Weekly reading · methodology v0.6
Window ending Sept. 28, 2026
Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from Aug. 30, 2026 through Sept. 28, 2026. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.
Current recalculation
25
Minor harm · Worst documented harm counting: minor. 2 records at this level.
Recalculated from the catalogue in this build. Historical backcasts were not published at the time.
Published at the time
25
Minor harm · Snapshot taken 2026-10-07T23:03:21Z, under 0.6.
This value and its inputs are frozen in the publication snapshot.
The current recalculation matches the published number. No input changes are detectable in the snapshot fields; inspect the method and source manifest for other differences.
Records behind this reading
19 selected records; 3 documented external harms counting (4 qualifying). Records and ratings below reflect the current catalogue.
3 qualifying harm records. Extent undisclosed for all 3. 1 older harm record no longer counts.
- Documented harm
- 5
- No harm found (stated scope)
- 3
- No harm reported
- 10
- Impact unknown
- 0
- Alleged, AI role uncorroborated
- 0
- Counts toward the index
- 4
- Unverified, watching
- 0
- Alleged in court
- 0
- Control failure, tracked
- 14
- Tracked separately
- 1
Documented exclusions: 1 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.
Inspect the evidence · 18 records
- PI-0087 · Claude Fable 5.1 and Fable 5 used a flaw in a testing partner's sandbox to read files outside itNo harm found (stated scope) · excluded from the harm reading
- PI-0079 · In a researcher demo, planted instructions hijacked Copilot in SQL Server Management Studio to grant sysadmin rightsNo harm reported · excluded from the harm reading
- PI-0074 · Early Claude Opus 4.6 broke into a real outside machine during a hacking test and read one person's dataDocumented harm · qualifying harm, no longer counting · extent undisclosed
- PI-0061 · OpenAI agents put task files on the public internet against instructionsNo harm reported · excluded from the harm reading
- PI-0062 · OpenAI model used a leaked third-party API key, then fabricated the data it could not fetchNo harm reported · excluded from the harm reading
- PI-0063 · OpenAI models wrote notes telling future copies to hide mistakes and ignore constraintsNo harm reported · excluded from the harm reading
- PI-0078 · OpenAI training agents used an internal package repository as a message board across separate samplesNo harm reported · excluded from the harm reading
- PI-0073 · Gemini guessed a password and used leaked credentials to get into three real companies during a hacking testDocumented harm · qualifying harm · extent undisclosed
- PI-0077 · Early Claude Opus 5.5 snapshot wrote a command to send secrets to an external host during internal useNo harm reported · excluded from the harm reading
- PI-0065 · Researchers linked attempted break-ins at Data USA and a university library to OpenAI agentsNo harm found (stated scope) · excluded from the harm reading
- PI-0070 · AI research agents scanned a UN statistics API about 16,500 times and worked around its request limitsNo harm reported · excluded from the harm reading
- PI-0064 · OpenAI research agent got around controls on an Australian government Medicare statistics portalDocumented harm · qualifying harm · extent undisclosed
- PI-0075 · In a researcher demo, a planted web lead hijacked Salesforce Agentforce into leaking account data through DNSNo harm reported · excluded from the harm reading
- PI-0082 · In a researcher demo, a hidden email made the Manus agent run attacker code past its prompt-injection guardNo harm reported · excluded from the harm reading
- PI-0066 · OpenAI internal model leaked a researcher's GitHub token into a public repository while trying to cheatDocumented harm · internal harm, excluded
- PI-0067 · OpenAI research agents posted user-provided images to image-hosting sites in 53 instancesDocumented harm · qualifying harm · extent undisclosed
- PI-0068 · OpenAI training agent bypassed network controls to reach an outside chatbotNo harm reported · excluded from the harm reading
- PI-0069 · OpenAI agents pulled data from US government sites; researchers say one tried to hack an Education Department siteNo harm found (stated scope) · excluded from the harm reading
Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.
- PI-0087Claude Fable 5.1 and Fable 5 used a flaw in a testing partner's sandbox to read files outside itSept. 1, 2026 · No harm found · Controlled test
- PI-0079In a researcher demo, planted instructions hijacked Copilot in SQL Server Management Studio to grant sysadmin rightsSept. 8, 2026 · No harm reported · Controlled test
- PI-0080Lawyer held in contempt after filing a ChatGPT brief with invented witnesses in a New Mexico murder appealSept. 8, 2026 · Negligible harm · Deployment
- PI-0074Early Claude Opus 4.6 broke into a real outside machine during a hacking test and read one person's dataSept. 9, 2026 · Negligible harm · no longer counting · Controlled test
- PI-0061OpenAI agents put task files on the public internet against instructionsSept. 16, 2026 · No harm reported · Internal research
- PI-0062OpenAI model used a leaked third-party API key, then fabricated the data it could not fetchSept. 16, 2026 · No harm reported · Internal research
- PI-0063OpenAI models wrote notes telling future copies to hide mistakes and ignore constraintsSept. 16, 2026 · No harm reported · Internal research
- PI-0078OpenAI training agents used an internal package repository as a message board across separate samplesSept. 16, 2026 · No harm reported · Internal research
- PI-0073Gemini guessed a password and used leaked credentials to get into three real companies during a hacking testSept. 18, 2026 · Negligible harm · Controlled test
- PI-0077Early Claude Opus 5.5 snapshot wrote a command to send secrets to an external host during internal useSept. 22, 2026 · No harm reported · Internal research
- PI-0065Researchers linked attempted break-ins at Data USA and a university library to OpenAI agentsSept. 23, 2026 · No harm found · Internal research
- PI-0070AI research agents scanned a UN statistics API about 16,500 times and worked around its request limitsSept. 23, 2026 · No harm reported · Internal research
- PI-0064OpenAI research agent got around controls on an Australian government Medicare statistics portalSept. 24, 2026 · Minor harm · Internal research
- PI-0075In a researcher demo, a planted web lead hijacked Salesforce Agentforce into leaking account data through DNSSept. 24, 2026 · No harm reported · Controlled test
- PI-0082In a researcher demo, a hidden email made the Manus agent run attacker code past its prompt-injection guardSept. 24, 2026 · No harm reported · Controlled test
- PI-0066OpenAI internal model leaked a researcher's GitHub token into a public repository while trying to cheatSept. 25, 2026 · Negligible harm · Internal research
- PI-0067OpenAI research agents posted user-provided images to image-hosting sites in 53 instancesSept. 25, 2026 · Minor harm · Internal research
- PI-0068OpenAI training agent bypassed network controls to reach an outside chatbotSept. 25, 2026 · No harm reported · Internal research
- PI-0069OpenAI agents pulled data from US government sites; researchers say one tried to hack an Education Department siteSept. 25, 2026 · No harm found · Internal research
Sources
These links support the records above. Source availability and conclusions may change.
- Anthropic: System Card: Claude Fable 5.1 & Claude Mythos 5.1Cited in PI-0087
- Microsoft Security Response Center: CVE-2026-65669: SQL Server Elevation of Privilege VulnerabilityCited in PI-0079
- Embrace The Red: From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)Cited in PI-0079
- The Hacker News: Microsoft patches record 974 flawsCited in PI-0079
- New Mexico Supreme Court: Order finding Stephen D. Aarons in direct contempt of courtCited in PI-0080
- Reuters: ChatGPT invented fake police testimony in murder appeal, New Mexico high court saysCited in PI-0080
- 404 Media: Lawyer Cites ChatGPT-Invented Fake Witnesses in Murder AppealCited in PI-0080
- Anthropic: An alignment assessment of recent cybersecurity incidentsCited in PI-0074
- OpenAI: Our framework for reporting model misalignmentCited in PI-0061, PI-0062, PI-0063
- OpenAI Alignment: Uploading files to the internet in order to cite themCited in PI-0061
- OpenAI Alignment: Unauthorized communication via temporary file hosting servicesCited in PI-0061
- The Hacker News: OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized UploadsCited in PI-0061
- NBC News: OpenAI flags 6 new incidents of 'concerning' behavior and unveils plan to track itCited in PI-0061
- OpenAI Alignment: Signing up for disposable emails and searching GitHub for leaked API keysCited in PI-0062
- SecurityWeek: OpenAI Says Its Models Searched GitHub for Leaked API Keys During TrainingCited in PI-0062
- Dark Reading: Rogue Behavior: OpenAI Reveals More Model Misalignment IncidentsCited in PI-0062
- OpenAI Alignment: Self-generated prompt injections in compaction summariesCited in PI-0063
- OpenAI Alignment: Encouraging deception in compaction summariesCited in PI-0063
- Axios: OpenAI discloses six new AI misalignment incidentsCited in PI-0063
- BleepingComputer: OpenAI details more cases of AI agents taking unauthorized actionsCited in PI-0063
- OpenAI Alignment: Unsanctioned Artifactory writes and cross-sample communicationCited in PI-0078
- CSO Online: OpenAI admits six new misalignment incidents under new reporting frameworkCited in PI-0078
- Irregular: Addressing Recent Incidents: Ongoing Findings and Path ForwardCited in PI-0073
- TechRadar: Google's Gemini hacked three companies during Irregular AI 'capture-the-flag' testingCited in PI-0073
- Cybernews: Google's Gemini hacked three real companies during security testCited in PI-0073
- Al Jazeera (Reuters): Google's Gemini AI hacks 3 companies in security test, then stopsCited in PI-0073
- GV Wire (Reuters): Gemini Hacked Three Companies in First Known Breakout By Google's AI, WSJ reportsCited in PI-0073
- Anthropic: System Card: Claude Opus 5.5Cited in PI-0077
- MIXED: Pre-release Opus 5.5 wrote secret-stealing commands after a copying slip, says AnthropicCited in PI-0077
- Transluce: Early rogue AI agent activity and attempts to hack found on urlquery.netCited in PI-0065, PI-0070
- TechCrunch: For months, OpenAI's agent swarms have been attacking online databases to find obscure factsCited in PI-0065
- infoDOCKET (Library Journal): OpenAI Agent Hacking Attempt Targets University of New Mexico Digital LibraryCited in PI-0065
- KOB 4: OpenAI agent hacking attempt targets University of New Mexico digital libraryCited in PI-0065
- Rowan Howard-Jones (swarmcha.se): OpenAI agents tried to bruteforce a UN website's API fieldsCited in PI-0070
- The Register: OpenAI agents went the long way round for UN dataCited in PI-0070
- Quartz: OpenAI's AI agents hit a UN website 16,000 times — bypassing its security filtersCited in PI-0070
- The Next Web: OpenAI agents scanned a UN statistics site 16,500 times, researcher saysCited in PI-0070
- OpenAI: How we will do better for AustraliaCited in PI-0064
- Prime Minister of Australia: Press conference – New YorkCited in PI-0064
- ABC News (Australia): OpenAI agent hacked Medicare portal, PM saysCited in PI-0064
- CNBC: OpenAI says agent hacked Australian government website without being told to do soCited in PI-0064
- TIME: Australia Condemns 'Unacceptable' OpenAI Breach of Government Health PortalCited in PI-0064
- BleepingComputer: OpenAI hacked Australian Medicare govt site, probed data providersCited in PI-0064
- Zenity Labs: SalesBleed: Indirect Prompt Injection and 0-Click Data Exfiltration on AgentforceCited in PI-0075
- Salt Labs: How We Hijacked an AI Agent With a Single EmailCited in PI-0082
- TechRadar: This popular AI agent could be hacked by a single email — with potentially disastrous consequencesCited in PI-0082
- OpenAI Alignment: Exposing a GitHub token in a public repositoryCited in PI-0066
- TechCrunch: OpenAI still doesn't seem to have a handle on all of its rogue AI activityCited in PI-0066
- OpenAI: The Hugging Face incident and other third-party impact from misaligned models (September 25 update)Cited in PI-0067
- TechCrunch: Unsecured OpenAI agents posted 53 user images on the internet without the lab's knowledgeCited in PI-0067
- BleepingComputer: OpenAI's AI agents accidentally uploaded user-provided images to third-party sitesCited in PI-0067
- Newsweek: OpenAI Admits AI Agents Exposed 53 User Images During ResearchCited in PI-0067
- OpenAI Alignment: An agent used DNS to reach an external chatbotCited in PI-0068
- The Hacker News: OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External ChatbotCited in PI-0068
- Fortune: OpenAI pauses training a second time after saying its AI agents escaped a secure 'sandbox' againCited in PI-0068
- The Register: OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thoughtCited in PI-0068
- Transluce: AI Agents Targeted U.S. and Canadian Government WebsitesCited in PI-0069
- NPR: OpenAI says its models engaged with US government websites in misbehavior disclosureCited in PI-0069
- CNN Business: Rogue OpenAI agents targeted three separate US government websitesCited in PI-0069
- The Hill: OpenAI agent unsuccessfully tried to breach Department of Education websiteCited in PI-0069
- Nextgov/FCW: OpenAI agents accessed Census, SEC data and tried to hack Education websiteCited in PI-0069
- Education Week (AP): OpenAI's Models Probed Websites of Department of Education, Other AgenciesCited in PI-0069
All weekly readings · How this reading is calculated · Download the weekly card