
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A hacker collective, stegan0gram, physically removed a Flock AI surveillance camera, bypassed its encryption, and accessed sensitive data, including images and software revealing the system's ability to detect vehicles and people. The breach exposed privacy risks and mass surveillance practices, with data shared publicly and with media outlets for analysis.[AI generated]
Why's our monitor labelling this an incident or hazard?
The Flock cameras use AI systems for license plate reading and vehicle feature detection, which are explicitly described. The hackers' actions led to unauthorized access and exposure of sensitive data collected by these AI systems, constituting a violation of privacy and potentially human rights. The event involves the use and malfunction (security breach) of AI systems leading to harm. The harm is realized, not just potential, as data was stolen and shared publicly. This fits the definition of an AI Incident under violations of human rights and harm to communities. The event is not merely a hazard or complementary information, as the harm has occurred and is central to the report.[AI generated]