English

Places to contact

AI Vulnerability Database (AVID)

Type
Public reporting channel
Place
International — Global
Last checked
2026-09-22
Next check due
2027-03-21

Ways to reach them

  • Submission page · Incident reporting
    Open contact route · 2026-09-22

    Who may use it: public

    Evidence that this route accepts contact · 2026-09-22

    Failure modes in general-purpose AI systems — open-weight generative models, closed-API systems, developer tools, and end-to-end AI applications and agents. Records are split into vulnerabilities and reports, organised by a taxonomy library. Rebuilt in 2026 for agentic AI.

    Public 'Submit an AI Vulnerability!' link on avidml.org, which routes to a Google Form. Alternatively contribute structured records via the avidml GitHub organisation. Documentation at docs.avidml.org.

  • Homepage · Homepage
    Verification expired

    Evidence that this route accepts contact

What it does

Failure modes in general-purpose AI systems — open-weight generative models, closed-API systems, developer tools, and end-to-end AI applications and agents. Records are split into vulnerabilities and reports, organised by a taxonomy library. Rebuilt in 2026 for agentic AI.

Honest assessment

Modest but real: it is an actively maintained, citable identifier namespace with 2026-dated records, and it is one of the few places a model-behaviour flaw can get a permanent public ID. Small organisation, small readership; do not expect it to force a vendor response on its own.

How to file

Public 'Submit an AI Vulnerability!' link on avidml.org, which routes to a Google Form. Alternatively contribute structured records via the avidml GitHub organisation. Documentation at docs.avidml.org.

Format

Structured record against AVID's taxonomy (security / ethics / performance dimensions), with reproduction detail. Short, technical, evidence-led.

Timing

Rolling.

What happens after

Accepted records get an AVID identifier (e.g. AVID-2026-R1407) and are published in the searchable database.

What it accepts

Failure modes in general-purpose AI systems — open-weight generative models, closed-API systems, developer tools, and end-to-end AI applications and agents. Records are split into vulnerabilities and reports, organised by a taxonomy library. Rebuilt in 2026 for agentic AI.

What it does not accept

Not explicitly documented. In practice it is oriented to reproducible model/system failure modes rather than narrative harm accounts — those belong in AIID.

Operated by

AI Risk and Vulnerability Alliance (ARVA), a nonprofit

Sources

Something wrong here?