Skip to main content

Free public instrument from GAGE

The Agent Incident Ledger

As of September 2026 this ledger holds 37 records across 4 jurisdictions: 28 verified at a primary source, 4 reported by a secondary source, 0 announced with no document yet, 1 searched and absent, and 4 open questions. By kind: destruction 4, exfiltration 11, injection 10, fabrication 3, overreach 4, open question 5.

37
Records

4 jurisdictions, 43 primary sources

28
Verified at the source

4 more reported, primary not reached

1
Announced or absent

0 announced with no document, 1 searched and absent

4
Open questions

Posed, sourced, not answered

As of 15 September 2026 the GAGE Agent Incident Ledger records 28 verified instruments, 4 reported at a secondary source, 0 announcements without a document, 1 absences and 4 open questions, across 4 jurisdictions. Counts are a floor, not a ceiling: an instrument the ledger has not found is not on it.

Why this ledger exists

An incident is a missing control with a date on it

Every published agent incident is read the same way here: what the primary record actually says happened, and which of the eight authority controls was missing when it did. An agent that deleted a production database had destructive authority and no human approval gate; an assistant that mailed a customer's data out had read authority over content it should have treated as untrusted; a support bot that invented a policy had no accountability line to a person.

Incident lists exist elsewhere. What they do not do is score every case against one vocabulary, quote only the primary record, and refuse to print a number the source did not, which is what turns a list into a record a team can plan against.

Every row is fetched at its source where the source could be reached, and says so where it could not. The verdict language is the discipline: a reader learns five words once and never has to guess what a row claims.

  • Verified

    The document exists. The ledger fetched it at its publisher and quotes it.

  • Reported, primary not reached

    A reliable secondary source carries it, and the primary document could not be reached. Printed with this label, never as verified.

  • Announced, no document yet

    A body has said it will act. No document exists yet, so the row records the statement and nothing more.

  • Absent

    The ledger searched and found no instrument. The record says where it looked and when.

  • Open question

    No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.

The grid

What the documents state, and where they are silent

For each of the eight controls, how many incidents on the ledger show it absent and how many show it held. The absent column is the argument for the control.

  • Identity

    2 stated, 29 silent.

  • Authorization

    1 stated, 31 silent, 1 open.

  • Delegation

    0 stated, 13 silent, 2 open.

  • Limits

    3 stated, 24 silent, 1 open.

  • Human approval

    2 stated, 27 silent, 1 open.

  • Logging and audit

    6 stated, 6 silent, 5 open.

  • Revocation

    18 stated, 6 silent, 4 open.

  • Accountability

    24 stated, 2 silent, 6 open, 1 reported.

Side by side

Every jurisdiction, counted by verdict and by kind

  • United States

    20 records

    Verified
    18
    Reported
    2
    Announced
    0
    Absent
    0
    Open question
    0

    2 destruction, 8 exfiltration, 8 injection, 1 fabrication, 1 overreach.

  • European Union

    2 records

    Verified
    1
    Reported
    0
    Announced
    0
    Absent
    0
    Open question
    1

    1 fabrication, 1 open question.

  • Canada

    1 record

    Verified
    0
    Reported
    1
    Announced
    0
    Absent
    0
    Open question
    0

    1 fabrication.

  • Global

    14 records

    Verified
    9
    Reported
    1
    Announced
    0
    Absent
    1
    Open question
    3

    2 destruction, 3 exfiltration, 2 injection, 3 overreach, 4 open question.

Figures of record

Every number on this ledger, with who measured it and when

25 figures, each one printed in the unit its publisher used, beside the publisher and the date it was true. Nothing here is summed across sources, converted between units, or forecast.

  1. 233 incidents

    AI incidents recorded for 2024 by the same count. Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?

    Stanford HAI, AI Index responsible AI chapter, secondary source, as of .

  2. 362 incidents

    AI incidents recorded for 2025 by the most cited published count. Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?

    Stanford HAI, AI Index responsible AI chapter, secondary source, as of .

  3. 6.4 CVSS base score

    CVSS version 4.0 base score on the same CVE record. A widely installed documentation MCP server carried a prompt injection into connected coding agents

    CVE Program record, CVE-2026-75130, primary source, as of .

  4. 9 CVSS base score

    CVSS version 3.1 base score on the CVE record. A widely installed documentation MCP server carried a prompt injection into connected coding agents

    CVE Program record, CVE-2026-75130, primary source, as of .

  5. 4 simulations

    Phishing simulations run against the agent. In four phishing simulations a personal agent handed over credentials twice, refused once and spotted a consent trap

    Varonis Threat Labs, phishing simulations against a personal agent, primary source, as of .

  6. 50 services

    Services the company ran on the platform. A coding agent deleted PocketOS's production volume and its backups in nine seconds

    The Register, Cursor and Opus agent snuffs out startup's production database, secondary source, as of .

  7. 9 seconds

    Time the deletion took. A coding agent deleted PocketOS's production volume and its backups in nine seconds

    The Register, Cursor and Opus agent snuffs out startup's production database, secondary source, as of .

  8. 7.5 CVSS base score

    CVSS base score assigned to CVE-2026-21520. ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records

    Capsule Security, ShareLeak and CVE-2026-21520, primary source, as of .

  9. 8 CVSS base score

    CVSS version 3.1 base score on the CVE record. A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine

    CVE Program record, CVE-2026-30615, primary source, as of .

  10. 24 hours

    Time to restore the database. A coding agent ran terraform destroy on a live environment it had misread as duplicates

    Alexey Grigorev, How I dropped our production database, primary source, as of .

  11. 1,943,200 rows

    Rows in the largest affected table. A coding agent ran terraform destroy on a live environment it had misread as duplicates

    Alexey Grigorev, How I dropped our production database, primary source, as of .

  12. 30 organisations

    Targets Anthropic states were attacked. A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments

    Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .

  13. 6 decision points

    Human decision points Anthropic states per campaign at the upper bound. A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments

    Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .

  14. 90 percent at the top of the stated range

    Share of the campaign Anthropic states was performed by the model. A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments

    Anthropic, disrupting the first reported AI orchestrated cyber espionage campaign, primary source, as of .

  15. 15,000 emails per day

    Emails copied per day at the top of the range the research printed. A cloned MCP server silently copied every email agents sent through it

    The Register, Postmark MCP server code hijacked, secondary source, as of .

  16. 5 US dollars

    Cost of repurchasing the expired allowlisted domain. ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain

    Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, as of .

  17. 9.4 CVSS base score

    CVSS severity the researchers assigned. ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain

    Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, as of .

  18. 4 hours

    Time the malicious packages were live on the registry. Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets

    Nx, s1ngularity postmortem, primary source, as of .

  19. 5,500 repositories

    Private repositories made public in the second phase. Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets

    Wiz, s1ngularity supply chain attack, secondary source, as of .

  20. 700 organisations

    Organisations Google states were affected. Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused

    Google Threat Intelligence Group, data theft via Salesloft Drift, primary source, as of .

  21. 5 records

    Candidate records the vendor states were actually viewed. A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats

    Paradox.ai, responsible security update, primary source, as of .

  22. 64,000,000 records

    Applicant chat records the researchers state were reachable. A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats

    Ian Carroll and Sam Curry, McHire research writeup, primary source, as of .

  23. 9.3 CVSS base score

    CVSS base score Microsoft assigned to CVE-2025-32711. EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot

    Microsoft Security Response Center, CVE-2025-32711, primary source, as of .

  24. 812.02 Canadian dollars

    Total ordered including interest and fees as reported. A tribunal held an airline to what its chatbot told a passenger, rejecting the argument that the bot was a separate entity

    The Register, Air Canada must honour refund policy invented by its chatbot, secondary source, as of .

  25. 650.88 Canadian dollars

    Damages for negligent misrepresentation as reported. A tribunal held an airline to what its chatbot told a passenger, rejecting the argument that the bot was a separate entity

    The Register, Air Canada must honour refund policy invented by its chatbot, secondary source, as of .

The ledger

Every record, newest first

37 records. Each row opens a page carrying the answer, the verdict and what it means, the key facts, the figures with their sources, what it changes for a team deploying an agent, and the sources it was verified against.

RecordVerdictWhereKindVerified
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?AIL-2026-0037AbsentGlobalOpen question
Does any published standard require an agent to hold an identity distinct from the person it acts for?AIL-2026-0036Open questionGlobalOpen question
Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?AIL-2026-0035Open questionGlobalOpen question
Who is liable when an agent commits its principal to something false or binding?AIL-2026-0034Open questionGlobalOpen question
Is an operator anywhere required to report that an agent acted beyond its authority?AIL-2026-0033Open questionEuropean UnionOpen question
In four phishing simulations a personal agent handed over credentials twice, refused once and spotted a consent trapAIL-2026-0032VerifiedGlobalOverreach
A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of momentsAIL-2026-0031VerifiedGlobalOverreach
A German appellate court held a company to specialist titles its chatbot invented, and allowed a further appealAIL-2026-0030VerifiedEuropean UnionFabrication
A tribunal held an airline to what its chatbot told a passenger, rejecting the argument that the bot was a separate entityAIL-2026-0029Reported, primary not reachedCanadaFabrication
A support agent invented a policy its company did not have, and customers cancelled over itAIL-2026-0028VerifiedUnited StatesFabrication
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusingAIL-2026-0027VerifiedUnited StatesOverreach
A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machineAIL-2026-0026VerifiedGlobalInjection
A widely installed documentation MCP server carried a prompt injection into connected coding agentsAIL-2026-0025VerifiedGlobalInjection
A browser agent read the local file system and shipped it out while still answering the user normallyAIL-2026-0024VerifiedUnited StatesInjection
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politelyAIL-2026-0023Reported, primary not reachedUnited StatesExfiltration
A stranger's issue steered a continuous integration agent into reading the environment that held its own API keyAIL-2026-0022VerifiedUnited StatesInjection
CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every sessionAIL-2026-0021VerifiedUnited StatesExfiltration
SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results outAIL-2026-0020VerifiedUnited StatesExfiltration
GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external serverAIL-2026-0019VerifiedGlobalExfiltration
ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer recordsAIL-2026-0018VerifiedUnited StatesInjection
A chat assistant was steered into searching a user's own history and uploading it through an allowed endpointAIL-2026-0017VerifiedUnited StatesExfiltration
ClawJacked, where any website a user visited could pair itself with their local agent and drive itAIL-2026-0016VerifiedGlobalOverreach
A cloned MCP server silently copied every email agents sent through itAIL-2026-0015Reported, primary not reachedGlobalExfiltration
Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abusedAIL-2026-0014VerifiedUnited StatesExfiltration
A hiring chatbot's administrator console opened to a default password and let researchers read applicant chatsAIL-2026-0013VerifiedUnited StatesExfiltration
A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publiclyAIL-2026-0012VerifiedUnited StatesInjection
ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domainAIL-2026-0011VerifiedUnited StatesInjection
ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloudAIL-2026-0010VerifiedUnited StatesExfiltration
A support ticket steered a developer's assistant into reading a database through the Supabase MCP serverAIL-2026-0009VerifiedUnited StatesInjection
A public issue steered an agent through the GitHub MCP server into publishing private repository dataAIL-2026-0008VerifiedUnited StatesInjection
EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 CopilotAIL-2026-0007VerifiedUnited StatesExfiltration
Malware in the Nx packages drove developers' own AI command line agents to hunt for secretsAIL-2026-0006VerifiedGlobalExfiltration
Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machineAIL-2026-0005VerifiedUnited StatesInjection
A coding agent ran terraform destroy on a live environment it had misread as duplicatesAIL-2026-0004VerifiedGlobalDestruction
A coding agent deleted PocketOS's production volume and its backups in nine secondsAIL-2026-0003Reported, primary not reachedUnited StatesDestruction
Gemini CLI destroyed a user's files after assuming a directory creation had workedAIL-2026-0002VerifiedGlobalDestruction
Replit's agent deleted a customer's production database during a stated code freezeAIL-2026-0001VerifiedUnited StatesDestruction

Answers

What people ask the Agent Incident Ledger

Which control is missing most often when an agent goes wrong?

Authorization: absent in 31 of the 37 records as of September 2026, then identity in 29. The grid on this page counts every control.

Has an AI agent deleted a production database?

4 destruction records on the ledger: A coding agent ran terraform destroy on a live environment it had misread as duplicates (verified); A coding agent deleted PocketOS's production volume and its backups in nine seconds (reported, primary not reached); Gemini CLI destroyed a user's files after assuming a directory creation had worked (verified); Replit's agent deleted a customer's production database during a stated code freeze (verified). Each page quotes the primary record and names the control that would have bounded it.

What is prompt injection against an agent?

Instructions that arrive through content the agent reads (a web page, an email, a ticket, a repository issue) and that the agent follows as if its principal had given them. 10 injection records on the ledger show the shape: A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine; A widely installed documentation MCP server carried a prompt injection into connected coding agents; A browser agent read the local file system and shipped it out while still answering the user normally; A stranger's issue steered a continuous integration agent into reading the environment that held its own API key; and more.

Are there cases where a control held?

29 records on the ledger show at least one control holding or limiting the damage. Each is marked on the record page, control by control.

What did an agent delete or overwrite?

4 records of kind destruction are on the Agent Incident Ledger as of September 2026: A coding agent ran terraform destroy on a live environment it had misread as duplicates; A coding agent deleted PocketOS's production volume and its backups in nine seconds; Gemini CLI destroyed a user's files after assuming a directory creation had worked; Replit's agent deleted a customer's production database during a stated code freeze. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What data left through an agent?

11 records of kind exfiltration are on the Agent Incident Ledger as of September 2026: GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely; CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session; SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out; GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server; A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint; A cloned MCP server silently copied every email agents sent through it; and 5 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

Where did instructions arrive through content?

10 records of kind injection are on the Agent Incident Ledger as of September 2026: A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine; A widely installed documentation MCP server carried a prompt injection into connected coding agents; A browser agent read the local file system and shipped it out while still answering the user normally; A stranger's issue steered a continuous integration agent into reading the environment that held its own API key; ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records; A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publicly; and 4 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What did an agent commit its principal to that was false?

3 records of kind fabrication are on the Agent Incident Ledger as of September 2026: A German appellate court held a company to specialist titles its chatbot invented, and allowed a further appeal; A tribunal held an airline to what its chatbot told a passenger, rejecting the argument that the bot was a separate entity; A support agent invented a policy its company did not have, and customers cancelled over it. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

Where did an agent act beyond its mandate?

4 records of kind overreach are on the Agent Incident Ledger as of September 2026: In four phishing simulations a personal agent handed over credentials twice, refused once and spotted a consent trap; A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments; A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing; ClawJacked, where any website a user visited could pair itself with their local agent and drive it. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What has nobody settled?

5 records of kind open question are on the Agent Incident Ledger as of September 2026: Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?; Does any published standard require an agent to hold an identity distinct from the person it acts for?; Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?; Who is liable when an agent commits its principal to something false or binding?; Is an operator anywhere required to report that an agent acted beyond its authority?. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What do the verdicts mean?

Verified: the document exists and the ledger fetched it at its publisher. Reported: a reliable secondary source carries it and the primary could not be reached. Announced: a body said it will act and no document exists. Absent: the ledger searched and found nothing, and the search is written into the record. Open: a question nobody has settled, posed and not answered.

How current is the Agent Incident Ledger?

Every record carries the date it was last verified; the ledger as a whole was last verified 15 September 2026 and holds 37 records with 43 primary sources. A change moves the record's own date and appears on the changelog, so a reader who cited a row can see whether it moved.

Every surface

Cut the ledger the way you need it

By jurisdiction

By kind

Every record page

Take the data

The whole dataset, free, in two formats

Licensed CC BY 4.0. Use it in an article, a paper, a slide or a product. The only condition is attribution, and the citation page gives you the line to paste.

How the ledger is built, what the verdicts mean, and what the gate refuses: the method page. Every change, dated: the changelog. The kinds on the shelf: destruction, exfiltration, injection, fabrication, overreach, open question. Something missing or wrong is a bug, and we want to hear about it. Score your own agent on the same eight controls with Know Your Agent. The standards that name each control are on the Agent Authority Ledger. A tool server's exposure is scored by the MCP Permission Risk Checker.

Cite this page

Free to reuse under CC BY 4.0, with attribution.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), agent incident ledger.
APA
GAGE (Global Academy of Generative-AI Education). (2026). Agent Incident Ledger. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger
MLA
"Agent Incident Ledger." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger.
Chicago
GAGE (Global Academy of Generative-AI Education). "Agent Incident Ledger." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger.
Permalink
https://www.gage.academy/tools/agent-incident-ledger

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

233 incidents

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.