# AI incident management and regulatory reporting

- **Record type**: Control
- **Kind**: Process
- **Owner**: Incident coordinator
- **Frequency**: Continuous
- **Duties served**: 14

## What the control achieves

Ensures that harm or near-harm caused by an AI system is detected, contained, investigated and, where a rule requires it, reported to the right authority and affected people within the applicable time limit.

## How it is typically implemented

The existing incident-response playbook is extended with AI-specific triggers: harmful or discriminatory output, safety failures, security breaches involving models or training data, misuse of the system and loss of control over an agent. A severity scale maps each trigger to the reporting regimes that may apply and their clocks, and a named coordinator decides within a set time whether a report is due. Investigation records the timeline, impact, root cause and corrective action, and lessons feed back into testing, monitoring and the risk register. Reporting channels for staff, users and third parties are published, and reports made to authorities are logged.

## Evidence it produces

- AI incident response playbook (procedure): Triggers, severity scale, reporting clocks per regime, roles and escalation.
- AI incident record (incident_record): Timeline, impact, root cause, corrective action and reporting decisions for one incident.
- Incident report to an authority (regulatory_filing)

## Legal duties this control serves

- Manage systemic risk for high-impact general-purpose models — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-gpai-systemic-risk
- Operate a post-market monitoring system — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-post-market-monitoring
- Report serious incidents to market surveillance authorities — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-serious-incident-reporting
- Providers must take corrective action and inform the supply chain about non-conforming high-risk AI — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-20-corrective-actions-and-information
- Deployers must monitor high-risk AI, suspend use on risk and report serious incidents — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-26-5-deployer-monitoring-and-suspension
- Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-55-systemic-risk-incident-reporting
- Implement reasonable security safeguards and notify breaches — India DPDP Act, India (satisfies): https://aipolicytracker.org/obligations/india-dpdp-security-and-breach-notification
- Report incidents and mark AI-generated content (generative AI framework) — Singapore Model AI Governance Framework, Singapore (satisfies): https://aipolicytracker.org/obligations/singapore-mgf-genai-incident-reporting-and-provenance
- Operators of AI above the compute threshold must run lifecycle risk management and report safety results — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (supports): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-32-safety-measures-for-high-performance-ai
- Report critical safety incidents to the Office of Emergency Services — California SB 53, California (United States) (satisfies): https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting
- Frontier developers must protect employees who report catastrophic-risk concerns — California SB 53, California (United States) (supports): https://aipolicytracker.org/obligations/us-california-sb-53-whistleblower-protections
- Developers must notify the Attorney General and deployers of discovered algorithmic discrimination — Colorado AI Act, Colorado (United States) (satisfies): https://aipolicytracker.org/obligations/us-colorado-ai-act-developer-disclosure-to-attorney-general
- Deployers must notify the Attorney General of discovered algorithmic discrimination — Colorado AI Act, Colorado (United States) (satisfies): https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-disclosure-to-attorney-general
- Prioritise, respond to and monitor AI risks (Manage) — NIST AI RMF, United States (supports): https://aipolicytracker.org/obligations/us-nist-ai-rmf-manage

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Clause 10.2; Annex A.8.3, A.8.4
- NIST AI RMF 1.0: MANAGE 4.1, 4.3; GOVERN 4.3, 6.2
- ISO/IEC 27001:2022: Annex A 5.24 to 5.28 Information security incident management

## MIT AI Risk Repository subdomains addressed

6.5, 7.3, 2.2, 4.2

## Provenance

- **Record page**: https://aipolicytracker.org/controls/ai-incident-management-and-reporting
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: high
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
