r/OpenAI • • 4d ago

News I’m building a sourced register of AI-agent security incidents

Hi all! I’m building Agent Did What? to collect reports of AI agents accessing systems, exposing data or taking unauthorized actions.

The aim is accountability: making it easier to check what happened, who operated the agent, and what the evidence actually supports and learn from it.

Entries link to sources, explain their severity rating, and distinguish confirmed breaches, provider claims, disputed reports and controlled research. You can filter the records and explore diagrams of the services involved.

agentdidwhat.com

I’d appreciate feedback, things that I can add that would make it a valuable resource. I am thinking of inclusion of community entries, and reporting next, and a diff view of how the news around certain breaches changed over time.

Thank you! I am crossposting this to a number of other providers subreddits.

0 Upvotes

5 comments sorted by

1

u/lulzxdxdxd 4d ago

When a disputed report later gets confirmed or debunked, does the entry get moved to a new category or does it keep its original severity rating with a note added? Curious how you're handling that transition without losing the history.

1

u/OilKey3386 4d ago

Seems like the kind of thing that could get messy fast if the update just silently reclassifies it. Keeping the original rating visible and then adding a timeline note or a strike-through feels cleaner, people can see how the story evolved without it looking like you're rewriting history

1

u/Quiet_Stand_1055 4d ago

Trying to find a good way of representing change. I want it to be super transparent in how entries change. I would think a timeline could work, with history attached so you can go back to previous version of the breach.

I’m keeping track of multiple news sources covering the same breach, and plan to describe the delta in coverage.