GovernanceCore

When AI causes harm

A record of AI systems causing real harm: physical injury, discrimination, privacy breaches, fabricated content, security misuse and reliability failures. Every entry carries a source you can open.

40 incidents recorded5 of 8 harm types seenUpdated Sep 7, 2026
How this record is built, and what it leaves out

Entries are harvested from public incident reporting, chiefly the AI Incident Database, alongside security research that surfaces harms general reporting misses. Each candidate has to describe something that actually happened rather than a risk that might: a proposal, a framework or a warning is not an incident. The source link is checked before publication.

One event is usually reported many times, so reports about the same incident are grouped and counted once. Where several outlets covered it, that is shown as corroboration rather than as separate entries.

This is a recent window, not a complete history, and it is weighted toward harms that get reported in English. For the full historical record see 1,600+ incidents indexed by the AI Incident Database and 17,000+ incident reports in the OECD AI Incidents Monitor.

Where

40 incidents

  1. 1 incident
  2. 5 incidents
  3. 5 incidents
  4. 4 incidents
    • Security & misuse
      Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies

      Russian-speaking hackers used SpaceX's (SPCX.O), opens new tab AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other firms earlier this year, according to data reviewed by Reuters and reports iss…

      AI Incident Database
    • Reliability failures
      Pizza Hut franchisee says AI caused $100M in damages

      Dive Brief: Pizza Hut franchisee Chaac Pizza Northeast has sued the franchisor, alleging the chain's Dragontail Artificial Intelligence system caused "cascading operational breakdowns," slowed down order times and disrupted integrations wi…

      AI Incident Database
    • Reliability failuresUnited States
      A Pizza Hut franchisee is suing over a forced AI system it says wrecked deliveries

      A lawsuit filed May 6 in Texas Business Court puts Chaac Pizza Northeast --- a franchisee running roughly 111 Pizza Hut locations spanning New York, New Jersey, Maryland, Washington, D.C., and Pennsylvania --- at the center of a dispute ove…

      AI Incident Database
    • Reliability failures
      Frustrated franchisee sues Pizza Hut over crappy kitchen AI

      The back-of-house AI system that Pizza Hut has mandated its restaurants to adopt has been so poorly received by some franchisees, that one is suing the company for $100 million in losses tied to the technology. Put that in your crust and st…

      AI Incident Database
  5. 2 incidents
    • Security & misuse
      Legal resident loses thousands seeking citizenship to AI immigration attorney

      NEW YORK (WABC) -- It's a perfect storm where online scammers use artificial intelligence to victimize vulnerable people out of thousands of dollars, with many losing their life savings, and immigrants are increasingly the target. Not only…

      AI Incident Database
    • Security & misuse
      Breaking Claude Code Opus 5 Auto Mode

      In this post, we explore how a simple website summary request hijacks Claude Code Opus 5 in Auto Mode and achieves code execution with 60-80% attack success rate using a small sample size. 
 
 This is interesting because a third-party evaluation commissioned by Anthropic showed a 0.00% prompt injection attack success rate for Opus 5 in Auto Mode. 
 Auto Mode Is Now the Default in Claud

      Embrace The Red
  6. 11 incidents
  7. 1 incident
  8. 1 incident
  9. 1 incident
  10. 1 incident
  11. 1 incident
  12. 1 incident
  13. 2 incidents
    • Reliability failures
      OWASP ASI03: Identity & Privilege Abuse in AI Agents

      OWASP ranks Identity & Privilege Abuse #3 because it sets the blast radius for every other AI agent risk.

      Adversa AI
    • Security & misuse
      Computer-Use and TOCTOU: What You Click Is Not What You Get!

      Last year, Jun Kokatsu disclosed an interesting vulnerability with ChatGPT Operator by exploiting a race condition. I was wondering if I could reproduce this attack chain, and this post describes the results of that research. 
 I had this post drafted for months, and yesterday at the Real-world AI security conference I included a video demo of this attack in my talk and that reminded me that I

      Embrace The Red
  14. 1 incident
  15. 1 incident
  16. 1 incident
  17. 1 incident
    • Security & misuse
      Top GenAI security resources — May 2026

      May 2026 in GenAI security: Anthropic's Mythos model running a 32-step network attack, new research bypassing GPT-5.4 safety, and LLM-specific CIS guidance.

      Adversa AI

Incident data is aggregated from public reporting. Titles and summaries belong to the outlets that published them, linked on every entry. See also the incident monitor and the regulation tracker.