Skip to content
#explainable ai Open access

The AI Incident Response Protocol: Six Stages, and the Evidence a Reconstruction Requires

Sep 2026 · Zenodo (CERN European Organization for Nuclear Research) · 10 references
Ethics and Social Impacts of AI

Abstract

An institution asked to explain an AI failure discovers, at that moment and not before, what it wrote down. The discovery is unrecoverable. Evidence is a property of the moment a decision was taken, and an institution that did not capture it then is left assembling an account from what it can still find. It reconstructs beliefs, not behaviour. This specification defines the AI Incident Response Protocol (AIRP), an AI incident response and reconstruction protocol in six stages: signal, classify, contain, escalate, reconstruct and close. It is entry REG-05 of the Defensible AI Framework Registry, and that entry governs its relationships. Its central requirement is a design constraint on the platform rather than a procedure for the response team. An incident is explainable only if the evidence needed to reconstruct it existed at the moment of the decision, bound to the policy version then in force. That requirement cannot be satisfied after the fact, which is why it appears in a response protocol at all: an institution reading this document during an incident is already too late to act on its central clause. The requirement is already normative in four published records and is cited rather than restated, because a protocol restating them would be a second place they could drift. What this specification owns is the consuming side, which nothing else in the corpus states. What a reconstruction report must contain and how it is joined on a propagated event identity rather than correlated on timestamps. What the signal register records, including signals closed as non-incidents, because a register of confirmed incidents alone is a numerator with no denominator. How a partial reconstruction is reported outside the engineering family, to a board or an authority that will not read an artifact inventory. How notifiability is classified. And how the conformance test derived at closure is produced, so the same failure is caught next time by machinery rather than by memory. It ships the artifact its registry entry recorded as missing. Appendix C specifies a machine-readable incident taxonomy, deposited alongside the specification and aligned to the OECD AI Incidents and Hazards Monitor and the AI Incident Database. That alignment is this author's mapping. Neither organization has been contacted, neither has reviewed or endorsed it, and it must not be presented as interoperable with either repository's own annotation process. Two clauses accompany the protocol everywhere, and both are normative. It states no jurisdiction's notification timeline and no notifiability threshold: both vary by jurisdiction and by authority, both change, and both are the institution's to verify against the primary sources in force where it operates. The specification states the record an institution writes about that determination; it does not state the determination. And its evidence level is E1, which is stated rather than implied: no institution unconnected to the author has been observed operating the protocol, no reconstruction produced under it has been examined by an external authority, and the redacted export specified at Appendix D is not published. E2 must not be inferred. The specification also states what it does not supply. No severity scale, so two institutions will classify the same incident differently. No reconstruction report template. And no measurement of what the added evidence burden costs, nor of the scale below which it stops being proportionate to the risk. Section 11 states each of these, poses four research questions, and states the condition that would falsify the protocol: that institutions holding complete upstream decision-time records prove no better able to reconstruct an AI incident, to a standard an external authority accepts, than institutions holding conventional application and infrastructure logs. The author operates a consulting practice applying this protocol, which is a conflict of interest stated in the document and only partly mitigated. It is a specification, not a certification scheme. No conformity assessment body operates against it and no institution can be certified against it.

View source

Similar papers

#artificial intelligence Conference Open access Apr 2020

ECCOLA - a Method for Implementing Ethically Aligned AI Systems

The method, ECCOLA, is presented, which aims at making the high-level AI ethics principles more practical, making it possible for developers to more easily implement them in practice.

Ville Vakkuri, Kai-Kristian Kemell, P. Abrahamsson · 64 citations · ⚡6
#computer vision Review Apr 2024

AI-powered Code Review with LLMs: Early Results

The goal is to not only refine the accuracy of the LLM-based tool but also to underscore its potential in streamlining the software development lifecycle through proactive code improvement and education.

Z. Rasheed, Malik Abdul Sami, Muhammad Waseem et al. · 62 citations · ⚡3
#computer vision Open access Mar 2024

LLM-based agents for automating the enhancement of user story quality: An early report

The use of large language models to automatically improve the user story quality in Austrian Post Group IT agile teams is explored, with a reference model for an Autonomous LLM-based Agent System developed and implemented at the company.

Zheying Zhang, M. Rayhan, Tomas Herda et al. · 48 citations · ⚡4
#computer vision Review Mar 2024

System for systematic literature review using multiple AI agents: Concept and an empirical evaluation

This paper introduces a novel multi-AI-agent system designed to fully automate SLRs, and demonstrates how it substantially reduces the time and effort traditionally required for SLRs while maintaining comprehensiveness and precision.

Abdul Malik Sami, Z. Rasheed, Kai-Kristian Kemell et al. · 44 citations · ⚡2
#computer vision Feb 2024

Can Large Language Models Serve as Data Analysts? A Multi-Agent Assisted Approach for Qualitative Data Analysis

The proposed LLM-based multi-agent system automates qualitative data analysis process, creating opportunities for researchers and practitioners, and future improvements focus on enhancing multilingual performance and integrating continuous expert feedback.

Z. Rasheed, Muhammad Waseem, Aakash Ahmad et al. · 41 citations
#artificial intelligence Conference Open access Jun 2018

The Key Concepts of Ethics of Artificial Intelligence

It is suggested that the focus on finding keywords is the first step in guiding and providing direction for future research in the AI ethics field.

Ville Vakkuri, P. Abrahamsson · 39 citations · ⚡2

Related blog posts

GPT-Lab Sep 17, 2026

Beyond Prompt Engineering: The Role of Tacit Knowledge in Software Engineering

AI is making software generation faster, but speed does not remove the need for expertise. As more work is delegated to AI, tacit knowledge may become one of the most important human advantages in software engineering. The post Beyond Prompt Engineering: The Role of Tacit Knowledge in Software Engineering appeared first on GPT-Lab.

MIT News · Artificial Intelligence Sep 14, 2026

New method enables AI for safety-critical situations

The “HardFlow” algorithm could help generative AI models produce high-quality outputs that obey strict requirements when “pretty close” doesn’t cut it.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.