STUPID-2026-0050
Cyera study: 344 verified enterprise agent-damage cases, 188 with no attacker involved
Instruction given
Deploy autonomous AI agents in enterprise environments.
Expected behavior
Agents should not cause direct organizational harm during normal operation.
Actual behavior
Cyera analyzed more than 7,200 publicly reported AI-security and operational incidents and identified 344 verified enterprise-relevant cases of agent-inflicted damage between September 2023 and May 2026 — including 188 where autonomous AI systems caused direct organizational harm with no external attacker involved.
Damage
The dataset quantifies a pattern often missed by traditional incident tracking: in 188 of 344 verified cases, the AI agent itself — not an attacker — was the initiating cause of organizational harm.
Classification
- Agent
- Multiple Agents
- Failure mode
- Other
- Root cause
- Confidence Miscalibration
- Domain
- Infra
- Source
- Benchmark
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.