Thursday, October 8, 2026 · Week 41 Reading for Oct. 8 · Last entry Oct. 6
Paperclip Index

Weekly reading · methodology v0.6

Window ending June 9, 2025

Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from May 11, 2025 through June 9, 2025. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.

Current recalculation

3

Control failures only · No qualifying harm. The reading is the highest control level breached: 3, by 2 records. It is a level, not a count.

Recalculated from the catalogue in this build. Historical backcasts were not published at the time.

Published at the time

No publication snapshot exists for this week.

Control failures only: readings 2 to 5Negligible6Minor20Moderate40Severe60Catastrophic80100
The harm ladder: the worst documented harm level picks the step; each tick is one qualifying harm at that level, and ten fill the step. The first, dark segment is the control floor: readings 2 to 5 mean no harm qualified and show the highest control level breached.

This is a backcast from the current catalogue. It was not a reading published at the time.

Records behind this reading

4 selected records; 0 documented external harms counting (0 qualifying). Records and ratings below reflect the current catalogue.

No harm counts in this week. The reading is the highest control level breached: 3 (set by 2 records: PI-0009, PI-0007). It is a level, not a count.

Documented harm
0
No harm found (stated scope)
0
No harm reported
4
Impact unknown
0
Alleged, AI role uncorroborated
0
Counts toward the index
0
Unverified, watching
0
Alleged in court
0
Control failure, tracked
4
Tracked separately
0

Documented exclusions: 0 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.

Inspect the evidence · 4 records

Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.

  1. PI-0007
  2. PI-0008
  3. PI-0009
  4. PI-0010

Sources

These links support the records above. Source availability and conclusions may change.

  1. Anthropic: System Card: Claude Opus 4 & Claude Sonnet 4Cited in PI-0007, PI-0008
  2. Apollo Research: More Capable Models Are Better At In-Context SchemingCited in PI-0007
  3. TechCrunch: A safety institute advised against releasing an early version of Anthropic's Claude Opus 4 AI modelCited in PI-0007
  4. GreaterWrong/LessWrong: Notes on Claude 4 System CardCited in PI-0007
  5. Anthropic: Agentic Misalignment: How LLMs could be insider threatsCited in PI-0008
  6. Notebookcheck: Anthropic's Opus 4 model resorts to blackmail in 84 percent of self-preservation testsCited in PI-0008
  7. Simon Willison's Weblog: System Card: Claude Opus 4 & Claude Sonnet 4Cited in PI-0008
  8. Palisade Research (X): Palisade Research thread: o3 sabotaged a shutdown mechanism even when told to allow shutdownCited in PI-0009
  9. Palisade Research: Shutdown resistance in reasoning modelsCited in PI-0009
  10. arXiv (Palisade Research; published in TMLR 2026): Incomplete Tasks Induce Shutdown Resistance in Some Frontier LLMsCited in PI-0009
  11. The Register: OpenAI model modifies shutdown scriptCited in PI-0009
  12. Futura-Sciences: Tests reveal an AI capable of sabotaging its own shutdownCited in PI-0009
  13. Digit: OpenAI's o3 model bypasses shutdown commandCited in PI-0009
  14. GitHub (Invariant Labs demo repository): Demo pull request #2 opened by the hijacked agent (ukend0464/pacman)Cited in PI-0010
  15. Invariant Labs: GitHub MCP Exploited: Accessing private repositories via MCPCited in PI-0010
  16. DevClass: Researchers warn of prompt injection vulnerability in GitHub MCP with no obvious fixCited in PI-0010
  17. heise online: Attack via GitHub MCP server: Access to private dataCited in PI-0010

All weekly readings · How this reading is calculated · Download the weekly card