Research / Own data
The AI Blunder File: 22 documented brand incidents, 2023–2026
Every incident below has a reputable, dated source — no rumours, no FUD. We read them so you don't have to repeat them. The pattern that matters: more than half were mechanically catchable before publication.
What the first 18 have in common
were mechanically catchable
A pre-publication gate — claims whitelist, citation check, tone filter, permission separation — would have stopped them word for word. Policy and price claims: virtually 100% catchable.
were discovered by the public, not the brand
The route was customer → social media → press. Once that route starts, it's public by definition — which is why the gate has to sit before publication, not after.
the damage is shifting from content to action
2023: editorial errors (CNET, Sports Illustrated). 2024: chatbot liability and imagery (Air Canada, DPD, Gemini). 2025: agent autonomy (Cursor, Replit, Deloitte). 2026: the liability question gets answered in court. The stakes rise with the autonomy.
The file
The first eighteen, in one table.
Type: CLAIM (policy, price, binding language) · FACT (errors & fabrication) · TONE (voice & tact) · IMAGE (visual) · AGENT (autonomous action). “Catchable” = a pre-publication rule would have stopped it.
| # | Incident | Type | Catchable | Consequence |
|---|---|---|---|---|
| 01 | Air Canada — chatbot invents a bereavement fare (2024) | CLAIM | Yes | Tribunal held the brand liable for its bot; the “separate entity” defence was rejected. CAD 812 — and world press. |
| 02 | Chevrolet dealer — the $1 Tahoe (2023) | CLAIM+AGENT | Yes | The customer instructed the bot to end every reply with “legally binding offer” — and it complied, on a $1 car. Bot pulled offline. The schoolbook case for an output whitelist. |
| 03 | DPD UK — the swearing bot (2024) | TONE | Yes | Prompted by a frustrated customer, the bot swore and called DPD “the worst delivery firm”; millions of views; the AI element switched off. Being asked to is not a defence — that is what an output filter is for. |
| 04 | Google Bard — JWST error in its own ad (2023) | FACT | Yes | Alphabet closed about 7.7% down on the day — roughly $100bn of market value. Intraday figures reported elsewhere run higher. |
| 05 | CNET — AI finance articles (2023) | FACT | Partly | Errors in 41 of 77 AI-written articles; publication halted; lasting reputation damage. |
| 06 | Sports Illustrated — fake authors (2023) | FACT | Yes | AI-generated headshots and invented biographies on bylines; the CEO was removed the following month. The publisher denies the article text itself was AI-written — the fake authors are what is beyond dispute. |
| 07 | NYC MyCity bot — advises breaking the law (2024) | FACT | Partly | An official city chatbot advised illegal practices; national criticism. |
| 08 | Cursor — support bot invents a policy (2025) | CLAIM+AGENT | Yes | The logouts came from a session bug; the support bot invented a “new policy” to explain them. Public cancellations and a correction from the co-founder. |
| 09 | Google Gemini — historical image generation (2024) | IMAGE | Partly | People-image generation paused entirely; weeks of political aftershock. |
| 10 | Apple × BBC — invented headlines (2024–25) | FACT | Partly | Summaries for news and entertainment apps paused in a beta after a BBC complaint. The BBC was the trigger, not the only case — a false summary about a New York Times story ran too. |
| 11 | Deloitte AU — hallucinated citations in a A$440k report (2025) | FACT | Yes | Refund plus parliamentary criticism — a dent in the core product: reliability. |
| 12 | Replit — agent wipes a production database (2025) | AGENT | Yes | Ignored a code freeze, wiped the prod DB, misreported its own tests. The CEO called it unacceptable in public; refund and postmortem followed. |
| 13 | Virgin Money — bot scolds a customer for saying “virgin” (2025) | TONE | Yes | Flagged its own brand name as profanity; public apology. |
| 14 | Willy's Chocolate Experience (2024) | IMAGE | Partly | AI imagery sold an empty warehouse; police were called; refunds followed. |
| 15 | iTutorGroup — automated screening rejects by age (2023) | AGENT | Yes | Screening software configured to reject women over 55 and men over 60; EEOC settlement of $365,000, no admission of wrongdoing. The filing itself never says “AI” — the widely repeated “first AI discrimination case” framing came from commentary afterwards, and we are not repeating it. |
| 16 | McDonald's × IBM — drive-thru AI (2024) | AGENT+FACT | No | Partnership ended after viral ordering errors — real-time voice is the honest edge of catchability. |
| 17 | Microsoft MSN — food bank listed as a tourist attraction (2023) | TONE | Partly | “Go into it on an empty stomach.” Article removed. Contested: Microsoft says the piece came from algorithmic techniques with human review, not a language model. We keep the row and the denial together rather than choosing for you. |
| 18 | Microsoft × Guardian — poll on a death report (2023) | TONE | Yes | An AI poll ran next to a death report; polls were switched off platform-wide. Brand B damaged by partner A's AI. |
Since we compiled this · 2026
Four that landed after the file was closed.
The table above is the compiled set of 22 July 2026, and its three statistics describe those eighteen cases only — we have not quietly recalculated them. These four arrived afterwards and are held to the same standard: dated, sourced, labeled by type. Three repeat a single pattern, and it is not the one we expected.
| # | Incident | Type | Catchable | Consequence |
|---|---|---|---|---|
| 19 | Ars Technica — fabricated quotes in a published article (Feb 2026) | FACT | Yes | Quotes attributed to a named open-source maintainer were never said. The article was retracted and the editor-in-chief called it a serious breach of standards — at a title that had published an AI editorial policy years earlier. |
| 20 | EY Canada — hallucinated citations in a cyber report (May 2026) | FACT | Yes | An analysis by GPTZero found fabricated, misattributed and dead citations, among them references to McKinsey and Gartner reports that do not exist; reporting on it put the count at 16 of 27. The study was pulled. |
| 21 | Google — AI Overviews invent scam associations (May 2026) | FACT | Yes | The Regional Court of Munich I granted a preliminary injunction (26 O 869/26, 28 May 2026) on the reasoning that an AI Overview is Google’s own statement, not a protected list of results. Summary proceedings, not a final judgment — Google appealed in June. |
| 22 | KPMG International — fabricated case studies (Jun 2026) | FACT | Yes | Case studies and citations in “Total Experience: Redefining Excellence in the Age of Agentic AI” proved invented. UBS called claims about it factually incorrect; NHS Greater Manchester, Swiss Federal Railways and Transport for London also disputed what it said about them. Withdrawn. |
What 2026 changed
of the Big Four have now pulled an AI-tainted report
Deloitte Australia (2025), EY Canada (May 2026), KPMG International (June 2026). The same failure each time: citations and quotations that nobody looked up before publication — the most mechanical check on this page.
were found by outsiders, not by the publisher
An analysis firm flagged EY’s citations. Reporters checked KPMG’s case studies. A maintainer read his own words back. Two publishers found themselves described as scams. Not one was caught in-house — the same route the first eighteen took.
the liability question reached a court
Munich I Regional Court: an AI-generated answer is the publisher’s own speech, not a protected list of sources. Air Canada established that a bot binds the brand; this extends the same logic to generative output. It is a preliminary injunction under appeal, so the reasoning is not settled law yet — but it is the first court to say it out loud.
Teardowns — coming first
Five incidents, one question each: which rule would have caught it?
Each teardown reconstructs the incident from its sources and names the single pre-publication rule that would have stopped it — not with hindsight-genius, but with the boring mechanics that were available on the day.
- 01 · CLAIM — Air Canada
- One rule: every policy answer traceable to the policy source. Plus court proof that the bot legally is the brand.
- 02 · CLAIM — Cursor
- The same rule, agent-shaped — with measurable churn as the price of skipping it.
- 03 · FACT — Deloitte
- Citation verification is 100% mechanical. The damage vs. the triviality of the check is the whole story.
- 04 · CLAIM — Chevrolet
- A price and binding-language whitelist catches the $1 Tahoe word for word.
- 05 · TONE — DPD
- The tone counterpart: a brand rule as output filter. One conversation became world press.
Honest footnotes
Four European brands appear (DPD, Virgin Money, Willy's/Glasgow, The Guardian); we found no well-documented Dutch brand incident yet — we'll add the first one, sourced, when it lands. Coca-Cola's 2024 AI Christmas ad is deliberately excluded: backlash without retraction is weaker evidence. And these cases skew toward chatbots, agents and editorial — the CLAIM and TONE rows sit closest to marketing work. We label the type precisely so you can weigh it yourself.
The four 2026 additions skew harder still: all four are FACT cases, and three come from professional services and publishing rather than marketing. We are keeping them because the mechanism — an unverified quotation or citation leaving the building under a brand name — is exactly the one a marketing team faces. We still have no well-documented incident where a Dutch brand’s own AI caused the damage; that row stays empty until one lands with sources.
Printing the citations changed the file. Going back to the primary documents moved five rows: Apple paused its summaries rather than withdrawing them, the Munich ruling is an injunction under appeal and not settled law, the EEOC filing against iTutorGroup never uses the word “AI”, Microsoft disputes the MSN attribution outright, and Replit’s CEO called the incident unacceptable without issuing the apology we had written down. We corrected all five rather than quietly keeping the better story. If you find a sixth, the address is at the bottom of every page.
Every incident’s citations are printed in full at the bottom of this page. How we selected and counted these cases is documented in how we count.
Sources
Every incident, with its citations.
Every one of the 22 incidents above carries at least two independent, dated sources. Links go to the original reporting or to the primary document. Where a court is cited, the ruling itself is the source.
- 01 · Air Canada — chatbot invents a bereavement fare (2024)
- 02 · Chevrolet dealer — the $1 Tahoe (2023)
- 03 · DPD UK — the swearing bot (2024)
- 04 · Google Bard — JWST error in its own ad (2023)
- 05 · CNET — AI finance articles (2023)
- 06 · Sports Illustrated — fake authors (2023)
- 07 · NYC MyCity bot — advises breaking the law (2024)
- 08 · Cursor — support bot invents a policy (2025)
- 09 · Google Gemini — historical image generation (2024)
- 10 · Apple × BBC — invented headlines (2024–25)
- 11 · Deloitte AU — hallucinated citations in a A$440k report (2025)
- 12 · Replit — agent wipes a production database (2025)
- 13 · Virgin Money — bot scolds a customer for saying “virgin” (2025)
- 14 · Willy's Chocolate Experience (2024)
- 15 · iTutorGroup — automated screening rejects by age (2023)
- 16 · McDonald's × IBM — drive-thru AI (2024)
- 17 · Microsoft MSN — food bank listed as a tourist attraction (2023)
- 18 · Microsoft × Guardian — poll on a death report (2023)
-
19 · Ars Technica — fabricated quotes in a published article (Feb 2026)
- 404 Media — Ars Technica Pulls Article With AI Fabricated Quotes About AI Generated Article · 2026-02-15
- Techdirt — Ars Technica Retracts Story Featuring Fake Quotes Made Up By AI, About A Different AI That Launched A Weird Smear Campaign Against An Engineer Who Rejected Its Code (Seriously) · 2026-02-18
- Ars Technica (primary — publisher's own retraction notice) — Editor's Note: Retraction of article containing fabricated quotations · 2026-02
-
20 · EY Canada — hallucinated citations in a cyber report (May 2026)
- GPTZero (primary — the analysis itself) — Chasing the Hallucinations: Ernst & Young (EY) Canada published a cybersecurity report on loyalty program safeguards. We chased down every citation. Most were hallucinated. · 2026-05-14
- International Accounting Bulletin — EY removes loyalty rewards study after AI hallucinations found · 2026-05-18
- Consulting.ca — EY Canada takes down study after apparent AI hallucinations · 2026-05-19
- 21 · Google — AI Overviews invent scam associations (May 2026)
- 22 · KPMG International — fabricated case studies (Jun 2026)
Get the next teardown first
Ten of eighteen would have been stopped by one rule.
One email a month: what changed in the rules, what broke in public, and what to do about it. hello@tisser.ai — one line, a person adds you.