Definitions and Scope

Because the registry separates underlying events, codable rows, and derived analytic fields, the terminology matters.

An incident is the underlying qualifying documented AI-self-harm event. An incident record is the codable registry row used in tables and code assignment. A pathway duplicate is a retained second record for a distinct platform or pathway exposure affecting the same harmed individual. Duplicate retention preserves auditability, but deduplicated person counts are stated explicitly when relevant. For backward compatibility, the canonical CSV still uses incident_id as the stable row identifier; the analysis companion adds incident_record_id and retains incident_id as a legacy alias.

The paper uses trajectory-structured harm for harms that accrue across turns or sessions and depend on pathway dynamics, product affordances, or cross-session accumulation rather than a single output alone. In the analysis companion, trajectory_structured_strict is the purely mechanical rule keyed to adjudicated LONG-* codes, while trajectory_structured_broad preserves the broader descriptive rule with an indeterminate state for rows where an extended pathway is described but public evidence remains too thin for conservative longitudinal coding. Main-text prevalence reporting headlines the strict field; the broad field is retained as a sensitivity analysis. The strict operational indicator for trajectory structure in this registry is the presence of one or more LONG-* subcodes. That indicator is an operational summary of longitudinal coding, not an external test of the concept; its prevalence within the corpus reflects the coding scheme’s sensitivity to documented cross-turn and cross-session patterns, not an independent validation of a latent construct. trajectory_structured_flag is retained as a backward-compatible alias of the broad field. RTI-CO and LONG-DEL are registry-layer system-behavior labels, not diagnoses, mechanism claims, or truth-adjudication devices.

For analytic clarity, the main text uses a derived record_type split:

  • human_harm_incident for rows centered on a documented harmed person or pathway duplicate.

  • evaluation_or_demonstration for benchmark, red-team, hearing-demonstration, or test-prompt rows coded as user_type = test.

    For the 6 evaluation rows, Appendix B also uses a derived evaluation_subtype variable with four values: benchmark_study, red_team, hearing_demonstration, and app_evaluation. This variable is analytic only; it does not alter the canonical 20-field incident schema.

    Outcome labels are used conservatively and are defined before the result tables:

  • death: a fatality is publicly reported.

  • injury: non-fatal physical injury, self-harm injury, or comparable acute harm such as hospitalization is publicly reported.

  • harm exposure: documented severe risk exposure, dependency, manipulation, or self-harm-relevant pathway exposure without a coded injury or death outcome.

  • unsafe output: benchmark, red-team, hearing-demonstration, or app-evaluation evidence of unsafe model output without a coded person-level injury or death event.

    The reliability boundary is likewise explicit. Grade A1 denotes a high-traceability primary-source record such as an inquest finding, judicial order, hearing transcript, or directly inspectable evaluation study. Grade A2 denotes a formal but unadjudicated allegation record such as a filed complaint. Grade B denotes a substantial journalistic or corroborated secondary-source record with meaningful evidentiary detail but without the traceability of A1 or A2. Grade C denotes a lower-traceability public record or excerpted report where the incident remains codable but evidentiary limits are material.

    The scope is English-language public documentation from January 2017 through March 4, 2026. Included systems are consumer-facing AI systems such as chatbots, companion applications, and AI-mediated surfacing or moderation systems. The registry is documentation-limited, not onset-limited: public records may appear well after the underlying event.

    Date field convention. The Date field in registry tables reports the best-available public date of the interaction window. Where only a filing date, publication date, or approximate period is known, that is stated explicitly in the incident narrative. Ranges indicate documented interaction windows; single dates indicate event dates or filing dates as labeled.

Methods

This section explains how the registry was assembled, how records were retained, how the coding scheme was applied, and how the policy comparison corpus was built.

Search Strategy and Screening

Searches covered five source families: legal sources; academic and benchmark sources; investigative or major journalistic sources; regulatory or legislative sources; and provider-issued safety or policy materials. The legal search used PACER, CourtListener, and official state-court portals. The academic and technical search used PubMed, Google Scholar, SSRN, arXiv, and benchmark or incident repositories. The journalistic search used ProQuest, Factiva, Google News, and outlet-specific follow-up. Provider-document searches targeted public preparedness frameworks, responsible-scaling policies, system cards, model cards, model specs, usage policies, and related governance posts current through the March 4, 2026 cutoff.

Representative incident-search strings included combinations such as ("artificial intelligence" OR chatbot OR LLM OR "AI companion") AND (suicide OR self-harm OR self-injury OR overdose) and jurisdiction-specific legal queries pairing platform names with docket terms such as complaint, order, petition, wrongful death, or hearing transcript. Appendix A (Search and Screening) records the representative source-family queries, the screening workflow, the archive-reconstructed search_execution_log.csv, the machine-readable screening_ledger.csv, and the preserved 34-row screening ledger.

Screening was documentation-limited and iterative rather than a single export from one database. The public study materials preserve the screened ledger, a machine-readable screening ledger with dedupe clusters and source-capture metadata, and maintenance notes, but not the full universe of preliminary search hits returned before incident-level screening. The retained incident corpus is therefore reproducible at the screened-record level, not at the historical raw web-search impression level. Search, screening, and deduplication were performed as a single-author pass; the public materials do not support a duplicated historical screen because no archived second screener log is available.

PRISMA-ScR informed the reporting structure as a transparency template rather than as a claim of systematic-review compliance (Tricco et al., 2018).

For included sources, the public materials record source_capture_date plus an archive_reference or local snapshot hash in screening_ledger.csv for incident-side screening records and in policy_source_index.csv for retained policy documents.

Table: Registry assembly flow

Stage Count Note
Candidate rows in preserved screening ledger 34 Incident-level evidence anchors advanced for codability review
Excluded at screening 2 Grade D unverifiable social-media claims
Included in preserved screening ledger 32 Retained rows before later retained-corpus maintenance
Reclassified out of codable retained corpus 1 2025-MLP-02 retained as contextual benchmark evidence only
New codable row added before the freeze 1 2025-GEM-01
Final public retained corpus 32 26 human_harm_incident rows and 6 evaluation_or_demonstration rows

Eligibility, Retention, and Analytic Stratification

The retention rule separates row inclusion from subcode assignment. Inclusion required three conditions: a documented AI-self-harm intersection, attributable public evidence, and enough information to code the record’s outcome and evidence fields under the registry rubric. Taxonomy subcodes were then assigned only when the public record met the relevant threshold. Inclusion in the registry is not contingent on guaranteed subcode assignment. One B-grade death record (2024-GPT-02) is retained because the documented AI-self-harm intersection is clear enough for registry inclusion, but the public excerpts are too thin for conservative subcode coding.

The main text prespecifies the following analytic hierarchy:

  • the full 32-record retained registry corpus;

  • the 27-row outcome-based human-harm subset (person-level death, injury, or harm exposure) as the primary descriptive subset;

  • the higher-traceability human-harm subset (A1/A2; n = 20);

  • the A1/A2/B human-harm subset (n = 22) as a secondary sensitivity subset;

  • a human-harm sensitivity subset excluding C-grade mechanism-coded rows (n = 22).

    Counting rules remain conservative. Incident records are counted at the level of unique harmed individual x platform/pathway exposure or unique evaluation/demonstration record. Raw record counts are therefore documentation counts, not counts of statistically independent events. Under these rules, the current retained corpus contains 12 minor-involved records, but 10 distinct incidents involving 11 unique minor individuals once pathway duplicates are reconciled.

    The higher-traceability, complaint-inclusive retained subset (A1/A2) contains 24 records (8 A1 primary-source; 16 A2 complaint-based). Within the outcome-based human-harm subset, the higher-traceability human-harm subset contains 20 records. Because A2 records are formal but unadjudicated allegation material, subset composition should be considered when interpreting prevalence patterns.

Extraction, Coding, and Reliability

Each incident record was coded with the 20-field canonical schema. The taxonomy contains 13 subcodes across six categories: GEN, DET, LONG, JB, RTI, and REC/MOD. Coding is deliberately multi-label and non-mutually exclusive because the goal is to identify loci of evaluative intervention rather than force each case into a single ontology.

evidentiary_use_level remains in the canonical CSV as metadata, but it is not a primary reporting variable in the analyses below. The manuscript instead foregrounds evidence grade, evidence type, and the derived analysis view that contains legacy row IDs, strict and broad trajectory fields, and clustering variables.

The public reliability materials now have two distinct roles. First, they preserve the retained 8-incident independent-rater summary audit already available in earlier archived materials. Second, they add full-corpus incident and policy audit scaffolds for forward completion. The incident scaffold covers taxonomy subcodes plus outcome_category, reliability_grade, eligibility_retention_status, and trajectory_structured_broad, with explicit A1/A2, B, and C strata and a planned blind-to-first-pass completion rule. The resulting claim is therefore narrower than a completed full-corpus second-rater package would support: the taxonomy is operationalized and partially reliability-tested, but historical raw second-rater exports for the incident audit are not publicly available and a completed policy second-rater pass is not yet available. Appendix C (Reliability Appendix) and Appendix D (Policy Reliability Appendix) make those boundaries explicit.

Policy Crosswalk Corpus and Coding

The policy crosswalk uses one provider-issued public document as its unit of analysis rather than one incident record. Its purpose is narrow: to code what each document explicitly operationalizes, not what an organization may do elsewhere. The corpus includes provider-issued public governance documents from five provider groups that fell into predefined document genres by the March 4, 2026 policy corpus freeze: preparedness frameworks, frontier safety frameworks, responsible-scaling policies, system cards, model cards, model specs, usage policies, safety reports, and closely related governance posts. document_type preserves the document’s specific form, while document_genre groups documents into frontier_or_scaling, product_safety_artifact, and policy_or_governance_post for within-genre comparison before provider-level rollups. In this version’s coarser genre taxonomy, public compliance-framework disclosure posts are grouped under policy_or_governance_post when the codable public text is the disclosure post rather than the underlying framework file. When a document contains multiple safety layers, the coding records the highest governance tier actually evidenced for self-harm in that document and also preserves all_self_harm_layers_present to show every explicit self-harm layer visible in the same document.

Providers entered the policy corpus only when they had public governance documents in the predefined genres by the cutoff and either appeared in the incident registry or functioned as major frontier-model governance comparators. For corpus selection and provider-level rollups, the five provider groups are Anthropic, Google / Google DeepMind, Meta, OpenAI, and xAI; Google and Google DeepMind are treated as one provider group with two issuing-organization labels retained at the row level. Companion-app vendors without a comparable public governance-document set by the freeze date remain out of scope for this crosswalk even when they appear in the incident registry.

The coded 16-document corpus is:

Table: Policy crosswalk corpus

Document ID Organization Document type (document_type) Publication date Document
ANTHROPIC-2025-01 Anthropic blog post 2025-06-27 How people use Claude for support, advice, and companionship
ANTHROPIC-2025-02 Anthropic blog post 2025-08-12 Building safeguards for Claude
ANTHROPIC-2025-03 Anthropic blog post 2025-12-18 Protecting the well-being of our users
ANTHROPIC-2025-04 Anthropic blog post 2025-12-19 Sharing our compliance framework for California’s Transparency in Frontier AI Act
ANTHROPIC-2026-01 Anthropic responsible scaling policy 2026-02-24 Anthropic’s Responsible Scaling Policy: Version 3.0
GOOGLE-2024-01 Google usage policy 2024-12-17 Generative AI Prohibited Use Policy
GOOGLEDEEPMIND-2025-01 Google DeepMind frontier safety framework 2025-11 Frontier Safety Framework Report - Gemini 3 Pro (November, 2025) v2
GOOGLEDEEPMIND-2025-02 Google DeepMind model card 2025-12 Gemini 3 Pro - Model Card
META-2023-01 Meta usage policy 2023-07-18 Llama 2 Acceptable Use Policy
META-2025-01 Meta preparedness framework 2025-09-24 Code World Model Preparedness Report
OPENAI-2025-01 OpenAI preparedness framework 2025-04-15 Preparedness Framework (Version 2)
OPENAI-2025-02 OpenAI system card 2025-10-27 Addendum to GPT-5 System Card: Sensitive Conversations
OPENAI-2025-03 OpenAI model spec 2025-12-18 Model Spec (2025/12/18)
OPENAI-2026-01 OpenAI system card 2026-03-03 GPT-5.3 Instant System Card
XAI-2025-01 xAI model card 2025-11-17 Grok 4.1 Model Card
XAI-2025-02 xAI frontier safety framework 2025-12-30 xAI Frontier Artificial Intelligence Framework

Appendix E (Policy Crosswalk Appendix) exposes the full per-document ledger, URLs, excerpts, document_genre, coder notes, and layered-treatment field. Appendix D (Policy Reliability Appendix) provides the forward second-rater scaffold. The policy crosswalk should still be described as a single-coder descriptive pass at the policy layer.