An AI incident can start aregulatory clock you can’t see.
The deadline is rarely the hard part. Different regimes attach reporting periods to different facts, knowledge standards, or determinations, and the hard part is recognizing and assessing a potential trigger in time, before days burn. Drill it before it’s real.
Not legal advice. This is a readiness drill that grades your notification process from your own marks. It is date-agnostic and asserts no deadline; it files nothing, confirms no regulatory obligation, and scores no people. Notification duties (GDPR, the EU AI Act, SEC, HIPAA, and US state breach laws) vary by jurisdiction and change often — confirm which apply to you and every deadline with qualified counsel.
Update notice — version 1.1.0 (2026-09-23). This package replaces version 1.0 of the AI Incident Reporting & Regulatory Notification Drill. The regime-triage, trigger-assessment and drafting controls are renamed and re-scaled, the text about when a reporting period begins is revised, and the SEC and HIPAA crosswalk rows are rewritten. Scoring is unchanged: the same marks produce the same score and verdict as in version 1.0. Existing buyers: the download link in your original purchase email now serves version 1.1.0.
You knew the deadline. You missed it anyway.
Each regime has its own trigger
Under GDPR Article 33 the period runs from awareness of a personal-data breach. Domestic registrants generally file Item 1.05 Form 8-K within four business days after determining that a cybersecurity incident is material; the determination may not be unreasonably delayed following discovery. For a covered entity, HIPAA discovery occurs when the breach is known or would have been known through reasonable diligence; analyze individual, HHS, media, and business-associate notification paths separately. Record each potential trigger point separately.
One incident, several clocks
The same event can fire a data-breach duty, an AI safety report, and a securities disclosure at once — each with a different deadline and a different start.
No one was authorized to act on it
A plan that routes the decision to a committee that meets next week can miss a reporting period. Someone has to be authorized to assess and document potential trigger points and activate the appropriate escalation path, even at 2am.
Drill a scenario. Read whether your process is ready.
This is the live scoring logic from the engine. The “AI Act serious incident” preset scores 82 and still reads WOULD MISS THE CLOCK — because no one is authorized to assess potential trigger points and escalate. Give it an authorized decision-maker and it clears.
Defined, rehearsed path; awareness time recorded
Potentially applicable regimes are mapped to their scope, triggers, recipients, required content, timing, exceptions, and responsible owners, with legal review where appropriate.
No one authorized to assess and document potential awareness, discovery, materiality, or other applicable trigger points and to activate the appropriate escalation path
Authorities, portals, channels mapped in advance
Templates and internal records are maintained, and any staged-reporting path is documented for the regimes that permit or require it.
Rehearsed cross-functional parallel-track process
Trigger-assessment gate fired: no one is authorized to assess and document potential trigger points and activate the appropriate escalation path. The score alone would read NOTIFIABLE-READY AS DESCRIBED, but a potential trigger nobody assesses can consume time a reporting period allows.
Drill first: A named, authorized decision-maker for trigger assessment and escalation
Weighted to 100. The gate forces WOULD MISS THE CLOCK when you could not recognize and assess a potential trigger in time (⚡ detection or triage) or no one is authorized to assess potential trigger points and escalate (⚡ authority). Date-agnostic — it grades your process, never a specific deadline. Not legal advice.


How the gate works, in one image
How the AI Incident Reporting & Regulatory-Notification Drill scores notification readiness and reads WOULD MISS THE CLOCK when the authorized decision-maker is missing — the same math the demo runs, as a diagram you can share or embed anywhere.
View & embed the full diagramThe same verdicts, from the runnable engine.
Verbatim output from the included Python engine on the six-scenario sample. The workbook reproduces these byte-for-byte.
========================================================================== AI INCIDENT REPORTING & REGULATORY-NOTIFICATION DRILL ========================================================================== Customer PII leak via AI chatbot verdict: NOTIFIABLE-READY AS DESCRIBED (score 94/100) Model failure harms a user (AI Act serious incident) verdict: WOULD MISS THE CLOCK (score 82/100) gate: WOULD MISS THE CLOCK — no one is authorized to assess and document potential trigger points and activate the appropriate escalation path drill first: A named, authorized decision-maker for trigger assessment and escalation Same incident after naming an on-call authorized decision-maker verdict: NOTIFIABLE-READY AS DESCRIBED (score 100/100) Material cyber incident in a public-co AI system verdict: TIGHTEN (score 50/100) drill first: Detection-to-awareness path Vendor/sub-processor breach reaches your data verdict: WOULD MISS THE CLOCK (score 50/100) gate: WOULD MISS THE CLOCK — you could not recognize and assess a potential trigger in time drill first: Regime, trigger, and severity triage Prompt-injection exfiltrates regulated records verdict: WOULD MISS THE CLOCK (score 56/100) gate: WOULD MISS THE CLOCK — you could not recognize and assess a potential trigger in time drill first: Detection-to-awareness path -------------------------------------------------------------------------- PROGRAM: WOULD MISS NOTIFICATION (3 of 6 would miss the clock · exposure 50.0%) -------------------------------------------------------------------------- Grades your notification PROCESS against the clock, never a specific deadline — so it does not break when a regime's dates shift. It grades a process, never people, and confirms no actual regulatory obligation. A readiness drill, not legal advice. Confirm which regimes apply, and every deadline, with counsel.
The AI Act scenario above is a hypothetical future-state rehearsal. Under the Digital Omnibus, the Annex III high-risk obligations apply from 2 December 2027, and serious-incident reporting falls primarily on providers; a deployer’s information duties, and any circumstances in which Article 73 applies to a deployer, should be mapped separately. Confirm system classification, your operator role, territorial scope and the applicable date before relying on any scenario here.
Six controls, weighted to 100. The weakest trigger-assessment control is dispositive.
⚡ Detection-to-awareness path
Regimes use different triggering events and knowledge standards. Record detection, discovery, awareness, escalation, and any required legal determination separately; confirm the applicable start point, decision-maker, recipient, and deadline with counsel. Here “awareness” is operational shorthand rather than a universal legal trigger.
⚡ Regime, trigger, and severity triage
Which regimes may apply, what event or determination starts each reporting period, and which potentially applicable period is shortest? For rehearsal purposes, use the shortest potentially applicable period as the initial internal triage target. Each regime retains its own scope, trigger, recipient, required content, timing, and exceptions; satisfying one does not satisfy the others.
⚡ A named, authorized decision-maker for trigger assessment and escalation
Someone authorized to assess and document potential awareness, discovery, materiality, or other applicable trigger points and to activate the appropriate escalation path, at any hour — not a committee that meets Monday.
Regulator contact map & filing channel
Authorities, a lead supervisory authority where one applies, portals, and channels mapped before the incident, not during it.
Notification drafting and incident-record path
Pre-drafted templates, a maintained internal incident record, and — where the applicable regime permits or requires staged reporting — an initial report that can be supplemented as additional information becomes available. GDPR Article 33(4), for example, permits information to be provided in phases when it cannot be provided at the same time.
Cross-track coordination
One incident can trigger several potentially applicable reporting periods at once — legal, security, comms, privacy pre-aligned.
⚡ = a trigger-assessment gate control. If detection-to-awareness or severity triage is absent, or no one is authorized to assess potential trigger points and escalate, the scenario is WOULD MISS THE CLOCK regardless of score. The gate worsens only — it never promotes a verdict.
A readiness drill, not a compliance ruling.
It is
- A rehearsal of your incident-notification process.
- Date-agnostic — it grades the process, never a deadline.
- A deterministic, offline engine + workbook you control.
It isn’t
- Legal advice, a filing service, or a certification.
- A ruling on whether an incident is legally reportable.
- A score of people — it grades a process.
Not legal advice. This is a readiness drill that grades your notification process from your own marks. It is date-agnostic and asserts no deadline; it files nothing, confirms no regulatory obligation, and scores no people. Notification duties (GDPR, the EU AI Act, SEC, HIPAA, and US state breach laws) vary by jurisdiction and change often — confirm which apply to you and every deadline with qualified counsel.
Whoever owns the first hour of an AI incident.
- Security, privacy, and compliance leads who own incident response.
- Legal and DPO functions tracking GDPR, AI Act, SEC, HIPAA, and state clocks.
- Teams deploying high-risk or customer-facing AI that could cause a reportable incident.
- Not a filing tool — it rehearses readiness, it doesn’t notify anyone.
- Not a ruling on what’s reportable — confirm that with counsel.
- Not a postmortem tool — that’s the close-out gate it pairs with.
Detect and notify, then recover and close out.
Ransomware & AI-Outage Recovery Readiness Drill
Would you actually recover? The recovery-side drill to this notification-side one.
ViewAI Incident Postmortem & Readiness Gate
Close the loop after: grade the blameless writeup and gate the close.
ViewNIST AI RMF / US AI Governance Readiness Kit
The governance program this incident drill lives inside.
ViewAnswers before you buy.
It grades whether your notification process is ready for the reporting periods an AI incident could trigger — scenario by scenario. For each drilled incident you mark six controls 0/1/2: your detection-to-awareness path, regime, trigger, and severity triage, whether a named person is authorized to assess potential trigger points and escalate, your regulator contact map and filing channel, your notification drafting and incident-record path, and cross-track coordination. The six are weighted to a 0–100 score banded NOTIFIABLE-READY AS DESCRIBED, TIGHTEN, or WOULD MISS THE CLOCK, and the program rolls up to DRILL-READY, GAPS, or WOULD MISS NOTIFICATION. It grades the process, never people, and never asserts a deadline as the verdict.
Because of the trigger-assessment gate, which is the heart of the drill. A scenario is forced to WOULD MISS THE CLOCK regardless of score when either gate-triggering pattern is present: you could not recognize and assess a potential trigger in time (your detection-to-awareness path or your regime, trigger, and severity triage is absent), or no one is authorized to assess and document potential trigger points and activate the appropriate escalation path. The deadline is rarely the hard part — the hard part is that a potentially applicable reporting period can begin at a trigger you may not recognize or assess, so days burn before anyone registers it. Different regimes attach reporting periods to different facts, knowledge standards, or determinations. Record detection, discovery, awareness, escalation, materiality assessment, and other potentially relevant trigger points separately. In the worked example a model-failure scenario scores 82 yet reads WOULD MISS THE CLOCK because no one is authorized to assess potential trigger points and escalate; the next row is the same incident after naming an on-call authorized decision-maker, and it clears at 100. The gate worsens only — it never promotes a verdict.
An AI incident rarely triggers only one reporting period. The same event can trigger a personal-data breach notification (e.g. GDPR Article 33, under which, where required, a controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal-data breach), an AI safety / serious-incident report (e.g. EU AI Act Article 73, which principally imposes serious-incident reporting duties on providers of covered high-risk AI systems, with different periods for specified incident categories), a material-cyber disclosure (e.g. SEC Item 1.05, under which domestic registrants generally file Item 1.05 Form 8-K within four business days after determining that a cybersecurity incident is material; the determination may not be unreasonably delayed following discovery), sector duties like HIPAA breach notification (for a covered entity, HIPAA discovery occurs when the breach is known or would have been known through reasonable diligence; analyze individual, HHS, media, and business-associate notification paths separately), and US state breach laws with their own windows. Potentially applicable regimes may use different triggers, recipients, content, deadlines, and exceptions. For rehearsal only, the drill uses the shortest potentially applicable period as an internal triage target; meeting one regime’s process does not establish that another is satisfied. These specifics are named in the playbooks as planning references — the engine itself is deliberately date-agnostic so it does not break when a regime’s dates shift. Which regimes apply to you, and every deadline, must be confirmed with qualified counsel.
Because the deadlines move, and a tool that hard-codes a date is wrong the moment a regime shifts. The EU AI Act’s high-risk timeline, state breach windows, and sector rules all change. So the drill grades the thing that actually determines whether you hit any clock — your process for recognizing and assessing potential trigger points, escalating, and filing — rather than checking a calendar. That makes the verdict durable, and it keeps the tool honest: it tells you whether you would be ready, not whether a specific statute applies to you. Which regimes apply, and every deadline, must be confirmed with counsel.
No. It is a readiness drill that grades your notification process from your own marks. It files nothing, contacts no regulator, connects to no system, and confirms no actual regulatory obligation — it cannot tell you whether a given incident is legally reportable or to whom. It is not legal advice, a filing service, a certification, or a safe harbor, and it scores a process, never people. Use it to find and close the gaps in your incident-notification readiness, then confirm which regimes apply to you and every applicable deadline with qualified counsel.
A runnable zero-dependency Python engine, a workbook that reproduces it exactly (Start Here, Dashboard, and a Drill Scorecard with the mark definitions built into each column), a six-scenario worked example, and two playbooks: a Drill Facilitator Playbook for running the tabletop and marking honestly, and a Notification-Readiness Runbook that sets the controls beside several regimes as planning references and walks the trigger-assessment, triage, and filing steps. Pick the incident types that matter to you — a data breach, an AI serious incident, a material cyber event — drill each one, and, where a control is short, close the one the tool names first. Deterministic and offline; one-time purchase, lifetime access, 12 months of updates.
Don’t discover the clock
after it’s run out.
One purchase, lifetime access, 12 months of updates. $79, once.
Not legal advice. This is a readiness drill that grades your notification process from your own marks. It is date-agnostic and asserts no deadline; it files nothing, confirms no regulatory obligation, and scores no people. Notification duties (GDPR, the EU AI Act, SEC, HIPAA, and US state breach laws) vary by jurisdiction and change often — confirm which apply to you and every deadline with qualified counsel.
Sold by RedHub AI LLC · Secured by Stripe · redhub.ai