The Agent Incident Registry (AIR) was created to address the lack of a centralized repository for analyzing AI agent failures. The registry contains over 10,000 records of agent-related events, sourced from various disclosures. Each record includes supporting evidence, a stable identifier, and labels for causal role, disclosure class, mechanism, and outcome.
Within the generative-system records, approximately 80% involved realized harm, with a primary percentage of 90%. The majority of outcomes were found in in-the-wild and safety-failure records. Responsible disclosures and research demonstrations accounted for the remaining share.
Initial curation involved a second human reviewer checking all records and their existing labels. InjecAgent's 128 cases occupied three surfaces, all triggered by attackers. AIR contains no no-adversary safety failures.
The registry supports source-grounded case retrieval and evaluation-scope auditing. It does not provide failure-rate or control-efficacy estimation. Source: https://arxiv.org/abs/2609.11030