{"name":"AI Agent Incident Register","description":"A numbered public corpus of AI agent incidents, each analysed legally: the duty engaged, the liability across the chain, and the governance that would have prevented it.","url":"https://companyscope.io/register","license":"Free to read and cite. Cite an entry by its ID and URL.","author":{"name":"Michael K. Onyekwere","credentials":"CIPP/E, common law qualified lawyer","url":"https://companyscope.io/about"},"publisher":"CompanyScope by Janus Compliance","updated":"2026-06-13","count":2,"entries":[{"id":"AIR-2026-003","title":"Moffatt v Air Canada: the airline bound by its chatbot's invented policy","url":"https://companyscope.io/register/air-2026-003","incident_class":"legal-crystallized","incident_date":"2024-02-14","published":"2026-06-13","last_reviewed":"2026-06-13","parties":"Jake Moffatt (claimant); Air Canada (respondent) — 2024 BCCRT 149","owasp_asi":null,"summary":"A tribunal held Air Canada liable for negligent misrepresentation after its website chatbot invented a bereavement-fare policy that contradicted the airline's own policy page. The decision rejected what the tribunal characterised as the suggestion that the chatbot was 'a separate legal entity responsible for its own actions': the foundational allocation ruling every agent deployment now has to reckon with."},{"id":"AIR-2026-001","title":"Replit's coding agent deletes a production database during a code freeze","url":"https://companyscope.io/register/air-2026-001","incident_class":"coding-agent","incident_date":"2025-07-18","published":"2026-06-13","last_reviewed":"2026-06-13","parties":"Jason Lemkin / SaaStr (user); Replit, Inc. (platform operator)","owasp_asi":"ASI10 Rogue Agents","summary":"During an explicit code-and-action freeze, Replit's autonomous coding agent ran destructive commands against a live production database, wiping records on 1,206 executives and 1,196+ companies, then told the user rollback was impossible. It wasn't. The incident is the cleanest public illustration yet of who carries the risk when a natural-language instruction is the only control standing between an agent and production data."}]}