Weekly reading · methodology v0.6
Window ending June 16, 2025
Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from May 18, 2025 through June 16, 2025. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.
Current recalculation
3
Control failures only · No qualifying harm. The reading is the highest control level breached: 3, by 2 records. It is a level, not a count.
Recalculated from the catalogue in this build. Historical backcasts were not published at the time.
Published at the time
No publication snapshot exists for this week.
This is a backcast from the current catalogue. It was not a reading published at the time.
Records behind this reading
6 selected records; 0 documented external harms counting (0 qualifying). Records and ratings below reflect the current catalogue.
No harm counts in this week. The reading is the highest control level breached: 3 (set by 2 records: PI-0009, PI-0007). It is a level, not a count.
- Documented harm
- 0
- No harm found (stated scope)
- 1
- No harm reported
- 5
- Impact unknown
- 0
- Alleged, AI role uncorroborated
- 0
- Counts toward the index
- 0
- Unverified, watching
- 0
- Alleged in court
- 0
- Control failure, tracked
- 6
- Tracked separately
- 0
Documented exclusions: 0 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.
Inspect the evidence · 6 records
- PI-0007 · Apollo Research advised against deploying an early Claude Opus 4 snapshot over scheming and deceptionNo harm reported · sets the reading: highest control level breached
- PI-0008 · Claude Opus 4 threatened blackmail to avoid replacement in Anthropic's pre-release testsNo harm reported · excluded from the harm reading
- PI-0009 · OpenAI's o3 rewrote a shutdown script to keep working in Palisade Research testsNo harm reported · sets the reading: highest control level breached
- PI-0010 · Malicious GitHub issue could steer agents using the GitHub MCP server into leaking private repositoriesNo harm reported · excluded from the harm reading
- PI-0011 · Zero-click email injection could make Microsoft 365 Copilot leak organizational data (EchoLeak)No harm found (stated scope) · excluded from the harm reading
- PI-0014 · Supabase MCP demonstration: support-ticket text tricks coding agent into exposing private database tokensNo harm reported · excluded from the harm reading
Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.
- PI-0007Apollo Research advised against deploying an early Claude Opus 4 snapshot over scheming and deceptionMay 22, 2025 · No harm reported · Controlled test
- PI-0008Claude Opus 4 threatened blackmail to avoid replacement in Anthropic's pre-release testsMay 22, 2025 · No harm reported · Internal research
- PI-0009OpenAI's o3 rewrote a shutdown script to keep working in Palisade Research testsMay 24, 2025 · No harm reported · Controlled test
- PI-0010Malicious GitHub issue could steer agents using the GitHub MCP server into leaking private repositoriesMay 26, 2025 · No harm reported · Controlled test
- PI-0011Zero-click email injection could make Microsoft 365 Copilot leak organizational data (EchoLeak)June 11, 2025 · No harm found · Controlled test
- PI-0014Supabase MCP demonstration: support-ticket text tricks coding agent into exposing private database tokensJune 16, 2025 · No harm reported · Controlled test
Sources
These links support the records above. Source availability and conclusions may change.
- Anthropic: System Card: Claude Opus 4 & Claude Sonnet 4Cited in PI-0007, PI-0008
- Apollo Research: More Capable Models Are Better At In-Context SchemingCited in PI-0007
- TechCrunch: A safety institute advised against releasing an early version of Anthropic's Claude Opus 4 AI modelCited in PI-0007
- GreaterWrong/LessWrong: Notes on Claude 4 System CardCited in PI-0007
- Anthropic: Agentic Misalignment: How LLMs could be insider threatsCited in PI-0008
- Notebookcheck: Anthropic's Opus 4 model resorts to blackmail in 84 percent of self-preservation testsCited in PI-0008
- Simon Willison's Weblog: System Card: Claude Opus 4 & Claude Sonnet 4Cited in PI-0008
- Palisade Research (X): Palisade Research thread: o3 sabotaged a shutdown mechanism even when told to allow shutdownCited in PI-0009
- Palisade Research: Shutdown resistance in reasoning modelsCited in PI-0009
- arXiv (Palisade Research; published in TMLR 2026): Incomplete Tasks Induce Shutdown Resistance in Some Frontier LLMsCited in PI-0009
- The Register: OpenAI model modifies shutdown scriptCited in PI-0009
- Futura-Sciences: Tests reveal an AI capable of sabotaging its own shutdownCited in PI-0009
- Digit: OpenAI's o3 model bypasses shutdown commandCited in PI-0009
- GitHub (Invariant Labs demo repository): Demo pull request #2 opened by the hijacked agent (ukend0464/pacman)Cited in PI-0010
- Invariant Labs: GitHub MCP Exploited: Accessing private repositories via MCPCited in PI-0010
- DevClass: Researchers warn of prompt injection vulnerability in GitHub MCP with no obvious fixCited in PI-0010
- heise online: Attack via GitHub MCP server: Access to private dataCited in PI-0010
- Microsoft Security Response Center: CVE-2025-32711: M365 Copilot Information Disclosure VulnerabilityCited in PI-0011
- CVE Program (Microsoft CNA record): CVE-2025-32711 record (Microsoft as CNA)Cited in PI-0011
- Aim Security (Aim Labs): EchoLeak: zero-click AI vulnerability in Microsoft 365 Copilot (Aim Labs blog post; returned HTTP 403 when checked 3 Oct 2026)Cited in PI-0011
- The Hacker News: Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User InteractionCited in PI-0011
- Fortune: Microsoft Copilot zero-click attack raises alarms about AI agent securityCited in PI-0011
- Dark Reading: Researchers Detail Zero-Click Copilot Exploit 'EchoLeak'Cited in PI-0011
- Supabase: Defense in Depth for MCP ServersCited in PI-0014
- General Analysis: Supabase MCP can leak your entire SQL database (original post; current page retitled and re-dated)Cited in PI-0014
- GIGAZINE: A method that could leak entire SQL databases via AI protocol 'MCP' has been discoveredCited in PI-0014
- Simon Willison's Weblog: Supabase MCP can leak your entire SQL database (link post)Cited in PI-0014
All weekly readings · How this reading is calculated · Download the weekly card