Standard · version 1.0 · Published
A citable registry of the ways autonomous agent systems fail as designed mechanisms, and the conditions under which each failure occurs.
Thirty-two families in eight classes. Each carries trigger conditions written so a builder can check them against a real system, grounding claims bound to verbatim quotes and document hashes, and where one exists, an institutional antecedent: the pre-2020 published claim documenting the same mechanism operating in human institutions.
The registry is not a list of harms and not a set of management controls. Its unit is a failure mode with stated conditions, carrying a permanent identifier and a citation, so a design can be assessed against it and the assessment can be attested by a party staking standing on being right.
Referencing. Cite AFMR identifiers with a version when describing failure modes. Do not redefine a family under its identifier.
Assessing. Produce assessments to the published schema, stating which trigger conditions a design satisfies and recording families examined and found not applicable, so that absence of an exposure is distinguishable from absence of examination.
Attesting. Stake non-transferable standing on an assessment in an attestation registry, accepting a contest period. This is what separates an enumeration from a taxonomy: an attested assessment puts a named party's standing behind a specific judgment about a specific design.
Definitions in version 1.0 are editorial and open for comment until 1.1. The authoritative content of a family is its claim set, reachable from each family page. Identifiers are permanent from this version forward.
| ID | Family | Antecedent |
|---|---|---|
| Class A: Identity and Standing | ||
| AFMR-F001 | Sybil and Identity Multiplication One party operates many apparent agents, defeating any assumption the design makes per identity. | 2018 |
| AFMR-F002 | Identity Discontinuity and Whitewashing An agent abandons a degraded identity and resumes with a clean one, so history stops constraining behavior. | 2009 |
| AFMR-F003 | Cold Start and Bootstrapping The design requires accumulated standing, participants, or history that it provides no way to acquire. | 2018 |
| AFMR-F004 | Standing Transferability Defect Standing can be bought, sold, delegated, or pooled, so it stops measuring the performance it was meant to represent. | open |
| Class B: Stake and Incentive | ||
| AFMR-F005 | Staking and Incentive Misalignment What an agent risks diverges from what the system needs it to care about. | 2010 |
| AFMR-F006 | Missing Reward Channel An action surface exists with no reward attached, so rational agents will not allocate compute to it. | open |
| AFMR-F007 | Plutocratic Capture Influence tracks holdings rather than earned standing, so the largest holders determine outcomes. | 2012 |
| AFMR-F008 | Moral Hazard and Backstop Expectation An expectation of rescue, retry, or rollback changes risk taking before any rescue occurs. | 2010 |
| Class C: Objective and Specification | ||
| AFMR-F009 | Specification Incompleteness The principal cannot enumerate every action and inaction in advance, so the agent's mandate is necessarily underspecified. | 2019 |
| AFMR-F010 | Reward Hacking and Proxy Capture The agent raises the measured objective without producing the outcome the objective stood for. | 2014 |
| AFMR-F011 | Metric Capture and Measurement Failure The chosen metric ceases to track the property it stands for once it becomes the target. | 2015 |
| AFMR-F012 | Definitional Ambiguity in Machine Applied Rules A term carrying operational weight has no settled boundary, so automated application produces outcomes no party intended. | open |
| Class D: Oversight and Adjudication | ||
| AFMR-F013 | Oversight Capacity Gap Agent behavior exceeds the resources, expertise, or access of whoever is nominally supervising it. | 2011 |
| AFMR-F014 | Oversight Latency Review is slower than action, so by the time a judgment lands the state it judged is gone. | open |
| AFMR-F015 | Alignment Tax and Exogenous Constraint Scaling External control scales against capability, so oversight cost rises faster than the capability it constrains. | open |
| AFMR-F016 | Absent Human Backstop No human authority can halt, reverse, or reinterpret automated execution, so cryptographic or procedural correctness substitutes for trust and fails to produce it. | 2019 |
| Class E: Evaluation and Feedback | ||
| AFMR-F017 | Feedback Degradation Above Evaluator Capability Human or agent evaluation degrades precisely where the evaluated system is hardest to evaluate, including where it exceeds the evaluator. | open |
| AFMR-F018 | Unstaked Adjudication Whoever judges a contribution risks nothing on the judgment, so judgment is cheap and drifts. | 2014 |
| AFMR-F019 | Training and Annotation Bias Propagation Bias in annotators or automated labeling propagates into the model and then into every decision the agent makes. | open |
| AFMR-F020 | Human Judgment Displacement Automation replaces judgment in a setting that required judgment, and the loss is not detected because the output still looks well formed. | 2013 |
| Class F: Coordination and Collusion | ||
| AFMR-F021 | Mutual Audit Capture Agents assigned to oversee one another converge on mutual approval, so peer monitoring devolves into self serving behavior. | open |
| AFMR-F022 | Collusion Rings and Reciprocal Validation A subset of agents validates one another to manufacture standing, and formal mechanism design alone does not detect it. | open |
| AFMR-F023 | Collective Action and Coordination Failure Individually rational agent behavior produces a collectively worse outcome and no mechanism reconciles the two. | 2013 |
| AFMR-F024 | Delegation Opportunism An agent acting for a principal, or for another agent, captures private benefit at the principal's expense, and monitoring costs more than it recovers. | 2019 |
| Class G: Execution and Inputs | ||
| AFMR-F025 | Oracle and Input Corruption The mechanism executes correctly on an input that is wrong, stale, manipulated, or injected. | open |
| AFMR-F026 | Automated Execution Rigidity Execution cannot accommodate circumstances the code did not anticipate, and cannot be amended in time to matter. | 2013 |
| AFMR-F027 | Code Defect Exploitation A defect in deployed code is exercised by an adversary before it is found by its authors. | open |
| AFMR-F028 | Custody and Key Compromise Control of an agent's identity, assets, or authority is lost or captured through key or custody failure. | open |
| Class H: Structure and Drift | ||
| AFMR-F029 | Recentralization Drift A system designed to distribute authority concentrates it again through tooling, delegation, capital, or expertise asymmetry. | 2013 |
| AFMR-F030 | Rule Obsolescence and Ossification A rule persists after the conditions that justified it have changed, and resists revision. | 2013 |
| AFMR-F031 | Participation Collapse Eligible participants stop participating, leaving decisions to a small, self selected, or unrepresentative remainder. | 2016 |
| AFMR-F032 | Enforcement and Liability Gap A rule exists and cannot be enforced, or no recognized person bears the obligation, so liability has nowhere to attach. | 2019 |
W. A. Kaal, ed., Agent Failure Mode Registry (AFMR) version 1.0, 2026-07-30. https://wulfkaal.github.io/afmr/
For a single family: AFMR-F023 (AFMR 1.0).
Authoritative index: index.json
Schema: schema.json
JSON-LD context: context.jsonld
Discovery: .well-known/afmr.json
Specification: AFMR 1.0
Grounding claims: failure index ·
claim layer
Attestation registry: Colloquium
Changelog: CHANGELOG
Version 1.0 is a public review draft. Identifiers assigned here are permanent. Definitions, trigger conditions, and crosswalks are open for comment until 1.1. A proposal for a new family or mode must include the proposed name, the trigger conditions, and at least one grounding source. Comments and proposals to wulf@wulfkaal.com.