The AI Incident Registry documents real incidents at real organizations. To ensure the registry remains an authoritative, safe, and blame-free infrastructure resource, all contributors, maintainers, and reporters must strictly adhere to these non-negotiable ethical requirements.
Reports describe patterns, not blame specific organizations. Company names are entirely optional. If included, they require written permission from the reporting organization. Registry language must remain neutral and analytical.
Reports can be filed anonymously. Reporter identity is optional. Company name is optional. Only the technical pattern and its measurable negative impact are required. We prioritize the safety and privacy of those stepping forward to share failures.
Incidents involving active, exploitable vulnerabilities follow strict responsible disclosure timelines. By default, there is a 90-day embargo from vendor notification to public disclosure to allow for mitigation strategies to be developed.
We document what happened, not which AI tool is "bad." Every AI tool on the market has produced failures and vulnerable code. The registry is neutral infrastructure designed for learning, not a comparison shopping guide or a platform for vendor attacks.
Every report goes through a strict maintainer review process. Anonymous tips are investigated for technical accuracy and feasibility before becoming public entries. False reports or reports lacking technical detail will be rejected.
If a report is later found to misrepresent the incident or expose unintended sensitive data, the reporter or affected organization can request redaction. The entry remains listed (to preserve research integrity and prevent broken links) but with corrected, redacted details.