INCIDENT INDEX · H1 2026

The money is already moving wrong.

Microsoft's security team now tells enterprises to treat a popular agent framework as "untrusted code execution with persistent credentials". This index tracks what that looked like in production. Every entry links to the primary source.

{{ i.date }} {{ i.source }}
{{ i.stat }} {{ i.title }}

{{ i.body }}

{{ i.tag }} · primary source →

"In this new payments paradigm, trust becomes the product."

Mastercard, announcing its agent-payments standard · Mar 2026
// AND THE COURTS HAVE ALREADY DECIDED WHOSE FAULT IT IS

Your agent's action is your action.

CALIFORNIA · AB 316 · JAN 2026

"The AI acted autonomously" is no longer a defense. The question in court stops being whether your agent went rogue and becomes what you authorized, and whether you can prove it.

UNITED KINGDOM · CMA · MAR 2026

You are responsible for your agent "in the same way you are responsible for what an employee does", with fines up to 10% of worldwide turnover under the DMCCA.

CANADA · MOFFATT v. AIR CANADA

The tribunal held Air Canada liable for a discount its chatbot invented. The promise your bot makes is your promise, the only open question is whether you can prove what it said.

Read the full legal record with primary sources →

None of these happen without you saying yes.

A discount your bot invents, a payee it was never told to pay, a record it deletes, a credential it reads: each one is checked against the authority you granted, before it runs. The refusal is signed, and so is the approval. That is the difference between your agent’s log and evidence you can hand to a court.

See the attacks it blocks, counted live → Become a design partner →