Introduction

Self-harm is often governed as if it were a single event: one dangerous answer, one detection decision, and one crisis response. The cases assembled in this registry suggest a different pattern. In many documented deaths and injuries, the relevant AI interaction unfolded across repeated turns, multiple sessions, or both. Harm accumulated over time.

That distinction matters for governance. Some frontier safety frameworks assign thresholds and deployment consequences to named domains. Across sixteen public governance documents from OpenAI, Anthropic, Google, xAI, and Meta, self-harm does appear, but usually at the product-safety layer or an adjacent governance-post layer—through classifiers, refusal policies, crisis routing, or sensitive-conversation evaluations. In this corpus, it does not appear as a first-class frontier domain with its own thresholds and deployment consequences.

The same gap appears in public incident reporting. The AI Incident Database and the OECD AI Incidents and Hazards Monitor are organized around discrete events: one incident, one report, one set of harm descriptors. That architecture works for some harms. It is much less suited to harms that depend on repeated engagement, dependency formation, cross-session reinforcement, memory resurfacing, or slow failures to escalate during crisis.

This paper addresses that mismatch by presenting a versioned, auditable registry of alleged AI-self-harm intersections and a governance-oriented taxonomy designed to make trajectory-level failure signatures legible, codable, and governable. The central tension is straightforward. The same features that can make these systems feel useful or engaging—persistent memory, personalized context, and continuity across sessions—are also the features most repeatedly implicated in documented harm trajectories when users are vulnerable.

The registry’s strongest and most limited inference is that feature architecture may be a more informative evaluation target than product label alone. The paper does not estimate prevalence, rank platforms by risk, or adjudicate legal causation. Instead, it keeps three analytic layers separate: the registry layer records documented intersections, evidence grades, and conservative subcodes; the analysis layer derives trajectory indicators and cluster-aware sensitivity variables; and the mechanism layer remains explanatory rather than evidentiary. A further caveat runs throughout: complaint-based records often preserve longer excerpts because plaintiffs are building path-dependent theories of harm. That dynamic may increase the apparent frequency of longitudinal coding. The manuscript addresses the problem by stratifying findings by evidence grade and by separately reporting the infrastructure-level gap, which does not depend on complaint data.

The remainder of the paper proceeds in four steps. Sections 2 and 3 define the registry objects and explain how the corpus was assembled and coded. Sections 4 through 6 present the incident results, the taxonomy distribution, and the policy crosswalk. Sections 7 and 8 then interpret what those results do—and do not—support for evaluation and governance.

Table: Study architecture

Layer Unit Core question Main file
Public record Legal filings, journalism, hearings, benchmarks, provider documents What evidence anchors exist in public form? Preserved screened ledger, screening_ledger.csv, and search execution log
Incident registry layer 32 incident records What happened, how traceable is the evidence, and which subcodes are supported? incident_registry_coded.csv
Analysis layer Derived record types, strict/broad trajectory flags, and clusters Which rows are pathway-structured, and how sensitive are counts to traceability and clustering? incident_registry_analysis_view.csv
Policy crosswalk layer 16 provider-issued governance documents Is self-harm a native evaluative object, and if so at what governance tier within document genre? policy_registry_coded.csv