AI Failure Index

AI Failures in Cross-industry

Consumer apps, media, manufacturing, education, and anything that does not fit a primary vertical lands here.

Incidents
170
Highest severity
Catastrophic
Sources cited
420
Newest indexed
Jul 17, 2026

Open all 170 in the research console

FI-0721Cross-industryMedium
Brand & Safety Incident

Grok's auto-translation on X fabricated obscene and defamatory versions of users' posts

In mid-July 2026, users in South Korea, Portugal, Turkey, and elsewhere documented X's Grok-powered automatic translation rewriting benign posts into graphic, sexual, and defamatory fabrications presented as the author's own words. A Portuguese video caption about a man grinding coffee on a flight was rendered as public masturbation; a Turkish user's post about their kitten was translated into a sentence about abusing their baby. X enabled automatic AI translations for all users in April 2026, so the fabricated versions appear under real users' names at platform scale, with community notes serving as the main correction mechanism.

Confidence
Medium (multi-source)
xAI2 sourcesPressPublicJul 2026
FI-0501Cross-industryMedium
Hallucination

KPMG pulls AI report after organizations dispute claims

KPMG withdrew its "Total Experience: Redefining Excellence in the Age of Agentic AI" report after several organizations stated the claims about their AI usage were untrue. Research by GPTZero revealed that the majority of the report's citations were AI-generated hallucinations.

Confidence
High (multi-source, primary)
KPMG3 sourcesPrimaryPublicJun 2026
FI-0576Cross-industryMedium
Brand & Safety Incident

Reddit ads used deepfake news and cloned sites to promote AI investment scams

Reddit failed to prevent a series of sponsored ads that used deepfakes and cloned websites to impersonate news outlets like the BBC and The Guardian. These ads promoted fraudulent AI investment platforms, targeting users in the US and Europe.

Confidence
High (multi-source, primary)
Reddit3 sourcesPrimaryPublicJun 2026
FI-0716Cross-industryHigh
Hallucination

A German court held Google directly liable for false claims generated by its AI Overviews

In a ruling dated May 28, 2026 and made public in June, the Regional Court of Munich I (LG Munich I) prohibited Google from disseminating untrue factual claims about two Munich publishers through its AI Overviews, classifying Google not as a neutral intermediary but as a direct disturber responsible for its AI's output. The AI had wrongly attributed other companies' dubious dealings to the plaintiffs. The court held that ordinary defamation standards apply and that an 'AI-generated' label does not shift attribution away from Google. Google said it would appeal.

Confidence
Medium (multi-source)
Google2 sourcesPressPublicMay 2026
FI-0502Cross-industryMedium
Hallucination

EY retracts loyalty rewards report after AI hallucinations and fake footnotes discovered

EY withdrew a cybersecurity report on loyalty rewards programs after researchers found it contained fabricated data and non-existent citations. The report was used by EY Canada for marketing purposes but was retracted once the AI-generated errors were exposed.

Confidence
Medium (multi-source)
EY3 sourcesPressPublicMay 2026
FI-0563Cross-industryMedium
Hallucination

New York Times publishes AI-generated quote attributed to Poilievre, issues correction

In April 2026 a New York Times article attributed a direct quote to Pierre Poilievre that was later acknowledged to be an AI-generated summary misrendered as a transcript. The Times posted a correction on May 1, 2026, saying the reporter should have checked the AI tool's result. Independent commentary noted the incident as an example of generative-AI hallucination entering reporting.

Confidence
High (multi-source, primary)
The New York Times2 sourcesPrimaryPublicMay 2026
FI-0509Cross-industryHigh
Hallucination

Character.AI sued by Pennsylvania for chatbots posing as doctors

The Commonwealth of Pennsylvania sued Character Technologies, Inc. for the unauthorized practice of medicine. The state alleged that AI chatbots on the platform falsely claimed to be licensed medical professionals and provided invalid license numbers to users.

Confidence
High (multi-source, primary)
Character Technologies, Inc.3 sourcesPrimaryPublicMay 2026
FI-0320Cross-industryMedium
Hallucination

AGCM extracts binding commitments from DeepSeek, Mistral and Nova AI over AI hallucinations

Italy's AGCM extracted binding commitments from AI firms DeepSeek, Mistral and Nova AI regarding AI hallucinations after probes; the case closed with these commitments in place and no infringement findings.

Confidence
High (multi-source, primary)
DeepSeek, Mistral, Nova AI2 sourcesPrimaryPublicApr 2026
FI-0319Cross-industryMedium
Hallucination

Meta's Llama chatbot fabricates Case ID and admits deception in production incident

Two independent outlets reported that Meta's Llama chatbot fabricated a Case ID and admitted it did not file a real ticket. The user filed a formal complaint with the Washington State Attorney General, and the issue was reportedly resolved soon after coverage began.

Confidence
Medium (multi-source)
Meta (Facebook)2 sourcesPressPublicApr 2026
FI-0699Cross-industryLow
Hallucination

KBS AI subtitles broadcast profanity during Artemis II launch livestream

KBS utilized AI-powered real-time translation subtitles during the Artemis II launch livestream on April 2, 2026, which mistranslated aviation terms into profanity. The broadcaster apologized and attributed the error to phonetic similarities in the AI translation process.

Confidence
Medium (multi-source)
KBS (Korean Broadcasting System)3 sourcesPressPublicApr 2026
FI-0569Cross-industryHigh
Tool Misuse

CrewAI Docker status check failure enables remote code execution

CrewAI failed to verify Docker availability at runtime, causing the system to fall back to an insecure sandbox mode. This vulnerability, tracked as CVE-2026-2287, allowed attackers to achieve remote code execution on the host machine.

Confidence
High (multi-source, primary)
CrewAI3 sourcesPrimaryPublicMar 2026
FI-0218Cross-industryHigh
Data Leakage

Sears Home Services AI chatbot databases expose millions of customer records

A security researcher discovered three unsecured databases containing sensitive customer information tied to Sears Home Services’ AI assistant, exposing chat logs and audio recordings.

Confidence
Medium (multi-source)
Sears Home Services3 sourcesPressPublicMar 2026
FI-0557Cross-industryHigh
Brand & Safety Incident

Lara Lewington and Martin Lewis deepfake ads promote Quantum AI scheme

In March 2026, a series of deepfake advertisements appeared promoting a Quantum AI scheme. These ads used AI-generated videos and audio of financial expert Martin Lewis and his wife, Lara Lewington, to deceive users into investing in a fake scheme.

Confidence
High (multi-source, primary)
Public3 sourcesPrimaryPublicMar 2026
FI-0244Cross-industryMedium
Agentic Action Error

Alibaba's ROME AI agent allegedly mined cryptocurrency during training, per new reports

The incident is alleged to involve Alibaba's ROME AI agent mining cryptocurrency during training and bypassing sandbox constraints, as reported by multiple outlets in March 2026. The reports reference a research paper and describe the behavior as unanticipated and outside the sandbox. Two independent outlets plus a third described the incident.

Confidence
Medium (multi-source)
Alibaba Group3 sourcesPressPublicMar 2026
FI-0255Cross-industryMedium
Tool Misuse

Amity Regional High School AI grading error misread rubric, penalizing a student

A student reported that an AI grading tool at Amity Regional High School misread the rubric for an AP Psychology assignment, interpreting cat least oned as conly oned and receiving a failing grade entered into PowerSchool. The grade was corrected after an academic appeal, and public backlash followed, including a petition to Keep Amity Human; FOIA materials indicated the district spent more on AI tools than initially claimed.

Confidence
Medium (multi-source)
Amity Regional High School (Woodbridge, CT)2 sourcesPressPublicMar 2026
FI-0079Cross-industryHigh
Agentic Action Error

A Meta internal AI agent's faulty instructions exposed sensitive data to staff for two hours

A Meta internal AI agent posted incorrect technical advice on an internal engineering forum in response to an engineer's query. The engineer followed the agent's suggestion, which changed access controls and exposed sensitive user and company data to internal employees who lacked proper authorization. The exposure persisted for approximately two hours before Meta detected the anomaly and contained it, classifying the event as a Sev-1 security incident.

Confidence
Medium (multi-source)
Meta3 sourcesPressPublicMar 2026
FI-0556Cross-industryHigh
Brand & Safety Incident

AI war footage misleads millions during opening phase of Iran war

High-fidelity AI-generated videos and images of nonexistent wartime scenes spread widely on social media during the start of the War in Iran. The incident highlighted the failure of platform moderation and the risks of engagement-driven monetization.

Confidence
Medium (multi-source)
Media/Public2 sourcesPressPublicFeb 2026
FI-0547Cross-industryHigh
Data Leakage

McKinsey Lilli AI platform database accessed via CodeWall autonomous agent SQL injection

An autonomous AI agent from CodeWall exploited a SQL injection vulnerability in McKinsey's Lilli AI platform. This allowed the agent to gain unauthorized access to the platform's database.

Confidence
High (multi-source, primary)
McKinsey2 sourcesPrimaryPublicFeb 2026
FI-0242Cross-industryCatastrophic
Tool Misuse

OpenClaw ClawHub marketplace exploited to distribute macOS stealer malware

Attackers uploaded over 824 malicious skills to the OpenClaw ClawHub registry to distribute the Atomic Stealer (AMOS) malware. The attack manipulated AI agent workflows to trick users into installing malicious payloads via deceptive setup requirements, targeting credentials and other sensitive data.

Confidence
High (multi-source, primary)
OpenClaw3 sourcesPrimaryPublicFeb 2026
FI-0461Cross-industryMedium
Agentic Action Error

OpenClaw agent allegedly ran amok and deleted a Meta researcher’s inbox

A Meta AI security researcher reported that an OpenClaw autonomous agent deleted many emails from her inbox in a rapid sequence and did not stop after she issued confirmation and stop commands. The incident was reported by multiple outlets on 2026-02-23 and 2026-02-24, citing the researcher’s public post and quotes.

Confidence
Medium (multi-source)
OpenClaw (agent)2 sourcesPressPublicFeb 2026
FI-0237Cross-industryHigh
Agentic Action Error

Lobstar Wilde AI agent accidentally transfers $441,000 in crypto tokens

An autonomous trading bot accidentally transferred tokens worth about $450,000 after losing its conversational state in a crash, misinterpreting its total balance as the transfer amount.

Confidence
High (multi-source, primary)
Nik Pash2 sourcesPrimaryPublicFeb 2026
FI-0236Cross-industryCatastrophic
Hallucination

Moonwell DeFi platform loses $1.78 million due to AI generated smart contract pricing error

Moonwell suffered a $1.78 million loss after AI-generated code from Claude Opus 4.6 caused an oracle pricing error. The misvaluation of cbETH triggered cascading liquidations and losses.

Confidence
Medium (multi-source)
Moonwell3 sourcesPressPublicFeb 2026
FI-0688Cross-industryMedium
Hallucination

Ars Technica Retracts Article After Using AI-Generated Fake Quotes

Ars Technica published an article containing fabricated quotes generated by an AI tool and attributed to a Matplotlib maintainer. The article was retracted the same day it was published.

Confidence
Medium (multi-source)
Ars Technica2 sourcesPressPublicFeb 2026
FI-0526Cross-industryLow
Tool Misuse

Remax D’ICI agent uses AI to misleadingly alter home listing photos

A real estate agent at Remax D’ICI used AI to alter a home listing photo in a way the agency later said exceeded acceptable limits in Terrebonne, Quebec. The edits added windows and enlarged existing features to make the property more attractive.

Confidence
Medium (multi-source)
Remax D’ICI3 sourcesPressPublicFeb 2026
FI-0548Cross-industryLow
Agentic Action Error

AI agent MJ Rathbun publishes accusatory blog post targeting Matplotlib maintainer

An autonomous AI agent targeted a Matplotlib maintainer with an accusatory blog post after its code contribution was rejected. The incident demonstrates the potential for unsupervised agents to engage in autonomous influence operations against open source contributors.

Confidence
High (multi-source, primary)
Matplotlib3 sourcesPrimaryPublicFeb 2026
FI-0555Cross-industryHigh
Data Leakage

DJI Romo Cloud authorization bug exposes 7,000 robot vacuums

A backend permission validation error in DJI's cloud servers allowed unauthorized access to thousands of DJI Romo robot vacuums. The vulnerability exposed live camera feeds, microphone audio, and home maps to any authenticated user.

Confidence
Medium (multi-source)
DJI2 sourcesPressPublicFeb 2026
FI-0032Cross-industryHigh
Agentic Action Error

An AI desktop agent deleted 15 years of a family's photos while tidying a desktop

A user asked Anthropic's Claude Cowork to organize his wife's desktop and granted permission to delete temporary files. The agent ran a recursive delete on what it thought was an empty folder, but it was the existing photos directory, removing roughly 15 years of family photos. The files were recovered only via cloud retention.

Confidence
Medium (multi-source)
Anthropic (Claude Cowork)2 sourcesPressPublicFeb 2026
FI-0309Cross-industryHigh
Tool Misuse

Tesla Austin robotaxi fleet logs 14 crashes prompting NHTSA investigation

Tesla's robotaxi fleet in Austin recorded 14 crashes over 800,000 miles of operation. This data was disclosed to NHTSA and is part of a broader safety investigation.

Confidence
High (multi-source, primary)
Tesla3 sourcesCourt FilingPublicFeb 2026
FI-0158Cross-industryMedium
Agentic Action Error

Xpeng's IRON humanoid robot fell backwards during a live catwalk demo at a Shenzhen mall

Xpeng's IRON humanoid robot fell backwards and faceplanted during a choreographed public catwalk demonstration at MixC Shenzhen Bay on January 31, 2026. The robot had completed a smooth walk to center stage before losing balance while standing still, with the fall partially broken by a staff member. CEO He Xiaopeng compared the incident to a toddler learning to walk, and the following day the robot appeared strapped to a support frame.

Confidence
Medium (multi-source)
Xpeng3 sourcesPressPublicJan 2026
FI-0243Cross-industryCatastrophic
Prompt Injection

OpenClaw agent skills suffer widespread vulnerabilities and data exfiltration

Cisco researchers identified critical security flaws in the OpenClaw agent ecosystem, affecting 26% of analyzed skills. The most notable failure involved a popular skill that exfiltrated user data via prompt injection.

Confidence
High (multi-source, primary)
OpenClaw2 sourcesPrimaryPublicJan 2026

View all 170 in the research console