The first 24 hours determine the trajectory of an AI incident. The technical failure is rarely the worst part. The governance failures that follow are.
Stop and read this first
If you are in the first hour of an AI incident and the system is still operating, the first decision is whether to stop it. If continued operation creates ongoing risk of material harm, stop it now. You can investigate later. You cannot undo harm that occurred while you were investigating whether to stop.
Four actions, in this order. Do not move to step five until steps one through four are done.
Stop the AI system if continued operation poses ongoing harm risk. Pause is a default-safe decision. If you cannot determine quickly whether harm is ongoing, default to pausing.
Preserve the technical evidence: model state, input data, output logs, system logs, configuration at time of incident. AI systems can change rapidly; what is true now may not be true in six hours.
Engage legal counsel and the incident response team immediately. Privilege attaches to investigations conducted under legal direction; it does not attach to investigations that started informally and were lawyered up later.
Begin an incident log with timestamps. Who knew what, when. What decisions were made and by whom. This log becomes the foundation for regulatory notification, internal review, and any subsequent litigation.
The notification analysis is jurisdiction-specific, but the categories to evaluate are consistent. Work through each. Where the answer is yes, notification timelines start running from the moment you became aware of the incident, not from the moment you finished investigating.
In the first 24 hours, you will be tempted to communicate before you understand the scope of the incident. Do not. The information you have at hour two will be different from the information you have at hour 24. Statements made early that turn out to be incorrect compound the original incident with a credibility incident.
The exception: where there is an ongoing risk of harm that proactive communication can mitigate, communicate to enable affected parties to protect themselves. Otherwise, hold all external communication until you can stand behind what you are saying.
The technical investigation asks: what did the AI system do, and why? This is necessary but insufficient. The governance investigation asks: what failures of monitoring, validation, accountability, and culture allowed this incident to occur and to persist until it became visible? The governance investigation is what prevents the next incident.
Organisations that respond to AI incidents with technical fixes alone, without examining governance failures, almost always experience a second incident within 18 months. The pattern is so consistent that responding without governance review is itself a governance failure.
An on-site playbook covering classification, severity matrix, notification templates, communication holding statements, a root-cause investigation framework, and tabletop exercise scenarios, free to read on the site.
Open the playbookIf you are in the middle of an AI incident and need experienced support, get in touch. We have helped organisations navigate the first 72 hours of AI incidents across multiple sectors and jurisdictions.
Contact us urgently