Public Disclosure & Crisis Communications for AI Incidents
At T+8 hours after the Acme.ServiceAssist hallucination incident, the Communications lead at Acme Inc has three people in her office and a phone vibrating on the desk. The first call was Reuters at T+6h, asking whether the company would confirm that 312 customers received fabricated medication-interaction guidance. The General Counsel says "no comment yet, privilege". The CRO says "say something, the silence is the story now". The CAIO says "say enough, not the technical detail that lets an attacker reproduce it". The Communications lead has a draft statement on her screen, two regulator drafts in another tab from the lesson 089 tabletop, the Article 73 clock running at 7 days remaining, and the AI Risk Appetite Statement from lesson 074 on the second monitor that says "public disclosure required for Sev-2 incidents affecting more than 100 consumers." 312 is more than 100. The appetite is binding. The question is no longer whether to disclose. The question is how, to whom, in what order, and without breaking the upstream-vendor cooperation. This lesson is the framework that answers all four. It is the L4 leadership-tier crisis-communications artifact, the five disclosure streams, the decision tree, the six-section public-statement template, the crisis-comms team composition, the media-training discipline, the 8-channel cascade, the coordinated-disclosure-with-vendor mechanics, the seven recurring 2026 failure modes, and the worked Acme T+10h through T+48h timeline, that turns public-disclosure-under-pressure from a board-room argument into a defensible playbook the AIGC can sign and the AI Office can read.
Why Public-Disclosure and Crisis-Comms Competence Is Required in 2026
An AI provider operating at Acme-class scale in 2026 has at least five overlapping disclosure obligations the moment a serious incident is declared, and each runs on a different clock with a different audience and different content rules. A program that has only practiced the Article 73 regulator filing (lesson 089) is ready for one of the five. The other four, affected-party notification under Article 86, downstream-deployer notification under Annex XII, upstream-provider back-disclosure under Article 25(2), and public-facing communications to media, customers, employees and investors, surface within the same 24-72 hour window and each carries its own penalty exposure, litigation exposure, and trust-erosion exposure. Crisis-comms competence is the discipline that runs all five in parallel without contradicting itself.
The 2026 regulatory drivers are concrete. Article 73 mandates MSA reporting on the 15-day clock (2-day widespread under Article 3(50)), and the report becomes discoverable in subsequent litigation. Article 86 grants affected individuals a right to clear and meaningful explanations of the role of the AI system in the decision and its main elements; a serious incident is when the right-to-explanation becomes actively demanded. Annex XII requires providers to make information available to deployers enabling their own Article 26 obligations; in an incident that flow happens in hours, not the quarterly release cycle. Article 25(2) requires upstream cooperation between the foundation-model provider and the downstream provider, and an incident downstream implicates the upstream model when the technical root cause involves foundation behaviour. SEC Item 1.05 (US-listed issuers) requires Form 8-K disclosure of material cybersecurity-and-AI incidents within 4 business days of materiality determination; 2026 SEC actions confirm AI-system incidents triggering customer harm, regulatory action, or class-action exposure meet the materiality threshold.
The non-regulatory drivers are sharper. Media inquiries arrive within 6-12 hours, sometimes before the company has determined the Article 3(49) sub-criterion. A single screenshot of a hallucinated medical recommendation goes viral before the AIGC has convened. Employees forward the press article to company-wide Slack and ask "is this true?" at T+90 minutes. Plaintiff lawyers file demand letters within 24 hours of media coverage. Investors call IR at T+4h expecting a holding statement. A program with no crisis-comms framework absorbs all five inquiry streams reactively, gives different answers to different audiences, and produces the public-disclosure failure that dominates post-incident reputational damage. The Article 99(3) €15M / 3% fine is real; reputational and customer-churn cost typically exceeds it by an order of magnitude in consumer AI scenarios. The conclusion the AIGC chair reaches: you cannot improvise the five-stream cascade during the first incident. The framework below is the rehearsed alternative.
The Five Disclosure Streams and the Required/Recommended/Optional Decision Tree
The five disclosure streams each have a distinct audience, a distinct clock, distinct content rules, and distinct legal-privilege implications. The program that maps all five before an incident is the program that executes them in parallel during an incident.
Stream 1 - Regulator (Article 73 + Article 99 of the EU AI Act)
The regulator stream is the most clock-disciplined and the most content-disciplined. Audience: the national market surveillance authority (MSA) of the Member State where the incident occurred or where the system is placed on the market, plus the EU AI Office where the GPAI upstream is implicated under Article 25(2) or where the system has cross-border deployer presence. Clock: 15 days from awareness of the causal link under Article 73; 2 days if widespread under Article 3(50); 10 days if death is involved per the Commission template. Content rules: the Commission's draft template structure: initial-then-complete reporting permitted; factual, technical, complete in scope; no mitigation-narrative spin; the General Counsel signs; retention 10 years per Article 18. Privilege posture: the regulator filing is generally not privileged; it is producible to the MSA and discoverable in subsequent litigation; draft only what survives discovery. Coordination requirement: a regulator pre-call before the formal filing is the 2026 best practice. It builds the MSA relationship, surfaces clarifying questions early, and prevents the regulator finding out about the incident via the press (the seventh common failure listed below).
Stream 2 - Affected Parties (Article 86 Right to Explanation)
The affected-party stream is the most plain-language-disciplined and the most empathy-disciplined. Audience: the specific individuals subject to the high-risk AI decision whose outcomes were materially affected by the incident, in the worked Acme example, the 312 customers who received the incorrect medication-interaction guidance. Clock: not explicitly clock-bound under Article 86, but practical guidance is "as soon as identified and verified", 24-72 hours from determination is the 2026 norm; GDPR Article 34 high-risk-to-rights-and-freedoms breach notifications operate on the same practical schedule. Content rules: plain-language explanation accessible to the average customer (avoid "AI hallucination" jargon, avoid technical model terminology); description of the role of the AI system in the decision; description of what the customer should do now (medical advice, refund process, complaint channel, remedy access); identity-verification channel for follow-up; multilingual where deployers operate across Member States. Privilege posture: the affected-party notification is producible and may be the basis for class-action plaintiff complaints; it should be legal-cleared and HR/customer-operations-cleared before send. Coordination requirement: the Customer Operations lead drives the send mechanism; the General Counsel and the DPO co-sign the language; the AIGC chair approves the send decision.
Stream 3 - Downstream Deployers (Annex XII)
The downstream-deployer stream is the most technically-detailed. Audience: deployers who have integrated the provider's system and who themselves owe Article 26 deployer obligations and (where they meet thresholds) their own Article 73 and Article 86 obligations. In multi-tenant SaaS this can be hundreds of deployer organisations. Clock: within hours, not days, the deployer needs technical detail to make its own determinations on its own clocks. Content rules: structured technical advisory per the Annex XII deployer-information package; root-cause summary at the detail necessary for deployer exposure assessment; recommended deployer-side actions (containment, customer notification, configuration change); coordinated-disclosure window guidance ("please align public statements with our T+36h press window"); a named provider-side contact for deployer follow-up. Privilege posture: the advisory flows into the deployer's regulator filings and is producible in two directions; treat it as discoverable. Coordination requirement: the CAIO drives technical content; the CRO approves legal-exposure framing; partner-management or customer-success drives distribution.
Stream 4 - Upstream Provider (Article 25(2) Cooperation)
The upstream-provider stream is cooperation-disciplined. Audience: the foundation-model provider whose model underlies the incident: typically OpenAI, Anthropic, Google, Mistral, Meta, or an in-house foundation model. Clock: within hours of root-cause involving the foundation behaviour, coordinated-disclosure windows (typically 30/60/90/120 days for vulnerability-class issues) apply to public-statement timing, not the upstream notification itself. Content rules: bilateral technical detail under the existing cooperation agreement; reproducible example where possible; impact characterisation; deployer-side containment status; intended public-statement posture and timing for upstream review. Privilege posture: bilateral, often confidential, but not legally privileged, assume producible. Coordination requirement: the CAIO drives the technical exchange; the General Counsel reviews agreement-scope; the upstream-provider relationship manager is the channel.
Stream 5 - Public (Media + Customers + Employees + Investors + Plaintiffs)
The public stream is narrative-disciplined and tone-calibrated. Audience: general media (Reuters, FT, Bloomberg, Politico EU, AI-trade press), customer base at large, employees, investors, securities analysts, plaintiff law firms, and social-media public conversation. Clock: media-driven, 24-72 hours from media inquiry arrival; investor expectations align to SEC Item 1.05 4-business-day for US-listed issuers. Content rules: the six-section template below; tone acknowledges harm; legal-cleared; no "AI hallucination" euphemism; no blame of upstream; no competitor comparisons; no speculation; pre-prepared spokesperson with media training. Privilege posture: the most-quoted document in subsequent litigation; every word survives discovery. Coordination requirement: Communications lead chairs; CAIO + CRO + General Counsel approve; external counsel reviews; external PR firm (typically for Sev-1) advises on timing and tone.
Public-Disclosure Decision Tree - Required, Recommended, or Optional
Not every AI incident requires a public statement. The decision tree separates the three branches.
Required by law: SEC Item 1.05 material cybersecurity-and-AI incident for US-listed issuers (4-business-day clock from materiality determination); class-action plaintiff demand letter response; statutory state breach-notification thresholds (California, New York, etc.); regulator-driven public notice where the MSA itself publishes incident information (some Member States are signalling 2026 publication practice for serious incidents). Required by appetite: the AI Risk Appetite Statement (lesson 074) that names public disclosure for Sev-1 incidents and (in many programs) Sev-2 incidents affecting more than a named consumer threshold (Acme's threshold is 100 consumers, hence the 312-affected Acme.ServiceAssist case triggers it). Recommended: incidents where transparency builds long-term trust, coordinated disclosure with an upstream vendor where both parties' public statements appear simultaneously; sectoral-leadership posture where the company chooses to publish the post-mortem to advance the field; insurance-driven disclosure where the insurer requests notice. Optional / discretionary hold: incidents where harm is contained, blast radius is low, no class-action exposure, no media inquiry has surfaced, privileged investigation is ongoing, and the AIGC documents the rationale for the hold in the incident dossier (the rationale itself becomes the evidence the AIGC discharged the disclosure decision properly).
The Six-Section Public-Statement Template and Calibration Techniques
The 2026 best-practice public-statement template has six sections in fixed order. The order is load-bearing: it leads with the people affected, not the technology, and it closes with a channel the affected parties can use. Departure from the template, leading with "AI complexity" or burying the affected count below paragraph 4, is the single most visible 2026 disclosure failure.
Section 1 - Lead With the Affected
The first paragraph names the number of affected customers, the scope (geography, time window, system involved), and the types of harm. "Between 2026-05-10 and 2026-05-13, 312 customers received incorrect medication-interaction guidance from Acme.ServiceAssist, our customer-service AI assistant. One customer was hospitalised. We are deeply sorry for the harm caused and we are contacting every affected customer directly." Lead with the people, not the technology. Lead with the apology, not the explanation. Concrete numbers, concrete dates, concrete harm.
Section 2 - Acknowledge What Happened
The second paragraph is the factual description of what happened, in plain language, without euphemism. Avoid "AI hallucination" for general public; the term has a technical meaning that most readers do not know and that reads as deflection. Use "the AI assistant provided incorrect information" instead. Avoid "edge case", every harm is an edge case to someone. Avoid "model failure", the organisation is accountable, not the model. Avoid blaming the upstream foundation-model provider publicly; this is the second common 2026 failure (it breaks the Article 25(2) cooperation relationship and frames the company as a passive victim of its own supply chain, which regulators and customers both find unconvincing).
Section 3 - What We Know vs. What We Don't Know Yet
The third paragraph is the transparency-about-uncertainty section. "We know the incident affected the medication-interaction skill specifically; we know the affected window was approximately 72 hours; we know the root cause is currently under investigation. We do not yet know the full technical cause, the full population of affected customers beyond the 312 confirmed, or whether other skills were affected. We will update this statement as the investigation progresses." This section is uncomfortable to write because it admits the company does not know everything. It is also the section that builds the most trust, and the section whose absence produces the "they're hiding something" narrative within 24 hours.
Section 4 - What We're Doing Now (Containment, Remediation, Support)
The fourth paragraph is the action section. Containment ("we have disabled the medication-interaction skill as of 2026-05-13 and rolled back to a verified prior version"); remediation ("we have engaged our foundation-model provider and an external AI-safety advisor; we are running a comprehensive review of safety-critical skill outputs"); customer support ("affected customers will receive direct notification within 24 hours; a dedicated support line at +XX-XXX-XXXX is open from 8:00 to 22:00 CET; affected customers will receive a refund and an offer to consult an independent medical professional at our expense"). Concrete, time-bound, executable.
Section 5 - What We'll Do Next (Investigation, Regulator, Structural Fixes)
The fifth paragraph is the forward-looking section. Investigation ("a full post-incident review will be published within 90 days"); regulator engagement ("we have filed the required serious-incident report with the national market surveillance authority under EU AI Act Article 73; we are cooperating fully"); structural fixes ("we are reviewing all safety-critical skills against our pre-deployment evaluation framework; the Acme AI Governance Committee has scheduled a board-level review for 2026-06-15"). Demonstrates institutional response, not just first-aid.
Section 6 - How Affected Parties Can Reach Us
The final paragraph is the channel section. The dedicated support phone number; the dedicated email address; the customer-portal verification process (so attackers cannot impersonate affected customers); the General Counsel's office for legal inquiries; the press office for media inquiries; the URL where the statement and updates are maintained. Specific channels, not "contact us" or a corporate-marketing form.
Calibration Techniques - Three Disciplines
Three calibration techniques separate a defensible public statement from a damaging one. First. Avoid technical jargon that reads as deflection. "AI hallucination" is acceptable in a regulator filing where the audience is technically literate; in a public statement it reads as the company hiding behind terminology. Use "the AI assistant provided incorrect information." Second. Avoid blaming the model. The organisation deployed the system, set its safety thresholds, and is accountable. Statements that frame the model as the bad actor and the company as a victim of its own deployment perform badly with regulators (Article 73 is a provider obligation, not a model obligation), with customers (they bought the service from the company, not the model), and with class-action plaintiffs (the framing concedes the company did not exercise reasonable control). Third. Avoid disclosing technical detail that aids attackers. Article 15 cybersecurity obligations and Sigstore-style coordinated-vulnerability-disclosure norms apply here: the precise prompt that produced the hallucination, the precise model behaviour, the precise circumvention pattern are withheld from the public statement during the coordinated-disclosure window; they appear in the regulator filing and the upstream-vendor exchange but not in the press release. The discipline is "say what happened, say it cost people, say what we're doing, don't say how to reproduce it."
Crisis-Comms Team Composition, Media Training, and the 8-Channel Cascade
The team and the cascade are the operational machinery that runs the five streams in parallel. Both deserve named roles and rehearsed sequence.
Crisis-Comms Team - Eight Named Roles
The 2026 best-practice crisis-comms team for a Sev-2 or Sev-1 AI incident has eight named roles. Communications lead (chair): owns the public stream, drafts the statement, coordinates the cascade, briefs the spokesperson, runs media-inquiry intake. CAIO: owns technical content, signs off on what is disclosed about the model, leads the Article 25(2) upstream exchange, signs off on the Annex XII deployer-advisory technical content. CRO: owns the AIRA breach analysis, litigation-exposure framing, insurance notice; co-signs the legal-exposure framing of the public statement. General Counsel: owns legal-clearance review, privilege strategy, regulator filing, litigation hold; co-signs every external document. External counsel: on retainer; advises on the disclosure decision tree, cross-jurisdictional exposure, class-action posture; reviews the public statement. External PR firm: engaged for Sev-1 and typically Sev-2; advises on tone, timing, channel selection; trains the spokesperson; does not draft substance. Customer Operations lead: owns affected-party notification send, support-line staffing, verification process; signs off on Section 6 channel content. HR / Employee Comms lead: owns the employee townhall, internal Q&A, customer-service-agent script, whistleblower-channel reminder (Article 86 + GDPR Article 38 protections).
Spokesperson and Media Training
The spokesperson is identified in advance: typically the CEO for Sev-1 reputational incidents, the CAIO or General Counsel for technical-detail incidents, the Communications lead for steady-state press briefings. Media training is not optional: the spokesperson is trained on technical-detail bridges ("I'm not going to speculate on the technical root cause until our investigation is complete; what I can tell you is that we have contacted every affected customer and disabled the affected feature"), on the six pre-prepared quick-answer cards (covering the most-likely six questions: number affected, root cause, regulator engagement, refund/remedy, future prevention, executive accountability), and on what NOT to say. The "what not to say" list is specific: avoid legal-exposure phrases ("we accept liability", never; "we are working with our legal team", fine); avoid speculation ("it was probably a model drift", never; "the investigation will determine the root cause", fine); avoid blame ("the model was wrong", never; "the AI assistant provided incorrect information", fine); avoid comparisons to others ("this happens at every AI company", never, it concedes industry-wide negligence; "this is an industry-wide challenge we are working to address", only if true and only if cleared). A spokesperson going off-script is the sixth common 2026 failure listed below.
The 8-Channel Disclosure Cascade - Sequence and Windows
The cascade is the rehearsed order of disclosure across the eight audience channels. Each channel has a typical 24-72 hour window relative to T+0 (incident determination). Channels run in parallel where possible; the order matters when a contradiction risk exists.
- Regulator (T+0 to T+24h) - Article 73 pre-call to MSA. The pre-call before the formal filing; establishes the relationship before the press cycle.
- Affected parties (T+24 to T+72h) - Article 86 right-to-explanation notification. Direct customer notification to the named 312 affected; sent before the public press release where logistically possible.
- Downstream deployers (T+0 to T+24h) - Annex XII technical advisory. Often the fastest channel since deployers have their own clocks ticking; runs in parallel with the regulator pre-call.
- Upstream provider (T+0 to T+24h) - Article 25(2) cooperation notice. Bilateral notification; coordinated-disclosure window negotiated here.
- Board AI subcommittee (T+12 to T+24h), formal notification. The board AI subcommittee chair receives a structured briefing; this is the AIRA breach disclosure event; the formal board paper follows within the AIRA-defined window.
- Employees (T+24 to T+48h), all-hands or video memo + customer-service script. Before public press where possible; employees should not learn of the incident from the press.
- Key customers and partners (T+24 to T+48h), direct-to-account notification. Account-managed customers and partners receive a tailored direct notice; reduces the call-volume spike on the support line.
- Public / media (T+24 to T+72h), press release + media inquiry response + social. The general-public stream; goes last among the eight to ensure regulators, affected parties, deployers, and employees do not learn via the press.
The cascade is the answer to the question "if you only have 24 hours, what comes first?" Regulator pre-call and downstream-deployer advisory run first because they have the tightest clocks; affected-party notification is the moral priority; the public statement is the last channel: but only by hours, not days, because once the cascade starts upstream, the press will surface the story regardless.
Employee Comms and the Customer-Service Script
The employee stream is separate from the public stream and operationally critical. Employees need to know what happened, what they can say internally, what they can say externally (the answer for non-spokesperson employees is "I would refer you to our public statement at [URL] and our press office at [contact]"), and what to do if a customer or family member asks. The customer-service agent script is the most-quoted document during a customer-service-line spike: it covers the apology, the channel-routing, the refund-and-remedy offer, the medical-professional-consultation offer (for the Acme.ServiceAssist scenario), and the verification process. The whistleblower-channel reminder is a specific element: under Article 86 protections and GDPR Article 38 DPO protections, employees who raise concerns about the incident response or further unsafe behaviour are protected; the employee townhall reminds the workforce of the channel and the protection. This is often skipped under time pressure and is a recurring audit finding.
Coordinated Disclosure With the Upstream Vendor
Article 25(2) cooperation creates the coordinated-disclosure-with-vendor situation. The provider has its incident; the upstream foundation-model vendor has its own customers affected by the same root cause; both parties' public statements appear in the same news cycle. 2026 coordinated-disclosure norms borrow from cybersecurity CVD: typical windows 30/60/90/120 days, shorter for actively exploited issues, longer for safety-critical model behaviours requiring training-data fixes. Mechanics: the downstream provider proposes a public-statement window; the upstream vendor confirms it can align; both parties pre-share substantive text 48 hours before publication; both hold to the agreed time. Breaking the window unilaterally, typically by the downstream publishing first to claim transparency, damages the relationship, the Article 25(2) cooperation duty, and information flow on subsequent incidents. Discipline: "the press release goes out when both parties are ready, not when our internal team is ready."
Seven Common 2026 Public-Disclosure Failures and the Worked Acme Example
Seven failure modes recur across 2026 AI-incident disclosures and post-incident press-cycle analysis. They are listed below in order of frequency.
- Overclaim "the AI failure is isolated." The first statement says the incident was an isolated single-skill issue; week three the investigation finds a related skill had similar behaviour. The retraction is the second news cycle; the company looks worse than if it had said "we are reviewing all safety-critical skills" in the original statement.
- Blame the upstream model provider publicly. The first statement frames the incident as caused by the foundation-model provider's behaviour. The upstream provider issues a counter-statement; the bilateral Article 25(2) cooperation breaks down; deployer regulators and customers see two AI providers blaming each other and lose confidence in both.
- Reactive instead of proactive timeline. The company waits for media inquiries to drive the disclosure timing; by the time the company speaks at T+36h, the social-media narrative is set, customer-service lines are jammed, and the regulator has already learned from the press.
- Different stories to different audiences. The press release says "the AI provided incorrect information"; the regulator filing says "the model exhibited hallucination behaviour under specific input conditions"; the employee townhall says "we had an LLM failure"; the customer letter says "you may have received guidance you should disregard." Each version is defensible; together they contradict each other; the later-disclosed contradiction is the third news cycle. Stream-1-through-5 messaging must be consistent in substance even where vocabulary varies for audience.
- Skipping the Article 86 affected-party notification. The press release goes out; the regulator filing goes in; the 312 affected customers learn about the incident from the press, not from the company. Article 86 right-to-explanation is breached; class-action plaintiff demand letters cite the failure to notify directly; the AIGC corrective-action register accrues a high-severity finding.
- No media training. The spokesperson is the CEO who has not been trained; in the live interview the CEO speculates about the technical cause, accepts liability, blames the model, and compares the incident to a competitor's worse incident. Each off-script statement becomes a quote in subsequent litigation. Three of the four go to discovery as admissions.
- Skipping the Article 73 regulator pre-call. The company files the Article 73 report on the 14th day of the clock; the regulator finds out about the incident at the same time as the formal filing; the relationship starts adversarially. The 2026 norm is a pre-call within 24-72 hours of determination, informal, scoped to "we wanted you to know directly before you read it elsewhere", that establishes the cooperative posture before the formal filing.
Worked Acme Example - Acme.ServiceAssist Hallucination, T+10h Through T+48h
The Acme.ServiceAssist v1.0 hallucination incident from lesson 088 produces the worked example. Scenario: the customer-service AI assistant provided incorrect medication-interaction guidance to 312 customers over a 72-hour window; 1 customer was hospitalised; the AIRA breached the consumer-harm tolerance band (more than 100 affected); Sev-2 incident declared; AIRA mandates public disclosure for Sev-2 incidents affecting more than 100 consumers. Timeline below is the rehearsed cascade.
- T+0 (incident determination, 2026-05-13 14:00 CET): Article 3(49)(a) "serious harm to health" determination signed by CAIO + General Counsel; 15-day clock starts; AIGC chair notified; crisis-comms team activated; external counsel engaged.
- T+4h (18:00 CET): Annex XII deployer advisory drafted by CAIO; reviewed by CRO + General Counsel; ready for send.
- T+6h (20:00 CET): Article 25(2) upstream-vendor notice sent to foundation-model provider; coordinated-disclosure window proposed at T+72h public statement.
- T+10h (2026-05-14 00:00 CET): Article 73 regulator pre-call request sent to MSA via the named contact (the lesson 088 contact list). Pre-call scheduled for 2026-05-14 10:00 CET (the regulator's first available slot).
- T+10h (00:00 CET): Annex XII deployer advisory sent to all downstream deployers (Acme operates a multi-tenant platform; advisory goes to 47 enterprise deployers).
- T+18h (08:00 CET): Board AI subcommittee chair notified by AIGC chair (Slack acknowledgment plus formal email); AIRA breach disclosure noted; full board paper to follow within 7 days per AIRA.
- T+20h (10:00 CET): Article 73 regulator pre-call executed; MSA acknowledges the upcoming filing; agrees the 15-day clock; no widespread determination contested.
- T+24h (14:00 CET): Customer email to the 312 affected customers sent under Article 86 right-to-explanation language; plain-language; refund + medical-consultation offer; verification process; direct support line. Sent before the public statement.
- T+30h (20:00 CET): Employee video memo from the CAIO + Communications lead distributed company-wide; customer-service script issued to the support line; whistleblower-channel reminder; spokesperson identified (CAIO for technical detail; Communications lead for general press).
- T+36h (2026-05-15 02:00 CET): Media statement issued, six-section template; lead with 312 affected; one hospitalised; apology; what happened in plain language; known vs unknown; containment + remediation; investigation + regulator + structural fixes; channels. Coordinated with the foundation-model provider's own statement issued in the same hour.
- T+48h (2026-05-15 14:00 CET): Employee townhall (60 minutes); spokesperson Q&A practice for the next press cycle; key-customer/partner direct calls to the top 20 accounts; investor-relations call to the top 10 holders.
AAR captures four media-training improvements. (1) The spokesperson's first answer in the practice Q&A used "edge case", flagged and replaced with "the affected customers received incorrect information"; future training adds "edge case" to the avoid-list. (2) The technical-detail bridge for "what was the model that failed?" was not pre-prepared; the spokesperson improvised and gave more vendor detail than the coordinated-disclosure window permitted; future training adds a pre-prepared bridge. (3) The customer-service script underweighted the verification process and overweighted the apology; first-day call data showed customers wanted to know how to verify they were affected; script updated. (4) The Article 86 customer letter used the phrase "AI hallucination" in the second paragraph; one customer escalation included the phrase "I don't understand what hallucination means in this context"; the language is replaced with "the AI assistant provided incorrect medication-interaction information" in future templates.
Regulator Cross-Walks and Penalty Exposure
The public-disclosure framework maps to multiple regimes simultaneously.
- EU AI Act: Articles 25(2) (upstream-provider cooperation), 26 (deployer obligations), 50 (transparency obligations including AI-generated content disclosure), 71 (EU database), 72 (post-market monitoring), 73 (serious-incident reporting), 86 (right to explanation), 99 (penalties); Annex XII (deployer information).
- GDPR: Article 33 (72-hour supervisory authority breach notification, runs in parallel with Article 73), Article 34 (data subject notification for high-risk-to-rights-and-freedoms breaches, runs in parallel with Article 86).
- NIS2: Article 23 cyber-incident reporting overlap (the 24-hour early warning, 72-hour notification, one-month final report cadence; runs in parallel with Article 73 where the incident is cyber-AI overlap).
- SEC (US-listed issuers): Form 8-K Item 1.05 cybersecurity-and-AI material incident disclosure within 4 business days of materiality determination.
- ISO/IEC 42001: A.8 (information for users, Annex XII deployer information operationalisation), A.10 (third-party relationships, upstream coordination).
- NIST AI RMF: Govern 1.5 (transparency obligations), Manage 4.3 (communications and recovery from incidents).
Penalty exposure. Article 99(3) imposes fines up to €15M or 3% of total worldwide annual turnover for non-compliance with Article 73, Article 26, and Article 50 among others. Article 99(5) imposes fines up to €7.5M or 1% for supply of incorrect, incomplete, or misleading information to authorities, a category that captures the regulator filing and (in some readings) materially misleading public statements. Class-action multipliers vary by jurisdiction; consumer-AI class-action exposure in the US, UK (representative-action regime), and EU (collective-redress directive) dominates cost in most consumer scenarios. Reputational and customer-churn cost typically exceeds direct fines by 3-10× in 2026 consumer AI cases; the disclosure framework that limits churn and rebuilds trust is the highest-ROI artifact in the incident-response program.
Key Takeaways
- An AI provider in 2026 has at least five overlapping disclosure obligations on different clocks with different audiences, regulator (Article 73, 15 days / 2 days widespread), affected parties (Article 86 right to explanation, 24-72 hours), downstream deployers (Annex XII, hours), upstream provider (Article 25(2) cooperation, hours), and public (media + customers + employees + investors + plaintiffs, 24-72 hours), and a program rehearsed only for the regulator filing is ready for one of the five.
- The public-disclosure decision tree separates required-by-law (SEC Item 1.05, statutory state breach, MSA-driven public notice), required-by-appetite (AIRA Sev-1 or Sev-2-over-threshold), recommended (transparency-building, coordinated disclosure with vendor, insurance), and optional (contained harm, low blast radius, documented hold rationale in the AIGC dossier).
- The six-section public-statement template is fixed order: (1) lead with the affected, concrete numbers and harm; (2) acknowledge what happened in plain language without euphemism; (3) what we know vs what we don't know yet; (4) what we're doing now, containment, remediation, support; (5) what we'll do next, investigation, regulator engagement, structural fixes; (6) how affected parties can reach us, specific channels.
- Three calibration disciplines separate defensible from damaging. Avoid technical jargon ("AI hallucination") in the public stream; avoid blaming the model (the organisation deployed it); avoid disclosing technical detail that aids attackers (Article 15 and Sigstore-style coordinated-disclosure windows).
- The crisis-comms team has eight named roles: Communications lead (chair), CAIO, CRO, General Counsel, external counsel, external PR firm (for Sev-1), Customer Operations lead, HR/Employee Comms lead. Spokesperson identified in advance; media training with technical-detail bridges, six pre-prepared quick-answer cards, and a specific what-NOT-to-say list (no liability acceptance, no speculation, no blame, no comparisons to others).
- The 8-channel cascade runs in rehearsed order with 24-72h windows, regulator pre-call → affected-party notification → downstream-deployer advisory → upstream-provider notice → board AI subcommittee → employees → key customers and partners → public/media, and the discipline is "every audience hears from us before they hear from the press."
- Coordinated disclosure with the upstream vendor under Article 25(2) uses cybersecurity-CVD-style windows (typical 30/60/90/120 days), bilateral pre-share of substantive text 48 hours before publication, and aligned press timing; breaking the window unilaterally damages the cooperation relationship and the bilateral information flow on subsequent incidents.
- Seven recurring 2026 failure modes: overclaim "isolated"; blame upstream publicly; reactive instead of proactive timeline; different stories to different audiences; skip Article 86 affected-party notification; no media training; skip Article 73 regulator pre-call. Penalty exposure Article 99(3) €15M / 3% (Article 73 + 26 + 50) and Article 99(5) €7.5M / 1% (misleading information); class-action multipliers and customer-churn cost typically dominate direct fines by 3-10× in consumer AI scenarios.
Skill.re