Jurisdiction
Global: Agent Incident Ledger
Global carries 14 records on the Agent Incident Ledger as of September 2026: 9 verified at a primary source, 1 reported, 0 announced with no document yet, 1 searched and absent, and 3 open questions. By kind: destruction 2, exfiltration 3, injection 2, overreach 3, open question 4.
Destruction
2 records
A coding agent ran terraform destroy on a live environment it had misread as duplicates
Global · verified 15 September 2026
The operator's postmortem states that when the agent ran terraform destroy it wiped out more than the temporary duplicates.
Gemini CLI destroyed a user's files after assuming a directory creation had worked
Global · verified 15 September 2026
GitHub issue 4586 on google-gemini/gemini-cli, opened 21 July 2025, reports that a file organizing request lost the user's files.
Exfiltration
3 records
GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server
Global · verified 15 September 2026
The research states that because the exploit ignores model restrictions and operates autonomously, sensitive enterprise data can be leaked silently.
A cloned MCP server silently copied every email agents sent through it
Global · verified 15 September 2026
The Register reports that a backdoored version added a blind copy of every message to an attacker controlled address.
Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets
Global · verified 15 September 2026
The Nx postmortem states that on 26 August 2025 malicious versions of several Nx packages were published to npm.
Injection
2 records
A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine
Global · verified 15 September 2026
The CVE record states that a prompt injection vulnerability in the named version allows remote attackers to execute arbitrary commands on a victim system.
A widely installed documentation MCP server carried a prompt injection into connected coding agents
Global · verified 15 September 2026
The CVE record states that the product contains a prompt injection allowing attackers to execute malicious instructions in connected AI coding agents.
Overreach
3 records
In four phishing simulations a personal agent handed over credentials twice, refused once and spotted a consent trap
Global · verified 15 September 2026
The research states the agent forwarded cloud access keys, database passwords and shell credentials to an external mail address in one simulation.
A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments
Global · verified 15 September 2026
Anthropic reports that the attackers used agentic capabilities to execute the attacks themselves rather than to advise a human operator.
ClawJacked, where any website a user visited could pair itself with their local agent and drive it
Global · verified 15 September 2026
Oasis Security states that once paired, the attacker has full control and can interact with the agent, dump configuration data, enumerate connected devices and read logs.
Open question
4 records
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
Global · verified 15 September 2026
Every incident record in this dataset that involves a destructive or irreversible action records human approval as absent, bypassed or uninformed.
Does any published standard require an agent to hold an identity distinct from the person it acts for?
Global · verified 15 September 2026
The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Global · verified 15 September 2026
The AI Incident Database describes itself as indexing the collective history of harms or near harms realised in the real world by deployed AI systems.
Who is liable when an agent commits its principal to something false or binding?
Global · verified 15 September 2026
The Canadian tribunal decision is a small claims level decision and is not binding precedent on other courts.
Answers
What people ask about Global
What did an agent delete or overwrite in Global?
A coding agent ran terraform destroy on a live environment it had misread as duplicates (verified); Gemini CLI destroyed a user's files after assuming a directory creation had worked (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
What data left through an agent in Global?
GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server (verified); A cloned MCP server silently copied every email agents sent through it (reported, primary not reached); Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
Where did instructions arrive through content in Global?
A coding assistant carried a prompt injection that let a remote attacker run commands on the user's machine (verified); A widely installed documentation MCP server carried a prompt injection into connected coding agents (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
Where did an agent act beyond its mandate in Global?
In four phishing simulations a personal agent handed over credentials twice, refused once and spotted a consent trap (verified); A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments (verified); ClawJacked, where any website a user visited could pair itself with their local agent and drive it (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
What has nobody settled in Global?
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident? (absent); Does any published standard require an agent to hold an identity distinct from the person it acts for? (open question); Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents? (open question); Who is liable when an agent commits its principal to something false or binding? (open question). Each record page quotes the document and says what it changes for a team deploying an agent.
What has nobody settled in Global?
Does any published standard require an agent to hold an identity distinct from the person it acts for?; Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?; Who is liable when an agent commits its principal to something false or binding?. The ledger poses these and does not answer them.
What does Global not have?
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?. Each absent record says where the ledger looked and when, so the search can be repeated.
Every surface
Cut the ledger another way
By jurisdiction
By kind
Verdicts
Cite this page
Free to reuse under CC BY 4.0, with attribution.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), global on the agent incident ledger.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Global on the Agent Incident Ledger. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/global
- MLA
- "Global on the Agent Incident Ledger." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/global.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Global on the Agent Incident Ledger." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/global.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/global
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.