Skip to main content
v2026.11,858 entries · CC-BY 4.0
NIKOLAI elementN7 · IncidentsProposednikolai-v0.1

Incident reporting deadline and recipient

NIKOLAI editorial proposal (unsourced): Incident reporting deadline and recipient is an if-then rule -- if an Incident meets a source's reportability trigger, then a report is owed to a named recipient (a regulator, agency, or the AI Office) within a specified clock, sometimes with a shorter emergency clock for imminent physical harm. NIKOLAI proposes recording the trigger condition, the clock (in days or hours from the triggering event), the recipient, and any follow-up/final-report obligations as four sub-properties of this rule, since no two sources currently share identical timing.

This is CASRAI's own proposed definition, not a definition any named organisation has agreed to. See what NIKOLAI is and is not.

Source of record

Where this definition comes from

  • Anthropic Advanced AI Framework, p.7

    "Critical Safety Incidents. Require Covered Developers to report Critical Safety Incidents to the designated Agency within 15 days of the Covered Developer discovering the Critical Safety Incident or facts that would lead the Covered Developer to have a reasonable belief that a Critical Safety Incident has occurred. Reports should be shared with relevant federal government agencies and national laboratories. Information shared should be exempt from public records disclosure laws, consistent with existing state law." (fetched and extracted directly with pypdf, 16 Sep 2026, fourth pass; p.7). Note the text says "the designated Agency" (lower-case "designated"), not a capitalised defined term.

    https://www-cdn.anthropic.com/files/4zrzovbb/website/0a58d567024a8b448ff15158ebc3625328dfcc1f.pdf
  • EU GPAI Code of Practice, Safety and Security Chapter, Commitment 9 / Measure 9.3

    Measure 9.3 gives four numbered, harm-typed clocks running from when the Signatory "become[s] aware of the involvement of their model in the incident": critical-infrastructure disruption "not later than two days"; serious cybersecurity breach (incl. weight exfiltration) "not later than five days"; death "not later than 10 days"; serious harm to health, fundamental rights, property or environment "not later than 15 days". Intermediate reports follow "at least every four weeks"; a final report is due "not later than 60 days after the serious incident has been resolved". Recipient: "the AI Office and, as applicable, national competent authorities" (Commitment 9).

    https://ec.europa.eu/newsroom/dae/redirection/document/118119
  • California SB 53, 22757.13(c)

    "within 15 days of discovering the critical safety incident" to OES; "within 24 hours to an authority, including any law enforcement agency or public safety agency with jurisdiction" where there is "an imminent risk of death or serious physical injury" (22757.13(c)).

    https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53

Crosswalk

How named organisations use this concept

Every row below is a shadow mapping. It is CASRAI's own reading of a published document. No lab, evaluator or regulator named here has declared, endorsed, or been consulted on this mapping. That will change only when an organisation files its own Mapping Declaration — see the non-endorsement policy.
OrganisationTheir term, as publishedMatchSource
Anthropic
Anthropic Advanced AI Framework
"Critical Safety Incidents. Require Covered Developers to report Critical Safety Incidents to the designated Agency within 15 days of the Covered Developer discovering the Critical Safety Incident or facts that would lead the Covered Developer to have a reasonable belief that a Critical Safety Incident has occurred. Reports should be shared with relevant federal government agencies and national laboratories. Information shared should be exempt from public records disclosure laws, consistent with existing state law." (verbatim, p.7). Note the text says "the designated Agency" (lower-case "designated"), not a capitalised defined term "Designated Agency" as earlier drafts of this row implied.
This is a legislative proposal, not a binding rule Anthropic has committed itself to as a developer; "the designated Agency" is recipient-TBD language, not a named agency.
close
confidence: high
Anthropic Advanced AI Framework
OpenAI
OpenAI Frontier Governance Framework; OpenAI -- Hugging Face Incident and the Road Ahead
"If an incident is determined to be reportable, we will gather relevant information ... for reporting to appropriate authorities within the required deadlines" (FGF §2.6). Internal 30-minute pause rule referenced alongside it.
"the required deadlines" is not itself quantified in the quoted text -- it references external law rather than stating OpenAI's own clock.
close
confidence: medium
OpenAI Frontier Governance Framework
xAI
xAI Frontier AI Framework, 30 June 2026
"When reportable under applicable laws and regulations, xAI will provide the relevant authorities with a copy of the incident report within the required deadlines" (s.3).
The FAIF26 PDF's own metadata /Title reads "Privileged/Confidential DRAFT working FRAMEWORK DOC"; no xAI statement disambiguating draft vs. final status was found (open-VERIFY register item 4). Also note: like the OpenAI row, this defers to external law rather than stating xAI's own clock.
close
confidence: medium
xAI Frontier AI Framework, 30 June 2026
Meta
Meta Advanced AI Scaling Framework v2
"reporting critical incidents as appropriate" (§2.3.2).none
confidence: medium
Meta Advanced AI Scaling Framework v2
EU
EU GPAI Code of Practice, Safety and Security Chapter
Measure 9.3 gives four numbered, harm-typed clocks running from when the Signatory "become[s] aware of the involvement of their model in the incident": critical-infrastructure disruption "not later than two days"; serious cybersecurity breach (incl. weight exfiltration) "not later than five days"; death "not later than 10 days"; serious harm to health, fundamental rights, property or environment "not later than 15 days". Intermediate reports follow "at least every four weeks"; a final report is due "not later than 60 days after the serious incident has been resolved". Recipient: "the AI Office and, as applicable, national competent authorities" (Commitment 9).exact
confidence: high
EU GPAI Code of Practice, Safety and Security Chapter
California SB 53
California SB 53
"within 15 days of discovering the critical safety incident" to OES; "within 24 hours to an authority, including any law enforcement agency or public safety agency with jurisdiction" where there is "an imminent risk of death or serious physical injury" (22757.13(c)).exact
confidence: high
California SB 53
Frontier Model Forum
Frontier Model Forum -- Information Sharing Issue Brief
"Incident reporting: a formal notification submitted to a designated government body or authority that a qualifying AI safety or security incident has occurred." Warns against "reporting timelines that assume root-cause analysis is already done" (para.).close
confidence: medium
Frontier Model Forum -- Information Sharing Issue Brief
New York (RAISE Act, S8828)
NY RAISE Act
New York S8828: reports to a DFS office "within 72 hours" (para.).exact
confidence: medium
NY RAISE Act (S8828)

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →