Global AI Assurance · Layer 07

    AI Incident Intelligence

    Most AI incident records say the model failed. That is not a record an institution can learn from, report against or defend. An AI incident is a control event with an actor, a reach, a regulation and an aftermath, and it needs to be captured that way from the first minute.

    The incident record

    Institution and entity

    Which legal entity carries the obligation that was engaged.

    Model

    Provider, family and hosting arrangement at the time of the event.

    Agent

    The acting identity, so the authority envelope can be tested against what happened.

    Version

    Behaviour is version-specific. Without it, the incident is not reproducible.

    Environment

    Production, pilot or evaluation. It changes the reporting obligation.

    Tool

    The interface through which the action reached an institutional system.

    Data

    Classes touched, and whether a transfer or a disclosure obligation followed.

    Action

    What the system actually did, separate from what it output.

    Control that failed

    Named control, so effectiveness monitoring can be corrected.

    Regulation engaged

    The obligation and the authority, with the reporting clock that started.

    Impact

    Client, market, financial and service impact, measured not asserted.

    Containment

    What stopped it, who authorised that, and how long it took.

    What changed after

    The control, envelope or test that was altered as a result.

    The same record satisfies an internal post-incident review, a third-line audit request and a supervisory notification, because it was never written for only one of them.

    Early warning

    Read across the estate rather than incident by incident, and the signal usually arrives before the loss does.

    Repeat refusals at one boundary

    An envelope is mis-scoped or a business process is routing around a control.

    Drift clustering on one model version

    A provider change is propagating across every agent on that version.

    Tool-server failures across owners

    A shared dependency, not a local fault. Treat as concentration.

    Rising human-review volume

    Evaluation confidence is falling before any incident is recorded.

    Evidence freshness decaying

    The control may still operate, but it can no longer be proven.

    Incidents and dependencies read together produce a systemic view rather than a queue of unrelated events.

    AI Systemic Risk