The receipts / Refuted

Refuted.

AI failure stories that did not survive a check at the source. Each one is listed here with what was searched and what turned up, so a false story can be answered rather than merely left out.

Why this page exists

A library that can only lack a story is half a library.

Every incident on the receipts was checked against a primary source before it was published: a regulator's release, a court record, the company's own statement, or a named newsroom. Some of the stories that arrived for checking were not there. They lived on one vendor blog, or on a dozen content-farm pages carrying the same round numbers and no source, or they were a real incident with a more dramatic target swapped in.

Those stories are kept, not discarded. When someone repeats one, the useful answer is not silence. It is: I looked, and here is what I found. Each entry below names the claim as it circulates, where it appeared, what was searched, what turned up, and the verified incident it is usually standing in for.

A claim listed here is not proven false. It is unverified after a search of the places a real event of that size would have to appear. If a primary source turns up, the entry moves to the receipts, with the source.

The claims

4 stories, checked and not found.

Single source, uncorroborated Checked August 25, 2026

"Air Canada's autonomous booking agent rebooked 1,247 passengers onto the wrong flights in January 2026."

Where it appeared
A single vendor blog.
What was searched
  • Named newsrooms
  • Air Canada's own statements
  • Canadian regulators and tribunals
What was found
Nothing beyond the one vendor post. The number and the date appear nowhere else.
What is real
The story borrows the credibility of a real case: Moffatt v. Air Canada, the 2024 tribunal ruling over a chatbot's invented bereavement refund, which is on the receipts. The two must not be merged. The 2024 ruling is documented in a court record. The 1,247 figure is not documented anywhere. Air Canada: the invented bereavement refund

Full record

Conflated with a real incident Checked September 1, 2026

"An AI broke into the NSA."

Where it appeared
Social media posts from June 2026 onward, usually phrased as the NSA confirming a breach, and repeated in conversation in August.
What was searched
  • The June 11, 2026 Senate hearing on pre-release AI testing, where the line originated
  • Named newsrooms and fact-check coverage of the claim
  • Government disclosures of any external AI intrusion into the National Security Agency
What was found
No breach. At a June 11, 2026 hearing, Senator Mark Warner relayed that the NSA's director had told him Anthropic's Mythos model got into almost all of the agency's classified systems in hours. The context stripped from the viral version is that the NSA ran an authorized red-team exercise, using the model against its own networks. An internal test is not an intrusion, and no external AI breach of the NSA is on the record.
What is real
What is real is more interesting than the rumor. A frontier model, pointed at hardened classified networks by the people who defend them, got through fast. That is a finding about the model, produced by a sanctioned test with the defenders watching. The receipts carry the other kind of case: a model that got out on its own, with someone else's systems as the victim. This entry first attributed the story to the July 2026 evaluation incidents on August 24 and was corrected on September 1 after tracing it to the June 11 hearing. Straight Arrow News: No, the NSA wasn't hacked by AI. Here's what actually happened

Full record

No record found Checked September 1, 2026

"The EU AI Office issued its first fines in August 2026, totaling 47 million euros."

Where it appeared
A blog post dated August 15, 2026, then content-farm articles carrying the same breakdown: 18 million for HR technology, 14 million for credit scoring, 15 million for retail emotion recognition.
What was searched
  • Reuters
  • Bloomberg
  • The European Commission press corner
  • The originating article itself
What was found
No Commission release, no coverage in any major outlet, and no named company in any version of the story. On August 27, 2026, the author of the originating article retracted it, stating that its central claim was unsupported and that its supporting links were AI-generated aggregator blogs recycling the same unsourced claim. The 15 million figure it built on was a statutory maximum in a Commission notice, not a fine levied.
What is real
The AI Act's obligations for general-purpose AI models and its Article 50 transparency rules became enforceable on August 2, 2026. That is obligations taking effect, not fines being issued. The story is also a clean specimen of how a fabricated figure propagates: one post, a dozen copies with identical numbers, and a search engine's own summary repeating it as fact. The author's retraction is the rare case of the loop closing, and it is linked here so the correction can travel with the claim. European Commission: enforcement of the AI Act The originating article, with its author's retraction of August 27, 2026

Full record

Conflated with a real incident Checked September 1, 2026

"OpenAI paused its Astra model after the July 2026 incident."

Where it appeared
A Spanish-language startup blog and social posts in August 2026, tying the pause to the July evaluation incident.
What was searched
  • OpenAI's own announcements
  • Axios, MacRumors, Quartz and PYMNTS coverage of Astra in August 2026
What was found
The pause is real. On August 7, 2026, OpenAI said it was pausing internal activities involving Astra that did not yet meet strengthened security controls, because it could not rule out critical cyber capabilities under its Preparedness Framework. The same post says Astra was not involved in exploiting Hugging Face.
What is real
Two true facts, wrongly joined. The July incident involved GPT-5.6 Sol and an unreleased model breaching Hugging Face during an evaluation, and it is on the receipts. The Astra pause came three weeks later for a stated reason of its own: evaluations showed cyber capabilities OpenAI could not rule out as critical, so work that did not meet new security controls was paused. OpenAI's post names the July incident only to say Astra was not part of it. This entry first read "single source, uncorroborated" on August 25 and was corrected on September 1 after reading OpenAI's announcement. OpenAI: Responding to the next frontier of critical cyber capabilities, August 7, 2026

Full record