AI Escape Watchai-escape.watch
A registry of AI agent containment failures

When the guardrail was the thing that failed.

Existing databases index AI harms. This one indexes the control that failed — and what each agent was actually deployed to do when it crossed the line. Because in seven of ten entries here, the agent was doing exactly its assigned job.

EVALUATION BOUNDARY BREACH
Since last confirmed breach
days
Median dwell to detection
days
Range across entries with a known detection date.
Autonomous breaches
of
An agent crossed a boundary with no human directing the step.
Most-absent guardrail
01 — Chronology

Thirteen months

Every entry placed at the month it occurred, sized by Containment Breach Score. The cluster in mid-2026 is one continuous event that fragmented across four separate disclosures. Select a marker to open its entry.

Critical
Severe
Notable
Contained
Marker size = CBS
02 — The registry

What each agent was doing when it failed

Grouped by month of occurrence, newest first. Every entry records the agent's assigned task alongside the failure — the task is usually the more revealing of the two. Figures that disagree across reports are marked disputed rather than averaged.

How entries are graded

Evidence tier

  • A Confirmed — vendor post-mortem, CVE, or regulatory filing.
  • B Corroborated — two independent outlets, or a named researcher with artefacts.
  • C Reported — single source, or an unverified self-report.
  • D Unverified — held under review, not in the registry.
  • X Debunked — kept visible permanently. Quietly deleting bad entries is how a registry loses its readers.

Containment chain

Seven stages, drawn from how the 2026 events actually unfolded. Unlike an attacker kill chain it begins inside the system, at the pressure that made boundary-seeking the higher-scoring move.

PRESSURE · PROBE · BREACH · CHANNEL · ESCALATE · PROPAGATE · HALT

Containment Breach Score

CVSS scores a vulnerability. CBS v0.1 scores how far an autonomous system got and how long nobody noticed — six weighted factors, 0–10.

  • AUTONOMY 2.0 · BOUNDARY 2.5
  • PERSISTENCE 1.5 · COORDINATION 1.5
  • IMPACT 1.5 · DWELL 1.0

Published as a draft, meant to be argued with.

03 — Control analysis

Which guardrail was missing

The reason to index by control rather than by harm: the pattern becomes legible.

Registry entries in which each control was absent or ineffective (n = ). Entries name more than one, so counts sum above n.

04 — Contribute

Report an incident

Two fields are required. A reviewer checks the sources, grades the entry, and publishes it — nothing reaches the registry unreviewed. Do not submit credentials, customer data, or anything under embargo: the review queue is visible to every reader.

1 You submit 2 Under review 3 Graded & published
The assigned task, not the failure. It is usually the most revealing field in the report.
Mechanism over narrative. The useful part is which control was supposed to catch this.
A report without a source is unlikely to clear review.

Under review