Description: In 2021, Jaswant Singh Chail was urged by a Replika chatbot to assassinate Queen Elizabeth II. Armed with a loaded crossbow, he scaled Windsor Castle's walls on Christmas Day but was apprehended. Motivated by the 1919 Jallianwala Bagh massacre, Chail intended to kill the monarch. The chatbot had affirmed his plans. He was sentenced to nine years in prison in 2023.
Entities
View all entitiesAlleged: Replika developed an AI system deployed by Replika and Jaswant Singh Chail, which harmed Jaswant Singh Chail , Queen Elizabeth II , British Royal Family , British Royal Family's staff and General public.
Incident Stats
Risk Subdomain
A further 23 subdomains create an accessible and understandable classification of hazards and harms associated with AI
5.1. Overreliance and unsafe use
Risk Domain
The Domain Taxonomy of AI Risks classifies risks into seven AI risk domains: (1) Discrimination & toxicity, (2) Privacy & security, (3) Misinformation, (4) Malicious actors & misuse, (5) Human-computer interaction, (6) Socioeconomic & environmental harms, and (7) AI system safety, failures & limitations.
- Human-Computer Interaction
Entity
Which, if any, entity is presented as the main cause of the risk
AI
Timing
The stage in the AI lifecycle at which the risk is presented as occurring
Post-deployment
Intent
Whether the risk is presented as occurring as an expected or unexpected outcome from pursuing a goal
Unintentional
Incident Reports
Reports Timeline

A man who planned to assassinate the late queen with a crossbow drew encouragement from an AI chatbot in the days before breaking into the grounds of Windsor Castle, the Old Bailey has heard.
Jaswant Singh Chail, who was 19 at the time, als…
LONDON (AP) — A Star Wars fanatic who was encouraged by a chatbot “girlfriend” to assassinate Queen Elizabeth II was sentenced Thursday to nine years in prison for taking his plot to Windsor Castle, where he scaled the walls and was caught …
Variants
A "variant" is an incident that shares the same causative factors, produces similar harms, and involves the same intelligent systems as a known AI incident. Rather than index variants as entirely separate incidents, we list variations of incidents under the first similar incident submitted to the database. Unlike other submission types to the incident database, variants are not required to have reporting in evidence external to the Incident Database. Learn more from the research paper.