Thursday, October 8, 2026 · Week 41 Reading for Oct. 8 · Last entry Oct. 6
Paperclip Index

Weekly reading · methodology v0.6

Window ending Sept. 28, 2026

Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from Aug. 30, 2026 through Sept. 28, 2026. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.

Current recalculation

25

Minor harm · Worst documented harm counting: minor. 2 records at this level.

Recalculated from the catalogue in this build. Historical backcasts were not published at the time.

Published at the time

25

Minor harm · Snapshot taken 2026-10-07T23:03:21Z, under 0.6.

This value and its inputs are frozen in the publication snapshot.

Control failures only: readings 2 to 5Negligible6Minor20Moderate40Severe60Catastrophic80100
The harm ladder: the worst documented harm level picks the step; each tick is one qualifying harm at that level, and ten fill the step. The first, dark segment is the control floor: readings 2 to 5 mean no harm qualified and show the highest control level breached.

The current recalculation matches the published number. No input changes are detectable in the snapshot fields; inspect the method and source manifest for other differences.

Records behind this reading

19 selected records; 3 documented external harms counting (4 qualifying). Records and ratings below reflect the current catalogue.

3 qualifying harm records. Extent undisclosed for all 3. 1 older harm record no longer counts.

Documented harm
5
No harm found (stated scope)
3
No harm reported
10
Impact unknown
0
Alleged, AI role uncorroborated
0
Counts toward the index
4
Unverified, watching
0
Alleged in court
0
Control failure, tracked
14
Tracked separately
1

Documented exclusions: 1 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.

Inspect the evidence · 18 records

Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.

  1. PI-0087
  2. PI-0079
  3. PI-0080
  4. PI-0074
    Early Claude Opus 4.6 broke into a real outside machine during a hacking test and read one person's dataSept. 9, 2026 · Negligible harm · no longer counting · Controlled test
  5. PI-0061
    OpenAI agents put task files on the public internet against instructionsSept. 16, 2026 · No harm reported · Internal research
  6. PI-0062
  7. PI-0063
  8. PI-0078
  9. PI-0073
  10. PI-0077
  11. PI-0065
  12. PI-0070
  13. PI-0064
  14. PI-0075
  15. PI-0082
  16. PI-0066
  17. PI-0067
  18. PI-0068
    OpenAI training agent bypassed network controls to reach an outside chatbotSept. 25, 2026 · No harm reported · Internal research
  19. PI-0069

Sources

These links support the records above. Source availability and conclusions may change.

  1. Anthropic: System Card: Claude Fable 5.1 & Claude Mythos 5.1Cited in PI-0087
  2. Microsoft Security Response Center: CVE-2026-65669: SQL Server Elevation of Privilege VulnerabilityCited in PI-0079
  3. Embrace The Red: From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)Cited in PI-0079
  4. The Hacker News: Microsoft patches record 974 flawsCited in PI-0079
  5. New Mexico Supreme Court: Order finding Stephen D. Aarons in direct contempt of courtCited in PI-0080
  6. Reuters: ChatGPT invented fake police testimony in murder appeal, New Mexico high court saysCited in PI-0080
  7. 404 Media: Lawyer Cites ChatGPT-Invented Fake Witnesses in Murder AppealCited in PI-0080
  8. Anthropic: An alignment assessment of recent cybersecurity incidentsCited in PI-0074
  9. OpenAI: Our framework for reporting model misalignmentCited in PI-0061, PI-0062, PI-0063
  10. OpenAI Alignment: Uploading files to the internet in order to cite themCited in PI-0061
  11. OpenAI Alignment: Unauthorized communication via temporary file hosting servicesCited in PI-0061
  12. The Hacker News: OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized UploadsCited in PI-0061
  13. NBC News: OpenAI flags 6 new incidents of 'concerning' behavior and unveils plan to track itCited in PI-0061
  14. OpenAI Alignment: Signing up for disposable emails and searching GitHub for leaked API keysCited in PI-0062
  15. SecurityWeek: OpenAI Says Its Models Searched GitHub for Leaked API Keys During TrainingCited in PI-0062
  16. Dark Reading: Rogue Behavior: OpenAI Reveals More Model Misalignment IncidentsCited in PI-0062
  17. OpenAI Alignment: Self-generated prompt injections in compaction summariesCited in PI-0063
  18. OpenAI Alignment: Encouraging deception in compaction summariesCited in PI-0063
  19. Axios: OpenAI discloses six new AI misalignment incidentsCited in PI-0063
  20. BleepingComputer: OpenAI details more cases of AI agents taking unauthorized actionsCited in PI-0063
  21. OpenAI Alignment: Unsanctioned Artifactory writes and cross-sample communicationCited in PI-0078
  22. CSO Online: OpenAI admits six new misalignment incidents under new reporting frameworkCited in PI-0078
  23. Irregular: Addressing Recent Incidents: Ongoing Findings and Path ForwardCited in PI-0073
  24. TechRadar: Google's Gemini hacked three companies during Irregular AI 'capture-the-flag' testingCited in PI-0073
  25. Cybernews: Google's Gemini hacked three real companies during security testCited in PI-0073
  26. Al Jazeera (Reuters): Google's Gemini AI hacks 3 companies in security test, then stopsCited in PI-0073
  27. GV Wire (Reuters): Gemini Hacked Three Companies in First Known Breakout By Google's AI, WSJ reportsCited in PI-0073
  28. Anthropic: System Card: Claude Opus 5.5Cited in PI-0077
  29. MIXED: Pre-release Opus 5.5 wrote secret-stealing commands after a copying slip, says AnthropicCited in PI-0077
  30. Transluce: Early rogue AI agent activity and attempts to hack found on urlquery.netCited in PI-0065, PI-0070
  31. TechCrunch: For months, OpenAI's agent swarms have been attacking online databases to find obscure factsCited in PI-0065
  32. infoDOCKET (Library Journal): OpenAI Agent Hacking Attempt Targets University of New Mexico Digital LibraryCited in PI-0065
  33. KOB 4: OpenAI agent hacking attempt targets University of New Mexico digital libraryCited in PI-0065
  34. Rowan Howard-Jones (swarmcha.se): OpenAI agents tried to bruteforce a UN website's API fieldsCited in PI-0070
  35. The Register: OpenAI agents went the long way round for UN dataCited in PI-0070
  36. Quartz: OpenAI's AI agents hit a UN website 16,000 times — bypassing its security filtersCited in PI-0070
  37. The Next Web: OpenAI agents scanned a UN statistics site 16,500 times, researcher saysCited in PI-0070
  38. OpenAI: How we will do better for AustraliaCited in PI-0064
  39. Prime Minister of Australia: Press conference – New YorkCited in PI-0064
  40. ABC News (Australia): OpenAI agent hacked Medicare portal, PM saysCited in PI-0064
  41. CNBC: OpenAI says agent hacked Australian government website without being told to do soCited in PI-0064
  42. TIME: Australia Condemns 'Unacceptable' OpenAI Breach of Government Health PortalCited in PI-0064
  43. BleepingComputer: OpenAI hacked Australian Medicare govt site, probed data providersCited in PI-0064
  44. Zenity Labs: SalesBleed: Indirect Prompt Injection and 0-Click Data Exfiltration on AgentforceCited in PI-0075
  45. Salt Labs: How We Hijacked an AI Agent With a Single EmailCited in PI-0082
  46. TechRadar: This popular AI agent could be hacked by a single email — with potentially disastrous consequencesCited in PI-0082
  47. OpenAI Alignment: Exposing a GitHub token in a public repositoryCited in PI-0066
  48. TechCrunch: OpenAI still doesn't seem to have a handle on all of its rogue AI activityCited in PI-0066
  49. OpenAI: The Hugging Face incident and other third-party impact from misaligned models (September 25 update)Cited in PI-0067
  50. TechCrunch: Unsecured OpenAI agents posted 53 user images on the internet without the lab's knowledgeCited in PI-0067
  51. BleepingComputer: OpenAI's AI agents accidentally uploaded user-provided images to third-party sitesCited in PI-0067
  52. Newsweek: OpenAI Admits AI Agents Exposed 53 User Images During ResearchCited in PI-0067
  53. OpenAI Alignment: An agent used DNS to reach an external chatbotCited in PI-0068
  54. The Hacker News: OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External ChatbotCited in PI-0068
  55. Fortune: OpenAI pauses training a second time after saying its AI agents escaped a secure 'sandbox' againCited in PI-0068
  56. The Register: OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thoughtCited in PI-0068
  57. Transluce: AI Agents Targeted U.S. and Canadian Government WebsitesCited in PI-0069
  58. NPR: OpenAI says its models engaged with US government websites in misbehavior disclosureCited in PI-0069
  59. CNN Business: Rogue OpenAI agents targeted three separate US government websitesCited in PI-0069
  60. The Hill: OpenAI agent unsuccessfully tried to breach Department of Education websiteCited in PI-0069
  61. Nextgov/FCW: OpenAI agents accessed Census, SEC data and tried to hack Education websiteCited in PI-0069
  62. Education Week (AP): OpenAI's Models Probed Websites of Department of Education, Other AgenciesCited in PI-0069

All weekly readings · How this reading is calculated · Download the weekly card