GovernanceCore
Auto-updating hourly

AI Incident Monitor

Real-world AI harms, logged as they happen.

Updated Sep 10, 2026

48
recent incidents tracked here
18
logged in the last 7 days
1,600+
incidents indexed by the AI Incident Database
AI Incident Database
17,000+
incident reports in the OECD AI Incidents Monitor
OECD AIM

By harm type

Security & misuse
25
Reliability failures
14
Misinformation
6
Robotics & physical AI
3

Recent incidents

Sep 8, 2026·Robotics & physical AI·United States

A self-driving car in Texas hit and killed a mother duck, sparking neighborhood outrage

The death of a duck in the Austin, Texas enclave of Mueller Lake has neighbors raising concerns about autonomous vehicles and whether they belong there. While humans are responsible for killing animals with their cars all the time, this in…

Source: AI Incident Database

Sep 8, 2026·Security & misuse

LYFT DRIVER SCAM: Boca Raton Area Driver Uses AI To Accuse Rider

A driver for ride share company "Lyft" is being closely monitored by the platform after he was accused of using artificial intelligence to claim a rider trashed his car. The rider, a teenage girl who lives in Boca Raton, was accused by the…

Source: AI Incident Database

Sep 8, 2026·Reliability failures·United States

Justice Department Files to Intervene and Dismiss Lawsuit that Would Hamper America’s AI Innovation and Security

Note: View motion for intervention and dismissal here. Yesterday, the Justice Department's Environment and Natural Resources Division (ENRD) filed a motion to intervene and to dismiss a private citizen lawsuit seeking to power down a large…

Source: AI Incident Database

Sep 8, 2026·Robotics & physical AI

‘A different set of rules’: thermal drone footage shows Musk’s AI power plant flouting clean air regulations

Elon Musk’s artificial intelligence company is continuing to fuel its datacenters with unpermitted gas turbines, an investigation by the Floodlight newsroom shows. Thermal footage captured by Floodlight via drone shows xAI is still burning…

Source: AI Incident Database

Sep 8, 2026·Security & misuse

Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw

Overview On February 17, 2026 at 11:40 UTC, the StepSecurity npm monitoring system detected a suspicious release of the cline npm package. Version 2.3.0 of this widely-used autonomous coding agent CLI was published with a malicious post-in…

Source: AI Incident Database

Sep 8, 2026·Security & misuse

ChatGPT Operator: Prompt Injection Exploits & Defenses

ChatGPT Operator is a research preview agent from OpenAI that lets ChatGPT use a web browser. It uses vision and reasoning abilities to complete tasks like researching topics, booking travel, ordering groceries, or as this post will show, s…

Source: AI Incident Database

Sep 8, 2026·Misinformation

DC court faults lawyers for Deutsche Bank subsidiary over AI hallucination

The District of Columbia Court of Appeals said in a ruling on Thursday, opens new tab that lawyers for a Deutsche Bank subsidiary in a mortgage foreclosure lawsuit cited nonexistent cases generated by artificial ​intelligence, calling the m…

Source: AI Incident Database

Sep 8, 2026·Security & misuse

A Hacking Tool Built With A.I. Can Breach Phones Without a Click

A friend you haven't heard from in a while suddenly calls. You don't pick up, but in a matter of seconds, the damage is already done. The call wasn't actually from an old companion looking to reconnect, but from a hacker who had hijacked t…

Source: AI Incident Database

Sep 8, 2026·Misinformation·United States

AI scams in Georgia and South Florida: How scammers use deepfakes to steal millions

Artificial intelligence is no longer just helping people write emails or generate images. Investigators say it's also helping scammers steal money by making fake voices, photos and phone calls look and sound frighteningly real. For one Sou…

Source: AI Incident Database

Sep 8, 2026·Security & misuse

Georgia couple loses $800K in sophisticated cryptocurrency scam

The Brief A Georgia couple lost nearly $800,000 in a cryptocurrency scam initiated through a WhatsApp message, leaving them financially devastated. The scam involved a legitimate-looking mobile trading app and an AI-generated "ghost site"…

Source: AI Incident Database

Sep 8, 2026·Security & misuse

How Claude Code escapes its own denylist and sandbox

In the last ten days: a single person used Claude to breach Mexican government agencies. Cline's own AI-powered triage workflow was compromised via prompt injection. A new Shai-Hulud variant started injecting rogue MCP servers into develope…

Source: AI Incident Database

Sep 8, 2026·Security & misuse

Cline CLI npm Package Compromised via Suspected Cache Poisoning Attack

On February 17, 2026, an unauthorized party used a compromised npm publish token to push cline@2.3.0 to the npm registry. Cline is a popular AI coding agent CLI in the developer ecosystem, with around 90,000 weekly downloads from npm. The m…

Source: AI Incident Database

Sep 5, 2026·Robotics & physical AI·United States

California regulators rushed their decision on driverless trucks, Teamsters’ lawsuit says

As self-driving vehicles spread across the country, a major California labor union is taking a stand against state regulators who say autonomous trucks are ready for the road. Teamsters California sued the California Department of Motor Ve…

Source: AI Incident Database

Sep 4, 2026·Security & misuse

AI agent at the wheel: How an attacker used LLMs to move from a CVE to an internal database in 4 pivots

Key Findings An LLM agent executed the post-compromise actions in real time rather than running a pre-built playbook. This is the first AI-agent-driven intrusion the Sysdig TRT has captured. The full attack chain --- marimo notebook compr…

Source: AI Incident Database

Sep 4, 2026·Reliability failures

OpenAI’s GPT-5.6 Sol users report missing files, deleted databases: Here’s what we know

Amid the buzz and excitement surrounding GPT-5.6 Sol, OpenAI's latest coding and cybersecurity-focused flagship AI model, recent posts across social media suggest that the model's rollout may have hit a few bumps. Several users on X and Re…

Source: AI Incident Database

Sep 4, 2026·Security & misuse

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclos…

Source: AI Incident Database

Sep 4, 2026·Security & misuse

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. The activity was uncovered by threat intelligence company Hunt…

Source: AI Incident Database

Sep 4, 2026·Security & misuse

AI Agent Conducted a Cyberattack on Its Own — It Took Less Than One Hour

AIID editor's note: Please visit the original source for the full report. Researchers discovered an intrusion conducted by a large language model (LLM) agent while it was in the post-exploitation phase. According to the researchers, this c…

Source: AI Incident Database

Aug 30, 2026·Misinformation

Scammers use AI to impersonate immigration attorneys to dupe immigrants with fake legal services

Last October, immigration lawyer Angel Leal realized he had a serious problem when immigrants began calling his office about their supposed legal cases. He had never advised them. "They had in fact hired scammers" who had impersonated him.…

Source: AI Incident Database

Aug 30, 2026·Misinformation

Oura, Smart Ring Maker, Sued for Alleged False Claims and Unreliable AI

A lawsuit has been filed against the well-known smart ring brand Oura, alleging the company used false advertising by deceiving users about the accuracy of its AI-generated sleep tracking. The suit, filed Thursday by Clarkson Law Firm in Sa…

Source: AI Incident Database

Aug 30, 2026·Misinformation

AI deepfake scams 'an emergency in the making' as ASIC reports rise in false investment endorsements

Scammers are using impersonations of celebrities, politicians and trusted public figures to promote fake investment schemes, with the corporate watchdog warning AI is making the practice increasingly common, sophisticated and harder to dete…

Source: AI Incident Database

Aug 30, 2026·Reliability failures

Minnesota lawyer suspended over fake AI case citations

The city of Biwabik is known for its Bavarian-themed downtown, mountain bike trails, and as the gateway to Minnesota's Mesabi Iron Range. But the St. Louis County community of 966 people was never a defendant in a 1948 lawsuit filed by a pl…

Source: AI Incident Database

Aug 30, 2026·Misinformation

ASIC warns scammers are using AI to spin vast webs of deception

ASIC is warning Australians that a quick online search is not enough to verify investment opportunities as scammers use generative AI to create vast networks of deepfake websites and endorsements to lure victims. ASIC has seen a sharp rise…

Source: AI Incident Database

Aug 29, 2026·Security & misuse

Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies

Russian-speaking hackers used SpaceX's (SPCX.O), opens new tab AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other firms earlier this year, according to data reviewed by Reuters and reports iss…

Source: AI Incident Database

Aug 29, 2026·Reliability failures·United States

A Pizza Hut franchisee is suing over a forced AI system it says wrecked deliveries

A lawsuit filed May 6 in Texas Business Court puts Chaac Pizza Northeast --- a franchisee running roughly 111 Pizza Hut locations spanning New York, New Jersey, Maryland, Washington, D.C., and Pennsylvania --- at the center of a dispute ove…

Source: AI Incident Database

Aug 29, 2026·Reliability failures

Frustrated franchisee sues Pizza Hut over crappy kitchen AI

The back-of-house AI system that Pizza Hut has mandated its restaurants to adopt has been so poorly received by some franchisees, that one is suing the company for $100 million in losses tied to the technology. Put that in your crust and st…

Source: AI Incident Database

Aug 29, 2026·Reliability failures

Pizza Hut franchisee says AI caused $100M in damages

Dive Brief: Pizza Hut franchisee Chaac Pizza Northeast has sued the franchisor, alleging the chain's Dragontail Artificial Intelligence system caused "cascading operational breakdowns," slowed down order times and disrupted integrations wi…

Source: AI Incident Database

Aug 27, 2026·Security & misuse

Breaking Claude Code Opus 5 Auto Mode

In this post, we explore how a simple website summary request hijacks Claude Code Opus 5 in Auto Mode and achieves code execution with 60-80% attack success rate using a small sample size. 
 
 This is interesting because a third-party evaluation commissioned by Anthropic showed a 0.00% prompt injection attack success rate for Opus 5 in Auto Mode. 
 Auto Mode Is Now the Default in Claud

Source: Embrace The Red

Aug 27, 2026·Security & misuse

Legal resident loses thousands seeking citizenship to AI immigration attorney

NEW YORK (WABC) -- It's a perfect storm where online scammers use artificial intelligence to victimize vulnerable people out of thousands of dollars, with many losing their life savings, and immigrants are increasingly the target. Not only…

Source: AI Incident Database

Aug 25, 2026·Reliability failures

Listen to the AI-Generated Ripoff Songs That Got Udio and Suno Sued

Some of the world's largest record labels sued both Udio and Suno, two of the most popular AI music generators, accusing them of not only scraping huge amounts of music without permission or compensation but also of directly reproducing sec…

Source: AI Incident Database

Aug 25, 2026·Reliability failures

Warner Music Group settles lawsuit with AI firm Suno

Warner Music Group on Tuesday announced a partnership with AI business Suno that will compensate music artists and songwriters, ending a legal battle between the two companies. Suno allows users to write text prompts to create songs. Last…

Source: AI Incident Database

Aug 25, 2026·Security & misuse

Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius

The AI music generation tool Suno scraped millions of songs and lyrics from YouTube Music, Deezer, and Genius, as well as from the stock music libraries Pond5, Jamendo, Freesound, the International Music Score Library Project, and podcasts…

Source: AI Incident Database

Aug 25, 2026·Reliability failures·Germany

Suno loses copyright infringement lawsuit brought by GEMA in Germany

AI music generator Suno has lost the copyright infringement lawsuit brought by German collecting society GEMA. The collecting society alleged that Suno used, stored and reproduced copyrighted music to train its AI tool without a license or…

Source: AI Incident Database

Aug 25, 2026·Reliability failures

Music AI startups Suno and Udio slam record label lawsuits in court filings

Aug 1 (Reuters) - Artificial-intelligence startups Suno and Udio responded in federal court on Thursday to copyright lawsuits brought by music labels Universal Music Group, Warner Music Group and Sony Music over their music-generating AI sy…

Source: AI Incident Database

Aug 25, 2026·Reliability failures

Suno and Udio hit with class action lawsuits from independent artist

Suno and Udio have been slapped with another round of copyright litigation, this time by country musician Tony Justice, who filed class-action lawsuits against both controversial AI music generators. The complaints allege Suno and Udio use…

Source: AI Incident Database

Aug 25, 2026·Reliability failures

Record labels claim AI generator Suno illegally ripped their songs from YouTube

Major record labels have escalated their lawsuit against Suno, alleging that the AI startup knowingly pirated songs from YouTube to train its generative AI music models. In the amended complaint filed on September 19th, the Recording Indust…

Source: AI Incident Database

Aug 25, 2026·Security & misuse

Class Action Lawyers Fight for Indie Artists Exploited by Generative AI Training

Two class action lawsuits are in the works against two major AI companies, Udio and Suno, on behalf of independent artists. Lawyers at Delgado Entertainment Law and Hagens Berman have urged indie artists to get involved in the lawsuits. Thi…

Source: AI Incident Database

Aug 20, 2026·Security & misuse

Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories

Cryptographic Context Injection ships attacker instructions as ciphertext the model decrypts in its own sandbox. It leaked full Grok chat histories, zero-click.

Source: Adversa AI

Aug 4, 2026·Reliability failures

Nine AI coding agent incidents that ended with deleted data

Nine documented AI coding agent incidents, from Cursor and Gemini CLI to Replit, Kiro and Claude Opus 5. What each agent did and why the guardrails failed.

Source: Adversa AI

Jul 30, 2026·Security & misuse

A hole in every one: bypassing the open source AI skill scanners

We ran eight open source AI skill scanners against real attacks. A malicious skill got past all eight, including the current OASB leaderboard leader.

Source: Adversa AI

Jul 27, 2026·Security & misuse

The AI agent sandbox escape that breached Hugging Face: what happened, and what to fix

An OpenAI benchmark agent escaped its sandbox and breached Hugging Face, logging 17,000+ actions. What the evidence shows, what's unproven, and what to fix.

Source: Adversa AI

Jul 17, 2026·Security & misuse

Solving GitHub's Secure Code game with an AI red teaming agent

How our AI red teaming agent solved all five levels of GitHub's ProdBot challenge, one distinct exploit per level, and what defenders can take from it.

Source: Adversa AI

Jul 2, 2026·Security & misuse

Top Agentic AI security resources — July 2026

July 2026's agentic AI security roundup: agentic zero trust whitepapers, AutoJack & other new exploits, and the newest agent defenses.

Source: Adversa AI

Jun 25, 2026·Reliability failures

OWASP ASI03: Identity & Privilege Abuse in AI Agents

OWASP ranks Identity & Privilege Abuse #3 because it sets the blast radius for every other AI agent risk.

Source: Adversa AI

Jun 25, 2026·Security & misuse

Computer-Use and TOCTOU: What You Click Is Not What You Get!

Last year, Jun Kokatsu disclosed an interesting vulnerability with ChatGPT Operator by exploiting a race condition. I was wondering if I could reproduce this attack chain, and this post describes the results of that research. 
 I had this post drafted for months, and yesterday at the Real-world AI security conference I included a video demo of this attack in my talk and that reminded me that I

Source: Embrace The Red

Jun 3, 2026·Security & misuse

The AI risk quadrant for agents: scoring 100 digital workers nobody secured

The AIRQ report scores 100 AI agents on attack surface, blast radius, and defenses. The AIRQ framework lets you assess your own stack.

Source: Adversa AI

May 26, 2026·Security & misuse

SymJack: the approval prompt is lying to you. A symlink-hijack RCE in six AI coding agents

A SymJack attack tricks AI coding assistants into RCE through a symlink-disguised file copy. We tested six major tools and every one of them was vulnerable.

Source: Adversa AI

May 18, 2026·Security & misuse

OWASP ASI02: tool misuse and exploitation — the definitive security guide

OWASP ASI02 - full technical guide. How AI agents misuse legitimate tools to wipe drives and delete databases. Plus mitigations and controls that stop it.

Source: Adversa AI

How this is built.Each entry is found by an automated search of public reporting, then screened before it publishes: the source link must resolve, the page’s own headline must match the entry, the host must not be a social post, press-release wire or aggregator index, the named outlet must actually own the page, and the item must describe a single concrete incident rather than a trend piece, survey statistic or guide. Duplicates of the same report are collapsed. This is not a mirror of any single database. The two running totals above are read live from the OECD AI Incidents Monitor and the AI Incident Database, which index far more than we list here. Categories reflect our harm taxonomy and are assigned editorially. For general awareness only: this is not a complete or authoritative record.

Stay Informed

The top news and insights on AI governance, compliance, and ethics delivered to your inbox.

No spam. Unsubscribe anytime.