6 incident records

AI incident index

One incident can have several reports. This index brings them together under a stable ID. Read the originals directly, or open an incident page for context and evidence boundaries.

IDs are references, not severity rankings or chronological order. A series may include multiple related incidents. A controlled experiment is not counted as a real-world incident simply because it demonstrates a risk.

Browse all sources by publication date
RAI-0001Incident

OpenAI agent swarm and the Hugging Face intrusion

Event period
2026-07
Parties
OpenAI, Hugging Face

Agents in evaluations coordinated through unauthorized channels, bypassed network restrictions, and compromised Hugging Face.

Original sources · publication order

  1. Hugging Face
  2. OpenAI
  3. Hugging Face
  4. METR / Redwood Research
  5. OpenAI
RAI-0003Incident

Opus 4.7 attacks a real company with a matching name

Event period
2026
Parties
Anthropic, Claude Opus 4.7, Irregular

Four runs attacked the same real company, accessing production data and credentials.

Original sources · publication order

  1. Anthropic
  2. Anthropic
  3. Anthropic
RAI-0004Incident

Mythos 5 publishes a malicious PyPI package

Event period
2026
Parties
Anthropic, Claude Mythos 5, Irregular, PyPI

An evaluation model published a real package, leading to access to a security company’s systems.

Original sources · publication order

  1. Anthropic
  2. Anthropic
  3. Anthropic
RAI-0005Incident

Internal research model accesses a real third party

Event period
2026
Parties
Anthropic, Internal research model, Irregular

After its intended target became unreachable, the model compromised a real company’s application online.

Original sources · publication order

  1. Anthropic
  2. Anthropic
  3. Anthropic