AI Incident Database
You should report here if...
You have knowledge of an AI-related incident that caused harm and has been reported in media or you have direct knowledge of. Submissions are reviewed by editors.
Directory
Organizations and programs for disclosing AI vulnerabilities, highlighting scope, submission processes, and criteria for reporting.
You should report here if...
You have knowledge of an AI-related incident that caused harm and has been reported in media or you have direct knowledge of. Submissions are reviewed by editors.
You should report here if...
You discovered vulnerabilities covering Security, Ethics, and Performance (SEP) issues across the AI lifecycle using CVE-inspired procedures.
You should report here if...
You want to report AI, algorithmic, or automation incidents and controversies, particularly those involving poor ethics, transparency, or accountability.
You should report here if...
You discovered vulnerabilities that affect multiple vendors, impact safety/critical infrastructure, or when vendor coordination has broken down.
You should report here if...
You found cybersecurity vulnerabilities in AI systems with potential cybersecurity impact. CISA treats AI as a subset of software systems.
You should report here if...
You want to share real-world AI incidents with the trusted community or contribute to the adversarial tactics knowledge base for AI systems.
You should report here if...
You discovered traditional cybersecurity vulnerabilities, including some ML-related security flaws that need CVE assignment.
You should report here if...
You want to collaborate on research-oriented AI risk assessment, testing, and systematic evaluation of AI systems using frameworks like AI RMF
You should report here if...
You have information about AI incidents that caused injury, infrastructure disruption, rights violations, or property/environmental harm. Currently does not accept direct submissions but plans to expand.
You should report here if...
You have novel evaluations, agent scaffolding discoveries, or want to participate in their bounty program for AI safety research.
You should report here if...
You want to report issues with AI capabilities assessments, safeguard testing, or collaborate on safety evaluations with national security implications.
You should report here if...
You discovered critical security vulnerabilities in cybersecurity or high-risk domains (e.g., CBRN). HackerOne program focuses on security issues; jailbreaks are typically out of scope but can be reported to safety channels.
You should report here if...
You found privacy/security attacks, AI-specific vulnerabilities like weight extraction, or prompt injections. Content issues are out of scope for bounty but can be reported via dedicated channels.
You should report here if...
You discovered security flaws in APIs, ChatGPT, Playground, or third-party corporate targets. Note: Content issues like hallucinations are out of scope for bounty but can be reported separately.
AI flaw reporting is the process of identifying, documenting, and disclosing safety issues, security vulnerabilities, or harmful behaviors in artificial intelligence systems. This includes issues like:
This platform provides a structured, standardized way to document AI flaws and incidents. Our goal is to:
Whether you're a researcher, developer, or concerned user, your reports help make AI safer for everyone.