From Loss of Containment to Regulatory Inquiry-An Article 91 Information-Request Framework for Frontier AI Incidents
Rosie · Team Tracebound
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
This project develops an **Incident-to-Inquiry Mapping** framework for regulatory response to frontier AI incidents. Using the 2026 OpenAI–Hugging Face incident as a case study, it maps public evidence to legal uncertainties, relevant EU AI Act provisions, and targeted information requests under Article 91. The project also proposes a stepwise escalation pathway from fact-finding to Article 92 evaluation and, where justified, Article 93 mitigation measures.
Reviews
I appreciate the efforts to systematically break an incident down into actionable questions that a regulator could ask. I would like to see more effort put into 'related work,' as I believe there are numerous frameworks for dissecting incidents.
The paper states that it maps each question to a specific provision, and it would benefit from showing more clearly that it does so. Five of the six rows in the table in 4.1 hook onto Article 55(1)(a)–(d), while Article 53 and Annex XI do not appear in the paper at all, so the question of how much of the requested evidence is already required as part of the technical documentation is not asked.
The Code of Practice is listed as a reference but is not really used in the analysis: there is no discussion of the Safety and Security Framework or of the model reports that OpenAI, as a signatory, submits to the AI Office, and Parts C and D of the appendix leave the Commission's reporting template for serious incidents unaddressed. Overall the paper would benefit from a much deeper legal analysis of what is already covered by the Code or by Article 53 anyway.
Some of the controls also seem to restate existing law. C4, the minimisation control, is arguably what the EU principle of proportionality already requires, and C5, together with the claim in 5.3 that the framework "disciplines escalation", describes the sequence the AI Act itself sets out. Article 91 is likewise treated as the default information-gathering step without any discussion of informal requests.
Finally, the method rests on public incident evidence - the stated aim is to show "how the EU AI Office could convert public incident evidence into a proportionate, legally grounded request for information" - but what if there is none? Relying on what providers have chosen to disclose raises the question of why they would, and what the incentives are, which is precisely the gap a regulatory instrument should close. Focusing on that question could make the paper considerably stronger.
Read full reviewShow less
Cite this project
@misc{rosie2026from,
title = {{From Loss of Containment to Regulatory Inquiry-An Article 91 Information-Request Framework for Frontier AI Incidents}},
author = {Rosie},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/from-loss-of-containment-to-regulatory-inquiryan-article-91-informationrequest-framework-for-frontier-ai-incidents-c40t}},
url = {https://apartresearch.com/sprints/projects/from-loss-of-containment-to-regulatory-inquiryan-article-91-informationrequest-framework-for-frontier-ai-incidents-c40t}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …