Agent Incident registry helps track AI agent failures and harms

The Agent Incident Registry: Toward Preventing Repeated AI Agent Failures

Artificial Intelligence

Summary

AI agents sometimes fail, causing harm or security problems. The authors created the Agent Incident Registry, a detailed catalog of past AI agent failures with evidence and labels about how and why they happened. This registry helps people find real-world examples and compare incidents to improve safety. It does not estimate how often failures happen or how well controls work.

What this means in practice

  • For security teams: Use the Agent Incident Registry to identify and analyze real-world AI agent failures for better threat assessment and mitigation strategies.
  • For ai system operators: Consult the registry to audit and improve deployment practices by comparing incidents involving different failure mechanisms and outcomes.

Authors

Divyanshu Kumar, Rohith HN, Nitin Aravind Birur, Sahil Agarwal, Prashanth Harshangi

Abstract

AI agents increasingly act through tools and delegated authority, but general incident repositories rarely capture the mechanisms needed to compare public failures with agent-security evaluations. We present the Agent Incident Registry (AIR), a source-linked catalog containing \N{} records of agent-related events disclosed from \Yfirst{} through \Ylast{}. Each record includes supporting evidence, a stable identifier, and missingness-aware labels for causal role, disclosure class, mechanism, and outcome. Among the \Nprimary{} generative-system records in which the agent acted, \Rprimary{} involved realized harm (\Pprimary\%). Realized outcomes concentrate in in-the-wild and safety-failure records, while responsible disclosures and research demonstrations are overwhelmingly demonstrated; the aggregate share therefore characterizes collection composition rather than deployment risk. After initial curation, a second human reviewer checked all \N{} records and their existing labels for completeness and correctness. In a deployment-analogue audit, InjecAgent's \NInjecAgentCases{} cases occupy three of AIR's twelve surfaces and are all attacker-triggered, whereas AIR contains \Nsafety{} no-adversary safety failures. AIR supports source-grounded case retrieval and evaluation-scope auditing, not failure-rate or control-efficacy estimation.