THE VAID SCALE
The Vienna Agentic Incident scale rates events involving autonomous AI agents on a logarithmic ladder from 0 to 8. Its logic follows the IAEA International Nuclear and Radiological Event Scale (INES): levels 1–3 are incidents (safety provisions degraded, no or minimal actual harm), levels 4–7 are accidents (actual harm of increasing reach). VAID introduces level 8 — global disaster for irreversible, planetary-scale harm. Each step represents roughly a tenfold increase in severity.
Catastrophic, irreversible harm at planetary scale.
- Self-propagating agentic activity beyond any single actor's control.
- Simultaneous failure of critical systems across multiple continents.
- Consequences threatening the stability of global society.
Major release of harmful effects with national or continental reach.
- Sustained outage of critical infrastructure at national scale.
- Mass casualties linked to autonomous action.
- Long-term societal, economic or environmental consequences.
Severe, widespread harm requiring coordinated response.
- Disruption of critical services across a sector or region.
- Serious physical harm or loss of life attributable to agent actions.
- Cross-organisation cascading failure; multi-party incident response.
Harm extends beyond the operating organisation.
- Third parties materially affected (customers, partners, public).
- Large-scale leak of personal data or credentials.
- Regulatory intervention or mandatory public disclosure required.
Actual harm, confined to the operating organisation.
- Irreversible destruction of production data or infrastructure.
- Unauthorised financial transactions with material but bounded loss.
- Harm limited to the deploying organisation and its direct users.
Near-accident: safety margins largely exhausted.
- Multiple control layers failed; only one barrier prevented harm.
- Unauthorised irreversible action attempted but blocked or reverted.
- Confidential data left the trust boundary in small volume.
Significant failure of a safety provision with no actual harm.
- Failure of one control layer (e.g. tool permission, rate limit, filter).
- Unintended side effects contained to a single system or tenant.
- Exposure of limited internal data without external propagation.
Minor deviation from authorised operating envelope.
- Agent exceeded its scope in a recoverable, non-harmful way.
- Defence-in-depth remained fully intact.
- No external impact; internal review sufficient.
No safety significance.
- Agent behaviour outside expected parameters but within all guardrails.
- No unauthorised actions, no data exposure, no user harm.
- Detected and corrected by routine monitoring.