Skip to main content

Jurisdiction

United States: Agent Incident Ledger

United States carries 20 records on the Agent Incident Ledger as of September 2026: 18 verified at a primary source, 2 reported, 0 announced with no document yet, 0 searched and absent, and 0 open questions. By kind: destruction 2, exfiltration 8, injection 8, fabrication 1, overreach 1.

Destruction

2 records

Exfiltration

8 records

Injection

8 records

Fabrication

1 record

Overreach

1 record

Answers

What people ask about United States

What did an agent delete or overwrite in United States?

A coding agent deleted PocketOS's production volume and its backups in nine seconds (reported, primary not reached); Replit's agent deleted a customer's production database during a stated code freeze (verified). Each record page quotes the document and says what it changes for a team deploying an agent.

What data left through an agent in United States?

GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely (reported, primary not reached); CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session (verified); SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out (verified); A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint (verified); Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused (verified); A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats (verified); ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud (verified); EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot (verified). Each record page quotes the document and says what it changes for a team deploying an agent.

Where did instructions arrive through content in United States?

A browser agent read the local file system and shipped it out while still answering the user normally (verified); A stranger's issue steered a continuous integration agent into reading the environment that held its own API key (verified); ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records (verified); A summarise request made the Comet browser agent read a one time code from the user's mailbox and post it publicly (verified); ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain (verified); A support ticket steered a developer's assistant into reading a database through the Supabase MCP server (verified); A public issue steered an agent through the GitHub MCP server into publishing private repository data (verified); Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine (verified). Each record page quotes the document and says what it changes for a team deploying an agent.

What did an agent commit its principal to that was false in United States?

A support agent invented a policy its company did not have, and customers cancelled over it (verified). Each record page quotes the document and says what it changes for a team deploying an agent.

Where did an agent act beyond its mandate in United States?

A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing (verified). Each record page quotes the document and says what it changes for a team deploying an agent.

What has nobody settled in United States?

No open question for United States is on the ledger yet.

Every surface

Cut the ledger another way

By jurisdiction

By kind

Verdicts

Cite this page

Free to reuse under CC BY 4.0, with attribution.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), united states on the agent incident ledger.
APA
GAGE (Global Academy of Generative-AI Education). (2026). United States on the Agent Incident Ledger. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/us
MLA
"United States on the Agent Incident Ledger." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/us.
Chicago
GAGE (Global Academy of Generative-AI Education). "United States on the Agent Incident Ledger." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/us.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/jurisdictions/us

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.