HomeSolutionsServicesResearchAccountabilityResourcesBookCompanyCommunityTEI
TERA Incident Learning

AI Incident Observatory

Curated, source-linked analysis of publicly reported AI and automated-system incidents. The observatory separates reported facts from TeraSystemsAI analysis so institutions can learn without overstating causation, fault, or preventability.

Reported evidence → failure classification → TERA control consideration
Selected public cases

What was reported, and what it suggests evaluating.

Each entry distinguishes the public record from TeraSystemsAI's analytical classification. Control considerations are not claims that a specific control would have prevented the historical event.

Rite Aid Facial Recognition

Primary regulatory source

Reported: The FTC alleged that Rite Aid's facial recognition program generated thousands of false-positive matches and that the company failed to adequately assess risks to consumers. The matter resulted in a five-year ban on Rite Aid's use of facial recognition under the settlement.

Failure classificationFalse-positive identification · risk assessment
TERA dimensionsTrustworthiness · Reliability · Accountability
Control consideration: Pre-deployment error analysis, subgroup evaluation, operator escalation, and outcome logging are relevant controls for similar biometric systems.
View FTC source →

iTutorGroup Automated Hiring

Primary regulatory source

Reported: The EEOC stated that iTutorGroup programmed application software to automatically reject female applicants age 55 or older and male applicants age 60 or older. The case was resolved through a 2023 settlement.

Failure classificationDiscriminatory automated screening
TERA dimensionsTrustworthiness · Accountability
Control consideration: Protected-attribute testing, rule audits, documented exception handling, and human review are relevant controls for automated screening.
View EEOC source →

Cruise Automated Driving Incident

Primary safety source

Reported: NHTSA stated that Cruise submitted incomplete crash reports concerning an October 2023 incident in which a driverless vehicle dragged a pedestrian after the initial collision. A 2024 consent order addressed the reporting failures and increased oversight requirements.

Failure classificationPost-event system behavior · incident reporting
TERA dimensionsReliability · Accountability
Control consideration: Post-event recovery logic, complete incident reporting, independent review, and traceable safety records are relevant controls for automated systems.
View NHTSA source →

DoNotPay AI Capability Claims

Primary regulatory source

Reported: In 2025, the FTC finalized an order requiring DoNotPay to stop making deceptive claims about the capabilities of its AI chatbot, including claims associated with an "AI lawyer" service.

Failure classificationCapability representation · validation claims
TERA dimensionsTrustworthiness · Accountability
Control consideration: Capability claims should be tied to defined evaluations, known limitations, reviewable evidence, and disciplined customer-facing representations.
View FTC source →
TERA incident framework

One incident can reveal several kinds of failure.

The observatory does not force every case into a single category. TERA provides four analytical questions that can be applied across domains and failure mechanisms.

T

Trustworthiness

Examine evidence quality, uncertainty, validity, unsupported outputs, and misleading capability claims.

Question: What justified belief in the output or action?
E

Efficiency

Examine whether the level of automation, model complexity, and operational dependence were proportionate to the task.

Question: Was this the simplest sufficient system?
R

Reliability

Examine edge cases, drift, monitoring, recovery behavior, fallback paths, and performance under changed conditions.

Question: What happened when the system failed?
A

Accountability

Examine authority, escalation, audit records, incident reporting, human intervention, and responsibility boundaries.

Question: Who could act, stop, review, and reconstruct the event?
TERA rule: do not infer more than the public evidence supports.
Recurring governance patterns

Patterns to test before deployment.

These are recurring control areas raised by incident analysis. They are not population failure rates and they do not imply that any single control guarantees prevention.

01

Pre-Deployment Evaluation

Test edge cases, known failure modes, subgroup behavior, adversarial inputs, and domain-specific limitations before operational promotion.

02

Human Authority

Define approval, override, escalation, and circuit-breaking authority before consequential automated actions occur.

03

Evidence Validation

Distinguish model output from verified evidence and apply independent checks when unsupported generation could create material harm.

04

Monitoring and Recovery

Detect changed behavior, retain useful telemetry, define degraded modes, and specify what happens after abnormal system behavior.

05

Access and Data Boundaries

Constrain sensitive data exposure, tool permissions, retention, and cross-context access according to the operating environment.

06

Capability Claims

Connect public and internal claims to defined evaluations, limitations, versions, and the actual conditions under which the system was tested.

Methodology

Reported fact and TERA analysis remain separate.

01
Source firstPrioritize regulator records, court decisions, official investigations, company postmortems, and reputable reporting.
02
Classify the failureRecord the observed mechanism, consequence, system boundary, and relevant TERA dimensions without forcing a single-label taxonomy.
03
Bound the inferenceDescribe control considerations for similar deployments without claiming that a control would have prevented the historical event unless evidence supports that conclusion.
04
Version the analysisEntries may change when new public evidence appears. Material changes should be dated and reviewable.

Transparency and analytical limits

The AI Incident Observatory is a curated learning resource. It does not provide real-time surveillance, assign legal fault, certify causal explanations, or replace independent audits. Public reporting may be incomplete and classifications may change as new evidence appears.

  • Source-reported facts are distinguished from TeraSystemsAI analysis.
  • Control considerations indicate relevance for similar systems, not proven historical preventability.
  • The observatory does not infer population failure rates from reported incidents.
  • No prevention percentage is published without a defined study design and supporting methodology.
  • Absence from the observatory does not imply absence of risk.