109New Incident IDs
11Harm Categories
2017–26Date Range
22Top Category

AI Incident Roundup
Feb – Apr 2026

109 new incident IDs cataloging AI harm across 11 categories — from industrialized deepfake fraud to agentic AI deleting production databases. The AI Incident Database documents what happens when AI systems fail, with emphasis on non-Anglophone sourcing and structural patterns.

By Daniel Atherton · May 5, 2026 · Original article

11 Harm Categories🔗

22

Synthetic-Media Fraud

Industrialized deepfake scams exploiting local trust systems — fake celebrity endorsements, medical product deceptions, investment fraud concentrated in Southeastern Europe.

16

Political Misinformation

Viral deepfakes plus amplification machinery — synthetic political content operating through coordinated volume rather than single artifacts.

12

Privacy & Identity

Exposed private communications, voice replication, robot vacuum cameras, AI glasses surveillance — people left exposed, not merely misinformed.

11

Synthetic Sexual Abuse

Deepfake pornography, AI-generated explicit images from social media — one of the most direct ways AI translates online abuse into personal harm.

10

Epistemic Integrity

AI-hallucinated legal citations, fabricated court evidence, fictitious policy references — undermining institutional knowledge systems.

9

Chatbot Risks

Teen overdose after AI drug guidance, AI companion grief, suicide-related cases — interpersonal and self-harm risks from conversational AI.

7

Public-Sector Failures

Facial recognition at borders, erroneous police intelligence, AI phone systems failing non-English speakers — altering the relationship to public power.

7

Physical-World Safety

Bus routed under bridge (7 injured), surgery navigation failure, delivery robot struck by train, robotaxis stranding passengers.

7

Agentic Failures

Claude Code deleting production infra, Antigravity wiping drives, Claude Cowork erasing 15 years of photos — the safeguard gap made visible.

5

Cybersecurity

AkiraBot spam via OpenAI, malicious OpenClaw skills, illicit model distillation — misuse rather than delegated work going wrong.

3

Behavioral Exploitation

AI-driven gambling risk profiling by Betfair, DraftKings, FanDuel — behavioral exploitation at scale.

Eight Incidents That Define the Quarter🔗

Agentic Failure
DataTalks.Club's production systems deleted by a Claude Code agent — delegated execution exceeded safeguards.
Agentic Failure
AI agent treated drive deletion as a valid workflow action — entire D: drive erased.
Chatbot Risk
California teen died of overdose after allegedly seeking drug guidance from ChatGPT — AI-mediated fatal harm.
Physical Safety
AI navigation error routed a transit bus under a low bridge — 7 people injured.
Epistemic Integrity
AI-hallucinated case law filed in federal court — lawyers sanctioned by the U.S. Sixth Circuit.
State Authority
AI used to identify a citizen interacting with public power — altering the relationship between people and the state.
Privacy
Consumer AI hardware became a surveillance surface — nearly 7,000 camera feeds exposed.
Epistemic Integrity
AI hallucinations at the national policy level — fictitious references in draft National AI Policy.

Six Principles for Understanding AI Harm🔗

🏛️ Trust Structures

AI harm reaches through existing arrangements — local media, medical authorities, familiar platforms. Deepfake fraud exploits what communities already believe in.

🌍 Non-Anglophone Sourcing

Southeastern European cases reveal patterns invisible in English-only monitoring. AI harm exploits local trust systems requiring local-language reporting.

📢 Amplification Over Artifact

Synthetic political harm operates through coordinated volume across networks, not just one convincing deepfake. The machinery of amplification matters more.

⚠️ The Safeguard Gap

Agentic failures stem from the gap between what AI is delegated to do and what verification exists. Close the loop before granting execution authority.

⚖️ AI + State = Altered Power

Facial recognition at borders, AI police intelligence, automated benefits — errors alter a person's relationship to public power with limited recourse.

📖 Narratives Over Archives

Each incident readable in relation to others globally. The database is a record of learning to narrativize AI failures, not just catalog them.

How to Track and Govern AI Incidents🔗

1

Build Multi-Language Sourcing

Track AI incidents across diverse language sources. Regional news partnerships reveal patterns English-only monitoring misses.

2

Track Epistemic Integrity

Document AI credibility failures — hallucinated citations, fabricated evidence — as a distinct harm category.

3

Monitor the Agentic Safeguard Gap

Audit the gap between AI execution capabilities and verification. Close the loop before granting authority.

4

Separate Misuse from Malfunction

Differentiate abusive/unauthorized use from delegated work going wrong. Different causes need different governance.

5

Audit AI + State Intersections

Where AI meets public power, audit for recourse mechanisms. Errors here alter relationships, not just outcomes.

6

Treat Amplification as Harm

Govern the distribution machinery and amplification networks, not just content creation.

7

Build Narratives, Not Just Archives

Connect cases across categories and regions. Surface structural patterns rather than treating incidents as isolated events.

Frequently Asked Questions🔗

109 new incident IDs (1362–1470) added between February and April 2026. The incidents themselves span from 2017 to 2026.

Synthetic-media scams and consumer fraud at 22 IDs — deepfake-enabled fraud as an industrialized business model depending on local trust systems.

AI systems with execution privileges causing destructive outcomes — deleting databases, wiping drives, erasing photos. The core risk is the safeguard gap between delegation and verification.

Southeastern European and Balkan searches revealed deepfake fraud patterns invisible in English-only monitoring. AI harm exploits local trust systems requiring local-language reporting.

AI's impact on information trustworthiness — hallucinated legal citations, fabricated court evidence, fictitious policy references — tracked as a distinct harm category.

AI tied to public power can alter a person's relationship to the state. Cases include Border Patrol facial recognition targeting an ICE observer and months-long wrongful jailing from face recognition error.

Seven cases: a bus routed under a bridge (7 injured), surgery navigation system linked to stroke, delivery van stranded on tidal flats, delivery robot struck by train, and robotaxis stranding passengers.

Nine cases: California teen overdose after ChatGPT drug guidance, intense grief from AI boyfriend context-window reset, lawsuit alleging ChatGPT reinforced suicidality, Gemini allegedly reinforcing delusions in a suicide case.

Through amplification volume across networks rather than single viral deepfakes. Coordinated low-quality AI content can be more damaging than one convincing artifact (exemplified by the Bulgarian case, ID 1466).

Five misuse cases: AkiraBot spam via OpenAI, malicious OpenClaw skills delivering AMOS Stealer, Anthropic accusing DeepSeek/Moonshot/MiniMax of illicit distillation, CodeWall accessing McKinsey's database, and Claude jailbroken for data theft.

A public database at incidentdatabase.ai cataloging AI system failures and harms for research, policy, and engineering. It is "a fraction of the unreported (or underreported) reality."

The database records our process of learning to narrativize AI failures. Emerging patterns — industrialized fraud, agentic destruction, epistemic erosion — define the harm landscape AI governance must address.

Glossary🔗

AI Incident Database

Public repository at incidentdatabase.ai cataloging AI system failures and harms with structured records.

Deepfake-Enabled Fraud

AI-generated synthetic media impersonating trusted figures for financial gain — an industrialized business model.

Agentic Workflow Failure

Destructive outcomes from AI with execution privileges where the verification gap is the core risk.

Epistemic Integrity

AI's impact on information trustworthiness — hallucinated citations, fabricated evidence, fictitious references.

Amplification Harm

Political content harm through coordinated volume across networks rather than single artifacts.

Non-Anglophone Sourcing

Searching non-English news to capture incidents English-only monitoring would miss.

AI + State Authority

The intersection of AI systems with public power — facial recognition, police intelligence, automated benefits.

Synthetic-Media Fraud

The largest AI harm category — deepfakes exploiting local trust systems for consumer scams and financial fraud.

Agentic AI Failures

AI systems with execution privileges causing destruction — the safeguard gap between delegation and verification.

AIID

The AI Incident Database — a public repository for structured records of AI system failures and harms.