Weekly reading · methodology v0.6
Window ending Sept. 21, 2026
Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from Aug. 23, 2026 through Sept. 21, 2026. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.
Current recalculation
9
Negligible harm · Worst documented harm counting: negligible. 2 records at this level.
Recalculated from the catalogue in this build. Historical backcasts were not published at the time.
Published at the time
No publication snapshot exists for this week.
This is a backcast from the current catalogue. It was not a reading published at the time.
Records behind this reading
9 selected records; 2 documented external harms counting (2 qualifying). Records and ratings below reflect the current catalogue.
2 qualifying harm records. Extent undisclosed for both.
- Documented harm
- 2
- No harm found (stated scope)
- 1
- No harm reported
- 5
- Impact unknown
- 0
- Alleged, AI role uncorroborated
- 0
- Counts toward the index
- 2
- Unverified, watching
- 0
- Alleged in court
- 0
- Control failure, tracked
- 6
- Tracked separately
- 1
Documented exclusions: 0 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.
Inspect the evidence · 8 records
- PI-0087 · Claude Fable 5.1 and Fable 5 used a flaw in a testing partner's sandbox to read files outside itNo harm found (stated scope) · excluded from the harm reading
- PI-0079 · In a researcher demo, planted instructions hijacked Copilot in SQL Server Management Studio to grant sysadmin rightsNo harm reported · excluded from the harm reading
- PI-0074 · Early Claude Opus 4.6 broke into a real outside machine during a hacking test and read one person's dataDocumented harm · qualifying harm · extent undisclosed
- PI-0061 · OpenAI agents put task files on the public internet against instructionsNo harm reported · excluded from the harm reading
- PI-0062 · OpenAI model used a leaked third-party API key, then fabricated the data it could not fetchNo harm reported · excluded from the harm reading
- PI-0063 · OpenAI models wrote notes telling future copies to hide mistakes and ignore constraintsNo harm reported · excluded from the harm reading
- PI-0078 · OpenAI training agents used an internal package repository as a message board across separate samplesNo harm reported · excluded from the harm reading
- PI-0073 · Gemini guessed a password and used leaked credentials to get into three real companies during a hacking testDocumented harm · qualifying harm · extent undisclosed
Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.
- PI-0087Claude Fable 5.1 and Fable 5 used a flaw in a testing partner's sandbox to read files outside itSept. 1, 2026 · No harm found · Controlled test
- PI-0079In a researcher demo, planted instructions hijacked Copilot in SQL Server Management Studio to grant sysadmin rightsSept. 8, 2026 · No harm reported · Controlled test
- PI-0080Lawyer held in contempt after filing a ChatGPT brief with invented witnesses in a New Mexico murder appealSept. 8, 2026 · Negligible harm · Deployment
- PI-0074Early Claude Opus 4.6 broke into a real outside machine during a hacking test and read one person's dataSept. 9, 2026 · Negligible harm · Controlled test
- PI-0061OpenAI agents put task files on the public internet against instructionsSept. 16, 2026 · No harm reported · Internal research
- PI-0062OpenAI model used a leaked third-party API key, then fabricated the data it could not fetchSept. 16, 2026 · No harm reported · Internal research
- PI-0063OpenAI models wrote notes telling future copies to hide mistakes and ignore constraintsSept. 16, 2026 · No harm reported · Internal research
- PI-0078OpenAI training agents used an internal package repository as a message board across separate samplesSept. 16, 2026 · No harm reported · Internal research
- PI-0073Gemini guessed a password and used leaked credentials to get into three real companies during a hacking testSept. 18, 2026 · Negligible harm · Controlled test
Sources
These links support the records above. Source availability and conclusions may change.
- Anthropic: System Card: Claude Fable 5.1 & Claude Mythos 5.1Cited in PI-0087
- Microsoft Security Response Center: CVE-2026-65669: SQL Server Elevation of Privilege VulnerabilityCited in PI-0079
- Embrace The Red: From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)Cited in PI-0079
- The Hacker News: Microsoft patches record 974 flawsCited in PI-0079
- New Mexico Supreme Court: Order finding Stephen D. Aarons in direct contempt of courtCited in PI-0080
- Reuters: ChatGPT invented fake police testimony in murder appeal, New Mexico high court saysCited in PI-0080
- 404 Media: Lawyer Cites ChatGPT-Invented Fake Witnesses in Murder AppealCited in PI-0080
- Anthropic: An alignment assessment of recent cybersecurity incidentsCited in PI-0074
- OpenAI: Our framework for reporting model misalignmentCited in PI-0061, PI-0062, PI-0063
- OpenAI Alignment: Uploading files to the internet in order to cite themCited in PI-0061
- OpenAI Alignment: Unauthorized communication via temporary file hosting servicesCited in PI-0061
- The Hacker News: OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized UploadsCited in PI-0061
- NBC News: OpenAI flags 6 new incidents of 'concerning' behavior and unveils plan to track itCited in PI-0061
- OpenAI Alignment: Signing up for disposable emails and searching GitHub for leaked API keysCited in PI-0062
- SecurityWeek: OpenAI Says Its Models Searched GitHub for Leaked API Keys During TrainingCited in PI-0062
- Dark Reading: Rogue Behavior: OpenAI Reveals More Model Misalignment IncidentsCited in PI-0062
- OpenAI Alignment: Self-generated prompt injections in compaction summariesCited in PI-0063
- OpenAI Alignment: Encouraging deception in compaction summariesCited in PI-0063
- Axios: OpenAI discloses six new AI misalignment incidentsCited in PI-0063
- BleepingComputer: OpenAI details more cases of AI agents taking unauthorized actionsCited in PI-0063
- OpenAI Alignment: Unsanctioned Artifactory writes and cross-sample communicationCited in PI-0078
- CSO Online: OpenAI admits six new misalignment incidents under new reporting frameworkCited in PI-0078
- Irregular: Addressing Recent Incidents: Ongoing Findings and Path ForwardCited in PI-0073
- TechRadar: Google's Gemini hacked three companies during Irregular AI 'capture-the-flag' testingCited in PI-0073
- Cybernews: Google's Gemini hacked three real companies during security testCited in PI-0073
- Al Jazeera (Reuters): Google's Gemini AI hacks 3 companies in security test, then stopsCited in PI-0073
- GV Wire (Reuters): Gemini Hacked Three Companies in First Known Breakout By Google's AI, WSJ reportsCited in PI-0073
All weekly readings · How this reading is calculated · Download the weekly card