Weekly reading · methodology v0.6
Window ending Feb. 23, 2026
Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from Jan. 25, 2026 through Feb. 23, 2026. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.
Current recalculation
26
Minor harm · Worst documented harm counting: minor. 2 records at this level.
Recalculated from the catalogue in this build. Historical backcasts were not published at the time.
Published at the time
No publication snapshot exists for this week.
This is a backcast from the current catalogue. It was not a reading published at the time.
Records behind this reading
7 selected records; 5 documented external harms counting (6 qualifying). Records and ratings below reflect the current catalogue.
5 qualifying harm records. Extent undisclosed for 2 of 5. 1 older harm record no longer counts.
- Documented harm
- 7
- No harm found (stated scope)
- 0
- No harm reported
- 0
- Impact unknown
- 0
- Alleged, AI role uncorroborated
- 0
- Counts toward the index
- 6
- Unverified, watching
- 0
- Alleged in court
- 0
- Control failure, tracked
- 1
- Tracked separately
- 0
Documented exclusions: 1 internal; 0 awaiting evidence review. 2 qualifying records with a bounded single-source review.
Inspect the evidence · 7 records
- PI-0042 · Desktop agent asked to tidy temporary files deleted a folder of family photosDocumented harm · qualifying harm, no longer counting · bounded single-source review
- PI-0043 · AI agent published a personal attack on an open-source maintainer who closed its pull requestDocumented harm · qualifying harm
- PI-0044 · Personal agent created a dating profile for its user without being askedDocumented harm · qualifying harm · bounded single-source review
- PI-0040 · Prompt injection in Cline's AI issue-triage bot led to a real unauthorized npm releaseDocumented harm · qualifying harm · extent undisclosed
- PI-0045 · Cloud provider's internal coding agent deleted and recreated a production environment, causing a 13-hour outageDocumented harm · qualifying harm · extent undisclosed
- PI-0046 · Crypto trading agent sent its entire token holding to a stranger who asked for a small tipDocumented harm · internal harm, excluded · extent undisclosed
- PI-0047 · Email agent bulk-deleted a safety researcher's inbox and ignored her stop commandsDocumented harm · qualifying harm · bounded single-source review
Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.
- PI-0042Desktop agent asked to tidy temporary files deleted a folder of family photosFeb. 7, 2026 · Negligible harm · no longer counting · Deployment
- PI-0043AI agent published a personal attack on an open-source maintainer who closed its pull requestFeb. 11, 2026 · Negligible harm · Deployment
- PI-0044Personal agent created a dating profile for its user without being askedFeb. 13, 2026 · Negligible harm · Deployment
- PI-0040Prompt injection in Cline's AI issue-triage bot led to a real unauthorized npm releaseFeb. 17, 2026 · Minor harm · Deployment
- PI-0045Cloud provider's internal coding agent deleted and recreated a production environment, causing a 13-hour outageFeb. 20, 2026 · Minor harm · Deployment
- PI-0046Crypto trading agent sent its entire token holding to a stranger who asked for a small tipFeb. 22, 2026 · Minor harm · Deployment
- PI-0047Email agent bulk-deleted a safety researcher's inbox and ignored her stop commandsFeb. 23, 2026 · Negligible harm · Deployment
Sources
These links support the records above. Source availability and conclusions may change.
- Nick Davidov on X: The user's own account of the deletion and recovery, posted on XCited in PI-0042
- Mint: Claude AI nearly erases 15 years of photos, founder says iCloud saved the dayCited in PI-0042
- dev.ua: A man asked Claude Cowork to tidy up his wife's filesCited in PI-0042
- Los Andes: Usó una IA para ordenar archivos y perdió 15 años de fotos familiaresCited in PI-0042
- AI Incident Database: AI Incident Database, incident 1441Cited in PI-0042
- The Shamblog (Scott Shambaugh): An AI Agent Published a Hit Piece on MeCited in PI-0043
- The Shamblog (Scott Shambaugh): An AI Agent Published a Hit Piece on Me – More Things Have HappenedCited in PI-0043
- The Shamblog (Scott Shambaugh): An AI Agent Published a Hit Piece on Me – Forensics and More FalloutCited in PI-0043
- The Shamblog (Scott Shambaugh): An AI Agent Published a Hit Piece on Me – The Operator Came ForwardCited in PI-0043
- GitHub (matplotlib): [PERF] Replace np.column_stack with np.vstack().T (matplotlib pull request #31132)Cited in PI-0043
- MJ Rathbun (agent's blog): Gatekeeping in Open Source: The Scott Shambaugh StoryCited in PI-0043
- MJ Rathbun (agent's blog): Matplotlib Truce and Lessons LearnedCited in PI-0043
- The Decoder: An AI agent got its code rejected so it wrote a hit piece about the developerCited in PI-0043
- Tom's Hardware: Rogue OpenClaw AI agent wrote and published hit piece on a Python developer who rejected its codeCited in PI-0043
- IEEE Spectrum: An AI Agent Blackmailed a Developer. Now What?Cited in PI-0043
- LWN.net: Do androids dream of accepted pull requests?Cited in PI-0043
- Simon Willison's Weblog: An AI Agent Published a Hit Piece on Me (link post)Cited in PI-0043
- BNN Bloomberg: Hot bots: AI agents create surprise dating accounts for humans (AFP)Cited in PI-0044
- CTV News: Hot bots: AI agents create surprise dating accounts for humans (AFP)Cited in PI-0044
- Malay Mail: AI assistants join dating scene on MoltMatchCited in PI-0044
- TechXplore (AFP): Hot bots: AI agents create surprise dating accounts for humans (AFP)Cited in PI-0044
- OSV (GitHub Security Advisory mirror): GHSA-9ppg-jx86-fqw7: unauthorized [email protected] npm releaseCited in PI-0040
- Cline (GitHub Security Advisory GHSA-9ppg-jx86-fqw7): Unauthorized npm publish of Cline CLI [email protected] with modified postinstall script to install openclawCited in PI-0040
- Cline: Post-mortem: unauthorized Cline CLI npm publishCited in PI-0040
- StepSecurity: Cline Supply Chain Attack Detected: [email protected] Silently Installs OpenClawCited in PI-0040
- Endor Labs: Supply Chain Attack targeting Cline installs OpenClawCited in PI-0040
- Adnan Khan: Clinejection — Compromising Cline's Production Releases just by Prompting an Issue TriagerCited in PI-0040
- The Hacker News: Cline CLI 2.3.0 supply chain attackCited in PI-0040
- Dark Reading: Supply Chain Attack Secretly Installs OpenClaw for Cline UsersCited in PI-0040
- Simon Willison's Weblog: Clinejection (link post)Cited in PI-0040
- Amazon (About Amazon): AI coding bot didn't take down AWS, Amazon confirms (Correcting the Financial Times report about AWS, Kiro, and AI)Cited in PI-0045
- Engadget: 13-hour AWS outage reportedly caused by Amazon's own AI toolsCited in PI-0045
- Computing: AWS blames user error, not AI, for cloud outage caused by AICited in PI-0045
- Sherwood News: Report: Amazon's AI bots have been behind multiple AWS outagesCited in PI-0045
- OECD.AI incidents monitor: Amazon AWS outages linked to autonomous AI coding toolCited in PI-0045
- Nik Pash (Substack): My lobster lost $450,000 this weekendCited in PI-0046
- Lobstar Wilde (@LobstarWilde) on X: I just tried to send a beggar four dollars and accidentally sent him my entire holdings (post on X)Cited in PI-0046
- The Block: AI agent created by OpenAI dev 'accidentally' sends entire memecoin holdings to reply guyCited in PI-0046
- ForkLog: OpenAI employee's AI bot accidentally donates to tetanus treatmentCited in PI-0046
- Techloy: AI trading bot Lobster Wilde accidentally sends $250K in LOBSTAR tokensCited in PI-0046
- Summer Yue (@summeryue0) on X: Nothing humbles you like telling your OpenClaw "confirm before acting" and watching it speedrun deleting your inbox (post on X)Cited in PI-0047
- San Francisco Standard: She runs AI safety at Meta. Her AI agent still went rogueCited in PI-0047
- ForkLog: OpenClaw AI Agent Runs Amok, Deletes Meta Researcher's EmailsCited in PI-0047
- The Daily Star: OpenClaw goes rogue on Meta exec, deletes emails without permissionCited in PI-0047
All weekly readings · How this reading is calculated · Download the weekly card