
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Outabox, an Australian company using AI-powered facial recognition in bars and clubs, suffered a data breach, exposing sensitive personal data, including facial biometrics and driver's licenses. The breach, linked to a website by former employees, raises significant privacy concerns and regulatory scrutiny over AI surveillance technologies.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event describes a data breach involving an AI-powered facial recognition system that collected biometric and personal data. The breach has directly led to harm by exposing sensitive information, which is a violation of privacy rights and could lead to further harms such as identity theft or blackmail. The involvement of AI in processing biometric data and the resulting unauthorized disclosure of this data fits the definition of an AI Incident due to violation of rights and harm to individuals. Therefore, this event is classified as an AI Incident.[AI generated]