A year of AI-agent incidents. The model is rarely the bug. (opens in new tab)
I want to walk through the public AI-agent incidents from the last sixteen months in chronological order. The headline framing on each of them, when they hit the press, was the AI did X. Read with a few months of distance, the structural cause in each case turns out to be something much more pedestrian: a permission scope nobody narrowed, a retry loop nobody bounded, a credential nobody rotated, a context window nobody made visible to the operator, a prompt-injection vector nobody walled off....
Read the original article