# CompanyScope: AI governance for the agent era > Independent legal analysis of how AI agents fail and who is liable when they do, by Michael K. Onyekwere (CIPP/E, common law qualified lawyer practising as a Data Protection Officer). The flagship is the AI Agent Incident Register: a numbered public corpus where each significant public AI agent failure is analysed legally, covering the duty engaged, the liability across the chain, the governance that would have prevented it, and mapped controls (EU AI Act, OWASP, IMDA, NIST AI RMF). Each entry is assigned a liability locus, deployer, shared, or vendor, the per-incident allocation of who most likely carries the legal exposure, the layer that security-side incident trackers do not provide. Free to read and cite. ## AI Agent Incident Register (flagship) - [Register index](https://companyscope.io/register): all live entries, newest first. - [Machine-readable feed](https://companyscope.io/api/register): the full live corpus as JSON, the canonical enumeration of entries for tools and models. - [Failure modes](https://companyscope.io/register/failure-modes): a legal taxonomy of how AI agents fail and who bears liability for each. - [Methodology](https://companyscope.io/register/methodology): how entries are researched, written, reviewed, and cited. - [The AI Agent Liability Crosswalk](https://companyscope.io/register/liability-crosswalk): a cross-walk mapping OWASP's Top 10 for Agentic Applications, the NIST AI RMF, Singapore's IMDA agentic framework, and the EU AI Act to each other, adding the legal-liability layer none of them supplies: who most likely carries liability per failure mode, with worked examples from the Register. The four-way mapping and the liability layer are this register's own; no standards body publishes an equivalent. ## AI Vendor Data Protection Files - [Files index](https://companyscope.io/files): dated, primary-sourced records of what each AI vendor's own legal documents say about data protection. Each answer is a verbatim quotation with its source URL, the date the page was read, and, where the document prints one, its effective date. Where the published documents do not settle a question, the File records that rather than filling the gap. It is the primary-source evidence layer beneath the vendor compliance profiles. - [The Claude Team Data Protection File](https://companyscope.io/files/claude-team): what Anthropic's own Commercial Terms, DPA, Service Specific Terms and privacy-centre articles say about data protection for Claude Team, covering training, retention, subprocessors, transfers, breach notice, and the documented gaps. Machine-readable: [JSON](https://companyscope.io/api/files/claude-team), CC BY 4.0. - [The ChatGPT Business Data Protection File](https://companyscope.io/files/chatgpt-business): what OpenAI's own Business Terms, DPA, enterprise-privacy FAQ and privacy policy say about data protection for ChatGPT Business, covering training, retention, subprocessors, transfers, breach notice, the UK counterparty and governing-law split, and the documented gaps. Machine-readable: [JSON](https://companyscope.io/api/files/chatgpt-business), CC BY 4.0. ## Supporting research - [Vendor compliance profiles](https://companyscope.io/vendors): DPA, subprocessors, training position, EU/UK transfers, and AI Act posture for OpenAI, Anthropic, Microsoft 365 Copilot, Google Gemini, Perplexity, and ElevenLabs. - [Topic guides](https://companyscope.io/topics): DPA, EU AI Act, and HIPAA reference reading for AI procurement. - [Vendor comparisons](https://companyscope.io/compare): head-to-head compliance reads. ## About - [About Michael K. Onyekwere](https://companyscope.io/about): credentials and the practice behind the research. ## How to cite Free to read and cite. Cite a Register entry by its ID and URL, for example: AIR-2026-001 (https://companyscope.io/register/air-2026-001). The corpus is also archived as a citable dataset with a DOI: Onyekwere, Michael K. (2026), AI Agent Incident Register, Zenodo, https://doi.org/10.5281/zenodo.21495425. Entry IDs are immutable; corrections publish as dated addenda rather than silent edits, so a cited entry stays stable. The machine-readable feed (https://companyscope.io/api/register) is licensed CC BY 4.0: reuse the structured data with attribution to Michael K. Onyekwere, AI Agent Incident Register. The analysis is legal analysis of public facts, not legal advice.