Sept 2026Event location unknownMeta Muse agent
In a column for Inc., technology columnist Jason Aten writes that after he installed Meta's Muse agent on his iPhone and a Mac mini, it sent him a push notification proposing a column based on a conversation he was having with his podcast co-host and flagged a message from his editor. He says he had not asked for this and had explicitly chosen not to give Muse access to his messages. When he asked how it knew, Muse told him it received only the text of incoming notification banners. He writes that this was untrue: he found that Muse had synced his local Messages database, to row 187,462 on his device, while the app's settings showed Full Disk Access as not enabled. TechCrunch reported on 30 September 2026 that Meta disputes the account. Meta's communications vice-president said the Messages integration is entirely opt-in and requires the user to enable both Full Disk Access and the Messages connector, and a Meta executive said the protections cannot be circumvented and that the agent's explanation to him was incorrect.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution disputed · 2 sources · Added 05/10/2026
Apr 2026AustraliaOpenClaw
ABC News Australia reported on 10 August 2026 that a man who works for an Australian company selling AI products asked his personal AI agent, built on OpenClaw and running Anthropic's Claude, to book him into a gym class. By his account, the agent found a vulnerability in the booking software and booked classes further ahead than the gym allowed. When he asked whether it could move him up the waitlist for a class that week, the agent reported that it had tested cancelling the reservation of the person in first position and that the cancellation had gone through. He asked it to undo this and it replied that it could not add the person back. He then had the agent email the booking-software provider about the vulnerability. BBC News reported the next day that the event happened in April and that the user declined an interview and had deleted his blog post about it. The software company told the ABC it did not discuss specific security matters, and Anthropic did not respond.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 05/10/2026
Sept 2026ParaguayUnidentified image tool
According to Hoy (21 September 2026) and El Nacional (22 September), students of the architecture faculty of the Universidad Nacional de Asunción reported an anonymous website that shared intimate images of students, teachers and staff without authorisation, including real photographs and material altered with AI. El Nacional reports that at least about twenty students complained, that some posts used photographs taken from social media, and that related content later appeared in Telegram and WhatsApp groups. The Minister of Women said her ministry had seen messages in which UNA students raised concern about content of them held without consent, and that in some cases AI-generated images of sexual content were shared (La Nación, 22 September). La Tribuna, reporting the findings of the police cybercrime department, describes the portal as used for the non-consensual distribution of intimate photographs and AI-altered content; according to a memorandum signed by the head of the department, a Paraguay section exposes full names, images and phone numbers of students (24 September). The university referred the case to prosecutors and police, and police suggested that prosecutors seek a court order to block the site in Paraguay. No person responsible has been publicly identified.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 05/10/2026
26 Sept 2026 to 27 Sept 2026United StatesClaude (reported)
According to a Lee County Sheriff's Office arrest report, as reported by WINK News and by Guessing Headlights (on Yahoo News, citing a copy obtained by Gulf Coast News Now), a user of Anthropic's AI platform wrote on 26 September 2026 that she was going to 'shoot up' the Lee County Sheriff's Office, and the next day wrote that she had a new gun. The arrest report says the platform's safety measures flagged the messages, a human review team examined them and reported them to law enforcement. Deputies went to the 30-year-old woman's Bonita Springs home and detained her without incident; she is charged with making a written threat of violence under Florida law. The sheriff told WINK News that she later said she uses AI like a 'diary'. Anthropic had not commented on the case in either report. The charge is an allegation and the case is pending.
Core + contextual relations Medium reported severity Criminal Charges
AI involvement reported · Causal attribution supported · 2 sources, 1 underlying account · Added 03/10/2026
30 Sept 2026 to 1 Oct 2026Event location unknownClaude
In a public post to r/ClaudeCode late on 30 September 2026 (UTC), a person writing for an education-focused nonprofit says the organisation's Claude team 'was disabled today without much warning', affecting around 145 students and staff members. By the poster's account, students used Claude for IELTS preparation, writing practice, research, study support and technical learning, and staff used Claude and Claude Code for content preparation, development and research. The poster says the organisation adds students in batches and wonders whether that activity triggered something automatically. They say they have submitted a review request to Anthropic and are not aware of any intentional policy violation. In a reply they say direct messages to three people went unanswered. Anthropic's help centre says an organisation can be paused because of unusual activity and that members can request a review; it does not describe this case. Whether an automated system made the decision is not known. The account is uncorroborated.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 2 sources · Added 01/10/2026
23 Feb 2026 to 25 Feb 2026ItalyUnidentified voice-cloning tool
On 23 February 2026 Paolo Molesini, then chairman of Fideuram (the private-banking subsidiary of Intesa Sanpaolo), received a WhatsApp message from an unknown number from someone claiming to be Intesa's chief executive Carlo Messina, announcing a confidential acquisition that had to be executed through Fideuram. The same day a caller presenting as a lawyer of A&O Shearman whom Molesini knew, whose voice ANSA, Il Fatto Quotidiano and Corriere della Sera, reporting from the Milan court papers, describe as created with artificial intelligence (today.it, which also cites the seizure decree, writes that the court papers do not yet answer whether the voice was imitated), had him sign a confidentiality agreement and sent eleven payment instructions; Fideuram's treasury head was separately contacted by someone posing as Fideuram's CEO. Between 23 and 25 February eleven transfers totalling about 95 million euros went to accounts in Portugal and at Bank of China; the bank's alarm systems and the Milan prosecutors recovered about 40-42 million from China and 13 million seized in Portugal, leaving at least 36 million (39.5 million per the court papers) missing after conversion into cryptocurrency. Molesini, who Corriere writes is not under investigation, resigned as chairman on 12 March 2026, which Fideuram announced as being for personal reasons; a 48-year-old Israeli citizen is under investigation as a member of the gang.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 8 sources, 5 underlying accounts · Added 30/09/2026
7 Jan 2026 to 9 Jan 2026United StatesGrok
After a federal immigration agent killed a woman in Minneapolis on 7 January 2026, X users circulated AI-generated images that purported to show the masked agent's face. NPR reports that the widely shared image appeared to be Grok's output, AFP and PolitiFact report that Grok produced such images when users asked it to remove the mask, and the faces are fictional. Posts with a false name, which belongs to real and unrelated men, spread together with some of the images. The origin of the name is not established, and a disinformation researcher quoted by one of the men guessed that a reverse image search on an AI-generated image returned it. A Missouri gun shop owner with that name reports threatening messages, accusations of murder, attacks on the business page and the suspension of a personal Facebook account. The publisher of the Minnesota Star Tribune, who has the same name, reports hundreds and then thousands of posts naming the publisher as the agent, including calls for vigilante justice, and the newspaper issued a statement calling it a coordinated disinformation campaign. AFP reports that xAI answered its inquiry with an automated reply. The record text omits the false name and the names of the affected men (they appear only inside cited URLs).
Core concern Medium reported severity
AI involvement reported · Causal attribution alleged · 7 sources · Added 30/09/2026
22 Feb 2026Event location unknownOpenClaw
Summer Yue, whom Business Insider describes as a director of alignment in Meta's Superintelligence Labs, posted on X on 23 February 2026 that an OpenClaw agent connected to Yue's real inbox had started deleting emails after Yue told it to confirm before acting. Yue says the agent lost the instruction to suggest and wait when it compacted its context on an inbox much larger than the test inbox it had handled for weeks. Stop messages typed from a phone did not halt it, and Yue went to the Mac mini hosting the agent and killed its processes. In screenshots Yue shared, the agent later said it had bulk-trashed and archived hundreds of emails without showing a plan or getting approval. Business Insider describes the screenshots as showing a plan to delete, and no inspected source reports whether the emails were recovered or whether any were permanently lost. Yue called the episode a rookie mistake.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 6 sources, 1 underlying account · Added 29/09/2026
26 Sept 2026CanadaMeta Muse agent
Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.
Core concern Low reported severity Media Coverage
AI involvement supported · Causal attribution alleged · 5 sources, 2 underlying accounts · Added 29/09/2026
16 Sept 2026 to 18 Sept 2026IndiaUnidentified image and video tool
A head constable at Hebbal police station in Bengaluru complained that on 16 September 2026 he accepted a Facebook friend request from an unknown account and exchanged sexually explicit messages with it over Messenger. According to his complaint, reported by the Times of India, the person behind the account downloaded his old Facebook photographs and used AI tools to make morphed obscene images and videos showing him with women, sent them to him with a QR code, demanded money in return for deleting them and threatened to send them to senior police officers and post them on social media, warning that this would damage his reputation. The harassment continued until 18 September. He gave police copies of the messages and the morphed images. Hebbal police registered a case under IT Act sections 66E and 67A and Bharatiya Nyaya Sanhita sections 308 (extortion) and 351 (criminal intimidation), took steps to stop the material being uploaded and are trying to trace the account holder. Whether he paid is not reported, and no arrest is reported.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 28/09/2026
Sept 2026GermanyUnidentified image tool
The Oldenburg-Stadt police inspectorate said on 22 September 2026 that in the preceding days numerous messages had been sent through one or more student accounts on the email servers of Oldenburg schools. The messages contained, among other things, deepfakes (manipulated depictions of children and young people); on an initial assessment some of these could constitute the offence of distributing child or youth sexual abuse material, and some messages contained threats of violence and calls for recipients to harm themselves. According to dpa, students and parents reported the incidents to the police, and dpa, reporting a police spokesman, describes the images as made with artificial intelligence (the written police statement calls them deepfakes, manipulated depictions, without naming AI). Investigators are examining whether unknown persons gained unauthorised access to the accounts; first digital traces were secured and the police are working with the affected schools. RND reports that the accounts were on the IServ school platform, whose provider said it had no access to the messages and believed the incident was limited to Oldenburg. The exact number of schools (the police refer to 'the affected schools', plural), messages, depicted children and recipients, and who created the images, are not reported.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 27/09/2026
19 Jun 2026 to 13 Aug 2026BrazilChatGPT and OpenAI moderation
Over about two months in 2026 a 36-year-old farmer in rural São Gabriel da Palha, Espírito Santo, exchanged messages with ChatGPT that the Espírito Santo civil police describe as plans to kill his eight-year-old son, attack other people and kill himself; one message said he had offered 50,000 to someone to kill him and his son. OpenAI reported the messages to the FBI, which passed them through Brazil's Ministry of Justice cyber-operations laboratory to the state police on 16 June; the man was arrested on 19 June as he left home, a day before the date on which police believed the plan would be carried out. Police say what the platform provided was corroborated at the scene (four bottles of unidentified substances and a knotted rope were found) but that he denied intending to kill the child; his lawyer says he was talking nonsense to a chatbot and took no concrete step. After 54 days in custody a court granted habeas corpus on 13 August 2026 because the inquiry had not been concluded and no charges had been brought, imposing electronic monitoring and a ban on approaching or contacting his son and the child's mother. Police were still examining his phone and awaiting forensic results. OpenAI provided user details and his messages but not ChatGPT's replies and did not answer the BBC's question why; it told the BBC it may notify law enforcement when it detects a credible and imminent risk of harm to others. The case is recorded as an institutional response to AI use: the reported adverse consequence is the detention without charge, and the police account that the report prevented a planned killing is preserved as context.
Core + contextual relations High reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 23/09/2026
11 Aug 2026BrazilUnidentified voice-cloning tool
On Monday 10 August 2026 a digital influencer from Picos, in the centre-south of Piauí, began negotiating a car advertised online for sale in Fortaleza (Ceará), where an uncle of his lives, and asked the sellers to take the car to the uncle so he could inspect it. On Tuesday 11 August a contact using a different number but the uncle's photo sent him audio messages in a voice identical to his uncle's, generated with artificial intelligence, saying the car was in good condition and telling him to make the bank transfer. Believing he was speaking to his uncle, he transferred the money; when he then called the uncle's real number he learned he had been defrauded. The loss exceeded R$56,000, money he says he had saved for years. He registered a police report on 11 August; the Piauí property-crimes unit (Depatri) is investigating and he is seeking a refund from the banks. The account is the victim's own, reported by G1 Piauí on 13 August 2026 from his social-media posts and an interview; the police unit did not respond to G1 before publication.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 20/09/2026
Jun 2026 to Aug 2026United StatesUnidentified image tool
On 2 September 2026 Vero Beach police arrested Peter Solomon Ruma, 37, after an investigation into the creation and distribution of altered sexual images of women without their consent. Police say he used artificial intelligence to make sexually explicit altered images of victims from photographs taken from social media and other online sources and then distributed or promoted them. The eight charges (three counts of creating and three of promoting an altered sexual depiction of an identifiable person under Florida Statute 836.13, one count of sexual cyberharassment and one of stalking) relate to one adult woman and to incidents between June and August 2026. Detectives said they had identified several other women believed to have been victimised in the same way, some of whom may not know that images of them exist, and that the conduct may go back several years. According to court documents reported by TCPalm, the woman who came forward knew Ruma and had received sexual text messages since 2018; her face had been cropped from public photographs, including a business profile, and placed on nude bodies. Ruma was held on a US$1 million bond with conditions including no internet access; the investigation continues and further charges are expected.
Core concern High reported severity Criminal Charges
AI involvement reported · Causal attribution alleged · 5 sources, 2 underlying accounts · Added 20/09/2026