362 Documented AI Incidents
Documented AI incidents rose sharply. Stanford’s independent annual report counts 362 documented AI incidents for 2025. The same report notes that responsible AI is falling behind capability.
That figure covers only what got documented. So the real number runs higher; most incidents never reach a record, and in small businesses almost none do. What goes unrecorded also goes unseen. And what stays unseen never gets managed.
What the Number Says
BU BÖLÜMÜN ÖZETİ
- The rise tracks the usage
- Keeping records is the exception
- Responsible AI is behind
Three findings.
The rise tracks the usage
As use spreads, incidents multiply. That is expected. More usage brings more error, and the problem is not the rise itself but its pace. The real issue is the pace of the rise. The adoption curve and the incident curve climb together while the oversight curve lags behind.
Keeping records is the exception
The report highlights that most organisations keep no incident log. A business without records cannot see what is going wrong. Learning does not accumulate either. The same mistake repeats. A three-line note would have prevented it.
Responsible AI is behind
This is the report’s most repeated warning. Capabilities advance markedly every year. Oversight and governance do not advance at the same pace. The gap accumulates as risk.
What the Headline Misses
BU BÖLÜMÜN ÖZETİ
- An incident is not a catastrophe
- Human oversight gets treated as optional
- Confident errors are the dangerous ones
Three details.
An incident is not a catastrophe
Most documented incidents are not disasters. Wrong information, an inappropriate output, a flawed decision. The same kinds of thing happen in small businesses; nobody just calls them incidents. They get corrected and forgotten. Then they recur a few months later, and nobody recognises the repeat.
Human oversight gets treated as optional
The report stresses that human review is not a choice. But in practice oversight stays formal in most places. Approval gets given without reading. Signing off does not mean checking.
Confident errors are the dangerous ones
The output arrives in a confident tone. When it is wrong, it arrives in the same tone. The reader therefore does not question it. The text does not look like something that needs questioning. The problem is not ignorance. It is trust built in the wrong place.
What a Business Should Do
BU BÖLÜMÜN ÖZETİ
- Cost: three lines per incident
- First step: look backwards
- Next step: put in a checkpoint
Three steps.
Cost: three lines per incident
When something goes wrong, write three lines. What happened? Where was it caught? What was done? Four or five notes across a year are enough to expose a trend. They also point to the jobs where mistakes gather, so the checking can shift there.
First step: look backwards
Did any AI output need fixing since the spring? If so, an incident already exists in your business. Nobody logged it, so nobody can point to it. Put down whatever you recall; a partial note still beats an empty page.
Next step: put in a checkpoint
Let every text going to a customer pass through one person. That single rule stops most incidents before they leave the building. Matching tools to tasks reduces the risk earlier still, and a verification routine makes the checkpoint sustainable.
A business that keeps no record only notices the problem when the same mistake happens twice.
