Skip to the content.

AI Incident Response Playbook

Purpose

Use this playbook to coordinate investigation, containment, communication, recovery, and learning when an AI system causes or may cause material harm, privacy/security exposure, unsafe behavior, significant reliability degradation, or policy/control failure.

1. Detect and triage

2. Contain and protect

3. Investigate

Question Record
What happened? observable symptoms, timeline, affected scope
Which version was active? model, prompt/configuration, retrieval, tool, and deployment identifiers
Why did controls not prevent it? missing, failed, bypassed, or insufficient controls
Who is affected? users, customers, systems, or stakeholders, using approved privacy-safe detail
What evidence supports conclusions? logs, evaluations, approvals, monitoring, and human review notes

4. Recover and decide

5. Learn and improve