THE SHORT ANSWER

For an AI incident, protect people first, stop or contain the behavior, preserve evidence, establish facts, involve responsible specialists, communicate appropriately, correct affected outcomes, remediate the system and require accountable approval before restart.

Define what enters the incident process

  • Harmful or materially false output
  • Unauthorized action or permission use
  • Personal or confidential data exposure
  • Discriminatory or inaccessible outcome
  • Loss of required human control
  • Systematic failure after model, data or prompt change

PROTECT → CONTAIN → PRESERVE → ASSESS → CORRECT → COMMUNICATE → REMEDIATE → REVIEW

The order may overlap. Protect affected people and prevent further harm while preserving prompts, outputs, versions, logs, approvals and system context needed to understand what happened.

Prepare a cross-functional response

Incident responsibilities
RoleResponsibility
Incident leadCoordinates decisions and timeline
Business ownerOwns service impact and affected outcomes
Technical/securityContains, preserves and diagnoses
Privacy/legal/complianceAdvises on applicable obligations
Communications/supportProvides accurate help and correction

Do not confuse a patch with safe recovery

Identify root and contributing causes, correct affected records where feasible, test the remediation, update controls and obtain a new release decision. Keep the system paused when evidence is insufficient.

If the event is a cyber compromise, follow the existing business incident response guide and qualified response advice.

Evidence & context: National Institute of Standards and Technology · National Institute of Standards and Technology

Sources & further reading

  1. Artificial Intelligence Risk Management Framework (AI RMF 1.0)

    National Institute of Standards and Technology. Voluntary, rights-preserving guidance organized around GOVERN, MAP, MEASURE and MANAGE. NIST was revising AI RMF 1.0 when checked on 28 September 2026, so organizations should verify the current version before formal adoption.

  2. The NIST Cybersecurity Framework 2.0

    National Institute of Standards and Technology. Current outcome-based guidance for governing, identifying, protecting, detecting, responding to and recovering from cybersecurity risk. It does not prescribe one implementation.

  3. ISO/IEC 42001 explained: What it is, why it matters, and how it works

    International Organization for Standardization. Official overview of the AI management-system standard and its continual-improvement approach. Certification scope and a management system do not by themselves prove that a specific AI use is safe, fair or legally compliant.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗