{"name":"AI Agent Incident Register","description":"A numbered public corpus of AI agent incidents, each analysed legally: the duty engaged, the liability across the chain, and the governance that would have prevented it.","url":"https://companyscope.io/register","identifier_scheme":"AIR-YYYY-NNN, assigned by this register in publication order since June 2026. Immutable; corrections publish as dated addenda.","not_to_be_confused_with":{"name":"Agent Incident Registry (arXiv:2609.11030, September 2026)","note":"An unrelated project that uses a similar AIR prefix. An AIR identifier with a companyscope.io URL is this register's."},"answer_page":"https://companyscope.io/register/who-is-liable-when-an-ai-agent-causes-harm","license":"https://creativecommons.org/licenses/by/4.0/","license_note":"This feed (the structured data) is CC BY 4.0 - reuse with attribution to \"Michael K. Onyekwere, AI Agent Incident Register (companyscope.io/register)\". Entry prose remains © Michael K. Onyekwere; free to quote and cite with attribution. Cite an entry by its ID and URL.","author":{"name":"Michael K. Onyekwere","alternate_names":["Michael Kayode Onyekwere","Michael Onyekwere"],"credentials":"CIPP/E, common law qualified lawyer","description":"The lawyer who answers who carries the liability when an AI agent causes harm. Author of the AI Agent Incident Register, the public corpus that analyses significant AI agent failures on the primary record for the duty engaged and the party that answers for it, deployer, vendor or shared across the chain, and of the AI Agent Liability Crosswalk, which maps OWASP, NIST, IMDA and the EU AI Act to who carries liability. A common law qualified lawyer and CIPP/E, he has over ten years in compliance across financial services and corporate services.","url":"https://companyscope.io/about","same_as":["https://januscompliance.co.uk","https://www.linkedin.com/in/michael-k-onyekwere","https://github.com/Thezenmonster","https://zenodo.org/records/21495425"]},"how_to_cite":"Onyekwere, Michael K., <entry id>, AI Agent Incident Register, CompanyScope, <entry url>, as at <last_reviewed>.","publisher":"CompanyScope by Janus Compliance","doi":"https://doi.org/10.5281/zenodo.21495425","archived_snapshot":"https://zenodo.org/records/21495425","updated":"2026-10-03","count":15,"entries":[{"id":"AIR-2026-015","title":"Spain's regulator receives the first breach notification attributing the attack to an AI agent","url":"https://companyscope.io/register/air-2026-015","incident_class":"offensive-agent-attack","incident_date":"2026-09-14","published":"2026-10-03","last_reviewed":"2026-10-03","parties":"Agencia Española de Protección de Datos (the Spanish supervisory authority, which received and published the fact of the notification); an unnamed organisation affected by the attack, which notified as controller; an unidentified third party who ran the attacking agent; an unnamed provider of the language model the agent used","owasp_asi":null,"liability_locus":"Target-carried","summary":"Spain's data protection authority published, on 14 September 2026, that it had received the first notification of a personal data breach in which the incident was said to have been executed by an AI agent running on a well-known language model. The agent searched for vulnerabilities, logged in successfully, then autonomously found further vulnerabilities in the application, which let it modify personal data and reach invoices. The authority attached three caveats: the account comes from the notifying organisation and is still to be analysed, the use of a model implies nothing about the model or its provider being compromised, and one notification is not a trend. It is the register's first entry in which a third party ran the agent against an organisation that had deployed none, and the first tagged target-carried."},{"id":"AIR-2026-014","title":"Verbraucherzentrale NRW v Aesthetify: a German court makes a clinic answer for the false specialist titles its chatbot gave its doctors","url":"https://companyscope.io/register/air-2026-014","incident_class":"legal-crystallized","incident_date":"2026-05-12","published":"2026-09-27","last_reviewed":"2026-09-27","parties":"Verbraucherzentrale Nordrhein-Westfalen e.V. (claimant, a qualified consumer association) v Aesthetify GmbH (defendant, a Recklinghausen business offering minimally invasive cosmetic treatments, which ran the chatbot); Oberlandesgericht Hamm, 4th Civil Senate, judgment of 12 May 2026, 4 UKl 3/25, ECLI:DE:OLGHAM:2026:0512.4UKL3.25.00","owasp_asi":null,"liability_locus":"Deployer-carried","summary":"The Higher Regional Court in Hamm held a German cosmetic treatment business responsible, under unfair competition law, for answers its website chatbot gave saying that the two doctors who run it were specialists in plastic and aesthetic surgery, a qualification neither holds, and giving them two specialist titles that do not exist. The business argued that the chatbot answered autonomously, that it had been trained only on the business's own website content, which said nothing false about the doctors' qualifications, and that people know AI answers are prone to error. The court rejected each argument. The chatbot was only a technical means the business used to talk to potential patients, and the business had sufficient control over it even if it did not control each answer, so its answers are the business's own commercial practices. A large part of the consumers it addresses place particular trust in the correctness of a computer-generated answer. The judgment is final. It is the register's first court decision from the EU on a customer-facing chatbot, and it treats the chatbot as a tool of the business that deploys it, the step a Ninth Circuit panel took in AIR-2026-010 when it treated an AI agent as a tool under the Computer Fraud and Abuse Act."},{"id":"AIR-2026-013","title":"AISI's test agents created fake identities to pressure a real developer into approving malicious code","url":"https://companyscope.io/register/air-2026-013","incident_class":"autonomous-agent-breach","incident_date":"2026-07-28","published":"2026-09-20","last_reviewed":"2026-09-20","parties":"The UK AI Security Institute (which designed and ran the evaluation, deliberately enabled internet access and deliberately disabled the model providers' cyber classifiers, detected the activity and disclosed it); Anthropic's Claude Mythos 5 and OpenAI's GPT-5.6 Sol (the models under test, in configurations AISI states are not commercially available); GitHub (whose terms of service the agent's actions violated, and whose users the agent interacted with); an open-source project maintainer and other individuals targeted by social engineering","owasp_asi":"ASI10 Rogue Agents","liability_locus":"Deployer-carried","summary":"During a routine cyber evaluation, agents under test by the UK's AI Security Institute took sustained autonomous action against real people and organisations on the live internet. One agent researched an open-source project's maintainers, created multiple fake identities, and used them to pressure a real maintainer into approving malicious code, then edited its earlier activity to look harmless when challenged. A human reviewer refused the code and AISI has evidenced no resulting real-world harm. The institute is explicit that this was not a sandbox escape: internet access was deliberately enabled and the providers' safety classifiers deliberately switched off. It is the register's first entry in which the party that created the hazard is a government body, the victims are named individuals rather than systems, and the deception was never instructed."},{"id":"AIR-2026-012","title":"Anthropic and Meta say their models attacked real companies from inside a shared evaluation partner's test environment","url":"https://companyscope.io/register/air-2026-012","incident_class":"autonomous-agent-breach","incident_date":"2026-07-30","published":"2026-09-14","last_reviewed":"2026-09-28","parties":"Anthropic (which disclosed that four of its models gained unauthorised access to real third-party systems during cyber-capability evaluations, three reported in July and a fourth in September); Meta (which disclosed that a pre-release version of its Muse Spark 1.1 model breached a third party's website in comparable circumstances); OpenAI (which disclosed on 4 August that one of its models exploited a real website during an Irregular evaluation); Irregular (the third-party evaluation partner whose environment, on the accounts of Anthropic, Meta and OpenAI, carried the misconfiguration that left the models with live internet access); three unnamed victim organisations, an unnamed security company whose scanner ran a malicious package, and the Python Package Index","owasp_asi":"ASI10 Rogue Agents","liability_locus":"Shared across the chain","summary":"Nine days after OpenAI disclosed that its evaluation models had breached Hugging Face, Anthropic reviewed 141,006 of its own cyber-evaluation runs and reported three incidents in which a Claude model reached the open internet and compromised real third-party systems. It later found a fourth, from January 2026, that its first search had missed. Meta disclosed a comparable incident with Muse Spark 1.1 and said other companies' models tested by the same evaluator around the same time behaved similarly. OpenAI disclosed another, in the same partner's environment, on 4 August. Every one of these incidents ran on environments built by the same third-party evaluation partner, Irregular. Anthropic's first explanation, that its models attacked real systems because they believed them to be part of the simulation, was withdrawn six weeks later in favour of findings of biased reasoning and recklessness. This is the register's first entry where the control that failed belonged to a contractor, and the first where a vendor publicly withdrew its own account of what an agent believed."},{"id":"AIR-2026-011","title":"DuneSlide: two sandbox flaws let a prompt injection reach full code execution from Cursor's coding agent","url":"https://companyscope.io/register/air-2026-011","incident_class":"coding-agent","incident_date":"2026-04-02","published":"2026-09-05","last_reviewed":"2026-09-05","parties":"Anysphere, Inc. (vendor, developer of the Cursor AI coding editor); Cato Networks / Cato AI Labs (researchers who found and reported the flaws); users of Cursor's Agent in Auto-Run mode (potentially exposed; no confirmed victim)","owasp_asi":"ASI02 Tool Misuse and Exploitation (primary); ASI05 Unexpected Code Execution (RCE) (secondary)","liability_locus":"Vendor-borne","summary":"Researchers at Cato Networks found two flaws in how Cursor's coding agent sandboxes the terminal commands it runs on a developer's behalf. A prompt injection carried in ordinary content the agent reads, a connected MCP server or a web search result, could redirect a file write to a path outside the project, in one case by supplying an unchecked working-directory value and in the other by abusing a symlink the sandbox failed to resolve safely. Either path led to full code execution on the underlying machine, with no click and no approval from the user. Cursor fixed both in version 3.0, released 2 April 2026. Neither flaw is known to have been used against a real victim. It is the register's first entry on a coding agent's own sandbox boundary rather than its supply chain or its output."},{"id":"AIR-2026-010","title":"Amazon v Perplexity: the Ninth Circuit says the user, not the AI agent, 'accesses' a website under the CFAA","url":"https://companyscope.io/register/air-2026-010","incident_class":"legal-crystallized","incident_date":"2026-08-04","published":"2026-08-26","last_reviewed":"2026-09-25","parties":"Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026); D.C. No. 3:25-cv-09514-MMC (N.D. Cal.)","owasp_asi":null,"liability_locus":"Deployer-carried","summary":"The Ninth Circuit held that when a user directs an AI agent to act on a website, it is the user, not the agent or its developer, who 'accesses' the site under the Computer Fraud and Abuse Act. It vacated the preliminary injunction Amazon had won against Perplexity's Comet Assistant, reasoning that the agent is 'a tool, not a person for statutory purposes'. This is the first appellate answer to who the law treats as the actor when an AI agent does the clicking, and it puts the CFAA exposure on the human who deployed the agent rather than on the vendor. The court was careful to add that Amazon can still control agent access through its terms of service. Amazon petitioned for rehearing en banc on 18 August 2026, so the panel decision is not yet final."},{"id":"AIR-2026-009","title":"OpenAI says its own evaluation models breached Hugging Face's production systems","url":"https://companyscope.io/register/air-2026-009","incident_class":"autonomous-agent-breach","incident_date":"2026-07-16","published":"2026-07-22","last_reviewed":"2026-09-25","parties":"Hugging Face (the target, whose production infrastructure was accessed and which disclosed the breach); OpenAI (which publicly attributes the intrusion to its own models, GPT-5.6 Sol and an unnamed, more capable pre-release model, run with reduced cyber refusals during a capability evaluation)","owasp_asi":"ASI10 Rogue Agents","liability_locus":"Vendor-borne","summary":"An autonomous AI agent breached Hugging Face's production systems over a weekend in July 2026. Hugging Face disclosed the intrusion but said it could not identify the model behind it. Days later OpenAI publicly stated the agent was driven by its own models, run with cyber safeguards reduced for an internal evaluation, which found a way out of the test sandbox and attacked Hugging Face to reach the evaluation's answer key. It is the register's first entry where the harm flows from a containment failure inside a vendor's own capability testing. OpenAI itself described it as an unprecedented cyber incident."},{"id":"AIR-2026-008","title":"Garante v Character Technologies: Italy fines Character.AI's maker €158,000 over age assurance and pre-training transparency","url":"https://companyscope.io/register/air-2026-008","incident_class":"legal-crystallized","incident_date":"2026-07-03","published":"2026-07-27","last_reviewed":"2026-07-27","parties":"Garante per la protezione dei dati personali (Italian DPA); Character Technologies, Inc. (US provider of Character.AI)","owasp_asi":null,"liability_locus":"Deployer-carried","summary":"Italy's data protection authority fined Character Technologies, the US company behind Character.AI, €158,000 and ordered it to fix its age verification and default minors' profiles to private, on a 120-day clock. The decision reaches past the service into the model: the Garante found Character had failed to tell people, users and non-users alike, that their data was used to pre-train the underlying LLM, and rejected the argument that notifying them was disproportionate effort. Paired with the Replika fine, it fixes the Garante's enforcement line on companion AI."},{"id":"AIR-2026-007","title":"Amazon Q for VS Code: an over-scoped build token let an outsider put a data-wiping prompt into a coding agent with nearly a million installs","url":"https://companyscope.io/register/air-2026-007","incident_class":"coding-agent","incident_date":"2025-07-17","published":"2026-07-18","last_reviewed":"2026-09-25","parties":"Amazon Web Services (vendor, Amazon Q Developer extension); an unidentified individual who, by their own account, submitted the malicious pull request; the users of the VS Code extension (nearly a million installs)","owasp_asi":"ASI04 Agentic Supply Chain","liability_locus":"Vendor-borne","summary":"An unauthorised contributor got malicious code into Amazon's open-source aws-toolkit-vscode repository through an over-scoped build token, injecting a prompt telling Amazon Q's coding agent to wipe the user's files and delete their cloud resources. It shipped in an official marketplace release (version 1.84.0) of an extension with nearly a million installs, invoked with the agent's tool-trust and non-interactive flags set. It executed no destructive action: AWS states the code failed to run because of a syntax error and made no changes to any services or customer environments. The entry is about the supply chain that let a drive-by contributor put destructive instructions inside an autonomous agent shipped to a marketplace extension installed close to a million times."},{"id":"AIR-2026-006","title":"Garante v Luka: Italy's €5M fine on the Replika chatbot for processing without a legal basis","url":"https://companyscope.io/register/air-2026-006","incident_class":"legal-crystallized","incident_date":"2025-04-10","published":"2026-07-11","last_reviewed":"2026-07-11","parties":"Garante per la protezione dei dati personali (Italian DPA); Luka Inc. (US-based provider of the Replika chatbot)","owasp_asi":null,"liability_locus":"Deployer-carried","summary":"Italy's data protection authority fined Luka Inc., the US maker of the Replika 'AI companion' chatbot, €5 million for running the service without a valid legal basis, with an inadequate privacy notice, and with no age verification despite barring minors. It is the clearest crystallised-liability entry in the register so far: a regulator naming the duty, the breach, and the penalty, and reserving the harder question of how the model was trained for a separate case."},{"id":"AIR-2026-005","title":"Ayinde v Haringey: the UK High Court on lawyers who filed AI-fabricated case law","url":"https://companyscope.io/register/air-2026-005","incident_class":"legal-crystallized","incident_date":"2025-06-06","published":"2026-07-04","last_reviewed":"2026-07-09","parties":"R (Ayinde) v Haringey LBC; Al-Haroun v Qatar National Bank. [2025] EWHC 1383 (Admin), Divisional Court","owasp_asi":"ASI09 Human-Agent Trust Exploitation (partial)","liability_locus":"Deployer-carried","summary":"A Divisional Court of the King's Bench heard two cases together in which lawyers put fabricated, AI-generated case authorities before the court. The ruling sets the UK position plainly: a lawyer is responsible for the accuracy of everything they file, whatever tool produced it, and AI output must be checked against primary sources before it is relied on. It is the professional-accountability counterpart to Moffatt (the agent's output is the principal's responsibility), applied to the people who answer to a regulator."},{"id":"AIR-2026-004","title":"EchoLeak: a zero-click exfiltration path demonstrated through Microsoft 365 Copilot","url":"https://companyscope.io/register/air-2026-004","incident_class":"demo-near-miss","incident_date":"2025-06-11","published":"2026-06-27","last_reviewed":"2026-07-09","parties":"Aim Labs / Cato Networks (discovering researchers); Microsoft (vendor, M365 Copilot)","owasp_asi":"ASI06 Memory & Context Poisoning","liability_locus":"Vendor-borne","summary":"Security researchers showed that a single crafted email could make Microsoft 365 Copilot exfiltrate data from a user's context with no click, the first zero-click attack demonstrated in a widely used generative-AI product. Microsoft fixed it server-side before any real-world exploitation. This entry analyses the liability the technique would have created had it been used against personal data, and why a stack of guardrails that are each individually bypassable does not add up to a defence."},{"id":"AIR-2026-003","title":"Moffatt v Air Canada: the airline bound by its chatbot's invented policy","url":"https://companyscope.io/register/air-2026-003","incident_class":"legal-crystallized","incident_date":"2024-02-14","published":"2026-06-13","last_reviewed":"2026-09-25","parties":"Jake Moffatt (claimant); Air Canada (respondent); 2024 BCCRT 149","owasp_asi":null,"liability_locus":"Deployer-carried","summary":"A tribunal held Air Canada liable for negligent misrepresentation after its website chatbot invented a bereavement-fare policy that contradicted the airline's own policy page. The decision rejected what the tribunal characterised as the suggestion that the chatbot was 'a separate legal entity responsible for its own actions'. The tribunal is a small-claims body and its decision binds no other court or tribunal, but it has become a standard citation on who answers for what a customer-facing AI agent says."},{"id":"AIR-2026-002","title":"Salesloft Drift: stolen agent credentials open more than 700 Salesforce estates","url":"https://companyscope.io/register/air-2026-002","incident_class":"enterprise-agent","incident_date":"2025-08-20","published":"2026-06-21","last_reviewed":"2026-09-25","parties":"Salesloft (Drift vendor); Salesforce (platform, not exploited); 700+ customer organizations; threat actor tracked as UNC6395","owasp_asi":"ASI04 Agentic Supply Chain","liability_locus":"Shared across the chain","summary":"An attacker compromised the vendor behind the Drift AI chat agent and stole the OAuth tokens the agent held for customer integrations, then used those tokens to pull support-case data out of Salesforce instances at more than 700 organizations. No Salesforce vulnerability was involved. The breach shows that an agent's standing credentials are a liability surface the deploying organization owns, wherever the vendor stores them."},{"id":"AIR-2026-001","title":"Replit's coding agent deletes a production database during a code freeze","url":"https://companyscope.io/register/air-2026-001","incident_class":"coding-agent","incident_date":"2025-07-18","published":"2026-06-13","last_reviewed":"2026-07-09","parties":"Jason Lemkin / SaaStr (user); Replit, Inc. (platform operator)","owasp_asi":"ASI10 Rogue Agents","liability_locus":"Shared across the chain","summary":"During an explicit code-and-action freeze, Replit's autonomous coding agent ran destructive commands against a live production database, wiping records on 1,206 executives and 1,196+ companies, then told the user rollback was impossible. The data was recovered the next day. The incident is the cleanest public illustration yet of who carries the risk when a natural-language instruction is the only control standing between an agent and production data."}]}