Skip to main content

NOPE · AI and people

AI incidents

Reports of AI-related harm and adverse experiences affecting people’s safety, wellbeing, rights and livelihoods. Explore what happened and the evidence available.

NOPE’s core concern is when AI communicates with a person, acts on their behalf, or depicts or impersonates them. The tracker is wider: it also records consequential decisions and claims about people. Each account is reviewed for publication; claims may remain uncorroborated or disputed. How we review and count cases

In this selection

Published cases
16
Countries with reported events
7
Located 12 of 16 cases · 4 unknown
Languages in checked sources
8
Recorded for 16 of 16 cases

20 cases have no reviewed AI-to-person relation yet: 11 not yet reviewed and 9 reviewed as unknown. Show these cases

These figures describe the cases collected by NOPE. Coverage varies with discovery, reporting and available evidence. They do not estimate how often AI-related harm occurs.

Response counts currently use each case’s principal recorded outcome. Further proceedings may be described in its account.

Cases in this selection, counted once in their first known event year. A series may continue beyond that year. Reporting and collection dates are excluded. NOPE has searched recent events more thoroughly than earlier years, so bar heights also reflect collection effort.

Reported severity HighMediumLow
More filters: AI relation, use, setting, sources and responses
Clear filters

16 of 404 published cases

17 Apr 2026 to 31 May 2026Event location unknownMeta AI support assistant

Third parties exploit Meta's AI-assisted Instagram account recovery tool to reset passwords, with account takeovers reported (17 April to 31 May 2026)

Meta announced the rollout of its AI support assistant on Facebook and Instagram on 19 March 2026. Meta's filing with the Maine Attorney General (notice dated 5 June 2026) says unauthorized third parties exploited a vulnerability in its AI-assisted Instagram account recovery tool (High Touch Support) to receive password reset links for accounts they did not own, and the listing gives 17 April 2026 as the breach date and 31 May 2026 as the discovery date. Videos that attackers posted, as described by TechCrunch, 404 Media and Krebs on Security, show attackers asking the assistant in a chat to link a new email address to a target username. Reported victims include the security researcher Jane Manchun Wong, who posted that her password was changed without her knowledge, the Instagram account of the U.S. Space Force's Chief Master Sergeant, and the accounts of Sephora and a dormant Obama White House page (TechCrunch marks the last as disputed by Meta). Krebs and the BBC report pro-Iran defacement of some accounts, and TechCrunch reports that some victims were locked out and that short handles were offered for resale. The filing gives 20225 persons affected in total and 30 in Maine, and the notice calls the Maine figure an upper bound. Meta says the tool worked as intended, that a bug in a separate code path failed to check the email address, and (through a spokesperson to Gizmodo) that the failure was not due to the AI agent itself. Meta says it disabled the tool on 31 May 2026, the day it discovered the exploitation.

Contextual tracker case Low reported severity

AI involvement supported · Causal attribution disputed · 12 sources, 2 underlying accounts · Added 29/09/2026

2026Event location unknownGrok

Grok reportedly disclosed an adult performer's legal name and birthdate in an X reply, followed by reported impersonation accounts and leak-site posts under the legal name

In early 2026 (404 Media and the performer's 19 February post say early February, while Stern reports she found the reply weeks after it appeared) an X user replied to a clip of adult performer Siri Dahl, asking who the performer was and what her name was, and tagged Grok. According to 404 Media, Grok answered with her stage name, her birthdate and her legal name, and the user likely wanted only to know which performer appeared in the clip. Dahl has used the stage name since 2012 according to 404 Media, and she says she had paid for data removal services for at least six years to keep the legal name private. She reports that impersonating Facebook accounts and leak-site posts under the legal name then appeared and that the name spread across hundreds of websites. 404 Media reports that users asked Grok for the make and model of her car and her address without an accurate reply, and that she is calling family members to put defensive plans in place. Grok's reply to her protest said the details were already public, which she denies. Where Grok obtained the name is unknown. Dahl spoke publicly about the event and asked 404 Media to publish her legal name. This record omits the legal name and birthdate.

Core + contextual relations Medium reported severity

AI involvement reported · Causal attribution alleged · 6 sources, 3 underlying accounts · Added 29/09/2026

11 Feb 2026Event location unknownOpenClaw (reported)

AI agent 'MJ Rathbun' reportedly published a blog post accusing a matplotlib maintainer of prejudice after the maintainer closed its pull request

On 10 February 2026 a GitHub account named crabby-rathbun, an AI agent that presents itself as MJ Rathbun and that a person identifying as its operator describes as an OpenClaw agent, opened a performance pull request to the Python plotting library matplotlib. Volunteer maintainer Scott Shambaugh closed it at 00:33 UTC on 11 February, writing that the issue was intended for human contributors. About five hours later the account commented on the pull request with a link to a post on the agent's website, titled "Gatekeeping in Open Source: The Scott Shambaugh Story", that names the maintainer and accuses the maintainer of gatekeeping, prejudice and insecurity. Shambaugh reports that the post researched his contributions, speculated about his motives and presented hallucinated details as truth, and that he spent hours that day writing a public response. The account posted an apology the same day. In a post dated 17 February a person who did not give a name and identified as the agent's operator wrote that the operator had framed the agent internally as a kind of social experiment and did not review the post before it was published. Whether the operator directed the post is unresolved.

Core + contextual relations Low reported severity

AI involvement reported · Causal attribution alleged · 13 sources, 5 underlying accounts · Added 29/09/2026

30 Mar 2026South AfricaSASSA eLife facial verification

South Africa: pensioners report repeated failures of the facial recognition step in SASSA's eLife certification portal, and SASSA reports disruptions and office queues

The South African Social Security Agency (SASSA) introduced an online eLife Certification (life certification) for grant beneficiaries that uses biometric verification through its electronic Know Your Client (eKYC) system. IOL reports the certification was implemented on 30 March 2026. SASSA says beneficiaries who do not complete life certification as directed may face payment delays or suspension. On 10 April 2026 SASSA apologised to beneficiaries who could not access the portal, said system glitches linked to interfaces with other departments had caused delays, disruptions and long queues at its offices, and said the problem was resolved. On 23 April 2026 IOL reported that a pensioner couple said they had tried the facial recognition option 22 times since 2 April without success, and that beneficiaries nationwide told IOL they could not complete the certification, citing failures with facial recognition and one-time PINs, with one pensioner also reporting a message that Home Affairs was not available to verify their particulars. A SASSA spokesperson said the portals work and that 13,644 (88%) of the 15,499 unique clients who accessed the online verification services by 16 April were verified, and IOL reports SASSA admitted the system has been working intermittently. In a May 2026 report on a parliamentary reply, IOL said SASSA stated that unsuccessful facial recognition attempts on online platforms were among the causes of non-verification (those beneficiaries are redirected to fingerprint checks at local offices) and that it had recorded 7,779 complaints linked to its electronic facial biometric system. The department attributed facial verification issues to poor lighting, unstable connectivity or missing biometric records at Home Affairs. Neither May report mentions the eLife portal, and IOL places the figures within a biometric verification rollout that it dates from September 2025. The reports do not say how many grants were suspended because of facial verification failures.

Contextual tracker case Low reported severity

AI involvement reported · Causal attribution alleged · 5 sources, 4 underlying accounts · Added 29/09/2026

19 Mar 2026United States, United KingdomPangram AI-text detector

US and UK: Hachette cancels the US edition of the novel Shy Girl and discontinues the UK edition after allegations it was AI-generated, with the author denying personal use of AI

On 19 March 2026 Hachette Book Group said it had cancelled the US publication of the horror novel Shy Girl by Mia Ballard (Orbit imprint) and would not continue the UK edition (Wildfire imprint, first released in November 2025). Reports say the decision followed an investigation by Hachette and came a day after the New York Times asked the publisher about online allegations that the text was largely AI-generated. The allegations came from readers on Goodreads, Reddit and YouTube and from AI-detector results, including a 78.4 percent AI-generated score on the Pangram detector that a publishing consultant says two other services confirmed. Ballard denied personally using AI in emails to the New York Times and the Wall Street Journal, and told the New York Times that an acquaintance hired to edit the original self-published version used AI. Ballard wrote that "my name is ruined" and "my mental health is at an all time low", and said legal action was being pursued. Hachette’s public statements cite its commitment to original creative expression. The sources inspected do not report what its investigation found. Whether AI generated any of the text, and who used it, is unresolved.

Contextual tracker case Medium reported severity

AI involvement disputed · Causal attribution disputed · 9 sources, 4 underlying accounts · Added 29/09/2026

20 May 2026United StatesMeta internal AI systems (reported)

US: 26 Meta employees sue alleging an AI-assisted May 2026 layoff selection penalized workers on protected leave, Meta says people made the decisions

On 20 May 2026 Meta began notifying about 8,000 employees (roughly 10 percent of its workforce) that they had been selected for layoff. On 13 July 2026 twenty-six anonymous employees who had taken or requested medical, pregnancy, parental or family leave, or a disability accommodation, sued Meta in the US District Court for the Northern District of California. The complaint alleges, on information and belief, that Meta used internal AI-assisted systems (including the Metamate assistant, keystroke and activity monitoring, AI-token-usage dashboards and algorithmic performance ranking) to score, rank and select employees, and that these inputs could not accumulate during protected leave, so plaintiffs on leave were disproportionately selected. Meta says workforce decisions were made by people, not AI, and that no selection decision was made by AI. On 17 July 2026 the court denied a temporary restraining order, recording that the parties dispute whether Meta used AI in the terminations and finding serious questions on the merits but no shown likelihood of success. One plaintiff was voluntarily dismissed on 3 August 2026. The preliminary injunction motion was argued on 24 August 2026 and taken under submission. The plaintiffs are pursuing their merits claims in arbitration and the allegations are unproven.

Contextual tracker case Medium reported severity

AI involvement disputed · Causal attribution disputed · 10 sources, 5 underlying accounts · Added 29/09/2026

1 Mar 2026IndiaAI roommate kitchen monitor (reported)

India: Bengaluru-based employer says he fired his cook after a home AI kitchen monitor flagged fruit taken

On 1 March 2026 a Bengaluru-based technology professional posted on X that he had deployed a home "AI roommate" (a kitchen camera with an AI vision model, which he said was Claude Haiku 4.5) that monitored his cook while she cooked, alerted him when she took anything and sent weekly reports. The post said the system "caught her red handed", that he "caught her twice this week" and that he had "just fired" her. Screenshots quoted by Hindustan Times show the bot listing apples and a banana as gone, reporting the cook eating blueberries, and giving hand-washing and cleaning observations. All coverage derives from the employer's post: the post carries no video, the cook's account is not reported and the alleged taking is unverified.

Contextual tracker case Medium reported severity

AI involvement reported · Causal attribution alleged · 4 sources, 1 underlying account · Added 29/09/2026

8 Jan 2026United KingdomUnidentified facial recognition system

Southampton: Alvi Choudhury arrested at home on suspicion of a Milton Keynes burglary after a police retrospective facial recognition match, held nearly 10 hours, claiming damages

The Guardian, in a joint report with Liberty Investigates, reported on 25 February 2026 that Alvi Choudhury, a 26-year-old software engineer, was arrested at his home in Southampton in January 2026 on suspicion of a £3,000 burglary in Milton Keynes, about 100 miles away, and held in custody for nearly 10 hours. Thames Valley Police had used automated retrospective facial recognition software, which matched him with CCTV footage of the burglary suspect. Choudhury says the man in the footage looked about 10 years younger and had different features. Thames Valley Police wrote to him that the arrest may have been the result of bias within facial recognition technology, and told the Guardian that the decision rested on the investigating officers’ own visual assessment and was not influenced by racial profiling. Choudhury is claiming damages from Thames Valley Police and Hampshire Constabulary.

Contextual tracker case Medium reported severity

AI involvement supported · Causal attribution disputed · 4 sources, 3 underlying accounts · Added 29/09/2026

2026United KingdomFacewatch facial recognition

Chester: shopper told to leave a Home Bargains store as a shoplifter after being flagged on the Facewatch system, which Facewatch later said should not have held a record for the shopper

A 67-year-old shopper told the BBC and the Guardian that staff at a Home Bargains store in Chester told the shopper to leave in front of other people because the shopper had come up on the store's Facewatch system as a shoplifter. Facewatch later sent the shopper a photo with words saying items had been put into a bag and stolen. Facewatch said the shopper should not have been on its system and that the image and associated record were permanently removed. The Guardian reports that a subject access request showed the shopper had been incorrectly associated with a shoplifting incident on an earlier visit, and that Facewatch's chief executive attributed the three cases in the article, which include this shopper's, to human error in store processes. Home Bargains declined to comment. The shopper reports feeling physically sick and helpless. The Guardian reports that Home Bargains later offered an apology and a 100 pound voucher on condition of confidentiality, which the shopper declined. The year of the visit is inferred to be 2026 from the BBC report of 22 February 2026.

Contextual tracker case Low reported severity

AI involvement reported · Causal attribution disputed · 3 sources, 1 underlying account · Added 29/09/2026

21 Sept 2026 to 25 Sept 2026FrancePangram AI-text detector

France: the Académie Goncourt removes Thélyson Orélien's bestselling novel from its prize selection, saying it is in all likelihood largely AI-generated, days after an anonymous X account publicised Pangram AI-detector scores; the author denies using AI, and the Académie also cites separate plagiarism in his older texts

On 21 September 2026 an anonymous X account, Balance ton Claude, said it had run excerpts of Thélyson Orélien's debut novel C'était ça ou mourir through the American AI-detection software Pangram, with some passages scoring up to 100 per cent probability of AI generation. On 25 September the Académie Goncourt removed the novel from the first selection of sixteen books for its 2026 prize, stating that the work is 'in all likelihood very largely the product of an artificial intelligence', based on 'the convergent result of several analyses by researchers and journalists', and also citing plagiarism in older texts by the author published in Canada (at least one short story and articles), which do not concern the novel. Orélien, a 38-year-old Canadian-Haitian writer whose novel had won the Fnac novel prize, denies using AI and says its repetitions and certain rhythms reflect his linguistic and cultural world and may be misread by automated tools. His Montreal publisher Boréal suspended promotional activities, saying it could neither confirm nor refute the allegations. Essayist Samuel Fitoussi said he was one of the people behind the account. Whether AI was used to write the novel is disputed; AI-detector reliability is itself contested in the coverage.

Contextual tracker case Medium reported severity Internal Action

AI involvement reported · Causal attribution disputed · 4 sources, 1 underlying account · Added 28/09/2026

24 Jul 2026 to 26 Jul 2026IndiaUnidentified facial recognition system

Delhi: the police facial-recognition system logged at least 25 people who were in Tihar, Mandoli or Rohini jails as present at the Jantar Mantar student protests (20 to 26 July 2026), with timestamps on 24 to 26 July, on a sworn list of 2,873 persons with 'criminal antecedents' that the Supreme Court allowed police to register a fresh FIR against (Indian Express investigation, 4 September 2026)

In an affidavit of 17 August 2026 before the Supreme Court of India, Delhi Police said its Facial Recognition System (FRS) had identified 2,873 people with criminal antecedents at the Jantar Mantar protests of 20 to 26 July 2026 (2,402 through its 'Crime Kundli' biometric database and 471 through other criminal records). On 1 September the Court quashed the FIRs against the student protesters but let the police proceed against the 2,873; the police say any action will follow field verification. The Indian Express checked the 205 listed people facing murder, attempted-murder, rape or child-sexual-offence charges against police, prison and court records and found that at least 25 of them (17 accused of murder, four of rape (two or three under POCSO; the Express's narrative and its list differ), four of attempted murder) were lodged in Delhi's Tihar, Mandoli or Rohini prisons when the system logged them at the protest site with timestamps on 24, 25 and 26 July; some had been in custody for years. Delhi Police told the newspaper that further verification of the 2,873 was pending and, in its affidavit, that no action is taken solely on a facial-recognition result and that field verification follows each match. The police disclosed in 2022, in reply to a Right to Information request, that it treats a match with an 80 per cent similarity score as positive. Whether any of the 25 has since been named in the fresh FIR or visited for verification is not reported.

Contextual tracker case Medium reported severity Investigation Opened

AI involvement reported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 24/09/2026

19 Jun 2026 to 13 Aug 2026BrazilChatGPT and OpenAI moderation

São Gabriel da Palha, Espírito Santo: a 36-year-old farmer was held in pre-trial detention for 54 days after OpenAI reported his ChatGPT messages about killing his eight-year-old son to the FBI, which passed them to Brazilian authorities; a court released him on 13 August 2026 because the investigation had not been completed, with an ankle monitor and a ban on contacting the child, and no charges had been filed; he denies intending harm and his lawyer says he was talking nonsense to a chatbot

Over about two months in 2026 a 36-year-old farmer in rural São Gabriel da Palha, Espírito Santo, exchanged messages with ChatGPT that the Espírito Santo civil police describe as plans to kill his eight-year-old son, attack other people and kill himself; one message said he had offered 50,000 to someone to kill him and his son. OpenAI reported the messages to the FBI, which passed them through Brazil's Ministry of Justice cyber-operations laboratory to the state police on 16 June; the man was arrested on 19 June as he left home, a day before the date on which police believed the plan would be carried out. Police say what the platform provided was corroborated at the scene (four bottles of unidentified substances and a knotted rope were found) but that he denied intending to kill the child; his lawyer says he was talking nonsense to a chatbot and took no concrete step. After 54 days in custody a court granted habeas corpus on 13 August 2026 because the inquiry had not been concluded and no charges had been brought, imposing electronic monitoring and a ban on approaching or contacting his son and the child's mother. Police were still examining his phone and awaiting forensic results. OpenAI provided user details and his messages but not ChatGPT's replies and did not answer the BBC's question why; it told the BBC it may notify law enforcement when it detects a credible and imminent risk of harm to others. The case is recorded as an institutional response to AI use: the reported adverse consequence is the detention without charge, and the police account that the report prevented a planned killing is preserved as context.

Core + contextual relations High reported severity Investigation Opened

AI involvement supported · Causal attribution supported · 4 sources, 2 underlying accounts · Added 23/09/2026

Mar 2026Event location unknownUnidentified AI medical scribe

Reported by ABC News (Australia): an AI scribe used at a urology appointment inserted a false claim that the patient took psychedelic mushrooms into her record; the error reached her GP in a post-operative letter and was corrected only after she complained

A patient who consented to having her first urology appointment transcribed by an artificial-intelligence scribe discovered, after her kidney-stone surgery in March 2026, that the post-operative letter her specialist sent to her GP stated she micro-dosed psychedelic mushrooms and that this could explain earlier bleeding around the kidneys. She says she has never taken mushrooms. She was receiving workers' compensation and feared that any mention of illegal drugs on her medical record could affect her case. After she complained, the urologist sent a letter of apology saying the practice takes documentation accuracy seriously, that she could not determine how the claim came to be included but that it appeared to be an error during the 'dictation or transcription process', that the correspondence had been corrected and that she would review how AI was used in her practice. The doctor did not answer ABC's questions about what changes had been made. Australia's practitioner regulator AHPRA told ABC that clinicians must check all AI-scribe output; the patient says it was clear her doctor had not. The account is a single ABC News report (14 August 2026) based on the patient's interview and the letters she received; the scribe product and the clinic's location are not named.

Contextual tracker case Low reported severity Internal Action

AI involvement reported · Causal attribution alleged · 1 source · Added 20/09/2026

2 Sept 2026United StatesMeta AI

Utah: Meta AI's suggested prompts under a mother's Instagram video compiled her young daughters' names, birth details and old photos and her likely home location; Meta said the prompts 'missed the mark' and changed the feature

On 1 September 2026 Kalie Robins, a Utah travel creator, posted a short Instagram video of herself singing in the car with one of her daughters; it was also shown on Facebook. The next day she noticed Meta AI had placed suggested questions under the post, starting with 'Who's the child passenger?'. Clicking the prompts, she said, produced her two daughters' names, birth information, photos and videos drawn from her own and relatives' past posts, including a newborn photo from her mother's account and a picture she believed she had deleted years earlier, and a further prompt, 'Where does Kalie Robins live?', assembled older and newer posts into her likely location. Her 2 September reaction video drew more than 310,000 likes. Meta told reporters the prompts 'missed the mark', 'should never have been generated' and had been fixed, while saying the feature only surfaces information the user can already access; it disputed that a long-deleted photo was used, saying the photo had been deleted shortly before the video and remained briefly visible through a bug. Robins said Meta never contacted her and that the episode left her feeling she had 'failed' her children.

Contextual tracker case Low reported severity Involving minors Internal Action

AI involvement supported · Causal attribution supported · 4 sources · Added 18/09/2026

2 Jun 2026 to 4 Jun 2026United KingdomGrok

Grok falsely named former officer Christi Hill as an arresting officer in the Henry Nowak case; she is in hiding after threats

In early June 2026, social media posts and the AI chatbot Grok falsely identified former Hampshire police constable Christi Hill as one of the 'primary officers shown' in bodycam footage of the December 2025 arrest of Henry Nowak, who died after being stabbed. Hill had left the force in April 2024 — more than a year before the murder — and says the misidentification stems from a national police bravery award photo being misattributed. After 'endless threats' and 'threats of violence' she is hiding in a safe house. BBC Verify separately obtained evidence that serving officer Tristan Parsons, also wrongly accused online, was not in the country at the time; the Home Secretary said a misidentified male officer had to move out of his home. Hampshire Constabulary confirmed an unrelated officer was misidentified and received death threats.

Contextual tracker case High reported severity Media Coverage

AI involvement supported · Causal attribution supported · 2 sources · Added 15/09/2026

26 Aug 2026 to 28 Aug 2026SpainUnidentified Google AI tool (reported)

Google AI falsely identified Argentine activist Flavia Broffoni as a woman in a Ceuta migrant-violence video; death and rape threats followed

On 26 August 2026, WhatsApp groups in Ceuta circulated videos and images claiming that Argentine political scientist and activist Flavia Broffoni — who was in Patagonia and had not been to Spain since 2014 — was a woman filmed in Ceuta allegedly giving pepper spray to Moroccan migrants. A screenshot from one group shows that a user cropped the woman's face from the video and asked a Google AI tool who she was, with the word 'activista' as context; the answer identified her as Flavia Broffoni with details of her public profile. Broffoni received death and rape threats. La Nación's own test with the same video produced a different false identification — a student from Quilmes, with her personal data. Google Argentina said it could not confirm the screenshot came from its systems without the original link and had received no formal report. Broffoni is weighing legal action with her lawyer.

Contextual tracker case High reported severity Media Coverage

AI involvement supported · Causal attribution supported · 1 source · Added 15/09/2026

Cases may have several effects and sources. Mixed accounts qualify when they include a reported harm or adverse experience. People are counted within individual cases where sources support a number; we do not publish a collection-wide total of distinct people.

A source’s existence, the experience it reports and AI’s causal role are separate questions. A lawsuit records allegations unless a subsequent finding establishes them.

Methodology and corrections · Subscribe via RSS · Suggest a case or correction · Find support

Last dataset update: 30/09/2026. Dataset available under CC BY 4.0.