
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
ClarityCheck, a U.S.-based AI-powered reverse image search and people-search service, left an unsecured database containing over 9 million facial images publicly accessible. The exposure, caused by misconfigured cloud storage, poses significant privacy and identity theft risks, affecting adults and children. The database was later restricted after discovery.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (facial recognition and people-search tool) whose malfunction (misconfiguration and insecure storage) directly led to the exposure of sensitive biometric and personal data. This exposure constitutes a violation of privacy rights and poses harm to individuals, including children, through potential misuse. The AI system's role is pivotal as it processes and stores the data that was exposed. The harm is realized, not just potential, as the data was accessible for months. Therefore, this qualifies as an AI Incident under the framework.[AI generated]