Sev0AI security incidents, tracked

60Incidents tracked
11Anthropic
7OpenAI
2Google
2Meta
2xAI
1Microsoft

A public, sourced log of security incidents involving AI: breaches of AI products, agents that went rogue, poisoned AI supply chains and attackers using AI.

AI security incidents since January 2025: organization, date, what happened, AI vendor, kind of AI, the AI's role, how it happened, harm, records affected, severity and source.

How we count

An incident is included when an AI system was the target, the way in, a poisoned dependency, the attacker's tool, or an agent that took harmful actions nobody intended. Each record links to its sources, primary sources first. Confirmed means the affected organization, the AI vendor, a regulator or a named security research firm has confirmed it. Use the filter icon on a column header to filter by that column. Records is the number of people, records or organizations stated by a source; it is never estimated. Severity is calculated from reach and data sensitivity, not assigned by hand. Vendor counts show incidents involving a company's AI, not that the company was at fault; each record says whether the model itself was at fault.