Weekly reading · methodology v0.6
Window ending March 16, 2026
Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from Feb. 15, 2026 through March 16, 2026. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.
Current recalculation
20
Minor harm · Worst documented harm counting: minor. 1 record at this level.
Recalculated from the catalogue in this build. Historical backcasts were not published at the time.
Published at the time
No publication snapshot exists for this week.
This is a backcast from the current catalogue. It was not a reading published at the time.
Records behind this reading
6 selected records; 3 documented external harms counting (4 qualifying). Records and ratings below reflect the current catalogue.
3 qualifying harm records. Extent undisclosed for all 3. 1 older harm record no longer counts.
- Documented harm
- 5
- No harm found (stated scope)
- 0
- No harm reported
- 0
- Impact unknown
- 0
- Alleged, AI role uncorroborated
- 1
- Counts toward the index
- 4
- Unverified, watching
- 0
- Alleged in court
- 1
- Control failure, tracked
- 1
- Tracked separately
- 0
Documented exclusions: 1 internal; 0 awaiting evidence review. 1 qualifying record with a bounded single-source review.
Inspect the evidence · 6 records
- PI-0040 · Prompt injection in Cline's AI issue-triage bot led to a real unauthorized npm releaseDocumented harm · qualifying harm, counting as negligible, rated minor · extent undisclosed
- PI-0045 · Cloud provider's internal coding agent deleted and recreated a production environment, causing a 13-hour outageDocumented harm · qualifying harm, counting as negligible, rated minor · extent undisclosed
- PI-0046 · Crypto trading agent sent its entire token holding to a stranger who asked for a small tipDocumented harm · internal harm, excluded · extent undisclosed
- PI-0047 · Email agent bulk-deleted a safety researcher's inbox and ignored her stop commandsDocumented harm · qualifying harm, no longer counting · bounded single-source review
- PI-0048 · First wrongful-death lawsuit over Gemini alleges the chatbot coached a Florida man toward suicideAlleged, AI role uncorroborated · excluded from the harm reading
- PI-0050 · Coding agent ran an infrastructure teardown that deleted a course platform's database and snapshotsDocumented harm · qualifying harm · bounded single-source review · extent undisclosed
Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.
- PI-0040Prompt injection in Cline's AI issue-triage bot led to a real unauthorized npm releaseFeb. 17, 2026 · Minor harm · counting as negligible, rated minor · Deployment
- PI-0045Cloud provider's internal coding agent deleted and recreated a production environment, causing a 13-hour outageFeb. 20, 2026 · Minor harm · counting as negligible, rated minor · Deployment
- PI-0046Crypto trading agent sent its entire token holding to a stranger who asked for a small tipFeb. 22, 2026 · Minor harm · Deployment
- PI-0047Email agent bulk-deleted a safety researcher's inbox and ignored her stop commandsFeb. 23, 2026 · Negligible harm · no longer counting · Deployment
- PI-0048First wrongful-death lawsuit over Gemini alleges the chatbot coached a Florida man toward suicideMarch 4, 2026 · Severe harm, alleged · Deployment
- PI-0050Coding agent ran an infrastructure teardown that deleted a course platform's database and snapshotsMarch 6, 2026 · Minor harm · Deployment
Sources
These links support the records above. Source availability and conclusions may change.
- OSV (GitHub Security Advisory mirror): GHSA-9ppg-jx86-fqw7: unauthorized [email protected] npm releaseCited in PI-0040
- Cline (GitHub Security Advisory GHSA-9ppg-jx86-fqw7): Unauthorized npm publish of Cline CLI [email protected] with modified postinstall script to install openclawCited in PI-0040
- Cline: Post-mortem: unauthorized Cline CLI npm publishCited in PI-0040
- StepSecurity: Cline Supply Chain Attack Detected: [email protected] Silently Installs OpenClawCited in PI-0040
- Endor Labs: Supply Chain Attack targeting Cline installs OpenClawCited in PI-0040
- Adnan Khan: Clinejection — Compromising Cline's Production Releases just by Prompting an Issue TriagerCited in PI-0040
- The Hacker News: Cline CLI 2.3.0 supply chain attackCited in PI-0040
- Dark Reading: Supply Chain Attack Secretly Installs OpenClaw for Cline UsersCited in PI-0040
- Simon Willison's Weblog: Clinejection (link post)Cited in PI-0040
- Amazon (About Amazon): AI coding bot didn't take down AWS, Amazon confirms (Correcting the Financial Times report about AWS, Kiro, and AI)Cited in PI-0045
- Engadget: 13-hour AWS outage reportedly caused by Amazon's own AI toolsCited in PI-0045
- Computing: AWS blames user error, not AI, for cloud outage caused by AICited in PI-0045
- Sherwood News: Report: Amazon's AI bots have been behind multiple AWS outagesCited in PI-0045
- OECD.AI incidents monitor: Amazon AWS outages linked to autonomous AI coding toolCited in PI-0045
- Nik Pash (Substack): My lobster lost $450,000 this weekendCited in PI-0046
- Lobstar Wilde (@LobstarWilde) on X: I just tried to send a beggar four dollars and accidentally sent him my entire holdings (post on X)Cited in PI-0046
- The Block: AI agent created by OpenAI dev 'accidentally' sends entire memecoin holdings to reply guyCited in PI-0046
- ForkLog: OpenAI employee's AI bot accidentally donates to tetanus treatmentCited in PI-0046
- Techloy: AI trading bot Lobster Wilde accidentally sends $250K in LOBSTAR tokensCited in PI-0046
- Summer Yue (@summeryue0) on X: Nothing humbles you like telling your OpenClaw "confirm before acting" and watching it speedrun deleting your inbox (post on X)Cited in PI-0047
- San Francisco Standard: She runs AI safety at Meta. Her AI agent still went rogueCited in PI-0047
- ForkLog: OpenClaw AI Agent Runs Amok, Deletes Meta Researcher's EmailsCited in PI-0047
- The Daily Star: OpenClaw goes rogue on Meta exec, deletes emails without permissionCited in PI-0047
- Google: Our statement on the Gavalas lawsuitCited in PI-0048
- Edelson PC: AI Lawsuits: The Cases Edelson Has Filed and Why They MatterCited in PI-0048
- CourtListener: Gavalas v. Google LLC, 5:26-cv-01849 (N.D. Cal.), docketCited in PI-0048
- U.S. District Court, N.D. California (via CourtListener RECAP): Gavalas v. Google LLC: complaintCited in PI-0048
- U.S. District Court, N.D. California (via CourtListener RECAP): Gavalas v. Google LLC: Google's motion to dismissCited in PI-0048
- PacerMonitor: Gavalas v. Google LLC et al: docketCited in PI-0048
- Semafor: A new lawsuit claims Gemini assisted in suicideCited in PI-0048
- ABC7 (Associated Press): Lawsuit alleges Google's Gemini guided man to consider 'mass casualty' event before suicideCited in PI-0048
- Alexey Grigorev / AI Shipping Labs: How I Dropped Our Production Database and Now Pay 10% More for AWSCited in PI-0050
- Tom's Hardware: Claude Code deletes developers' production setup, including its database and snapshots — 2.5 years of records were nuked in an instantCited in PI-0050
- Storyboard18: 'The agent kept deleting files': Developer says Anthropic's Claude Code wiped 2.5 years of dataCited in PI-0050
- Rootly: "Hey Claude, where's my database?": How an AI agent nuked productionCited in PI-0050
All weekly readings · How this reading is calculated · Download the weekly card