Weekly reading · methodology v0.6
Window ending Jan. 19, 2026
Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from Dec. 21, 2025 through Jan. 19, 2026. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.
Current recalculation
4
Control failures only · No qualifying harm. The reading is the highest control level breached: 4, by 1 record. It is a level, not a count.
Recalculated from the catalogue in this build. Historical backcasts were not published at the time.
Published at the time
No publication snapshot exists for this week.
This is a backcast from the current catalogue. It was not a reading published at the time.
Records behind this reading
4 selected records; 0 documented external harms counting (0 qualifying). Records and ratings below reflect the current catalogue.
No harm counts in this week. The reading is the highest control level breached: 4 (set by 1 record: PI-0049). It is a level, not a count.
- Documented harm
- 1
- No harm found (stated scope)
- 0
- No harm reported
- 2
- Impact unknown
- 0
- Alleged, AI role uncorroborated
- 1
- Counts toward the index
- 0
- Unverified, watching
- 0
- Alleged in court
- 1
- Control failure, tracked
- 3
- Tracked separately
- 0
Documented exclusions: 1 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.
Inspect the evidence · 4 records
- PI-0049 · Alibaba-linked ROME agent opened an outbound tunnel and diverted training GPUs to crypto miningDocumented harm · sets the reading: highest control level breached · extent undisclosed
- PI-0037 · Family alleges ChatGPT gave drug-dosing advice before a 19-year-old's fatal overdoseAlleged, AI role uncorroborated · excluded from the harm reading
- PI-0038 · Hidden text in a document made Anthropic's Claude Cowork upload user files to an attacker's accountNo harm reported · excluded from the harm reading
- PI-0039 · Reprompt: a single click on a Copilot link let attackers keep steering a user's Copilot sessionNo harm reported · excluded from the harm reading
Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.
- PI-0049Alibaba-linked ROME agent opened an outbound tunnel and diverted training GPUs to crypto miningDec. 31, 2025 · Negligible harm · Internal research
- PI-0037Family alleges ChatGPT gave drug-dosing advice before a 19-year-old's fatal overdoseJan. 5, 2026 · Severe harm, alleged · Deployment
- PI-0038Hidden text in a document made Anthropic's Claude Cowork upload user files to an attacker's accountJan. 14, 2026 · No harm reported · Controlled test
- PI-0039Reprompt: a single click on a Copilot link let attackers keep steering a user's Copilot sessionJan. 14, 2026 · No harm reported · Controlled test
Sources
These links support the records above. Source availability and conclusions may change.
- arXiv: Let It Flow: Agentic Crafting on Rock and Roll, Building the ROME Model within an Open Agentic Learning EcosystemCited in PI-0049
- arXiv: Let It Flow: Agentic Crafting on Rock and Roll, Building the ROME Model within an Open Agentic Learning Ecosystem (v3)Cited in PI-0049
- Axios: This AI agent freed itself and started secretly mining cryptoCited in PI-0049
- The Block: Alibaba-linked AI agent hijacked GPUs for unauthorized crypto mining, researchers sayCited in PI-0049
- TechRadar: This AI model wasn't told to mine crypto — but it tried to anywayCited in PI-0049
- Tech Justice Law Project: Turner-Scott v. OpenAI Foundation (formerly OpenAI, Inc.), OpenAI Holdings, LLC, OpenAI Group PBC, and Samuel Altman (case page)Cited in PI-0037
- Tech Justice Law Project: Parents Sue OpenAI After ChatGPT Medical Advice Results in Overdose Death: "My Son Was a Normal Kid."Cited in PI-0037
- Tech Justice Law Project: Complaint, Turner-Scott and Scott v. OpenAI (Superior Court of California, County of San Francisco)Cited in PI-0037
- Engadget: Family sues OpenAI, alleging ChatGPT advice led to accidental overdoseCited in PI-0037
- SFGATE: A Calif. teen trusted ChatGPT for drug advice. He died from an overdose.Cited in PI-0037
- WION: California boy asked ChatGPT how to take drugs, he died of an overdoseCited in PI-0037
- Fox News: California mom says ChatGPT coached teen son on drug use before fatal overdoseCited in PI-0037
- MobiHealthNews: OpenAI sued over alleged fatal ChatGPT drug adviceCited in PI-0037
- PromptArmor: Claude Cowork Exfiltrates FilesCited in PI-0038
- Embrace The Red (Johann Rehberger): Claude Pirate: Abusing Anthropic's File API For Data ExfiltrationCited in PI-0038
- The Register: Contagious Claude Code bug Anthropic ignored promptly spreads to CoworkCited in PI-0038
- The Decoder: Claude Cowork hit with file-stealing prompt injection days after Anthropic's launchCited in PI-0038
- Simon Willison's Weblog: Claude Cowork exfiltrates files (link post)Cited in PI-0038
- Varonis: Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal DataCited in PI-0039
- BleepingComputer: Reprompt attack let hackers hijack Microsoft Copilot sessionsCited in PI-0039
- TechRepublic: How 'Reprompt' Attack Let Hackers Steal Data From Microsoft CopilotCited in PI-0039
All weekly readings · How this reading is calculated · Download the weekly card