A video conferencing startup has filed suit against Palo Alto Networks and its recently acquired Koi Security subsidiary, claiming an AI-generated threat report falsely accused the company of operating infrastructure for a Chinese espionage campaign. The case highlights a growing problem: security firms using AI to produce threat intelligence without adequate human oversight, then publishing those findings as established fact.
How a hallucinated report spiraled into real consequences
MeetingTV, a webinar and meeting recording service founded by entrepreneur Michael Robertson, learned it had been labeled malware infrastructure only when security vendors around the world started blocking its domains. The startup never received a heads-up from Koi Security before its December 30, 2025 blog post went live. According to Robertson, he only discovered the report after contacting security companies one by one to ask why they were blocking him. One finally responded and pointed him to the Koi blog.
The report, titled "DarkSpectre: Unmasking the Threat Actor Behind 7.8 Million Infected Browsers," claimed MeetingTV's Zoomcorder product was a "public-facing front" for a Chinese criminal operation running corporate espionage and malware campaigns. It alleged the service served as a monetization channel for an actor Koi called DarkSpectre. The blog also tied Zoomcorder to a browser extension identified as "Twitter X Video Downloader," described as the critical link connecting Zoom Stealer campaigns to DarkSpectre infrastructure.
That extension, according to MeetingTV's lawsuit, does not exist. Koi refused to provide information about the software when MeetingTV requested it.
The AI platform at the center of the dispute
The lawsuit alleges Koi used its proprietary "Wings" analytical platform, which relies on large language models, to generate the threat report. The complaint accuses Koi of "unsupervised reliance" on the system, which produced erroneous correlations between MeetingTV's legitimate business and the alleged cybercriminal operation. Koi then published those findings without human review or verification, the lawsuit claims.
The December blog was silently edited after publication to remove references to Zoomcorder. Archived versions of the page captured on January 1, 2026 show the original language labeling the product as part of the criminal operation.
Palo Alto Networks acquired Koi Security in April 2026. The company confirmed it is aware of the lawsuit but declined to address specific allegations, saying only that it expects "this dispute will be resolved through the appropriate legal process."
Blocking cascades and the LLM echo chamber
The practical damage to MeetingTV has been severe. Security companies and service providers worldwide blocked the startup's domains after the Koi report, labeling them as command-and-control infrastructure. Verizon and Palo Alto Networks itself continue to block MeetingTV's services, according to Robertson.
The problem extends beyond network blocks. Robertson says large language models now repeat the false claims. "All the LLMs now say we're working with Chinese cyber criminals," he told The Register. "How will that ever get removed?" The AI-generated report has essentially created a self-reinforcing cycle: Koi's AI hallucinated the findings, published them as fact, and now other AI systems treat those published findings as authoritative.
Robertson emailed Palo Alto CEO Nikesh Arora directly after the acquisition closed, asking the company to retract the report, remove MeetingTV's domains from its own blacklists, and help remove blocks placed by other vendors. He says he has received no meaningful response.
What this means for AI in security operations
The case raises questions about accountability when AI systems produce false positives with real-world consequences. Threat intelligence platforms increasingly rely on automated analysis to process large volumes of data, but the MeetingTV lawsuit argues that publishing AI-generated accusations without human verification crosses a legal line.
Robertson framed the issue broadly: "We're on the doorstep of an era where AI will be used to make critical life-altering decisions on people's lives. Will these be made without human oversight? Will people have due process, see the accusations against them, present their own evidence, have a neutral arbiter? None of that happened in our case."
The lawsuit, filed in May 2026, seeks damages and injunctive relief. The outcome could set precedent for how security vendors handle AI-generated threat intelligence and what obligations they have to verify findings before publishing them. For developers working in security tooling or building products that process sensitive data, the case is a reminder that automated systems without human checks can destroy businesses overnight.