The AI Incident Response Protocol: Six Stages, and the Evidence a Reconstruction Requires
Abstract
An institution asked to explain an AI failure discovers, at that moment and not before, what it wrote down. The discovery is unrecoverable. Evidence is a property of the moment a decision was taken, and an institution that did not capture it then is left assembling an account from what it can still find. It reconstructs beliefs, not behaviour. This specification defines the AI Incident Response Protocol (AIRP), an AI incident response and reconstruction protocol in six stages: signal, classify, contain, escalate, reconstruct and close. It is entry REG-05 of the Defensible AI Framework Registry, and that entry governs its relationships. Its central requirement is a design constraint on the platform rather than a procedure for the response team. An incident is explainable only if the evidence needed to reconstruct it existed at the moment of the decision, bound to the policy version then in force. That requirement cannot be satisfied after the fact, which is why it appears in a response protocol at all: an institution reading this document during an incident is already too late to act on its central clause. The requirement is already normative in four published records and is cited rather than restated, because a protocol restating them would be a second place they could drift. What this specification owns is the consuming side, which nothing else in the corpus states. What a reconstruction report must contain and how it is joined on a propagated event identity rather than correlated on timestamps. What the signal register records, including signals closed as non-incidents, because a register of confirmed incidents alone is a numerator with no denominator. How a partial reconstruction is reported outside the engineering family, to a board or an authority that will not read an artifact inventory. How notifiability is classified. And how the conformance test derived at closure is produced, so the same failure is caught next time by machinery rather than by memory. It ships the artifact its registry entry recorded as missing. Appendix C specifies a machine-readable incident taxonomy, deposited alongside the specification and aligned to the OECD AI Incidents and Hazards Monitor and the AI Incident Database. That alignment is this author's mapping. Neither organization has been contacted, neither has reviewed or endorsed it, and it must not be presented as interoperable with either repository's own annotation process. Two clauses accompany the protocol everywhere, and both are normative. It states no jurisdiction's notification timeline and no notifiability threshold: both vary by jurisdiction and by authority, both change, and both are the institution's to verify against the primary sources in force where it operates. The specification states the record an institution writes about that determination; it does not state the determination. And its evidence level is E1, which is stated rather than implied: no institution unconnected to the author has been observed operating the protocol, no reconstruction produced under it has been examined by an external authority, and the redacted export specified at Appendix D is not published. E2 must not be inferred. The specification also states what it does not supply. No severity scale, so two institutions will classify the same incident differently. No reconstruction report template. And no measurement of what the added evidence burden costs, nor of the scale below which it stops being proportionate to the risk. Section 11 states each of these, poses four research questions, and states the condition that would falsify the protocol: that institutions holding complete upstream decision-time records prove no better able to reconstruct an AI incident, to a standard an external authority accepts, than institutions holding conventional application and infrastructure logs. The author operates a consulting practice applying this protocol, which is a conflict of interest stated in the document and only partly mitigated. It is a specification, not a certification scheme. No conformity assessment body operates against it and no institution can be certified against it.