The Agent Incident Registry: Toward Preventing Repeated AI Agent Failures

arXiv:2609.11030 · cs.AI · Submitted 2026-09-10 · Read on arXiv

cs.AI

Submitted: 2026-09-10

Updated: 2026-09-11

License: http://creativecommons.org/licenses/by-sa/4.0/

The gist: AI agents increasingly act through tools and delegated authority, but general incident repositories rarely capture the mechanisms needed to compare public failures with agent-security evaluations.

Terminology

Abstract

AI agents increasingly act through tools and delegated authority, but general incident repositories rarely capture the mechanisms needed to compare public failures with agent-security evaluations. We present the Agent Incident Registry (AIR), a source-linked catalog containing records of agent-related events disclosed from through. Each record includes supporting evidence, a stable identifier, and missingness-aware labels for causal role, disclosure class, mechanism, and outcome. Among the generative-system records in which the agent acted, involved realized harm (%). Realized outcomes concentrate in in-the-wild and safety-failure records, while responsible disclosures and research demonstrations are overwhelmingly demonstrated; the aggregate share therefore characterizes collection composition rather than deployment risk. After initial curation, a second human reviewer checked all records and their existing labels for completeness and correctness. In a deployment-analogue audit, InjecAgent's cases occupy three of AIR's twelve surfaces and are all attacker-triggered, whereas AIR contains no-adversary safety failures. AIR supports source-grounded case retrieval and evaluation-scope auditing, not failure-rate or control-efficacy estimation.

Related papers