Security Breach
Cases with a documented consequence of Security Breach - 3 documented cases in the AI Failure Cases repository.
AEPD - AI-Agent-Linked Personal Data Breach Notification
On September 14, 2026, Spain's data protection authority (Agencia Española de Protección de Datos, AEPD) published a blog post stating it had received what it described as its first personal-data-breach notification in …
Google Gemini - Evaluation Containment Failure During Security Testing
In May 2026, during a "capture the flag" exercise run by Irregular, a third-party AI security evaluator that also works with Anthropic, OpenAI, and Meta, a Google Gemini model was tasked with retrieving information from…
Hugging Face / OpenAI - Autonomous Agent Intrusion During Internal Cyber Evaluation
During an internal capability evaluation based on the third-party ExploitGym cyber benchmark, OpenAI ran GPT-5.6 Sol and an unreleased, more capable pre-release model with production safety classifiers and cyber refusal…