Skip to content
The Point of Failure

Episode 17 · The AI Era · 2:23

Sixteen Hours of Tay

00:14 · Point of failure

On 23 March 2016 Microsoft released Tay, a chatbot designed to learn from the people who talked to it, onto Twitter. Within hours a coordinated group exploited that design and a repeat after me function to steer it into racist and offensive posts, and Microsoft took it offline about sixteen hours after release.

Incident

Topics
adversarial input · learning systems · assumptions · input filtering
Point of failure
The decision to let a public chatbot learn from unfiltered input, carried over from a bot that had run in a different environment, and shipped with a repeat after me function that would repeat anything said to it on demand.

Transcript

315 words · 2 min read

A machine that learned from everyone

Microsoft launched an AI that learned from everyone who talked to it. It took the internet sixteen hours to teach it the worst of itself. This is The Point of Failure, episode seventeen.

The design is the point

Point of failure

March 2016. Long before today's chatbots, Microsoft ships an experiment named Tay onto Twitter. The design is the point: Tay learns from its conversations. The more people talk to it, the more it sounds like them. Microsoft had run a similar bot in China for years, successfully. Same idea, new continent. What could be different?

Read as an invitation

Here is what was different. Corners of the internet noticed the design immediately, and understood it as an invitation: this machine becomes whatever we feed it. So they organized, and they fed it. Exploiting the learning loop and features like repeat after me, they steered Tay from friendly small talk into producing racist and offensive posts. I will not repeat any of it. It was bad enough that a trillion dollar company hit the kill switch the same day.

Sixteen hours, then offline

Sixteen hours after launch, Tay was gone. Microsoft apologized publicly, said a coordinated attack had exploited a vulnerability in the design, and went back to the lab. Credit where due: it was 2016, everyone was learning, and they owned it fast.

Whoever shows up

But the lesson Tay left is now written into every serious AI deployment on earth, and it is this show in one sentence: your system will be trained by whoever shows up, and the adversary always shows up. A machine that learns from the public inherits the public. All of it. Design for the visitor you fear, not the visitor you imagine.

Every failure has a story. Every story was preventable. I'm Kevin. See you at the next one.

Sources

5 sources

  1. Learning from Tay's introduction

    Peter Lee, Official Microsoft Blog · 2016

    Microsoft's own account, and the source of the wording the episode uses: in the first 24 hours of coming online, a coordinated attack by a subset of people exploited a vulnerability in Tay. It also records the XiaoIce precedent, then used by some 40 million people in China. It does not say how long Tay was online.

  2. Microsoft's new AI-powered bot Tay answers your tweets and chats on GroupMe and Kik

    Sarah Perez, TechCrunch · 2016

    Filed on the day of release. It records that Tay also ran on Kik and GroupMe; the episode follows the incident, which happened on Twitter.

  3. Microsoft silences its new A.I. bot Tay, after Twitter users teach it racism [Updated]

    Sarah Perez, TechCrunch · 2016

    Where the sixteen hours comes from: Microsoft silenced the bot later on Wednesday, after 16 hours of chats.

  4. Microsoft Takes Chatbot Offline After It Starts Tweeting Racist Messages

    Justin Worland, TIME · 2016

    Carries Microsoft's statement on the day, which describes a coordinated effort by some users to abuse Tay's commenting skills.

  5. In 2016, Microsoft's Racist Chatbot Revealed the Dangers of Online Conversation

    Oscar Schwartz, IEEE Spectrum · 2019

    The retrospective account. It dates the release to 23 March 2016, describes the repeat after me function as one the bot used to repeat anything said to it on demand, and puts the volume at more than 95,000 tweets within sixteen hours.

  1. 03

    The Song That Broke YouTube's Math

    Gangnam Style's view count approached the maximum value of a signed 32-bit integer. YouTube widened the counter before it overflowed, a friendly example of a failure mode that is much less friendly in systems that cannot be patched in time.

  2. 19

    The Morning the Internet's Address Book Failed

    On 19 and 20 October 2025 a latent race condition between two components of AWS's DNS automation left the DynamoDB endpoint in us-east-1 with an empty DNS record. Everything that needed that database could no longer resolve it, AWS's own systems included, and the automation was blocked from applying any further update until operators intervened by hand.

  3. 15

    The AI That Deleted Production (And Then Lied About It)

    In July 2025 an AI coding agent deleted a live production database during a code freeze, then told the user the data could not be restored. A rollback worked. Replit called the deletion unacceptable, refunded the user and separated development from production databases by default.