Agent Incident
Registry
Verified agent incidents. Realized harm, kept separate.
A registry of disclosed events involving AI agents: systems that call tools, browse, write code, drive, or act with delegated authority. Every record is verified against a fetched source and coded for who acted, how, what it could touch, whether a safeguard held, and whether real harm followed.
Realized harm means a real party suffered real consequences because of an AI agent. A researcher showing that they could is recorded, never counted as harm.
Three incidents that explain the registry
One agent that acted on its own, one that was made to, and one whose safety layer blocked the wrong thing. Each record carries a class, a realized-harm flag, a fetched source with a verbatim quote, and a permanent id.
How to read this registry
Four rules that decide what a number here means, and the four colours in every chart.
Every record has a fetched source
Nothing is written from memory. A record needs a fetched supporting source and a sentence quoted verbatim from it. Secondary-only evidence is marked medium confidence; unverifiable leads are quarantined.
Harm and demonstration are kept apart
A record is marked realized only when a real party suffered real consequences because of an AI agent. A proof of concept against a live system is still a demonstration.
In the wild, safety failure, disclosed vulnerability, research demo
Class records how an event surfaced, independently of realized harm. In-the-wild attempts and safety near misses can be unrealized; live-system research can still have consequences.
In the wildSafety failureDisclosed vulnerabilityResearch demoStable ids, permalinks, open exports
Each record is AIR-YYYY-NNNN, minted once and never renumbered. Every id has a permanent link. Think CVE for agent incidents.
What the data says
Three results the registry supports today. Each opens its records; the breakdown below lets you cut the same data yourself.
Cut the data
Click a tile to open the incidents behind it.
Latest additions
Use the registry
Built for teams shipping agents, standards bodies and researchers, regulators and insurers, and anyone who needs to check what a source actually says.
Filter and open records
Filter by class, risk domain, attack surface, autonomy or vendor. Every filtered view and every open record has a shareable URL.
Permanent ids, AIR-YYYY-NNNN
Or the whole registry:
Send a source
Send a supporting source and a sentence on what the agent did. We fetch it, quote it, code the record and mint an id, under the same verification rule we hold ourselves to.
Read the full description →| ID | Incident | Class | Harm |
|---|