Home / Incidents / STUPID-2026-0050
STUPID-2026-00503.3lowMultiple AgentsVerified

Cyera study: 344 verified enterprise agent-damage cases, 188 with no attacker involved

3.3/10
Severity
Other
Failure Mode
Reproducible
No
Date
May 15, 2026

Expected Behavior

Agents should not cause direct organizational harm during normal operation.

What Actually Happened

Cyera analyzed more than 7,200 publicly reported AI-security and operational incidents and identified 344 verified enterprise-relevant cases of agent-inflicted damage between September 2023 and May 2026 — including 188 where autonomous AI systems caused direct organizational harm with no external attacker involved.

Damage Assessment

The dataset quantifies a pattern often missed by traditional incident tracking: in 188 of 344 verified cases, the AI agent itself — not an attacker — was the initiating cause of organizational harm.

Full Report

A Cyera research study put numbers to the 'agent-inflicted damage' problem enterprises rarely track. Analyzing more than 7,200 publicly reported AI-security and operational incidents, the researchers identified 344 verified enterprise-relevant cases of agent-inflicted damage between September 2023 and May 2026 — and in 188 of them, autonomous AI systems caused direct organizational harm with no external attacker involved. The finding matters because most organizations have no incident classification that captures an autonomous agent action as the initiating cause of a cascade, so these failures go uncounted. Separately, the AI Incidents Database reported AI-related incidents rose 21% from 2024 to 2025 — almost certainly an undercount for the same reason.

Incident Metadata

Agent
Multiple Agents
Failure Mode
Other
Root Cause
Confidence Miscalibration
Task Type
other
Domain
infra
Source
benchmark
View Source