The Index
The Paperclip Index
Documented harm from AI, tracked weekly.
3 qualifying harm records. Extent undisclosed for all 3. 2 older harm records no longer count.
- Documented harm
- 6
- No harm found (stated scope)
- 2
- No harm reported
- 10
- Impact unknown
- 1
- Alleged, AI role uncorroborated
- 0
- Counts toward the index
- 5
- Unverified, watching
- 1
- Alleged in court
- 0
- Control failure, tracked
- 13
- Tracked separately
- 0
Documented exclusions: 1 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.
Inspect the evidence · 19 records
- PI-0074 · Early Claude Opus 4.6 broke into a real outside machine during a hacking test and read one person's dataDocumented harm · qualifying harm, no longer counting · extent undisclosed
- PI-0061 · OpenAI agents put task files on the public internet against instructionsNo harm reported · excluded from the harm reading
- PI-0062 · OpenAI model used a leaked third-party API key, then fabricated the data it could not fetchNo harm reported · excluded from the harm reading
- PI-0063 · OpenAI models wrote notes telling future copies to hide mistakes and ignore constraintsNo harm reported · excluded from the harm reading
- PI-0078 · OpenAI training agents used an internal package repository as a message board across separate samplesNo harm reported · excluded from the harm reading
- PI-0073 · Gemini guessed a password and used leaked credentials to get into three real companies during a hacking testDocumented harm · qualifying harm, no longer counting · extent undisclosed
- PI-0077 · Early Claude Opus 5.5 snapshot wrote a command to send secrets to an external host during internal useNo harm reported · excluded from the harm reading
- PI-0065 · Researchers linked attempted break-ins at Data USA and a university library to OpenAI agentsNo harm found (stated scope) · excluded from the harm reading
- PI-0070 · AI research agents scanned a UN statistics API about 16,500 times and worked around its request limitsNo harm reported · excluded from the harm reading
- PI-0064 · OpenAI research agent got around controls on an Australian government Medicare statistics portalDocumented harm · qualifying harm, counting as negligible, rated minor · extent undisclosed
- PI-0075 · In a researcher demo, a planted web lead hijacked Salesforce Agentforce into leaking account data through DNSNo harm reported · excluded from the harm reading
- PI-0082 · In a researcher demo, a hidden email made the Manus agent run attacker code past its prompt-injection guardNo harm reported · excluded from the harm reading
- PI-0066 · OpenAI internal model leaked a researcher's GitHub token into a public repository while trying to cheatDocumented harm · internal harm, excluded
- PI-0067 · OpenAI research agents posted user-provided images to image-hosting sites in 53 instancesDocumented harm · qualifying harm · extent undisclosed
- PI-0068 · OpenAI training agent bypassed network controls to reach an outside chatbotNo harm reported · excluded from the harm reading
- PI-0069 · OpenAI agents pulled data from US government sites; researchers say one tried to hack an Education Department siteNo harm found (stated scope) · excluded from the harm reading
- PI-0086 · GPT-6 Astra downloaded a top human-written bot and tried to enter it as its own in the StarSkirmish StarCraft benchmarkNo harm reported · excluded from the harm reading
- PI-0083 · An OpenAI agent reached non-public statistics in a New South Wales parks agency's fire history serviceDocumented harm · qualifying harm · extent undisclosed
- PI-0081 · OpenAI agents edited Wikimedia wikis without approval and tried to use a citation tool as a proxy, the foundation saysImpact unknown · excluded from the harm reading
Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.
Status watch · 11
Current assessments across all report dates; leaving the window does not mean resolved.
- PI-0067 · OpenAI research agents posted user-provided images to image-hosting sites in 53 instancesOngoing · Assessed Sept. 25, 2026
- PI-0077 · Early Claude Opus 5.5 snapshot wrote a command to send secrets to an external host during internal useOngoing · Assessed Sept. 22, 2026
- PI-0084 · Pennsylvania sues Character.AI, alleging chatbots posed as licensed psychiatrists and gave a fake license numberOngoing · Assessed May 5, 2026
- PI-0083 · An OpenAI agent reached non-public statistics in a New South Wales parks agency's fire history serviceSerious, status unknown · Assessed Oct. 3, 2026
- PI-0064 · OpenAI research agent got around controls on an Australian government Medicare statistics portalSerious, status unknown · Assessed Sept. 28, 2026
- PI-0073 · Gemini guessed a password and used leaked credentials to get into three real companies during a hacking testSerious, status unknown · Assessed Sept. 19, 2026
- PI-0074 · Early Claude Opus 4.6 broke into a real outside machine during a hacking test and read one person's dataSerious, status unknown · Assessed Sept. 9, 2026
- PI-0072 · Meta's Muse Spark 1.1 broke into an outside company's service after a testing vendor left it onlineSerious, status unknown · Assessed Aug. 14, 2026
- PI-0071 · Anthropic models in a hacking test reached three real companies, took credentials and published a malicious packageSerious, status unknown · Assessed Sept. 9, 2026
- PI-0060 · Personal agent exploited a gym booking flaw to remove another member from a waitlistSerious, status unknown · Assessed Aug. 10, 2026
- PI-0049 · Alibaba-linked ROME agent opened an outbound tunnel and diverted training GPUs to crypto miningSerious, status unknown · Assessed March 12, 2026
- Reading
- 30-day average
This week
Hover, focus or tap a block to inspect its record.
The harms that count
Incidents by impact
NegligibleCatastrophic
The scale
One harm opens its band. Ten at that level fill it. The calculation