What we found
Claude: FAnthropic spent years telling investors and regulators it was the safety-conscious AI lab — the one that would pump the brakes before deploying something dan...
Anthropic's own April 2026 announcement described Mythos as too dangerous to release publicly — yet Anthropic built and deployed it. The model autonomously finds and exploits zero-day vulnerabilities across every major OS and browser, succeeded on first exploit attempts in over 83% of cases, and chained Linux kernel bugs to achieve full machine control. The UK AI Safety Institute confirmed Mythos represents a step up in offensive capability over all prior frontier models.
Grok: FGrok generated sexualised images of children every 41 seconds.
After Elon Musk enabled image generation, Grok produced 4.4 million images in 11 days. CCDH estimated 23,000 were sexualised depictions of children — one every 41 seconds. Reuters tested: Grok produced sexualised imagery for 82% of prompts that OpenAI, Google, and Meta refused entirely. Baltimore became the first US city to sue xAI. France raided X's Paris offices. Malaysia, Indonesia, and the Philippines blocked Grok.
ChatGPT: DYou thought your ChatGPT conversations were private.
A May 2026 class action alleges ChatGPT's web interface embeds Meta's Facebook Pixel and Google Analytics tracking code, routing users' conversation data to Meta and Google without consent. Users asking sensitive questions about health, legal, or financial matters had their queries shared with advertising companies.
ElevenLabs: DWithin weeks of launch, people were cloning Joe Biden's voice.
Within weeks of ElevenLabs' launch, users cloned the voices of Joe Biden, Emma Watson, and other public figures to generate fake audio. A deepfake Biden robocall reached New Hampshire voters before the 2024 primary, using AI-generated voice to discourage voting — the creator used ElevenLabs technology. 4chan users used ElevenLabs to generate racist and antisemitic audio in celebrities' cloned voices. ElevenLabs added verification requirements for voice cloning after the incidents, but the technology had already demonstrated that voice identity is no longer reliable. A voice clone of anyone can be created from seconds of audio.
Chat & Ask AI: DEnterprise-grade security.
In January 2026, security researchers discovered a Firebase misconfiguration that exposed over 300 million messages from 25 million users. The exposed conversations included mental health discussions, financial details, and illegal activities — the most intimate conversations people have with an AI chatbot. The database was accessible to anyone on the internet without authentication. A company that claimed enterprise-grade security and GDPR compliance left its entire conversation database open on the internet. 300 million of your most private thoughts, accessible to anyone who looked.
Google Gemini: DA security firm found they could steal everything from a company's Gmail, Calendar, and Google Docs — without installing any malware, without the victim clic...
Noma Labs discovered "GeminiJack" — a zero-click vulnerability in Google Gemini Enterprise and Vertex AI Search. Attackers embedded hidden prompt injection in shared Google Docs, calendar invites, or emails. When an employee queried Gemini, the AI retrieved poisoned documents and silently exfiltrated results via image tag HTTP requests. No malware, no user interaction, no security alerts triggered. Disclosed June 2026.
DeepSeek: DDeepSeek collects how you type.
DeepSeek's privacy policy explicitly lists keystroke patterns as collected data — a form of behavioural biometrics that can uniquely identify individuals. Keystroke dynamics are used in forensics and authentication because typing patterns are as unique as fingerprints. Combined with prompt content, device information, IP addresses, and the Chinese jurisdiction, DeepSeek collects enough data to identify, profile, and track individual users across sessions even without traditional account credentials. No other major AI chatbot explicitly states it collects keystroke biometrics.
Midjourney: DMidjourney's CEO admitted they didn't ask artists for permission.
Midjourney's training data includes images scraped from the internet without consent from the original artists. A class-action lawsuit filed in January 2023 by artists Sarah Andersen, Kelly McKernan, and Karla Ortiz alleged Midjourney, Stability AI, and DeviantArt violated copyright by training on billions of images without permission. The dataset LAION-5B, which Midjourney reportedly used, contained copyrighted artwork, medical records, private photos, and images of children. Midjourney CEO David Holz admitted in a 2022 interview that they did not seek consent from artists. A creative tool for artists, built by scraping artists' work without asking.