Every entry below is checked against a primary source: a regulator's order, a court record, the company's own statement, or a named newsroom. Incidents that only lived in aggregator blogs were cut. Incidents that are still unresolved allegations were held back. The 26 entries below are the ones where the record is complete and settled enough to publish.
Across all 40 incidents we verified, at most five were first caught by the organization running the AI: one by a security audit, one by endpoint alerts, one by its own quarterly financials, one in a retrospective review months after the fact, and one by a security team's own monitoring during a controlled test. Customers, readers, journalists, opposing counsel, courts, and regulators found the rest.
One honest footnote before the list. Publicly documented incidents are a biased sample: a failure a company catches internally rarely makes the news, so the public record overstates external discovery. This page makes no claim about the true base rate. What it shows is what happens when nothing inside the company is watching, because that is the only version of the story the public ever gets to read.
The whole library is also published as data: JSON and CSV, one row per incident with the failure class, who found it, and the control that was missing. Every incident also has its own page, linked from its card below. The data is licensed CC BY 4.0: use it, cite it as Walker AI Systems LLC, The receipts: verified AI failures in production, version 2026.09.01, walkeraisystems.com/receipts. A versioned mirror lives at github.com/byronwalk3r-tech/ai-incident-receipts.