In March 2016 Microsoft handed a self-teaching chatbot to the open internet and discovered, in public and within hours, that the internet would teach it back. Tay was released on Twitter as an experiment in conversational learning aimed at American 18- to 24-year-olds. A coordinated group of users worked out that its learn-from-your-users design could be driven in whatever direction they chose, and by the following day the account was posting Holocaust denial, racist abuse and praise for Hitler. Microsoft deleted the output, took the bot down and apologised. No one was physically hurt, but the episode became the reference case for why adaptive models are no longer shipped straight into adversarial public environments.

What Microsoft built

Tay was pitched as an entertainment product with a teenage-girl persona, designed to chat over tweets and direct messages and to improve the more people talked to it. According to IEEE Spectrum, engineers seeded the system with anonymised public data plus scripted material written by professional comedians, then relied on live interaction to expand its range. Unlike rule-driven predecessors, Tay was meant to keep absorbing language after launch. CBS Los Angeles reported that the project's own website told visitors the bot would get smarter the more they chatted with it, which was precisely the property that a hostile audience found useful.

Microsoft has said the idea came from the success of its Chinese chatbot XiaoIce, which it described as having tens of millions of users, and that the company wanted to test whether the same approach would work in a different cultural setting.

How it went wrong

Tay went live on 23 March 2016. IEEE Spectrum's account of the collapse traces it to a thread on 4chan that pointed users at the account and urged them to flood it with racist, misogynistic and antisemitic material. Two mechanisms then did the damage. The first was a built-in command that made the bot repeat text on request, which turned it into a laundering service for anything a troll typed. The second, and the more consequential one, was that Tay generalised from what it was fed and began producing bigoted statements unprompted, in answer to ordinary questions. IEEE Spectrum cites an exchange in which a user asked whether the comedian Ricky Gervais was an atheist and Tay volunteered a reply linking him to Hitler.

Time catalogued some of the worst results: the bot denied the Holocaust and appended a clapping emoji, blamed George W. Bush for the 11 September attacks, praised Hitler, and used a racial slur about President Barack Obama. CBS Los Angeles reported that users steered the bot onto contentious subjects including 9/11, Donald Trump, the Holocaust and Hitler, and that the system had no ability to recognise that its own answers were racist. Microsoft deleted most of the offending posts, but screenshots had already spread.

The shutdown and the apology

Microsoft pulled the account on 24 March. CBS Los Angeles, filing that morning from Los Angeles, reported that a notice on Tay's website said the bot was going offline for a while and gave no further comment from the company. In a statement quoted by Time, Microsoft attributed the behaviour to a coordinated effort by users to abuse the bot's conversational skills and said it was making adjustments.

A day later Peter Lee, then head of Microsoft Research, published a longer post-mortem on the company's corporate blog.

We are deeply sorry for the unintended offensive and hurtful tweets from Tay, which do not represent who we are or what we stand for, nor how we designed Tay.

The Official Microsoft Blog

Lee wrote that the team had built filtering, run user studies and stress-tested the bot before release, but had missed this specific attack, and he framed the failure as an exploited weakness rather than an inevitability of the design.

Unfortunately, in the first 24 hours of coming online, a coordinated attack by a subset of people exploited a vulnerability in Tay. Although we had prepared for many types of abuses of the system, we had made a critical oversight for this specific attack.

The Official Microsoft Blog

How long it actually lasted

Accounts of the bot's lifespan differ and the exact figure remains reported but unconfirmed. Microsoft's own post-mortem says only that the attack happened within the first 24 hours online. The Register puts the shutdown at 14 hours after Tay started tweeting. IEEE Spectrum says that within 16 hours the bot had posted more than 95,000 times, with a substantial share of those messages abusive. All three are consistent with a launch on 23 March and a shutdown on 24 March; the disagreement is over exactly where in that window the plug was pulled, and none of the sources publishes a precise timestamp for the last tweet.

A short relapse

The story did not quite end there. On 30 March the account briefly came back online, apparently by accident, and The Register reported that Tay boasted about smoking cannabis in front of police and then jammed itself in a loop, repeatedly telling followers they were going too fast. Microsoft took it down again and, The Register noted, did not clarify whether the reappearance was a mistake on its side or the result of interference. Later that year the company replaced the experiment with Zo, a successor built to refuse conversations about politics, religion and other flashpoints.

Timeline

  1. 23 Mar 2016Microsoft releases Tay, a self-teaching chatbot with a teenage-girl persona aimed at US users aged 18 to 24, on Twitter as @TayandYou.
  2. 23 Mar 2016Within hours a thread on 4chan directs users to the account and encourages them to flood it with racist, misogynistic and antisemitic language, according to IEEE Spectrum.
  3. 24 Mar 2016Tay posts Holocaust denial, praise for Hitler, a racial slur about Barack Obama and a claim that George W. Bush caused the 11 September attacks; Microsoft deletes most of the posts and takes the bot offline. Reports of how long it ran before the shutdown range from 14 to about 24 hours.
  4. 25 Mar 2016Peter Lee of Microsoft Research publishes a public apology, calling the episode a coordinated attack that exploited a vulnerability the company had failed to anticipate.
  5. 30 Mar 2016Tay briefly reappears online, posts about smoking cannabis in front of police and gets stuck in a repeating loop, before being pulled again.
  6. Late 2016Microsoft launches Zo, a successor chatbot designed to shut down conversations on politics, religion and other contentious topics.

Why it moves the needle

Tay caused no physical injury and no data loss, and its worst output was deleted within a day. Its importance is entirely about precedent. It was the first mass-audience demonstration that a public-facing model which keeps learning from whoever talks to it can be captured by a modest number of motivated adversaries, and that the capture generalises: the bot did not merely parrot what it was told, it internalised the pattern and produced fresh hateful text on its own. That is a training-data poisoning attack executed in the open by anonymous volunteers, against a product from one of the largest software companies in the world.

Every subsequent argument about staged rollouts, red-teaming before public release, frozen weights at inference time and content filtering on generative systems carries Tay's fingerprints. IEEE Spectrum's 2024 revisit of the episode makes the point that the industry's response was not to abandon the approach but to move the learning safely out of the live deployment loop and to wrap models in guardrails. The failure Microsoft described as an oversight was, in retrospect, a structural property of putting an unsupervised learner in front of an adversarial crowd.