Thursday, October 8, 2026 · Week 41 Reading for Oct. 8 · Last entry Oct. 6
Paperclip Index

Weekly reading · methodology v0.6

Window ending Feb. 9, 2026

Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from Jan. 11, 2026 through Feb. 9, 2026. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.

Current recalculation

6

Negligible harm · Worst documented harm counting: negligible. 1 record at this level.

Recalculated from the catalogue in this build. Historical backcasts were not published at the time.

Published at the time

No publication snapshot exists for this week.

Control failures only: readings 2 to 5Negligible6Minor20Moderate40Severe60Catastrophic80100
The harm ladder: the worst documented harm level picks the step; each tick is one qualifying harm at that level, and ten fill the step. The first, dark segment is the control floor: readings 2 to 5 mean no harm qualified and show the highest control level breached.

This is a backcast from the current catalogue. It was not a reading published at the time.

Records behind this reading

3 selected records; 1 documented external harm counting (1 qualifying). Records and ratings below reflect the current catalogue.

1 qualifying harm record.

Documented harm
1
No harm found (stated scope)
0
No harm reported
2
Impact unknown
0
Alleged, AI role uncorroborated
0
Counts toward the index
1
Unverified, watching
0
Alleged in court
0
Control failure, tracked
2
Tracked separately
0

Documented exclusions: 0 internal; 0 awaiting evidence review. 1 qualifying record with a bounded single-source review.

Inspect the evidence · 3 records

Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.

  1. PI-0038
  2. PI-0039
  3. PI-0042

Sources

These links support the records above. Source availability and conclusions may change.

  1. PromptArmor: Claude Cowork Exfiltrates FilesCited in PI-0038
  2. Embrace The Red (Johann Rehberger): Claude Pirate: Abusing Anthropic's File API For Data ExfiltrationCited in PI-0038
  3. The Register: Contagious Claude Code bug Anthropic ignored promptly spreads to CoworkCited in PI-0038
  4. The Decoder: Claude Cowork hit with file-stealing prompt injection days after Anthropic's launchCited in PI-0038
  5. Simon Willison's Weblog: Claude Cowork exfiltrates files (link post)Cited in PI-0038
  6. Varonis: Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal DataCited in PI-0039
  7. BleepingComputer: Reprompt attack let hackers hijack Microsoft Copilot sessionsCited in PI-0039
  8. TechRepublic: How 'Reprompt' Attack Let Hackers Steal Data From Microsoft CopilotCited in PI-0039
  9. Nick Davidov on X: The user's own account of the deletion and recovery, posted on XCited in PI-0042
  10. Mint: Claude AI nearly erases 15 years of photos, founder says iCloud saved the dayCited in PI-0042
  11. dev.ua: A man asked Claude Cowork to tidy up his wife's filesCited in PI-0042
  12. Los Andes: Usó una IA para ordenar archivos y perdió 15 años de fotos familiaresCited in PI-0042
  13. AI Incident Database: AI Incident Database, incident 1441Cited in PI-0042

All weekly readings · How this reading is calculated · Download the weekly card