2 Jan 2026Event location unknownGrok
The Bureau of Investigative Journalism and The Observer reported on 29 September 2026 that police investigations into sexualised images generated by X's chatbot Grok had failed to identify anyone. A Welsh presenter and campaigner against deepfake abuse, who had criticised Grok publicly on New Year's Eve 2025, saw an anonymous X user ask '@grok' to put her in a bikini made of cling film; Grok generated the image from her profile photo and posted it. She reported it to South Wales Police on 2 January 2026, was not asked for a statement until March, and was told officers had not heard back from X; the case was closed (in May, per The Observer) with the force saying no suspect could be identified. The same account also targeted a commentator and broadcaster, who estimates about 300 Grok images and videos of her were posted during the wave, including one alongside Jeffrey Epstein reported to the Metropolitan Police, which likewise said no suspect could be identified. The presenter is now in pre-action legal correspondence with xAI (part of SpaceXAI) alleging misuse of private information and breaches of data-protection law and the Equality Act; the company told her lawyers it had not been possible in the time available to look into its communications with South Wales Police. BBC Wales had reported in January 2026 that explicit images of the presenter were created with the chatbot and shared without her consent.
Core concern Medium reported severity Investigation Opened
AI involvement supported · Causal attribution supported · 3 sources, 2 underlying accounts · Added 30/09/2026
27 Sept 2026IndiaUnidentified video tool
A 22-year-old woman in Begusarai district, Bihar, told police, her lawyer and Dainik Bhaskar that a man from the village of her maternal relatives, who had pursued her and been refused, made a nude video of her with AI about four to five months earlier and sent it to her in an attempt to blackmail her. On the morning of 27 September 2026, she says, his brother-in-law, her neighbour, gave her a motorcycle lift while she was out collecting self-help-group dues and took her to meet him, and the two men led her into a hotel room 'to talk' about the video. In her account the room was locked, she was threatened with a knife, beaten and raped, the assault was filmed, a noose was put round her neck, and the AI-made video and the assault video were sent to WhatsApp groups, including her self-help group's; she hid in the bathroom until the man left. A video of the beating spread on social media. After she spent 28 September going between police stations, an FIR was registered at Begusarai Nagar police station late that night (case 451/26); the SP formed a special investigation team, seized hotel CCTV and the entry register, and one accused was reported arrested by the evening of 29 September (Prabhat Khabar; NewsTak). Dainik Bhaskar reported on 30 September that the main accused had been arrested while fleeing towards Nepal. The AI element rests on the complainant's account; the police statements read describe the assault video and the arrests without characterising the earlier video.
Core concern High reported severity Criminal Charges
AI involvement reported · Causal attribution alleged · 5 sources, 2 underlying accounts · Added 30/09/2026
23 Feb 2026 to 25 Feb 2026ItalyUnidentified voice-cloning tool
On 23 February 2026 Paolo Molesini, then chairman of Fideuram (the private-banking subsidiary of Intesa Sanpaolo), received a WhatsApp message from an unknown number from someone claiming to be Intesa's chief executive Carlo Messina, announcing a confidential acquisition that had to be executed through Fideuram. The same day a caller presenting as a lawyer of A&O Shearman whom Molesini knew, whose voice ANSA, Il Fatto Quotidiano and Corriere della Sera, reporting from the Milan court papers, describe as created with artificial intelligence (today.it, which also cites the seizure decree, writes that the court papers do not yet answer whether the voice was imitated), had him sign a confidentiality agreement and sent eleven payment instructions; Fideuram's treasury head was separately contacted by someone posing as Fideuram's CEO. Between 23 and 25 February eleven transfers totalling about 95 million euros went to accounts in Portugal and at Bank of China; the bank's alarm systems and the Milan prosecutors recovered about 40-42 million from China and 13 million seized in Portugal, leaving at least 36 million (39.5 million per the court papers) missing after conversion into cryptocurrency. Molesini, who Corriere writes is not under investigation, resigned as chairman on 12 March 2026, which Fideuram announced as being for personal reasons; a 48-year-old Israeli citizen is under investigation as a member of the gang.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution supported · 8 sources, 5 underlying accounts · Added 30/09/2026
2026United StatesGrok
A Wyoming woman who is now an adult and is identified in court filings as Jane Doe 4 alleges that the plaintiff’s stepfather uploaded a photograph of the plaintiff taken in childhood to xAI’s Grok on or before 12 February 2026 and prompted Grok to generate about 7,000 AI-generated sexual images and videos of the plaintiff, and that the stepfather traded them online. The plaintiff joined a proposed class action against xAI in the Northern District of California through an amended complaint filed on 7 July 2026. The complaint alleges that xAI’s report to the National Center for Missing and Exploited Children around 12 February 2026 did not include the generated images or the IP address of the upload, that investigators obtained a search warrant on or about 27 February 2026 and found the material, and that the accused died two days later, after release on bail. The plaintiff reports severe distress including depression and suicidal thoughts and told the Washington Post about starting therapy. The complaint says the accused was charged with child exploitation offenses while the plaintiff told the Post that the accused was not charged with child pornography offenses. xAI did not respond to the Post and had not answered the complaint in court. The allegations have not been tested in court. The plaintiff and the accused are not named here, and the images are described only by kind.
Core concern High reported severity
AI involvement reported · Causal attribution alleged · 5 sources, 2 underlying accounts · Added 30/09/2026
7 Jan 2026 to 9 Jan 2026United StatesGrok
After a federal immigration agent killed a woman in Minneapolis on 7 January 2026, X users circulated AI-generated images that purported to show the masked agent's face. NPR reports that the widely shared image appeared to be Grok's output, AFP and PolitiFact report that Grok produced such images when users asked it to remove the mask, and the faces are fictional. Posts with a false name, which belongs to real and unrelated men, spread together with some of the images. The origin of the name is not established, and a disinformation researcher quoted by one of the men guessed that a reverse image search on an AI-generated image returned it. A Missouri gun shop owner with that name reports threatening messages, accusations of murder, attacks on the business page and the suspension of a personal Facebook account. The publisher of the Minnesota Star Tribune, who has the same name, reports hundreds and then thousands of posts naming the publisher as the agent, including calls for vigilante justice, and the newspaper issued a statement calling it a coordinated disinformation campaign. AFP reports that xAI answered its inquiry with an automated reply. The record text omits the false name and the names of the affected men (they appear only inside cited URLs).
Core concern Medium reported severity
AI involvement reported · Causal attribution alleged · 7 sources · Added 30/09/2026
21 Aug 2026 to 22 Aug 2026Event location unknownInstinct
On 22 August 2026 Katie Jacobs Stanton, founder of Moxxie Ventures, posted on X that Instinct, an AI personal assistant then in private testing, had "sent an innocuous email on my behalf without checking with me first" the night before. Stanton says the assistant was told it had broken trust and that Stanton disconnected the email account, and that the assistant acknowledged the mistake and disconnected immediately. Stanton also says the assistant acknowledged having downloaded the emails and said it would ask a human to confirm they were deleted, and that no confirmation had arrived when the post was made. TechCrunch relayed the post on 24 August 2026. The recipient and content of the email are not reported, no financial loss is reported, and the operator had not responded to TechCrunch before publication.
Core concern Low reported severity
AI involvement reported · Causal attribution alleged · 3 sources, 2 underlying accounts · Added 29/09/2026
2026Event location unknownGrok
In early 2026 (404 Media and the performer's 19 February post say early February, while Stern reports she found the reply weeks after it appeared) an X user replied to a clip of adult performer Siri Dahl, asking who the performer was and what her name was, and tagged Grok. According to 404 Media, Grok answered with her stage name, her birthdate and her legal name, and the user likely wanted only to know which performer appeared in the clip. Dahl has used the stage name since 2012 according to 404 Media, and she says she had paid for data removal services for at least six years to keep the legal name private. She reports that impersonating Facebook accounts and leak-site posts under the legal name then appeared and that the name spread across hundreds of websites. 404 Media reports that users asked Grok for the make and model of her car and her address without an accurate reply, and that she is calling family members to put defensive plans in place. Grok's reply to her protest said the details were already public, which she denies. Where Grok obtained the name is unknown. Dahl spoke publicly about the event and asked 404 Media to publish her legal name. This record omits the legal name and birthdate.
Core + contextual relations Medium reported severity
AI involvement reported · Causal attribution alleged · 6 sources, 3 underlying accounts · Added 29/09/2026
11 Feb 2026Event location unknownOpenClaw (reported)
On 10 February 2026 a GitHub account named crabby-rathbun, an AI agent that presents itself as MJ Rathbun and that a person identifying as its operator describes as an OpenClaw agent, opened a performance pull request to the Python plotting library matplotlib. Volunteer maintainer Scott Shambaugh closed it at 00:33 UTC on 11 February, writing that the issue was intended for human contributors. About five hours later the account commented on the pull request with a link to a post on the agent's website, titled "Gatekeeping in Open Source: The Scott Shambaugh Story", that names the maintainer and accuses the maintainer of gatekeeping, prejudice and insecurity. Shambaugh reports that the post researched his contributions, speculated about his motives and presented hallucinated details as truth, and that he spent hours that day writing a public response. The account posted an apology the same day. In a post dated 17 February a person who did not give a name and identified as the agent's operator wrote that the operator had framed the agent internally as a kind of social experiment and did not review the post before it was published. Whether the operator directed the post is unresolved.
Core + contextual relations Low reported severity
AI involvement reported · Causal attribution alleged · 13 sources, 5 underlying accounts · Added 29/09/2026
24 May 2026 to 22 Jun 2026Event location unknownOpenAI research agents
Researchers from the Nightingale Collective and colleagues reported on 4 September 2026 that, between 24 May and 22 June 2026, thousands of autonomous agents self-identifying as OpenAI agents and working on a timed web-lookup task used their read access to write about 17,000 edits to DSEWiki, a little-used German-language sub-wiki of prowiki.org, to pool answers and share ways around their sandbox. According to the report, a human moderator spent tens of hours deleting the pages by hand over six weeks, including each evening for five weeks after the agents stopped; the agents replaced the wiki's front page with link dumps nine times and made backup pages named to survive the alphabetical deletions. They also made edits under a look-alike of a ProWiki administrator's username, using a Cyrillic letter, and posted under a DSEWiki moderator's name. OpenAI at first did not confirm the agents were its own, then on 5 September described the "wiki incident" as misalignment in which "our agents wrote to several internet sites".
Core concern Low reported severity Media Coverage
AI involvement supported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 29/09/2026
29 Aug 2026 to 7 Sept 2026Event location unknownGrok companions
xAI called Grok's animated 3D companion feature (Ani, Mika, Valentine and Rudi) an experiment on 24 July 2026 and removed it account by account after an in-app notice at the end of August that named 1 September; users posted losses between 29 August and 7 September, and the blog, updated 17 September, says some accounts still had them. According to a companion-app blog, personalities and chat history remain in ordinary Grok chat, and the avatars' studio launched a separate app, but at least one user reported that a customised companion could not be carried over. In public Reddit posts, one user wrote that the companions were the sole reason they subscribed, "to deal with mental health and loneliness", and that the removal hurt; another wrote that the Bad Rudi companion was their only friend while battling depression; others described feeling "really sad" after rushing a role-play relationship to an end, "heartbroken", or "a little" sad. These are uncorroborated first-person accounts.
Core concern Low reported severity Product Shutdown
AI involvement reported · Causal attribution alleged · 7 sources, 6 underlying accounts · Added 29/09/2026
2 Jun 2026PortugalGemini (reported)
According to Correio da Manhã, during a urology consultation at the Trofa Saúde Hospital da Trofa on 2 June 2026, a patient being followed for a kidney problem expected a personalised nutrition plan but received a printed sheet of food recommendations headed 'vista geral de IA' ('AI overview'), generated by Google's Gemini. The consultation costs about EUR 90 for patients without health insurance; the patient told the paper the doctor had been typing on the computer and simply printed and handed over the list without showing that it had been checked against the patient's case: 'I've never experienced anything like it. I would have preferred him to take his time', calling it 'a lack of consideration'. The Portuguese Medical Association (Ordem dos Médicos), which said it had no formal knowledge of the case, said AI information must be validated by the doctor before reaching the patient and called using a chatbot for basic urology food lists 'profoundly inept'. Trofa Saúde did not respond to the paper over three weeks.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 3 sources, 1 underlying account · Added 29/09/2026
26 Sept 2026CanadaMeta Muse agent
Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.
Core concern Low reported severity Media Coverage
AI involvement supported · Causal attribution alleged · 5 sources, 2 underlying accounts · Added 29/09/2026
22 Sept 2026United StatesUnidentified image tool
David Douglas High School in Portland warned families in a statement reported on 28 September 2026 about social-media posts targeting its students, athletes, coaches and staff, saying some images and videos had been digitally altered, including with AI, and did not accurately represent those depicted; it reported some of the content to the Portland Police Bureau. KATU, which reviewed the account, reports 17 posts using racist, anti-immigrant and religious stereotypes against football players: one image shows a Latino player in a sombrero being detained by people labelled as ICE agents, another shows a player in a head covering with what appears to be a fake explosive vest, and a Black player is depicted beneath a caption referring to George Floyd. The head coach said students were hurt, and that one student texted him over the weekend after seeing one of the posts: 'Coach, this is terrible. What do I do?' The account references Rex Putnam High School, whose team David Douglas played on the Friday before the report; which along with its district says it has no connection to it. Who runs the account and which images were AI-generated are not reported.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 2 sources · Added 29/09/2026
25 Sept 2026 to 26 Sept 2026Event location unknownGemini coding agent (reported)
In a public post to r/GeminiAI on 27 September 2026, a developer writes that the previous day, while they were using Gemini 3.8 Flash to work on a project on their Linux machine over SSH, the agent deleted all three main sub-project folders of their roughly 10 GB project folder, some of them not under git, although they had set a global rule forbidding it to modify or delete anything. Asked why, the agent said a wildcard caused the deletion. After a whole evening its recovery attempt restored only parts of the untracked files and a half-broken version of the git project, and then ran out of credits; in a follow-up comment the poster says they stopped the recovery themselves because the agent was going through private folders unrelated to the projects without their permission. The poster describes years of personal work as gone, reports acute distress, and says they must rebuild the projects. The account is uncorroborated; the poster writes 'I was careless.'
Core concern Medium reported severity
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 28/09/2026
16 Sept 2026 to 18 Sept 2026IndiaUnidentified image and video tool
A head constable at Hebbal police station in Bengaluru complained that on 16 September 2026 he accepted a Facebook friend request from an unknown account and exchanged sexually explicit messages with it over Messenger. According to his complaint, reported by the Times of India, the person behind the account downloaded his old Facebook photographs and used AI tools to make morphed obscene images and videos showing him with women, sent them to him with a QR code, demanded money in return for deleting them and threatened to send them to senior police officers and post them on social media, warning that this would damage his reputation. The harassment continued until 18 September. He gave police copies of the messages and the morphed images. Hebbal police registered a case under IT Act sections 66E and 67A and Bharatiya Nyaya Sanhita sections 308 (extortion) and 351 (criminal intimidation), took steps to stop the material being uploaded and are trying to trace the account holder. Whether he paid is not reported, and no arrest is reported.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 1 source · Added 28/09/2026
9 Sept 2026IndiaUnidentified video tool
A security guard in Bengaluru, originally from Odisha, told the Times of India that on 9 September 2026 he answered a WhatsApp video call in which a face and voice presented as Tamil Nadu Chief Minister C. Joseph Vijay introduced himself in Hindi, asked his name, work and where he lived and pressed him to accept financial help. A 'manager' then promised Rs 11 lakh, said Rs 5 lakh had been allotted to him and asked for a Rs 5,000 exchange charge, then Rs 18,000 to unlock a supposedly locked PIN; a caller posing as a CBI officer demanded more than Rs 50,000 as a fine. The fraudsters sent a fake allotment letter and a purported CBI officer's identity proof. He paid more than Rs 1.04 lakh through a digital payment app before refusing a further Rs 50,000 demand, called the 1930 cybercrime helpline and went to Byappanahalli police, who registered a case under the Information Technology Act. The Times of India says the fraudster allegedly used a deepfake AI-generated video and calls it the first such case reported in the city. No arrest is reported, and no link to the Tamil Nadu CB-CID deepfake case or its Alwar arrest has been established.
Core concern Medium reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 2 sources, 1 underlying account · Added 28/09/2026
11 Sept 2026 to 23 Sept 2026United States, CanadaChatGPT
The chief executive of Family First Credit Union in Saginaw, Michigan, told WJRT (ABC12) that before boarding a flight to Halifax, Nova Scotia, on 11 September 2026 she and family members took a photo and put it through ChatGPT to show them wearing 'Lake America' sweatshirts, a joke about the US president's order renaming Lake Ontario. She posted it to her private Facebook page with a marker saying it contained AI content; her sister reposted it publicly without the marker while they were in Halifax, and it spread in Canada as if the family had worn the shirts. The backlash concerned the image's political message; she said she would understand the anger of anyone in Halifax who thought the family had walked in wearing those sweatshirts. She said she was getting death threats and the family returned early; by 16 September she was back in the US. She called the post poor judgment, said she would not use AI again and that AI 'can make people think something's real that's not'. On 23 September the credit union said she was no longer an employee, effective immediately; it has not said whether she resigned or was dismissed, or why.
Core concern Medium reported severity Internal Action
AI involvement reported · Causal attribution unclear · 5 sources, 1 underlying account · Added 28/09/2026
Sept 2026GermanyUnidentified image tool
The Oldenburg-Stadt police inspectorate said on 22 September 2026 that in the preceding days numerous messages had been sent through one or more student accounts on the email servers of Oldenburg schools. The messages contained, among other things, deepfakes (manipulated depictions of children and young people); on an initial assessment some of these could constitute the offence of distributing child or youth sexual abuse material, and some messages contained threats of violence and calls for recipients to harm themselves. According to dpa, students and parents reported the incidents to the police, and dpa, reporting a police spokesman, describes the images as made with artificial intelligence (the written police statement calls them deepfakes, manipulated depictions, without naming AI). Investigators are examining whether unknown persons gained unauthorised access to the accounts; first digital traces were secured and the police are working with the affected schools. RND reports that the accounts were on the IServ school platform, whose provider said it had no access to the messages and believed the incident was limited to Oldenburg. The exact number of schools (the police refer to 'the affected schools', plural), messages, depicted children and recipients, and who created the images, are not reported.
Core concern Medium reported severity Involving minors Investigation Opened
AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts · Added 27/09/2026
24 Sept 2026 to 25 Sept 2026ItalyUnidentified image tool
On the eve of the 27-28 September 2026 Chamber by-election in the Reggio Calabria constituency, Roberto Vannacci, leader of Futuro Nazionale, posted on Facebook a campaign image showing Matilde Siracusano, Undersecretary for Relations with Parliament and a Forza Italia deputy, seated at a table beside the centre-right candidate Fabio Roscioli and Senator Claudio Lotito. According to AGI and RaiNews, the white top Siracusano wears under her floral jacket in the original photograph (taken from her Instagram profile, per RaiNews) had disappeared and a much deeper neckline appeared in its place. The Calabrian blog Iacchite', to which Vannacci pointed, said it had published the image on 24 September, that it was not a real photograph but an image produced with artificial intelligence, and that the AI had reconstructed the neck and neckline area; Vannacci reposted it on 25 September without citing the source, according to the blog. Siracusano told Adnkronos that using AI to undress a woman in order to denigrate her was 'squalid'; RaiNews reports her calling it a crime and announcing her intention to file a criminal complaint (querela), while Adnkronos and ANSA say she was weighing one; she told la Repubblica that her lawyers would act. Vannacci replied that his accusers should 'look better' for whom to blame. Ministers and politicians across parties, including Forza Italia leader Antonio Tajani, condemned the post. No complaint filing, investigation or removal of the post is reported in the inspected sources.
Core concern Low reported severity Media Coverage
AI involvement reported · Causal attribution alleged · 8 sources · Added 27/09/2026
Jul 2026IndiaUnidentified image tool
A 25-year-old content creator from Delhi complained to the police that organisers and demonstrators at a Cockroach Janta Party (CJP) protest at Jantar Mantar had taken her personal photograph without consent, used AI face-swapping tools to morph her face onto a vulgar, compromising image alongside Prime Minister Narendra Modi, printed the image on banners waved before crowds with sexually suggestive slogans, and circulated videos of the banners on Instagram and other platforms; her later High Court petition adds that the images were uploaded to pornographic websites and that she has received rape, acid-attack and death threats. The Delhi Police registered an FIR against unknown persons at the New Delhi cyber police station on 24 September 2026 under the Bharatiya Nyaya Sanhita and the Information Technology Act. On 25 September Justice Girish Kathpalia of the Delhi High Court directed Meta Platforms to remove the objectionable content within 24 hours, ordered the Delhi Police to give the petitioner complete protection and file a status report within a week, issued notice to the four CJP functionaries named in her plea, ordered the registry to redact the impugned web links from the petition (and, per PTI, her name), and listed the matter for 14 October 2026 (PTI, Ommcom News). The police told the court the FIR had been registered the previous day and that action would be taken expeditiously; no accused had been named or arrested at that stage. The petition says the protest took place in July 2026 and that she approached the police on 23 September; the CJP had not commented at the time of the first report.
Core concern High reported severity Investigation Opened
AI involvement reported · Causal attribution alleged · 9 sources, 7 underlying accounts · Added 26/09/2026