CompanyScope
by Janus Compliance

AI Agent Incident Register

Methodology

The Register documents AI agent incidents and analyzes them legally. Each entry asks four questions: what happened, which legal duty was engaged, who bears liability across the chain, and what governance would have prevented it. This page describes how entries are made, so readers can judge the work and cite it with confidence.

What counts as an entry

An incident qualifies when an AI agent (a system that takes actions: executing commands, holding credentials, transacting, publishing, or advising with delegated authority) caused or nearly caused real-world harm, and the public record is rich enough to support a responsible legal analysis. Four classes appear in the Register:

Sourcing standards

The analysis is analysis

Liability sections set out how liability would plausibly allocate on the public facts, under the legal frameworks engaged (GDPR and UK GDPR, the EU AI Act, contract, negligence, agency principles, and sector rules where relevant). Conclusions are framed conditionally where facts are incomplete. Allegations in live proceedings are described as allegations. Nothing in the Register is an assertion that any named party broke the law, and nothing here is legal advice.

Entry IDs and corrections

Framework mappings

Where the fit is real, entries map to the OWASP Top 10 for Agentic Applications, Singapore IMDA's Model AI Governance Framework for Agentic AI, and runtime-control references. The Register sits alongside the security-side incident trackers; its distinct contribution is the per-incident legal layer. Partial fits are flagged as partial.

Who writes this

Michael K. Onyekwere — CIPP/E, common law qualified lawyer practising as a Data Protection Officer, founder of Janus Compliance. Research support uses AI tooling against public documentation; every entry is reviewed and edited by him before publication, and the legal analysis is his judgement.

Suggest an incident or flag an error: use the form on any entry, or contact Janus Compliance. Back to the Register.