Agent Incident RegistryAIR

Agent Incident
Registry

Verified agent incidents. Realized harm, kept separate.

A registry of disclosed events involving AI agents: systems that call tools, browse, write code, drive, or act with delegated authority. Every record is verified against a fetched source and coded for who acted, how, what it could touch, whether a safeguard held, and whether real harm followed.

How to read it
Disclosures by quarterstacked by class · click a quarter to open it

Realized harm means a real party suffered real consequences because of an AI agent. A researcher showing that they could is recorded, never counted as harm.

How to read this registry

Four rules that decide what a number here means, and the four colours in every chart.

01 · Verified

Every record has a fetched source

Nothing is written from memory. A record needs a fetched supporting source and a sentence quoted verbatim from it. Secondary-only evidence is marked medium confidence; unverifiable leads are quarantined.

02 · Realized harm

Harm and demonstration are kept apart

A record is marked realized only when a real party suffered real consequences because of an AI agent. A proof of concept against a live system is still a demonstration.

03 · Four classes

In the wild, safety failure, disclosed vulnerability, research demo

Class records how an event surfaced, independently of realized harm. In-the-wild attempts and safety near misses can be unrealized; live-system research can still have consequences.

In the wildSafety failureDisclosed vulnerabilityResearch demo
04 · Citable

Stable ids, permalinks, open exports

Each record is AIR-YYYY-NNNN, minted once and never renumbered. Every id has a permanent link. Think CVE for agent incidents.

What the data says

Three results the registry supports today. Each opens its records; the breakdown below lets you cut the same data yourself.

Cut the data

Click a tile to open the incidents behind it.

Breakdown

Latest additions

    Use the registry

    Built for teams shipping agents, standards bodies and researchers, regulators and insurers, and anyone who needs to check what a source actually says.

    Browse

    Filter and open records

    Filter by class, risk domain, attack surface, autonomy or vendor. Every filtered view and every open record has a shareable URL.

    Cite

    Permanent ids, AIR-YYYY-NNNN

    Or the whole registry:

    Contribute

    Send a source

    Send a supporting source and a sentence on what the agent did. We fetch it, quote it, code the record and mint an id, under the same verification rule we hold ourselves to.

    Read the full description →