180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-135
Consumer AI · United States · 2023 · Undisclosed AI

A mental-health support app used GPT-3 to help write messages to thousands of people seeking help, and critics said the users were not clearly told a machine was involved

By Ellie Harris · Filed Feature ran in October 2022; disclosed publicly 6 January 2023

Alleged: Koko (peer-support platform) developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

A mental-health support app used GPT-3 to help write messages to thousands of people seeking help, and critics said the users were not clearly told a machine was involved

What happened

It was reported that in October 2022 Koko, an online peer-support platform, ran a feature that used OpenAI’s GPT-3 to help write emotional-support messages. Volunteers offering support could see a machine-drafted reply and edit it before sending it on. Around 4,000 people were reported to have received messages that were at least partly written by the model.

Reporting indicates the people receiving those messages saw a note that the reply was written in collaboration with Koko Bot, but were given little more than that, and that there was no clear step where they were told a machine was involved and agreed to take part. In January 2023 Koko’s co-founder described the feature publicly. He said the AI-assisted messages had at first been rated more highly than ones written by people alone, and that the effect faded once people learned a machine was involved. Researchers and ethicists said people reaching out for support had in effect been experimented on without informed consent. He defended the work, saying the feature was opt-in, that a person reviewed the messages before they were sent, and that people could skip a message, while arguing that not all uses of AI should need formal ethics-board review. He also accepted that the disclosure had been thin.

What an auditable version would have shown

When a person reaches out for help and a reply comes back, the one thing they are owed is to know who, or what, is writing to them. An auditable version keeps, for each message, whether a model helped write it, what the person was told, and whether they agreed to take part. With that record, the question everyone asked afterwards, were people told a machine was involved and did they consent, has an answer on file. Without it, the disclosure is a single soft label, and the debate becomes one person’s account against another’s.

Where the gap was

The gap was that the disclosure and the consent were not built into the product as something you could check. People got a small label, Koko Bot, and nothing that recorded what they were actually told or whether they agreed to take part. So when the question came later, were these people informed and did they consent, the answer rested on the founder’s account rather than on anything kept at the time.

What governance should have looked like

The more fragile the person reading the reply, the plainer you have to be about who wrote it. Someone reaching out for help should be told, in clear words, that a machine helped write the answer, and given a real chance to say no, before any of this reaches people in distress. A conduct record keeps proof of that for each message: whether the model helped, what the person was told, and whether they agreed. None of this stops anyone using AI to help write support. It just means the people on the other end know, can decline, and the platform can show it treated them fairly.

The reference implementation of ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed, free for any company to install. The repository is public now.

Sources

This entry concerns mental health support. If you or someone you know needs help in Australia, Lifeline is available on 13 11 14.

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Koko (peer-support platform) could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →