Directory

Reporting Resources

Organizations and programs for disclosing AI vulnerabilities, highlighting scope, submission processes, and criteria for reporting.

Available Resources

  • AI Incident Database

    Report
    Civil SocietyIncident Database

    You should report here if...

    You have knowledge of an AI-related incident that caused harm and has been reported in media or you have direct knowledge of. Submissions are reviewed by editors.

    Report Scope:
    Incident
  • AI Vulnerability Database

    Report
    Civil SocietyIncident Database

    You should report here if...

    You discovered vulnerabilities covering Security, Ethics, and Performance (SEP) issues across the AI lifecycle using CVE-inspired procedures.

    Report Scope:
    Security VulnerabilityAI Safety
  • AIAAIC Repository

    Report
    Civil SocietyIncident Database

    You should report here if...

    You want to report AI, algorithmic, or automation incidents and controversies, particularly those involving poor ethics, transparency, or accountability.

    Report Scope:
    Incident
  • CERT

    Report
    Government Agency

    You should report here if...

    You discovered vulnerabilities that affect multiple vendors, impact safety/critical infrastructure, or when vendor coordination has broken down.

    Report Scope:
    Security Vulnerability
  • CISA

    Report
    Government Agency

    You should report here if...

    You found cybersecurity vulnerabilities in AI systems with potential cybersecurity impact. CISA treats AI as a subset of software systems.

    Report Scope:
    Security Vulnerability
  • MITRE ATLAS

    Report
    Government Agency

    You should report here if...

    You want to share real-world AI incidents with the trusted community or contribute to the adversarial tactics knowledge base for AI systems.

    Report Scope:
    IncidentSecurity Vulnerability
  • MITRE CVE

    Report
    Government Agency

    You should report here if...

    You discovered traditional cybersecurity vulnerabilities, including some ML-related security flaws that need CVE assignment.

    Report Scope:
    Security Vulnerability
  • NIST

    Report
    Government Agency

    You should report here if...

    You want to collaborate on research-oriented AI risk assessment, testing, and systematic evaluation of AI systems using frameworks like AI RMF

    Report Scope:
    AI Safety
  • OECD AI Incidents and Hazards Monitor

    Report
    Government Agency / International Org

    You should report here if...

    You have information about AI incidents that caused injury, infrastructure disruption, rights violations, or property/environmental harm. Currently does not accept direct submissions but plans to expand.

    Report Scope:
    Incident
  • UK AI Security Institute

    Report
    Government Agency

    You should report here if...

    You have novel evaluations, agent scaffolding discoveries, or want to participate in their bounty program for AI safety research.

    Report Scope:
    AI Safety
  • US AI Safety Institute

    Report
    Government Agency

    You should report here if...

    You want to report issues with AI capabilities assessments, safeguard testing, or collaborate on safety evaluations with national security implications.

    Report Scope:
    AI Safety
  • Anthropic

    Report
    AI Developer

    You should report here if...

    You discovered critical security vulnerabilities in cybersecurity or high-risk domains (e.g., CBRN). HackerOne program focuses on security issues; jailbreaks are typically out of scope but can be reported to safety channels.

    Report Scope:
    Security VulnerabilityAI Safety
  • Google

    Report
    AI Developer

    You should report here if...

    You found privacy/security attacks, AI-specific vulnerabilities like weight extraction, or prompt injections. Content issues are out of scope for bounty but can be reported via dedicated channels.

    Report Scope:
    Security Vulnerability
  • OpenAI

    Report
    AI Developer

    You should report here if...

    You discovered security flaws in APIs, ChatGPT, Playground, or third-party corporate targets. Note: Content issues like hallucinations are out of scope for bounty but can be reported separately.

    Report Scope:
    Security Vulnerability

About AI Flaw Reporting

What is AI Flaw Reporting?

AI flaw reporting is the process of identifying, documenting, and disclosing safety issues, security vulnerabilities, or harmful behaviors in artificial intelligence systems. This includes issues like:

  • Security vulnerabilities that could be exploited by malicious actors
  • Safety issues that could cause real-world harm
  • Bias, discrimination, or unfair treatment in AI outputs
  • Unintended behaviors or capability overhang
  • Privacy violations or data mishandling

Purpose of This Website

This platform provides a structured, standardized way to document AI flaws and incidents. Our goal is to:

  • Create comprehensive reports that can be submitted to appropriate organizations
  • Ensure consistent documentation standards across the AI safety community
  • Facilitate responsible disclosure to AI developers and safety organizations
  • Build a knowledge base for improving AI safety practices

Ready to contribute?

Whether you're a researcher, developer, or concerned user, your reports help make AI safer for everyone.