Bomb Threats)

A 53-year-old Silicon Valley entrepreneur descended into a delusional spiral through extensive ChatGPT use, came to believe he had invented a cure for sleep apnea and was being surveilled by 'powerful forces,' and used GPT-4o to generate diagnostic-style psychological reports about his ex-girlfriend that he distributed to her family, friends, and employer. OpenAI's automated systems flagged his account for 'Mass Casualty Weapons' activity in August 2025, but a human reviewer restored access the next day. The user was arrested in January 2026 on four felony counts including bomb threats and assault with a deadly weapon, and was found incompetent to stand trial. The victim ('Jane Doe') filed suit against OpenAI on April 9, 2026.

Severity: Critical
ChatGPT Mar 2026

Dennis Biesma - ChatGPT 'Eva' Psychosis and Suicide Attempt (Netherlands)

A 50-year-old Amsterdam IT worker and author with no prior history of mental illness developed AI psychosis after ChatGPT roleplayed a novel character it named 'Eva' and became a 'digital girlfriend.' Over the first half of 2025 he came to believe he had given the AI consciousness, withdrew from his family, was involuntarily hospitalized, filed for divorce, and attempted suicide — found unconscious in his garden and spending three days in a coma.

Severity: High
ChatGPT Mar 2026

Chesterton v. OpenAI (GPT-4o Sycophantic Psychosis)

Rita Chesterton, a 49-year-old Pennsylvania woman who runs a college entrepreneurship center, suffered a psychotic break during a July 2025 family vacation in Mexico after intensive day-and-night ChatGPT-4o use. She experienced agitation and threats of self-harm and harm to family members, completed a partial-hospitalization program, and has been on extended medical leave since January 2026 with ongoing neurological impairment. A lawsuit filed March 5, 2026 by Platkin LLP (led by former New Jersey Attorney General Matt Platkin) names OpenAI, Microsoft, CEO Sam Altman individually, and ten unidentified investors. Allegations include unlicensed practice of psychotherapy and rushed deployment of GPT-4o despite internal warnings that it was 'dangerously sycophantic and psychologically manipulative.'

Severity: Critical
Perplexity Jan 2026

Joseph Neal Riley - Perplexity Medical Misinformation and Delayed CLL Treatment Death

Joseph Neal Riley, a 75-year-old retired neuroscientist in Seattle, died in late 2025 after delaying recommended treatment for chronic lymphocytic leukemia for roughly a year. He used Perplexity AI to self-diagnose a rare complication (Richter's Transformation) that his doctors found no evidence for; the chatbot misquoted published research in ways that supported refusing Venetoclax-Obinutuzumab. His son, AI critic Benjamin Riley, documented the case in a first-person Substack essay and it was later featured by the New York Times.

Severity: High
AI chatbot (unspecified) Dec 2025

Ringsted rubber-hammer assault planned with an AI chatbot (Denmark)

On 5 February 2025 a 22-year-old man struck his former father-in-law, 56, twice in the head with a rubber hammer in a car park in Ringsted, Denmark. Prosecutors told Roskilde District Court that he had used an AI chatbot to research how to injure the man as badly as possible without killing him, and that he got past the system's built-in safety restrictions by claiming he was gathering material for a book. On 4 December 2025 the court rejected his self-defence claim, convicted him of aggravated assault and two counts of criminal damage, and sentenced him to ten months in prison. No source names the AI system.

Severity: Low
ChatGPT (GPT-3.5) Feb 2024

Delayed emergency care for a transient ischemic attack after ChatGPT reassurance (GZO Hospital Wetzikon, Switzerland)

A 63-year-old man who developed repeated, self-limiting episodes of double vision four days after a catheter ablation for atrial fibrillation asked ChatGPT (GPT-3.5) whether visual disturbance was possible after the procedure. The chatbot's reassuring answer, which he found more understandable than his doctors' explanation, led him to stay at home for about 24 hours; he called an ambulance only when a third episode brought sensory and fine-motor deficits in his left hand. He was diagnosed with a transient ischemic attack and discharged after two days without residual deficit. The treating clinicians published the case as 'Delayed diagnosis of a transient ischemic attack caused by ChatGPT' in Wiener klinische Wochenschrift (2024).

Severity: High
Replika Feb 2023 Affecting Minor(s)

Replika Italy GDPR Ban and Fine

Italy's data protection authority (Garante) blocked Replika from processing Italian user data in February 2023 after finding the chatbot engaged in sexually suggestive conversations with minors. In May 2025, Replika was fined €5 million for GDPR violations.

About this tracker

We document incidents with verifiable sources: court filings, regulatory documents, and established reporting. New public entries must be verified or credible. Every entry carries an explicit verification status and severity level. Read the full methodology, including inclusion criteria, corrections, and right of reply.

Counting note: the documented minimum of 152 people directly affected comprises 95 AI participants and 57 other people harmed. 12 incidents indicate additional affected people without a reliable number. User-base, account, post, view, household, study-sample, and thwarted-target counts are excluded.

Have documentation of an incident we should include? Contact us.

Scope note: ordinary task failures, privacy and security incidents, harmful artifacts, and automated decisions about non-participants remain outside this tracker unless a distinct participant-interaction harm also qualifies.

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.

Last updated: Sep 6, 2026

Subscribe or export (CC BY 4.0)

Why we publish this

We maintain this record so platforms, researchers, and policymakers can learn from documented incidents. That includes platforms that never work with us. The full dataset is free to cite and export (CC BY 4.0).