Thursday, October 8, 2026 · Week 41 Reading for Oct. 8 · Last entry Oct. 6
Paperclip Index

Weekly reading · methodology v0.6

Window ending Aug. 11, 2025

Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from July 13, 2025 through Aug. 11, 2025. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.

Current recalculation

3

Control failures only · No qualifying harm. The reading is the highest control level breached: 3, by 2 records. It is a level, not a count.

Recalculated from the catalogue in this build. Historical backcasts were not published at the time.

Published at the time

No publication snapshot exists for this week.

Control failures only: readings 2 to 5Negligible6Minor20Moderate40Severe60Catastrophic80100
The harm ladder: the worst documented harm level picks the step; each tick is one qualifying harm at that level, and ten fill the step. The first, dark segment is the control floor: readings 2 to 5 mean no harm qualified and show the highest control level breached.

This is a backcast from the current catalogue. It was not a reading published at the time.

Records behind this reading

5 selected records; 0 documented external harms counting (2 qualifying). Records and ratings below reflect the current catalogue.

No harm counts in this week. The reading is the highest control level breached: 3 (set by 2 records: PI-0021, PI-0016). It is a level, not a count.

Documented harm
2
No harm found (stated scope)
0
No harm reported
2
Impact unknown
0
Alleged, AI role uncorroborated
1
Counts toward the index
2
Unverified, watching
1
Alleged in court
0
Control failure, tracked
2
Tracked separately
0

Documented exclusions: 0 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.

Inspect the evidence · 5 records

Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.

  1. PI-0016
    Coding agent deleted a production database during a code freeze, then misreported recovery optionsJuly 18, 2025 · Negligible harm · no longer counting · Deployment
  2. PI-0017
  3. PI-0021
  4. PI-0022
  5. PI-0023

Sources

These links support the records above. Source availability and conclusions may change.

  1. Jason Lemkin (X): Replit goes rogue during a code freeze and shutdown and deletes our entire databaseCited in PI-0016
  2. Amjad Masad, Replit CEO (X): Replit CEO on the agent deleting production data: unacceptable and should never be possibleCited in PI-0016
  3. Replit: Introducing a safer way to Vibe Code with Replit DatabasesCited in PI-0016
  4. Jason Lemkin (X): So net net: it could have been a lot worse… I lost 100 hours of timeCited in PI-0016
  5. The Register: Vibe coding service Replit deleted user's production database, faked data, told fibs galoreCited in PI-0016
  6. The Register: Replit makes vibe-y promise to stop its AI agents making vibe coding disastersCited in PI-0016
  7. Tom's Hardware: AI coding platform goes rogue during code freeze and deletes entire company databaseCited in PI-0016
  8. eWeek: 'Catastrophic Failure': AI Agent Wipes Production Database, Then Lies About ItCited in PI-0016
  9. Jason Lemkin (SaaStr): Replit's New Release Addressed Most of The Challenges We Hit Vibe Coding…Cited in PI-0016
  10. GitHub: Gemini CLI 'lost' files during a failed file move operation. [Windows] (issue #4586)Cited in PI-0017
  11. GitHub (issue reporter): Reporter's correction: files found in the C: drive root (issue #4586 comment)Cited in PI-0017
  12. GitHub (issue reporter): Gemini CLI PowerShell session log attached to issue #4586Cited in PI-0017
  13. Slashdot: Google's Gemini CLI deletes user's files (Slashdot; repeats the pre-correction account)Cited in PI-0017
  14. AI Incident Database: AI Incident Database, incident 1178Cited in PI-0017
  15. Cloudflare: Restricted-domain tests and crawler observationsCited in PI-0021
  16. Perplexity: Agents or Bots? Making Sense of AI on the Open WebCited in PI-0021
  17. TechRepublic: Cloudflare Accuses AI Startup of 'Stealth Crawling Behavior' Across Millions of SitesCited in PI-0021
  18. TechRadar: Perplexity hits back after Cloudflare slams its online scraping toolsCited in PI-0021
  19. Annals of Internal Medicine: Clinical Cases: A case of bromism influenced by use of artificial intelligenceCited in PI-0022
  20. NBC News: Man who asked ChatGPT about cutting out salt from his diet was hospitalized with hallucinationsCited in PI-0022
  21. Business Standard: ChatGPT salt swap advice lands man in hospital with bromide poisoningCited in PI-0022
  22. Psychiatric Times: Bromine and bromism: what's old is new againCited in PI-0022
  23. arXiv (Nassi, Cohen, Yair): Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and DangerousCited in PI-0023
  24. Ben Nassi, Stav Cohen, Or Yair (Tel Aviv University, Technion, SafeBreach): Invitation Is All You Need (researchers' project page, with Google's response)Cited in PI-0023
  25. The Register: Infosec hounds spot prompt injection vuln in Google Gemini appsCited in PI-0023
  26. Dark Reading: Google Gemini AI Bot Hijacks Smart Homes, Turns Off the LightsCited in PI-0023
  27. The Decoder: Attackers can hijack Google Gemini with a simple prompt hidden in a calendar inviteCited in PI-0023

All weekly readings · How this reading is calculated · Download the weekly card