PipeRoll is a public registry of verified AI-agent incidents: what the agent controlled, what went wrong, what it cost, and what the evidence is. It is named for the Pipe Rolls - the English Exchequer's great rolls, 676 unbroken years of audited records kept tamper-evident by a parallel copy in different hands.
The registry is the first of PipeRoll's two instruments. The second is the seismograph - an independent observatory that measures each frontier model's behavioural drift against its own past, publishing witnessed statistical readings ("model X changed on date Y, in dimension Z"). The registry records verified facts; the seismograph publishes statistical readings with a stated false-positive posture. Two instruments, one institution, separate methodology charters.
The registry records publicly reported, verifiable incidents - a fraction of what occurs, biased toward the visible (on-chain losses, court records, published research, English-language sources). Counts are a floor, never a frequency estimate; absence from the registry is not evidence of safety; and no failure rate can be computed from registry counts alone, because the exposure base is unknown.
Each record page carries a plain citation and a BibTeX entry with copy buttons, plus a raw markdown endpoint for machine use. Registry-level archives carry a DOI (10.5281/zenodo.21968992, resolves to the latest archived release); doi.org content negotiation serves APA/Chicago/CSL formats from it. A machine manifest lives at /llms.txt; structured data at registry.json and registry.csv.
Four layers, honestly scoped. Commits are GPG-signed and main is protected (no force-pushes, four required checks) - which binds outsiders, not the maintainer. What binds the maintainer: every release is archived immutably at CERN (Zenodo, DOI), and every deployment writes a signature over a manifest of every record's bytes to the Sigstore Rekor public append-only transparency log - an external witness this registry cannot rewrite. The manifest, signature bundle, and Rekor pointer ship with the site at /witness/. Verify any deployment:
cosign verify-blob --bundle checksums.bundle.json --certificate-identity-regexp 'github.com/piperoll/registry' --certificate-oidc-issuer https://token.actions.githubusercontent.com checksums.txt
A silently rewritten record would hash differently from every witnessed manifest that came before it. Between the git history, the CERN snapshots, the Rekor entries, and every clone anyone has ever pulled, the registry's past is distributed beyond its own custody - the Chancellor's Roll, updated.
A live source link tells you a page still resolves; it does not tell you what the page said when the record cited it. So every record's sources are submitted to the Internet Archive's Wayback Machine at registration - a neutral third party that fetches and timestamps the page itself. To read the archived copy of any source, ask the Archive for its closest snapshot:
https://archive.org/wayback/available?url=THE-SOURCE-URL
The JSON reply gives a timestamped snapshot URL of the form
https://web.archive.org/web/YYYYMMDDhhmmss/THE-SOURCE-URL; shortening or dropping
the timestamp resolves to the nearest or latest capture. The Archive's own timestamp is the
witness of what the source served - no lookup table from PipeRoll is needed or kept. (A few
hosts block automated archiving; where a source cannot be captured, the record says so and
cites a reachable copy.)
Srinivas Gumdelli - founding editor. Registration authority currently rests with the editor; conflicts of interest are disclosed inside the affected records. Each record states who registered it.
PipeRoll and the AI Incident Database (AIID)
are complementary, not competing. AIID is the broad catalog of AI harms across every
domain; PipeRoll is a deep, individually verified registry of the agent subset,
adding what an underwriter or auditor needs - what authority the agent held, what it could
lose, what bounded the loss, and tamper-evident provenance. Where an event appears in both,
the PipeRoll record cross-references AIID (an aiid_incident_id and a
“see also” link) and verifies its own primary sources; AIID is a sibling
catalog, never PipeRoll's evidence.
Cross-references were matched against AIID's weekly database export dated 2026-08-17.
AIID's incident data is a project of the Responsible AI Collaborative, licensed
CC BY-SA (Creative Commons Attribution-ShareAlike); we gratefully credit it and cite it
as a whole via McGregor, S. (2021), Preventing Repeated Real World AI Failures by
Cataloging Incidents: The AI Incident Database (IAAI-21). Each AIID incident carries
its own suggested citation - crediting that incident's submitters and editors, with an
access date - on its incidentdatabase.ai/cite/<id> page; cite AIID
there when citing AIID itself.
On share-alike: a PipeRoll record cross-references AIID by incident id and is written from its own verified primary sources - it does not incorporate AIID's incident text, descriptions, or classifications - so we take the view that the share-alike term is not triggered and PipeRoll's records remain CC BY 4.0. Any artifact derived directly from AIID's licensed data (for example, a standalone PIR-to-AIID crosswalk we might publish) would carry AIID's CC BY-SA terms. We welcome RAIC's guidance on this.
Records and data: CC BY 4.0 (cite PipeRoll and the PIR id). Tooling: MIT.