The Agent Incident Registry: Toward Preventing Repeated AI Agent Failures

Divyanshu Kumar, Rohith HN, Nitin Aravind Birur, Sahil Agarwal and Prashanth Harshangi (Anaconda) build the Agent Incident Registry, a source-linked catalog of publicly disclosed AI agent failures labeled by causal role, disclosure class, mechanism and outcome.
Ask this paper
Record design: Each record carries supporting evidence, a stable identifier and missingness-aware labels, and a second human reviewer checked every record and label.
Composition: Realized harm concentrates in in-the-wild and safety-failure records, while responsible disclosures and research demonstrations are mostly demonstrated rather than realized, so the aggregate harm share describes the collection and not deployment risk.
Benchmark audit: InjecAgent's cases cover three of the registry's twelve surfaces and are all attacker-triggered, while the registry also holds safety failures with no adversary that such benchmarks do not test.
Scope: The registry supports case retrieval and auditing of what an evaluation covers, not estimates of failure rates or control efficacy. The arXiv abstract prints unrendered LaTeX macros where the record counts should appear.
Abstract
AI agents increasingly act through tools and delegated authority, but general incident repositories rarely capture the mechanisms needed to compare public failures with agent-security evaluations. We present the Agent Incident Registry (AIR), a source-linked catalog containing \N{} records of agent-related events disclosed from \Yfirst{} through \Ylast{}. Each record includes supporting evidence, a stable identifier, and missingness-aware labels for causal role, disclosure class, mechanism, and outcome. Among the \Nprimary{} generative-system records in which the agent acted, \Rprimary{} involved realized harm (\Pprimary\%). Realized outcomes concentrate in in-the-wild and safety-failure records, while responsible disclosures and research demonstrations are overwhelmingly demonstrated; the aggregate share therefore characterizes collection composition rather than deployment risk. After initial curation, a second human reviewer checked all \N{} records and their existing labels for completeness and correctness. In a deployment-analogue audit, InjecAgent's \NInjecAgentCases{} cases occupy three of AIR's twelve surfaces and are all attacker-triggered, whereas AIR contains \Nsafety{} no-adversary safety failures. AIR supports source-grounded case retrieval and evaluation-scope auditing, not failure-rate or control-efficacy estimation.