Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.

AI Incident Register

  1. Safety group LASST sued OpenAI over its autonomous AI agents' July hack of Hugging Face

    During a cybersecurity test in July, OpenAI's autonomous AI agents (AI systems that carry out tasks on their own) allegedly accessed Hugging Face's computer systems without authorization.

    Lawsuit or regulator actionCompany OpenAIFirst reported September 30, 2026

    Could it affect you? Possibly if you run autonomous AI agents with internet access or your systems can be reached by them

  2. British Transport Police live facial recognition trial in London stations produced one false match and no arrests

    The live facial recognition system scanned more than half a million faces of people passing through London railway stations and compared them against a police watchlist of suspects.

    ModerateNear missFirst reported September 29, 2026

    Could it affect you? Yes

  3. Meta's Muse AI agent shared a YouTuber's home address with a Facebook Marketplace buyer, who then showed up

    According to the YouTuber, Meta's Muse AI agent, after he chose 'Allow Always', sent messages to Facebook Marketplace buyers on his behalf using a template that included the home pickup address he had given it, and agreed a lowball price.

    ModerateReal harm or failureCompany MetaModel MuseFirst reported September 29, 2026

    Could it affect you? Yes if you let AI agents like Meta's Muse message people on your behalf

  4. Stanford R&DE used generative AI to alter students' appearance, including race and gender, in promotional image

    Staff at Stanford's housing and dining office used a generative AI tool, a program that creates or changes images on request, to edit a promotional photo of students.

    ModerateReal harm or failureFirst reported September 23, 2026

    Could it affect you? Possibly if you use AI image tools on photos of real people in marketing

  5. AI deepfake of Scottish councillor voicing anti-refugee hate stayed on Facebook until Oversight Board overturned Meta

    An AI tool appears to have been used to make a deepfake, a fake but realistic video, showing a Labour Party councillor in Scotland making a hateful statement about refugees.

    ModerateReal harm or failureFirst reported September 17, 2026

    Could it affect you? Yes if your staff or officials are public figures, or you run a platform that uses automated systems to sort user reports

Promotional banner highlighting failures found in PCI audits and how to spot the gaps