G8 - You May Have 15 Days to Report. Sometimes 2. Who Starts Your Clock?
Serious-incident reporting regimes for AI run on short, tiered clocks. Under pressure, unrehearsed teams burn those days answering questions a runbook should already have settled: who classifies, who drafts, who notifies.
Where this gets hard
- The ‘awareness’ clock is fixed by your own monitoring timestamps — your evidence plane knows before your lawyers do.
- Incident processes exist on paper and have never been run end to end, so the first rehearsal is the real thing.
- Nobody can name the notifying officer without looking it up — and under deadline, that lookup costs a day.
- Front-line overseers see the first credible signal but don't know it starts a statutory countdown.
- Teams delay reporting to ‘get the full picture’, not knowing an initial incomplete report is usually permitted. Perfectionism becomes a violation.
Where to start
- Classify severities in advance and map each to its reporting deadline; ambiguity is what burns the time.
- Name the roles now — incident lead, notifying officer, evidence owner. Names, not job titles.
- Rehearse once a year with a timed simulation, from detection to draft notification, clock running.
- Wire escalation from overseer to incident process, and teach the front line that a credible signal starts the clock.
- Close every incident with a review that changes something: thresholds, training, or the runbook itself.
The companion consulting document on our website includes a severity classification scheme, an incident runbook skeleton and a rehearsal design.
Part of RMAT's 12-part series on AI governance — Governing AI with Evidence. The companion consulting document — detailed checklists, a risk table, a maturity self-assessment and a 90-day action roadmap — is available on our website.