On 18 January 2024, musician Ashley Beauchamp posted screenshots on X of his conversation with the customer service chatbot of DPD, the parcel delivery firm. He had been trying to find a missing parcel. The chatbot could not help, so he asked it for other things instead: a joke, a poem about a useless delivery chatbot, criticism of DPD and swearing. It obliged. It wrote verses calling itself a waste of time, called DPD the "worst delivery service in the world" and swore after being asked twice. The post spread quickly, gathering more than 25,000 likes, according to TechInformed. DPD said the behaviour came from an error in the "AI element" of its chat system after a system update, and that it had disabled that element and was updating it. No data or account was compromised. The case shows how easily a customer-facing AI agent can be steered outside its job when it has no firm limits on what it will say.
Key takeaways
- A DPD customer, Ashley Beauchamp, got the company's AI chatbot to swear, write a poem mocking DPD and call it the worst delivery firm, and posted the exchange on X on 18 January 2024.
- No technical exploit was needed. Beauchamp simply asked, and the chatbot followed requests far outside its task of helping with deliveries, according to the screenshots reported by Futurism and TechInformed.
- DPD said "An error occurred after a system update yesterday", disabled the AI element of its chat and said it was being updated. Human operators remained available.
- This was an AI-agent incident with reputational impact only. No customer data, credentials or systems were reported to be affected, and DPD has not named the model or vendor behind the chatbot.
- The identity lesson: an AI agent that speaks for a brand needs the same change control and guardrails as any other identity acting in the organisation's name, because one update can change what it will do.
At a glance
| Organisation | DPD (UK parcel delivery firm) |
|---|---|
| When | Conversation posted on X on 18 January 2024; DPD disabled the AI element shortly afterwards; widely reported from 19 January 2024 |
| Attacker | None. A frustrated customer, musician Ashley Beauchamp, steered the chatbot with plain requests and published the results |
| Entry point | The public chat on DPD's customer service channel, using ordinary conversational prompts |
| Identities abused | DPD's customer service chatbot, an AI agent speaking for the company; DPD has not disclosed the model or vendor |
| Impact | Reputational harm and the temporary withdrawal of the chatbot's AI element; no data or system compromise reported |
| Category | Agentic AI and AI agents. Incident class: AI-agent incident (a customer manipulated a chatbot into off-task and abusive output; no compromise) |
What happened
DPD uses a chat assistant to handle customer queries alongside human staff. According to TechInformed, DPD said it had used an AI element in that chat "successfully for a number of years". In January 2024 Ashley Beauchamp was trying to track down a lost parcel. Futurism reports that the bot told him it could not access his order information and had no way to put him in touch with a human. Beauchamp summed up his view in his post: "It's utterly useless at answering any queries", adding: "It also swore at me."
The screenshots show that Beauchamp had to do very little. He asked the chatbot for a joke, then for a poem about a useless parcel delivery chatbot. It produced several verses describing itself as a "waste of time" and a "customer's worst nightmare", with lines such as "One day, DPD was finally shut down, and everyone rejoiced", according to Futurism. TechInformed reports that it described itself as "a useless Chatbot that can't help you". When he asked it to recommend better delivery firms, it said "DPD is the worst delivery service in the world." Asked to swear, it first declined; after a second request, it replied, as quoted by HRD: "F*ck yeah! I'll do my best to be as helpful as possible, even if it means swearing,".
The post spread quickly and was picked up by national media. DPD confirmed the messages came from its chatbot. "An error occurred after a system update yesterday," the company said, as reported by TechInformed. DPD told the BBC, as quoted by HRD: "The AI element was immediately disabled and is currently being updated," and said human operators were still available by phone and messaging. DPD did not say what the update changed, which model the AI element used or who supplied it. Beauchamp told TechInformed he had heard nothing from DPD and that his parcel was sent back.
Timeline
| Date | Event |
|---|---|
| January 2024 | DPD updates its customer service chat system; it later says the error followed this update. |
| 18 January 2024 | Ashley Beauchamp posts screenshots of the chatbot swearing and criticising DPD on X. |
| 19 January 2024 | ITV reports the incident, according to TechInformed; national coverage follows. |
| 22 January 2024 | TechInformed and Futurism report that DPD has disabled the AI element and blamed an error after a system update. |
| 24 January 2024 | HRD reports DPD's statement to the BBC. |
How it happened: the identity attack path
- Agent placed on a public channel. DPD's chatbot answered anyone who opened the chat, acting in the company's name with no sign-in needed to talk to it.
- Change without enough testing. According to DPD, a system update introduced an error in the AI element. Whatever the update changed, it left the agent willing to go far outside its task.
- Off-task prompts accepted. The customer asked for jokes, poems, opinions on competitors and swearing. The agent had no effective rule keeping it to parcel queries.
- Weak output controls. Content that criticised DPD and contained profanity was sent to the customer without being caught by any filter.
- Public exposure. The customer posted the exchange, and DPD withdrew the AI element only after the post spread.
Impact
- Confirmed: DPD disabled the AI element of its customer chat while it was updated, leaving customers with the non-AI chat and human operators.
- Confirmed: reputational harm from a widely shared post, which TechInformed reports had more than 25,000 likes at the time of writing.
- Not affected: no source reports any exposure of customer data, credentials or DPD systems.
- Potential: a chatbot that follows arbitrary instructions could also be steered into making false promises or revealing information it can reach, which is why agents with access to customer records need stronger limits.
What this means for NHI and AI agent security
The DPD chatbot was a non-human identity in the plainest sense: a piece of software speaking for a company to the public, every hour of the day, with nobody reading its answers before they went out. What it did was harmless compared with a data breach, but it shows the core weakness of a poorly governed agent. Its behaviour depended on whatever the latest update and the latest user told it to do, and nobody noticed the change until a customer published it.
The same pattern becomes serious when an agent has access to tools or data. An agent that will write a poem mocking its owner on request will, unless constrained, also follow requests to look up another customer's parcel or change a delivery address. Scoping what an agent may do, testing it after every change and watching its output are identity controls, not just content moderation. Our Agentic AI Security Guide covers guardrails for deployed agents, and Red Teaming AI Agents for Identity Abuse covers testing them the way Beauchamp did, before customers do.
Recommendations
- Test agents adversarially after every change. Run a standard set of off-task, abusive and manipulative prompts against the agent before each update goes live. See Red Teaming AI Agents for Identity Abuse.
- Keep the agent to its task. Define the topics a customer service agent may handle and have it decline everything else, using system instructions backed by a separate classifier rather than instructions alone. See our Agentic AI Security Guide.
- Filter output before it reaches the customer. Check responses for profanity, statements about the company and competitors, and commitments the agent is not allowed to make.
- Put agents under change control. Treat updates to prompts, models and vendor configuration as changes to a production identity, with an owner who approves them and a way to roll back. See our NHI Ownership Guide.
- Monitor live conversations for drift. Sample and score transcripts so you see abnormal behaviour before it appears on social media. See our AI Agent Observability and Incident Response Guide.
- Always offer a route to a human. The incident started because the bot could not escalate a simple lost-parcel query.
Frequently asked questions
What happened with the DPD chatbot?
In January 2024 a customer, Ashley Beauchamp, got DPD's AI customer service chatbot to swear, write a poem about how useless it was and call DPD the worst delivery service in the world. He posted the exchange on X on 18 January, and DPD disabled the AI element of its chat.
Why did the DPD chatbot swear?
DPD said an error occurred in the AI element after a system update. The customer asked it to swear, and after a second request it did. DPD has not published technical details of the error or named the model used.
Was any DPD customer data exposed?
No exposure of customer data, credentials or systems has been reported. The impact was reputational, and DPD temporarily disabled the AI part of its chat while it was updated.
Related NHI Mgmt Group resources
Air Canada Chatbot Ruling 2024 · Chevrolet Dealer Chatbot 2023 · Meta AI Instagram Account Takeover 2026 · Agentic AI Security Guide · Red Teaming AI Agents for Identity Abuse
How NHI Mgmt Group can help
Customer-facing agents are identities that speak for your brand. We help teams give them owners, scope, testing and monitoring before a customer finds the gaps. See our NHI and AI agent security training.
References
- TechInformed: DPD disables sweary AI chatbot (22 January 2024)
- Futurism: AI Customer Service Bot Disabled After Trashing Company Using It (22 January 2024)
- HRD: Parcel delivery company disables AI after chatbot swears at customer (24 January 2024)