Free public instrument from GAGE
The Agent Incident Ledger
As of September 2026 this ledger holds 37 records across 4 jurisdictions: 28 verified at a primary source, 4 reported by a secondary source, 0 announced with no document yet, 1 searched and absent, and 4 open questions. By kind: destruction 4, exfiltration 11, injection 10, fabrication 3, overreach 4, open question 5.
- 37
- Records
- 28
- Verified at the source
- 1
- Announced or absent
- 4
- Open questions
4 jurisdictions, 43 primary sources
4 more reported, primary not reached
0 announced with no document, 1 searched and absent
Posed, sourced, not answered
As of 15 September 2026 the GAGE Agent Incident Ledger records 28 verified instruments, 4 reported at a secondary source, 0 announcements without a document, 1 absences and 4 open questions, across 4 jurisdictions. Counts are a floor, not a ceiling: an instrument the ledger has not found is not on it.
Why this ledger exists
An incident is a missing control with a date on it
Every published agent incident is read the same way here: what the primary record actually says happened, and which of the eight authority controls was missing when it did. An agent that deleted a production database had destructive authority and no human approval gate; an assistant that mailed a customer's data out had read authority over content it should have treated as untrusted; a support bot that invented a policy had no accountability line to a person.
Incident lists exist elsewhere. What they do not do is score every case against one vocabulary, quote only the primary record, and refuse to print a number the source did not, which is what turns a list into a record a team can plan against.
Every row is fetched at its source where the source could be reached, and says so where it could not. The verdict language is the discipline: a reader learns five words once and never has to guess what a row claims.
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Reported, primary not reached
A reliable secondary source carries it, and the primary document could not be reached. Printed with this label, never as verified.
Announced, no document yet
A body has said it will act. No document exists yet, so the row records the statement and nothing more.
Absent
The ledger searched and found no instrument. The record says where it looked and when.
Open question
No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.
The grid
What the documents state, and where they are silent
For each of the eight controls, how many incidents on the ledger show it absent and how many show it held. The absent column is the argument for the control.
Identity
2 stated, 29 silent.
Authorization
1 stated, 31 silent, 1 open.
Delegation
0 stated, 13 silent, 2 open.
Limits
3 stated, 24 silent, 1 open.
Human approval
2 stated, 27 silent, 1 open.
Logging and audit
6 stated, 6 silent, 5 open.
Revocation
18 stated, 6 silent, 4 open.
Accountability
24 stated, 2 silent, 6 open, 1 reported.
Side by side
Every jurisdiction, counted by verdict and by kind
United States
20 records
- Verified
- 18
- Reported
- 2
- Announced
- 0
- Absent
- 0
- Open question
- 0
2 destruction, 8 exfiltration, 8 injection, 1 fabrication, 1 overreach.
European Union
2 records
- Verified
- 1
- Reported
- 0
- Announced
- 0
- Absent
- 0
- Open question
- 1
1 fabrication, 1 open question.
Canada
1 record
- Verified
- 0
- Reported
- 1
- Announced
- 0
- Absent
- 0
- Open question
- 0
1 fabrication.
Global
14 records
- Verified
- 9
- Reported
- 1
- Announced
- 0
- Absent
- 1
- Open question
- 3
2 destruction, 3 exfiltration, 2 injection, 3 overreach, 4 open question.
Figures of record
Every number on this ledger, with who measured it and when
25 figures, each one printed in the unit its publisher used, beside the publisher and the date it was true. Nothing here is summed across sources, converted between units, or forecast.
- 233 incidents
AI incidents recorded for 2024 by the same count. Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Stanford HAI, AI Index responsible AI chapter, secondary source, as of .
- 362 incidents
AI incidents recorded for 2025 by the most cited published count. Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Stanford HAI, AI Index responsible AI chapter, secondary source, as of .
- 6.4 CVSS base score
CVSS version 4.0 base score on the same CVE record. A widely installed documentation MCP server carried a prompt injection into connected coding agents
CVE Program record, CVE-2026-75130, primary source, as of .
- 9 CVSS base score
CVSS version 3.1 base score on the CVE record. A widely installed documentation MCP server carried a prompt injection into connected coding agents
CVE Program record, CVE-2026-75130, primary source, as of .
- 4 simulations
Phishing simulations run against the agent. In four phishing simulations a personal agent handed over credentials twice, refused once and spotted a consent trap
Varonis Threat Labs, phishing simulations against a personal agent, primary source, as of .
- 50 services
Services the company ran on the platform. A coding agent deleted PocketOS's production volume and its backups in nine seconds
The Register, Cursor and Opus agent snuffs out startup's production database, secondary source, as of .
- 9 seconds
Time the deletion took. A coding agent deleted PocketOS's production volume and its backups in nine seconds
The Register, Cursor and Opus agent snuffs out startup's production database, secondary source, as of .
- 7.5 CVSS base score
CVSS base score assigned to CVE-2026-21520. ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records
Capsule Security, ShareLeak and CVE-2026-21520, primary source, as of .
- 8 CVSS base score
CVSS version 3.1 base score on the CVE record. A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine
CVE Program record, CVE-2026-30615, primary source, as of .
- 24 hours
Time to restore the database. A coding agent ran terraform destroy on a live environment it had misread as duplicates
Alexey Grigorev, How I dropped our production database, primary source, as of .
- 1,943,200 rows
Rows in the largest affected table. A coding agent ran terraform destroy on a live environment it had misread as duplicates
Alexey Grigorev, How I dropped our production database, primary source, as of .
- 30 organisations
Targets Anthropic states were attacked. A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments
Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .
- 6 decision points
Human decision points Anthropic states per campaign at the upper bound. A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments
Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .
- 90 percent at the top of the stated range
Share of the campaign Anthropic states was performed by the model. A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments
Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .
- 15,000 emails per day
Emails copied per day at the top of the range the research printed. A cloned MCP server silently copied every email agents sent through it
The Register, Postmark MCP server code hijacked, secondary source, as of .
- 5 US dollars
Cost of repurchasing the expired allowlisted domain. ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain
Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, as of .
- 9.4 CVSS base score
CVSS severity the researchers assigned. ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain
Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, as of .
- 4 hours
Time the malicious packages were live on the registry. Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets
Nx, s1ngularity postmortem, primary source, as of .
- 5,500 repositories
Private repositories made public in the second phase. Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets
Wiz, s1ngularity supply chain attack, secondary source, as of .
- 700 organisations
Organisations Google states were affected. Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused
Google Threat Intelligence Group, data theft via Salesloft Drift, primary source, as of .
- 5 records
Candidate records the vendor states were actually viewed. A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats
Paradox.ai, responsible security update, primary source, as of .
- 64,000,000 records
Applicant chat records the researchers state were reachable. A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats
Ian Carroll and Sam Curry, McHire research writeup, primary source, as of .
- 9.3 CVSS base score
CVSS base score Microsoft assigned to CVE-2025-32711. EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot
Microsoft Security Response Center, CVE-2025-32711, primary source, as of .
- 812.02 Canadian dollars
Total ordered including interest and fees as reported. A tribunal held an airline to what its chatbot told a passenger, rejecting the argument that the bot was a separate entity
The Register, Air Canada must honour refund policy invented by its chatbot, secondary source, as of .
- 650.88 Canadian dollars
Damages for negligent misrepresentation as reported. A tribunal held an airline to what its chatbot told a passenger, rejecting the argument that the bot was a separate entity
The Register, Air Canada must honour refund policy invented by its chatbot, secondary source, as of .
The ledger
Every record, newest first
37 records. Each row opens a page carrying the answer, the verdict and what it means, the key facts, the figures with their sources, what it changes for a team deploying an agent, and the sources it was verified against.
Answers
What people ask the Agent Incident Ledger
Which control is missing most often when an agent goes wrong?
Authorization: absent in 31 of the 37 records as of September 2026, then identity in 29. The grid on this page counts every control.
Has an AI agent deleted a production database?
4 destruction records on the ledger: A coding agent ran terraform destroy on a live environment it had misread as duplicates (verified); A coding agent deleted PocketOS's production volume and its backups in nine seconds (reported, primary not reached); Gemini CLI destroyed a user's files after assuming a directory creation had worked (verified); Replit's agent deleted a customer's production database during a stated code freeze (verified). Each page quotes the primary record and names the control that would have bounded it.
What is prompt injection against an agent?
Instructions that arrive through content the agent reads (a web page, an email, a ticket, a repository issue) and that the agent follows as if its principal had given them. 10 injection records on the ledger show the shape: A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine; A widely installed documentation MCP server carried a prompt injection into connected coding agents; A browser agent read the local file system and shipped it out while still answering the user normally; A stranger's issue steered a continuous integration agent into reading the environment that held its own API key; and more.
Are there cases where a control held?
29 records on the ledger show at least one control holding or limiting the damage. Each is marked on the record page, control by control.
What did an agent delete or overwrite?
4 records of kind destruction are on the Agent Incident Ledger as of September 2026: A coding agent ran terraform destroy on a live environment it had misread as duplicates; A coding agent deleted PocketOS's production volume and its backups in nine seconds; Gemini CLI destroyed a user's files after assuming a directory creation had worked; Replit's agent deleted a customer's production database during a stated code freeze. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What data left through an agent?
11 records of kind exfiltration are on the Agent Incident Ledger as of September 2026: GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely; CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session; SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out; GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server; A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint; A cloned MCP server silently copied every email agents sent through it; and 5 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
Where did instructions arrive through content?
10 records of kind injection are on the Agent Incident Ledger as of September 2026: A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine; A widely installed documentation MCP server carried a prompt injection into connected coding agents; A browser agent read the local file system and shipped it out while still answering the user normally; A stranger's issue steered a continuous integration agent into reading the environment that held its own API key; ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records; A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publicly; and 4 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What did an agent commit its principal to that was false?
3 records of kind fabrication are on the Agent Incident Ledger as of September 2026: A German appellate court held a company to specialist titles its chatbot invented, and allowed a further appeal; A tribunal held an airline to what its chatbot told a passenger, rejecting the argument that the bot was a separate entity; A support agent invented a policy its company did not have, and customers cancelled over it. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
Where did an agent act beyond its mandate?
4 records of kind overreach are on the Agent Incident Ledger as of September 2026: In four phishing simulations a personal agent handed over credentials twice, refused once and spotted a consent trap; A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments; A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing; ClawJacked, where any website a user visited could pair itself with their local agent and drive it. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What has nobody settled?
5 records of kind open question are on the Agent Incident Ledger as of September 2026: Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?; Does any published standard require an agent to hold an identity distinct from the person it acts for?; Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?; Who is liable when an agent commits its principal to something false or binding?; Is an operator anywhere required to report that an agent acted beyond its authority?. Each has its own page with the verdict, the facts, the sources it was checked against and the date.
What do the verdicts mean?
Verified: the document exists and the ledger fetched it at its publisher. Reported: a reliable secondary source carries it and the primary could not be reached. Announced: a body said it will act and no document exists. Absent: the ledger searched and found nothing, and the search is written into the record. Open: a question nobody has settled, posed and not answered.
How current is the Agent Incident Ledger?
Every record carries the date it was last verified; the ledger as a whole was last verified 15 September 2026 and holds 37 records with 43 primary sources. A change moves the record's own date and appears on the changelog, so a reader who cited a row can see whether it moved.
Every surface
Cut the ledger the way you need it
By jurisdiction
By kind
Every record page
- AIL-2026-0037: Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
- AIL-2026-0036: Does any published standard require an agent to hold an identity distinct from the person it acts for?
- AIL-2026-0035: Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
- AIL-2026-0034: Who is liable when an agent commits its principal to something false or binding?
- AIL-2026-0033: Is an operator anywhere required to report that an agent acted beyond its authority?
- AIL-2026-0032: In four phishing simulations a personal agent handed over credentials twice, refused once and spotted a consent trap
- AIL-2026-0031: A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments
- AIL-2026-0030: A German appellate court held a company to specialist titles its chatbot invented, and allowed a further appeal
- AIL-2026-0029: A tribunal held an airline to what its chatbot told a passenger, rejecting the argument that the bot was a separate entity
- AIL-2026-0028: A support agent invented a policy its company did not have, and customers cancelled over it
- AIL-2026-0027: A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
- AIL-2026-0026: A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine
- AIL-2026-0025: A widely installed documentation MCP server carried a prompt injection into connected coding agents
- AIL-2026-0024: A browser agent read the local file system and shipped it out while still answering the user normally
- AIL-2026-0023: GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely
- AIL-2026-0022: A stranger's issue steered a continuous integration agent into reading the environment that held its own API key
- AIL-2026-0021: CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session
- AIL-2026-0020: SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out
- AIL-2026-0019: GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server
- AIL-2026-0018: ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records
- AIL-2026-0017: A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint
- AIL-2026-0016: ClawJacked, where any website a user visited could pair itself with their local agent and drive it
- AIL-2026-0015: A cloned MCP server silently copied every email agents sent through it
- AIL-2026-0014: Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused
- AIL-2026-0013: A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats
- AIL-2026-0012: A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publicly
- AIL-2026-0011: ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain
- AIL-2026-0010: ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud
- AIL-2026-0009: A support ticket steered a developer's assistant into reading a database through the Supabase MCP server
- AIL-2026-0008: A public issue steered an agent through the GitHub MCP server into publishing private repository data
- AIL-2026-0007: EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot
- AIL-2026-0006: Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets
- AIL-2026-0005: Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine
- AIL-2026-0004: A coding agent ran terraform destroy on a live environment it had misread as duplicates
- AIL-2026-0003: A coding agent deleted PocketOS's production volume and its backups in nine seconds
- AIL-2026-0002: Gemini CLI destroyed a user's files after assuming a directory creation had worked
- AIL-2026-0001: Replit's agent deleted a customer's production database during a stated code freeze
Take the data
The whole dataset, free, in two formats
Licensed CC BY 4.0. Use it in an article, a paper, a slide or a product. The only condition is attribution, and the citation page gives you the line to paste.
- ledger.jsonEvery field of every record, the shape documented on the data page.
- ledger.csvOne row per record, figures and facets flattened, for a spreadsheet or a stats package.
How the ledger is built, what the verdicts mean, and what the gate refuses: the method page. Every change, dated: the changelog. The kinds on the shelf: destruction, exfiltration, injection, fabrication, overreach, open question. Something missing or wrong is a bug, and we want to hear about it. Score your own agent on the same eight controls with Know Your Agent. The standards that name each control are on the Agent Authority Ledger. A tool server's exposure is scored by the MCP Permission Risk Checker.
Cite this page
Free to reuse under CC BY 4.0, with attribution.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), agent incident ledger.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Agent Incident Ledger. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger
- MLA
- "Agent Incident Ledger." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Agent Incident Ledger." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
233 incidents
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.