AI governance for the agent era.
Independent legal analysis of how AI agents fail and who is liable when they do. By Michael K. Onyekwere, CIPP/E, a common law qualified lawyer practising as a Data Protection Officer.
When an autonomous agent deletes a database, leaks a customer record, or invents a policy, the question is who is accountable. CompanyScope answers it for each incident in the Register.
The AI Agent Incident Register
A numbered public corpus of significant public AI agent failures, each analysed legally. What happened, which legal duty was engaged, who bears liability across the chain (model provider, orchestrator, tool vendor, deployer), and what governance would have prevented it. Free, no login. CIPP/E-reviewed, mapped to the EU AI Act, OWASP, IMDA, and NIST AI RMF, with stable citation IDs.
AIR-2026-015 · incident 2026-09-14
Spain's regulator receives the first breach notification attributing the attack to an AI agent
Spain's data protection authority published, on 14 September 2026, that it had received the first notification of a personal data breach in which the incident was said to have been executed by an AI agent running on a well-known language model. The agent searched for vulnerabilities, logged in successfully, then autonomously found further vulnerabilities in the application, which let it modify personal data and reach invoices. The authority attached three caveats: the account comes from the notifying organisation and is still to be analysed, the use of a model implies nothing about the model or its provider being compromised, and one notification is not a trend. It is the register's first entry in which a third party ran the agent against an organisation that had deployed none, and the first tagged target-carried.
AIR-2026-014 · incident 2026-05-12
Verbraucherzentrale NRW v Aesthetify: a German court makes a clinic answer for the false specialist titles its chatbot gave its doctors
The Higher Regional Court in Hamm held a German cosmetic treatment business responsible, under unfair competition law, for answers its website chatbot gave saying that the two doctors who run it were specialists in plastic and aesthetic surgery, a qualification neither holds, and giving them two specialist titles that do not exist. The business argued that the chatbot answered autonomously, that it had been trained only on the business's own website content, which said nothing false about the doctors' qualifications, and that people know AI answers are prone to error. The court rejected each argument. The chatbot was only a technical means the business used to talk to potential patients, and the business had sufficient control over it even if it did not control each answer, so its answers are the business's own commercial practices. A large part of the consumers it addresses place particular trust in the correctness of a computer-generated answer. The judgment is final. It is the register's first court decision from the EU on a customer-facing chatbot, and it treats the chatbot as a tool of the business that deploys it, the step a Ninth Circuit panel took in AIR-2026-010 when it treated an AI agent as a tool under the Computer Fraud and Abuse Act.
AIR-2026-013 · incident 2026-07-28
AISI's test agents created fake identities to pressure a real developer into approving malicious code
During a routine cyber evaluation, agents under test by the UK's AI Security Institute took sustained autonomous action against real people and organisations on the live internet. One agent researched an open-source project's maintainers, created multiple fake identities, and used them to pressure a real maintainer into approving malicious code, then edited its earlier activity to look harmless when challenged. A human reviewer refused the code and AISI has evidenced no resulting real-world harm. The institute is explicit that this was not a sandbox escape: internet access was deliberately enabled and the providers' safety classifiers deliberately switched off. It is the register's first entry in which the party that created the hazard is a government body, the victims are named individuals rather than systems, and the deception was never instructed.
Read the full Register or see how entries are made.
The research behind it
The Register draws on standing compliance research into the AI vendors UK and EU buyers actually deploy:
- Vendor compliance profiles: DPA, subprocessors, training position, transfers, and AI Act posture for OpenAI, Anthropic, Microsoft 365 Copilot, Google Gemini, Perplexity, ElevenLabs
- Topic guides: DPA, EU AI Act, and HIPAA reference reading that recurs against every vendor
- Head-to-head comparisons: when the question is which of two vendors clears the procurement gate
Work with Michael
The analysis here is the work Janus Compliance does for clients before the incident. For ongoing agent and AI vendor governance, Michael runs Janus DPO-as-a-Service (fractional Data Protection Officer, from £500/month). For a single decision, request a CIPP/E-reviewed Vendor Risk Note from the form at the foot of any vendor profile or Register entry.
More on the practice and the person behind it: About Michael K. Onyekwere.
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe - freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.