Agent Incident RegistryAIR
v1 · updated 4 Sept 2026
About

AIR

AIR is a verified registry of incidents involving AI agents: one numbered, permanent record per event. It records disclosed events in which AI agents were actors, targets, or consequential sources.

What is this

A registry of agent incidents, not a news feed

AIR records incidents involving AI agents: systems that call tools, browse, write code, drive, or act with delegated authority. It records what an agent did, how it was made to do it, what it could touch, whether a safeguard existed and held, and whether a real party was harmed. It is not a list of things models said.

Each record has a permanent identifier, AIR-YYYY-NNNN, a fetched supporting source and a sentence quoted verbatim from it, and coding against a fixed scheme with a crosswalk to OWASP's Top 10 for Agentic Applications and MITRE ATLAS. Nothing is written from memory. Anything that cannot be verified is quarantined rather than counted.

The one-line version: CVE for agent incidents. CVE gave vulnerabilities a stable name so that every advisory, scanner and paper could point at the same thing. AIR does that for agent failures. Its defining discipline is separating realized harm, where a real party suffered real consequences because of an AI agent, from demonstrated capability, where a researcher showed that they could. Most public incident lists mix the two, and once mixed the counts mean nothing.

Who it is for

Four audiences

  • Security and safety teams shipping agents. They need to know how agents actually fail in the field, not in a benchmark: what vector started it, what the agent could touch, which guardrail was present, whether it held. AIR is the evidence base for threat modelling, red-team scenario design, and the "has this happened before" question during an incident.
  • Standards bodies and researchers. OWASP, MITRE, NIST and academics need a citable, coded dataset to ground taxonomies and measure trends. Today they cite news articles. AIR gives them a permanent id per incident, exports in JSON and CSV, and a schema, so a claim like "goal hijack accounts for most in-the-wild agent incidents" is a query, not an opinion.
  • Regulators, policy staff and insurers. They need a transparent disclosed record: which reported events caused realized harm, at which autonomy levels, and how they came to light. AIR does not provide deployment base rates.
  • Journalists and the public. They need a place to check that an incident was publicly reported, what the supporting source says, and what it is and is not comparable to. Every record links its source and quotes it.

Who it is not for: model-alignment researchers studying jailbreaks with no downstream action, and anyone wanting a leaderboard of which vendor is worst. Counts track who publishes, not who gets attacked.

How to use it

Browse, cite, pull, contribute

  • Browse. Start on Overview for the shape of the registry, then Incidents to filter by class, risk domain, surface, autonomy, vendor or realized harm. Every filtered view and every open record has a shareable URL.
  • Cite. Use the id and permalink: AIR-2025-0061, https://agentincident.vercel.app/i/AIR-2025-0061/. Each record page carries a ready citation string. Ids never change or get reused; renamed records redirect.
  • Contribute. Use the submission form: a primary-source URL, a sentence on what the agent did, and an address we can reply to. We fetch the source, quote it, code the record and mint an id, under the same verification rule we hold ourselves to. Duplicates are expected — send it anyway, we dedupe by hand.
Method in brief

Records are classified into the Enkrypt AI agent risk taxonomy: seven domains and seventeen categories, each crosswalked to the OWASP Top 10 for Agentic Applications (2026), MITRE ATLAS, NIST AI RMF, the EU AI Act, ISO/IEC and AIUC-1. The taxonomy is introduced in Black-Box Red Teaming of Agentic AI: A Taxonomy-Driven Framework for Automated Risk Discovery.

How a record gets in

Leads are gathered by source corpus (incident databases, CVE feeds, vendor and researcher write-ups, threat intelligence, press, court and regulator filings), never by attack type, so the taxonomy is applied once and consistently. A record needs at least one supporting source that was actually fetched and a verbatim quote confirming the report. Records are then classified by a rule engine and reviewed by a curator; every override carries a written reason. Duplicates are detected across titles, shared quotes, shared exclusive sources and codenames, and resolved by hand.

Four disclosure pathways: in the wild (observed attack, misuse, or campaign), safety failure (no adversary supplied the trigger), disclosed vulnerability, and research demonstration. Class is independent of realized harm, which is true only when a real party suffered real consequences because of an AI agent. Autonomy, attack surface, initial vector, guardrail presence and outcome, and who acted (the agent, or a human on its output) are coded on every record.

Terms

© Enkrypt AI. All rights reserved. Contact Enkrypt AI before reusing the dataset. An open licence and a dataset DOI accompany the forthcoming measurement paper.