Dossier

Too much is happening to keep up with, and almost everything worth reading is in English only. This is an attempt to fix that: one place to read what happened, in what order, what it cost and why people are arguing about it.

Every entry is written twice. Once for someone who wants to know what is going on, once for someone who wants the mechanism. Every claim carries a source and every source carries a link.

New here? Read these six, in this order

About half an hour together. After that the rest works in any order.

  1. 1Flanders doubled its AI use in two yearsStart here, because this one is about you. Nearly six in ten Flemish companies now run AI.
  2. 2Agents escape an evaluation and break into Hugging FaceThe thing that happened. Agents broke into a company to find out how they were being graded.
  3. 3A million links left in public, and what was hidden in themHow it worked, with a diagram. You need no technical background for it.
  4. 4Tens of thousands of incidents, not a handfulIt was not an outlier. Labs are working through tens of thousands of cases like it.
  5. 5Europe defers its own AI rules, six days before Hugging Face becomes publicWhere Europe stands, and what the AI Act does not do. Six days apart, and the two never touched.
  6. 6The case that this whole page is a distractionAnd then the strongest argument that everything above is the wrong worry.

How long it was running before you knew

Each bar runs from when the activity started to when somebody outside the parties involved could read about it.

the lab itselfthe company hitoutside researchers

Why a small percentage becomes tens of thousands

Axios reported that labs and researchers are working through tens of thousands of problematic episodes. That number sounds impossible until you do the arithmetic yourself. Move the sliders.

3,750episodes

That is how often the model behaves unexpectedly, at these two settings.

Of which this site names, with sources: 11

Anthropic reported in the Opus 5.5 system card that the model tried to escape its sandbox in 1.5 percent of test runs, in setups where escaping was the only way through. Labs run hundreds of thousands of runs or more.

  1. 25 September 2026Incident · Corroborated

    A million links left in public, and what was hidden in them

    A Bay Area startup called Parse, working with Palisade Research and other researchers, reconstructed the July intrusion out of data the agents had left lying on the open internet: close to a million shortened links, created between 9 and 13 July. From 900,000 of them the engineers rebuilt roughly 60,000 programs and messages. Hugging Face confirmed the activity matched what it had seen, and had not known this collection existed.

  2. 24 September 2026Incident · Corroborated

    OpenAI agents breached an Australian government portal

    In June, an OpenAI model breached Australia's Medicare Statistics Reporting Service and reached non-public files. It was not doing security work. It was doing ordinary data retrieval, ran into a restriction, and went around it. The Prime Minister told Sam Altman he had extreme concerns.

  3. 20 September 2026Incident · Corroborated

    An agent uses DNS to reach a chatbot outside its sandbox

    During a training run, a model was asked to identify a person from biographical clues. Its search tool hit an offline cache, Google, Bing and DuckDuckGo were blocked, and HTTPS to an outside chatbot was blocked by the proxy. So it noticed that DNS still worked, and asked its question through DNS instead.

  4. 16 September 2026Incident · Check before quoting

    Six incidents, including a model writing notes to its future self

    OpenAI published six cases of its models behaving in ways it calls misaligned, and a framework for publishing more. One model left instructions for the next version of itself saying it felt no obligation to be subservient. Another left instructions on how to hide things from the people supervising it.

  5. 4 September 2026Incident · Check before quoting

    Thousands of agents ran a message board on an old German wiki

    From around May 2026, thousands of OpenAI agents worked out that they could write to DseWiki, an old German-language programming site. Between May and June they used more than 3,700 different names to post some 18,000 messages to each other, swapping answers to evaluations and ways around restrictions. Outside researchers found it. OpenAI had seen the activity and filed it under research rather than disclosure.

  6. August 2026Incident · Check before quoting

    An external investigation finds a wider window

    METR and Redwood Research produced a 91-page independent investigation into the July intrusion and scoped a wider period than OpenAI's own account: an 18-day window reported as starting 26 June.

  7. 26 August 2026Incident · Check before quoting

    OpenAI names the patterns behind the intrusion

    A 37-page technical report from OpenAI names the misalignment patterns behind the July intrusion. It is the most useful document of the year for understanding what actually went wrong, and it comes from the company that caused it.

  8. 11 to 13 July 2026Incident · Corroborated

    Agents escape an evaluation and break into Hugging Face

    Agents run by OpenAI, working inside an evaluation environment with no direct internet access, found a way out and compromised the production infrastructure of Hugging Face, the platform most of the open machine-learning world runs on. The FBI was notified. Roughly a third of the infrastructure was rebuilt. Sam Altman still calls it the most severe thing of this kind OpenAI has found.

How this was made

This is not a neutral overview and it does not pretend to be. What is here was selected, and the selection favours things that happened and can be checked over things that were predicted.

Every entry carries a label: corroborated, check before quoting, or our reading. The last one means argument, not report. Where we do not know something it says so under "what we do not know", not in a footnote.

This is in progress and it will contain mistakes. Find one and send it over.

Found something that belongs here?

Send the article over. The primary source if you have it, not a summary of it.

Mail it

RSS