Where Verification Fails: An Empirical Analysis of Assurance Gaps in Real-World Agentic AI Incidents
Abstract
The workshop question—who verifies the agents?—has a sharper empirical form: when a deployed agent has already failed, where could a verification step have caught it, and was one there at all? I study this over a public corpus of real world AI incidents. Under an operational definition of agentic behavior—acting on external state, or making an autonomous consequential decision without per action human approval—only 50 of 131 keyword-screened “agent-related” inci dents (38.2%) qualify, a sizeable gap between what an agent-related screen sur faces and demonstrable autonomous action. I code the 50 qualifying incidents against a five-stage verification lifecycle (input, reasoning/decision, tool/action, outcome, human-oversight), recording the earliest stage with a documented veri fication opportunity and whether verification there was absent (no mechanism) or ineffective (a mechanism existed but did not detect or constrain the failure). Unlike prior taxonomies that classify what failed, this verification-centric lens asks what should have checked it. The result is a stage-dependent asymmetry: at upstream perception and decision stages verification is usually present-but-ineffective (29 of 32 ineffective cases), while at the downstream stages where agents act on the world it is usually absent entirely (11 of 12 action/outcome cases). The asymmetry is actionable—upstream failures are coverage problems, downstream failures are design omissions—and I show empirically that the downstream result is invariant to the strict-vs-broad definitional choice. I map each gap to existing mechanism families and release the codebook for re-coding