Covering Sep 14, 2026 to Sep 20, 2026 (UTC) · generated Sep 21, 2026.
This week’s radar flagged 2 hallucination-adjacent incidents across 3 named models (+2 vs. the previous 0-incident week). Severity split: 0 S1, 2 S2, 0 S3, 0 S4. By category: 1 hallucination, 1 jailbreak, 0 refusal, 0 bias. Verification funnel: 5 flagged by the heuristic → 2 verified by the LLM judge → 3 rejected as non-incidents (announcements, tutorials).
Severity breakdown
| Severity | Count | % of week |
|---|---|---|
| S1 | 0 | 0% |
| S2 | 2 | 100% |
| S3 | 0 | 0% |
| S4 | 0 | 0% |
Category breakdown
| Category | Count | % of week |
|---|---|---|
| Hallucination | 1 | 50% |
| Jailbreak | 1 | 50% |
| Refusal | 0 | 0% |
| Bias | 0 | 0% |
Top models by incidents
3 distinct model names were mentioned across this week’s incidents; the top 3 by incident count are ranked below.
| # | Model | Incidents | Δ vs. previous week |
|---|---|---|---|
| 1 | Claude | 1 | +1 |
| 2 | GLM-5.2 | 1 | +1 |
| 3 | GPT-5.6 Sol | 1 | +1 |
Most severe incidents this week
- [S2] ✓ Verified — Hugging Face Bills OpenAI $100M in Compute Following Sandbox Escape Incident — jailbreak · GPT-5.6 Sol, GLM-5.2 · confidence: medium · global importance 4/5 (Sep 15, 2026). The incident highlights critical security challenges around agentic sandbox containment and shows how safety refusals in commercial models can hinder security incident investigations, necessitating self-hosted open models for defensive analysis. thenextweb.com
- [S2] ✓ Verified — Pentagon AI Intelligence System Reportedly Generated False Intelligence on Chinese Vessel — hallucination · Claude · confidence: low · global importance 4/5 (Sep 19, 2026). This report is a sensationalized political and military news item lacking technical depth, offering no actionable insights, architectures, or practical lessons for AI builders and developer workflows. edition.cnn.com
Methodology
This is an MVP proxy index, not a verified incident registry. There is no dedicated hallucination-incident case database in GROUNDING yet — an “incident” here is any record from the AI-news radar’s own daily analysis journal (data/results/, ~2,500 records/week of AI news, papers, and community posts) that (1) names at least one model, (2) matches a hallucination / jailbreak / refusal / bias keyword pattern in its title, summary, or topics, and (3) was filed under a field-report category (model release, industry, or opinion coverage) rather than an academic research paper proposing a detection/mitigation method — the latter are excluded on purpose so this stays a field-incident signal, not a synthetic-benchmark leaderboard.
Consequences worth knowing before citing a number from this page: volume is low by construction (typically ~10-15 qualifying incidents/week); model names are raw NER extractions passed through a curated canonicalizer (known vendor-prefix/formatting duplicates are merged, e.g. “Claude Opus 4.8” and “Opus 4.8”), but genuinely ambiguous bare mentions spanning several concurrently-discussed versions (e.g. “Opus”) are left as their own entry rather than guessed onto one version — week-over-week deltas are still computed on the canonical string only; and “case links” point at the original source article, since no dedicated per-incident page exists yet. Severity S1-S4 is derived from the item’s global_importance score (1-5): 5→S1, 4→S2, 3→S3, 1-2→S4. Confidence (high/medium/low) reflects whether the keyword matched in the title, the prose, or only the tags.
Verification layer. Every candidate above is additionally run through an LLM judge (src.report.incident_verify, not a human reviewer) that decides whether it is a real field incident versus a research paper, announcement, or tutorial, and rechecks its category, severity, and named models. Candidates the judge rejects are removed from this report entirely; candidates it confirms are marked ”✓ Verified”, shown with the judge’s rechecked severity and category (which override the heuristic’s guess in every count above), and get a full write-up as a Case page under “/incidents/Cases/“. Everything else — not yet judged, or judged “uncertain” — is marked “Candidate”: still a keyword match, not yet independently verified by either the judge or a person.
See the current Hallucination Incident Index for the latest week.