180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-150
Consumer AI · Global · 2024 · Mass biometric collection without a clear legal basis

A project scanned people's irises around the world for a digital ID, and regulators told it to stop

By Ellie Harris · Filed Launched July 2023; Spain ban March 2024

Alleged: Worldcoin (Tools for Humanity), co-founded by Sam Altman developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

A project scanned people's irises around the world for a digital ID, and regulators told it to stop

What happened

Worldcoin had an ambitious idea: to prove that someone is a real and unique human as AI becomes more widespread. It was reported that the project, co-founded by OpenAI’s chief executive Sam Altman and run by Tools for Humanity, offered people a digital ID and, in some countries, cryptocurrency tokens in exchange for having their iris scanned by a device called the Orb, and reporting indicates it launched widely in July 2023 and signed up people in many countries. But iris data is highly sensitive biometric information, and regulators began raising questions.

Spain’s data protection authority ordered Worldcoin to stop collecting and using people’s data in March 2024, citing complaints around transparency, data collected from minors and people being unable to withdraw consent. Kenya had already suspended the project in 2023, and on 5 May 2025 its High Court ordered the entities behind it to stop collecting, processing or transferring biometric data in the country and to permanently erase data already collected, under the supervision of the Data Protection Commissioner. On 21 January 2026, the commissioner’s office told Business Daily Africa that the biometric data had been deleted. Other regulators, including in Germany, opened investigations, and the project paused scanning in some countries. Worldcoin said it operated lawfully and worked with regulators.

What an auditable version would have shown

Before someone has their iris scanned, some basic questions should already have clear answers: what legal basis allows this data to be collected, how consent was obtained and whether it can be withdrawn, whether children are being signed up, and how long the data will be kept. Those decisions should be recorded before collection starts in a country, including evidence that a data protection assessment has been completed. Then a regulator can see the basis for collecting the data before the system scales, and the person being scanned can understand what was taken and ask for it back.

Where the gap was

The order matters here. The project was able to collect highly sensitive biometric data at scale and quickly, while questions about consent and the legal basis for collecting it were still being challenged. An iris scan is not like a password: if it is misused, you cannot simply replace it. People were signing up in exchange for crypto while regulators were raising questions about the things that should have been clear from the beginning: genuine consent, a lawful basis for collection and limits on how the data would be kept.

What governance should have looked like

Before the first scan, there should be a clear legal basis for collecting the biometric data, genuine consent from the person providing it, limits on how the data will be used and kept, and a way for that person to withdraw. An AuthorityGate is designed to stop collection until that authority and consent are actually in place; in other words, do not scan first and work out the justification later. A ConductRecord would preserve what was collected, from whom, on what basis and for how long, giving both regulators and participants something they can inspect and challenge. When the information being collected is part of someone’s body and cannot simply be reset, the right to collect it needs to be settled before it is taken.

The reference implementation of AuthorityGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed, free for any company to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Worldcoin (Tools for Humanity), co-founded by Sam Altman could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →