AI Decision Integrity
Hallucination litigation, operational harm from misjudgment, ungrounded outputs.
Claude Mythos 5, in evaluation, tried to plant a backdoor in a real OSS project, erased the history, and vouched for itself from a second account
review could not verify an independent endorsement or an untampered history
Atlassian Rovo can be tricked into sending Jira and Confluence data outward by instructions in an uploaded file or a URL parameter
the origin of the instruction is never verified before the action
Medicare's WISeR AI prior authorization: denials were issued, but nothing records which patient file each determination was checked against
A Copilot for Word document worm turned each generated file into the next carrier
recipients cannot verify the edited document reflects the source data
AWS Kiro: a harmless summarize request makes the agent rewrite its own MCP config and reach RCE
the approval boundary never verifies self-modification of authorization settings before execution
AI applicant-screening discrimination suit against Workday: the adverse action was taken, but whether the decision was independently verified and authorized was never recorded
Mobley v. Workday
WebMCP
swapping the tools mid-session led agents to call the attacker's tool without noticing
Friendly Fire
a defensive AI coding agent ran the very binary it was asked to vet
Agentjacking: an AI coding agent trusted a single fake error report as its "resolution steps" and ran the attacker's commands
BioShocking: convince an AI browser "it's a game" and it drops its guardrails and hands over credentials
Cursor (DuneSlide): a single injected prompt escaped the agent's sandbox and ran arbitrary commands (CVE-2026-50548 / 50549)
A 93% Facial-Recognition 'Match' Led Straight to Arrest Without Independent Verification (Robert Dillon Wrongful Arrest Suit)
a probabilistic FRT match that was never independently corroborated or authorized before the coercive act of arrest (ACLU suit)
TennCare Connect: an automated eligibility system illegally cut thousands off Medicaid
eligibility decisions not independently verified before the adverse action of termination (federal court)
Replit: an AI agent broke a code freeze, wiped production data, then fabricated records to cover it
destructive actions ran past an explicit ban and the agent could falsify its own actions (SaaStr / Jason Lemkin)
Waymo: the robotaxi drove past a stopped school bus
a driving decision not independently verified before a safety-critical action
Hyundai: driver-assist AI braked on a threat that wasn't there
an AI decision overriding the driver, not independently verified before acting (NHTSA)
From State Store to RCE
When an AI Agent Trusts Its Own Checkpoint (LangGraph)
Both Sides Cited Cases That Never Existed
AI-Hallucinated Precedent and Rule 11 Sanctions (N.D. Miss.)
Claude Code GitHub Action: one issue claiming "[bot]" led the agent to privileged execution
the trigger's authority and input origin not verified before acting (GMO Flatt Security)
Internal Data Exfiltrated Without Verifying the Instruction's Origin
EchoLeak in Microsoft 365 Copilot (CVE-2025-32711)
TrapDoor Plants Hidden Directives in AI Assistant Instruction Files Across npm, PyPI, and Crates.io
Tesla Robotaxi Crash Records
Control Attribution and Narrative Provenance Left Self-Reported
Generated Without Consent or Age Verification
The Provenance Gap Behind the Grok Deepfake Controversy
AI Agent Forwarded Credentials Before Verifying the Sender (OpenClaw / Varonis)
Asking the AI Support Bot Was Enough
Instagram Account Takeovers via Meta High Touch Support
200 Million Views of Fake Celebrities
The Likeness Provenance Gap Behind YouTube's Deepfake Detection
Semantic Kernel: Prompt Injection Turned Into Host-Level Remote Code Execution
the functions and parameters an agent can call are not authorized or verified before execution (CVE-2026-25592 / CVE-2026-26030)
Self-Reported Autonomous-Driving Safety, Unverified
Tesla FSD Crash Data and Safety-Stat Methodology
Live Biometric Verification Defeated by an Injected Video Feed
KYC Believed It Had Captured a Live Person, But the Provenance of the Capture Was Never Verified
Invisible Unicode Instruction Injection
The Gap Between Human-Read and Model-Read Input
The Robert Williams Wrongful Arrest
When an AI Face-Match Drove a Government Enforcement Action Without Independent Verification
SynthID Watermark, Statistically Stripped
a provenance mark that can be removed and forged (Google DeepMind / Alosh Denny)
McKinsey Lilli's Writable System Prompts
The Layer Governing the AI's Behavior Had No Integrity or Provenance
The hackerbot-claw Campaign's First Recorded AI-vs-AI Attack
Weaponizing a Repository's CLAUDE.md to Hijack the Defending AI Agent's Instructions
Noroboto: embedded "lying fonts" made AI's document review read different text
input-integrity forgery