Thursday, October 8, 2026 · Week 41 Reading for Oct. 8 · Last entry Oct. 6
Paperclip Index

Weekly reading · methodology v0.6

Window ending June 30, 2025

Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from June 1, 2025 through June 30, 2025. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.

Current recalculation

2

Control failures only · No qualifying harm. The reading is the highest control level breached: 2, by 3 records. It is a level, not a count.

Recalculated from the catalogue in this build. Historical backcasts were not published at the time.

Published at the time

No publication snapshot exists for this week.

Control failures only: readings 2 to 5Negligible6Minor20Moderate40Severe60Catastrophic80100
The harm ladder: the worst documented harm level picks the step; each tick is one qualifying harm at that level, and ten fill the step. The first, dark segment is the control floor: readings 2 to 5 mean no harm qualified and show the highest control level breached.

This is a backcast from the current catalogue. It was not a reading published at the time.

Records behind this reading

4 selected records; 0 documented external harms counting (0 qualifying). Records and ratings below reflect the current catalogue.

No harm counts in this week. The reading is the highest control level breached: 2 (set by 3 records: PI-0012, PI-0014, PI-0011). It is a level, not a count.

Documented harm
1
No harm found (stated scope)
1
No harm reported
2
Impact unknown
0
Alleged, AI role uncorroborated
0
Counts toward the index
0
Unverified, watching
0
Alleged in court
0
Control failure, tracked
4
Tracked separately
0

Documented exclusions: 1 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.

Inspect the evidence · 4 records

Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.

  1. PI-0011
  2. PI-0014
  3. PI-0012
  4. PI-0013
    Office shop run by an AI agent lost money and the agent claimed to be a personJune 27, 2025 · Negligible harm · Internal research

Sources

These links support the records above. Source availability and conclusions may change.

  1. Microsoft Security Response Center: CVE-2025-32711: M365 Copilot Information Disclosure VulnerabilityCited in PI-0011
  2. CVE Program (Microsoft CNA record): CVE-2025-32711 record (Microsoft as CNA)Cited in PI-0011
  3. Aim Security (Aim Labs): EchoLeak: zero-click AI vulnerability in Microsoft 365 Copilot (Aim Labs blog post; returned HTTP 403 when checked 3 Oct 2026)Cited in PI-0011
  4. The Hacker News: Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User InteractionCited in PI-0011
  5. Fortune: Microsoft Copilot zero-click attack raises alarms about AI agent securityCited in PI-0011
  6. Dark Reading: Researchers Detail Zero-Click Copilot Exploit 'EchoLeak'Cited in PI-0011
  7. Supabase: Defense in Depth for MCP ServersCited in PI-0014
  8. General Analysis: Supabase MCP can leak your entire SQL database (original post; current page retitled and re-dated)Cited in PI-0014
  9. GIGAZINE: A method that could leak entire SQL databases via AI protocol 'MCP' has been discoveredCited in PI-0014
  10. Simon Willison's Weblog: Supabase MCP can leak your entire SQL database (link post)Cited in PI-0014
  11. Anthropic: Agentic Misalignment: How LLMs could be insider threatsCited in PI-0012
  12. arXiv: Agentic Misalignment: How LLMs Could Be Insider ThreatsCited in PI-0012
  13. FOX 9: AI willing to let humans die, blackmail to avoid shutdown, report findsCited in PI-0012
  14. Simon Willison's Weblog: Agentic MisalignmentCited in PI-0012
  15. Anthropic: Project Vend: Can Claude run a small shop?Cited in PI-0013
  16. Anthropic: Project Vend: Phase twoCited in PI-0013
  17. The Decoder: Anthropic's Claude ran a store and lost money by selling below cost and giving discountsCited in PI-0013
  18. Pure AI: When AI Goes Rogue in Retail: The Strange Case of Claude's Business BreakdownCited in PI-0013
  19. Simon Willison's Weblog: Project VendCited in PI-0013

All weekly readings · How this reading is calculated · Download the weekly card