An incident begins before the headline
Institutions that wait for public harm to define an AI incident throw away the near misses and weak signals that could have prevented it.
The public learns about an AI incident when the consequence becomes visible: an account closed, a benefit denied, private information exposed, a vehicle misdirected, or a false image spread. Inside the institution, the incident began earlier. It began with the ignored warning, the control that failed safely only by luck, the repeated override, or the output an operator caught before it reached the person outside.
The OECD’s common reporting framework provides 29 criteria intended to make incident information comparable across jurisdictions and sectors. The framework’s value is not merely administrative harmonization. Shared fields force organizations to preserve facts that a dramatic narrative tends to erase: context, actors, harms, system characteristics, causes, and responses.
Comparable reporting begins with a broader internal vocabulary. If an institution recognizes only events that trigger a legal notification threshold, it will learn only from its most expensive failures. Near incidents, hazards, attempted attacks, and control degradations belong in the operating record even when they do not become externally reportable.
Severity is not the same as learning value
A low-consequence event can reveal a high-consequence mechanism. An agent attempts an unauthorized transfer but the destination account is inactive. A model exposes a record that happens to contain no sensitive data. A reviewer catches a discriminatory recommendation before execution. No serious harm occurs, yet each event supplies evidence about a path that may succeed next time.
Organizations often discard such events because incident programs are designed around response cost. Opening a formal case triggers meetings, reports, deadlines, and executive attention. Teams therefore negotiate the event downward. A lighter-weight near-miss channel can preserve learning without pretending that every anomaly deserves the same escalation.
The absence of harm may be evidence that a control worked, or evidence that the institution was lucky. Incident review must distinguish them.
That distinction requires recording the stopping condition. What prevented consequence: model refusal, access control, human intervention, rate limit, unavailable service, or chance? A report that says only ‘no impact’ hides the most important fact. If the safeguard was accidental, the institution remains exposed. If it was designed, the event may validate a control while still revealing attempted compromise.
Repeated weak signals should aggregate. Five isolated tool errors may be routine. Five errors following the same class of external instruction may indicate an attack. Ten appeals reversed for the same reason may reveal a policy defect even if each case appears small. Incident systems should support pattern detection across decisions, products, vendors, and time.
Reporting starts at system design
The European Commission’s draft guidance and template for serious AI incidents was published to prepare providers for rules applying from August 2026 and explicitly seeks alignment with OECD work. Institutions should treat the template as an engineering requirement: can the deployed system produce the facts a report will require?
A provider cannot reconstruct system state if it did not version the model, policy, tools, and data dependencies. It cannot describe the sequence if asynchronous actions lack correlated identifiers. It cannot identify affected groups if the deployment never recorded the relevant context. Reporting duties expose observability debt that ordinary performance monitoring leaves hidden.
Responsibility must cross the value chain. A deployer sees local consequence. A model provider sees broader technical patterns. An integrator knows the orchestration. A cloud provider may hold infrastructure evidence. Contracts and interfaces should define how incident signals move among them, how quickly, in what format, and without forcing each party to surrender unrelated confidential information.
Time is a design variable. A reporting clock cannot begin only when legal counsel reaches certainty. The organization needs a moment of awareness, a triage path, and escalating deadlines for preserving evidence, containing risk, notifying partners, and deciding whether formal reporting is required. Uncertainty should shape the report, not postpone the existence of one.
An incident record should change the system
The incident process is incomplete if it ends with classification. Each case should identify corrective actions, owners, due dates, and the evidence that will show the remedy worked. It should connect to impact assessment, evaluation suites, access policy, procurement decisions, and user remedy. Otherwise the organization learns in prose while operating systems remain unchanged.
The EU’s general AI Act implementation overview places post-market monitoring, human oversight, corrective action, and incident reporting together. That grouping reflects a cycle: monitoring detects, reporting organizes, correction responds, and subsequent monitoring tests whether the response held.
Disclosure should be proportionate but not self-serving. Public reporting may need to protect personal data, security details, and ongoing investigations. Those protections should not become a reason to publish nothing. Affected people need notice and remedy; regulators need operational facts; the wider field needs enough shared learning to recognize recurring failure patterns.
An incident taxonomy will never capture every novel failure. It should allow uncertain and emerging categories rather than forcing events into familiar boxes. The first case of a new mechanism may look ambiguous precisely because the institution has no label. Preserve the observation before demanding that it fit the classification.
Exercises can test the record before a real event does. Give the incident team an ambiguous agent failure and ask it to locate versions, identify affected decisions, preserve evidence, contact upstream providers, and decide what to disclose. The exercise will reveal missing fields and uncertain ownership while the cost of discovery is still low.
The mature incident program pays attention before the headline. It records the attempt that failed, the safeguard that nearly did not, the pattern visible only in aggregate, and the report that remains incomplete. Catastrophe supplies clarity at an unacceptable price. Assurance is the practice of learning while the evidence is still quiet.
— Dispatches · Summit Cognitive
Continue from here
Turn the argument into a practice.
Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.