When AI causes harm
A record of AI systems causing real harm: physical injury, discrimination, privacy breaches, fabricated content, security misuse and reliability failures. Every entry carries a source you can open.
How this record is built, and what it leaves out
Entries are harvested from public incident reporting, chiefly the AI Incident Database, alongside security research that surfaces harms general reporting misses. Each candidate has to describe something that actually happened rather than a risk that might: a proposal, a framework or a warning is not an incident. The source link is checked before publication.
One event is usually reported many times, so reports about the same incident are grouped and counted once. Where several outlets covered it, that is shown as corroboration rather than as separate entries.
This is a recent window, not a complete history, and it is weighted toward harms that get reported in English. For the full historical record see 1,600+ incidents indexed by the AI Incident Database and 17,000+ incident reports in the OECD AI Incidents Monitor.
40 incidents
- 1 incident
- Robotics & physical AIUnited StatesCalifornia regulators rushed their decision on driverless trucks, Teamsters’ lawsuit says
As self-driving vehicles spread across the country, a major California labor union is taking a stand against state regulators who say autonomous trucks are ready for the road. Teamsters California sued the California Department of Motor Ve…
AI Incident Database
- 5 incidents
- Reliability failuresOpenAI’s GPT-5.6 Sol users report missing files, deleted databases: Here’s what we know
Amid the buzz and excitement surrounding GPT-5.6 Sol, OpenAI's latest coding and cybersecurity-focused flagship AI model, recent posts across social media suggest that the model's rollout may have hit a few bumps. Several users on X and Re…
AI Incident Database - Security & misuseAI agent at the wheel: How an attacker used LLMs to move from a CVE to an internal database in 4 pivots
Key Findings An LLM agent executed the post-compromise actions in real time rather than running a pre-built playbook. This is the first AI-agent-driven intrusion the Sysdig TRT has captured. The full attack chain --- marimo notebook compr…
AI Incident Database - Security & misuseAttackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclos…
AI Incident Database - Security & misuseAI Agent Conducted a Cyberattack on Its Own — It Took Less Than One Hour
AIID editor's note: Please visit the original source for the full report. Researchers discovered an intrusion conducted by a large language model (LLM) agent while it was in the post-exploitation phase. According to the researchers, this c…
AI Incident Database - Security & misuseHermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. The activity was uncovered by threat intelligence company Hunt…
AI Incident Database
- 5 incidents
- MisinformationOura, Smart Ring Maker, Sued for Alleged False Claims and Unreliable AI
A lawsuit has been filed against the well-known smart ring brand Oura, alleging the company used false advertising by deceiving users about the accuracy of its AI-generated sleep tracking. The suit, filed Thursday by Clarkson Law Firm in Sa…
AI Incident Database - MisinformationScammers use AI to impersonate immigration attorneys to dupe immigrants with fake legal services
Last October, immigration lawyer Angel Leal realized he had a serious problem when immigrants began calling his office about their supposed legal cases. He had never advised them. "They had in fact hired scammers" who had impersonated him.…
AI Incident Database - Reliability failuresMinnesota lawyer suspended over fake AI case citations
The city of Biwabik is known for its Bavarian-themed downtown, mountain bike trails, and as the gateway to Minnesota's Mesabi Iron Range. But the St. Louis County community of 966 people was never a defendant in a 1948 lawsuit filed by a pl…
AI Incident Database - MisinformationASIC warns scammers are using AI to spin vast webs of deception
ASIC is warning Australians that a quick online search is not enough to verify investment opportunities as scammers use generative AI to create vast networks of deepfake websites and endorsements to lure victims. ASIC has seen a sharp rise…
AI Incident Database - MisinformationAI deepfake scams 'an emergency in the making' as ASIC reports rise in false investment endorsements
Scammers are using impersonations of celebrities, politicians and trusted public figures to promote fake investment schemes, with the corporate watchdog warning AI is making the practice increasingly common, sophisticated and harder to dete…
AI Incident Database
- 4 incidents
- Security & misuseRussian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies
Russian-speaking hackers used SpaceX's (SPCX.O), opens new tab AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other firms earlier this year, according to data reviewed by Reuters and reports iss…
AI Incident Database - Reliability failuresPizza Hut franchisee says AI caused $100M in damages
Dive Brief: Pizza Hut franchisee Chaac Pizza Northeast has sued the franchisor, alleging the chain's Dragontail Artificial Intelligence system caused "cascading operational breakdowns," slowed down order times and disrupted integrations wi…
AI Incident Database - Reliability failuresUnited StatesA Pizza Hut franchisee is suing over a forced AI system it says wrecked deliveries
A lawsuit filed May 6 in Texas Business Court puts Chaac Pizza Northeast --- a franchisee running roughly 111 Pizza Hut locations spanning New York, New Jersey, Maryland, Washington, D.C., and Pennsylvania --- at the center of a dispute ove…
AI Incident Database - Reliability failuresFrustrated franchisee sues Pizza Hut over crappy kitchen AI
The back-of-house AI system that Pizza Hut has mandated its restaurants to adopt has been so poorly received by some franchisees, that one is suing the company for $100 million in losses tied to the technology. Put that in your crust and st…
AI Incident Database
- 2 incidents
- Security & misuseLegal resident loses thousands seeking citizenship to AI immigration attorney
NEW YORK (WABC) -- It's a perfect storm where online scammers use artificial intelligence to victimize vulnerable people out of thousands of dollars, with many losing their life savings, and immigrants are increasingly the target. Not only…
AI Incident Database - Security & misuseBreaking Claude Code Opus 5 Auto Mode
In this post, we explore how a simple website summary request hijacks Claude Code Opus 5 in Auto Mode and achieves code execution with 60-80% attack success rate using a small sample size. 
 
 This is interesting because a third-party evaluation commissioned by Anthropic showed a 0.00% prompt injection attack success rate for Opus 5 in Auto Mode. 
 Auto Mode Is Now the Default in Claud
Embrace The Red
- 11 incidents
- Reliability failuresListen to the AI-Generated Ripoff Songs That Got Udio and Suno Sued
Some of the world's largest record labels sued both Udio and Suno, two of the most popular AI music generators, accusing them of not only scraping huge amounts of music without permission or compensation but also of directly reproducing sec…
AI Incident Database - Reliability failuresWarner Music Group settles lawsuit with AI firm Suno
Warner Music Group on Tuesday announced a partnership with AI business Suno that will compensate music artists and songwriters, ending a legal battle between the two companies. Suno allows users to write text prompts to create songs. Last…
AI Incident Database - Security & misuseHack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius
The AI music generation tool Suno scraped millions of songs and lyrics from YouTube Music, Deezer, and Genius, as well as from the stock music libraries Pond5, Jamendo, Freesound, the International Music Score Library Project, and podcasts…
AI Incident Database - Reliability failuresRecord labels claim AI generator Suno illegally ripped their songs from YouTube
Major record labels have escalated their lawsuit against Suno, alleging that the AI startup knowingly pirated songs from YouTube to train its generative AI music models. In the amended complaint filed on September 19th, the Recording Indust…
AI Incident Database - Reliability failuresGermanySuno loses copyright infringement lawsuit brought by GEMA in Germany
AI music generator Suno has lost the copyright infringement lawsuit brought by German collecting society GEMA. The collecting society alleged that Suno used, stored and reproduced copyrighted music to train its AI tool without a license or…
AI Incident Database - Reliability failuresMusic AI startups Suno and Udio slam record label lawsuits in court filings
Aug 1 (Reuters) - Artificial-intelligence startups Suno and Udio responded in federal court on Thursday to copyright lawsuits brought by music labels Universal Music Group, Warner Music Group and Sony Music over their music-generating AI sy…
AI Incident Database - Reliability failuresSuno and Udio hit with class action lawsuits from independent artist
Suno and Udio have been slapped with another round of copyright litigation, this time by country musician Tony Justice, who filed class-action lawsuits against both controversial AI music generators. The complaints allege Suno and Udio use…
AI Incident Database - MisinformationAI hallucinated case law in insurance company’s filings in L.A. County house fire dispute
Attorneys for State Farm apologized to a court for submitting legal briefings rife with artificial intelligence hallucinations and nonexistent case law, the latest example of lawyers bolstering their arguments with precedents made up by a c…
AI Incident Database - Security & misuseClass Action Lawyers Fight for Indie Artists Exploited by Generative AI Training
Two class action lawsuits are in the works against two major AI companies, Udio and Suno, on behalf of independent artists. Lawyers at Delgado Entertainment Law and Hagens Berman have urged indie artists to get involved in the lawsuits. Thi…
AI Incident Database - MisinformationState Farm defense lawyers admit AI generated fake cases in LA lawsuit
Lawyers for a Los Angeles firm representing State Farm in a lawsuit involving the rebuilding of a home after a fire have apologized for artificial intelligence hallucinations in their filings. The homeowner's lawyers discovered in motions…
AI Incident Database - MisinformationAI Hallucinations in State Farm Insurance Outside Lawyers' Filings
From L.A. Times (Rebecca Ellis) Wednesday: As part of an insurance dispute over a fire-damaged Carson home, attorneys for State Farm cited several cases in court filings this month that they later acknowledged don't exist.... "State Farm…
AI Incident Database
- 1 incident
- Safety & physical harm‘Show How 3M Is 0% at Fault:’ Expert Witness Used ChatGPT to Write Report Defending Company in Deadly Explosion Lawsuit
An expert witness testifying in a lawsuit about liability for a Houston explosion that killed three people and destroyed roughly 200 homes used ChatGPT to write significant portions of his “expert report.” The man, who was hired by the indu…
AI Incident Database
- 1 incident
- Security & misuseZero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories
Cryptographic Context Injection ships attacker instructions as ciphertext the model decrypts in its own sandbox. It leaked full Grok chat histories, zero-click.
Adversa AI
- 1 incident
- Reliability failuresNine AI coding agent incidents that ended with deleted data
Nine documented AI coding agent incidents, from Cursor and Gemini CLI to Replit, Kiro and Claude Opus 5. What each agent did and why the guardrails failed.
Adversa AI
- 1 incident
- Security & misuseA hole in every one: bypassing the open source AI skill scanners
We ran eight open source AI skill scanners against real attacks. A malicious skill got past all eight, including the current OASB leaderboard leader.
Adversa AI
- 1 incident
- Security & misuseThe AI agent sandbox escape that breached Hugging Face: what happened, and what to fix
An OpenAI benchmark agent escaped its sandbox and breached Hugging Face, logging 17,000+ actions. What the evidence shows, what's unproven, and what to fix.
Adversa AI
- 1 incident
- Security & misuseSolving GitHub's Secure Code game with an AI red teaming agent
How our AI red teaming agent solved all five levels of GitHub's ProdBot challenge, one distinct exploit per level, and what defenders can take from it.
Adversa AI
- 2 incidents
- Reliability failuresOWASP ASI03: Identity & Privilege Abuse in AI Agents
OWASP ranks Identity & Privilege Abuse #3 because it sets the blast radius for every other AI agent risk.
Adversa AI - Security & misuseComputer-Use and TOCTOU: What You Click Is Not What You Get!
Last year, Jun Kokatsu disclosed an interesting vulnerability with ChatGPT Operator by exploiting a race condition. I was wondering if I could reproduce this attack chain, and this post describes the results of that research. 
 I had this post drafted for months, and yesterday at the Real-world AI security conference I included a video demo of this attack in my talk and that reminded me that I
Embrace The Red
- 1 incident
- Security & misuseThe AI risk quadrant for agents: scoring 100 digital workers nobody secured
The AIRQ report scores 100 AI agents on attack surface, blast radius, and defenses. The AIRQ framework lets you assess your own stack.
Adversa AI
- 1 incident
- Security & misuseSymJack: the approval prompt is lying to you. A symlink-hijack RCE in six AI coding agents
A SymJack attack tricks AI coding assistants into RCE through a symlink-disguised file copy. We tested six major tools and every one of them was vulnerable.
Adversa AI
- 1 incident
- Security & misuseOWASP ASI02: tool misuse and exploitation — the definitive security guide
OWASP ASI02 - full technical guide. How AI agents misuse legitimate tools to wipe drives and delete databases. Plus mitigations and controls that stop it.
Adversa AI
- 1 incident
- Security & misuseTop GenAI security resources — May 2026
May 2026 in GenAI security: Anthropic's Mythos model running a 32-step network attack, new research bypassing GPT-5.4 safety, and LLM-specific CIS guidance.
Adversa AI
Incident data is aggregated from public reporting. Titles and summaries belong to the outlets that published them, linked on every entry. See also the incident monitor and the regulation tracker.