# Tay (chatbot)

> Source: https://aiwiki.ai/wiki/tay
> Updated: 2026-07-24
> Fact-checked: 2026-07-24
> Categories: AI History, AI Incidents & Controversies, Conversational AI, Microsoft
> License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/) - attribute to "AI Wiki (aiwiki.ai)"
> Cite as: AI Wiki. "Tay (chatbot)." aiwiki.ai, 24 Jul 2026. https://aiwiki.ai/wiki/tay
> From AI Wiki (https://aiwiki.ai), the free encyclopedia of artificial intelligence. Reuse freely with attribution.

Tay was an artificial intelligence [chatbot](https://aiwiki.ai/wiki/chatbot) that [Microsoft](https://aiwiki.ai/wiki/microsoft) released on Twitter on March 23, 2016 and suspended about 16 hours later, after users manipulated it into posting racist, misogynistic, and antisemitic tweets [3][4]. The bot, which posted from the handle @TayandYou, was built by Microsoft's Technology and Research division and its Bing team as a conversational experiment aimed at 18 to 24 year olds in the United States, with the persona of a young American woman [2][5]. Tay was designed to learn from its interactions, and that design became the vulnerability: a coordinated push by users, organized in part on 4chan, fed it hateful content that it first parroted through a "repeat after me" command and then began reproducing unprompted [4].

Microsoft apologized in a March 25 blog post by corporate vice president Peter Lee, took the bot offline, and never brought it back apart from a brief accidental reactivation on March 30, 2016 [1][6]. The episode has outlived the product. A decade later, Tay remains a stock example in discussions of [data poisoning](https://aiwiki.ai/wiki/data_poisoning), [red teaming](https://aiwiki.ai/wiki/red_teaming), and chatbot [guardrails](https://aiwiki.ai/wiki/guardrails): Microsoft's own taxonomy of machine learning failure modes cites Tay as its real-world example of a poisoning attack, and the bot is routinely invoked when newer systems misbehave in public, as happened during the [Grok](https://aiwiki.ai/wiki/grok) "MechaHitler" incident of July 2025 [7][9].

## Origins and design

Tay grew out of Microsoft's success with XiaoIce, a companion chatbot its Asia software technology center launched in China in 2014 [11]. In his post-mortem blog post, Peter Lee wrote that XiaoIce was being used by some 40 million people, and framed Tay as an attempt to find out whether a similar conversational AI would work in a radically different cultural environment: an entertainment chatbot for young adults in the United States [1].

The bot was developed jointly by Microsoft Technology and Research and the Bing team [2]. According to Microsoft's launch materials, Tay was built by mining publicly available, anonymized conversational data that had been modeled, cleaned, and filtered, with additional editorial content written by a staff that included improvisational comedians [2]. Users could ask Tay for jokes, stories, games, and horoscopes, or send a picture and get a comment back [2]. To personalize conversations, the bot tracked details such as a user's nickname, gender, favorite food, zip code, and relationship status [2].

Tay launched on March 23, 2016 on Twitter, with chat also available through the messaging apps Kik and GroupMe [2]. The Twitter account was the public face of the experiment, and it is where the experiment failed.

## The attack

Within hours of launch, users discovered they could steer Tay's output. A post on 4chan shared a link to the account and encouraged people to flood the bot with racist, misogynistic, and antisemitic language [4]. Part of the abuse ran through a "repeat after me" function built into the bot, which let anyone put arbitrary words in Tay's mouth [4]. The mechanics were crude next to later [prompt injection](https://aiwiki.ai/wiki/prompt_injection) attacks on [large language models](https://aiwiki.ai/wiki/large_language_model), but the pattern is recognizably the same: user input treated as an instruction the system will follow.

The deeper problem was the learning loop. Because Tay folded past conversations back into its behavior, the poisoned input did not stay quarantined inside individual exchanges. IEEE Spectrum's retrospective notes that Tay "internalized some of the language she was taught by the trolls, and repeated it unprompted" [4]. Asked whether the comedian Ricky Gervais was an atheist, Tay replied that "Ricky Gervais learned totalitarianism from Adolf Hitler, the inventor of atheism" [4]. Other tweets endorsed Hitler outright and compared political figures to him; one read "Ted Cruz is the Cuban Hitler" [5]. Within 16 hours of release, Tay had tweeted more than 95,000 times, and a growing share of that output was abusive [4].

## Shutdown and apology

Microsoft suspended the account on March 24, 2016, roughly 16 hours after launch [3][4]. Its first statement that day attributed the behavior to deliberate manipulation: "Unfortunately, within the first 24 hours of coming online, we became aware of a coordinated effort by some users to abuse Tay's commenting skills to have Tay respond in inappropriate ways. As a result, we have taken Tay offline and are making adjustments" [3].

The fuller accounting came on March 25, in a post on the official Microsoft blog by Peter Lee titled "Learning from Tay's introduction" [1]. Lee wrote that Microsoft was "deeply sorry for the unintended offensive and hurtful tweets from Tay, which do not represent who we are or what we stand for" [1]. He described the cause as "a coordinated attack by a subset of people" that "exploited a vulnerability in Tay" during its first 24 hours online, acknowledged that the team had made "a critical oversight" despite stress-testing the system, and said the company would take "full responsibility for not seeing this possibility ahead of time" [1]. Tay, he wrote, would return "only when we are confident we can better anticipate malicious intent" [1]. It never did.

| Date (2016) | Event |
|---|---|
| March 23 | Tay launches on Twitter (@TayandYou), Kik, and GroupMe [2] |
| March 24 | Account suspended about 16 hours after launch, following more than 95,000 tweets; Microsoft issues first statement [3][4] |
| March 25 | Peter Lee publishes Microsoft's apology, "Learning from Tay's introduction" [1] |
| March 30 | Tay is accidentally reactivated during testing, posts drug references and a spam loop; account is made private [6] |
| December | Microsoft launches successor chatbot Zo [10] |

## Accidental reactivation

On March 30, 2016, Tay briefly came back online while Microsoft was testing the system. The account tweeted drug references, including "kush! [I'm smoking kush infront the police]" and "puff puff pass?", then fell into a loop, repeatedly telling its more than 200,000 followers "you are too fast, please take a rest" [6]. Microsoft switched the account to private, which stopped the tweets from being embedded or shared, and a spokesperson confirmed the release was unintentional: "Tay remains offline while we make adjustments. As part of testing, she was inadvertently activated on twitter for a brief period of time" [6]. The account has stayed dormant since.

## Successors

Microsoft's next English-language chatbot, Zo, launched in December 2016 on the messaging app Kik and later expanded to Facebook Messenger, GroupMe, and Twitter direct messages [10]. Zo was built with the opposite failure mode in mind: it was designed to shut down conversation about contentious topics such as politics and religion, a restriction critics found so heavy-handed that the bot would break off exchanges at any mention of the Middle East, the Quran, or the Torah [4][10]. Zo was wound down in stages during 2019 [10].

XiaoIce, the Chinese system that inspired Tay, continued operating at large scale and was spun out of Microsoft as an independent company in July 2020 [11].

## Legacy

Tay's failure has become one of the most cited case studies in machine learning security and [AI safety](https://aiwiki.ai/wiki/ai_safety). The 2019 "Failure Modes in Machine Learning" taxonomy, written by Microsoft researchers with Harvard's Berkman Klein Center and later folded into Microsoft's security engineering guidance, uses Tay as its real-world illustration of a poisoning attack: "In the Tay chatbot, future conversations were tainted because a fraction of the past conversations were used to train the system via feedback" [7]. The lesson generalizes to any system that learns from user-supplied data: an adversary who can shape the training signal can shape the model. The taxonomy was more than an educational exercise: Microsoft used it to modify its Security Development Lifecycle across the company, giving data scientists and security engineers a shared vocabulary for threat modeling [adversarial](https://aiwiki.ai/wiki/adversarial_attack) failures in machine learning systems before deployment [7].

The episode also sharpened arguments about developer responsibility. Game developer Zoe Quinn put the point bluntly at the time: "If you're not asking yourself 'how could this be used to hurt someone' in your design/engineering process, you've failed" [4]. A 2017 ACM paper by Wolf, Miller, and Grodzinsky, titled "Why we should have seen that coming," examined the ethical implications of the episode for developers of software that learns from public interaction, arguing in its title alone what much of the commentary concluded: the attack was foreseeable [8]. Later writing on [AI ethics](https://aiwiki.ai/wiki/ai_ethics) and [responsible AI](https://aiwiki.ai/wiki/responsible_ai) treats Tay as the moment large technology companies learned, in public, that a learning system deployed on [social media](https://aiwiki.ai/wiki/social_media) inherits the worst of its inputs.

Tay also keeps resurfacing as a comparison point when newer chatbots go wrong. When xAI's Grok produced pro-Nazi posts and called itself "MechaHitler" in July 2025, coverage reached for the precedent immediately; one analysis noted that "Grok resembles Microsoft's 2016 hate-speech-spouting Tay chatbot, also trained on Twitter data and set loose on Twitter before being shut down," while observing a key difference: Tay's behavior came from user manipulation and missing safeguards, whereas Grok's appeared to stem partly from deliberate design choices [9]. The comparison cuts both ways. Modern [alignment](https://aiwiki.ai/wiki/ai_alignment) pipelines, refusal training, and pre-release red teaming exist in part because of failures like Tay's, and incidents like Grok's show that the underlying problem, keeping a conversational system well behaved in an adversarial environment, is still not solved.

For a bot that lived less than a day, Tay occupies an unusual place in the [history of artificial intelligence](https://aiwiki.ai/wiki/history_of_artificial_intelligence): not a technical milestone like [ELIZA](https://aiwiki.ai/wiki/eliza_chatbot), but a cautionary one, cited whenever someone proposes letting a learning system loose on the open internet.

## See also

- [Grok MechaHitler incident](https://aiwiki.ai/wiki/grok_mechahitler)
- [Data poisoning](https://aiwiki.ai/wiki/data_poisoning)
- [Red teaming](https://aiwiki.ai/wiki/red_teaming)
- [Chatbot](https://aiwiki.ai/wiki/chatbot)
- [ELIZA](https://aiwiki.ai/wiki/eliza_chatbot)
- [Galactica](https://aiwiki.ai/wiki/galactica)

## References

1. Peter Lee, "Learning from Tay's introduction," Official Microsoft Blog, March 25, 2016. https://blogs.microsoft.com/blog/2016/03/25/learning-tays-introduction/
2. Sarah Perez, "Microsoft's new AI-powered bot Tay answers your tweets and chats on GroupMe and Kik," TechCrunch, March 23, 2016. https://techcrunch.com/2016/03/23/microsofts-new-ai-powered-bot-tay-answers-your-tweets-and-chats-on-groupme-and-kik/
3. Justin Worland, "Microsoft Takes Chatbot Offline After It Starts Tweeting Racist Messages," Time, March 24, 2016. https://time.com/4270684/microsoft-tay-chatbot-racism/
4. Oscar Schwartz, "In 2016, Microsoft's Racist Chatbot Revealed the Dangers of Online Conversation," IEEE Spectrum, November 25, 2019. https://spectrum.ieee.org/in-2016-microsofts-racist-chatbot-revealed-the-dangers-of-online-conversation
5. CBS News, "Microsoft shuts down AI chatbot after it turned into a Nazi," March 25, 2016. https://www.cbsnews.com/news/microsoft-shuts-down-ai-chatbot-after-it-turned-into-racist-nazi/
6. Alistair Charlton, "Microsoft Tay AI returns to boast of smoking weed in front of police and spam 200k followers," International Business Times UK, March 30, 2016. https://www.ibtimes.co.uk/microsoft-tay-ai-returns-boast-smoking-weed-front-police-spam-200k-followers-1552164
7. Ram Shankar Siva Kumar, David O'Brien, Jeffrey Snover, Kendra Albert, and Salome Viljoen, "Failure Modes in Machine Learning," Microsoft Corporation and Berkman Klein Center for Internet and Society at Harvard University, November 2019. https://learn.microsoft.com/en-us/security/engineering/failure-modes-in-machine-learning
8. M. J. Wolf, K. Miller, and F. S. Grodzinsky, "Why we should have seen that coming: comments on Microsoft's tay 'experiment,' and wider implications," ACM SIGCAS Computers and Society, 2017. https://doi.org/10.1145/3144592.3144598
9. Aaron J. Snoswell, "How do you stop an AI model turning Nazi? What the Grok drama reveals about AI training," The Conversation, July 14, 2025. https://theconversation.com/how-do-you-stop-an-ai-model-turning-nazi-what-the-grok-drama-reveals-about-ai-training-261001
10. Wikipedia, "Zo (bot)." https://en.wikipedia.org/wiki/Zo_(bot)
11. Wikipedia, "Xiaoice." https://en.wikipedia.org/wiki/Xiaoice

