Skip to content

AI Incidents Require New Incident-Response Playbooks

The gist: Classical incident-response frameworks fall short for AI incidents because they do not capture probabilistic failures and a new classification schema with separate playbooks for model-induced and externally-induced failure scenarios is required.

Only 16 % of organisations with AI access to critical systems manage this access effectively. CISOs must revise their existing incident-response playbooks, as these are not tailored to the specifics of AI incidents.

The 2026 CISO AI Risk Report reveals a structural governance problem: 71 % of organisations have AI systems with access to core business systems in production, but only 16 % manage these accesses effectively. The reality in most operations is a critical misunderstanding: organisations have AI in production and an incident-response playbook. They assume that these two things are connected – they are not. CISOs who believe their existing IR playbooks cover AI incidents have typically not tested them. Those who have tested them know that it does not work.

AI incidents increased by 56.4 % between 2023 and 2024, reaching 233 documented cases. Common IR frameworks such as NIST SP 800-61, MITRE ATLAS and the GLACIS AI Incident Response Playbook offer a taxonomy of six incident types – yet this classification misses the crucial distinction: failures caused by the model itself versus failures caused by human intervention. Detection strategy, containment logic and liability risk differ fundamentally between the two groups. Model-induced failures – model degradation, bias, hallucinations – occur when the system operates exactly to specification but is defective. The Epic Sepsis Model, deployed in hundreds of US hospitals, demonstrated a sensitivity of only 33 % when validated on external data. It missed two-thirds of actual sepsis cases and bombarded physicians with false alarms – as a 2021 JAMA Internal Medicine study found. No one attacked the system. It simply failed silently in the background while all dashboards remained green.

Externally-induced failures – adversarial attacks, data poisoning, data breaches – arise from manipulation of inputs or training environment. Tesla’s Autopilot phantom-braking cases, investigated by the NHTSA across hundreds of thousands of vehicles, demonstrate how input errors in safety-critical systems appear. These two groups require different primary defences and their own playbooks.

The highest legal exposure currently lies in the hybrid case. Hallucinations originate from the model but appear in court like human error. When Air Canada’s chatbot presented a fabricated bereavement fare policy, the airline became liable. When the US Federal Court granted summary judgment in Mobley v. Workday, it accepted that an AI recruiting platform can be held directly liable as an “agent” of employers. None of these failures looked like security incidents. Both ended as legal ones. The classical CIA triad – confidentiality, integrity, availability – does not capture these incidents: nothing was unavailable, nothing was changed without authorisation, nothing was disclosed. The framework does not apply. Average detection time for AI incidents is 4.5 days, and 67 % of AI incidents result from model errors, not attacks – yet traditional IR metrics do not effectively capture either.


Source: www.csoonline.com · Published 14 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: