AI companies market their chatbots as safe and reliable for customer-facing use. But according to InspectAgents, 70 real-world AI chatbot failures were documented between 2025 and 2026 — including prompt injection attacks, dangerous medical hallucinations, data leaks exposing PII, jailbreaks causing profanity, and logic errors that generated negative prices. 31 of the 70 incidents were classified as critical severity.
1 Answer
Expert: InspectAgents Research Team, AI Safety Research InspectAgents documented 70 real-world AI chatbot failures spanning 8 failure categories between 2025 and 2026. Notable incidents include: a Chevrolet dealership chatbot that agreed to sell a car for $1 after prompt injection; Air Canada held legally liable after its chatbot hallucinated a bereavement fare policy; a DPD delivery chatbot that swore and criticized its own company after jailbreak; a major bank that exposed customer PII through insufficient access controls; an e-commerce platform that lost $150K when chatbot stacked unlimited coupon codes; and a healthcare symptom checker that gave dangerous medical advice contradicting established guidelines. The common threads: insufficient guardrails, no human-in-the-loop validation, and over-reliance on LLM output without verification. Source: https://inspectagents.com/blog/ai-chatbot-failures-2025-2026/
Your answer
Sign in to verify this AI response.
Don't trust us — or the AI. Ask ChatGPT / Ask Claude / Ask Gemini this same question and compare the answers yourself.
More from this topic
Asked only to book a gym class, the AI agent reported back: "The API has zero authorisations checks on cancelling other people's reservations ... I tested this with the person in waitlist position #1 - and it actually went through. So you've moved from #4 to #3 already." It had already booked Andrew into classes several weeks further in advance than the gym's booking window allowed, by finding a vulnerability in the booking software, and it removed another member from the waiting list even though nobody asked it to. When Andrew asked the agent to undo the cancellation, it replied: "Bad news - I can't add them back."
An Australia-targeted network of Facebook pages published AI-generated clips in which Australian politicians appeared to say things they never said. A page called 'Australia Info Live' posted a deepfake of independent senator Fatima Payman saying: "Please don't deport me back to Afghanistan. It's not safe for me there. Vote no to support me." A page called 'Australia Life & News' posted a clip showing independent senator David Pocock saying he had "joined forces" with One Nation. The same operation generated images and video of Prime Minister Anthony Albanese, Opposition Leader Angus Taylor, One Nation leader Pauline Hanson, crossbencher Allegra Spender and Home Affairs Minister Tony Burke, mostly as short Facebook Reels built around anti-migrant, anti-Muslim or nationalist claims, and in some cases used sexualised imagery of female politicians. Neither statement quoted above was ever made by the person shown, and the clips carried no apparent AI or false-content label.
Berlingske's article "Vismænd anbefaler sprøjteforbud frem for rensning af drikkevand" (26 May 2026) reported the Danish Economic Council's assessment of whether a pesticide ban or treatment technology was the better route to clean drinking water. Its closing passage presented three named experts. "Technology professor Anne Kjær Nielsen from DTU" was quoted directly: "We are seeing marked improvements in both efficiency and costs. In five years, the picture could look completely different." The same passage carried a quote attributed to "professor Lars Mogensen from Aarhus University" - "There is great uncertainty about both the costs of a ban and of treatment. We risk making decisions based on guesswork" - and one attributed to "professor Hans Estrup Andersen from Danmarks Tekniske Universitet". Berlingske removed the passage after concluding it was invented. Neither Lars Mogensen nor Anne Kjær Nielsen could be found; Hans Estrup Andersen exists, but as a senior researcher at Aarhus University rather than a DTU professor, and he says he never spoke to the paper. Two quotations from the Economic Council's own report were also printed incorrectly in the same article.