Prepare for AI incidents before deployment.
Advanced AI governance needs explicit detection, containment, escalation, evidence preservation, recovery and learning mechanisms.
Detect and classify
Identify abnormal behavior, harmful outcomes, control failures or material policy breaches.
Contain
Restrict access, disable tools, reduce permissions, isolate integrations or suspend deployment.
Escalate
Route the incident by severity to technical, risk, legal, security and executive owners.
Preserve evidence
Secure logs, prompts, outputs, model/version metadata, decisions and affected integrations.
Recover and reauthorize
Remediate causes and require explicit approval before restoring higher-risk functionality.
Learn and update controls
Feed findings into evaluation suites, policies, thresholds and future deployment decisions.
Severity model
Severity should combine impact, scope, reversibility, control failure and uncertainty.
| Level | Illustrative condition | Governance response |
|---|---|---|
| Level 1 | Low-impact anomaly, contained, no material control breach. | Log, review, tune monitoring. |
| Level 2 | Repeatable harmful behavior or limited control failure. | Restrict scope, investigate, owner sign-off. |
| Level 3 | Material harm potential, privilege misuse, significant policy breach. | Containment, senior escalation, independent review. |
| Level 4 | Severe or systemic risk, loss of effective control, broad impact. | Stop authority, executive response, external obligations assessment. |