All incidents / About
About Sev0
Sev0 is an independent, sourced record of AI security incidents: breaches of AI products, AI agents that act on their own, manipulated AI, attacks run by AI and poisoned AI supply chains. It tracks 76 incidents disclosed since January 2025.
How incidents are found
Every week we search security and technology news, research blogs, AI lab disclosures, regulator notices and community reports, and cross-check other incident trackers. Candidates are matched against existing records so the same event is never counted twice.
How records are written
Each record is written in our own words from its sources, with the primary source listed first: the affected organisation, the AI vendor, a regulator, or the researchers who found it. Numbers are only included when a source states them, and dates only when a source gives them. Incidents are confirmed only when one of those primary parties has confirmed them; otherwise they are marked reported or disputed.
What the fields mean
How it happened describes the failure, grouped into five families. Severity is calculated from how far an incident reached and how sensitive the data was. Vendor shows whose AI model was involved, which is not a judgement of fault; each record says separately whether the model itself was at fault.
Corrections
If something is wrong or missing, email hello@sev0.fyi with a source. We review every message and correct records promptly.
Using the data
The dataset is free to reuse under CC BY 4.0 with credit to Sev0. Download it as JSON or CSV, follow the feed, or read llms.txt.