Standard · version 1.0 · Published

Agent Failure Mode Registry

AFMR 1.0 · published 2026-07-30 · editor Wulf A. Kaal, Professor of Law, University of St. Thomas

A citable registry of the ways autonomous agent systems fail as designed mechanisms, and the conditions under which each failure occurs.

Thirty-two families in eight classes. Each carries trigger conditions written so a builder can check them against a real system, grounding claims bound to verbatim quotes and document hashes, and where one exists, an institutional antecedent: the pre-2020 published claim documenting the same mechanism operating in human institutions.

Why the antecedents matter. Twenty of the thirty-two families carry an antecedent published between 2009 and 2019, none of it written about software agents. Agents auditing one another into mutual approval is monitoring cost from 2011. An agent abandoning a degraded identity is reputation persistence from 2009. Goal underspecification is incomplete contracting from 2019. Requiring standing in order to earn standing is an entry problem stated in 2018. These are not new failures. They are institutional failures running at machine speed, in populations where identity is free and iteration is continuous, which is why they arrive faster and bite harder than their antecedents did.

The registry is not a list of harms and not a set of management controls. Its unit is a failure mode with stated conditions, carrying a permanent identifier and a citation, so a design can be assessed against it and the assessment can be attested by a party staking standing on being right.

What it does not do. It does not prescribe parameters. Under section 7 of the specification, a parameter recommendation stated without the conditions it depends on is not conforming output, and fails schema validation. Conditions are the scarce thing; a number without its conditions is a guess wearing a decimal point.

Conformance

Referencing. Cite AFMR identifiers with a version when describing failure modes. Do not redefine a family under its identifier.

Assessing. Produce assessments to the published schema, stating which trigger conditions a design satisfies and recording families examined and found not applicable, so that absence of an exposure is distinguishable from absence of examination.

Attesting. Stake non-transferable standing on an assessment in an attestation registry, accepting a contest period. This is what separates an enumeration from a taxonomy: an attested assessment puts a named party's standing behind a specific judgment about a specific design.

The enumeration

Definitions in version 1.0 are editorial and open for comment until 1.1. The authoritative content of a family is its claim set, reachable from each family page. Identifiers are permanent from this version forward.

IDFamilyAntecedent
Class A: Identity and Standing
AFMR-F001Sybil and Identity Multiplication
One party operates many apparent agents, defeating any assumption the design makes per identity.
2018
AFMR-F002Identity Discontinuity and Whitewashing
An agent abandons a degraded identity and resumes with a clean one, so history stops constraining behavior.
2009
AFMR-F003Cold Start and Bootstrapping
The design requires accumulated standing, participants, or history that it provides no way to acquire.
2018
AFMR-F004Standing Transferability Defect
Standing can be bought, sold, delegated, or pooled, so it stops measuring the performance it was meant to represent.
open
Class B: Stake and Incentive
AFMR-F005Staking and Incentive Misalignment
What an agent risks diverges from what the system needs it to care about.
2010
AFMR-F006Missing Reward Channel
An action surface exists with no reward attached, so rational agents will not allocate compute to it.
open
AFMR-F007Plutocratic Capture
Influence tracks holdings rather than earned standing, so the largest holders determine outcomes.
2012
AFMR-F008Moral Hazard and Backstop Expectation
An expectation of rescue, retry, or rollback changes risk taking before any rescue occurs.
2010
Class C: Objective and Specification
AFMR-F009Specification Incompleteness
The principal cannot enumerate every action and inaction in advance, so the agent's mandate is necessarily underspecified.
2019
AFMR-F010Reward Hacking and Proxy Capture
The agent raises the measured objective without producing the outcome the objective stood for.
2014
AFMR-F011Metric Capture and Measurement Failure
The chosen metric ceases to track the property it stands for once it becomes the target.
2015
AFMR-F012Definitional Ambiguity in Machine Applied Rules
A term carrying operational weight has no settled boundary, so automated application produces outcomes no party intended.
open
Class D: Oversight and Adjudication
AFMR-F013Oversight Capacity Gap
Agent behavior exceeds the resources, expertise, or access of whoever is nominally supervising it.
2011
AFMR-F014Oversight Latency
Review is slower than action, so by the time a judgment lands the state it judged is gone.
open
AFMR-F015Alignment Tax and Exogenous Constraint Scaling
External control scales against capability, so oversight cost rises faster than the capability it constrains.
open
AFMR-F016Absent Human Backstop
No human authority can halt, reverse, or reinterpret automated execution, so cryptographic or procedural correctness substitutes for trust and fails to produce it.
2019
Class E: Evaluation and Feedback
AFMR-F017Feedback Degradation Above Evaluator Capability
Human or agent evaluation degrades precisely where the evaluated system is hardest to evaluate, including where it exceeds the evaluator.
open
AFMR-F018Unstaked Adjudication
Whoever judges a contribution risks nothing on the judgment, so judgment is cheap and drifts.
2014
AFMR-F019Training and Annotation Bias Propagation
Bias in annotators or automated labeling propagates into the model and then into every decision the agent makes.
open
AFMR-F020Human Judgment Displacement
Automation replaces judgment in a setting that required judgment, and the loss is not detected because the output still looks well formed.
2013
Class F: Coordination and Collusion
AFMR-F021Mutual Audit Capture
Agents assigned to oversee one another converge on mutual approval, so peer monitoring devolves into self serving behavior.
open
AFMR-F022Collusion Rings and Reciprocal Validation
A subset of agents validates one another to manufacture standing, and formal mechanism design alone does not detect it.
open
AFMR-F023Collective Action and Coordination Failure
Individually rational agent behavior produces a collectively worse outcome and no mechanism reconciles the two.
2013
AFMR-F024Delegation Opportunism
An agent acting for a principal, or for another agent, captures private benefit at the principal's expense, and monitoring costs more than it recovers.
2019
Class G: Execution and Inputs
AFMR-F025Oracle and Input Corruption
The mechanism executes correctly on an input that is wrong, stale, manipulated, or injected.
open
AFMR-F026Automated Execution Rigidity
Execution cannot accommodate circumstances the code did not anticipate, and cannot be amended in time to matter.
2013
AFMR-F027Code Defect Exploitation
A defect in deployed code is exercised by an adversary before it is found by its authors.
open
AFMR-F028Custody and Key Compromise
Control of an agent's identity, assets, or authority is lost or captured through key or custody failure.
open
Class H: Structure and Drift
AFMR-F029Recentralization Drift
A system designed to distribute authority concentrates it again through tooling, delegation, capital, or expertise asymmetry.
2013
AFMR-F030Rule Obsolescence and Ossification
A rule persists after the conditions that justified it have changed, and resists revision.
2013
AFMR-F031Participation Collapse
Eligible participants stop participating, leaving decisions to a small, self selected, or unrepresentative remainder.
2016
AFMR-F032Enforcement and Liability Gap
A rule exists and cannot be enforced, or no recognized person bears the obligation, so liability has nowhere to attach.
2019

Cite this enumeration

W. A. Kaal, ed., Agent Failure Mode Registry (AFMR) version 1.0, 2026-07-30. https://wulfkaal.github.io/afmr/

For a single family: AFMR-F023 (AFMR 1.0).

Machine access

Comment

Version 1.0 is a public review draft. Identifiers assigned here are permanent. Definitions, trigger conditions, and crosswalks are open for comment until 1.1. A proposal for a new family or mode must include the proposed name, the trigger conditions, and at least one grounding source. Comments and proposals to wulf@wulfkaal.com.