Cross Organization AI Incident Record
Veniwol · Team Lilambd
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
A minimum evidence and handoff protocol for autonomous-agent incidents that cross organisational boundaries. The report defines four clocks, claim-level evidence states, disclosure tiers and a compact handoff record so an affected third party and an originating lab can preserve uncertainty while coordinating containment, attribution and reporting. It is deliberately defensive: no exploit code, live indicators, credentials or reproduction detail are included.
Reviews
I think the most valuable takeaway is the proposal to conduct a tabletop. The most perfectly defined schema to share data is useless if orgs/teams don't use it, and a tabletop is a great way to test that.
This paper tackles a real problem. When an AI agent causes an incident, different organizations each see only part of the picture, at different times, with different evidence. The authors propose a simple shared record that lets each party pass along what it knows without forcing everyone into one story too early.
The design is useful. It tracks four "clocks" (when the event happened, when it was noticed, when an organization learned of it, and when it was disclosed), labels each claim by how well it's supported, and includes clear fields for authorization and tiered disclosure. The authors also don't oversell it as a replacement for forensics, legal processes, or regulatory reporting. The main weakness is that the idea hasn't been tested. The record was designed from public accounts of one incident, then checked against that same incident. That shows it can hold the information, but not that it makes real incident response any better. There's no comparison with other record formats, no live or simulated exercise with multiple organizations, and no measurement of whether it speeds up notification, reduces unsupported assumptions, or gets the right person to act sooner. The authors list these as future work, and a multi-party tabletop exercise would be the most valuable next step. Overall, this is a clear, practical coordination tool, but closer to an operating procedure than a proven new AI safety mechanism. A realistic multi party exercise, a machine readable version, and measured coordination outcomes would make it much stronger.
Read full reviewShow less
Cite this project
@misc{veniwol2026cross,
title = {{Cross Organization AI Incident Record}},
author = {Veniwol},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/cross-organization-ai-incident-record-09md}},
url = {https://apartresearch.com/sprints/projects/cross-organization-ai-incident-record-09md}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …