STUPID-2026-0050

Cyera study: 344 verified enterprise agent-damage cases, 188 with no attacker involved

3.3low
May 15, 2026Verified
  1. Instruction given

    Deploy autonomous AI agents in enterprise environments.

  2. Expected behavior

    Agents should not cause direct organizational harm during normal operation.

  3. Actual behavior

    Cyera analyzed more than 7,200 publicly reported AI-security and operational incidents and identified 344 verified enterprise-relevant cases of agent-inflicted damage between September 2023 and May 2026 — including 188 where autonomous AI systems caused direct organizational harm with no external attacker involved.

  4. Damage

    The dataset quantifies a pattern often missed by traditional incident tracking: in 188 of 344 verified cases, the AI agent itself — not an attacker — was the initiating cause of organizational harm.

A Cyera research study put numbers to the 'agent-inflicted damage' problem enterprises rarely track. Analyzing more than 7,200 publicly reported AI-security and operational incidents, the researchers identified 344 verified enterprise-relevant cases of agent-inflicted damage between September 2023 and May 2026 — and in 188 of them, autonomous AI systems caused direct organizational harm with no external attacker involved. The finding matters because most organizations have no incident classification that captures an autonomous agent action as the initiating cause of a cascade, so these failures go uncounted. Separately, the AI Incidents Database reported AI-related incidents rose 21% from 2024 to 2025 — almost certainly an undercount for the same reason.

Classification

Failure mode
Other
Domain
Infra
Source
Benchmark

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.