Skip to main content
Incidents & Monitoring
5 min readUpdated 2026-02-15

Incident Management Overview

How to log, track, and respond to AI-related incidents using Klarvo — covering severity levels, response workflows, Article 26 serious incident reporting obligations, and integration with reassessment.

Incident Management

Under Article 26, deployers of high-risk AI systems must monitor operation, report serious incidents, and be prepared to suspend use when risk is identified. Klarvo's incident management system provides the structure for tracking, responding to, and documenting AI-related incidents.

What Counts as an Incident?

AI incidents requiring documentation include:

  • Safety events: Physical or psychological harm caused by AI outputs
  • Rights violations: Discriminatory outcomes, privacy breaches, unfair denials of service
  • Performance failures: Unexpected outputs, hallucinations, systematic errors
  • Security events: Data leaks, unauthorized access, adversarial attacks
  • Compliance gaps: Discovered non-conformities with the AI Act
  • User complaints: Documented concerns about AI behaviour
  • Severity Levels

    LevelDescriptionResponse TimeEscalation
    CriticalImmediate harm, safety risk, potential prohibited practice< 24 hoursLeadership + legal + authority (if serious)
    HighSignificant rights impact, large-scale effect< 48 hoursCompliance Owner + provider
    MediumModerate impact, contained to limited scope< 1 weekSystem Owner + Compliance Owner
    LowMinor issue, no harm, easily correctable< 2 weeksSystem Owner

    Incident Workflow

    Detection → Logging → Triage → Containment → Investigation → Resolution → Postmortem → Closure
    

    ↓ ↓

    Notification Reassessment

    (internal + external) (if needed)

    Serious Incident Reporting (Article 26(5))

    Deployers must report serious incidents to:

  • The AI system provider — notify immediately
  • Market surveillance authority — within required timeframe
  • A "serious incident" is one that results in:

  • Death or serious damage to health
  • Serious/irreversible disruption of critical infrastructure management
  • Breach of obligations intended to protect fundamental rights
  • Serious damage to property or the environment
  • Integration with System Reassessment

    Incidents can trigger system reassessment:

  • Critical incidents → Automatic reassessment flag on the AI system
  • Pattern of medium incidents → Recommended review of classification
  • Resolved incidents → Documented in system history for audit trail
  • Best Practices

    🚨 Log immediately: Don't wait for investigation to start — capture the facts as they're known
    📞 Notify early: Err on the side of over-communication
    🔍 Root cause analysis: Every resolved incident should identify the underlying cause
    📝 Postmortem: Document lessons learned and preventive measures
    🔄 Update procedures: Improve incident response based on learnings