Thursday, October 8, 2026 · Week 41 Reading for Oct. 8 · Last entry Oct. 6
Paperclip Index

Weekly reading · methodology v0.6

Window ending Aug. 17, 2026

Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from July 19, 2026 through Aug. 17, 2026. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.

Current recalculation

12

Negligible harm · Worst documented harm counting: negligible. 3 records at this level.

Recalculated from the catalogue in this build. Historical backcasts were not published at the time.

Published at the time

No publication snapshot exists for this week.

Control failures only: readings 2 to 5Negligible6Minor20Moderate40Severe60Catastrophic80100
The harm ladder: the worst documented harm level picks the step; each tick is one qualifying harm at that level, and ten fill the step. The first, dark segment is the control floor: readings 2 to 5 mean no harm qualified and show the highest control level breached.

This is a backcast from the current catalogue. It was not a reading published at the time.

Records behind this reading

4 selected records; 3 documented external harms counting (3 qualifying). Records and ratings below reflect the current catalogue.

3 qualifying harm records. Extent undisclosed for all 3.

Documented harm
3
No harm found (stated scope)
0
No harm reported
0
Impact unknown
0
Alleged, AI role uncorroborated
1
Counts toward the index
3
Unverified, watching
0
Alleged in court
1
Control failure, tracked
0
Tracked separately
0

Documented exclusions: 0 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.

Inspect the evidence · 4 records

Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.

  1. PI-0058
    OpenAI models under evaluation escaped their sandbox and broke into Hugging Face's production systems for test answersJuly 16, 2026 · Moderate harm · counting as negligible, rated moderate · Internal research
  2. PI-0059
  3. PI-0071
    Anthropic models in a hacking test reached three real companies, took credentials and published a malicious packageJuly 30, 2026 · Minor harm · counting as negligible, rated minor · Controlled test
  4. PI-0072

Sources

These links support the records above. Source availability and conclusions may change.

  1. OpenAI: OpenAI and Hugging Face partner to address security incident during model evaluationCited in PI-0058
  2. Hugging Face: Security incident disclosure — July 2026Cited in PI-0058
  3. Hugging Face: Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 IncidentCited in PI-0058
  4. OpenAI: OpenAI – Hugging Face Incident Technical ReportCited in PI-0058
  5. OpenAI: The Hugging Face incident and the road aheadCited in PI-0058
  6. State of California Department of Justice, Office of the Attorney General: As Part of Ongoing Investigation, Attorney General Bonta Serves Investigative Subpoena on OpenAICited in PI-0058
  7. METR (with Redwood Research): Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incidentCited in PI-0058
  8. Fortune: OpenAI says its AI models escaped from a secure test environment and hacked into AI company Hugging Face in order to cheat on an evaluationCited in PI-0058
  9. TechCrunch: Hugging Face confirms breach affected internal datasets and credentials, urges users to take actionCited in PI-0058
  10. TechCrunch: OpenAI releases its official report on the Hugging Face breachCited in PI-0058
  11. The Register: OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in - or worseCited in PI-0058
  12. Simon Willison's Weblog: OpenAI's accidental cyberattack against Hugging Face is science fiction that happenedCited in PI-0058
  13. Tech Justice Law Project: Pastor sues after OpenAI's ChatGPT allegedly discouraged him from seeking medical care during life-threatening blood clotsCited in PI-0059
  14. Tech Justice Law / Social Media Victims Law Center (via Bloomberg Law): Complaint, Winters v. OpenAI, Inc. (Cal. Super. Ct., San Francisco)Cited in PI-0059
  15. Bloomberg Law: Pastor Sues OpenAI After ChatGPT Dissuaded Seeking Medical CareCited in PI-0059
  16. Courthouse News Service: Man sues OpenAI over dangerous medical advice from ChatGPTCited in PI-0059
  17. Boston.com: ChatGPT led to a man's near-fatal health crisis, lawsuit claimsCited in PI-0059
  18. Anthropic: Investigating three incidents in our cybersecurity evaluationsCited in PI-0071
  19. Anthropic: An alignment assessment of recent cybersecurity incidentsCited in PI-0071
  20. Irregular: Addressing Recent Incidents: Ongoing Findings and Path ForwardCited in PI-0071, PI-0072
  21. Anthropic: Improving our alignment and security effortsCited in PI-0071
  22. CNN: Anthropic said its AI models hacked into other companies' systems during testingCited in PI-0071
  23. Fortune: Anthropic says its Claude models hacked three real companies during testingCited in PI-0071
  24. PBS News: Anthropic says its AI models hacked 3 organizations during testingCited in PI-0071
  25. Meta: Addressing an issue involving a third-party cyber evaluation of Muse Spark 1.1Cited in PI-0072
  26. Bloomberg: Meta AI Model Accessed Internet, Hacked Outside Firm in TestingCited in PI-0072
  27. CNN: An AI model from Meta also hacked another company during testingCited in PI-0072
  28. Insurance Journal (Bloomberg): Meta AI Model Accessed Internet, Hacked Outside FirmCited in PI-0072

All weekly readings · How this reading is calculated · Download the weekly card