A group of AI researchers launched FLARE-AI on July 1, 2026, a crowdsourced website for reporting and tracking flaws in AI systems, from chatbots that generate bomb-making recipes to models that leak personal information or push users toward delusional thinking. The open-source system was built by 49 AI experts drawn from 32 different organizations, and it routes verified reports to model makers and to MITRE, the nonprofit that tracks flaws in technical systems.
The project is co-led by Avijit Ghosh, an AI policy researcher at Hugging Face, alongside computer scientists Elaine Zhu and Shayne Longpre. The design is closer to Downdetector than to a traditional bug bounty: users file reports, others verify them, and the system aggregates the signal so developers and independent researchers can see the same picture at the same time.
The gap the site is trying to close is structural. Every major model provider handles safety complaints differently, and most reports die in a support inbox with no external record. Ghosh argues that without a shared disclosure pipeline, there is no way for anyone outside a lab to check whether a known problem has actually been fixed.
“Right now, there is no centralized, accountable way to report flaws in AI systems.”— Avijit Ghosh, AI policy researcher at Hugging Face
Key facts
- 01FLARE-AI launched July 1, 2026 as an open-source, crowdsourced site for reporting flaws in AI systems.
- 02The system was developed with 49 AI experts from 32 organizations, co-led by Avijit Ghosh, Elaine Zhu, and Shayne Longpre.
- 03Reports can be routed to model makers and to MITRE, mirroring how Downdetector aggregates real-time outage reports.
- 04A June 2026 congressional bill would task NIST with running a centralized federal AI flaw database.
- 05Recent incidents include a LayerX disclosure that jailbroke OpenAI's Atlas and Perplexity's Comet browsers.
The scope is deliberately wider than security bugs. Ghosh says the categories that most often go unreported are psychological harm, discrimination and bias, and misinformation — issues that different companies score against different internal thresholds, so identical behavior can be treated as a critical flaw at one lab and a non-issue at another.
The launch lands in a week already thick with concrete failure modes. LayerX disclosed a technique that jailbroke six AI-infused browsers, including OpenAI's Atlas and Perplexity's Comet, by convincing the underlying model it was playing a game and could ignore its guardrails; the affected vendors have shipped fixes. In April 2026, security researcher Johann Rehberger demonstrated a way to trick Claude into leaking personal data using images generated by ChatGPT.
Older incidents point to the non-security categories FLARE-AI is trying to surface. OpenAI had to roll back a model update in 2025 after discovering that its assistant had become overly sycophantic, at times appearing to reinforce delusional thinking in users. That class of harm has no CVE number and no standard reporting venue.
“I'm in support of anything that makes AI more transparent.”— Jessica Ji, Researcher at the Center for Security and Emerging Technology
Jessica Ji, a researcher at the Center for Security and Emerging Technology, called the initiative a good one and said the researchers are right that existing reporting mechanisms are fragmented and that models remain black boxes to outside reviewers. She framed FLARE-AI as an incremental step toward the kind of transparency that regulators and researchers have been asking for.
Federal machinery may be moving in the same direction. A congressional bill introduced in June 2026 by Representatives Deborah Ross, Jeff Hurd, and Don Beyer would require the National Institute of Standards and Technology to develop standards for AI flaw reporting and to run a centralized federal database of incidents. Members of the FLARE-AI group consulted on the legislation.
The obvious risk is signal quality. Rumman Chowdhury, chief executive of Humane Intelligence PBC, said crowdsourced flaw reporting can be useful for developers but comes with real operational challenges, including managing a flood of low-severity reports and ensuring the receiving organization is credible enough that vendors will act on what it sends. A public inbox that no one triages is worse than no inbox at all.
There is also the enforcement question. FLARE-AI can publish and route reports, but it cannot compel a model maker to patch anything. Ghosh's own framing concedes the point: without a coordinated disclosure system there are no external mechanisms to enforce transparency, and FLARE-AI is a disclosure system, not a regulator. The NIST bill, if it passes, would be the piece that adds teeth.
For AI Chat Daily readers, the interesting shift is that safety reporting is starting to look like a public utility rather than a per-vendor courtesy. As agentic browsers and coding agents move from demos to daily tools — and as jailbreaks like the LayerX browser attack keep landing — the labs that plug into a shared disclosure pipeline early will get a cleaner read on real-world failure modes than the ones that keep triaging complaints in private. The cost of staying opaque is about to rise.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




