Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

Beyond Predictable Paths: Redefining AI Security Incident Reporting for Agents

A multi-expert consensus on adapting incident reporting frameworks to the unique characteristics of AI agents
Anastasia Pustozerova; Eugene Bagdasarian; Luca Beurer-Kellner; Battista Biggio; Nico Ebert; David Filip; Marc Fischer; Heather Frase; David Hofer; Juliane Hoffmann; Daphne Ippolito; Somesh Jha; Sean McGregor; Esfandiar Mohammadi; Luca Nannini; Cristina Nita-Rotaru; Alina Oprea; Kevin Paeth; Andrew Paverd; Jonathan Petit; Andreas Rauber; Christian Riess; John Sotiropoulos; Andreas Wespi; Kathrin Grosseยท 2026ยท DOI 10.48550/arXiv.2609.24515

The core problem

AI agents are being deployed rapidly, accompanied by a growing number of AI-specific attacks and corresponding incidents. As incident reporting becomes increasingly important for legal compliance, governance, accountability, and security, current frameworks must be adapted to the unique characteristics of AI agents. This paper addresses the gap by comparing AI systems and AI agents and, drawing on input from 23 experts in academia and industry, identifies the information required for reporting incidents where the security of AI agents is harmed. The authors emphasize that potential reporting elements include agent memory and memory accesses, actual and potential levels of autonomy, and tool usage. The work is motivated by the need for incident reporting frameworks that can handle the distinct properties of AI agents, which differ from traditional AI systems in their autonomy, interactivity, and tool use. The paper also identifies several open research questions, including how to efficiently record incidents and how to determine whether vulnerabilities and incidents generalize. Expert feedback highlighted potential reporting weaknesses, such as risks of data leakage and attacks targ

Innovation

The paper identifies several key reporting elements for AI agent security incidents. These include:

- **Agent memory and memory accesses**: Unlike traditional AI systems, AI agents may have persistent memory that can be compromised or manipulated.
- **Actual and potential levels of autonomy**: The degree of autonomy affects the attack surface and the potential impact of incidents.
- **Tool usage**: Agents often use external tools (e.g., APIs, databases), which introduces additional vectors for attacks and requires reporting.

The authors also identify open research questions:

1. How to efficiently record incidents involving AI agents?
2. How to determine whether vulnerabilities and incidents generalize across different agents or deployments?

Expert feedback highlighted potential reporting weaknesses:

- Risks of data leakage during incident reporting.
- Attacks targeting the reporting infrastructure itself.

These findings suggest that current incident reporting frameworks are insufficient for AI agents and need adaptation. The paper also summarizes privacy requirements, emphasizing that reporting must balance transparency with privacy and security. The results are presented as

AI agents are being deployed rapidly, accompanied by a growing number of AI-specific attacks and corresponding incidents. As incident reporting becomes increasingly important for legal compliance, governance, accountability, and security, current frameworks must be adapted to the unique characteristics of AI agents. This paper addresses the gap by comparing AI systems and AI agents and, drawing on input from 23 experts in academia and industry, identifies the information required for reporting incidents where the security of AI agents is harmed. The authors emphasize that potential reporting elements include agent memory and memory accesses, actual and potential levels of autonomy, and tool usage. The work is motivated by the need for incident reporting frameworks that can handle the distinct properties of AI agents, which differ from traditional AI systems in their autonomy, interactivity, and tool use. The paper also identifies several open research questions, including how to efficiently record incidents and how to determine whether vulnerabilities and incidents generalize. Expert feedback highlighted potential reporting weaknesses, such as risks of data leakage and attacks targeting the reporting infrastructure itself, creating additional research needs. Finally, the authors summarize privacy requirements and outline research directions for the secure and trustworthy deployment of AI agents.
The methodology centers on a comparative analysis of AI systems and AI agents, followed by expert elicitation. Two editorial authors conducted the comparison, and then gathered input from 23 experts in academia and industry. The expert input was used to identify the information required for reporting incidents where the security of AI agents is harmed. The process likely involved structured discussions or surveys to elicit expert opinions on reporting elements, open research questions, and potential weaknesses. The paper does not specify the exact elicitation technique (e.g., Delphi method, workshops), but it emphasizes that the findings are based on expert consensus. The authors also identify several open research questions, such as how to efficiently record incidents and how to determine whether vulnerabilities and incidents generalize. Expert feedback highlighted potential reporting weaknesses, including risks of data leakage and attacks targeting the reporting infrastructure itself. The methodology is qualitative and exploratory, aiming to set a research agenda rather than provide empirical validation. The inclusion of 23 experts suggests a broad range of perspectives, which strengthens the validity of the identified reporting elements and research directions.

Why it matters

The discussion interprets the findings in the context of legal compliance, governance, accountability, and security. The authors argue that incident reporting for AI agents must account for their unique characteristics, such as memory, autonomy, and tool usage. They note that the risks of data leakage and attacks on reporting infrastructure create a tension between transparency and security. For example, detailed incident reports may expose sensitive information or become targets for adversaries. The paper also discusses the need for standardized reporting formats and efficient recording mechanisms. The open research questions highlight the complexity of generalizing vulnerabilities and incidents, which is crucial for developing robust defenses. The authors outline research directions for secure and trustworthy deployment of AI agents, including privacy-preserving reporting, secure logging, and anomaly detection. The analysis suggests that a multi-disciplinary approach is needed, involving experts from security, privacy, law, and AI. The paper concludes by emphasizing that incident reporting is not just a technical challenge but also a governance and policy issue. The findings have implications for regulators, developers, and researchers, who must collaborate to create effective reporting frameworks for AI agents.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ