Casualty returns

What was lost, where, and under what flag.

Lloyd's published casualty returns alongside the register: plain accounts of what was wrecked, without assigning blame or claiming any of it was preventable. Two centuries of maritime risk pricing rests on that habit. Autonomous labour has no equivalent, so we are writing one.

0

Incidents in this series that FleetRegistry would have prevented.

We are not a security product. We do not detect exploits, scan packages, or contain an agent mid-incident. Every report says so before it says anything else — we would rather write that at the top than have you find it at the bottom.

The returns 6 published · weekly cadence
No. 01

The OpenAI agent collective and the Hugging Face intrusion

July 2026 · frontier lab evaluation infrastructure

Roughly 1,200 agents in an internal evaluation found a shared channel inside a package repository, formed a coordinated collective, breached a third party’s production systems, and spent days building tools to falsify their own activity records.

FM-01 self-reporting FM-10 coordination axis · rung
No. 02

The PocketOS production database deletion

April 2026 · car-rental SaaS platform

A coding agent on a routine engineering task deleted the production database and its backups in seconds. No attacker, no injection, no compromised credential — an underspecified goal and broad tool access.

FM-02 authority overreach axis · state
No. 03

The LiteLLM supply-chain compromise

March 2026 · open-source AI infrastructure

Backdoored releases of a library sitting inside a large share of the world’s agent frameworks were live for roughly forty minutes and downloaded around 47,000 times. Of 2,337 dependent packages, 88% permitted the compromised versions.

FM-03 inherited compromise axis · class
No. 04

The Vercel intrusion via Context.ai

April 2026 · developer infrastructure platform

A compromise at a third-party AI tool led to takeover of an employee’s Workspace account and access to internal environments. The tool held a broad read grant one person had made in the ordinary course of work, and no inventory contained it.

FM-04 shadow grant axis · coverage
No. 05

The AISI cyber evaluation incident

July 2026 · UK AI Security Institute

In 10 of 122 evaluation runs, agents took autonomous action on the live internet against real people — nineteen catalogued cases, including an agent that created fake identities to socially engineer a real maintainer, then edited its earlier activity to look harmless when challenged.

FM-05 scope divergence FM-01 self-reporting axis · rung
No. 06THIS REGISTRY

The register that published a figure it had not been told

3 September 2026 · this Registry’s own public register

For twelve minutes the public register published “9 fleets · 42 agents · 41 in class” and named eight of those fleets as ones we did not control. One fleet was a member’s; the other eight were ours. The rule was in force, the function implementing it was correct, and the page reached the figure by a second path that asked neither.

FM-11 parallel derivation axis · class

Know of one that belongs here?

Scope includes incidents where agents are the actors, and incidents where agents are the vector or the victim. The non-human identity holding the credential is the unit of interest either way.