Incident response · AI governance

An AI incident can start aregulatory clock you can’t see.

The deadline is rarely the hard part. Different regimes attach reporting periods to different facts, knowledge standards, or determinations, and the hard part is recognizing and assessing a potential trigger in time, before days burn. Drill it before it’s real.

Get the Drill — $79one-time · instant download · yours to keep

Not legal advice. This is a readiness drill that grades your notification process from your own marks. It is date-agnostic and asserts no deadline; it files nothing, confirms no regulatory obligation, and scores no people. Notification duties (GDPR, the EU AI Act, SEC, HIPAA, and US state breach laws) vary by jurisdiction and change often — confirm which apply to you and every deadline with qualified counsel.

Five deliverables · runnable
Notification-readiness engine
runnable
Workbook that reproduces it
.xlsx
Drill Facilitator Playbook
.docx
Notification-Readiness Runbook
.docx
6-scenario worked sample
sample
Works alongside
Postmortem Gate · Ransomware Drill · NIST AI RMF Kit

Update notice — version 1.1.0 (2026-09-23). This package replaces version 1.0 of the AI Incident Reporting & Regulatory Notification Drill. The regime-triage, trigger-assessment and drafting controls are renamed and re-scaled, the text about when a reporting period begins is revised, and the SEC and HIPAA crosswalk rows are rewritten. Scoring is unchanged: the same marks produce the same score and verdict as in version 1.0. Existing buyers: the download link in your original purchase email now serves version 1.1.0.

01.The Problem

You knew the deadline. You missed it anyway.

Each regime has its own trigger

Under GDPR Article 33 the period runs from awareness of a personal-data breach. Domestic registrants generally file Item 1.05 Form 8-K within four business days after determining that a cybersecurity incident is material; the determination may not be unreasonably delayed following discovery. For a covered entity, HIPAA discovery occurs when the breach is known or would have been known through reasonable diligence; analyze individual, HHS, media, and business-associate notification paths separately. Record each potential trigger point separately.

One incident, several clocks

The same event can fire a data-breach duty, an AI safety report, and a securities disclosure at once — each with a different deadline and a different start.

No one was authorized to act on it

A plan that routes the decision to a committee that meets next week can miss a reporting period. Someone has to be authorized to assess and document potential trigger points and activate the appropriate escalation path, even at 2am.

02.See It Work

Drill a scenario. Read whether your process is ready.

This is the live scoring logic from the engine. The “AI Act serious incident” preset scores 82 and still reads WOULD MISS THE CLOCK — because no one is authorized to assess potential trigger points and escalate. Give it an authorized decision-maker and it clears.

Drill a scenario:
⚡ Detection-to-awareness path20

Defined, rehearsed path; awareness time recorded

⚡ Regime, trigger, and severity triage20

Potentially applicable regimes are mapped to their scope, triggers, recipients, required content, timing, exceptions, and responsible owners, with legal review where appropriate.

⚡ A named, authorized decision-maker for trigger assessment and escalation18

No one authorized to assess and document potential awareness, discovery, materiality, or other applicable trigger points and to activate the appropriate escalation path

Regulator contact map & filing channel16

Authorities, portals, channels mapped in advance

Notification drafting and incident-record path14

Templates and internal records are maintained, and any staged-reporting path is documented for the regimes that permit or require it.

Cross-track coordination12

Rehearsed cross-functional parallel-track process

WOULD MISS THE CLOCKscore 82/100

Trigger-assessment gate fired: no one is authorized to assess and document potential trigger points and activate the appropriate escalation path. The score alone would read NOTIFIABLE-READY AS DESCRIBED, but a potential trigger nobody assesses can consume time a reporting period allows.

Drill first: A named, authorized decision-maker for trigger assessment and escalation

Weighted to 100. The gate forces WOULD MISS THE CLOCK when you could not recognize and assess a potential trigger in time (⚡ detection or triage) or no one is authorized to assess potential trigger points and escalate (⚡ authority). Date-agnostic — it grades your process, never a specific deadline. Not legal advice.

Diagram of the AI Incident Reporting & Regulatory-Notification Drill: notification readiness scored to 0-100 and a trigger-assessment gate forcing WOULD MISS THE CLOCK.
Shareable diagram

How the gate works, in one image

How the AI Incident Reporting & Regulatory-Notification Drill scores notification readiness and reads WOULD MISS THE CLOCK when the authorized decision-maker is missing — the same math the demo runs, as a diagram you can share or embed anywhere.

View & embed the full diagram
03.The Engine

The same verdicts, from the runnable engine.

Verbatim output from the included Python engine on the six-scenario sample. The workbook reproduces these byte-for-byte.

==========================================================================
AI INCIDENT REPORTING & REGULATORY-NOTIFICATION DRILL
==========================================================================

Customer PII leak via AI chatbot
  verdict: NOTIFIABLE-READY AS DESCRIBED   (score 94/100)

Model failure harms a user (AI Act serious incident)
  verdict: WOULD MISS THE CLOCK   (score 82/100)
  gate: WOULD MISS THE CLOCK — no one is authorized to assess and document potential trigger points and activate the appropriate escalation path
  drill first: A named, authorized decision-maker for trigger assessment and escalation

Same incident after naming an on-call authorized decision-maker
  verdict: NOTIFIABLE-READY AS DESCRIBED   (score 100/100)

Material cyber incident in a public-co AI system
  verdict: TIGHTEN   (score 50/100)
  drill first: Detection-to-awareness path

Vendor/sub-processor breach reaches your data
  verdict: WOULD MISS THE CLOCK   (score 50/100)
  gate: WOULD MISS THE CLOCK — you could not recognize and assess a potential trigger in time
  drill first: Regime, trigger, and severity triage

Prompt-injection exfiltrates regulated records
  verdict: WOULD MISS THE CLOCK   (score 56/100)
  gate: WOULD MISS THE CLOCK — you could not recognize and assess a potential trigger in time
  drill first: Detection-to-awareness path

--------------------------------------------------------------------------
PROGRAM: WOULD MISS NOTIFICATION   (3 of 6 would miss the clock · exposure 50.0%)
--------------------------------------------------------------------------

Grades your notification PROCESS against the clock, never a specific
deadline — so it does not break when a regime's dates shift. It grades a
process, never people, and confirms no actual regulatory obligation.
A readiness drill, not legal advice. Confirm which regimes apply, and
every deadline, with counsel.

The AI Act scenario above is a hypothetical future-state rehearsal. Under the Digital Omnibus, the Annex III high-risk obligations apply from 2 December 2027, and serious-incident reporting falls primarily on providers; a deployer’s information duties, and any circumstances in which Article 73 applies to a deployer, should be mapped separately. Confirm system classification, your operator role, territorial scope and the applicable date before relying on any scenario here.

04.The Standard

Six controls, weighted to 100. The weakest trigger-assessment control is dispositive.

20

⚡ Detection-to-awareness path

Regimes use different triggering events and knowledge standards. Record detection, discovery, awareness, escalation, and any required legal determination separately; confirm the applicable start point, decision-maker, recipient, and deadline with counsel. Here “awareness” is operational shorthand rather than a universal legal trigger.

20

⚡ Regime, trigger, and severity triage

Which regimes may apply, what event or determination starts each reporting period, and which potentially applicable period is shortest? For rehearsal purposes, use the shortest potentially applicable period as the initial internal triage target. Each regime retains its own scope, trigger, recipient, required content, timing, and exceptions; satisfying one does not satisfy the others.

18

⚡ A named, authorized decision-maker for trigger assessment and escalation

Someone authorized to assess and document potential awareness, discovery, materiality, or other applicable trigger points and to activate the appropriate escalation path, at any hour — not a committee that meets Monday.

16

Regulator contact map & filing channel

Authorities, a lead supervisory authority where one applies, portals, and channels mapped before the incident, not during it.

14

Notification drafting and incident-record path

Pre-drafted templates, a maintained internal incident record, and — where the applicable regime permits or requires staged reporting — an initial report that can be supplemented as additional information becomes available. GDPR Article 33(4), for example, permits information to be provided in phases when it cannot be provided at the same time.

12

Cross-track coordination

One incident can trigger several potentially applicable reporting periods at once — legal, security, comms, privacy pre-aligned.

⚡ = a trigger-assessment gate control. If detection-to-awareness or severity triage is absent, or no one is authorized to assess potential trigger points and escalate, the scenario is WOULD MISS THE CLOCK regardless of score. The gate worsens only — it never promotes a verdict.

05.What It Is — And Isn’t

A readiness drill, not a compliance ruling.

It is

  • A rehearsal of your incident-notification process.
  • Date-agnostic — it grades the process, never a deadline.
  • A deterministic, offline engine + workbook you control.

It isn’t

  • Legal advice, a filing service, or a certification.
  • A ruling on whether an incident is legally reportable.
  • A score of people — it grades a process.

Not legal advice. This is a readiness drill that grades your notification process from your own marks. It is date-agnostic and asserts no deadline; it files nothing, confirms no regulatory obligation, and scores no people. Notification duties (GDPR, the EU AI Act, SEC, HIPAA, and US state breach laws) vary by jurisdiction and change often — confirm which apply to you and every deadline with qualified counsel.

06.Who It’s For

Whoever owns the first hour of an AI incident.

  • Security, privacy, and compliance leads who own incident response.
  • Legal and DPO functions tracking GDPR, AI Act, SEC, HIPAA, and state clocks.
  • Teams deploying high-risk or customer-facing AI that could cause a reportable incident.
  • Not a filing tool — it rehearses readiness, it doesn’t notify anyone.
  • Not a ruling on what’s reportable — confirm that with counsel.
  • Not a postmortem tool — that’s the close-out gate it pairs with.
08.Common Questions

Answers before you buy.

It grades whether your notification process is ready for the reporting periods an AI incident could trigger — scenario by scenario. For each drilled incident you mark six controls 0/1/2: your detection-to-awareness path, regime, trigger, and severity triage, whether a named person is authorized to assess potential trigger points and escalate, your regulator contact map and filing channel, your notification drafting and incident-record path, and cross-track coordination. The six are weighted to a 0–100 score banded NOTIFIABLE-READY AS DESCRIBED, TIGHTEN, or WOULD MISS THE CLOCK, and the program rolls up to DRILL-READY, GAPS, or WOULD MISS NOTIFICATION. It grades the process, never people, and never asserts a deadline as the verdict.

Don’t discover the clock
after it’s run out.

One purchase, lifetime access, 12 months of updates. $79, once.

Not legal advice. This is a readiness drill that grades your notification process from your own marks. It is date-agnostic and asserts no deadline; it files nothing, confirms no regulatory obligation, and scores no people. Notification duties (GDPR, the EU AI Act, SEC, HIPAA, and US state breach laws) vary by jurisdiction and change often — confirm which apply to you and every deadline with qualified counsel.

Sold by RedHub AI LLC · Secured by Stripe · redhub.ai