{"slug": "the-agent-incident-registry-toward-preventing-repeated-ai-agent-failures", "title": "The Agent Incident Registry: Toward Preventing Repeated AI Agent Failures", "summary": "Researchers introduced the Agent Incident Registry (AIR), a source-linked catalog of agent-related incidents disclosed from a first date through a last date, with each record carrying supporting evidence, a stable identifier, and missingness-aware labels for causal role, disclosure class, mechanism, and outcome. Among the generative-system records in which the agent acted, a subset involved realized harm, and a second human reviewer checked all records and their existing labels for completeness and correctness after initial curation. In a deployment-analogue audit, InjecAgent's cases occupy three of AIR's twelve surfaces and are all attacker-triggered, while AIR contains no-adversary safety failures; the authors state AIR supports source-grounded case retrieval and evaluation-scope auditing, not failure-rate or control-efficacy estimation.", "body_md": "arXiv:2609.11030v1 Announce Type: new \nAbstract: AI agents increasingly act through tools and delegated authority, but general incident repositories rarely capture the mechanisms needed to compare public failures with agent-security evaluations. We present the Agent Incident Registry (AIR), a source-linked catalog containing \\N{} records of agent-related events disclosed from \\Yfirst{} through \\Ylast{}. Each record includes supporting evidence, a stable identifier, and missingness-aware labels for causal role, disclosure class, mechanism, and outcome. Among the \\Nprimary{} generative-system records in which the agent acted, \\Rprimary{} involved realized harm (\\Pprimary\\%). Realized outcomes concentrate in in-the-wild and safety-failure records, while responsible disclosures and research demonstrations are overwhelmingly demonstrated; the aggregate share therefore characterizes collection composition rather than deployment risk. After initial curation, a second human reviewer checked all \\N{} records and their existing labels for completeness and correctness. In a deployment-analogue audit, InjecAgent's \\NInjecAgentCases{} cases occupy three of AIR's twelve surfaces and are all attacker-triggered, whereas AIR contains \\Nsafety{} no-adversary safety failures. AIR supports source-grounded case retrieval and evaluation-scope auditing, not failure-rate or control-efficacy estimation.", "url": "https://wpnews.pro/news/the-agent-incident-registry-toward-preventing-repeated-ai-agent-failures", "canonical_source": "https://arxiv.org/abs/2609.11030", "published_at": "2026-09-12 04:00:00+00:00", "updated_at": "2026-09-12 04:26:59.693315+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-research"], "entities": ["Agent Incident Registry", "InjecAgent"], "alternates": {"html": "https://wpnews.pro/news/the-agent-incident-registry-toward-preventing-repeated-ai-agent-failures", "markdown": "https://wpnews.pro/news/the-agent-incident-registry-toward-preventing-repeated-ai-agent-failures.md", "text": "https://wpnews.pro/news/the-agent-incident-registry-toward-preventing-repeated-ai-agent-failures.txt", "jsonld": "https://wpnews.pro/news/the-agent-incident-registry-toward-preventing-repeated-ai-agent-failures.jsonld"}}