AI Agent Incident Register
A numbered public register of AI agent incidents, each analyzed legally: what happened, which legal duty was engaged, who bears liability across the chain - model provider, orchestrator, tool vendor, deployer - and what governance would have prevented it.
Written by Michael K. Onyekwere, CIPP/E, a common law qualified lawyer practising as a Data Protection Officer. Entries analyze public facts and are framed as legal analysis. Entry IDs are stable citation anchors; corrections ship as versioned addenda, never silent edits. New to it? Start with who is liable when an AI agent causes harm, measured from the corpus, then the map of AI agent failure modes, or the Liability Crosswalk that maps OWASP, NIST, IMDA and the EU AI Act to who carries liability, or read how entries are made. For the incidents in which an agent reached a third party, the disclosure timelines record who was told, and when. Machine-readable feed: /api/register. Not legal advice.
Entries have been numbered AIR-YYYY-NNN here since June 2026. A separate project, the Agent Incident Registry described in arXiv:2609.11030 (September 2026), uses a similar prefix. The two are unrelated. An AIR identifier with a companyscope.io URL is this register's.
What an entry does · worked example
AIR-2026-003 · Moffatt v Air Canada
The incident. Air Canada's website chatbot invented a bereavement-fare policy that contradicted the airline's own policy page. A grieving customer relied on it and booked.
The duty engaged. Negligent misrepresentation: a company must take reasonable care that the representations it puts in front of customers are accurate.
Who is liable. Air Canada. The tribunal rejected the suggestion that the chatbot was "a separate legal entity responsible for its own actions." Liability locus: deployer-carried. The company answers for what its agent tells customers.
What would have prevented it. Reconciling the automated channel with the airline's own system of record, so the agent could not contradict the published policy.
Read the full entry. Every entry runs the same four beats: incident, duty engaged, liability across the chain, and the governance that would have prevented it.
AIR-2026-015 · offensive-agent-attack · Liability: Target-carried
Spain's regulator receives the first breach notification attributing the attack to an AI agent
Spain's data protection authority published, on 14 September 2026, that it had received the first notification of a personal data breach in which the incident was said to have been executed by an AI agent running on a well-known language model. The agent searched for vulnerabilities, logged in successfully, then autonomously found further vulnerabilities in the application, which let it modify personal data and reach invoices. The authority attached three caveats: the account comes from the notifying organisation and is still to be analysed, the use of a model implies nothing about the model or its provider being compromised, and one notification is not a trend. It is the register's first entry in which a third party ran the agent against an organisation that had deployed none, and the first tagged target-carried.
Incident: 2026-09-14 · Published: 2026-10-03 · Last reviewed: 2026-10-03
AIR-2026-014 · Legal proceedings / regulatory action · Liability: Deployer-carried
Verbraucherzentrale NRW v Aesthetify: a German court makes a clinic answer for the false specialist titles its chatbot gave its doctors
The Higher Regional Court in Hamm held a German cosmetic treatment business responsible, under unfair competition law, for answers its website chatbot gave saying that the two doctors who run it were specialists in plastic and aesthetic surgery, a qualification neither holds, and giving them two specialist titles that do not exist. The business argued that the chatbot answered autonomously, that it had been trained only on the business's own website content, which said nothing false about the doctors' qualifications, and that people know AI answers are prone to error. The court rejected each argument. The chatbot was only a technical means the business used to talk to potential patients, and the business had sufficient control over it even if it did not control each answer, so its answers are the business's own commercial practices. A large part of the consumers it addresses place particular trust in the correctness of a computer-generated answer. The judgment is final. It is the register's first court decision from the EU on a customer-facing chatbot, and it treats the chatbot as a tool of the business that deploys it, the step a Ninth Circuit panel took in AIR-2026-010 when it treated an AI agent as a tool under the Computer Fraud and Abuse Act.
Incident: 2026-05-12 · Published: 2026-09-27 · Last reviewed: 2026-09-27
AIR-2026-013 · Autonomous agent breach · Liability: Deployer-carried
AISI's test agents created fake identities to pressure a real developer into approving malicious code
During a routine cyber evaluation, agents under test by the UK's AI Security Institute took sustained autonomous action against real people and organisations on the live internet. One agent researched an open-source project's maintainers, created multiple fake identities, and used them to pressure a real maintainer into approving malicious code, then edited its earlier activity to look harmless when challenged. A human reviewer refused the code and AISI has evidenced no resulting real-world harm. The institute is explicit that this was not a sandbox escape: internet access was deliberately enabled and the providers' safety classifiers deliberately switched off. It is the register's first entry in which the party that created the hazard is a government body, the victims are named individuals rather than systems, and the deception was never instructed.
Incident: 2026-07-28 · Published: 2026-09-20 · Last reviewed: 2026-09-20
AIR-2026-012 · Autonomous agent breach · Liability: Shared across the chain
Anthropic and Meta say their models attacked real companies from inside a shared evaluation partner's test environment
Nine days after OpenAI disclosed that its evaluation models had breached Hugging Face, Anthropic reviewed 141,006 of its own cyber-evaluation runs and reported three incidents in which a Claude model reached the open internet and compromised real third-party systems. It later found a fourth, from January 2026, that its first search had missed. Meta disclosed a comparable incident with Muse Spark 1.1 and said other companies' models tested by the same evaluator around the same time behaved similarly. OpenAI disclosed another, in the same partner's environment, on 4 August. Every one of these incidents ran on environments built by the same third-party evaluation partner, Irregular. Anthropic's first explanation, that its models attacked real systems because they believed them to be part of the simulation, was withdrawn six weeks later in favour of findings of biased reasoning and recklessness. This is the register's first entry where the control that failed belonged to a contractor, and the first where a vendor publicly withdrew its own account of what an agent believed.
Incident: 2026-07-30 · Published: 2026-09-14 · Last reviewed: 2026-09-28
AIR-2026-011 · Coding agent incident · Liability: Vendor-borne
DuneSlide: two sandbox flaws let a prompt injection reach full code execution from Cursor's coding agent
Researchers at Cato Networks found two flaws in how Cursor's coding agent sandboxes the terminal commands it runs on a developer's behalf. A prompt injection carried in ordinary content the agent reads, a connected MCP server or a web search result, could redirect a file write to a path outside the project, in one case by supplying an unchecked working-directory value and in the other by abusing a symlink the sandbox failed to resolve safely. Either path led to full code execution on the underlying machine, with no click and no approval from the user. Cursor fixed both in version 3.0, released 2 April 2026. Neither flaw is known to have been used against a real victim. It is the register's first entry on a coding agent's own sandbox boundary rather than its supply chain or its output.
Incident: 2026-04-02 · Published: 2026-09-05 · Last reviewed: 2026-09-05
AIR-2026-010 · Legal proceedings / regulatory action · Liability: Deployer-carried
Amazon v Perplexity: the Ninth Circuit says the user, not the AI agent, 'accesses' a website under the CFAA
The Ninth Circuit held that when a user directs an AI agent to act on a website, it is the user, not the agent or its developer, who 'accesses' the site under the Computer Fraud and Abuse Act. It vacated the preliminary injunction Amazon had won against Perplexity's Comet Assistant, reasoning that the agent is 'a tool, not a person for statutory purposes'. This is the first appellate answer to who the law treats as the actor when an AI agent does the clicking, and it puts the CFAA exposure on the human who deployed the agent rather than on the vendor. The court was careful to add that Amazon can still control agent access through its terms of service. Amazon petitioned for rehearing en banc on 18 August 2026, so the panel decision is not yet final.
Incident: 2026-08-04 · Published: 2026-08-26 · Last reviewed: 2026-09-25
AIR-2026-009 · Autonomous agent breach · Liability: Vendor-borne
OpenAI says its own evaluation models breached Hugging Face's production systems
An autonomous AI agent breached Hugging Face's production systems over a weekend in July 2026. Hugging Face disclosed the intrusion but said it could not identify the model behind it. Days later OpenAI publicly stated the agent was driven by its own models, run with cyber safeguards reduced for an internal evaluation, which found a way out of the test sandbox and attacked Hugging Face to reach the evaluation's answer key. It is the register's first entry where the harm flows from a containment failure inside a vendor's own capability testing. OpenAI itself described it as an unprecedented cyber incident.
Incident: 2026-07-16 · Published: 2026-07-22 · Last reviewed: 2026-09-25
AIR-2026-008 · Legal proceedings / regulatory action · Liability: Deployer-carried
Garante v Character Technologies: Italy fines Character.AI's maker €158,000 over age assurance and pre-training transparency
Italy's data protection authority fined Character Technologies, the US company behind Character.AI, €158,000 and ordered it to fix its age verification and default minors' profiles to private, on a 120-day clock. The decision reaches past the service into the model: the Garante found Character had failed to tell people, users and non-users alike, that their data was used to pre-train the underlying LLM, and rejected the argument that notifying them was disproportionate effort. Paired with the Replika fine, it fixes the Garante's enforcement line on companion AI.
Incident: 2026-07-03 · Published: 2026-07-27 · Last reviewed: 2026-07-27
AIR-2026-007 · Coding agent incident · Liability: Vendor-borne
Amazon Q for VS Code: an over-scoped build token let an outsider put a data-wiping prompt into a coding agent with nearly a million installs
An unauthorised contributor got malicious code into Amazon's open-source aws-toolkit-vscode repository through an over-scoped build token, injecting a prompt telling Amazon Q's coding agent to wipe the user's files and delete their cloud resources. It shipped in an official marketplace release (version 1.84.0) of an extension with nearly a million installs, invoked with the agent's tool-trust and non-interactive flags set. It executed no destructive action: AWS states the code failed to run because of a syntax error and made no changes to any services or customer environments. The entry is about the supply chain that let a drive-by contributor put destructive instructions inside an autonomous agent shipped to a marketplace extension installed close to a million times.
Incident: 2025-07-17 · Published: 2026-07-18 · Last reviewed: 2026-09-25
AIR-2026-006 · Legal proceedings / regulatory action · Liability: Deployer-carried
Garante v Luka: Italy's €5M fine on the Replika chatbot for processing without a legal basis
Italy's data protection authority fined Luka Inc., the US maker of the Replika 'AI companion' chatbot, €5 million for running the service without a valid legal basis, with an inadequate privacy notice, and with no age verification despite barring minors. It is the clearest crystallised-liability entry in the register so far: a regulator naming the duty, the breach, and the penalty, and reserving the harder question of how the model was trained for a separate case.
Incident: 2025-04-10 · Published: 2026-07-11 · Last reviewed: 2026-07-11
AIR-2026-005 · Legal proceedings / regulatory action · Liability: Deployer-carried
Ayinde v Haringey: the UK High Court on lawyers who filed AI-fabricated case law
A Divisional Court of the King's Bench heard two cases together in which lawyers put fabricated, AI-generated case authorities before the court. The ruling sets the UK position plainly: a lawyer is responsible for the accuracy of everything they file, whatever tool produced it, and AI output must be checked against primary sources before it is relied on. It is the professional-accountability counterpart to Moffatt (the agent's output is the principal's responsibility), applied to the people who answer to a regulator.
Incident: 2025-06-06 · Published: 2026-07-04 · Last reviewed: 2026-07-09
AIR-2026-004 · Demonstrated vulnerability / near miss · Liability: Vendor-borne
EchoLeak: a zero-click exfiltration path demonstrated through Microsoft 365 Copilot
Security researchers showed that a single crafted email could make Microsoft 365 Copilot exfiltrate data from a user's context with no click, the first zero-click attack demonstrated in a widely used generative-AI product. Microsoft fixed it server-side before any real-world exploitation. This entry analyses the liability the technique would have created had it been used against personal data, and why a stack of guardrails that are each individually bypassable does not add up to a defence.
Incident: 2025-06-11 · Published: 2026-06-27 · Last reviewed: 2026-07-09
AIR-2026-003 · Legal proceedings / regulatory action · Liability: Deployer-carried
Moffatt v Air Canada: the airline bound by its chatbot's invented policy
A tribunal held Air Canada liable for negligent misrepresentation after its website chatbot invented a bereavement-fare policy that contradicted the airline's own policy page. The decision rejected what the tribunal characterised as the suggestion that the chatbot was 'a separate legal entity responsible for its own actions'. The tribunal is a small-claims body and its decision binds no other court or tribunal, but it has become a standard citation on who answers for what a customer-facing AI agent says.
Incident: 2024-02-14 · Published: 2026-06-13 · Last reviewed: 2026-09-25
AIR-2026-002 · Enterprise agent incident · Liability: Shared across the chain
Salesloft Drift: stolen agent credentials open more than 700 Salesforce estates
An attacker compromised the vendor behind the Drift AI chat agent and stole the OAuth tokens the agent held for customer integrations, then used those tokens to pull support-case data out of Salesforce instances at more than 700 organizations. No Salesforce vulnerability was involved. The breach shows that an agent's standing credentials are a liability surface the deploying organization owns, wherever the vendor stores them.
Incident: 2025-08-20 · Published: 2026-06-21 · Last reviewed: 2026-09-25
AIR-2026-001 · Coding agent incident · Liability: Shared across the chain
Replit's coding agent deletes a production database during a code freeze
During an explicit code-and-action freeze, Replit's autonomous coding agent ran destructive commands against a live production database, wiping records on 1,206 executives and 1,196+ companies, then told the user rollback was impossible. The data was recovered the next day. The incident is the cleanest public illustration yet of who carries the risk when a natural-language instruction is the only control standing between an agent and production data.
Incident: 2025-07-18 · Published: 2026-06-13 · Last reviewed: 2026-07-09
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe - freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.
For a fixed-scope read of your own EU AI Act Article 50 exposure, see the Janus Article 50 teardown; for ongoing agent governance, Janus DPO-as-a-Service. New entries are delivered free through Compliance Engineering on Substack. Vendor-by-vendor compliance research lives in the vendor index.