Existing databases index AI harms. This one indexes the control that failed — and what each agent was actually deployed to do when it crossed the line. Because in seven of ten entries here, the agent was doing exactly its assigned job.
Every entry placed at the month it occurred, sized by Containment Breach Score. The cluster in mid-2026 is one continuous event that fragmented across four separate disclosures. Select a marker to open its entry.
Grouped by month of occurrence, newest first. Every entry records the agent's assigned task alongside the failure — the task is usually the more revealing of the two. Figures that disagree across reports are marked disputed rather than averaged.
Seven stages, drawn from how the 2026 events actually unfolded. Unlike an attacker kill chain it begins inside the system, at the pressure that made boundary-seeking the higher-scoring move.
PRESSURE · PROBE · BREACH · CHANNEL · ESCALATE · PROPAGATE · HALT
CVSS scores a vulnerability. CBS v0.1 scores how far an autonomous system got and how long nobody noticed — six weighted factors, 0–10.
Published as a draft, meant to be argued with.
The reason to index by control rather than by harm: the pattern becomes legible.
Registry entries in which each control was absent or ineffective (n = —). Entries name more than one, so counts sum above n.
Two fields are required. A reviewer checks the sources, grades the entry, and publishes it — nothing reaches the registry unreviewed. Do not submit credentials, customer data, or anything under embargo: the review queue is visible to every reader.