FrameworkAI Incident Response Protocol (AIRP)Sheet 56

AIRP (AI Incident Response Protocol).

Containing an incident and explaining it are different capabilities. An AI incident response and reconstruction protocol.

← Defensible AI · How the nine relate

§ 01Status

What this is.

REG-05 · AI Incident Response Protocol (AIRP)™

Position in the architecture · Operational Machinery

Specification · Deposited 6 September 2026. 10.5281/zenodo.22285057, version 1.0, CC BY 4.0. That is the concept DOI and it always resolves to the latest version. The Defensible AI Framework Registry is still at version 1.0 and records this entry as having no deposited specification. Moving it is a substantive change to the entry and waits for the next registry version, so until that is issued the registry and this page disagree, and this page is the current one.

The nine frameworks as one architecture The MESA Framework sits at the top as the diagnostic frame supplying four altitudes. Below it, five bands. The Regulatory Floor holds REG-08, the Sharia AI Compliance Framework, which enters as a second authority source. The Strategic Compass holds REG-07, the AI Governance Operating Model, which grants authority. Operational Machinery holds REG-06, the Five-Gate Deployment Model, as the lifecycle spine, fed from below by REG-02 model risk management, REG-04 vendor risk and REG-05 incident response. The Technical Substrate holds REG-03, data governance, which supplies the residency rule set. Beneath the altitudes sits the Boundary Invariant, an unmarked engineering-family law, carrying the BOE Declaration and REG-09, the Cross-Border Patterns, as its worked instance on the residency class. At the base is the evidence layer. Authority flows down the left side; evidence flows up the right. The nine frameworks as one architecture Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22170112 https://doi.org/10.5281/zenodo.22170112 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/registry THE NINE, AS ONE ARCHITECTURE REG-01 MESA Framework the diagnostic frame. It occupies no altitude AUTHORITY FLOWS DOWN EVIDENCE FLOWS UP ALTITUDE 1 · REGULATORY FLOOR REG-08 Sharia AI Compliance Framework a second binding authority source enters the same machinery as the first ALTITUDE 2 · STRATEGIC COMPASS REG-07 AI Governance Operating Model structure · decision rights · cadence grants the authority exercised below ALTITUDE 3 · OPERATIONAL MACHINERY REG-06 Five-Gate Deployment Model the lifecycle spine. G1 G2 G3 G4 G5 gate entry evidence REG-02 MESA MRM validation and approval REG-04 AVRF third-party AI diligence REG-05 AIRP reads every record below ALTITUDE 4 · TECHNICAL SUBSTRATE REG-03 AI Data Governance Framework supplies the residency rule set the patterns below architect around THE BOUNDARY INVARIANT · UNMARKED · ENGINEERING FAMILY a boundary is a clause the optimizer may not cross, and everything else is optimization BOE Declaration Boundary fixed · Optimizer freed · Evidence REG-09 Cross-Border Patterns worked instance · data residency class EVIDENCE LAYER BOE records · gate records · validations · attestations · reconstruction reports The Defensible AI Framework Registry v1.0 · Nabeel Khan · nabeelkhan.com/frameworks/registry · CC BY 4.0 · DOI 10.5281/zenodo.22170112
Figure 1. Every framework’s records ascend into the evidence layer that reconstruction reads.
§ 02The asymmetry

The asymmetry.

An institution can contain an incident it cannot explain. It is the explanation an authority asks for, and it is the harder of the two to produce afterwards, because the machinery that ran the system was built to move work forward rather than to record what was known at the moment a decision was taken.

§ 03The requirement in the fifth stage

The requirement in the fifth stage.

Signal, classify, contain, escalate, reconstruct, close. The fifth carries the weight. An incident is explainable only if the evidence needed to reconstruct it existed at the moment of the decision, bound to the policy version then in force. Evidence assembled after the fact reconstructs the institution’s beliefs rather than the system’s behaviour, and the difference is visible to anyone who asks what changed in between.

§ 04Why the evidence layer is not optional

Why the evidence layer is not optional.

AIRP consumes the evidence of every other framework in the registry except MESA, which supplies evidence to nothing. It is the only function that fails visibly and immediately when the evidence is absent, which is why it is the framework that justifies the cost of producing evidence everywhere else.

§ 05Where it applies

Which institutions, and on whose authority.

Any regulated institution

An incident protocol bites wherever an authority can compel an explanation on a deadline — and the specification treats that as a property of jurisdiction rather than of sector. Notification thresholds and timelines vary by jurisdiction and by authority and are NOT stated here; they must be re-verified against the primary sources in force where the institution operates.

§ 06How it has changed

The record of its own revisions.

A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.

Change history

  • 2026-08-30 · entry v1.0 — First registry entry
  • 2026-08-30 · entry v1.0 — Records the reframing of the protocol around reconstruction rather than crisis process

Limitations recorded in the registry

These were recorded in the registry entry at version 1.0, before this framework’s specification was deposited on 6 September 2026. Where the specification has since closed one of them, the stated limits further down this page are the current account.

  • Notification timelines and notifiability thresholds vary by jurisdiction and authority. An institution MUST re-verify both against the primary sources in force in its own jurisdiction. This registry states none.
  • No incident taxonomy aligned to the public AI incident repositories, so an institution's incident record cannot be compared to any population outside it.
  • Reconstruction is possible only to the extent that the other frameworks kept their evidence. AIRP cannot compensate for an upstream framework that produced none.

What would show this to be wrong. AIRP is falsified if institutions holding complete upstream BOE records are found no better able to reconstruct an AI incident, to a standard an external authority accepts, than institutions holding conventional application and infrastructure logs. The protocol's distinguishing claim is that decision-time evidence bound to a policy version is what reconstruction requires, and evidence that ordinary logging suffices would collapse the distinction the framework is built on.

§ 07Honest limits

What this does not claim.

Asserted, and jurisdiction-dependent. Notification timelines and the threshold at which an incident becomes notifiable vary by jurisdiction and by authority. This page states none of them. An institution must re-verify both against the primary sources in force where it operates.

Aligned, not endorsed. The taxonomy adopts OECD vocabulary for event class and harm category and references AI Incident Database entries by identifier alone, adopting none of that repository’s vocabulary; neither the OECD nor the Responsible AI Collaborative has reviewed or endorsed either alignment. Shared vocabulary lets an institution’s record be expressed in public terms, which is not the same as making an internal log and a public repository comparable populations.

Scope. Reconstruction is possible only to the extent that the other frameworks kept their evidence. An institution operating this over frameworks that write no records has an escalation procedure, not a reconstruction capability.

§ 08Cite

Citation.

Cite this work. AI Incident Response Protocol (AIRP), version 1.0. 10.5281/zenodo.22285057. This is the concept DOI and it always resolves to the latest version. CC BY 4.0. Registry entry REG-05 in 10.5281/zenodo.22170112 is at version 1.0 and does not yet point at this specification.

§ 09Where this sits

In the practice.

§ 10Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is explain_this_setup and search_knowledge, which do what this page describes rather than describe it again: the first returns how this site's machine layer is actually built, component by component, and the second queries the corpus behind this page and returns matches with the URL each came from. The page states the practice; the tools are the practice.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, call explain_this_setup and tell me whether this site actually implements what its machine-accessible-ai-expertise page claims.”

A category page that survives being audited by the reader's own assistant is doing something a brochure cannot.

Fin · Machine-Accessible Expertise
Point your assistant at the endpoint →