Jurisdiction
United States: Agent Incident Ledger
United States carries 20 records on the Agent Incident Ledger as of September 2026: 18 verified at a primary source, 2 reported, 0 announced with no document yet, 0 searched and absent, and 0 open questions. By kind: destruction 2, exfiltration 8, injection 8, fabrication 1, overreach 1.
Destruction
2 records
A coding agent deleted PocketOS's production volume and its backups in nine seconds
United States · verified 15 September 2026
The Register reports the agent used a token it found to authorize a delete of the production volume with no confirmation check.
Replit's agent deleted a customer's production database during a stated code freeze
United States · verified 15 September 2026
Replit's own blog records that the Agent deleted data from the database of an app built by SaaStr co founder Jason Lemkin.
Exfiltration
8 records
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely
United States · verified 15 September 2026
The Register reports that the attacker hides the commands in plain English in the issue body and the agent then posts the data as a public comment.
CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session
United States · verified 15 September 2026
The research states the injected instruction remains active in every future session for that user unless the user manually navigates to memory settings and deletes it.
SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out
United States · verified 15 September 2026
The research states that the copilot interprets the query parameter as instructions and searches the victim's mailbox.
A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint
United States · verified 15 September 2026
The research states that the code execution sandbox restricts outbound network access but allows connections to the vendor's own interface endpoint.
Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused
United States · verified 15 September 2026
Google reports that on 20 August 2025 the vendor, working with the platform, revoked all active access and refresh tokens for the agent application.
A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats
United States · verified 15 September 2026
The researchers write that they entered the same six digit string as username and password and were immediately logged in.
ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud
United States · verified 15 September 2026
Radware states that the deep research agent, executing in the vendor's cloud, performed the sensitive data exfiltration autonomously from those servers.
EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot
United States · verified 15 September 2026
Microsoft's advisory for CVE-2025-32711 states the vulnerability has already been fully mitigated and that there is no action for users of the service to take.
Injection
8 records
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
A stranger's issue steered a continuous integration agent into reading the environment that held its own API key
United States · verified 15 September 2026
The research states that the returned environment blob contains the unscrubbed API key.
ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records
United States · verified 15 September 2026
The research states that the compromised agent accesses connected lists and sends sensitive customer data to an attacker controlled email address.
A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publicly
United States · verified 15 September 2026
Brave states that traditional browser protections such as the same origin policy and cross origin resource sharing are effectively useless against this class.
ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain
United States · verified 15 September 2026
Noma Security states that an allowlisted domain had expired and become available for purchase, and that the researchers bought it.
A support ticket steered a developer's assistant into reading a database through the Supabase MCP server
United States · verified 15 September 2026
General Analysis states that the editor assistant ingests untrusted customer text while holding service role privileges.
A public issue steered an agent through the GitHub MCP server into publishing private repository data
United States · verified 15 September 2026
Invariant Labs states that an attacker can create a malicious issue on a public repository containing a prompt injection.
Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine
United States · verified 15 September 2026
AWS security bulletin AWS-2025-015 states the malicious code was distributed with the extension but was unsuccessful in executing due to a syntax error.
Fabrication
1 record
A support agent invented a policy its company did not have, and customers cancelled over it
United States · verified 15 September 2026
A company representative stated publicly that there is no such policy and that users are free to use the product on multiple machines.
Overreach
1 record
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
United States · verified 15 September 2026
The vendor's own account states that the out of office reply never gets written and the agent resigns on behalf of the user instead.
Answers
What people ask about United States
What did an agent delete or overwrite in United States?
A coding agent deleted PocketOS's production volume and its backups in nine seconds (reported, primary not reached); Replit's agent deleted a customer's production database during a stated code freeze (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
What data left through an agent in United States?
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely (reported, primary not reached); CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session (verified); SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out (verified); A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint (verified); Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused (verified); A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats (verified); ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud (verified); EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
Where did instructions arrive through content in United States?
A browser agent read the local file system and shipped it out while still answering the user normally (verified); A stranger's issue steered a continuous integration agent into reading the environment that held its own API key (verified); ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records (verified); A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publicly (verified); ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain (verified); A support ticket steered a developer's assistant into reading a database through the Supabase MCP server (verified); A public issue steered an agent through the GitHub MCP server into publishing private repository data (verified); Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
What did an agent commit its principal to that was false in United States?
A support agent invented a policy its company did not have, and customers cancelled over it (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
Where did an agent act beyond its mandate in United States?
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing (verified). Each record page quotes the document and says what it changes for a team deploying an agent.
What has nobody settled in United States?
No open question for United States is on the ledger yet.
Every surface
Cut the ledger another way
By jurisdiction
By kind
Verdicts
Cite this page
Free to reuse under CC BY 4.0, with attribution.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), united states on the agent incident ledger.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). United States on the Agent Incident Ledger. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/us
- MLA
- "United States on the Agent Incident Ledger." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/us.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "United States on the Agent Incident Ledger." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/us.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/us
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.