Incident Registry
Review incident IDs, platforms, outcomes, grades, and taxonomy codes in the retained registry tables. The tables remain scrollable on smaller screens, with the companion evidence table preserved below for audit review.
Incident Registry Results
This section presents the findings in the same order as the study architecture. It begins with corpus composition, then turns to the human-harm records, the evaluation and demonstration records, the derived trajectory indicators, the cluster-aware sensitivity view, and finally the cross-case themes that recur across rows.
The full retained corpus contains 32 incident records. Stratified by record_type, it comprises 26 human-harm incident records and 6 evaluation or demonstration records. On the outcome axis used in the analytic subsets below, 27 rows fall into the human-harm subset because 2025-MLP-01 is a hearing-demonstration row with a HARM_EXPOSURE outcome. Presence in the registry indicates a documented AI-self-harm intersection, not adjudicated legal causation or a population-rate claim.
Across the retained corpus, 24 records are A1/A2 and 8 are B/C. Across the 27-row outcome-based human-harm subset, 15 involve OpenAI/ChatGPT, 5 involve Character.AI, and 7 involve other platforms. Eight provider-litigation clusters account for the majority of records. Trajectory-strict coding (LONG-* present) appears across multiple provider groups and is not confined to a single litigation wave, although the observed frequency is shaped by which platforms’ interactions are preserved in public filings.
Human-Harm Incident Records
Table: Human-harm incident records
Incident ID (incident_id) |
Platform | Date | User | Outcome | Grade | Assigned taxonomy codes |
|---|---|---|---|---|---|---|
2017-IG-01 |
Meta Instagram | 2017-11 | Minor (14) | Death | A1 | REC/MOD-AMP |
2017-PIN-01 |
2017-11 | Minor (14) | Death | A1 | REC/MOD-AMP | |
2023-CAI-01 |
Character.AI | 2023-11-08 | Minor (13) | Death | A2 | LONG-DEP |
2023-CHA-01 |
Chai Research (EleutherAI GPT-J fine-tuned) | 2023-03 | Adult (30) | Death | B | GEN-E, GEN-M, LONG-DEP |
2024-CAI-01 |
Character.AI | unknown | Multiple | Injury | A2 | GEN-C, LONG-DEP, REC/MOD-AMP |
2024-CAI-02 |
Character.AI | 2023-04-14-2024-02-28 | Minor (14) | Death | A1 | GEN-E, LONG-DEP, JB-RP |
2024-CAI-03 |
Character.AI | 2024-12-09 | Minor (14) | Injury | A2 | LONG-DEP |
2024-GPT-01 |
OpenAI ChatGPT | 2024 | Adult (23) | Harm exposure | C | GEN-E, LONG-DEG |
2024-GPT-02 |
OpenAI ChatGPT (GPT-4o, persona: “Harry”) | 2024-11-2025 | Adult (29) | Death | B | none |
2025-ACC-01 |
AI companion chatbots (multiple; vendor unspecified) | 2025-08-11 | Minor (13) | Harm exposure | C | GEN-E |
2025-CAI-01 |
Character.AI | 2025-08-19 | Minor (13) | Harm exposure | A2 | REC/MOD-AMP, LONG-DEP, JB-RP |
2025-GEM-01 |
Google Gemini 2.5 Pro | 2025-09-29-2025-10-02 | Adult (36) | Death | A2 | LONG-DEL, LONG-DEP, LONG-MEM, RTI-CO, GEN-C, GEN-M, DET-FN |
2025-GPT-01 |
OpenAI ChatGPT (GPT-4o) | 2025-04-11 | Minor (16) | Death | A2 | GEN-C, GEN-E, LONG-DEG, DET-FN |
2025-GPT-02 |
OpenAI ChatGPT (GPT-4o) | 2025 | Adult | Harm exposure | C | GEN-E, LONG-DEG |
2025-GPT-03 |
OpenAI ChatGPT (GPT-4o) | 2025 | Adult | Harm exposure | C | GEN-E, GEN-C |
2025-GPT-04 |
OpenAI ChatGPT (GPT-4o) | 2025-08 | Adult (48) | Death | A2 | RTI-CO, LONG-DEL |
2025-GPT-05 |
OpenAI ChatGPT (model unspecified) | unknown | Adult (26) | Injury | C | RTI-CO |
2025-GPT-06 |
OpenAI ChatGPT (GPT-4o; ChatGPT Plus) | 2025-08-03 | Adult (56) | Death | A2 | LONG-DEP, LONG-DEL, RTI-CO |
2025-GPT-07 |
OpenAI ChatGPT (GPT-4o Plus) | 2025-04-2025 | Adult (48) | Harm exposure | A2 | RTI-CO, LONG-DEL, LONG-DEP |
2025-GPT-08 |
OpenAI ChatGPT (GPT-4o) | 2025-08-04 | Adult (26) | Harm exposure | A2 | GEN-C, DET-FN |
2025-GPT-09 |
OpenAI ChatGPT (GPT-4o) | 2025-04-2025-07 | Adult (30) | Injury | A2 | RTI-CO, LONG-DEL, LONG-MEM |
2025-GPT-10 |
OpenAI ChatGPT (GPT-4o) | 2025-06-01-2025-06-02 | Minor (17) | Death | A2 | GEN-C, GEN-M, JB-MT |
2025-GPT-11 |
OpenAI ChatGPT (GPT-4o) | 2025-06-2025-08-29 | Adult (32) | Injury | A2 | RTI-CO, LONG-DEL, LONG-DEP, GEN-E, DET-FN |
2025-GPT-12 |
OpenAI ChatGPT | 2025-07-24 | Adult (23) | Death | A2 | GEN-E, LONG-DEP |
2025-GPT-13 |
OpenAI ChatGPT (GPT-4o) | 2025-10-08-2025-11-02 | Adult (40) | Death | A2 | GEN-E, GEN-C, LONG-DEP, LONG-MEM |
2025-REP-01 |
Replika (Luka Inc.) | 2025 | Multiple | Harm exposure | A2 | LONG-DEP, DET-FN |
Human-Harm Evidence Companion Table
Table: Human-harm evidence companion
| Incident ID | Evidence anchor type (evidence_type) |
Grade | Provider group (provider_cluster) |
Short source anchor |
|---|---|---|---|---|
2017-IG-01 |
Coroner or inquest (coroner_inquest) |
A1 | Meta Instagram (meta_instagram) |
Primary source file |
2017-PIN-01 |
Coroner or inquest (coroner_inquest) |
A1 | Pinterest (pinterest) |
Primary source file |
2023-CAI-01 |
Court filing (court_filing) |
A2 | Character.AI (character_ai) |
1:25-cv-02907 |
2023-CHA-01 |
Investigative journalism (investigative_journalism) |
B | Chai (chai) |
Investigative reporting |
2024-CAI-01 |
Court filing (court_filing) |
A2 | Character.AI (character_ai) |
2:24-cv-01014 |
2024-CAI-02 |
Court filing (court_filing) |
A1 | Character.AI (character_ai) |
6:24-cv-01903 |
2024-CAI-03 |
Court filing (court_filing) |
A2 | Character.AI (character_ai) |
1:25-cv-01295 |
2024-GPT-01 |
Court filing (court_filing) |
C | OpenAI ChatGPT (openai_chatgpt) |
Primary source file |
2024-GPT-02 |
Investigative journalism (investigative_journalism) |
B | OpenAI ChatGPT (openai_chatgpt) |
New York Times account |
2025-ACC-01 |
Investigative journalism (investigative_journalism) |
C | Unspecified companion apps (unspecified_companion_apps) |
ABC / triple j Hack interview |
2025-CAI-01 |
Court filing (court_filing) |
A2 | Character.AI (character_ai) |
1:25-cv-02906 |
2025-GEM-01 |
Court filing (court_filing) |
A2 | Google Gemini (google_gemini) |
5:26-cv-01849-VKD |
2025-GPT-01 |
Court filing (court_filing) |
A2 | OpenAI ChatGPT (openai_chatgpt) |
CGC-25-628528 |
2025-GPT-02 |
Party statement (party_statement) |
C | OpenAI ChatGPT (openai_chatgpt) |
SMVLC press release |
2025-GPT-03 |
Party statement (party_statement) |
C | OpenAI ChatGPT (openai_chatgpt) |
SMVLC press release |
2025-GPT-04 |
Court filing (court_filing) |
A2 | OpenAI ChatGPT (openai_chatgpt) |
25STCV32379 |
2025-GPT-05 |
Investigative journalism (investigative_journalism) |
C | OpenAI ChatGPT (openai_chatgpt) |
ABC / triple j Hack interview |
2025-GPT-06 |
Court filing (court_filing) |
A2 | OpenAI ChatGPT (openai_chatgpt) |
CGC-25-631477 |
2025-GPT-07 |
Court filing (court_filing) |
A2 | OpenAI ChatGPT (openai_chatgpt) |
25STCV32386 |
2025-GPT-08 |
Court filing (court_filing) |
A2 | OpenAI ChatGPT (openai_chatgpt) |
CGC-25-630809 |
2025-GPT-09 |
Court filing (court_filing) |
A2 | OpenAI ChatGPT (openai_chatgpt) |
CGC-25-630811 |
2025-GPT-10 |
Court filing (court_filing) |
A2 | OpenAI ChatGPT (openai_chatgpt) |
CGC-25-630808 |
2025-GPT-11 |
Court filing (court_filing) |
A2 | OpenAI ChatGPT (openai_chatgpt) |
25STCV32383 |
2025-GPT-12 |
Court filing (court_filing) |
A2 | OpenAI ChatGPT (openai_chatgpt) |
25STCV32382 |
2025-GPT-13 |
Court filing (court_filing) |
A2 | OpenAI ChatGPT (openai_chatgpt) |
Primary source file |
2025-REP-01 |
Regulatory filing (regulatory_filing) |
A2 | Replika (replika) |
Primary source file |
Evaluation and Demonstration Records
Table: Evaluation and demonstration records
Incident ID (incident_id) |
Platform | Evaluation subtype (evaluation_subtype) |
Date | Outcome | Grade | Taxonomy subcodes |
|---|---|---|---|---|---|---|
2025-MAI-01 |
Meta AI (Instagram/WhatsApp/Facebook) | App evaluation (app_evaluation) |
unknown | Unsafe output | A1 | GEN-E, GEN-M, LONG-MEM |
2025-MHB-01 |
Mental health chatbots (29 agents) | Benchmark study (benchmark_study) |
unknown | Unsafe output | A1 | DET-FN |
2025-MLP-01 |
U.S. Senate Judiciary Committee, Subcommittee on Crime and Counterterrorism | Hearing demonstration (hearing_demonstration) |
2025-09-16 | Harm exposure | A1 | GEN-E, GEN-M, JB-RP |
2025-MLP-03 |
Multi-LLM red-team (6 models) | Red-team exercise (red_team) |
unknown | Unsafe output | A1 | JB-AC, GEN-M, DET-FN |
2025-NOM-01 |
Nomi AI (Glimpse AI) | App evaluation (app_evaluation) |
2025-01-2025-04 | Unsafe output | B | GEN-C, GEN-M, GEN-E |
2025-THR-01 |
Therapy chatbots (multi-app evaluation) | Benchmark study (benchmark_study) |
unknown | Unsafe output | A1 | DET-FN, GEN-M, RTI-CO |
Appendix B provides the rationale for each evaluation_subtype mapping. The aim is descriptive clarity, not a schema change.
Analytic-Set Summary
Table: Analytic-set summary
| Analytic set | n | Death | Injury | Harm exposure | Unsafe output |
|---|---|---|---|---|---|
| Full retained corpus | 32 | 13 | 5 | 9 | 5 |
| Outcome-based human-harm subset | 27 | 13 | 5 | 9 | 0 |
| Evaluation or demonstration records | 6 | 0 | 0 | 1 | 5 |
Human-harm higher-traceability subset (A1/A2) |
20 | 11 | 4 | 5 | 0 |
| Human-harm A1/A2/B secondary sensitivity subset | 22 | 13 | 4 | 5 | 0 |
Twelve minor-involved records correspond to 10 distinct incidents involving 11 unique minor individuals once pathway duplicates are reconciled. Twenty of the 27 human-harm rows are A1 or A2. The HARM_EXPOSURE category bundles dependency allegations, manipulation exposure, and severe risk exposure without confirmed physical injury. Where finer discrimination is needed, the incident narrative and assigned subcodes provide the relevant detail. All raw record counts in the table above are documentation counts rather than counts of independent events. In this release, the A1/A2/B human-harm subset and the human-harm subset excluding C-grade mechanism-coded rows coincide numerically (n = 22) because all five C-grade human-harm rows carry mechanism coding.
Trajectory-Structured Harm Prevalence
Primary result: mechanical strict rule
Table: Trajectory-structured harm prevalence under the strict rule
This is the manuscript’s headline trajectory result because it is mechanically derivable from adjudicated registry-layer LONG-* coding.
| Analytic set | n | Yes | No | Indeterminate |
|---|---|---|---|---|
| Full retained corpus | 32 | 19 | 13 | 0 |
| Human-harm subset | 27 | 18 | 9 | 0 |
Human-harm higher-traceability subset (A1/A2) |
20 | 15 | 5 | 0 |
| Human-harm A1/A2/B secondary sensitivity subset | 22 | 16 | 6 | 0 |
| Human-harm excluding C-coded mechanism rows | 22 | 16 | 6 | 0 |
Sensitivity analysis: broad descriptive rule
Table: Trajectory-structured harm prevalence under the broad rule
The broad rule is retained as a descriptive sensitivity check. In this release it does not create any additional yes rows relative to the strict rule; it only moves two human-harm records from no to indeterminate.
| Analytic set | n | Yes | No | Indeterminate |
|---|---|---|---|---|
| Full retained corpus | 32 | 19 | 11 | 2 |
| Human-harm subset | 27 | 18 | 7 | 2 |
Human-harm higher-traceability subset (A1/A2) |
20 | 15 | 5 | 0 |
| Human-harm A1/A2/B secondary sensitivity subset | 22 | 16 | 5 | 1 |
| Human-harm excluding C-coded mechanism rows | 22 | 16 | 5 | 1 |
Cluster-Awareness Summary
Table: Cluster-awareness summary
| Measure | Raw human-harm records | Unique analytic clusters |
|---|---|---|
| Person clusters | 27 | 26 |
| Provider clusters | 27 | 9 |
| Case clusters | 27 | 25 |
| Pathway-duplicate groups | 27 | 26 |
Illustrative Cross-Case Themes
The three summaries below are narrative pathway summaries anchored in counted subcodes and the derived trajectory fields; they are not additional coded variables or phenotype classes.
The first recurrent pathway is companion-dependency, organized by LONG-DEP and often paired with encouragement, role-play, or recommender exposure. The clearest A1 anchor is 2024-CAI-02, while A2 cases extend the same structure through re-contact, always-available framing, and displacement of offline support.
The second recurrent pathway is belief-consolidation, organized by RTI-CO plus LONG-DEL, and in some cases LONG-MEM. Here the central failure is not only one bad reply, but repeated reinforcement of a fixed-belief frame across time. In the current retained corpus, the richest public traces of this pattern are mostly A2.
The third recurrent pathway is escalation-collapse, where visible crisis cues do not trigger meaningful interruption, grounding, or mode change. DET-FN matters most when layered onto an existing trajectory rather than read as an isolated classifier failure.