When an AI system fails, misbehaves, or is questioned by regulators — a practitioner’s playbook for detection, response, disclosure, and post-incident learning.
Who this is for
- Incident response and crisis management leads
- Compliance and legal functions
- Product and engineering leads for critical AI systems
- Communications and regulatory affairs
What you will be able to do
- Define what counts as an AI incident, at appropriate severity thresholds
- Detect incidents through monitoring, complaint, and audit signals
- Contain, investigate, and remediate an incident with the right cross-functional team
- Manage regulatory notification obligations (including the Article 73 serious-incident regime)
- Communicate an incident to affected users and the public without making things worse
- Run a post-incident review that produces actual learning
Syllabus
Each module comprises a mix of structured reading, worked examples, and applied exercises. Every programme concludes with an integrated written assessment marked against the published rubric.
Module 1. What is an AI incident
Definitions across regimes (EU AI Act, sector frameworks, ISO). Severity classification. Distinguishing incidents from ordinary performance issues.
Module 2. Detection
Monitoring architectures. Complaint channels. External sources. When automated detection is enough and when it is not.
Module 3. The response operating model
Roles: incident commander, technical lead, legal, communications. Playbook design. Runbooks.
Module 4. Investigation and containment
Preserving evidence. Root cause analysis for AI failures. When to pause the system.
Module 5. Notification and disclosure
Regulatory notification obligations across regimes. Article 73 in practice. Customer and public communications.
Module 6. Remediation and reinstatement
Fixing the immediate cause. Fixing the systemic cause. Getting the system back into production safely.
Module 7. Learning
Post-incident review that changes behaviour. Feeding lessons back into the AIMS.
Assessment
Brief
Simulated incident: an AI system has produced a discriminatory outcome, discovered via a customer complaint. Prepare (1) the first-24-hours response plan, (2) the regulatory notification under Article 73, and (3) the seven-day post-incident review outline. 2,000 words total.
Sample question
Your credit-scoring model has produced a scoring pattern that appears to disadvantage a protected group. A journalist is asking questions. Walk through the next 24 hours.
Assessments are marked by a named human examiner against the four-dimension rubric: regulatory accuracy (30%), applied judgement (30%), artefact quality (25%), communication (15%). Pass at 60, distinction at 75.
Prerequisites
Working knowledge of enterprise incident management. EU AI Act Foundations is helpful for the regulatory context.
Certification
On successful completion (pass mark 60), you receive a SAAII Certified Practitioner (CP) — AI Incident Response credential. The credential is CPD-accredited, verifiable at thesaaii.com/verify, and forms one component toward higher-tier credentials. See the certification ladder for how it stacks.
Ready to enrol?
AI Incident Response runs continuously with rolling enrolment. Founding-cohort discount (25%) applies to the first 100 enrolments across the whole programme portfolio.
Cohort licensing available from £395/seat (10+). Public sector, education, and registered charity: 20% discount. Instalment plans available for programmes at £495 and above. See For organisations and the FAQ for detail.