AI Governance · Incident Response
AI Incident Response: P1-P4 Severity Tiers
How to classify and respond to an AI incident, and the notification clocks you're already on — GDPR Article 33, EU AI Act Article 73.
Your AI system just made a harmful decision — a biased rejection, a data leak, a bad output at scale. If you don't have a playbook before that happens, you're improvising during the worst possible moment to improvise.
The four parts of a playbook
- Classify severityP1 (Critical) through P4 (Low) — the tier sets the clock.
- Contain itStop active harm before investigating root cause.
- Know who to notify, and by whenRegulators and affected parties, on the applicable timeline.
- Document + reviewRoot cause and lessons learned, in writing.
The 6-step response process
- Detect
- Contain
- Assess
- Notify
- Remediate
- Review
Get a free sample AI incident response playbook — no cost, just your email.
Email me the free sampleOr go straight to the full playbook — $49, one-time.
Frequently asked
- What are the P1-P4 AI incident severity tiers?
- P1 (Critical) means active harm that must be stopped immediately. P2 (High) is a significant risk that is contained but urgent. P3 (Moderate) is limited impact handled through standard process. P4 (Low) is a near-miss that gets logged.
- How long do you have to report an AI data breach?
- Under GDPR Article 33, a personal-data breach must be notified to the relevant supervisory authority within 72 hours of becoming aware of it. Separately, the EU AI Act Article 73 creates a reporting duty for serious incidents involving high-risk AI systems.
- What are the steps in an AI incident response process?
- Six steps: Detect, Contain, Assess, Notify, Remediate, and Review — each with an owner and an evidence requirement such as model logs and decision records.
- What evidence should you collect during an AI incident?
- Model logs and decision records that let you reconstruct exactly what happened, not a reconstruction based on memory — this evidence supports both the notification and the post-incident root cause review.
This page and the linked tool produce first-draft, AI-generated documents — not legal advice. Qualified review is required before you rely on any output.
Sources: Regulation (EU) 2024/1689 (EU AI Act), Article 73 · Regulation (EU) 2016/679 (GDPR), Article 33 · Responsible AI Studio .