← Back to Insights
Advisory Brief · AI Incident Reporting

AI Incidents Belong in the Incident System You Already Trust

A verified operating read of AI incident definitions and reporting regimes: what counts as an incident, which events must leave the building and on whose clock, and what to build before a regulator specifies it.

Date  Jul 2026 Prepared as  Outcome brief ✓ Verified  20 citations checked
Conditional sign-off verdict

It is safe to approve AI in consequence-bearing operations only if the sponsor can show the incident regime behind it: a written definition that turns on realized harm plus material AI contribution, separate internal categories for near misses and control failures, routing into the incident command system the enterprise already runs, and an evidence packet preserved before remediation changes the scene. A new AI portal, a policy binder, or a vendor dashboard does not satisfy this, and the AI label never pauses an existing reporting clock.

The operating regime

Define

An AI incident is realized harm with material AI contribution. A near miss is the same pattern where intervention, redundancy, or chance prevented harm. A control failure is a safeguard that did not work.

Route

All three classes flow into existing safety, cyber, reliability, privacy, legal, and disclosure incident command through a short AI addendum, not a parallel AI process.

Learn

Near misses and control failures report internally under protected good-faith rules, so the channel that punishes does not silence the channel that teaches.

Account

External reports fire when the underlying event crosses an existing legal threshold or a defined serious-harm threshold, on the existing clock, to the named recipient.

The sign-off test

Owner

Who classifies the event, commands the response, holds authority to stop the AI use, and owns each external reporting clock?

Briefing

Which severity gate the event crossed, which lane it sits in, and which external recipients, thresholds, and deadlines apply to it?

Proof

Can the team produce the evidence packet: model version, inputs, tool calls, approvals, overrides, failed controls, containment, and causal confidence?

What leaders should take from it

1
Define the incident by consequence, not by a bad answer.

The verified base definition turns on harm plus AI contribution: development, use, malfunction, or unauthorized behavior of AI that caused or materially contributed to realized harm. A wrong output with no consequence is a quality defect for the backlog, unless it recurs, aggregates, or exposes a failed control. Near misses and control failures get their own internal categories so the signal is captured without inflating the incident count.

2
Run two lanes: protected learning and mandatory accountability.

Aviation's confidential reporting system shows that a protected voluntary channel surfaces near misses a punitive channel suppresses; grid, securities, and drug-safety regimes show the other lane: named recipients, triggering tests, deadlines, and follow-ups. Protect good-faith internal reports while preserving discipline for recklessness, concealment, or a missed mandatory report. The protection is conditional, not immunity.

3
In regulated operations, AI rides inside existing incident command.

The worked utility example: an AI-related cyber event that meets the NERC CIP-008 test goes to E-ISAC and CISA on the existing one-hour clock; a reliability event follows EOP-004 and the entity's Operating Plan; DOE's separate form runs its own faster tiered clocks through its own channel. One internal case drives every route. The AI label never pauses, restarts, or merges any of those clocks.

4
Trigger on outcome, failed control, scale, and irreversibility.

Internal reporting starts on a reasonable possibility that AI contributed to harm, an unauthorized action, a failed stop, compromised data or evidence, or a recurring pattern. External reporting starts when the underlying event meets an applicable legal threshold. The two triggers are intentionally different, and related low-severity events must be aggregated because a series can be material when no single event is.

5
The minimum viable control is a preserved evidence packet.

Before remediation changes the scene, capture the system and model version, use case, inputs and context, tool calls, permissions, approvals and overrides, expected and failed controls, containment, and causal confidence. Then report in stages: fast initial facts, updates, a root-cause and corrective-action record, and a trend review. An event that cannot be reconstructed cannot support learning, disclosure, or assurance.

Where the evidence stops

Two claims run ahead of the evidence. Public AI incident databases show documented reports, not prevalence: the widely cited jump from 233 recorded cases in 2024 to 362 in 2025 comes from a voluntary, media-driven database with no exposure denominator, so it proves documented cases are accumulating, not that real harm rose by a measured amount. And while the two-lane architecture is strongly supported by mature regimes in aviation, grid reliability, securities, and drug safety, no controlled evidence yet proves any one universal reporting design reduces incidents. The operating pattern is verified; the outcome evidence stays open.

The Deep Dive holds the action map: the three-part taxonomy in policy form, six severity gates, the AI field set for the existing incident system, internal clocks that beat the fastest external clock, the regulated-utility routing example, the full claim ledger, and refresh triggers.

Open the Deep Dive
Outcome brief staged from verified Storm Research v2 · 20 citations checked · 0 fabricated · 8 corrected · 3 demoted