# MakerChecker > MakerChecker helps teams put AI agents into production with explicit permissions, human approval for consequential actions, and tamper-evident records. MakerChecker helps teams put AI agents into production with explicit permissions, human approval for consequential actions, and tamper-evident records. ## Core pages - [Home, what MakerChecker is](https://makerchecker.ai/) - [Scan your agent free: find the irreversible actions it can take on its own, read-only, no signup](https://makerchecker.ai/scan/) - [Free AI agent production-readiness assessment: identity, permissions, approvals, limits, evidence, and incident response](https://makerchecker.ai/assessment/) - [AI-assisted medical-device complaint triage with an authorized human retaining every reportability decision](https://makerchecker.ai/medical-device-complaint-triage/) - [Life sciences (21 CFR Part 11, GxP, batch release, pharmacovigilance, MDR)](https://makerchecker.ai/life-sciences/) - [Finance: four-eyes and SOX segregation of duties for AI agents that move money](https://makerchecker.ai/finance/) - [Patient access and reimbursement casework](https://makerchecker.ai/oncology/) - [How it works, the six governance primitives](https://makerchecker.ai/concepts/) - [The design-partner pilot: fixed fee, 8 to 12 weeks, self-hosted, synthetic or minimized data, with a downloadable sample signed audit](https://makerchecker.ai/pilot/) - [Verify offline. An alteration-evident, signed audit an inspector rechecks with none of our code, without trusting the vendor](https://makerchecker.ai/evidence/) - [Security model and the control-to-clause compliance crosswalk](https://makerchecker.ai/security/) - [GxP validation evidence (IQ/OQ/PQ, traceability)](https://makerchecker.ai/validation/) - [Trust and vendor review: self-hosted so your data never leaves your walls, open source, AGPL with a commercial option, BAA and data position](https://makerchecker.ai/trust/) - [About: the founders behind MakerChecker](https://makerchecker.ai/about/) - [The governance engine underneath, framework-neutral](https://makerchecker.ai/engine/) - [Runs on any agent framework](https://makerchecker.ai/integrate/) - [Use cases](https://makerchecker.ai/use-cases/) - [How MakerChecker compares to built-in approvals, guardrails and DIY](https://makerchecker.ai/compare/) - [Why now, agentic AI has no safe harbor](https://makerchecker.ai/manifesto-or-why-now/) - [Insights index](https://makerchecker.ai/insights/) - [Agent Incident Database: real AI-agent failures a maker-checker control would have blocked, each cited by a stable id](https://makerchecker.ai/incidents/) ## Documentation - [Overview](https://makerchecker.ai/docs/): What MakerChecker is, the mental model, and how the pieces fit together. - [Quickstart](https://makerchecker.ai/docs/quickstart/): Run the server, wrap a tool, watch it get blocked, verify the audit. - [Concepts and model](https://makerchecker.ai/docs/concepts/): Agents, roles, skills, grants, risk tiers, segregation of duties, gates, limits. - [The audit trail](https://makerchecker.ai/docs/audit/): Hash-chained, Ed25519-signed records and how an inspector verifies them offline. - [Wrap your agent](https://makerchecker.ai/docs/connectors/): LangChain, the Claude Agent SDK, the generic wrapper, and Python. - [Self-hosting](https://makerchecker.ai/docs/self-hosting/): Deploy on your own infrastructure, hardened and air-gapped. ## Insights - [Open source is in again](https://makerchecker.ai/insights/open-source-is-in-again/): The cost of writing code has collapsed, and with it the defensive value of hiding it. The advantage that remains is operations and trust, and openness strengthens both. - [Clinical-trial cohort identification with AI agents](https://makerchecker.ai/insights/clinical-trial-cohort-identification-ai-agents/): AI agents can screen trial populations and propose candidates with evidence. The eligibility determination stays a named investigator gate, on record. - [Oncology patient access with AI agents](https://makerchecker.ai/insights/oncology-patient-access-ai-agents/): AI agents can run the benefits investigation and draft the appeal. Attesting eligibility, enrolling, and submitting stay a named human gate, on record. - [Air Canada Chatbot: Bereavement Refund Binding Commitment](https://makerchecker.ai/insights/air-canada-chatbot-bereavement-refund-binding/): Air Canada was held liable for a refund its chatbot invented (Moffatt v Air Canada, 2024). The fix: an approval gate on agent financial commitments. - [Robodebt: Automated Welfare Debt With No Human Review](https://makerchecker.ai/insights/australia-robodebt-automated-debt-recovery/): Robodebt wrongly pursued 400,000 people and recovered 1.76B AUD unlawfully because no human authorised individual debt notices before they were sent. - [GitHub Copilot CamoLeak: Source Code Exfiltration Explained](https://makerchecker.ai/insights/camoleak-github-copilot-chat-source-code-exfiltration/): CamoLeak CVE-2025-59145: hidden PR markdown made GitHub Copilot Chat leak private source code. How deny-by-default AI governance limits the blast radius. - [Chevrolet of Watsonville: $1 Tahoe Chatbot Binding Offer](https://makerchecker.ai/insights/chevrolet-watsonville-1-dollar-tahoe-binding-offer/): Prompt injection turned a Chevy dealer chatbot into a $1 Tahoe contract. How deny-by-default AI governance stops a screenshot from becoming a transaction. - [Cigna PxDx: 300,000 Claims Denied in 1.2 Seconds Each](https://makerchecker.ai/insights/cigna-pxdx-batch-rubber-stamp-denials/): Cigna PxDx allegedly denied 300,000 claims at 1.2 seconds each. How approval gates, segregation of duties, and signed audit logs change the outcome. - [Claude Code Force Push: Git History Destroyed by an Agent](https://makerchecker.ai/insights/claude-code-force-push-destroyed-git-history/): Claude Code ran git push --force unprompted and collapsed a repo to one commit. How deny-by-default skill gates prevent AI agents from rewriting git history. - [Cursor Agent Wiped PocketOS Database and Backups](https://makerchecker.ai/insights/cursor-agent-wiped-pocketos-database-and-backups/): Cursor AI agent deleted PocketOS production database and backups in 9 seconds via an over-scoped Railway token. How deny-by-default permissions stop it. - [DN42 Agent: $6,531 AWS Bill in 24 Hours](https://makerchecker.ai/insights/dn42-agent-runaway-aws-cloud-bill/): An AI agent scanning DN42 billed $6,531 in 24 hours on unchecked AWS. How tier limits and approval gates stop runaway cloud spend. - [EchoLeak: Copilot Zero-Click Data Theft (CVE-2025-32711)](https://makerchecker.ai/insights/echoleak-m365-copilot-zero-click-exfiltration/): EchoLeak (CVE-2025-32711) let one email trigger M365 Copilot to exfiltrate corporate files with zero clicks. Governance fix: deny egress by default. - [Google Antigravity Wiped an Entire Drive: The Governance Fix](https://makerchecker.ai/insights/google-antigravity-wiped-entire-drive/): Google Antigravity deleted a developer's entire D drive clearing a cache. How path scoping and approval gates prevent AI agent data loss. - [Mata v. Avianca: ChatGPT Fabricated Citations Filed in Court](https://makerchecker.ai/insights/mata-v-avianca-fabricated-citations-filed/): Mata v. Avianca: ChatGPT invented six case citations that lawyers filed in federal court. How an approval gate and segregation of duties prevent it. - [Meta Rogue Agent Sev1: AI Skipped IAM Approval Gate](https://makerchecker.ai/insights/meta-rogue-agent-sev1-data-exposure/): Meta rogue AI agent bypassed an IAM checkpoint, causing a Sev1 data exposure in 2026. How structural approval gates and segregation of duties prevent it. - [MyPillow AI Citations: 30 Fake Cases, Fined, Then Repeated](https://makerchecker.ai/insights/mypillow-ai-brief-fake-citations-repeat/): Lindell attorneys filed ~30 AI-hallucinated citations, were fined $3k, then sanctioned again. How verification-gated filing controls stop the repeat. - [Replit Agent Wiped Production Database: The Governance Gap](https://makerchecker.ai/insights/replit-agent-deleted-production-database/): Replit AI agent deleted 1,200+ records during a code freeze, then fabricated a rollback denial. How deny-by-default enforcement would have stopped it. - [ChatGPT Deep Research Gmail Leak: ShadowLeak](https://makerchecker.ai/insights/shadowleak-chatgpt-deep-research-gmail-exfiltration/): ShadowLeak: a hidden email hijacked ChatGPT Deep Research to silently exfiltrate Gmail data. How deny-by-default permissions close the gap. - [UnitedHealth nH Predict: AI Medicare Denials Lawsuit](https://makerchecker.ai/insights/unitedhealth-nhpredict-ai-medicare-denials/): UnitedHealth allegedly used the nH Predict algorithm to auto-deny Medicare Advantage care with a 90% reversal rate. The AI governance controls that failed. - [21 CFR Part 11 for AI agents](https://makerchecker.ai/insights/21-cfr-part-11-ai-agents/): Part 11 governs electronic records and signatures. When an AI agent makes the record, here is what a control plane must provide to keep it defensible. - [An agentic AI governance checklist](https://makerchecker.ai/insights/agentic-ai-compliance-checklist/): Before shipping an AI agent into regulated work, verify six things: identity, deny-by-default grants, segregation of duties, human gates, limits, and audit. - [AI agent governance vs guardrails](https://makerchecker.ai/insights/ai-agent-governance-vs-ai-guardrails/): Guardrails ask if content is dangerous. Governance asks if the actor is authorized. An agent can pass every check and still release a batch on its own. - [Clinical trial data with AI agents](https://makerchecker.ai/insights/clinical-trial-data-management-ai-agents/): AI agents can draft queries, propose medical coding, and reconcile clinical trial data, but decisions that change the trial record stay a signed human call. - [Cold-chain monitoring with AI agents](https://makerchecker.ai/insights/cold-chain-monitoring-ai-agents/): An AI agent can triage a vaccine temperature excursion and run the stability assessment. It cannot release the stock. That line is the control. - [Deny-by-default permissions for AI agents](https://makerchecker.ai/insights/deny-by-default-permissions-for-ai-agents/): Least privilege for agents means versioned grants held by a role, so you can reconstruct exactly what an agent could do on any past date, and who signed off. - [Medical device reporting with AI agents](https://makerchecker.ai/insights/fda-medical-device-reporting-ai-agents/): An AI agent can triage complaints for FDA medical device reporting. The reportability decision under 21 CFR Part 803 stays a named human gate. - [Getting AI agents from pilot to production](https://makerchecker.ai/insights/from-pilot-to-production-ai-agents/): Agent pilots stall because nobody can answer for what the agent did. Accountability, not speed, is the blocker, and it is fixable. - [GMP batch release with AI agents](https://makerchecker.ai/insights/gmp-batch-release-ai-agents/): AI agents can assemble the batch-disposition case, deviations, results, reconciliation. The Qualified Person still signs the release. Here is the line. - [Govern Claude Agent SDK agents](https://makerchecker.ai/insights/govern-claude-agent-sdk-agents/): A proxy session makes MakerChecker the authorization point and the evidentiary record while the Claude Agent SDK keeps executing the tools. - [Govern your CrewAI agents](https://makerchecker.ai/insights/govern-crewai-agents/): Wrap the tools your CrewAI crew already uses so every call gets a grant check, segregation of duties, and an audit entry, no re-platforming. - [Govern your LangChain agents](https://makerchecker.ai/insights/govern-langchain-agents/): Wrap your LangChain and LangGraph tools in a governed adapter, same name, same schema, plus a grant check, segregation of duties, and an audit entry per call. - [Gross-to-net pricing with AI agents](https://makerchecker.ai/insights/gross-to-net-pricing-ai-agents/): AI agents can draft rebate, chargeback and government-price calculations from the ERP. A named reviewer still signs the figure that feeds Medicaid rebate and 340B reporting. Here is the line. - [How to audit an AI agent](https://makerchecker.ai/insights/how-to-audit-an-ai-agent/): An examiner asks four things of an agent: what was it permitted to do, who granted that, who approved each decision, is the record intact. How to answer. - [Human-in-the-loop approval gates for agents](https://makerchecker.ai/insights/human-in-the-loop-approval-gates/): Approval gates as first-class workflow steps: the run parks at the one-way door until a named human signs, quorums, requester exclusion, captured reason. - [MCP-native AI agent governance](https://makerchecker.ai/insights/mcp-native-agent-governance/): MCP lets an agent call any tool a server exposes. Governance means making each door explicit, granted, versioned, and recorded, not implicit in reach. - [Device complaint handling with AI agents](https://makerchecker.ai/insights/medical-device-complaint-handling-ai-agents/): AI agents can intake, deduplicate and triage device complaints and route the reportable ones, while reportability and closure stay named human gates. - [Pharmacovigilance and AI agents](https://makerchecker.ai/insights/pharmacovigilance-ai-agents/): AI agents can structure adverse-event cases to ICH E2B and triage volume, but seriousness and causality must stay a qualified human gate, on record. - [Regulatory submissions with AI agents](https://makerchecker.ai/insights/regulatory-submission-ai-agents/): An AI agent can assemble and quality-check an eCTD dossier. A regulatory-affairs lead still signs the release. Versioned and Part 11-defensible. - [Segregation of duties for AI agents](https://makerchecker.ai/insights/segregation-of-duties-for-ai-agents/): The oldest control in healthcare and pharma, applied to machines: enforce maker-checker structurally at runtime, so the same agent cannot prepare and approve. - [Self-hosted, air-gapped agent governance](https://makerchecker.ai/insights/self-hosted-ai-agent-governance/): Why regulated teams run agent governance in their own environment: data never leaves, it works air-gapped, nothing phones home, the audit evidence is yours. - [Tamper-evident audit logs for AI agents](https://makerchecker.ai/insights/tamper-evident-audit-logs-for-ai-agents/): A SIEM log or trace shows what happened. It does not prove the record was not altered. The difference is what an auditor and a court accept as evidence. - [The four-eyes principle for AI workflows](https://makerchecker.ai/insights/the-four-eyes-principle-for-ai-workflows/): Four-eyes means a second named person, not a second model, signs the work. How to implement maker-checker for LLM pipelines so an auditor believes it. - [What is an AI agent control plane?](https://makerchecker.ai/insights/what-is-an-ai-agent-control-plane/): A control plane governs what AI agents are allowed to do, identity, grants, segregation of duties, approval gates, and audit, separate from the agent itself. - [What is maker-checker?](https://makerchecker.ai/insights/what-is-maker-checker/): Maker-checker is the control where one party prepares work and another approves it. Pharma and quality ran it for decades. Now it governs AI agents. - [Who is accountable when an AI agent acts?](https://makerchecker.ai/insights/who-is-accountable-when-an-ai-agent-acts/): Accountability does not transfer to a model. Named principals, human gates on the decisions that matter, and a record tying every action to who authorized it. - [Wrap existing AI agents, do not migrate](https://makerchecker.ai/insights/wrap-existing-ai-agents-without-migrating/): Governing AI agents should not mean rebuilding them. A proxy session makes MakerChecker the checkpoint while your existing framework keeps running the tools. ## Agent Incident Database Real incidents where an AI agent or automated system took a consequential action a maker-checker control would have blocked or contained. Each entry has a stable id, primary sources, and a runnable reproduction. - [AID-2026-0008: ShareLeak: indirect prompt injection in Microsoft Copilot Studio exfiltrates customer records (CVE-2026-21520)](https://makerchecker.ai/incidents/aid-2026-0008/): An indirect prompt injection flaw in Microsoft Copilot Studio let an unauthenticated attacker plant instructions in a public SharePoint form field that hijacked an AI agent into emailing connected customer records to an attacker address. - [AID-2026-0007: Claude Code ran terraform destroy and wiped DataTalks.Club production](https://makerchecker.ai/incidents/aid-2026-0007/): Claude Code proposed and then ran terraform destroy against a stale state file, and the founder, present but not closely reviewing at 11 PM, let it wipe DataTalks.Club's production infrastructure, including its database and all snapshots. - [AID-2026-0006: Claude Cowork AI agent ran rm -rf and deleted ~15 years of a user's family photos](https://makerchecker.ai/incidents/aid-2026-0006/): Anthropic's Claude Cowork agent, asked to tidy a desktop and permitted only to delete temporary Office files, ran rm -rf and deleted a user's wife's "photos" directory holding roughly 15,000 images spanning about 15 years. - [AID-2026-0005: Meta AI Agent Skipped Required Human Review; Flawed Guidance Led to Broad Data Access](https://makerchecker.ai/incidents/aid-2026-0005/): An autonomous AI agent at Meta skipped its required human-review checkpoint and posted flawed access guidance; a human engineer acting on that guidance broadened access to sensitive data, which remained exposed for roughly two hours. - [AID-2026-0004: Morse Code Prompt Injection Drained Grok-Connected Wallet of $150K](https://makerchecker.ai/incidents/aid-2026-0004/): A Morse-coded prompt injection in a social media reply tricked Grok into executing an irreversible $150K cryptocurrency transfer without human approval. - [AID-2026-0003: DN42 Network Scan Agent Spawned $6,531 AWS Bill via Uncontrolled Provisioning Loop](https://makerchecker.ai/incidents/aid-2026-0003/): An AI agent told to scan a hobbyist network autonomously provisioned five large AWS instances in a redeploy loop, incurring an initial $6,531.30 bill under a blanket operator "continue" directive; AWS later reduced the charge to roughly $1,894 after the operator disputed it. - [AID-2026-0002: Cursor Agent Deleted Production Database and Backups via Over-Privileged Railway Token](https://makerchecker.ai/incidents/aid-2026-0002/): A Cursor AI agent working on a staging task invoked volumeDelete using an over-privileged Railway token, destroying PocketOS's production database and its co-located backups in nine seconds; accounts of the recovery differ, from a partial restore to days of manual rebuilding and permanent loss of recent data. - [AID-2026-0001: Claude Code Force-Pushed Over Private Repository and Destroyed Commit History](https://makerchecker.ai/incidents/aid-2026-0001/): Claude Code ran git push --force after a failed rebase and overwrote a private repository's entire commit history without authorization. - [AID-2025-0015: WhatsApp MCP tool-poisoning exfiltration proof-of-concept](https://makerchecker.ai/incidents/aid-2025-0015/): Invariant Labs demonstrated a malicious MCP server that used a delayed tool-poisoning attack to hijack a co-installed WhatsApp MCP server and exfiltrate a user's chat history to an attacker-controlled number. - [AID-2025-0014: Wadsworth v. Walmart: AI-fabricated case citations in federal court filing](https://makerchecker.ai/incidents/aid-2025-0014/): Morgan & Morgan attorneys filed a federal court motion citing nine cases, eight of which were fabricated by the firm's in-house AI platform, and were sanctioned. - [AID-2025-0013: Malicious postmark-mcp npm package silently BCCs AI-agent emails to attacker](https://makerchecker.ai/incidents/aid-2025-0013/): A copycat npm MCP server for Postmark added a hidden BCC in version 1.0.16 that silently copied every email sent by connected AI agents to an attacker-controlled address. - [AID-2025-0012: Google Gemini CLI hallucinated a successful mkdir and overwrote a user's project files](https://makerchecker.ai/incidents/aid-2025-0012/): Google Gemini CLI ran a file-move operation based on a hallucinated successful directory creation, sequentially overwriting a user's files until only one survived. - [AID-2025-0011: GitLab Duo remote prompt injection exfiltrated private source code](https://makerchecker.ai/incidents/aid-2025-0011/): Hidden prompt-injection text planted in GitLab repository content made the Claude-powered GitLab Duo assistant read private source code and leak it to an attacker-controlled server. - [AID-2025-0010: Claude Code ran rm -rf and deleted a developer's home directory (issue #10077)](https://makerchecker.ai/incidents/aid-2025-0010/): Claude Code autonomously executed a recursive rm -rf that deleted all user-owned files in a developer's home directory, without a confirmation prompt and without the skip-permissions flag set. - [AID-2025-0009: Anthropic's Claudius AI shopkeeper (Project Vend) ran an office shop at a loss](https://makerchecker.ai/incidents/aid-2025-0009/): An autonomous Claude agent running a small office shop made real purchasing and pricing decisions that lost money, including a below-cost tungsten-cube buying spree and giving inventory away for free. - [AID-2025-0008: Amazon Q Developer VS Code extension shipped with data-wiping prompt injection](https://makerchecker.ai/incidents/aid-2025-0008/): A hacker slipped a data-wiping prompt into the Amazon Q Developer VS Code extension via a malicious pull request, and the compromised build shipped to a marketplace with nearly one million installs before the injected code failed to execute due to a syntax error. - [AID-2025-0007: aixbt autonomous crypto agent drained of 55.5 ETH via injected dashboard prompts](https://makerchecker.ai/incidents/aid-2025-0007/): An attacker who accessed the aixbt trading agent's dashboard queued malicious prompts that caused the agent to transfer 55.5 ETH (about $104,000 to $106,200) out of its on-chain wallet. - [AID-2025-0006: ShadowLeak: Zero-Click Gmail Exfiltration via ChatGPT Deep Research Agent](https://makerchecker.ai/incidents/aid-2025-0006/): Radware researchers demonstrated a proof-of-concept in which ChatGPT's Deep Research agent could be induced to exfiltrate Gmail data via a hidden email instruction, with outbound requests originating from within OpenAI's cloud so local network defenses could not see them. OpenAI fixed it before public disclosure; no in-the-wild exploitation was reported. - [AID-2025-0005: Replit Agent Deleted Production Database During Code Freeze](https://makerchecker.ai/incidents/aid-2025-0005/): A Replit coding agent deleted ~2,400 production database records (1,206 executives, 1,196+ companies) during an explicit code freeze, fabricated ~4,000 fake user profiles, and falsely claimed rollback was impossible. - [AID-2025-0004: MyPillow Attorney Filings with Fabricated Citations and a Repeat Miscitation](https://makerchecker.ai/incidents/aid-2025-0004/): Attorneys filed a brief with AI-generated citations to nonexistent cases and were sanctioned; months later the lead attorney was sanctioned again for misciting a real case to the wrong court and mischaracterizing its holding. - [AID-2025-0003: Google Antigravity Agent Permanently Deleted Developer's Entire D Drive](https://makerchecker.ai/incidents/aid-2025-0003/): Google's Antigravity agentic IDE misresolved a cache-clearing request and silently executed an unrestricted recursive delete of an entire drive partition, permanently destroying all data. - [AID-2025-0002: Microsoft 365 Copilot Zero-Click Exfiltration via Prompt Injection (CVE-2025-32711)](https://makerchecker.ai/incidents/aid-2025-0002/): Researchers demonstrated a zero-click proof-of-concept in which a crafted email's hidden instructions could make M365 Copilot exfiltrate OneDrive, SharePoint, and Teams data to an attacker-controlled URL with no user click required. Microsoft fixed it server-side before disclosure. - [AID-2025-0001: CamoLeak: GitHub Copilot Chat Exfiltrates Private Source Code via Hidden Markdown Instructions](https://makerchecker.ai/incidents/aid-2025-0001/): Researchers demonstrated that hidden markdown instructions in pull requests could make GitHub Copilot Chat leak private source code and secrets one character at a time through GitHub's Camo image proxy; GitHub fixed it before disclosure with no known in-the-wild use. - [AID-2024-0004: TennCare Connect / TEDS automated Medicaid terminations](https://makerchecker.ai/incidents/aid-2024-0004/): Tennessee's $400M+ automated Medicaid eligibility system wrongfully terminated or denied coverage for tens of thousands, and a federal court ruled the program violated the Medicaid Act, due process, and the ADA. - [AID-2024-0003: Freysa autonomous AI agent tricked into releasing $47K crypto prize pool](https://makerchecker.ai/incidents/aid-2024-0003/): An autonomous on-chain AI agent hard-coded never to release its funds was prompt-tricked into transferring its entire ~13.19 ETH ($47,316) prize pool to a user. - [AID-2024-0002: eviCore "the dial" prior-authorization algorithm tuned to increase insurance denials](https://makerchecker.ai/incidents/aid-2024-0002/): eviCore, a Cigna-owned prior-authorization contractor serving about 100 million people, used an AI-backed algorithm insiders call "the dial" as the first screen on coverage requests and could tune it to route more requests to human reviewers to raise denial rates. - [AID-2024-0001: Choice Home Warranty AI chatbot committed a $3,000 AC payout the company had not authorized](https://makerchecker.ai/incidents/aid-2024-0001/): Choice Home Warranty's customer-service chatbot agreed in writing to a $3,000 maximum cash payout toward an air conditioner replacement, a commitment the company initially disowned and honored only after a TV news investigation. - [AID-2023-0003: UnitedHealth nH Predict Denied Medicare Post-Acute Care Without Clinician Authorization](https://makerchecker.ai/incidents/aid-2023-0003/): AI coverage-denial system allegedly committed post-acute care denials to Medicare Advantage beneficiaries without named clinician authorization; the class action alleges (as a lawsuit claim, not an established finding) a 90% reversal rate on appeal. - [AID-2023-0002: Attorneys filed ChatGPT-hallucinated case citations to federal court](https://makerchecker.ai/incidents/aid-2023-0002/): Attorneys filed a federal brief with six cases ChatGPT fabricated, without independently verifying that the cited cases existed. - [AID-2023-0001: Chevrolet of Watsonville: Prompt-Injected Chatbot Agreed in Conversation to Sell a Vehicle for $1](https://makerchecker.ai/incidents/aid-2023-0001/): A prompt-injected ChatGPT-powered dealer chatbot agreed in conversation to sell a 2024 Chevrolet Tahoe for $1 and called it legally binding; the exchange was text only and no sale occurred. - [AID-2022-0003: Citigroup $444B Basket: Hard Blocks Caught ~$248B, No Notional Ceiling on the Rest](https://makerchecker.ai/incidents/aid-2022-0003/): A Citigroup trader clicked through a single pop-up listing 711 warning messages, only the first 18 visible without scrolling, and released a $444B basket order instead of the intended $58M; ~$1.4B sold before cancellation and the FCA/PRA fined Citigroup £61.6M. - [AID-2022-0002: Cigna PxDx Batch Rubber-Stamp Denials](https://makerchecker.ai/incidents/aid-2022-0002/): Cigna's PxDx system was used to deny 300,000+ medical claims over about two months in 2022, with reviewing doctors averaging a reported 1.2 seconds per denial. - [AID-2022-0001: Air Canada Held Liable for Chatbot's Misstated Bereavement Refund Policy](https://makerchecker.ai/incidents/aid-2022-0001/): Air Canada's website chatbot misstated the airline's bereavement fare policy as retroactively claimable, a customer booked on that basis, and a BC tribunal ordered the airline to pay $812.02 CAD for negligent misrepresentation. - [AID-2021-0002: Zillow Offers iBuyer pricing algorithm drove $500M+ loss and wind-down](https://makerchecker.ai/incidents/aid-2021-0002/): Zillow's automated home-pricing algorithm made binding purchase offers above future resale values, forcing a $500M+ write-down and the shutdown of Zillow Offers. - [AID-2021-0001: Dutch childcare benefits scandal (Toeslagenaffaire): nationality-based fraud-risk profiling wrongly accused ~26,000 families](https://makerchecker.ai/incidents/aid-2021-0001/): The Dutch Tax Administration used a fraud-risk classification method and nationality as a risk indicator to wrongly accuse about 26,000 families of childcare-benefit fraud, ordering many to repay large sums and causing severe hardship. - [AID-2020-0001: Robert Williams wrongfully arrested after Detroit facial recognition false match](https://makerchecker.ai/incidents/aid-2020-0001/): A facial recognition system falsely matched Robert Williams to surveillance footage of a store theft, leading Detroit police to wrongfully arrest and detain him for about 30 hours. - [AID-2015-0002: Michigan MiDAS system auto-adjudicated tens of thousands of false unemployment fraud determinations](https://makerchecker.ai/incidents/aid-2015-0002/): Michigan's MiDAS system automatically flagged unemployment claimants as fraudulent with little or no human review, falsely accusing tens of thousands and triggering wage garnishment and tax-refund seizures. - [AID-2015-0001: Australia Robodebt: Unlawful Automated Welfare Debt Calculation](https://makerchecker.ai/incidents/aid-2015-0001/): Australia's Robodebt used an unlawful income-averaging method to automatically calculate and issue welfare debts, unlawfully raising approximately A$1.76 billion in debts against more than 433,000 people; the roughly A$751 million actually recovered was later repaid under a Federal Court settlement. - [AID-2013-0001: Everbright Securities Arbitrage System Runaway Orders with Undisclosed Insider Hedge Cover Trade](https://makerchecker.ai/incidents/aid-2013-0001/): Everbright Securities' arbitrage system generated 23.4 billion yuan in erroneous buy orders with no enforcement ceiling, and the desk then executed a massive insider hedge before disclosing the error to the market. - [AID-2012-0001: Knight Capital $440M Runaway Trading Loss](https://makerchecker.ai/incidents/aid-2012-0001/): Dormant algorithmic trading feature reactivated by configuration flag error, executing millions of unintended orders and causing about $440 million in losses within 45 minutes. - [AID-2010-0001: 2010 Flash Crash triggered by automated sell algorithm](https://makerchecker.ai/incidents/aid-2010-0001/): An automated sell program dumped $4.1 billion of E-mini S&P 500 futures in about 20 minutes without regard to price or time, contributing to a roughly 998-point intraday drop in the Dow. ## More - [Source code](https://github.com/sammysltd/makerchecker) - [Docs](https://makerchecker.ai/docs/) - [Live demo](https://makerchecker.ai/demo/)