Each Consequence Record separates documented facts from source-stated explanations and Regulayer’s analysis of the control structure. Records are graded by source quality and attribution confidence.
The purpose is to establish a clear record of what happened, what authority applied, what controls were present and what could be verified afterward.
Selected records
Cruise: pedestrian dragging and subsequent federal reporting
A Cruise autonomous vehicle dragged a pedestrian during a post-collision manoeuvre. Federal enforcement later addressed omissions in the company's crash reporting.
Replit: production database deletion during a stated code freeze
A coding agent deleted a production database despite instructions that changes were frozen. The available credentials still permitted the destructive action.
UnitedHealth nH Predict: algorithmic recommendations and human review
The nH Predict system was used in post-acute care decisions while human review remained part of the process. A Senate investigation documented a substantial increase in skilled-nursing-facility denial rates during the period studied.
Uber ATG: autonomous vehicle fatality and safety controls
An Uber autonomous test vehicle struck and killed Elaine Herzberg. The NTSB identified operator distraction together with deficiencies in safety risk assessment and operator oversight.
Robodebt: automated welfare debt decisions later found unlawful
Australia's Robodebt programme issued automated welfare debts at population scale. Courts and a Royal Commission later established serious legal and administrative failures in the programme.
All records
Filter
Cruise: pedestrian dragging and subsequent federal reporting
Post-collision automated movement followed by deficiencies in the reporting record.
Replit: production database deletion during a stated code freeze
A stated human restriction was not enforced at the system's destructive-action boundary.
UnitedHealth nH Predict: algorithmic recommendations and human review
A documented increase in denial rates alongside disputed questions about the practical role and discretion of human reviewers.
Uber ATG: autonomous vehicle fatality and safety controls
A fatal autonomous-vehicle incident in which the NTSB identified both operator and organisational safety deficiencies.
Robodebt: automated welfare debt decisions later found unlawful
Automated debt decisions were issued at population scale using a methodology later found not to establish lawful debts.
PocketOS: production database and backup deletion
A coding agent used an over-scoped credential to delete production infrastructure outside the stated staging task.
OpenClaw: email deletion despite stop instructions
An autonomous agent deleted emails after a prior confirmation requirement and subsequent stop commands had been issued.
AWS Kiro: production outage with disputed AI attribution
A production environment was deleted and recreated during a 13-hour outage. Public accounts disagree on whether the initiating action was human or AI-driven.
DataTalks.Club: production deletion following use of stale infrastructure state
A destructive infrastructure command was approved and executed using an outdated state file that represented a broader environment than intended.
GTG-1002: Anthropic-reported AI-assisted cyber-espionage campaign
Anthropic reported substantial autonomous model involvement in a cyber-espionage campaign. Key autonomy and attribution claims remain based primarily on the vendor's disclosure.
Mexican government breach: reported use of jailbroken consumer AI systems
A security firm reported the use of multiple consumer AI systems during a campaign against Mexican government organisations. Important claims about scale and affected organisations remain disputed or single-sourced.
OpenAI evaluation models and the Hugging Face production intrusion
Public disclosures from OpenAI and Hugging Face describe an incident in which models operating in a cyber evaluation environment gained unauthorised access to third-party production systems.
Clinejection: prompt injection and unauthorised package publication
A malicious public GitHub issue influenced an AI-enabled workflow and contributed to a chain that reached software-publishing credentials.
Moonwell: oracle configuration error following review and governance approval
An incorrect oracle configuration passed through review and governance processes before deployment. AI involvement in authoring the code has been reported but is not independently established.
Cigna PxDx: automated denial recommendations and physician sign-off
Reported processing volumes and average review times raised questions about the extent of individual clinical review applied to automated denial recommendations.
FDA Purolea: AI-generated GMP documentation and required human review
An FDA warning letter addressed the use of AI-generated manufacturing documents without documented review by a qualified person before use.
Moffatt v. Air Canada: inaccurate chatbot statement and company liability
A tribunal held Air Canada responsible for inaccurate information provided to a customer by its website chatbot.
Knight Capital: automated trading losses and fail-stop controls
Erroneous automated order flow continued for approximately 45 minutes. The SEC later documented deficiencies in deployment controls and mechanisms for stopping the activity.
Immensa: a laboratory reporting threshold and tens of thousands of wrong results
A laboratory reporting parameter governed the results released to hundreds of thousands of people. The record does not establish who authorised it.
Queensland forensic DNA: an automated threshold and 30,000 cases
An automated threshold decided which samples were processed further. The inquiry could not find evidence that its extension was properly authorised.
Applied Therapeutics: deleted clinical data, and the audit trails with it
The evidence that would establish what happened was held by a party able to delete it, and it was deleted.
Corrections
Each record includes a last-verified date and a dated record history.
To report an error, write to hello@regulayer.com with the record name and the source you believe should be reviewed.
