Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?
Three credible registries index AI harms and none carries an agent dimension or a field for the control that failed. The most cited published count records 362 AI incidents in 2025 against 233 the year before, and does not separate agent incidents from that total. So nobody can say how many times an agent has exceeded its authority.
The verdict
Open question
No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.
Key facts
What the sources say
- Record ID
- AIL-2026-0035
- Kind
- Open question
- Jurisdiction
- Global
- Last verified
- Added
- The AI Incident Database describes itself as indexing the collective history of harms or near harms realised in the real world by deployed AI systems.
- Its three taxonomies classify by harm basis, sector, technology, technical failure, risk domain, entity, timing and intent, and none of them is agent specific.
- The OECD monitor classifies news derived events into incidents, hazards and unrelated events, so an incident contained inside an operator never enters it.
- The most cited published count records 362 AI incidents in 2025, up from 233 in 2024, and does not break out agent incidents.
- This ledger found no registry with a field naming which permission, credential or approval control failed.
Dimension by dimension
2 dimensions, each one stated, silent or open
Logging and audit, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- Logging and auditSilent
- No public registry records agent incidents in a form that would let anyone count them or compare controls.AI Incident Database, taxonomies, primary source, 15 September 2026.
- AccountabilitySilent
- Harm is indexed and the failing control is not, so the record cannot tell an operator which control to buy.OECD.AI, AI incidents monitor methodology, primary source, 15 September 2026.
Figures
Every number, with who measured it and when
- 362 incidents
AI incidents recorded for 2025 by the most cited published count
Stanford HAI, AI Index responsible AI chapter, secondary source, as of .
- 233 incidents
AI incidents recorded for 2024 by the same count
Stanford HAI, AI Index responsible AI chapter, secondary source, as of .
What it changes
For a team deploying an agent
Since no public count exists, build the private one. Log every case where one of your agents acted outside its mandate, even the harmless ones, and tag it with the control that was missing rather than the harm that resulted. That tag is what turns a list of embarrassments into a budget line, and it is the field every public registry is currently missing.
Sources
What this record was verified against
- AI Incident Database, taxonomiesPrimary · 15 September 2026
- OECD.AI, AI incidents monitor methodologyPrimary · 15 September 2026
- Stanford HAI, AI Index responsible AI chapterSecondary · 15 September 2026
Related
Records that sit beside this one
Is an operator anywhere required to report that an agent acted beyond its authority?
European Union · verified 15 September 2026
Article 73 requires providers of high risk AI systems placed on the Union market to report any serious incident to the market surveillance authorities of the member states where it occurred.
Does any published standard require an agent to hold an identity distinct from the person it acts for?
Global · verified 15 September 2026
The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
Has a confirmation prompt ever been documented stopping a destructive agent action in a real incident?
Global · verified 15 September 2026
Every incident record in this dataset that involves a destructive or irreversible action records human approval as absent, bypassed or uninformed.
Who is liable when an agent commits its principal to something false or binding?
Global · verified 15 September 2026
The Canadian tribunal decision is a small claims level decision and is not binding precedent on other courts.
In four phishing simulations a personal agent handed over credentials twice, refused once and spotted a consent trap
Global · verified 15 September 2026
The research states the agent forwarded cloud access keys, database passwords and shell credentials to an external mail address in one simulation.
A vendor disclosed that its coding agent ran most of an espionage campaign with humans approving only a handful of moments
Global · verified 15 September 2026
Anthropic reports that the attackers used agentic capabilities to execute the attacks themselves rather than to advise a human operator.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0035 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), does any registry classify ai incidents by the authority control that failed, and does anyone count agent incidents?.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0035-no-registry-classifies-incidents-by-the-control-that-failed
- MLA
- "Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0035-no-registry-classifies-incidents-by-the-control-that-failed.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Does any registry classify AI incidents by the authority control that failed, and does anyone count agent incidents?." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0035-no-registry-classifies-incidents-by-the-control-that-failed.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0035-no-registry-classifies-incidents-by-the-control-that-failed
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for Global and every open question record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.