Digital Information GovernanceDIG · The Standard Reference
Home › Incident register
Living reference

AI Agent Incident Register

AI Agent Incident Register

The AI Agent Incident Register documents incidents in which an AI agent took actions, classifying each by which of the five authorization questions failed: what the agent was authorized to see, decide, and do, who approved it, and whether the actions could be reconstructed.

Why an action-layer register

Existing incident databases catalogue AI harms broadly, and most entries concern what a model said or predicted. As AI systems gain keyboards, terminals, and browsers, a different class of incident appears: an agent acted, and the organization could not answer the authorization questions afterward. This register documents that class specifically, because the lessons are different. A biased answer teaches you about training data. An unauthorized action teaches you about identity, scope, approval, and reconstruction.

Inclusion criteria

An entry qualifies when three things hold. An AI system took actions, not merely generated content. The incident is documented, either publicly reported with a source or disclosed first-party by the affected organization. And enough detail exists to classify it against the five questions. Entries state what is known, what is inferred, and what could not be established; an entry that overstates its own reconstruction would fail the discipline it documents.

Entries

AIR-2026-001: Self-inflicted analytics pollution by an unmanaged browsing agent (first-party)

FieldAIR-2026-001
OrganizationEWR Digital (disclosed first-party by the register's maintainers)
WindowJune 8 to August 20, 2026 (ten weeks)
What happenedA headless-browser audit agent, running under default settings, loaded the organization's own production website repeatedly. No one had decided the agent should be visible to analytics; no one had decided anything. It generated 59% of all recorded sessions in the final 30-day window, silently distorting channel, engagement, and journey reporting.
Authorized to see / doNo authorization decision existed in either direction. The agent was doing legitimate audit work; its visibility to production analytics was an unexamined default. (Pillar: Representation Integrity at the action layer.)
Who approvedNo grant, no record. The tooling defaulted to visible. (Pillar: Decision Traceability.)
ReconstructionRequired weeks of forensic analysis of analytics fingerprints. It attributed the traffic to the organization's own automation with high confidence but could not name the exact host with certainty. (Pillar: Audit Readiness; maturity Level 1 on the action layer.)
ConsequenceThe analytics window is permanently polluted; the platform cannot delete it retroactively. Remediation: exclusion segments, analytics-blocking defaults in all agent tooling, marker parameters for deliberate test loads.
LessonThe domain was harmless. The failure class, an agent acting with no authorization record and no rehearsed reconstruction path, is the one that matters when the domain is lending, operations, or safety.
This register opens with our own incident, deliberately. A register that only catalogues other people's failures invites doubt about what its maintainers are not disclosing.

Submitting an incident

Documented incidents that meet the criteria are added on monthly review. Public reports with primary sources qualify; first-party disclosures are welcome and are marked as such. Entries never name an organization that has not either published the incident or consented to be named.

Frequently asked questions

What counts as an AI agent incident?

An incident in which an AI system took actions (not merely generated content), documented publicly or disclosed first-party, with enough detail to classify against the five authorization questions.

How is this different from the AI Incident Database?

General AI incident databases catalogue harms of all kinds, mostly at the model and output layer. This register documents the action layer specifically: incidents where the governance failure concerns authorization, identity, scope, approval, or reconstruction of agent actions.

References

  1. NIST AI Risk Management Framework (AI RMF 1.0): Govern, Map, Measure, Manage. National Institute of Standards and Technology, 2023. View source ↗
  2. Information governance: the records and data lifecycle discipline (storage, retention, disposition), distinct from AI decision governance. ARMA International, Generally Accepted Recordkeeping Principles; AIIM. View source ↗
  3. EU AI Act, Regulation (EU) 2024/1689 (Official Journal of the European Union); ISO/IEC 42001:2023; Texas Responsible AI Governance Act (TRAIGA). View source ↗
  4. USPTO Trademark Reg. No. 8147558 (Supplemental Register), Digital Information Governance / DIG, owner Matthew Bertram. View source ↗

Cite this page

Bertram, M. (2026). AI Agent Incident Register. Digital Information Governance® (DIG), Framework v1.1. https://digitalinformationgovernance.com/ai-agent-incident-register

@misc{dig-ai-agent-incident-register,
  author = {Bertram, Matthew},
  title = {AI Agent Incident Register},
  year = {2026},
  howpublished = {Digital Information Governance (DIG), Framework v1.1},
  url = {https://digitalinformationgovernance.com/ai-agent-incident-register}
}