AI incident operations

When AI fails, move from uncertainty to accountable response.

Create a first-pass response path for containment, evidence preservation, escalation and potential notification timelines—without entering sensitive incident details.

Planning aid, not legal advice or emergency response. If people may be in danger, follow your emergency and safety procedures now. This tool never determines legal reportability or contacts any authority, customer or affected person.

The response spine

Four controls before any notification

01

Protect people

Stop or constrain harmful behavior and invoke emergency, safety and business-continuity procedures.

02

Preserve evidence

Protect versioned logs, model and prompt references, inputs, outputs, tool actions and approval records.

03

Establish ownership

Route legal, privacy, security, safety, business and regulatory review with separation of duties.

04

Control communications

Map potential deadlines while keeping every external notice pending authorized human approval.

Bounded local simulation

Plan the first response

Use only general categories. Do not enter incident narratives, names, system identifiers, personal data, secrets or customer information.

Controls already evidenced

Primary-source basis

Operational risk management, not a compliance promise

Reviewed 25 August 2026. EU AI Act Article 73 establishes serious-incident reporting for providers of high-risk AI systems, with scenario-dependent outside limits of two, ten or fifteen days and allowance for an initial incomplete report where needed for timeliness. NIST's voluntary AI RMF supports lifecycle risk management through Govern, Map, Measure and Manage.

Questions buyers ask

Does this calculate the legal deadline?

No. It displays potential Article 73 review lanes only when bounded selections indicate that EU high-risk-system rules may be relevant. Legal owners must verify all facts and current requirements.

Can we paste an incident report into it?

No. Deliberately. There is no free-text or file field, so confidential, personal and security-sensitive incident details stay out of this public tool.

Can it notify an authority automatically?

No. It has no network or publication path. A named authorized person must approve any external communication through the organization's controlled process.

What should a live implementation add?

An authenticated incident register, immutable audit log, evidence access controls, retention policy, authority matrix, tested notification workflow, monitoring integration, legal sign-off and rehearsed incident playbooks.