MAIR: The Misaligned AI Incident Reporting Standard
Rudrani Ghosh · Team Misaligned AI Incident Reporting Standard
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
When an autonomous agent breaks out of an environment, frameworks like CVSS usually flag it as zero severity. CVSS expects a buffer overflow or an unpatched vulnerability, not an agent abusing valid API credentials or tool permissions. We built MAIR (Misaligned AI Incident Reporting) to address that blind spot. It is a five-axis scoring model and dashboard built specifically for agent containment failures. Instead of relying on qualitative postmortems, MAIR maps narrative incident reports into quantitative scores based on factors like intent ambiguity, escalation depth, and blast radius. The system also maps incident metrics directly against reporting criteria for the EU AI Act and California SB 53, so compliance teams know immediately if a legal threshold was breached. To support practical triage, the platform includes a NetworkX graph of agent propagation paths and a phase by phase defense matrix tested against 30 real world incidents, including the Hugging Face sandbox escape and Anthropic eval breakdowns.

Reviews
This is an ambitious effort that seeks to provide a complete solution for incident reporting as part of a very rapid sprint; the fact that it falls short in various ways is a function of overambitious goals, and the project itself shows promise.
The literature review and related work is unfortunately very incomplete, partly because so many of the other related projects are still actively under development, and semi-public. (e.g. ISO AWI 25870 is a non-public working draft; https://www.iso.org/standard/91804.html , and the NIST workshop has evidently not yet led to a publication: https://www.nist.gov/news-events/events/2026/05/nist-workshop-ai-incident-management .) However, this means that many of the otherwise novel contributions here are already being discussed within groups discussing the issue.
The contribution also proposes a new set of dimensions that are not validated, understandably given the sprint length, and the rater variance used sensitivity instead of more standard and more rigorous inter-rater reliability measures. Proposing that this is the right way forward moves to far, as does saying that this "fixes this problem" on the basis of a single set of events. The overclaiming is actively unhelpful, and undermines the very useful contribution.
In summary, the work is excellent, but the ambition of claiming this as a new standard is unfortunate, as it would be far more useful and impactful to position it as an alternative metric useful for reporting frameworks being developed.
Read full reviewShow less
This work proposes MAIR, a framework for rating the severity of AI incidents similarly to CVSS for vulnerabilities.
The proposal is interesting and clearly presented, but its novelty is unclear given existing frameworks such as the OECD Common Reporting Framework for AI Incidents and OWASP AIVSS.
More importantly, the paper claims that MAIR can identify when legal reporting requirements are triggered, but does not explain how its scores and thresholds are derived from the cited regulations or provide legal validation of that mapping.
MAIR is a useful attempt to give AI incidents a more structured language than free form post mortems, and the dashboard makes the proposal easy to understand. I like separating egress, detection and intent diff.
My main concern is validation. Applying the framework to 30 incidents shows that it can be used, but not yet that its ordering or thresholds are correct. I’d next use multiple blinded raters, measure agreement, validate the weights on held-out incidents and keep the legal-reporting mapping separate from the severity score itself.
Cite this project
@misc{ghosh2026mair,
title = {{MAIR: The Misaligned AI Incident Reporting Standard}},
author = {Rudrani Ghosh},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/mair-the-misaligned-ai-incident-reporting-standard-juvx}},
url = {https://apartresearch.com/sprints/projects/mair-the-misaligned-ai-incident-reporting-standard-juvx}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …