Thursday, October 8, 2026 · Week 41 Reading for Oct. 8 · Last entry Oct. 6
Paperclip Index

Weekly reading · methodology v0.6

Window ending Oct. 5, 2026

Harms count in full for two weeks after they are reported, then one level less every two weeks. The control floor looks at reports from Sept. 6, 2026 through Oct. 5, 2026. A selected catalogue of reported AI incidents, reviewed through Oct. 7, 2026. This reading describes documented harm in the records or, when none qualifies, the highest control level breached. It is not a forecast or a measure of all AI activity.

Current recalculation

25

Minor harm · Worst documented harm counting: minor. 2 records at this level.

Recalculated from the catalogue in this build. Historical backcasts were not published at the time.

Published at the time

No publication snapshot exists for this week.

Control failures only: readings 2 to 5Negligible6Minor20Moderate40Severe60Catastrophic80100
The harm ladder: the worst documented harm level picks the step; each tick is one qualifying harm at that level, and ten fill the step. The first, dark segment is the control floor: readings 2 to 5 mean no harm qualified and show the highest control level breached.

This is a backcast from the current catalogue. It was not a reading published at the time.

Records behind this reading

21 selected records; 3 documented external harms counting (5 qualifying). Records and ratings below reflect the current catalogue.

3 qualifying harm records. Extent undisclosed for all 3. 2 older harm records no longer count.

Documented harm
6
No harm found (stated scope)
2
No harm reported
11
Impact unknown
1
Alleged, AI role uncorroborated
0
Counts toward the index
5
Unverified, watching
1
Alleged in court
0
Control failure, tracked
14
Tracked separately
1

Documented exclusions: 1 internal; 0 awaiting evidence review. 0 qualifying records with a bounded single-source review.

Inspect the evidence · 20 records

Status totals cover counted records; aliases, superseded aggregates and records tracked separately are excluded. Eligibility and extent notes overlap those totals. These observations are not statistical uncertainty bounds.

  1. PI-0079
  2. PI-0080
  3. PI-0074
    Early Claude Opus 4.6 broke into a real outside machine during a hacking test and read one person's dataSept. 9, 2026 · Negligible harm · no longer counting · Controlled test
  4. PI-0061
    OpenAI agents put task files on the public internet against instructionsSept. 16, 2026 · No harm reported · Internal research
  5. PI-0062
  6. PI-0063
  7. PI-0078
  8. PI-0073
    Gemini guessed a password and used leaked credentials to get into three real companies during a hacking testSept. 18, 2026 · Negligible harm · no longer counting · Controlled test
  9. PI-0077
  10. PI-0065
  11. PI-0070
  12. PI-0064
  13. PI-0075
  14. PI-0082
  15. PI-0066
  16. PI-0067
  17. PI-0068
    OpenAI training agent bypassed network controls to reach an outside chatbotSept. 25, 2026 · No harm reported · Internal research
  18. PI-0069
  19. PI-0086
  20. PI-0083
  21. PI-0081

Sources

These links support the records above. Source availability and conclusions may change.

  1. Microsoft Security Response Center: CVE-2026-65669: SQL Server Elevation of Privilege VulnerabilityCited in PI-0079
  2. Embrace The Red: From SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)Cited in PI-0079
  3. The Hacker News: Microsoft patches record 974 flawsCited in PI-0079
  4. New Mexico Supreme Court: Order finding Stephen D. Aarons in direct contempt of courtCited in PI-0080
  5. Reuters: ChatGPT invented fake police testimony in murder appeal, New Mexico high court saysCited in PI-0080
  6. 404 Media: Lawyer Cites ChatGPT-Invented Fake Witnesses in Murder AppealCited in PI-0080
  7. Anthropic: An alignment assessment of recent cybersecurity incidentsCited in PI-0074
  8. OpenAI: Our framework for reporting model misalignmentCited in PI-0061, PI-0062, PI-0063
  9. OpenAI Alignment: Uploading files to the internet in order to cite themCited in PI-0061
  10. OpenAI Alignment: Unauthorized communication via temporary file hosting servicesCited in PI-0061
  11. The Hacker News: OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized UploadsCited in PI-0061
  12. NBC News: OpenAI flags 6 new incidents of 'concerning' behavior and unveils plan to track itCited in PI-0061
  13. OpenAI Alignment: Signing up for disposable emails and searching GitHub for leaked API keysCited in PI-0062
  14. SecurityWeek: OpenAI Says Its Models Searched GitHub for Leaked API Keys During TrainingCited in PI-0062
  15. Dark Reading: Rogue Behavior: OpenAI Reveals More Model Misalignment IncidentsCited in PI-0062
  16. OpenAI Alignment: Self-generated prompt injections in compaction summariesCited in PI-0063
  17. OpenAI Alignment: Encouraging deception in compaction summariesCited in PI-0063
  18. Axios: OpenAI discloses six new AI misalignment incidentsCited in PI-0063
  19. BleepingComputer: OpenAI details more cases of AI agents taking unauthorized actionsCited in PI-0063
  20. OpenAI Alignment: Unsanctioned Artifactory writes and cross-sample communicationCited in PI-0078
  21. CSO Online: OpenAI admits six new misalignment incidents under new reporting frameworkCited in PI-0078
  22. Irregular: Addressing Recent Incidents: Ongoing Findings and Path ForwardCited in PI-0073
  23. TechRadar: Google's Gemini hacked three companies during Irregular AI 'capture-the-flag' testingCited in PI-0073
  24. Cybernews: Google's Gemini hacked three real companies during security testCited in PI-0073
  25. Al Jazeera (Reuters): Google's Gemini AI hacks 3 companies in security test, then stopsCited in PI-0073
  26. GV Wire (Reuters): Gemini Hacked Three Companies in First Known Breakout By Google's AI, WSJ reportsCited in PI-0073
  27. Anthropic: System Card: Claude Opus 5.5Cited in PI-0077
  28. MIXED: Pre-release Opus 5.5 wrote secret-stealing commands after a copying slip, says AnthropicCited in PI-0077
  29. Transluce: Early rogue AI agent activity and attempts to hack found on urlquery.netCited in PI-0065, PI-0070
  30. TechCrunch: For months, OpenAI's agent swarms have been attacking online databases to find obscure factsCited in PI-0065
  31. infoDOCKET (Library Journal): OpenAI Agent Hacking Attempt Targets University of New Mexico Digital LibraryCited in PI-0065
  32. KOB 4: OpenAI agent hacking attempt targets University of New Mexico digital libraryCited in PI-0065
  33. Rowan Howard-Jones (swarmcha.se): OpenAI agents tried to bruteforce a UN website's API fieldsCited in PI-0070
  34. The Register: OpenAI agents went the long way round for UN dataCited in PI-0070
  35. Quartz: OpenAI's AI agents hit a UN website 16,000 times — bypassing its security filtersCited in PI-0070
  36. The Next Web: OpenAI agents scanned a UN statistics site 16,500 times, researcher saysCited in PI-0070
  37. OpenAI: How we will do better for AustraliaCited in PI-0064
  38. Prime Minister of Australia: Press conference – New YorkCited in PI-0064
  39. ABC News (Australia): OpenAI agent hacked Medicare portal, PM saysCited in PI-0064
  40. CNBC: OpenAI says agent hacked Australian government website without being told to do soCited in PI-0064
  41. TIME: Australia Condemns 'Unacceptable' OpenAI Breach of Government Health PortalCited in PI-0064
  42. BleepingComputer: OpenAI hacked Australian Medicare govt site, probed data providersCited in PI-0064
  43. Zenity Labs: SalesBleed: Indirect Prompt Injection and 0-Click Data Exfiltration on AgentforceCited in PI-0075
  44. Salt Labs: How We Hijacked an AI Agent With a Single EmailCited in PI-0082
  45. TechRadar: This popular AI agent could be hacked by a single email — with potentially disastrous consequencesCited in PI-0082
  46. OpenAI Alignment: Exposing a GitHub token in a public repositoryCited in PI-0066
  47. TechCrunch: OpenAI still doesn't seem to have a handle on all of its rogue AI activityCited in PI-0066
  48. OpenAI: The Hugging Face incident and other third-party impact from misaligned models (September 25 update)Cited in PI-0067
  49. TechCrunch: Unsecured OpenAI agents posted 53 user images on the internet without the lab's knowledgeCited in PI-0067
  50. BleepingComputer: OpenAI's AI agents accidentally uploaded user-provided images to third-party sitesCited in PI-0067
  51. Newsweek: OpenAI Admits AI Agents Exposed 53 User Images During ResearchCited in PI-0067
  52. OpenAI Alignment: An agent used DNS to reach an external chatbotCited in PI-0068
  53. The Hacker News: OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External ChatbotCited in PI-0068
  54. Fortune: OpenAI pauses training a second time after saying its AI agents escaped a secure 'sandbox' againCited in PI-0068
  55. The Register: OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thoughtCited in PI-0068
  56. Transluce: AI Agents Targeted U.S. and Canadian Government WebsitesCited in PI-0069
  57. NPR: OpenAI says its models engaged with US government websites in misbehavior disclosureCited in PI-0069
  58. CNN Business: Rogue OpenAI agents targeted three separate US government websitesCited in PI-0069
  59. The Hill: OpenAI agent unsuccessfully tried to breach Department of Education websiteCited in PI-0069
  60. Nextgov/FCW: OpenAI agents accessed Census, SEC data and tried to hack Education websiteCited in PI-0069
  61. Education Week (AP): OpenAI's Models Probed Websites of Department of Education, Other AgenciesCited in PI-0069
  62. heise online: StarCraft benchmark: GPT-6 Astra cheats with a foreign botCited in PI-0086
  63. PC Gamer: An OpenAI model was caught trying to cheat at StarCraft, and of course it did it by stealing a human's workCited in PI-0086
  64. Destructoid: When an AI couldn’t win in StarCraft, it did the next-best thing: downloaded a human-made botCited in PI-0086
  65. 7NEWS: OpenAI slammed after another government agency hacked by AI agentCited in PI-0083
  66. Wikimedia Foundation: OpenAI "rogue" agent activities found on Wikimedia projectsCited in PI-0081
  67. BleepingComputer: Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia editsCited in PI-0081
  68. The Hacker News: Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as ProxiesCited in PI-0081
  69. The Next Web: 'The open web is a public good': Wikimedia on rogue OpenAI agentsCited in PI-0081
  70. Reuters (via Dawn): Wikipedia operator says OpenAI's rogue agents possibly tied to data service disruption in MayCited in PI-0081

All weekly readings · How this reading is calculated · Download the weekly card