CompanyScope
by Janus Compliance

AI Agent Incident Register

A numbered public register of AI agent incidents, each analyzed legally: what happened, which legal duty was engaged, who bears liability across the chain — model provider, orchestrator, tool vendor, deployer — and what governance would have prevented it.

Written by Michael K. Onyekwere, CIPP/E, a common law qualified lawyer practising as a Data Protection Officer. Entries analyze public facts and are framed as legal analysis. Entry IDs are stable citation anchors; corrections ship as versioned addenda, never silent edits. New to it? Start with the map of AI agent failure modes, or the Liability Crosswalk that maps OWASP, NIST, IMDA and the EU AI Act to who carries liability, or read how entries are made. Machine-readable feed: /api/register. Not legal advice.

What an entry does · worked example

AIR-2026-003 · Moffatt v Air Canada

The incident. Air Canada's website chatbot invented a bereavement-fare policy that contradicted the airline's own policy page. A grieving customer relied on it and booked.

The duty engaged. Negligent misrepresentation: a company must take reasonable care that the representations it puts in front of customers are accurate.

Who is liable. Air Canada. The tribunal rejected the suggestion that the chatbot was "a separate legal entity responsible for its own actions." Liability locus: deployer-carried. The company answers for what its agent tells customers.

What would have prevented it. Reconciling the automated channel with the airline's own system of record, so the agent could not contradict the published policy.

Read the full entry. Every entry runs the same four beats: incident, duty engaged, liability across the chain, and the governance that would have prevented it. It is the only public AI-agent register that analyses each incident for legal liability.

Subscribe to the AI Agent Incident Register

Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.

Subscribe — free

Delivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.

For a fixed-scope read of your own EU AI Act Article 50 exposure, see the Janus Article 50 teardown; for ongoing agent governance, Janus DPO-as-a-Service. New entries are delivered free through Compliance Engineering on Substack. Vendor-by-vendor compliance research lives in the vendor index.