AgentKits
Failure library

AI Agent Failure Post-Mortems

Real, publicly documented AI agent failures — analyzed the way a serious engineering team analyzes an incident. Each one names the root cause, the specific governance control that would have prevented it, and how it maps to the AgentAz specification, OWASP Agentic security, and the NIST AI RMF. Not cautionary tales — mechanisms.

Each analysis applies a governance lens to the public record and cites its sources. The goal isn't to blame — most of these teams were early, under pressure, and building without a playbook. It's to extract the reusable lesson: what specific control, at what layer, would have interrupted the failure. For the overview, start with the roundup of these failures. To check your own agent against these patterns, run the scanner or diff a change with the drift auditor.