ClarityCheck AI-Powered Face Search Service Exposes 9 Million Biometric Images

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

ClarityCheck, a U.S.-based AI-powered reverse image search and people-search service, left an unsecured database containing over 9 million facial images publicly accessible. The exposure, caused by misconfigured cloud storage, poses significant privacy and identity theft risks, affecting adults and children. The database was later restricted after discovery.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (facial recognition and people-search tool) whose malfunction (misconfiguration and insecure storage) directly led to the exposure of sensitive biometric and personal data. This exposure constitutes a violation of privacy rights and poses harm to individuals, including children, through potential misuse. The AI system's role is pivotal as it processes and stores the data that was exposed. The harm is realized, not just potential, as the data was accessible for months. Therefore, this qualifies as an AI Incident under the framework.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Media, social platforms, and marketing

Affected stakeholders
General publicChildren

Harm types
Human or fundamental rightsEconomic/Property

Business function:
Other

AI system task:
Recognition/object detection


Articles about this incident or hazard