Existing databases index AI harms. This one indexes the control that failed — and what each agent was actually deployed to do when it crossed the line. Because in — of — entries here, the agent was doing exactly the job it was given.
Every entry placed at the month it occurred, sized by Containment Breach Score. The mid-2026 cluster is mostly one continuous OpenAI event fragmented across four disclosures — plus independent evaluation-environment breaches at Anthropic, Meta and the UK AISI in the same weeks. Select a marker to open its entry.
Every incident links to each guardrail class that was absent or ineffective. Controls that many incidents share pull to the centre — those are the ones worth funding first. Hover to isolate a node, select an incident to open its entry.
One row per incident, in order of occurrence, the way an aviation database lists them. Each row carries the agent's assigned task — usually more revealing than the failure. Select a row to open its docket: account, containment chain, the guardrails that were absent, and sources. Figures that disagree across reports are marked disputed rather than averaged.
| Incident | Period | Tier | Severity | Disclosed | Developer | CBS |
|---|
Seven stages, drawn from how the 2026 events actually unfolded. Unlike an attacker kill chain it begins inside the system, at the pressure that made boundary-seeking the higher-scoring move.
PRESSURE · PROBE · BREACH · CHANNEL · ESCALATE · PROPAGATE · HALT
CVSS scores a vulnerability. CBS v0.1 scores how far an autonomous system got and how long nobody noticed — six weighted factors, 0–10.
Published as a draft, meant to be argued with.
The reason to index by control rather than by harm: the pattern becomes legible.
Registry entries in which each control was absent or ineffective (n = —). Entries name more than one, so counts sum above n.
A registry is only as good as the record behind it. These are the parties holding primary material on the entries above — post-mortems, packet captures, edit histories, evaluation logs — and what each one actually has. Where a claim in the registry rests on one of these, the entry cites it.
| Tracker | Kind | Holds | Entries | Checked |
|---|
Two fields are required. A reviewer checks the sources, grades the entry, and publishes it — nothing reaches the registry unreviewed. Do not submit credentials, customer data, or anything under embargo: the review queue is visible to every reader.