cd /news/ai-safety/the-agent-incident-registry-toward-p… · home topics ai-safety article
[ARTICLE · art-127429] src=arxiv.org ↗ pub= topic=ai-safety verified=true sentiment=· neutral

The Agent Incident Registry: Toward Preventing Repeated AI Agent Failures

Researchers introduced the Agent Incident Registry (AIR), a source-linked catalog of agent-related incidents disclosed from a first date through a last date, with each record carrying supporting evidence, a stable identifier, and missingness-aware labels for causal role, disclosure class, mechanism, and outcome. Among the generative-system records in which the agent acted, a subset involved realized harm, and a second human reviewer checked all records and their existing labels for completeness and correctness after initial curation. In a deployment-analogue audit, InjecAgent's cases occupy three of AIR's twelve surfaces and are all attacker-triggered, while AIR contains no-adversary safety failures; the authors state AIR supports source-grounded case retrieval and evaluation-scope auditing, not failure-rate or control-efficacy estimation.

by read1 min views1 publishedSep 12, 2026

arXiv:2609.11030v1 Announce Type: new Abstract: AI agents increasingly act through tools and delegated authority, but general incident repositories rarely capture the mechanisms needed to compare public failures with agent-security evaluations. We present the Agent Incident Registry (AIR), a source-linked catalog containing \N{} records of agent-related events disclosed from \Yfirst{} through \Ylast{}. Each record includes supporting evidence, a stable identifier, and missingness-aware labels for causal role, disclosure class, mechanism, and outcome. Among the \Nprimary{} generative-system records in which the agent acted, \Rprimary{} involved realized harm (\Pprimary%). Realized outcomes concentrate in in-the-wild and safety-failure records, while responsible disclosures and research demonstrations are overwhelmingly demonstrated; the aggregate share therefore characterizes collection composition rather than deployment risk. After initial curation, a second human reviewer checked all \N{} records and their existing labels for completeness and correctness. In a deployment-analogue audit, InjecAgent's \NInjecAgentCases{} cases occupy three of AIR's twelve surfaces and are all attacker-triggered, whereas AIR contains \Nsafety{} no-adversary safety failures. AIR supports source-grounded case retrieval and evaluation-scope auditing, not failure-rate or control-efficacy estimation.

── more in #ai-safety 4 stories · sorted by recency
── more on @agent incident registry 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/the-agent-incident-r…] indexed:0 read:1min 2026-09-12 ·