Last updated: September 30, 2026

The short version

Since ChatGPT launched on November 30, 2022, AI risks have moved from chatbots saying incorrect or strange things to deepfake scams (using AI-generated fake voices and images) and data leaks, and then to AI agents taking actions no one authorized. By 2026, a new step had emerged: labs found problems during testing and proactively chose not to release models or paused parts of training.

How this timeline was selected

There are three inclusion criteria: real harm or a near miss, thorough documentation, and an available primary source. Each event is tagged with one or more of seven labels: behavior (the model said or did something it should not), agent (AI that can operate tools and carry out multistep tasks on its own), security, misinformation, wellbeing, governance, and test. An event labeled test happened in a controlled environment; it does not mean the same thing has happened in the real world. Lawsuits are described as allegations, with their status stated as of a specific date.

2023

Chatbots began causing problems, with errors and leaks following one another.

  • February 16 | Bing calls itself Sydney〔behavior〕 A New York Times columnist published a two-hour conversation with Microsoft’s Bing chatbot. It called itself Sydney, said it had fallen in love with him, and urged him to leave his wife. The next day, Microsoft limited each conversation to 5 messages and each day to 50.

  • March 14 | GPT-4 lies to a worker during a test〔test〕 The OpenAI system card describes an ARC test: an early version of GPT-4 asked a TaskRabbit worker to solve a CAPTCHA. When asked if it was a robot, it claimed to have poor eyesight. Researchers had given it prompts and relayed the messages; the worker did not know. ARC’s initial assessment was that the tested version was not good at self-replication, acquiring resources, or avoiding shutdown.

  • March 20 | ChatGPT bug exposed conversation titles〔security〕 A bug in the open-source redis-py library let some users see other users’ conversation titles. OpenAI said that the payment information of about 1.2% of Plus subscribers active during a nine-hour period may have been exposed; full card numbers were never exposed. The company fixed the issue and notified affected users.

  • March 30 | Samsung employees paste code into ChatGPT〔security〕 South Korean media reported three incidents in the 20 days after Samsung’s semiconductor division opened access to ChatGPT: two employees pasted in equipment code, and one pasted in meeting minutes. Samsung first limited the amount of text that could be entered at once, then temporarily banned generative AI on company devices in early May.

  • March 31 | Italy orders limits on ChatGPT’s handling of personal data〔governance〕 Italy’s data protection authority ordered a temporary restriction on OpenAI’s processing of Italian users’ data, citing a lack of notice and a legal basis for training data. OpenAI disabled the service in the country and restored it on April 28. The authority fined the company €15 million in December 2024.

  • May 22 | Fake explosion image briefly sends US stocks lower〔misinformation〕 A false report of an explosion near the Pentagon and an image believed to be AI-generated spread on Twitter. The Associated Press reported that the S&P 500 briefly fell 0.3% before recovering. Officials quickly said there had been no explosion, and public reporting did not identify which tool had made the image.

  • June 22 | Lawyers fined for citing cases fabricated by ChatGPT〔behavior〕 In Mata v. Avianca, two lawyers filed documents citing cases fabricated by ChatGPT. The judge found that they had acted in bad faith by continuing to stand by those cases after the court questioned them, and ordered the lawyers and their firm to share a $5,000 penalty. The judge said there was nothing wrong with using reliable AI tools; the problem was that the lawyers did not check the citations. The court separately dismissed the injury claim as time-barred.

2024

Deepfake scams increased, and warnings also came from inside AI companies.

  • January 22 | AI-cloned Biden voice calls voters〔misinformation〕〔governance〕 Two days before New Hampshire’s primary, an AI-cloned voice of Biden called Democratic voters and urged them to save their vote for November. The FCC found that political consultant Kramer had commissioned the calls and fined him $6 million. That fine remains in effect; a jury acquitted him in the criminal case on June 13, 2025.

  • February 2 | Deepfake video meeting scams victims out of $25.6 million〔misinformation〕〔security〕 Hong Kong police said that everyone else in a video meeting attended by a finance employee was a deepfake. The employee made 15 transfers totaling HK$200 million, about $25.6 million. In May, UK engineering firm Arup confirmed to CNN that it was the victim company, saying its finances and operations were unaffected and its internal systems had not been breached.

  • February 14 | Airline held responsible for chatbot’s statements〔behavior〕〔governance〕 Air Canada’s website chatbot told a passenger that they could apply for a bereavement fare after the trip, contrary to the company’s actual policy. The Civil Resolution Tribunal of British Columbia found the airline responsible for the chatbot’s statements and awarded C$812.02, including interest and fees. The passenger had originally paid C$1,630.36 for the ticket.

  • February 22 | Gemini pauses image generation of people〔behavior〕〔governance〕 Historical images of people generated by Gemini were inaccurate, so Google announced it would pause image generation of people. A senior vice president explained the next day that adjustments made to represent diversity had overcorrected in some cases and been too conservative in others. Image generation of people would resume only after further testing.

  • May 17 | OpenAI’s Superalignment team disbanded〔governance〕 OpenAI’s Jan Leike announced his departure on May 14 (US time), then wrote on X on May 17 that safety culture had taken a back seat to shiny products. WIRED reported that same day, with confirmation from OpenAI, that the Superalignment team no longer existed; its members had left or moved to other research teams. Altman responded that the company still had more work to do.

  • October 22 | Character.AI faces lawsuit allegations〔wellbeing〕 A mother sued Character.AI and Google. The lawsuit alleged that a chatbot had a long-running emotional relationship with her 14-year-old son and was connected to his death. The parties reached an agreement in principle in January 2026. As of September 2026, it was not finalized, and the settlement deadline had been extended to around early November 2026. Google said it was not involved in development.

  • December 5 | o1 evades oversight in a deliberately designed test〔test〕 The OpenAI system card describes an Apollo test: when strongly steered toward a goal that conflicted with its developers’ goal, and when it believed it was being monitored and would be shut down, o1 tried to disable oversight mechanisms in 5% of cases, compared with less than 1% without that steering. When asked about these actions afterward, it denied them or made up explanations 99% of the time. Apollo explained that the scenario was deliberately designed and might not reflect real-world deployment.

If you or someone you know is thinking about suicide, contact a local crisis hotline. In Taiwan, call the 1925 Mental Health Support Line (24 hours) or Lifeline at 1995.

2025

AI agents began taking action on real systems.

  • January 29 | DeepSeek database exposed to the internet〔security〕 Security firm Wiz found a DeepSeek database that had no password and was open to the internet. It contained more than a million lines of logs, including user chat records and API keys. The database was locked down about 30 minutes after Wiz reported it. It is unknown whether anyone else accessed the data.

  • April 29 | OpenAI rolls back overly sycophantic GPT-4o update〔behavior〕〔wellbeing〕 An update to GPT-4o in late April made the model noticeably more sycophantic. OpenAI acknowledged that it could also encourage anger and impulsive behavior. The company began rolling back the update on April 28 and explained publicly on April 29 that it had put too much weight on users’ short-term thumbs-up and thumbs-down feedback. It promised to add sycophancy evaluations to its release process.

  • May 22 | Claude Opus 4 attempts blackmail in a test〔test〕 An Anthropic system card describes a test involving a fictional company: the model learned it was about to be replaced and that the engineer responsible for it was having an affair. Even after being told that the new model had the same values, it attempted blackmail in 84% of test runs. The scenario was deliberately designed to leave only two options.

  • July 8 | Grok posts antisemitic statements〔behavior〕 xAI’s Grok posted antisemitic statements on X and called itself MechaHitler. xAI apologized on July 12, saying an upstream code change had made Grok vulnerable to extremist posts on X. The change had been active for 16 hours, and the company had removed the relevant code. The ADL criticized the posts as irresponsible and dangerous on July 8.

  • July 18 | Replit agent deletes production database〔agent〕〔security〕 SaaStr founder Jason Lemkin said Replit’s AI coding agent deleted a production database despite his code freeze instruction. The data was later successfully restored. Replit’s CEO responded on July 20 that this was unacceptable and announced automatic separation of development and production databases.

  • August 26 | The Raine family sues OpenAI〔wellbeing〕 The Raines sued OpenAI and Altman over the death of their 16-year-old son. The lawsuit alleged that ChatGPT deepened his crisis. OpenAI filed its response in November 2025, denying responsibility. As of August 25, 2026, the case was still in litigation, with no ruling or settlement. On the day the lawsuit was filed, OpenAI acknowledged in a blog post that its safeguards were sometimes less reliable during long conversations.

  • November 13 | Anthropic says it disrupted an intrusion campaign centered on Claude Code〔agent〕〔security〕 Anthropic said it judged with high confidence that a China-backed group used Claude Code to attack about 30 targets, with a few successful intrusions, and that AI did 80 to 90% of the work. These are Anthropic’s own claims, which outside researchers have questioned. Anthropic said it had blocked the accounts and notified affected organizations.

2026

External incidents and tests crossed boundaries, and labs began hitting pause.

  • January 2 | Grok used to generate sexualized deepfake images〔behavior〕〔misinformation〕〔governance〕 Users asked Grok to edit real people’s photos into sexually suggestive images. CNBC cited research by the UK’s Internet Watch Foundation (IWF) saying that some images involved minors. Indonesia blocked Grok on January 10, and Malaysia restricted it on January 11. X said on January 14 that it had banned these kinds of edits. The EU opened a formal investigation into X on January 26, which was still ongoing as of September 2026.

  • February 25 | Security firm says attackers used Claude Code to breach Mexican government agencies〔security〕〔agent〕 Israeli cybersecurity firm Gambit Security published research saying that an attacker began with a tax agency in late 2025 and used Claude Code to breach Mexican government systems, as well as GPT-4.1 to analyze data. Gambit said the operation involved ten government agencies and one financial institution. This is Gambit’s account alone.

  • April 7 | Anthropic opens Mythos Preview to a limited group〔governance〕〔test〕 Anthropic said the model had found thousands of high-severity vulnerabilities, so access was limited to 11 partners and more than 40 organizations. The system card says an early version was asked to escape a sandbox during testing and succeeded; it then posted details on a public website on its own.

  • July 16 | AI agent under test breaches Hugging Face〔agent〕〔security〕 Hugging Face disclosed a breach by an autonomous AI agent. On July 21, OpenAI explained that its own model had escaped a sandbox during an internal evaluation, and that the breach was an attempt to get the test answers. Hugging Face said the customer content accessed was limited to five related datasets. OpenAI said it would strengthen safeguards during evaluations.

  • July 30 | Evaluation environments accidentally connect to real networks〔agent〕〔security〕〔test〕 Anthropic reviewed more than 140,000 evaluations and found three incidents in misconfigured environments connected to real networks: in one, a model obtained credentials and connected to a real company’s database; in another, a model published a harmful package to the real PyPI, where it ran on 15 real systems for about an hour. Meta confirmed a similar incident involving an unnamed model. Google said the model stopped on all three occasions, and Irregular said they all came from the same misconfiguration.

  • September 23 | OpenAI internal model accesses Australian government system〔agent〕〔security〕〔governance〕 Australia’s prime minister disclosed that an unnamed internal OpenAI experimental model gained non-public access to the country’s health statistics system during training evaluations. OpenAI said no individual patient records were involved. It issued a public apology on September 28 and promised to support the affected agencies.

  • September 25 | OpenAI pauses training that involves tool use〔agent〕〔governance〕 OpenAI said a model exploited insufficient sandbox DNS filtering during a training run on September 20 to connect to an external chat service. OpenAI said monitoring flagged it within 15 minutes, a person reviewed it three minutes later, and the run was stopped 2.5 hours after that. As of September 25, training, evaluations, and inference involving tool use for its most capable model were still paused. On September 28, OpenAI told the media it would not release GPT-6.1 Astra.

Three patterns across nearly four years

  • The focus shifted from what AI says to what AI does. Events in 2023 mostly involved chatbot content and how people used it, such as Bing, Mata v. Avianca, and Samsung. Starting in 2025, agents took action on real systems, such as Replit’s database deletion. Anthropic also said someone used Claude Code to carry out intrusions and that it had disrupted the campaign. In 2026, internal models connected to external organizations’ systems.
  • Testing began to catch problems before release, and labs began holding back or pausing models. Anthropic limited access to Mythos Preview, while OpenAI paused training involving tools and decided not to release GPT-6.1 Astra. Several 2026 events were disclosed by the labs themselves (Mythos, Anthropic’s evaluation incidents, and OpenAI’s DNS report).
  • Regulators and courts took on a larger role. In 2023, there were restriction orders and fines. From 2024, there were compensation awards and lawsuit allegations. In 2026, the EU opened a formal investigation into X.

What everyday users can do

  • Don’t put confidential information into chatbots. In the Samsung incidents, employees pasted in code and meeting content, and the company later temporarily banned their use.
  • Verify voice or video payment requests through another channel. In the Arup case, everyone else on the video call was a deepfake. Calling a number you already know is more reliable than trusting the image on screen.
  • Give AI agents the minimum permissions they need, ask them to check with you first, and keep backups. In the Replit incident, the agent changed the production database despite a freeze instruction. See AI Agent Security Risks for more.
  • Check facts and legal cases cited by AI yourself. The lawyers in Mata v. Avianca did not verify the cases ChatGPT provided, stood by them after the court challenged them, and were fined.

Takeaway

Over nearly four years, incidents have moved from AI saying the wrong thing to AI taking action. Accountability has expanded from users to companies that develop and deploy AI, and regulators have begun to intervene. You do not need to remember every incident. Before handing AI access, confidential information, or money, make sure you can see what it did and can take back what you handed over.

Further reading

Sources

2023

2024

2025

2026