Practical guide · AI incident

Company AI incident handling: the first decisions that matter

A useful AI incident flow limits impact, preserves facts and assigns ownership without treating every error as a crisis.

Contain the effect before rushing the investigation

First limit the impact: pause publication, temporarily remove access or suspend the affected use. Do not erase conversations, logs or versions that may establish what happened.

Capture minimum viable facts

Initial reporting should be short and accessible. Record the tool, use case, time, data involved, output, affected people and action already taken.

  • what was observed without premature conclusions
  • who owns the incident
  • which access or distribution was contained
  • which specialist roles need to join

Use proportionate severity

A hallucination caught before use and an accidental data exposure require different responses. Severity should consider data, people, distribution, impact and reversibility.

Close the loop in policy and training

After resolution, record the operational cause, corrective action, owner and closure evidence. Update the inventory, approval conditions or training examples only when the facts support the change.

General educational material. It is not legal advice and does not replace legal, DPO, HR or security review appropriate to your organisation.