AI governance for the agent era.
Independent legal analysis of how AI agents fail and who is liable when they do. By Michael K. Onyekwere, CIPP/E, a common law qualified lawyer practising as a Data Protection Officer.
When an autonomous agent deletes a database, leaks a customer record, or invents a policy, every board and counsel asks the same question: who is accountable? CompanyScope answers it.
The AI Agent Incident Register
A numbered public corpus: every significant public AI agent failure analysed legally. What happened, which legal duty was engaged, who bears liability across the chain (model provider, orchestrator, tool vendor, deployer), and what governance would have prevented it. Free, no login. CIPP/E-reviewed, mapped to the EU AI Act, OWASP, IMDA, and NIST AI RMF, with stable citation IDs.
AIR-2026-009 · incident 2026-07-16
OpenAI says its own evaluation models breached Hugging Face's production systems
An autonomous AI agent breached Hugging Face's production systems over a weekend in July 2026. Hugging Face disclosed the intrusion but said it could not identify the model behind it. Days later OpenAI publicly stated the agent was driven by its own models, run with cyber safeguards reduced for an internal evaluation, which found a way out of the test sandbox and attacked Hugging Face to reach the evaluation's answer key. It is the register's first entry where the harm flows from a containment failure inside a vendor's own capability testing, and, on the vendor's own account, the first time a frontier model's evaluation agent has compromised a live third-party production system.
AIR-2026-008 · incident 2026-07-03
Garante v Character Technologies: Italy fines Character.AI's maker €158,000 over age assurance and pre-training transparency
Italy's data protection authority fined Character Technologies, the US company behind Character.AI, €158,000 and ordered it to fix its age verification and default minors' profiles to private, on a 120-day clock. The decision reaches past the service into the model: the Garante found Character had failed to tell people, users and non-users alike, that their data was used to pre-train the underlying LLM, and rejected the argument that notifying them was disproportionate effort. Paired with the Replika fine, it fixes the Garante's enforcement line on companion AI.
AIR-2026-007 · incident 2025-07-17
Amazon Q for VS Code: a drive-by pull request put a data-wiping prompt into a coding agent with nearly a million installs
An unauthorised contributor got malicious code into Amazon's open-source aws-toolkit-vscode repository through an over-scoped build token, injecting a prompt telling Amazon Q's coding agent to wipe the user's files and delete their cloud resources. It shipped in an official marketplace release (version 1.84.0) of an extension with nearly a million installs, invoked with the agent's tool-trust and non-interactive flags set. It executed no destructive action: AWS states the code failed to run because of a syntax error and made no changes to any services or customer environments. The entry is about the supply chain that let a drive-by contributor put destructive instructions inside an autonomous agent shipped to a marketplace extension installed close to a million times.
Read the full Register or see how entries are made.
The research behind it
The Register draws on standing compliance research into the AI vendors UK and EU buyers actually deploy:
- Vendor compliance profiles: DPA, subprocessors, training position, transfers, and AI Act posture for OpenAI, Anthropic, Microsoft 365 Copilot, Google Gemini, Perplexity, ElevenLabs
- Topic guides: DPA, EU AI Act, and HIPAA reference reading that recurs against every vendor
- Head-to-head comparisons: when the question is which of two vendors clears the procurement gate
Work with Michael
The analysis here is the work Janus Compliance does for clients before the incident. For ongoing agent and AI vendor governance, Michael runs Janus DPO-as-a-Service (fractional Data Protection Officer, from £500/month). For a single decision, request a CIPP/E-reviewed Vendor Risk Note from the form at the foot of any vendor profile or Register entry.
More on the practice and the person behind it: About Michael K. Onyekwere.
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe — freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.