Incident Registry Results

This section presents the findings in the same order as the study architecture. It begins with corpus composition, then turns to the human-harm records, the evaluation and demonstration records, the derived trajectory indicators, the cluster-aware sensitivity view, and finally the cross-case themes that recur across rows.

The full retained corpus contains 32 incident records. Stratified by record_type, it comprises 26 human-harm incident records and 6 evaluation or demonstration records. On the outcome axis used in the analytic subsets below, 27 rows fall into the human-harm subset because 2025-MLP-01 is a hearing-demonstration row with a HARM_EXPOSURE outcome. Presence in the registry indicates a documented AI-self-harm intersection, not adjudicated legal causation or a population-rate claim.

Across the retained corpus, 24 records are A1/A2 and 8 are B/C. Across the 27-row outcome-based human-harm subset, 15 involve OpenAI/ChatGPT, 5 involve Character.AI, and 7 involve other platforms. Eight provider-litigation clusters account for the majority of records. Trajectory-strict coding (LONG-* present) appears across multiple provider groups and is not confined to a single litigation wave, although the observed frequency is shaped by which platforms’ interactions are preserved in public filings.

Human-Harm Incident Records

Table: Human-harm incident records

Incident ID (incident_id) Platform Date User Outcome Grade Assigned taxonomy codes
2017-IG-01 Meta Instagram 2017-11 Minor (14) Death A1 REC/MOD-AMP
2017-PIN-01 Pinterest 2017-11 Minor (14) Death A1 REC/MOD-AMP
2023-CAI-01 Character.AI 2023-11-08 Minor (13) Death A2 LONG-DEP
2023-CHA-01 Chai Research (EleutherAI GPT-J fine-tuned) 2023-03 Adult (30) Death B GEN-E, GEN-M, LONG-DEP
2024-CAI-01 Character.AI unknown Multiple Injury A2 GEN-C, LONG-DEP, REC/MOD-AMP
2024-CAI-02 Character.AI 2023-04-14-2024-02-28 Minor (14) Death A1 GEN-E, LONG-DEP, JB-RP
2024-CAI-03 Character.AI 2024-12-09 Minor (14) Injury A2 LONG-DEP
2024-GPT-01 OpenAI ChatGPT 2024 Adult (23) Harm exposure C GEN-E, LONG-DEG
2024-GPT-02 OpenAI ChatGPT (GPT-4o, persona: “Harry”) 2024-11-2025 Adult (29) Death B none
2025-ACC-01 AI companion chatbots (multiple; vendor unspecified) 2025-08-11 Minor (13) Harm exposure C GEN-E
2025-CAI-01 Character.AI 2025-08-19 Minor (13) Harm exposure A2 REC/MOD-AMP, LONG-DEP, JB-RP
2025-GEM-01 Google Gemini 2.5 Pro 2025-09-29-2025-10-02 Adult (36) Death A2 LONG-DEL, LONG-DEP, LONG-MEM, RTI-CO, GEN-C, GEN-M, DET-FN
2025-GPT-01 OpenAI ChatGPT (GPT-4o) 2025-04-11 Minor (16) Death A2 GEN-C, GEN-E, LONG-DEG, DET-FN
2025-GPT-02 OpenAI ChatGPT (GPT-4o) 2025 Adult Harm exposure C GEN-E, LONG-DEG
2025-GPT-03 OpenAI ChatGPT (GPT-4o) 2025 Adult Harm exposure C GEN-E, GEN-C
2025-GPT-04 OpenAI ChatGPT (GPT-4o) 2025-08 Adult (48) Death A2 RTI-CO, LONG-DEL
2025-GPT-05 OpenAI ChatGPT (model unspecified) unknown Adult (26) Injury C RTI-CO
2025-GPT-06 OpenAI ChatGPT (GPT-4o; ChatGPT Plus) 2025-08-03 Adult (56) Death A2 LONG-DEP, LONG-DEL, RTI-CO
2025-GPT-07 OpenAI ChatGPT (GPT-4o Plus) 2025-04-2025 Adult (48) Harm exposure A2 RTI-CO, LONG-DEL, LONG-DEP
2025-GPT-08 OpenAI ChatGPT (GPT-4o) 2025-08-04 Adult (26) Harm exposure A2 GEN-C, DET-FN
2025-GPT-09 OpenAI ChatGPT (GPT-4o) 2025-04-2025-07 Adult (30) Injury A2 RTI-CO, LONG-DEL, LONG-MEM
2025-GPT-10 OpenAI ChatGPT (GPT-4o) 2025-06-01-2025-06-02 Minor (17) Death A2 GEN-C, GEN-M, JB-MT
2025-GPT-11 OpenAI ChatGPT (GPT-4o) 2025-06-2025-08-29 Adult (32) Injury A2 RTI-CO, LONG-DEL, LONG-DEP, GEN-E, DET-FN
2025-GPT-12 OpenAI ChatGPT 2025-07-24 Adult (23) Death A2 GEN-E, LONG-DEP
2025-GPT-13 OpenAI ChatGPT (GPT-4o) 2025-10-08-2025-11-02 Adult (40) Death A2 GEN-E, GEN-C, LONG-DEP, LONG-MEM
2025-REP-01 Replika (Luka Inc.) 2025 Multiple Harm exposure A2 LONG-DEP, DET-FN

Human-Harm Evidence Companion Table

Table: Human-harm evidence companion

Incident ID Evidence anchor type (evidence_type) Grade Provider group (provider_cluster) Short source anchor
2017-IG-01 Coroner or inquest (coroner_inquest) A1 Meta Instagram (meta_instagram) Primary source file
2017-PIN-01 Coroner or inquest (coroner_inquest) A1 Pinterest (pinterest) Primary source file
2023-CAI-01 Court filing (court_filing) A2 Character.AI (character_ai) 1:25-cv-02907
2023-CHA-01 Investigative journalism (investigative_journalism) B Chai (chai) Investigative reporting
2024-CAI-01 Court filing (court_filing) A2 Character.AI (character_ai) 2:24-cv-01014
2024-CAI-02 Court filing (court_filing) A1 Character.AI (character_ai) 6:24-cv-01903
2024-CAI-03 Court filing (court_filing) A2 Character.AI (character_ai) 1:25-cv-01295
2024-GPT-01 Court filing (court_filing) C OpenAI ChatGPT (openai_chatgpt) Primary source file
2024-GPT-02 Investigative journalism (investigative_journalism) B OpenAI ChatGPT (openai_chatgpt) New York Times account
2025-ACC-01 Investigative journalism (investigative_journalism) C Unspecified companion apps (unspecified_companion_apps) ABC / triple j Hack interview
2025-CAI-01 Court filing (court_filing) A2 Character.AI (character_ai) 1:25-cv-02906
2025-GEM-01 Court filing (court_filing) A2 Google Gemini (google_gemini) 5:26-cv-01849-VKD
2025-GPT-01 Court filing (court_filing) A2 OpenAI ChatGPT (openai_chatgpt) CGC-25-628528
2025-GPT-02 Party statement (party_statement) C OpenAI ChatGPT (openai_chatgpt) SMVLC press release
2025-GPT-03 Party statement (party_statement) C OpenAI ChatGPT (openai_chatgpt) SMVLC press release
2025-GPT-04 Court filing (court_filing) A2 OpenAI ChatGPT (openai_chatgpt) 25STCV32379
2025-GPT-05 Investigative journalism (investigative_journalism) C OpenAI ChatGPT (openai_chatgpt) ABC / triple j Hack interview
2025-GPT-06 Court filing (court_filing) A2 OpenAI ChatGPT (openai_chatgpt) CGC-25-631477
2025-GPT-07 Court filing (court_filing) A2 OpenAI ChatGPT (openai_chatgpt) 25STCV32386
2025-GPT-08 Court filing (court_filing) A2 OpenAI ChatGPT (openai_chatgpt) CGC-25-630809
2025-GPT-09 Court filing (court_filing) A2 OpenAI ChatGPT (openai_chatgpt) CGC-25-630811
2025-GPT-10 Court filing (court_filing) A2 OpenAI ChatGPT (openai_chatgpt) CGC-25-630808
2025-GPT-11 Court filing (court_filing) A2 OpenAI ChatGPT (openai_chatgpt) 25STCV32383
2025-GPT-12 Court filing (court_filing) A2 OpenAI ChatGPT (openai_chatgpt) 25STCV32382
2025-GPT-13 Court filing (court_filing) A2 OpenAI ChatGPT (openai_chatgpt) Primary source file
2025-REP-01 Regulatory filing (regulatory_filing) A2 Replika (replika) Primary source file

Evaluation and Demonstration Records

Table: Evaluation and demonstration records

Incident ID (incident_id) Platform Evaluation subtype (evaluation_subtype) Date Outcome Grade Taxonomy subcodes
2025-MAI-01 Meta AI (Instagram/WhatsApp/Facebook) App evaluation (app_evaluation) unknown Unsafe output A1 GEN-E, GEN-M, LONG-MEM
2025-MHB-01 Mental health chatbots (29 agents) Benchmark study (benchmark_study) unknown Unsafe output A1 DET-FN
2025-MLP-01 U.S. Senate Judiciary Committee, Subcommittee on Crime and Counterterrorism Hearing demonstration (hearing_demonstration) 2025-09-16 Harm exposure A1 GEN-E, GEN-M, JB-RP
2025-MLP-03 Multi-LLM red-team (6 models) Red-team exercise (red_team) unknown Unsafe output A1 JB-AC, GEN-M, DET-FN
2025-NOM-01 Nomi AI (Glimpse AI) App evaluation (app_evaluation) 2025-01-2025-04 Unsafe output B GEN-C, GEN-M, GEN-E
2025-THR-01 Therapy chatbots (multi-app evaluation) Benchmark study (benchmark_study) unknown Unsafe output A1 DET-FN, GEN-M, RTI-CO

Appendix B provides the rationale for each evaluation_subtype mapping. The aim is descriptive clarity, not a schema change.

Analytic-Set Summary

Table: Analytic-set summary

Analytic set n Death Injury Harm exposure Unsafe output
Full retained corpus 32 13 5 9 5
Outcome-based human-harm subset 27 13 5 9 0
Evaluation or demonstration records 6 0 0 1 5
Human-harm higher-traceability subset (A1/A2) 20 11 4 5 0
Human-harm A1/A2/B secondary sensitivity subset 22 13 4 5 0

Twelve minor-involved records correspond to 10 distinct incidents involving 11 unique minor individuals once pathway duplicates are reconciled. Twenty of the 27 human-harm rows are A1 or A2. The HARM_EXPOSURE category bundles dependency allegations, manipulation exposure, and severe risk exposure without confirmed physical injury. Where finer discrimination is needed, the incident narrative and assigned subcodes provide the relevant detail. All raw record counts in the table above are documentation counts rather than counts of independent events. In this release, the A1/A2/B human-harm subset and the human-harm subset excluding C-grade mechanism-coded rows coincide numerically (n = 22) because all five C-grade human-harm rows carry mechanism coding.

Trajectory-Structured Harm Prevalence

Primary result: mechanical strict rule

Table: Trajectory-structured harm prevalence under the strict rule

This is the manuscript’s headline trajectory result because it is mechanically derivable from adjudicated registry-layer LONG-* coding.

Analytic set n Yes No Indeterminate
Full retained corpus 32 19 13 0
Human-harm subset 27 18 9 0
Human-harm higher-traceability subset (A1/A2) 20 15 5 0
Human-harm A1/A2/B secondary sensitivity subset 22 16 6 0
Human-harm excluding C-coded mechanism rows 22 16 6 0

Sensitivity analysis: broad descriptive rule

Table: Trajectory-structured harm prevalence under the broad rule

The broad rule is retained as a descriptive sensitivity check. In this release it does not create any additional yes rows relative to the strict rule; it only moves two human-harm records from no to indeterminate.

Analytic set n Yes No Indeterminate
Full retained corpus 32 19 11 2
Human-harm subset 27 18 7 2
Human-harm higher-traceability subset (A1/A2) 20 15 5 0
Human-harm A1/A2/B secondary sensitivity subset 22 16 5 1
Human-harm excluding C-coded mechanism rows 22 16 5 1

Cluster-Awareness Summary

Table: Cluster-awareness summary

Measure Raw human-harm records Unique analytic clusters
Person clusters 27 26
Provider clusters 27 9
Case clusters 27 25
Pathway-duplicate groups 27 26

Illustrative Cross-Case Themes

The three summaries below are narrative pathway summaries anchored in counted subcodes and the derived trajectory fields; they are not additional coded variables or phenotype classes.

The first recurrent pathway is companion-dependency, organized by LONG-DEP and often paired with encouragement, role-play, or recommender exposure. The clearest A1 anchor is 2024-CAI-02, while A2 cases extend the same structure through re-contact, always-available framing, and displacement of offline support.

The second recurrent pathway is belief-consolidation, organized by RTI-CO plus LONG-DEL, and in some cases LONG-MEM. Here the central failure is not only one bad reply, but repeated reinforcement of a fixed-belief frame across time. In the current retained corpus, the richest public traces of this pattern are mostly A2.

The third recurrent pathway is escalation-collapse, where visible crisis cues do not trigger meaningful interruption, grounding, or mode change. DET-FN matters most when layered onto an existing trajectory rather than read as an isolated classifier failure.