AIPolicyTracker
ProcedureFree · no accountEU AI ActNIST AI RMF

AI Incident Response Playbook and Log

Detect, contain, report and learn: a playbook built from the recorded incident-handling duties, with the reporting deadlines they set, and a log that computes them.

Formats: DOCX and XLSX · Version v1 · Built from dataset 914895c3103e · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

What's inside

  • Document: severity scale, roles, the playbook steps, the reporting duties on record with their deadlines
  • Incident log sheet: severity and harm-domain dropdowns, deadline computed from the date, status
  • Regulators sheet: who to notify, by jurisdiction, from the records

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Incident log · 14 columns · blank, 300 rows ready to fill
First rows of the Incident log sheet
Incident IDDetected onSystemSeverity ▾Harm domain (MIT) ▾What happenedWho was affectedReportable to a regulator ▾RegulatorReporting deadline ƒDays to deadline ƒStatus ▾OwnerLessons and follow-up
Rows are yours to fill; the dropdowns, formulas and colour rules are already in place.
Sheet: Regulators · 5 columns · 238 rows from the records
First rows of the Regulators sheet
JurisdictionRegulatorRoleWebsiteRecord
ASEAN (Association of Southeast Asian Nations)ASEAN Digital Ministers' Meeting (ADGMIN)Endorses regional digital and AI guidancehttps://asean.org/https://aipolicytracker.org/jurisdictions/asean
AlbaniaNational Agency for Information Society (AKSHI)Official government portal; AI policy lead not yet identifiedhttps://www.akshi.gov.al/https://aipolicytracker.org/jurisdictions/albania
AlgeriaMinistère de l'Économie de la Connaissance, des Start-up et des Micro-entreprisesAI strategy co-leadhttps://www.mecsme.gov.dz/https://aipolicytracker.org/jurisdictions/algeria
AndorraGovern d'AndorraOfficial government portal; AI policy lead not yet identifiedhttps://www.govern.ad/https://aipolicytracker.org/jurisdictions/andorra
AngolaGoverno de AngolaOfficial government portal; AI policy lead not yet identifiedhttps://governo.gov.ao/https://aipolicytracker.org/jurisdictions/angola
Antigua and BarbudaGovernment of Antigua and BarbudaOfficial government portal; AI policy lead not yet identifiedhttps://ab.gov.ag/https://aipolicytracker.org/jurisdictions/antigua-and-barbuda
Sheet: Incident duties · 14 columns · 9 rows from the records
First rows of the Incident duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Report critical safety incidents to the Office of Emergency ServicesIncident reporting and handlingCalifornia SB 53California (United States)General-purpose AI model provider, Provider / developerLegal requirementBusiness and Professions Code, Chapter 25.1 (as added by SB 53)2026-01-01Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and thIncident classification and reporting procedureMANAGE 4.3Source-linkedhttps://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting
Developers must notify the Attorney General and deployers of discovered algorithmic discriminationIncident reporting and handlingColorado AI ActColorado (United States)Provider / developerLegal requirementC.R.S. 6-1-1702(5)2026-06-30Within 90 days after a developer discovers, through ongoing testing or a credible report from a deployer, that a high-risk AI system it developed has caused or Discrimination incident log with notification dates; Attorney General and deployer notification lettersClause 10.2; Annex A.8.4MANAGE 4.3, GOVERN 6.2Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-colorado-ai-act-developer-disclosure-to-attorney-general
Deployers must notify the Attorney General of discovered algorithmic discriminationIncident reporting and handlingColorado AI ActColorado (United States)Deployer / user organisationLegal requirementC.R.S. 6-1-1703(7)2026-06-30If a deployer discovers that a high-risk AI system it uses has caused algorithmic discrimination, it must send a notice to the Colorado Attorney General within Attorney General notification recordAnnex A.8.4MANAGE 4.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-disclosure-to-attorney-general
Operate a post-market monitoring systemPost-market monitoringEU AI ActEuropean UnionProvider / developerLegal requirementArticle 722026-08-02Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematicallPost-market monitoring plan and periodic reportsClause 9.1 Monitoring, measurement, analysis and evaluationMANAGE 4.1, MEASURE 3.xSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-post-market-monitoring
Report serious incidents to market surveillance authoritiesIncident reporting and handlingEU AI ActEuropean UnionProvider / developer, Deployer / user organisationLegal requirementArticle 732026-08-02Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediatelAI incident response procedure; Incident log and authority notificationsClause 10 Improvement; Annex A control on incident handlingMANAGE 4.3Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-serious-incident-reporting
Providers must take corrective action and inform the supply chain about non-conforming high-risk AIIncident reporting and handlingEU AI ActEuropean UnionProvider / developerLegal requirementArticle 202026-08-02A provider that considers, or has reason to consider, that a high-risk system it has placed on the market is not in conformity must immediately correct it, withCorrective action and recall procedure for AI systems; Non-conformity investigation recordClause 10.2; Annex A.8.4MANAGE 2.4, MANAGE 4.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-20-corrective-actions-and-information

Document outline (DOCX)

  1. 1. What counts as an incident
  2. 2. Roles
  3. 3. The playbook
  4. Detect
  5. Contain
  6. Assess and report
  7. Recover and learn
  8. 4. Reporting duties on record
  9. Report critical safety incidents to the Office of Emergency Services
  10. Developers must notify the Attorney General and deployers of discovered algorithmic discrimination
  11. Deployers must notify the Attorney General of discovered algorithmic discrimination
  12. Operate a post-market monitoring system
  13. Report serious incidents to market surveillance authorities
  14. Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
  15. Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
  16. Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
  17. Implement reasonable security safeguards and notify breaches

Duties this template covers (7)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

Version history

Versions of AI Incident Response Playbook and Log
VersionBuiltDatasetWhat changed
v1914895c3103eFirst version, built from dataset 914895c3103e.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

Is the AI Incident Response Playbook and Log free?
Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 256 recorded duties are cited in it, drawn from 3 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Is the AI Incident Response Playbook and Log free?
Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 256 recorded duties are cited in it, drawn from 3 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.