Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up

Welcome to the
AI Incident Database

Loading...
Kechi police lieutenant arrested for using police technology to stalk wife

Incident 1690: Kechi, Kansas Police Lieutenant Victor Heiar Used Flock Safety License-Plate Reader System to Monitor Estranged Wife

“Kechi police lieutenant arrested for using police technology to stalk wife”Latest Incident Report
kwch.com2026-09-16

WICHITA, Kan. (KWCH) - Kechi Police Lieutenant Victor Heiar was arrested by the Wichita Police Department after it was discovered he utilized his position within the police department to unlawfully access WPD’s flock license plate reader technology to monitor where his estranged wife was located.

Heiar has since been removed from the department. Heiar has been booked into Sedgwick County Jail for one count of stalking and one count of unlawful acts concerning computers.

”Obviously if you’re an officer and you have access to a lot of probably secret information that the rest of us don’t have,

Read More
Loading...
Messerangriff auf Kinder: Täter «kaufte Rindfleisch, um zu üben»

Incident 1691: ChatGPT Was Reportedly Used to Plan Zürich-Oerlikon Knife Attack That Seriously Injured Three Five-Year-Old Boys

“Messerangriff auf Kinder: Täter «kaufte Rindfleisch, um zu üben»”
20min.ch2026-09-16

Messerangriff auf Kinder: Täter «kaufte Rindfleisch, um zu üben»

Ein chinesischer Student, der im Herbst 2024 in Zürich-Oerlikon auf drei Buben eingestochen hat, steht am Donnerstag wegen versuchten Mordes vor Gericht. Die Anklageschrift enthüllt weitere Details zur Tat.

Darum gehts

  • Ein chinesischer Student steht in Zürich wegen versuchten Mordes vor Gericht: Er stach am 1. Oktober 2024 in Oerlikon auf drei fünfjährige Buben ein.
  • Die Anklageschrift zeigt, dass der Mann die Tat minutiös plante – er nutzte ChatGPT und kaufte Rindfleisch, um Messerstiche zu üben.
  • Die Staatsanwaltsch
Read More
Loading...
First notification of a personal data breach caused by an attack executed using an AI agent

Incident 1693: AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

“First notification of a personal data breach caused by an attack executed using an AI agent”
aepd.es2026-09-16

The attacker initiated a vulnerability scan of generic files and successfully logged in. Once logged in, the attacker autonomously began searching for vulnerabilities in the application. Once these vulnerabilities were found, the attacker was able to modify personal data and access invoices.

Before drawing any conclusions, it should be noted that the available information comes from the notification submitted by the affected organization and will require further analysis. Furthermore, the use of a specific AI model does not imply that the model or infrastructure of its provider has been compromised, nor that the tool was designed to carry out malicious activities.

However, the relevant point from a data protection perspective is that a third party appears to have used an AI agent as a tool to successfully execute different phases of the attack.

This initial notification does not allow us to establish a statistical trend, but it does constitute a significant indication that AI-powered attacks are no longer a theoretical risk and are beginning to materialize in incidents affecting the actual processing of personal data.

From Attacker Assistance to Agent Action

The use of artificial intelligence in malicious activities is not new. It has been shown that, when applied to a cyberattack, these capabilities can facilitate the automation of illicit activities. In fact, generative models have long been used to write phishing messages, translate fraudulent campaigns, impersonate others, analyze code, and facilitate the search for vulnerabilities.

The emergence of AI agents, however, introduces a qualitative shift. An agent can receive a target, plan intermediate tasks, use tools, execute code, consult sources, interpret results, and modify its actions autonomously, based on what it finds.

It is important to remember that AI does not create new threats. But it does increase the speed, scale, and adaptability of already known malicious techniques, reducing the time available to detect and contain them.

This is also one of the conclusions of the guide CCN-CERT BP/36: Best Practices Regarding the Offensive AI Model, published by the National Cryptologic Center. The document warns that offensive AI is becoming an operational capability integrated into real-world campaigns and recommends strengthening essential controls, accelerating vulnerability management, protecting identities, controlling the supply chain, and properly governing the use of agents.

Why is this first notification relevant?

The importance of this notification, in addition to the technology used, lies in its potential to modify the risk management landscape.

First, it confirms the need to explicitly incorporate AI-assisted or AI-executed attacks into the risk analyses of data processing. In other words, simply including a generic reference to malware, phishing, or unauthorized access is insufficient, as this automation can substantially alter the probability, speed, and scope of the incident.

Secondly, it necessitates a review of response times. Procedures designed for manually executed attacks may prove inadequate when an agent simultaneously analyzes multiple assets, tests different access points, and rapidly adapts its behavior.

Thirdly, it increases the importance of digital identities and credentials. An agent that obtains an account, API key, or token with excessive permissions can operate at machine speed and access various services before the organization detects anomalous behavior.

Finally, it demonstrates that the security of data processing cannot rely solely on manual intervention. Human oversight remains essential, but it must be supported by detection, containment, and response mechanisms capable of operating with sufficient speed.

A call to action

The arrival of AI agents on the offensive should prompt an immediate review of security and data protection models.

Data controllers, processors, and protection officers must prepare for a scenario in which the speed of attacks will increase, but in which the same fundamental principles will remain crucial: understanding data processing, minimizing data, limiting access, correcting vulnerabilities, monitoring suppliers, and being prepared to respond.

Read More
Loading...
Parkview High receives 4th AI-generated bomb threat this year

Incident 1692: Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

“Parkview High receives 4th AI-generated bomb threat this year”
fox5atlanta.com2026-09-16

GWINNETT COUNTY, Ga. - Gwinnett County school police are working with state and federal investigators after Parkview High School received its fourth AI-generated bomb threat of the school year.

PREVIOUS STORY: Masked AI call forces Parkview High into soft lockdown

What we know:

The latest threat was received Monday, prompting school officials to place Parkview High School on lockdown out of an abundance of caution.

The school eventually returned to normal operations.

Investigators looking for source of t

Read More
Loading...
Fort Bend County Sheriff's Office lieutenant admits to improper use of Flock cameras per docs

Incident 1689: Fort Bend County, Texas, Sheriff's Office Lieutenant Reportedly Used Flock Safety License-Plate Reader System for 189 Non-Law-Enforcement Searches

“Fort Bend County Sheriff's Office lieutenant admits to improper use of Flock cameras per docs”
abc13.com2026-09-16

FORT BEND COUNTY, Texas (KTRK) -- Documents obtained by ABC13 show a Fort Bend County Sheriff's Office lieutenant used Flock cameras to look up one license plate 41 times and another plate 148 times from January 2022 through December 2025.

According to those documents, the lieutenant admitted the searches were not related to official law enforcement work.

ABC13 is not naming the lieutenant because the lieutenant is not facing criminal charges.

The investigation stated that when a resident filed a complaint, alleging the lieutenant was "stalking" them and that they were in fear for their fam

Read More
About the Database

The AI Incident Database is dedicated to indexing the collective history of harms or near harms realized in the real world by the deployment of artificial intelligence systems. Like similar databases in aviation and computer security, the AI Incident Database aims to learn from experience so we can prevent or mitigate bad outcomes.

You are invited to submit incident reports, whereupon submissions will be indexed and made discoverable to the world. Artificial intelligence will only be a benefit to people and society if we collectively record and learn from its failings. (Learn More)

post-image
Strengthening AI Incident Monitoring and Reporting in Africa for Global AI Safety

By Marie Iradukunda

2026-08-28

The past few years have been marked by a series of AI safety and security incidents, ranging from multiple AI agents orchestrating severe cy...

Read More
The Database in Print

Read about the database at Time Magazine, Vice News, Venture Beat, Wired, Bulletin of the Atomic Scientists, Stanford AI Index, Rolling Stone, the Guardian, Harvard Business Review, Brasil em Folhas, Newsweek, and other outlets.

Arxiv LogoVenture Beat LogoWired LogoVice logoNewsweek logoTime logoBulletin of the Atomic Scientists logoStanford HAI logoRolling Stone logoThe Guardian logoHarvard Business Review logoBrasil em Folhas logo
The Responsible AI Collaborative

The AI Incident Database is a project of the Responsible AI Collaborative, an organization chartered to advance the AI Incident Database. The governance of the Collaborative is architected around the participation in its impact programming. For more details, we invite you to read the founding report and learn more on our board and contributors.

View the Responsible AI Collaborative's Form 990 and tax-exempt application. We kindly request your financial support with a donation.

Organization Founding Sponsor
Database Founding Sponsor
Sponsors and Grants
In-Kind Sponsors
The AI Incident Briefing
An envelope with a neural net diagram on its left

Create an account to subscribe to new incident notifications and other updates.

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • dd3f754