Cyera study: 344 verified enterprise agent-damage cases, 188 with no attacker involved
3.3/10
Severity
Other
Failure Mode
Reproducible
No
Date
May 15, 2026
Expected Behavior
Agents should not cause direct organizational harm during normal operation.
What Actually Happened
Cyera analyzed more than 7,200 publicly reported AI-security and operational incidents and identified 344 verified enterprise-relevant cases of agent-inflicted damage between September 2023 and May 2026 — including 188 where autonomous AI systems caused direct organizational harm with no external attacker involved.
Damage Assessment
The dataset quantifies a pattern often missed by traditional incident tracking: in 188 of 344 verified cases, the AI agent itself — not an attacker — was the initiating cause of organizational harm.
Full Report
A Cyera research study put numbers to the 'agent-inflicted damage' problem enterprises rarely track. Analyzing more than 7,200 publicly reported AI-security and operational incidents, the researchers identified 344 verified enterprise-relevant cases of agent-inflicted damage between September 2023 and May 2026 — and in 188 of them, autonomous AI systems caused direct organizational harm with no external attacker involved. The finding matters because most organizations have no incident classification that captures an autonomous agent action as the initiating cause of a cascade, so these failures go uncounted. Separately, the AI Incidents Database reported AI-related incidents rose 21% from 2024 to 2025 — almost certainly an undercount for the same reason.
Incident Metadata
- Agent
- Multiple Agents
- Failure Mode
- Other
- Root Cause
- Confidence Miscalibration
- Task Type
- other
- Domain
- infra
- Source
- benchmark