ProcedureFree · no accountEU AI ActNIST AI RMF
AI Incident Response Playbook and Log
Detect, contain, report and learn: a playbook built from the recorded incident-handling duties, with the reporting deadlines they set, and a log that computes them.
What's inside
- Document: severity scale, roles, the playbook steps, the reporting duties on record with their deadlines
- Incident log sheet: severity and harm-domain dropdowns, deadline computed from the date, status
- Regulators sheet: who to notify, by jurisdiction, from the records
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Incident log
| Incident ID | Detected on | System | Severity ▾ | Harm domain (MIT) ▾ | What happened | Who was affected | Reportable to a regulator ▾ | Regulator | Reporting deadline ƒ | Days to deadline ƒ | Status ▾ | Owner | Lessons and follow-up |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rows are yours to fill; the dropdowns, formulas and colour rules are already in place. | |||||||||||||
Sheet: Regulators
| Jurisdiction | Regulator | Role | Website | Record |
|---|---|---|---|---|
| ASEAN (Association of Southeast Asian Nations) | ASEAN Digital Ministers' Meeting (ADGMIN) | Endorses regional digital and AI guidance | https://asean.org/ | https://aipolicytracker.org/jurisdictions/asean |
| Albania | National Agency for Information Society (AKSHI) | Official government portal; AI policy lead not yet identified | https://www.akshi.gov.al/ | https://aipolicytracker.org/jurisdictions/albania |
| Algeria | Ministère de l'Économie de la Connaissance, des Start-up et des Micro-entreprises | AI strategy co-lead | https://www.mecsme.gov.dz/ | https://aipolicytracker.org/jurisdictions/algeria |
| Andorra | Govern d'Andorra | Official government portal; AI policy lead not yet identified | https://www.govern.ad/ | https://aipolicytracker.org/jurisdictions/andorra |
| Angola | Governo de Angola | Official government portal; AI policy lead not yet identified | https://governo.gov.ao/ | https://aipolicytracker.org/jurisdictions/angola |
| Antigua and Barbuda | Government of Antigua and Barbuda | Official government portal; AI policy lead not yet identified | https://ab.gov.ag/ | https://aipolicytracker.org/jurisdictions/antigua-and-barbuda |
Sheet: Incident duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Report critical safety incidents to the Office of Emergency Services | Incident reporting and handling | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Business and Professions Code, Chapter 25.1 (as added by SB 53) | 2026-01-01 | Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and th | Incident classification and reporting procedure | MANAGE 4.3 | Source-linked | https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting | |
| Developers must notify the Attorney General and deployers of discovered algorithmic discrimination | Incident reporting and handling | Colorado AI Act | Colorado (United States) | Provider / developer | Legal requirement | C.R.S. 6-1-1702(5) | 2026-06-30 | Within 90 days after a developer discovers, through ongoing testing or a credible report from a deployer, that a high-risk AI system it developed has caused or | Discrimination incident log with notification dates; Attorney General and deployer notification letters | Clause 10.2; Annex A.8.4 | MANAGE 4.3, GOVERN 6.2 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-colorado-ai-act-developer-disclosure-to-attorney-general |
| Deployers must notify the Attorney General of discovered algorithmic discrimination | Incident reporting and handling | Colorado AI Act | Colorado (United States) | Deployer / user organisation | Legal requirement | C.R.S. 6-1-1703(7) | 2026-06-30 | If a deployer discovers that a high-risk AI system it uses has caused algorithmic discrimination, it must send a notice to the Colorado Attorney General within | Attorney General notification record | Annex A.8.4 | MANAGE 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-colorado-ai-act-deployer-disclosure-to-attorney-general |
| Operate a post-market monitoring system | Post-market monitoring | EU AI Act | European Union | Provider / developer | Legal requirement | Article 72 | 2026-08-02 | Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematicall | Post-market monitoring plan and periodic reports | Clause 9.1 Monitoring, measurement, analysis and evaluation | MANAGE 4.1, MEASURE 3.x | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-post-market-monitoring |
| Report serious incidents to market surveillance authorities | Incident reporting and handling | EU AI Act | European Union | Provider / developer, Deployer / user organisation | Legal requirement | Article 73 | 2026-08-02 | Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediatel | AI incident response procedure; Incident log and authority notifications | Clause 10 Improvement; Annex A control on incident handling | MANAGE 4.3 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-serious-incident-reporting |
| Providers must take corrective action and inform the supply chain about non-conforming high-risk AI | Incident reporting and handling | EU AI Act | European Union | Provider / developer | Legal requirement | Article 20 | 2026-08-02 | A provider that considers, or has reason to consider, that a high-risk system it has placed on the market is not in conformity must immediately correct it, with | Corrective action and recall procedure for AI systems; Non-conformity investigation record | Clause 10.2; Annex A.8.4 | MANAGE 2.4, MANAGE 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-20-corrective-actions-and-information |
Document outline (DOCX)
- 1. What counts as an incident
- 2. Roles
- 3. The playbook
- Detect
- Contain
- Assess and report
- Recover and learn
- 4. Reporting duties on record
- Report critical safety incidents to the Office of Emergency Services
- Developers must notify the Attorney General and deployers of discovered algorithmic discrimination
- Deployers must notify the Attorney General of discovered algorithmic discrimination
- Operate a post-market monitoring system
- Report serious incidents to market surveillance authorities
- Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
- Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
- Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
- Implement reasonable security safeguards and notify breaches
Duties this template covers (7)
Each is cited in the file with its source reference and a link back to the record.
- Report critical safety incidents to the Office of Emergency Services
- Operate a post-market monitoring system
- Report serious incidents to market surveillance authorities
- Providers must take corrective action and inform the supply chain about non-conforming high-risk AI
- Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
- Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
- Implement reasonable security safeguards and notify breaches
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | 914895c3103e | First version, built from dataset 914895c3103e. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
- Is the AI Incident Response Playbook and Log free?
- Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 256 recorded duties are cited in it, drawn from 3 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is the AI Incident Response Playbook and Log free?
- Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 256 recorded duties are cited in it, drawn from 3 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.