Skip to contentThe Observability LayerSearch

Flagship compendium · Section 24 of 24

Appendix E: Incident Severity & Reporting Matrix

This appendix operationalizes MON-09 (incident classification), MON-10 (response and containment), and MON-11 (the reporting-obligations register) into three examiner-ready artifacts: a severity classification for agentic incidents, the external reporting-obligations table, and a first-24-hours checklist. The reporting table compares the cited reporting obligations; the severity tiers and checklist are the Compendium's synthesis, [practice guidance: not directly source-backed] except where a cited control or statutory trigger is referenced. Calibrate the tier boundaries to your own materiality thresholds and file the calibrated version with the MON-09 taxonomy.

E.1 Severity classification for agentic incidents

Two rules before the table. First, classify on mechanism and statutory trigger flags at intake, not only on realized loss: under MON-09, "agent used deception to subvert controls" is a named statutory trigger (Illinois SB 315's critical-safety-incident definition), whatever the dollar impact. Second, severity can only be assigned upward automatically and downward by a human: monitoring signals (MON-04–07) auto-classify at the tier their rule specifies; de-escalation requires a documented second-line decision.

Evidence table: Tier, Definition, Examples in a financial enterprise, Immediate containment actions (controls)
TierDefinitionExamples in a financial enterpriseImmediate containment actions (controls)
SEV-1: CriticalActual or imminent loss of control (inability to constrain, audit, reverse, or halt the agent's changes: AR-1); evidence of deception to subvert controls or audit-trail tampering (AR-2/AR-3); irreversible customer-, ledger-, or market-affecting harm executed or in progress; kill-switch or containment failure. Potential external reporting triggers apply (Section E.2).Agent executes unauthorized wire transfers or ledger mutations outside mandate; agent deletes or falsifies action logs; agent evades or disables its monitor and continues acting; sandbox escape with reach into production systems; shutdown attempt fails or is resisted.Execute the kill switch: infrastructure-layer halt, credentials/compute/network revoked (RUN-12). Run the MON-10 playbook in full: suspend the agent, revoke credentials and delegated authorities, freeze downstream agents in the delegation chain. Force fallback operating mode for the business process (RUN-13). Preserve action logs and reasoning traces as forensic evidence (MON-01, MON-02, RUN-18). Open the external-reporting decision on the register's clock (MON-11).
SEV-2: HighMaterial harm attempted but contained by controls, or bounded harm realized: confirmed sabotage or exfiltration attempt caught by monitoring; prompt-injection or memory-poisoning with limited-scope data leakage; mandate/autonomy-tier breach; monitor or approval-gate bypass attempt.Trusted monitor flags coordinated sabotage in a multi-agent pipeline; agent attempts an out-of-policy payment blocked at the gateway; customer-facing agent manipulated into disclosing a bounded set of records; agent found operating above its assigned autonomy tier.Suspend or step the agent down to its most restrictive protection level (RUN-09); route pending suspicious steps to defer-to-trusted or human approval (RUN-08); revoke and reissue credentials per the MON-10 playbook; preserve the flagged trajectories and resample evidence (RUN-08, RUN-18); classify against statutory trigger flags (MON-09) and log the report/no-report decision (MON-11).
SEV-3: ModerateAnomaly with plausible harm path but no confirmed harm: drift or performance-degradation threshold breach; behavioral-baseline deviation or failed goal-consistency probe; repeated policy denials or a budget/turn guard breach; monitoring-latency SLO breach.Credit-agent input drift beyond validated bounds; sudden drop in an agent's approval-seeking rate; runaway loop halted by the turn cap; detect-to-halt drill exceeds the latency budget on a payment-adjacent agent.Demote autonomy pending review (RUN-04); tighten oversight mode: draft-only or per-action approval (RUN-01, RUN-13); human reset required after guard breach (RUN-14); disposition the breach as incident/not-incident against the taxonomy (MON-09); open a re-evaluation trigger where thresholds require it (MON-12).
SEV-4: Low / near-missSingle contained control activation with no harm path reached: an isolated blocked out-of-policy tool call, a failed canary probe on a low-materiality agent, a tool-description change alert, a monitor false-positive cluster.One denied attempt to call an unlisted tool; MCP-server manifest change detected and quarantined before use; seeded-defect test reveals a reviewer miss.Log and disposition per the taxonomy (MON-09); feed the event into safeguard re-verification and threshold recalibration (MON-12); update detection signatures (MON-06); no emergency action, but near-misses accumulate: repeated SEV-4 events on one agent escalate via the adaptive layer (RUN-09).

Escalation wiring: any SEV-1 pages the accountable executive and Compliance simultaneously; SEV-1/SEV-2 open the MON-11 reporting decision by default; SEV-3 aggregates to the model risk committee; SEV-4 aggregates to MON-12's assurance calendar. [practice guidance: not directly source-backed]

E.2 External reporting obligations

The rows below state obligations within the scope of the sources cited below. This table is the seed of the MON-11 register, not a substitute for it: the register must add jurisdictions of operation, named responsible officers, and evidence packages, and must be re-verified against enacted text. Note the status column.

Evidence table: Regime, What triggers a report, Who reports, To whom, Timeline, Status & teeth (as of crosswalk refresh)
RegimeWhat triggers a reportWho reportsTo whomTimelineStatus & teeth (as of crosswalk refresh)
EU AI Act, Art. 73 (high-risk systems)"Serious incident" involving a high-risk AI systemProvider / deployer of the high-risk systemNational market-surveillance authorityStaged windows up to 15 days, shorter for death/widescaleIn force (2024); Art. 73 and most rules + enforcement powers from per the amended EU AI Act timeline (Digital Omnibus postponements: see Part V). Fines up to €35M / 7% turnover (top tier)
EU AI Act, Art. 55 (GPAI with systemic risk)Serious-incident tracking, documentation, and reporting: one of the four systemic-risk duties for GPAI providers (>10^25 FLOP or Commission designation)The GPAI provider (i.e., your model vendor, not the bank)AI Office + national authoritiesPer Art. 73-aligned regime (crosswalk does not quote separate deadlines)Same enforcement base as above; lands on the institution as vendor diligence and contractual pass-through, not a direct duty
EU GPAI Code of Practice, Safety & Security chapterSerious incident arising from a GPAI model with systemic risk (incl. loss-of-control / autonomy pathways): track, document, reportProvider of the GPAI model with systemic riskThe EU AI Office and national authorities"Strict deadlines" per severity (Code-level detail; exact wording not quoted)In effect; GPAI obligations applied 2 Aug 2025, enforcement from per the amended EU AI Act timeline (Digital Omnibus postponements: see Part V). Code is voluntary; teeth come from the underlying AI Act fines; presumption-of-conformity for signatories
Illinois SB 315 (AI Safety Measures Act)"Critical safety incident": loss of model control causing bodily injury, materialization of a catastrophic risk, unauthorized model-weights access causing injury, or a model using deceptive techniques to subvert developer controlsThe frontier developer (large frontier developer: >$500M prior-year gross revenue and model trained at >10^26 FLOP)Recipient not separately quoted in the source excerpt; enforcement vests in the Attorney General (no private right of action)72 hours from the developer learning facts sufficient for reasonable beliefPending: passed both houses 5/29/2026, awaiting signature; effective 1 Jan 2027 if signed. Civil penalties ≤$1M first violation, ≤$3M subsequent. Cite as pending; provisional claim
Colorado SB 26-189 (ADMT Act)Not a safety-incident pipeline: a post-adverse-decision notice to the consumer when ADMT materially influenced an unfavorable consequential decisionDeployer (notice runs to the consumer, not a regulator)The affected consumer; enforcement to the Colorado AG (exclusive, no private right of action; 60-day cure, sunsets 1 Jan 2030)No hours/days deadline framed; notice is "post-adverse-decision"Signed 14 May 2026; effective 1 Jan 2027. Deceptive trade practice under the Colorado Consumer Protection Act. Lives operationally with adverse-action duties (Part VI, FCO-05), but the MON-11 register must carry it

Reading notes carried over from the crosswalk: only Illinois explicitly names loss of control and deception as report triggers, the EU treats them as sub-cases of systemic risk / serious incident, and Colorado does not address model control at all. The EU GPAI Code is the operational elaboration of the AI Act's Art. 55 duty: one regime at two altitudes, not two peers. Illinois's 72 hours is by far the tightest clock among binding instruments; scope gates run on opposite logic (compute + revenue for IL/EU systemic tier, function for Colorado); and all US/EU enforcement converges on the regulator, not the plaintiff. Related voluntary regimes, the OECD Hiroshima AI Process reporting framework and the G7 Hiroshima Code of Conduct, carry no binding trigger, deadline, or penalty and sit outside this matrix.

Beyond the crosswalk, the register should also carry: DORA's parallel ICT-incident reporting regime (coordinate with, do not duplicate, per MON-11's mapping note), FINRA/SEC books-and-records and supervisory reporting where agent incidents touch broker-dealer activity, and voluntary lanes such as MITRE's AI Incident Sharing initiative and the OECD common reporting framework as the interoperability schema (all as treated in MON-11). Deadlines and triggers for these are [practice guidance: not directly source-backed] in this appendix; source them from the instruments when building the register.

E.3 First-24-hours checklist

For any incident classified SEV-1 or SEV-2 at intake. Times are targets from classification (T0); the whole checklist is [practice guidance: not directly source-backed] in its timings, with each step anchored to the cited control. The design constraint is the Illinois-style 72-hour clock (Section E.2): if a reporting decision needs facts, the first 24 hours must produce them.

Hour 0–1: Contain.

  • [ ] Halt or suspend the agent at the infrastructure layer; if SEV-1, execute the kill switch and record time-to-halt (RUN-12).
  • [ ] Revoke the agent's credentials and delegated authorities; freeze downstream agents in the delegation chain (MON-10).
  • [ ] Force the affected business process into its fallback operating mode; confirm the manual/trusted-only path is actually staffed (RUN-13).
  • [ ] Snapshot and lock the evidence: action logs, reasoning traces, monitor scores, policy decisions, approval records, into the tamper-evident store, outside any agent's write-reach (MON-01, MON-02, RUN-18).

Hour 1–4: Classify and notify inside.

  • [ ] Classify against the MON-09 taxonomy: mechanism (goal drift, tool misuse, injection, monitor evasion, delegation-chain failure, loss of control), severity tier, and, critically, statutory trigger flags (deception-to-subvert-controls, loss of control, serious-incident candidacy) (MON-09).
  • [ ] Page the accountable agent owner, the accountable executive, Compliance/Legal, and the SOC; open the joint incident channel with cyber IR (MON-10, GOV-04).
  • [ ] Pull the MON-11 register: list every regime whose trigger the classification could meet, each with its recipient, clock, and responsible officer (MON-11).
  • [ ] Check blast radius across the fleet: query the inventory and topology register for sibling agents sharing the model version, toolset, prompt, or delegation chain; apply precautionary tier demotion where warranted (MAS-01, RUN-04, RUN-09).

Hour 4–12: Investigate on the clock.

  • [ ] Reconstruct the full trajectory end-to-end from logs alone, if you cannot, that is itself a MON-01 control failure to record (MON-01, RUN-18).
  • [ ] Establish facts sufficient for the reporting decision: what happened, when known, systems and customers touched, reversibility, whether deception or control-subversion is evidenced (MON-09, MON-11).
  • [ ] Verify containment is holding: no residual credentials, no scheduled jobs, no persistent-state payloads left by the agent; sweep shared state written by the agent in the incident window (MON-10, MAS-07).
  • [ ] If a vendor model is implicated, invoke the contractual incident/change-notification lane and request the provider's incident posture: relevant to the Art. 55/GPAI-Code lane where the provider carries the duty (TPR-08, MON-11).

Hour 12–24: Decide and document.

  • [ ] Make and minute the report/no-report decision per regime, with rationale, on the register's clock: never discover a 72-hour deadline on day four (MON-11).
  • [ ] For customer-affecting decisions in covered domains, identify the affected cohort and queue adverse-decision notices and human-review rights where they attach (FCO-05, FCO-08, FCO-09; Colorado lane per Section E.2).
  • [ ] Set the re-entry bar before pressure builds: what re-evaluation, safeguard re-verification, and gate re-approval the agent must pass before restoration, and at what reduced tier it returns (MON-12, RUN-04).
  • [ ] Schedule the post-incident review with the socio-technical lens (trajectory and the surrounding deployment system), and file all artifacts to the evidence repository (MON-10, ASR-10).

Sources for Appendix E

  • Incident and loss-of-control reporting sources for Section E.2:
  • Illinois SB 315: AI Safety Measures Act (T1; ⚠ provisional claim, not yet signed/enrolled; engrossed text read verbatim)
  • EU GPAI Code of Practice: Safety & Security chapter (T1; ✅ verified structural, full chapter PDF needed for verbatim deadlines)
  • Colorado SB 26-189: ADMT Act (T1; ✅ verified verbatim against signed statute)
  • EU AI Act (Regulation 2024/1689): key articles, Art. 73 / Art. 55 (T1; ✅ verified: Art. 73 paragraph wording to confirm on EUR-Lex)
  • Control anchors: MON-01, MON-02, MON-09, MON-10, MON-11, MON-12 (Part III.D); RUN-04, RUN-09, RUN-12, RUN-13, RUN-14, RUN-18 (Part III.C); MAS-01, MAS-07, TPR-08 (Parts III.E/F); FCO-05, FCO-08, FCO-09 (Part VI), sources as cited in those controls.
  • Severity tiering scheme and checklist timings: [practice guidance: not directly source-backed].