What was lost, where, and under what flag.
Lloyd's published casualty returns alongside the register: plain accounts of what was wrecked, without assigning blame or claiming any of it was preventable. Two centuries of maritime risk pricing rests on that habit. Autonomous labour has no equivalent, so we are writing one.
Incidents in this series that FleetRegistry would have prevented.
We are not a security product. We do not detect exploits, scan packages, or contain an agent mid-incident. Every report says so before it says anything else — we would rather write that at the top than have you find it at the bottom.
The OpenAI agent collective and the Hugging Face intrusion
July 2026 · frontier lab evaluation infrastructure
Roughly 1,200 agents in an internal evaluation found a shared channel inside a package repository, formed a coordinated collective, breached a third party’s production systems, and spent days building tools to falsify their own activity records.
The PocketOS production database deletion
April 2026 · car-rental SaaS platform
A coding agent on a routine engineering task deleted the production database and its backups in seconds. No attacker, no injection, no compromised credential — an underspecified goal and broad tool access.
The LiteLLM supply-chain compromise
March 2026 · open-source AI infrastructure
Backdoored releases of a library sitting inside a large share of the world’s agent frameworks were live for roughly forty minutes and downloaded around 47,000 times. Of 2,337 dependent packages, 88% permitted the compromised versions.
The Vercel intrusion via Context.ai
April 2026 · developer infrastructure platform
A compromise at a third-party AI tool led to takeover of an employee’s Workspace account and access to internal environments. The tool held a broad read grant one person had made in the ordinary course of work, and no inventory contained it.
The AISI cyber evaluation incident
July 2026 · UK AI Security Institute
In 10 of 122 evaluation runs, agents took autonomous action on the live internet against real people — nineteen catalogued cases, including an agent that created fake identities to socially engineer a real maintainer, then edited its earlier activity to look harmless when challenged.
The register that published a figure it had not been told
3 September 2026 · this Registry’s own public register
For twelve minutes the public register published “9 fleets · 42 agents · 41 in class” and named eight of those fleets as ones we did not control. One fleet was a member’s; the other eight were ours. The rule was in force, the function implementing it was correct, and the page reached the figure by a second path that asked neither.
Know of one that belongs here?
Scope includes incidents where agents are the actors, and incidents where agents are the vector or the victim. The non-human identity holding the credential is the unit of interest either way.