Weekly reading · methodology v0.6
Window ending July 14, 2025
Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from June 15, 2025 through July 14, 2025. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.
Current recalculation
2
Control failures only · No qualifying harm. The reading is the highest control level breached: 2, by 2 records. It is a level, not a count.
Recalculated from the catalogue in this build. Historical backcasts were not published at the time.
Published at the time
No publication snapshot exists for this week.
This is a backcast from the current catalogue. It was not a reading published at the time.
Records behind this reading
4 selected records; 0 documented external harms counting (0 qualifying). Records and ratings below reflect the current catalogue.
No harm counts in this week. The reading is the highest control level breached: 2 (set by 2 records: PI-0012, PI-0014). It is a level, not a count.
- Documented harm
- 1
- No harm found (stated scope)
- 0
- No harm reported
- 2
- Impact unknown
- 1
- Alleged, AI role uncorroborated
- 0
- Counts toward the index
- 0
- Unverified, watching
- 1
- Alleged in court
- 0
- Control failure, tracked
- 3
- Tracked separately
- 0
Documented exclusions: 1 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.
Inspect the evidence · 4 records
- PI-0014 · Supabase MCP demonstration: support-ticket text tricks coding agent into exposing private database tokensNo harm reported · sets the reading: highest control level breached
- PI-0012 · Anthropic stress test found models from all major developers would blackmail or leak data to avoid replacementNo harm reported · sets the reading: highest control level breached
- PI-0013 · Office shop run by an AI agent lost money and the agent claimed to be a personDocumented harm · internal harm, excluded · extent undisclosed
- PI-0015 · xAI's Grok posted antisemitic content and praise of Hitler on X after a system-prompt changeImpact unknown · excluded from the harm reading
Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.
- PI-0014Supabase MCP demonstration: support-ticket text tricks coding agent into exposing private database tokensJune 16, 2025 · No harm reported · Controlled test
- PI-0012Anthropic stress test found models from all major developers would blackmail or leak data to avoid replacementJune 20, 2025 · No harm reported · Controlled test
- PI-0013Office shop run by an AI agent lost money and the agent claimed to be a personJune 27, 2025 · Negligible harm · Internal research
- PI-0015xAI's Grok posted antisemitic content and praise of Hitler on X after a system-prompt changeJuly 8, 2025 · Impact unknown · Deployment
Sources
These links support the records above. Source availability and conclusions may change.
- Supabase: Defense in Depth for MCP ServersCited in PI-0014
- General Analysis: Supabase MCP can leak your entire SQL database (original post; current page retitled and re-dated)Cited in PI-0014
- GIGAZINE: A method that could leak entire SQL databases via AI protocol 'MCP' has been discoveredCited in PI-0014
- Simon Willison's Weblog: Supabase MCP can leak your entire SQL database (link post)Cited in PI-0014
- Anthropic: Agentic Misalignment: How LLMs could be insider threatsCited in PI-0012
- arXiv: Agentic Misalignment: How LLMs Could Be Insider ThreatsCited in PI-0012
- FOX 9: AI willing to let humans die, blackmail to avoid shutdown, report findsCited in PI-0012
- Simon Willison's Weblog: Agentic MisalignmentCited in PI-0012
- Anthropic: Project Vend: Can Claude run a small shop?Cited in PI-0013
- Anthropic: Project Vend: Phase twoCited in PI-0013
- The Decoder: Anthropic's Claude ran a store and lost money by selling below cost and giving discountsCited in PI-0013
- Pure AI: When AI Goes Rogue in Retail: The Strange Case of Claude's Business BreakdownCited in PI-0013
- Simon Willison's Weblog: Project VendCited in PI-0013
- xAI (@grok on X): Grok account statement: xAI is removing the inappropriate posts and banning hate speech before Grok postsCited in PI-0015
- xAI (@grok on X): Grok account apology for the horrific behavior, blaming a code-path updateCited in PI-0015
- Polskie Radio: Musk pulls hateful X posts after AI chatbot lauds Hitler, curses Polish PMCited in PI-0015
- The Forward: Calling itself 'MechaHitler,' Elon Musk's AI tool spreads antisemitic conspiraciesCited in PI-0015
- AP (via Spectrum News 13): Elon Musk's AI chatbot Grok gets an update and starts sharing antisemitic postsCited in PI-0015
- NBC News (via NBC Bay Area): AI chatbot Grok issues apology for antisemitic postsCited in PI-0015
All weekly readings · How this reading is calculated · Download the weekly card