AI Governance · Incident Response

AI Incident Response: P1-P4 Severity Tiers

How to classify and respond to an AI incident, and the notification clocks you're already on — GDPR Article 33, EU AI Act Article 73.

Last reviewed:

Your AI system just made a harmful decision — a biased rejection, a data leak, a bad output at scale. If you don't have a playbook before that happens, you're improvising during the worst possible moment to improvise.

The four parts of a playbook

  1. Classify severityP1 (Critical) through P4 (Low) — the tier sets the clock.
  2. Contain itStop active harm before investigating root cause.
  3. Know who to notify, and by whenRegulators and affected parties, on the applicable timeline.
  4. Document + reviewRoot cause and lessons learned, in writing.

The 6-step response process

  1. Detect
  2. Contain
  3. Assess
  4. Notify
  5. Remediate
  6. Review

Get a free sample AI incident response playbook — no cost, just your email.

Email me the free sample

Or go straight to the full playbook — $49, one-time.

Frequently asked

What are the P1-P4 AI incident severity tiers?
P1 (Critical) means active harm that must be stopped immediately. P2 (High) is a significant risk that is contained but urgent. P3 (Moderate) is limited impact handled through standard process. P4 (Low) is a near-miss that gets logged.
How long do you have to report an AI data breach?
Under GDPR Article 33, a personal-data breach must be notified to the relevant supervisory authority within 72 hours of becoming aware of it. Separately, the EU AI Act Article 73 creates a reporting duty for serious incidents involving high-risk AI systems.
What are the steps in an AI incident response process?
Six steps: Detect, Contain, Assess, Notify, Remediate, and Review — each with an owner and an evidence requirement such as model logs and decision records.
What evidence should you collect during an AI incident?
Model logs and decision records that let you reconstruct exactly what happened, not a reconstruction based on memory — this evidence supports both the notification and the post-incident root cause review.

This page and the linked tool produce first-draft, AI-generated documents — not legal advice. Qualified review is required before you rely on any output.

Sources: Regulation (EU) 2024/1689 (EU AI Act), Article 73 · Regulation (EU) 2016/679 (GDPR), Article 33 · Responsible AI Studio .

← All AI governance resources