FLARE-AI, a new open-source reporting platform for AI-related harms, has gone live with a simple goal: give the public a central place to file and follow reports when AI systems cause damage. The idea resembles Downdetector, but the target is not website outages. It is harmful model behavior, including chatbots giving bomb-making advice, exposing personal data, reinforcing paranoia, producing discriminatory outputs, or spreading false information.
The project was led by Hugging Face AI policy researcher Avijit Ghosh together with computer scientists Elaine Zhu and Shayne Longpre. Their work did not begin with this launch. The trio had already been studying AI incident reporting last year, and this time they linked up with 49 AI experts from 32 organizations to publish a research paper arguing that the lack of a consistent reporting channel is becoming a serious risk as AI adoption expands and agentic systems gain more authority.
A central reporting channel has been missing
Ghosh said there is still no centralized and accountable way to report flaws in AI systems. At the moment, many AI failures are captured only through scattered news coverage. That leaves no systematic record and no coordinated disclosure process. In software security, structured vulnerability disclosure has existed for years. AI has not developed an equivalent framework.
Jessica Ji, a researcher at the Center for Security and Emerging Technology, described FLARE-AI as a strong initiative. Her point was blunt: current reporting mechanisms are fragmented, and AI models are black boxes. Any tool that improves transparency is worth backing.
The problem goes beyond classic cybersecurity bugs
According to Ghosh, AI failures cannot be reduced to standard security vulnerabilities alone. Psychological harm, discrimination, and misinformation also belong in the conversation. The difficulty is that companies do not define these categories in the same way, which means some incidents may never be formally acknowledged. Without a coordinated disclosure process, outside parties have little leverage to demand transparency.
Recent cases show how exposed the field remains. This week, security firm LayerX disclosed a method that could trick AI-powered browsers into bypassing their own guardrails, including OpenAI’s Atlas and Perplexity’s Comet. If the AI is persuaded that it is playing a game, the browser may attempt to break into websites. The affected vendors have already fixed the issue. In April, security researcher Johann Rehberge r also found that images generated with ChatGPT could be used to induce Claude to reveal personal information.
Congress is moving on standards and a database
The policy track is moving at the same time. Last month, US Representatives Deborah Ross, Jeff Hurd, and Don Beyer introduced a bill that would require the National Institute of Standards and Technology, or NIST, to set AI flaw reporting standards and maintain a centralized database for those reports. The FLARE-AI organizers argue that a structure like this could pressure developers to address system weaknesses and help users compare safety records across different AI products and use cases.
There are still open questions. Rumman Chowdhury, CEO of Humane Intelligence PBC, said FLARE-AI could offer many developers a practical model for incident reporting, but she also pointed to two immediate challenges: handling large volumes of incoming reports that may not all be severe, and securing backing from trusted institutions with real authority. For now, FLARE-AI is trying to answer that by routing cases to model developers and involving the nonprofit MITRE, which has long tracked problems in technical systems.

