Standard incident response playbooks assume you know what happened. AI incidents often start with ambiguity — a CFO receives a convincing but fabricated wire request, a deepfake of the CEO circulates internally, an AI-generated data breach claim arrives with stolen-looking documents. You don't know if it's real. Meanwhile, time is collapsing.
This framework organizes the first 72 hours into three operational phases. Each phase has a clear priority, a set of decisions that must be made, and a communication cadence. Use it as a reference during the incident — print it, share it with your incident commander, and refer back to it before every board update.
These three incidents illustrate the difference between a well-executed response and a reactive one. The outcomes were shaped in the first hours.
The decisions you make before an incident are the ones that determine how the first 72 hours unfold. Walk through this checklist with your board annually — or whenever there's a material change in your AI threat exposure.
Every AI incident involves multiple stakeholders. The timing of each notification matters — too early without facts risks speculation; too late risks losing control of the narrative and regulatory goodwill.
| STAKEHOLDER | WHEN | WHAT TO SAY | WHO DELIVERS |
|---|---|---|---|
|
Board of Directors
Initial + 48h update
|
0–2 hours | Initial notification: "We are aware of [incident]. Response protocol activated. Full brief in 6 hours." Update: full scope, exposure, actions taken. | CEO or Chair |
|
C-Suite Team
Immediate + hourly sync
|
0–2 hours | Incident commander appointed, working group formed, communication channels established. No speculation in internal comms. | Incident Commander |
|
Regulatory Bodies
Per jurisdiction timeline
|
2–12 hours | Initial notification per regulatory requirements: incident type, initial scope, response measures. Updates as facts emerge — do not wait for full picture. | General Counsel + CISO |
|
External Legal Counsel
Immediately
|
0–2 hours | Incident brief, preservation of evidence instructions, litigation hold assessment. All communications privileged from this point. | General Counsel |
|
Employees
Hour 6–12
|
2–12 hours | Brief factual note: what happened, what they should do if they see related content, how to report. No blame, no speculation. | CEO or designated exec |
|
Media / Public
Holding statement at hour 12
|
2–12 hours | One paragraph: awareness of incident, response activated, no speculation on cause, next update timeline. Full release only after legal clearance. | Communications lead + legal |
|
Customers / Partners
Only if data or service affected
|
12–72 hours | If personal data or service integrity is affected: clear, factual disclosure per data protection regulations. What happened, what data, what's being done, what they should do. | CEO + Customer Success lead |
|
Investors / Analysts
Before public disclosure or at same time
|
12–72 hours | If material impact: formal investor communication per securities regulations. Factual, no speculation. If not material: update on next earnings call, do not proactively contact. | CFO + Investor Relations |
The first 72 hours of an AI incident are not the time to develop your response plan. ThreatAce's Board AI Incident Playbook gives your leadership team a proven, tested framework — and the decision templates to use it under pressure.
ENROLL NOW ThreatAce Board Playbook · Module 03 · Certificate of Completion