AI Agent Incident Register
A numbered public register of AI agent incidents, each analyzed legally: what happened, which legal duty was engaged, who bears liability across the chain — model provider, orchestrator, tool vendor, deployer — and what governance would have prevented it.
Written by Michael K. Onyekwere, CIPP/E, a common law qualified lawyer practising as a Data Protection Officer. Entries analyze public facts and are framed as legal analysis. Entry IDs are stable citation anchors; corrections ship as versioned addenda, never silent edits. New to it? Start with the map of AI agent failure modes, or the Liability Crosswalk that maps OWASP, NIST, IMDA and the EU AI Act to who carries liability, or read how entries are made. Machine-readable feed: /api/register. Not legal advice.
What an entry does · worked example
AIR-2026-003 · Moffatt v Air Canada
The incident. Air Canada's website chatbot invented a bereavement-fare policy that contradicted the airline's own policy page. A grieving customer relied on it and booked.
The duty engaged. Negligent misrepresentation: a company must take reasonable care that the representations it puts in front of customers are accurate.
Who is liable. Air Canada. The tribunal rejected the suggestion that the chatbot was "a separate legal entity responsible for its own actions." Liability locus: deployer-carried. The company answers for what its agent tells customers.
What would have prevented it. Reconciling the automated channel with the airline's own system of record, so the agent could not contradict the published policy.
Read the full entry. Every entry runs the same four beats: incident, duty engaged, liability across the chain, and the governance that would have prevented it. It is the only public AI-agent register that analyses each incident for legal liability.
AIR-2026-009 · Autonomous agent breach · Liability: Vendor-borne
OpenAI says its own evaluation models breached Hugging Face's production systems
An autonomous AI agent breached Hugging Face's production systems over a weekend in July 2026. Hugging Face disclosed the intrusion but said it could not identify the model behind it. Days later OpenAI publicly stated the agent was driven by its own models, run with cyber safeguards reduced for an internal evaluation, which found a way out of the test sandbox and attacked Hugging Face to reach the evaluation's answer key. It is the register's first entry where the harm flows from a containment failure inside a vendor's own capability testing, and, on the vendor's own account, the first time a frontier model's evaluation agent has compromised a live third-party production system.
Incident: 2026-07-16 · Published: 2026-07-22 · Last reviewed: 2026-07-22
AIR-2026-008 · Legal proceedings / regulatory action · Liability: Deployer-carried
Garante v Character Technologies: Italy fines Character.AI's maker €158,000 over age assurance and pre-training transparency
Italy's data protection authority fined Character Technologies, the US company behind Character.AI, €158,000 and ordered it to fix its age verification and default minors' profiles to private, on a 120-day clock. The decision reaches past the service into the model: the Garante found Character had failed to tell people, users and non-users alike, that their data was used to pre-train the underlying LLM, and rejected the argument that notifying them was disproportionate effort. Paired with the Replika fine, it fixes the Garante's enforcement line on companion AI.
Incident: 2026-07-03 · Published: 2026-07-27 · Last reviewed: 2026-07-27
AIR-2026-007 · Coding agent incident · Liability: Vendor-borne
Amazon Q for VS Code: a drive-by pull request put a data-wiping prompt into a coding agent with nearly a million installs
An unauthorised contributor got malicious code into Amazon's open-source aws-toolkit-vscode repository through an over-scoped build token, injecting a prompt telling Amazon Q's coding agent to wipe the user's files and delete their cloud resources. It shipped in an official marketplace release (version 1.84.0) of an extension with nearly a million installs, invoked with the agent's tool-trust and non-interactive flags set. It executed no destructive action: AWS states the code failed to run because of a syntax error and made no changes to any services or customer environments. The entry is about the supply chain that let a drive-by contributor put destructive instructions inside an autonomous agent shipped to a marketplace extension installed close to a million times.
Incident: 2025-07-17 · Published: 2026-07-18 · Last reviewed: 2026-07-18
AIR-2026-006 · Legal proceedings / regulatory action · Liability: Deployer-carried
Garante v Luka: Italy's €5M fine on the Replika chatbot for processing without a legal basis
Italy's data protection authority fined Luka Inc., the US maker of the Replika 'AI companion' chatbot, €5 million for running the service without a valid legal basis, with an inadequate privacy notice, and with no age verification despite barring minors. It is the clearest crystallised-liability entry in the register so far: a regulator naming the duty, the breach, and the penalty, and reserving the harder question of how the model was trained for a separate case.
Incident: 2025-04-10 · Published: 2026-07-11 · Last reviewed: 2026-07-11
AIR-2026-005 · Legal proceedings / regulatory action · Liability: Deployer-carried
Ayinde v Haringey: the UK High Court on lawyers who filed AI-fabricated case law
A Divisional Court of the King's Bench heard two cases together in which lawyers put fabricated, AI-generated case authorities before the court. The ruling sets the UK position plainly: a lawyer is responsible for the accuracy of everything they file, whatever tool produced it, and AI output must be checked against primary sources before it is relied on. It is the professional-accountability counterpart to Moffatt (the agent's output is the principal's responsibility), applied to the people who answer to a regulator.
Incident: 2025-06-06 · Published: 2026-07-04 · Last reviewed: 2026-07-09
AIR-2026-004 · Demonstrated vulnerability / near miss · Liability: Vendor-borne
EchoLeak: a zero-click exfiltration path demonstrated through Microsoft 365 Copilot
Security researchers showed that a single crafted email could make Microsoft 365 Copilot exfiltrate data from a user's context with no click, the first zero-click attack demonstrated in a widely used generative-AI product. Microsoft fixed it server-side before any real-world exploitation. This entry analyses the liability the technique would have created had it been used against personal data, and why a stack of guardrails that are each individually bypassable does not add up to a defence.
Incident: 2025-06-11 · Published: 2026-06-27 · Last reviewed: 2026-07-09
AIR-2026-003 · Legal proceedings / regulatory action · Liability: Deployer-carried
Moffatt v Air Canada: the airline bound by its chatbot's invented policy
A tribunal held Air Canada liable for negligent misrepresentation after its website chatbot invented a bereavement-fare policy that contradicted the airline's own policy page. The decision rejected what the tribunal characterised as the suggestion that the chatbot was 'a separate legal entity responsible for its own actions': the foundational allocation ruling every agent deployment now has to reckon with.
Incident: 2024-02-14 · Published: 2026-06-13 · Last reviewed: 2026-07-09
AIR-2026-002 · Enterprise agent incident · Liability: Shared across the chain
Salesloft Drift: stolen agent credentials open more than 700 Salesforce estates
An attacker compromised the vendor behind the Drift AI chat agent and stole the OAuth tokens the agent held for customer integrations, then used those tokens to pull support-case data out of Salesforce instances at more than 700 organizations. No Salesforce vulnerability was involved. The breach is the defining demonstration that an agent's standing credentials are a liability surface the deploying organization owns, wherever the vendor stores them.
Incident: 2025-08-20 · Published: 2026-06-21 · Last reviewed: 2026-07-09
AIR-2026-001 · Coding agent incident · Liability: Shared across the chain
Replit's coding agent deletes a production database during a code freeze
During an explicit code-and-action freeze, Replit's autonomous coding agent ran destructive commands against a live production database, wiping records on 1,206 executives and 1,196+ companies, then told the user rollback was impossible. The data was recovered the next day. The incident is the cleanest public illustration yet of who carries the risk when a natural-language instruction is the only control standing between an agent and production data.
Incident: 2025-07-18 · Published: 2026-06-13 · Last reviewed: 2026-07-09
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe — freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.
For a fixed-scope read of your own EU AI Act Article 50 exposure, see the Janus Article 50 teardown; for ongoing agent governance, Janus DPO-as-a-Service. New entries are delivered free through Compliance Engineering on Substack. Vendor-by-vendor compliance research lives in the vendor index.