The pattern in every case below is the same: a system collected more about people than they realized, and then either leaked it or was used against them. What you type into a chatbot is data sitting on somebody's server.
300 million private chatbot messages left open to anyone
An independent researcher found that Chat & Ask AI — a wrapper app with more than 50 million downloads — had left its Firebase backend configured as public. Around 300 million messages belonging to more than 25 million users were reachable without a password, including full conversation histories with timestamps. Reported examples included people asking about suicide.
Source Hackread — 18 February 2026
Read it carefully: The scale comes from the researcher's own sampling, not from the company. It was not a sophisticated attack — it was a setting left on the wrong value. Assume anything you type into a chatbot could be read by a stranger one day.
A university AI assistant breached, chats included
ChatMinerva, the AI assistant built by Sapienza University of Rome, told subscribers that an unidentified outsider reached its user databases with administrator privileges. The data involved names, email addresses, hashed passwords and users' conversations with the model.
Source Report based on CyberSecurity Italia's reporting — 21 September 2026
Read it carefully: Second-hand: this write-up summarizes CyberSecurity Italia's reporting of a notice sent to subscribers, not a document I can read myself. Treat the outline as reliable and the details as provisional.
Scraping faces off the internet: Clearview AI fined
The UK Information Commissioner's Office fined Clearview AI £7.5m and ordered it to delete UK residents' data, for building a searchable database of more than 20 billion facial images scraped from the web and social media without telling anyone.
Source UK Information Commissioner's Office — 23 May 2022
Read it carefully: Fines are not the same as deletion. Clearview contested the UK regulator's jurisdiction, and similar orders in several countries have been slow to produce visible change in the product.
A wrongful arrest from a face match
Robert Williams, a Black man in Michigan, was arrested at his home in front of his wife and children in 2020 after Detroit police matched his driver's license photo to security footage of a shoplifting. He had nothing to do with it. In June 2024 the city agreed to pay $300,000 and to adopt what the ACLU called the strongest US police rules on facial recognition: no arrest on a face match alone, no lineup built from a match without independent evidence.
Source American Civil Liberties Union — 28 June 2024
Read it carefully: Announced by the organization that brought the case, so read the framing as advocacy — but the settlement terms and the $300,000 are a matter of public record. All three known wrongful arrests from facial recognition in Detroit involved Black people.
A retailer banned from using facial recognition for five years
The US Federal Trade Commission found Rite Aid had deployed facial recognition in hundreds of stores without reasonable safeguards, generating thousands of false matches that led staff to follow, search and publicly accuse innocent shoppers — disproportionately women and people of color. The order barred the company from using the technology for five years.
Source US Federal Trade Commission — 19 December 2023
Read it carefully: A regulator's complaint and a settled order — Rite Aid did not admit the allegations. It is still the clearest documented case of ordinary shoppers being harmed by a match nobody checked.
In the glossaryHuman in the Loop (HITL)
A chatbot fined over children and unclear data use
Italy's data protection authority fined Character Technologies, maker of Character.AI, €158,000 and ordered corrective measures. Its findings included an age gate that was a simple self-declaration — a tester declaring an age of fifteen registered and used the service — and a privacy notice available only in English that was unclear on retention and legal basis.
Source Summary of Garante decision n. 487, AI Agent Incident Register — 27 July 2026
Read it carefully: This is a compliance analyst's summary of the regulator's decision, not the decision itself. The fine is small; the finding that matters is that the protection for minors was a checkbox.
A people-search broker lost its own website over removal requests
Atlas Data Privacy Corp sued the consumer data broker Radaris in February 2024 under New Jersey's Daniel's Law, which lets police officers, judges, government staff and their families demand removal from commercial people-search sites and sets fines of $1,000 per violation. After what Krebs on Security describes as repeated stonewalling by Radaris's attorneys, the judge ordered radaris.com and more than a dozen other data broker domains transferred to the plaintiffs.
Source Krebs on Security — 16 September 2026
Read it carefully: I picked this out of the live headline strip below and then read it against the reporting before writing it up. Two honest limits: no AI model is involved — this is the personal-data supply that feeds profiling and training, which is why it sits here — and the outcome came from the company's conduct in the case, not from a ruling that its business is unlawful. Krebs reported on the owners and was threatened with a defamation suit, so he is a participant in this story as well as its reporter.