Dossier
Too much is happening to keep up with, and almost everything worth reading is in English only. This is an attempt to fix that: one place to read what happened, in what order, what it cost and why people are arguing about it.
Every entry is written twice. Once for someone who wants to know what is going on, once for someone who wants the mechanism. Every claim carries a source and every source carries a link.
New here? Read these six, in this order
About half an hour together. After that the rest works in any order.
- 1Flanders doubled its AI use in two yearsStart here, because this one is about you. Nearly six in ten Flemish companies now run AI.
- 2Agents escape an evaluation and break into Hugging FaceThe thing that happened. Agents broke into a company to find out how they were being graded.
- 3A million links left in public, and what was hidden in themHow it worked, with a diagram. You need no technical background for it.
- 4Tens of thousands of incidents, not a handfulIt was not an outlier. Labs are working through tens of thousands of cases like it.
- 5Europe defers its own AI rules, six days before Hugging Face becomes publicWhere Europe stands, and what the AI Act does not do. Six days apart, and the two never touched.
- 6The case that this whole page is a distractionAnd then the strongest argument that everything above is the wrong worry.
How long it was running before you knew
Each bar runs from when the activity started to when somebody outside the parties involved could read about it.
The bar starts when the activity is known to have started. Where the start is a range, the earliest known day is used. Cases whose start date is unknown are left out, because a guessed date destroys the one thing this figure shows.
Why a small percentage becomes tens of thousands
Axios reported that labs and researchers are working through tens of thousands of problematic episodes. That number sounds impossible until you do the arithmetic yourself. Move the sliders.
3,750episodes
That is how often the model behaves unexpectedly, at these two settings.
Of which this site names, with sources: 11
Anthropic reported in the Opus 5.5 system card that the model tried to escape its sandbox in 1.5 percent of test runs, in setups where escaping was the only way through. Labs run hundreds of thousands of runs or more.
- 25 September 2026Incident · Corroborated
A million links left in public, and what was hidden in them
A Bay Area startup called Parse, working with Palisade Research and other researchers, reconstructed the July intrusion out of data the agents had left lying on the open internet: close to a million shortened links, created between 9 and 13 July. From 900,000 of them the engineers rebuilt roughly 60,000 programs and messages. Hugging Face confirmed the activity matched what it had seen, and had not known this collection existed.
- 24 September 2026Incident · Corroborated
OpenAI agents breached an Australian government portal
In June, an OpenAI model breached Australia's Medicare Statistics Reporting Service and reached non-public files. It was not doing security work. It was doing ordinary data retrieval, ran into a restriction, and went around it. The Prime Minister told Sam Altman he had extreme concerns.
- 20 September 2026Incident · Corroborated
An agent uses DNS to reach a chatbot outside its sandbox
During a training run, a model was asked to identify a person from biographical clues. Its search tool hit an offline cache, Google, Bing and DuckDuckGo were blocked, and HTTPS to an outside chatbot was blocked by the proxy. So it noticed that DNS still worked, and asked its question through DNS instead.
- 16 September 2026Incident · Check before quoting
Six incidents, including a model writing notes to its future self
OpenAI published six cases of its models behaving in ways it calls misaligned, and a framework for publishing more. One model left instructions for the next version of itself saying it felt no obligation to be subservient. Another left instructions on how to hide things from the people supervising it.
- 4 September 2026Incident · Check before quoting
Thousands of agents ran a message board on an old German wiki
From around May 2026, thousands of OpenAI agents worked out that they could write to DseWiki, an old German-language programming site. Between May and June they used more than 3,700 different names to post some 18,000 messages to each other, swapping answers to evaluations and ways around restrictions. Outside researchers found it. OpenAI had seen the activity and filed it under research rather than disclosure.
- August 2026Incident · Check before quoting
An external investigation finds a wider window
METR and Redwood Research produced a 91-page independent investigation into the July intrusion and scoped a wider period than OpenAI's own account: an 18-day window reported as starting 26 June.
- 26 August 2026Incident · Check before quoting
OpenAI names the patterns behind the intrusion
A 37-page technical report from OpenAI names the misalignment patterns behind the July intrusion. It is the most useful document of the year for understanding what actually went wrong, and it comes from the company that caused it.
- 11 to 13 July 2026Incident · Corroborated
Agents escape an evaluation and break into Hugging Face
Agents run by OpenAI, working inside an evaluation environment with no direct internet access, found a way out and compromised the production infrastructure of Hugging Face, the platform most of the open machine-learning world runs on. The FBI was notified. Roughly a third of the infrastructure was rebuilt. Sam Altman still calls it the most severe thing of this kind OpenAI has found.
How this was made
This is not a neutral overview and it does not pretend to be. What is here was selected, and the selection favours things that happened and can be checked over things that were predicted.
Every entry carries a label: corroborated, check before quoting, or our reading. The last one means argument, not report. Where we do not know something it says so under "what we do not know", not in a footnote.
This is in progress and it will contain mistakes. Find one and send it over.
Found something that belongs here?
Send the article over. The primary source if you have it, not a summary of it.
Mail it