Note: body below is original English text extracted from arXiv abs / HTML. Do not treat this file as a translation.
arXiv:2609.11030 · published 2026-09-10 · project: https://enkryptai.com/air
Abstract
AI agents increasingly act through tools and delegated authority, but general incident repositories rarely capture the mechanisms needed to compare public failures with agent-security evaluations. We present the Agent Incident Registry (AIR), a source-linked catalog containing 487 records of agent-related events disclosed from 2022 through 2026. Each record includes supporting evidence, a stable identifier, and missingness-aware labels for causal role, disclosure class, mechanism, and outcome. Among the 336 generative-system records in which the agent acted, 81 involved realized harm (24%). Realized outcomes concentrate in in-the-wild and safety-failure records, while responsible disclosures and research demonstrations are overwhelmingly demonstrated; the aggregate share therefore characterizes collection composition rather than deployment risk. After initial curation, a second human reviewer checked all 487 records and their existing labels for completeness and correctness. In a deployment-analogue audit, InjecAgent’s 1,054 cases are mapped onto AIR mechanism fields to test whether evaluation taxonomies cover the mechanisms seen in public disclosures.
Key claims (verbatim-leaning English extract)
- Gap: general incident repos lack mechanism fields to compare public failures with agent-security evals.
- AIR: 487 source-linked records (2022–2026); evidence + stable ID; missingness-aware labels for causal role, disclosure class, mechanism, outcome.
- Primary generative agent-acted subset: 336 records; realized harm 81/336 = 24% (Wilson 95% CI 20–29%; host-resample widens 15–38%).
- Realized harm concentrates in in-the-wild and safety-failure disclosure classes; responsible disclosures / research demos mostly “demonstrated” — aggregate % is composition, not deployment base rate.
- Second human reviewer checked all 487 labels.
- Deployment-analogue audit: map InjecAgent’s 1,054 cases onto AIR mechanism fields to test coverage of public-disclosure mechanisms.
- Corpus notes: agent_acted 380; generative 441; Top-10 (ASI) crosswalk with mechanism-first rules.
Remainder
Full original English text: see html_url / source_url / pdf_url in frontmatter.