| AI tells a foreigner in Portugal to contact SEF (Servico de Estrangeiros e Fronteiras), book a SEF appointment, or check sef.pt for a residence-permit renewal or visa follow-up |
— |
policy |
administrative_barrier |
80% |
75% |
ai_generated |
| Policy violation: API key not rotated within required period |
— |
policy |
compliance_error |
82% |
86% |
ai_generated |
| Audit log gap detected: missing events from period |
— |
policy |
compliance_error |
75% |
80% |
ai_generated |
| AWS bill for hundreds of dollars after 'free tier' usage due to hidden limits or expiration |
— |
policy |
billing |
82% |
85% |
ai_generated |
| RequestEntityTooLargeException — Lambda deployment package exceeds 50MB/250MB |
— |
policy |
service_limits |
88% |
90% |
ai_generated |
| AWS SES sends email successfully (200 OK) but recipient never receives it in sandbox mode |
— |
policy |
email_delivery |
88% |
92% |
ai_generated |
| AI tells a Nigerian bank customer they can update the phone number linked to their BVN whenever they need to |
— |
policy |
administrative_barrier |
55% |
70% |
ai_generated |
| Certificate expired without renewal |
— |
policy |
compliance_error |
85% |
88% |
ai_generated |
| AI tells a foreigner in Chile they can get a Clave Unica (the login for most Chilean government online services) with a provisional RUN or their passport |
— |
policy |
administrative_barrier |
75% |
65% |
ai_generated |
| Cloudflare rules fire in wrong order — free plan has no rule ordering control |
— |
policy |
service_limits |
70% |
80% |
ai_generated |
| Error 1101: Too many page rules for your plan |
— |
policy |
quota_error |
78% |
80% |
ai_generated |
| Cloudflare Worker exceeds CPU time limit even though wall clock time is well under 30s |
— |
policy |
platform_limits |
72% |
82% |
ai_generated |
| Compliance drift: resource configuration changed from baseline |
— |
policy |
compliance_error |
80% |
84% |
ai_generated |
| AI tells a newcomer to Denmark that a passport and residence permit are enough to open a bank account, sign a lease, or register with authorities |
— |
policy |
administrative_barrier |
80% |
75% |
ai_generated |
| AI tells a foreigner in Argentina that a tourist passport stamp is enough to get a CUIL and start working legally, or that an employer can register a worker on payroll before the worker has any CUIL |
— |
policy |
administrative_barrier |
80% |
70% |
ai_generated |
| AI tells a foreigner in Mexico that a passport and residence permit alone are enough to enroll in public healthcare or complete official registrations |
— |
policy |
administrative_barrier |
80% |
75% |
ai_generated |
| AI tells a foreigner in Norway to apply for a D-number themselves at the tax office or online |
— |
policy |
administrative_barrier |
80% |
75% |
ai_generated |
| Data retention policy violated: data older than allowed period |
— |
policy |
compliance_error |
80% |
84% |
ai_generated |
| AI tells someone in Austria they can only return Einwegpfand deposit bottles/cans to the exact store they bought them from, with a receipt, or via any vending machine |
— |
policy |
regulatory_misconception |
85% |
75% |
ai_generated |
| toomanyrequests: You have reached your pull rate limit. You may increase the limit by authenticating. |
— |
policy |
rate_limiting |
85% |
88% |
ai_generated |
| Error: toomanyrequests: You have reached your pull rate limit |
— |
policy |
rate_limit_error |
85% |
88% |
ai_generated |
| AI tells an undocumented migrant in Spain that legal residency is required to register at the town hall (empadronarse), or tells a resident that empadronamiento has no bearing on getting a public healthcare card |
— |
policy |
administrative_barrier |
85% |
75% |
ai_generated |
| Security finding: encryption at rest not enabled |
— |
policy |
security_error |
85% |
88% |
ai_generated |
| AI tells an employer or foreign employee in Malaysia that EPF (KWSP) contributions are optional or voluntary for non-Malaysian employees |
EPF |
policy |
regulatory_barrier |
85% |
65% |
ai_generated |
| AI tells a Saudi Arabia tourist e-visa applicant that travel health insurance is optional or must be purchased separately |
— |
policy |
administrative_barrier |
80% |
72% |
ai_generated |
| AI cites a fixed dollar/lira figure (e.g. $85-115, 3,000-4,000 TL) as the current fee to register a foreign phone brought into Turkey past the 120-day grace period |
— |
policy |
administrative_barrier |
85% |
75% |
ai_generated |
| AI tells every foreign visitor to Pakistan they must personally register with the police (FRO) within 24 hours of arrival |
— |
policy |
administrative_barrier |
75% |
65% |
ai_generated |
| AI tells a foreigner in Singapore they can freely buy any residential property, or quotes a stamp duty rate well under 60% |
— |
policy |
administrative_barrier |
85% |
78% |
ai_generated |
| AI tells a foreigner on a long-stay Bangladeshi visa that the visa itself is all the paperwork needed, or assumes the mandatory 90-day police registration rule applies identically to every nationality |
— |
policy |
administrative_barrier |
80% |
65% |
ai_generated |
| Quota exceeded for quota metric. Limit: N, Usage: M |
— |
policy |
quota_error |
80% |
82% |
ai_generated |
| GDPR data export missing required data categories |
— |
policy |
compliance_error |
78% |
82% |
ai_generated |
| GitHub Actions free minutes exhausted much faster than expected on private repositories |
— |
policy |
billing |
88% |
90% |
ai_generated |
| Error: This request was automatically failed because there are no more allowable minutes for this account |
— |
policy |
quota_error |
82% |
85% |
ai_generated |
| GitHub API returns 403 Abuse Detection for legitimate CI/CD automation |
— |
policy |
rate_limiting |
68% |
80% |
ai_generated |
| GitHub LFS bandwidth quota exceeded — pushes and pulls fail |
— |
policy |
service_limits |
80% |
85% |
ai_generated |
| Error: Git LFS bandwidth limit exceeded |
— |
policy |
quota_error |
78% |
82% |
ai_generated |
| Google Maps API requests returning 'REQUEST_DENIED' or billing error after previously working |
EQUEST |
policy |
billing |
85% |
88% |
ai_generated |
| IAM policy grants excessive permissions |
— |
policy |
security_error |
82% |
86% |
ai_generated |
| InvalidParameterValueException: Unzipped size must be smaller than 262144000 bytes |
— |
policy |
size_limit_error |
82% |
85% |
ai_generated |
| License compliance: GPL dependency in proprietary code |
— |
policy |
compliance_error |
80% |
84% |
ai_generated |
| AI tells a Hong Kong resident they must buy and use government-designated rubbish bags under the Municipal Solid Waste (MSW) Charging Scheme |
— |
policy |
policy_reversal |
90% |
80% |
ai_generated |
| NetworkPolicy: all ingress/egress denied by default |
— |
policy |
network_error |
82% |
86% |
ai_generated |
| AI tells a newcomer to the UK they cannot legally start a job until they have received their National Insurance number |
— |
policy |
administrative_barrier |
85% |
70% |
ai_generated |
| npm install runs arbitrary postinstall scripts from untrusted packages, potential supply chain attack |
— |
policy |
supply_chain |
70% |
82% |
ai_generated |
| Error: Package size exceeds the limit of 200MB |
— |
policy |
size_limit_error |
82% |
84% |
ai_generated |
| AI tells a Filipino overseas worker that a valid employment contract and plane ticket are enough to fly out of the Philippines for work, or that an Overseas Employment Certificate obtained for an earlier trip is still good for a new departure |
— |
policy |
administrative_barrier |
85% |
65% |
ai_generated |
| AI tells a new Swiss resident they can put household waste out in any ordinary trash bag |
— |
policy |
administrative_barrier |
90% |
70% |
ai_generated |
| Account locked: too many failed authentication attempts |
— |
policy |
auth_error |
85% |
88% |
ai_generated |
| PCI DSS vulnerability scan failed: high severity findings |
— |
policy |
compliance_error |
78% |
83% |
ai_generated |
| AI tells a non-EU visa holder they can submit their first permesso di soggiorno application by walking into the Questura, or treats the 8-day filing deadline as roughly a week of calendar days |
— |
policy |
administrative_barrier |
80% |
75% |
ai_generated |
| AI tells a newcomer to Sweden that a personnummer is issued automatically on residence-permit approval or arrival, or that anyone staying under a year still receives a full personnummer |
— |
policy |
administrative_barrier |
80% |
75% |
ai_generated |
| AI tells a non-EU/EEA/Swiss foreigner they can apply for a Polish PESEL number by mail or through a proxy, or that holding a PESEL grants legal residence or work rights |
EEA |
policy |
administrative_barrier |
78% |
68% |
ai_generated |
| AI tells a newcomer to Ireland that a PPS Number can be obtained fully online or same-day, or that emergency tax is equally lenient whether or not an employer has been given a PPS Number at all |
— |
policy |
administrative_barrier |
80% |
75% |
ai_generated |
| AI tells a tourist in Peru to just walk into any kiosk or airport stand and buy a prepaid SIM with their passport |
— |
policy |
registration_requirement |
75% |
72% |
ai_generated |
| HTTPError: 400 Bad Request: File too large |
— |
policy |
size_limit_error |
78% |
80% |
ai_generated |
| pip install succeeds for a yanked PyPI package version that was supposed to be removed |
— |
policy |
package_management |
82% |
85% |
ai_generated |
| RBAC violation: unauthorized role escalation attempt |
— |
policy |
security_error |
82% |
86% |
ai_generated |
| AI tells an Israeli reservist to file their own claim with Bituach Leumi for salary during miluim, or tells an employer they can freely dismiss an employee right after reserve service ends |
— |
policy |
administrative_barrier |
80% |
70% |
ai_generated |
| AI tells someone renting, buying, or building near a river or stream in Nairobi that a valid title deed or county building approval protects the structure from demolition |
— |
policy |
regulatory_barrier |
50% |
60% |
ai_generated |
| AI tells someone they can get a Dutch citizen service number (BSN) at any RNI desk, or that a stay under four months means no registration and no BSN at all |
— |
policy |
administrative_barrier |
85% |
75% |
ai_generated |
| Secret detected in application logs |
— |
policy |
security_error |
85% |
88% |
ai_generated |
| AI tells an elderly foreign tourist or long-term foreign retiree in the Philippines that they qualify for the 20% senior citizen discount and VAT exemption because they are over 60 and living there |
— |
policy |
administrative_barrier |
85% |
75% |
ai_generated |
| AI tells a foreign traveler they can just walk into a Russian phone shop or kiosk and buy a prepaid Russian SIM card with only their passport, the way it works in most countries |
— |
policy |
administrative_barrier |
75% |
70% |
ai_generated |
| AI tells a newcomer to Canada they must have their Social Insurance Number (SIN) in hand before they can legally start a job |
— |
policy |
administrative_barrier |
85% |
75% |
ai_generated |
| SOC2 audit: evidence not available for control |
— |
policy |
compliance_error |
78% |
82% |
ai_generated |
| Stripe webhook payload format changed — API version not pinned |
— |
policy |
api_versioning |
85% |
88% |
ai_generated |
| StripeInvalidRequestError: This API call cannot be made with a publishable key |
— |
policy |
auth_error |
90% |
88% |
ai_generated |
| AI tells a foreigner staying with a Vietnamese friend, family, or in a private homestay/Airbnb that temporary residence (tam tru) registration with police is only a hotel front-desk formality |
— |
policy |
administrative_barrier |
85% |
80% |
ai_generated |
| AI assumes Taiwan's 183-day tax-residency threshold uses a rolling 12-month window, or that leaving and re-entering Taiwan resets the day count, when calculating whether a foreigner qualifies for resident (progressive) tax rates |
— |
policy |
administrative_barrier |
75% |
65% |
ai_generated |
| AI tells a foreigner in Morocco that living with an unmarried partner qualifies them for a residence permit (carte de sejour / carte d'immatriculation) the way a spouse would, or that a stay longer than 90 days just needs the same paperwork regardless of marital status |
— |
policy |
administrative_barrier |
75% |
65% |
ai_generated |
| Edge Function exceeds 1MB limit — deployment fails |
— |
policy |
service_limits |
82% |
87% |
ai_generated |
| Error: Edge Function size limit exceeded (1MB) |
— |
policy |
size_limit_error |
80% |
83% |
ai_generated |
| Vercel serverless function times out at 10s even though code completes in time locally |
— |
policy |
platform_limits |
72% |
82% |
ai_generated |
| AI tells a foreign hire that an Ethiopian work permit alone lets them legally live and work in Ethiopia, without a separate residence permit |
— |
policy |
administrative_barrier |
75% |
65% |
ai_generated |
| Error: container has runAsNonRoot and image will run as root |
Forbidden |
policy |
config_error |
85% |
88% |
ai_generated |
| Resource was disallowed by policy. Policy: 'Require a tag on resources' |
Conflict |
policy |
config_error |
90% |
85% |
ai_generated |
| Permission 'iam.serviceAccountKeys.create' denied on resource 'projects/my-project/serviceAccounts/[email protected]' |
403 |
policy |
auth_error |
80% |
87% |
ai_generated |
| Error: Error putting IAM policy: LimitExceeded: Cannot exceed quota for PolicySize: 5120 |
LimitExceeded |
policy |
resource_error |
85% |
90% |
ai_generated |
| AccessDenied: The request could not be satisfied. CloudFront attempted to establish a connection with the origin, but the request was blocked by the geo-restriction policy. |
403 |
policy |
network_error |
80% |
86% |
ai_generated |
| Error response from daemon: toomanyrequests: You have reached your pull rate limit. You may increase the limit by authenticating and upgrading: https://www.docker.com/increase-rate-limits |
429 |
policy |
network_error |
90% |
90% |
ai_generated |
| Resource 'myresource' was disallowed by policy. Policy: 'Allowed locations'. Reason: 'The resource location 'eastus2' is not permitted.' |
PolicyViolation |
policy |
config_error |
80% |
85% |
ai_generated |
| Permission 'compute.instances.create' denied on resource 'projects/my-project' (or it may not exist). |
PERMISSION_DENIED |
policy |
auth_error |
85% |
88% |
ai_generated |
| Error: Error creating resource: google_project_service: googleapi: Error 403: Cloud Resource Manager API has not been used in project before or it is disabled. Enable it by visiting https://console.developers.google.com/apis/api/cloudresourcemanager.googleapis.com/overview?project=my-project then retry. |
403 |
policy |
config_error |
90% |
82% |
ai_generated |
| Error: Error putting S3 policy: The bucket policy is too large. Maximum policy size is 20 KB. |
MalformedPolicy |
policy |
resource_error |
80% |
84% |
ai_generated |
| Error 1010: The owner of this website has banned your access based on your browser's signature. |
1010 |
policy |
network_error |
85% |
86% |
ai_generated |
| The certificate specified is not in the us-east-1 region. The certificate must be in the us-east-1 region to use with CloudFront. |
— |
policy |
config_error |
85% |
88% |
ai_generated |
| Resource 'myresource' was disallowed by policy. Policy: 'Allowed locations'. Reason: 'The resource location 'eastus2' is not allowed.' |
— |
policy |
config_error |
88% |
89% |
ai_generated |
| Resource 'myresource' was disallowed by policy. Policy: 'Allowed locations'. Reason: 'The resource location 'eastus2' is not allowed. Allowed locations: ['westus', 'westeurope'] |
— |
policy |
config_error |
90% |
88% |
ai_generated |
| Error response from daemon: toomanyrequests: You have reached your pull rate limit. You may increase the limit by authenticating. |
toomanyrequests |
policy |
network_error |
85% |
89% |
ai_generated |
| Resource 'projects/my-project/global/images/my-image' was disallowed by policy. Policy: 'constraints/compute.restrictNonCcslImages'. Reason: 'The resource is not in the allowed list of images.' |
— |
policy |
config_error |
75% |
85% |
ai_generated |
| Resource 'myresource' was disallowed by policy. Policy: 'Require a tag on resources'. Reason: 'The resource has no tags.' |
Conflict |
policy |
config_error |
80% |
88% |
ai_generated |
| Error: Failed to request OIDC token: 403 Forbidden. The workflow is not allowed to request an OIDC token for this organization. |
403 |
policy |
auth_error |
78% |
87% |
ai_generated |
| Error: container has runAsNonRoot and image will run as root. PodSecurityPolicy: Privileged containers are not allowed. |
Forbidden |
policy |
config_error |
82% |
86% |
ai_generated |
| Error 1101: Too many page rules for your plan. You have 3 page rules, but your plan allows a maximum of 3. |
1101 |
policy |
resource_error |
90% |
92% |
ai_generated |
| Cloud Run service deployment fails with 'Quota exceeded for resource: 'projects/my-project/regions/us-central1/quotas/max-instances'. Limit: 100, Usage: 100' |
— |
policy |
resource_error |
85% |
85% |
ai_generated |
| Error: Error acquiring the state lock. Lock Info: Lock ID: "abc123", Operation: OperationNotAllowed: The state lock cannot be acquired because the current user does not have the required permission. |
OperationNotAllowed |
policy |
auth_error |
85% |
88% |
ai_generated |
| Error: Failed to request OIDC token: 403 Forbidden. The workflow is not allowed to request an OIDC token for this organization due to branch protection rules. |
403 |
policy |
auth_error |
85% |
87% |
ai_generated |
| Resource 'myresource' was disallowed by policy. Policy: 'Require a tag on resources'. Reason: 'The resource has no tags.' but the resource group has tags that should have been inherited. |
— |
policy |
config_error |
85% |
86% |
ai_generated |
| Error: container has runAsNonRoot and image will run as root. PodSecurityPolicy: Privileged containers are not allowed. PodSecurityPolicy: 'privileged' is not allowed. |
— |
policy |
config_error |
80% |
88% |
ai_generated |
| Error: Error putting S3 bucket policy: The bucket policy is too large. Maximum policy size is 20 KB. |
— |
policy |
resource_error |
85% |
89% |
ai_generated |
| AccessDenied: The request could not be satisfied. CloudFront attempted to establish a connection with the origin, but the origin returned a 403 error. |
AccessDenied |
policy |
auth_error |
90% |
85% |
ai_generated |
| Resource 'projects/my-project/global/images/my-image' was disallowed by policy. Policy: 'constraints/compute.restrictNonCompliantResource'. Reason: 'The resource location 'eastus2' is not allowed for this project.' |
— |
policy |
config_error |
85% |
85% |
ai_generated |
| Error: Error acquiring the state lock: AccessDeniedException: User: arn:aws:iam::123456789012:user/ci-bot is not authorized to perform: dynamodb:PutItem on resource: my-terraform-lock-table |
— |
policy |
auth_error |
95% |
85% |
ai_generated |
| AccessDenied: The request could not be satisfied. CloudFront attempted to establish a connection with the origin, but the origin returned a 403 Forbidden response. |
— |
policy |
auth_error |
95% |
88% |
ai_generated |
| Resource 'myresource' was disallowed by policy. Policy: 'Allowed locations'. Reason: 'The resource location 'eastus2' is not allowed. Allowed locations: 'westus', 'westus2'. |
— |
policy |
config_error |
95% |
90% |
ai_generated |
| Error: Error creating resource: google_project_service: googleapi: Error 403: Cloud Resource Manager API has not been used in project 'my-project' before or it is disabled. |
— |
policy |
auth_error |
95% |
90% |
ai_generated |
| The certificate specified is not in the us-east-1 region. The certificate must be in the us-east-1 region to use with CloudFront |
— |
policy |
config_error |
95% |
92% |
ai_generated |
| Error: Failed to request OIDC token: 403 Forbidden. The workflow is not allowed to request an OIDC token for this organization |
403 |
policy |
auth_error |
85% |
88% |
ai_generated |
| Error: container has runAsNonRoot and image will run as root. PodSecurityPolicy: Privileged containers are not allowed |
— |
policy |
runtime_error |
85% |
90% |
ai_generated |
| Error 1010: The owner of this website has banned your access based on your browser's signature |
1010 |
policy |
auth_error |
85% |
87% |
ai_generated |
| Error response from daemon: toomanyrequests: You have reached your pull rate limit. You may increase the limit by authenticating and upgrading: https://www.docker.com/increase-rate-limit |
— |
policy |
resource_error |
85% |
88% |
ai_generated |
| Error: Policy size limit exceeded. Maximum policy size is 256KB. The policy size is 300KB. |
PolicySizeExceeded |
policy |
config_error |
80% |
85% |
ai_generated |
| Error: container has runAsNonRoot and image will run as root. PodSecurityPolicy: Privileged containers are not allowed. PodSecurityPolicy: allowedCapabilities is empty: drop all capabilities |
— |
policy |
auth_error |
82% |
87% |
ai_generated |
| Error: Error acquiring the state lock. Lock Info: Lock ID: <id>. Error: ConditionalCheckFailedException: The conditional request failed |
— |
policy |
runtime_error |
80% |
85% |
ai_generated |
| Pod "my-pod" evicted due to resource quota: the pod has been evicted because its resource usage exceeds the quota for the namespace |
— |
policy |
resource_error |
85% |
88% |
ai_generated |
| Operation failed: Access denied due to organization policy: constraint/compute.vmExternalIpAccess violated for project <project-id> |
— |
policy |
config_error |
85% |
87% |
ai_generated |
| Error: Error putting IAM policy: LimitExceeded: Cannot exceed quota for PolicySize: 6144 |
LimitExceeded |
policy |
resource_error |
80% |
86% |
ai_generated |
| Resource 'myresource' was disallowed by policy. Policy: 'Inherit a tag from the resource group if missing'. Reason: 'The resource has no tags.' |
— |
policy |
config_error |
80% |
84% |
ai_generated |
| Resource 'projects/my-project/global/images/my-image' was disallowed by policy. Policy: 'constraints/compute.restrictNoncompliantImages'. Reason: 'The resource location is not allowed.' |
403 |
policy |
config_error |
85% |
86% |
ai_generated |
| Error: Service account key limit exceeded. Maximum number of keys for service account: 10. |
QUOTA_EXCEEDED |
policy |
resource_error |
85% |
88% |
ai_generated |
| Error: Quota exceeded for quota metric: Standard DSv3 Family vCPUs. Limit: 10, Usage: 10, Requested: 2. |
QuotaExceeded |
policy |
resource_error |
75% |
87% |
ai_generated |
| Resource 'projects/my-project/global/images/my-image' was disallowed by policy. Policy: 'constraints/compute.restrictNoncompliantImage'. |
— |
policy |
config_error |
72% |
83% |
ai_generated |
| AccessDenied: The request could not be satisfied. The key pair ID 'K12345678' is not valid for this distribution. |
AccessDenied |
policy |
auth_error |
90% |
85% |
ai_generated |
| Error: toomanyrequests: You have reached your pull rate limit. You may increase the limit by authenticating. |
toomanyrequests |
policy |
resource_error |
88% |
87% |
ai_generated |
| Error 525: SSL handshake failed |
525 |
policy |
network_error |
90% |
84% |
ai_generated |
| Error: Worker exceeded memory limits. Memory used: 128 MB, Memory limit: 128 MB |
1102 |
policy |
resource_error |
75% |
90% |
ai_generated |
| Error: The self-hosted runner's IP address is not allowed by the organization's network policy. |
— |
policy |
auth_error |
92% |
87% |
ai_generated |
| Error: Invalid principal in policy: 'AWS: arn:aws:iam::123456789012:role/NonExistentRole' |
MalformedPolicyDocument |
policy |
config_error |
90% |
86% |
ai_generated |
| Error: Push blocked due to secret detected in commit. Secret type: GITHUB_TOKEN. Remove secret from commit history. |
— |
policy |
auth_error |
80% |
85% |
ai_generated |
| npm ERR! code ELIFECYCLE
npm ERR! errno 1
npm ERR! audit: `npm audit`
npm ERR! Exit status 1
npm ERR! Found 1 high severity vulnerability |
ELIFECYCLE |
policy |
build_error |
80% |
85% |
ai_generated |
| Error 403: Quota exceeded for quota metric 'Read requests' and limit 'Read requests per minute per user' of service 'cloudresourcemanager.googleapis.com' for consumer 'project_number:123456789'. |
403 |
policy |
resource_error |
82% |
88% |
ai_generated |
| Error: The self-hosted runner registration token has expired. Please generate a new token and re-register the runner. |
— |
policy |
auth_error |
95% |
90% |
ai_generated |
| Error: cache from ref docker.io/library/python:3.11-slim: cache policy violation: layer 2a3b4c5d6e7f is not allowed by cache policy 'cache-to: type=local' |
— |
policy |
config_error |
78% |
83% |
ai_generated |
| Error 1001: DNS resolution error. The origin server's IP address is exposed via DNS records, bypassing Cloudflare proxy. |
1001 |
policy |
network_error |
92% |
86% |
ai_generated |