Runaway spend, by root cause
Every documented AI-agent spending incident, grouped by the failure mode that caused it — and the one spend rule that would have stopped it before any money moved.
Retry loops
6 documented incidents
Stops with: velocity + per-period total →
Prompt injection
1 documented incident
Stops with: merchant allowlist + FLAG for unknown →
Unattended sessions
4 documented incidents
Stops with: time-of-day + daily total →
Leaked credentials
1 documented incident
Stops with: velocity + anomaly FLAG →
Caps that didn't enforce
2 documented incidents
Stops with: independent per-tx cap →
Why causes matter
Mapping incidents to causes is what turns fear into a checklist. Pick the causes your agents are exposed to, configure the matching rules in sipi.bot, and you've closed the gap.