Incident
When an AI system goes wrong in public
Zenatia Insights · July 2026 · 4 min
What it looks like
A chatbot promising a refund that no policy provides, and the screenshot is circulating. A screening model that consistently filters out one profile, and somebody measured it. A data leak through an AI integration nobody had mapped. The common thread: the moment the incident becomes public is no longer yours. What is still yours is the quality of your response.
The first 48 hours
Three moves, in order. Contain: the system is isolated or degraded into a controlled mode, not unplugged in panic. Understand: what the system did, on which data, since when, for how many users. This is where the logs and traceability built before the incident earn their keep. Document: every decision taken is dated and written down, because the account you will be able to give in a month depends on the notes you take today.
What must never be done
Denying what can be demonstrated: the screenshot wins. Patching quietly and hoping nobody asks: if the incident is notifiable, the silence becomes the second fault, graver than the first. And touching the logs: nothing turns a technical incident into a case like records that disappear.
What gets prepared beforehand
A well handled incident is settled before the incident. A register of systems kept current. Accountabilities carried by named people, not by a theoretical committee. A decision channel that works on a Saturday night. And someone who has seen this before, reachable within hours. That is exactly what an incident retainer buys: not panic on demand, preparation in advance.
And for you?
One hour of conversation is enough to place your case. It commits you to nothing, beyond knowing where you stand.
Start the conversation