Figure 1. Every framework’s records ascend into the evidence layer that reconstruction reads.
§ 02The asymmetry
The asymmetry.
An institution can contain an incident it cannot explain. It is the explanation an authority asks for, and it is the harder of the two to produce afterwards, because the machinery that ran the system was built to move work forward rather than to record what was known at the moment a decision was taken.
§ 03The requirement in the fifth stage
The requirement in the fifth stage.
Signal, classify, contain, escalate, reconstruct, close. The fifth carries the weight. An incident is explainable only if the evidence needed to reconstruct it existed at the moment of the decision, bound to the policy version then in force. Evidence assembled after the fact reconstructs the institution’s beliefs rather than the system’s behaviour, and the difference is visible to anyone who asks what changed in between.
§ 04Why the evidence layer is not optional
Why the evidence layer is not optional.
AIRP consumes the evidence of every other framework in the registry except MESA, which supplies evidence to nothing. It is the only function that fails visibly and immediately when the evidence is absent, which is why it is the framework that justifies the cost of producing evidence everywhere else.
§ 05Where it applies
Which institutions, and on whose authority.
Any regulated institution
An incident protocol bites wherever an authority can compel an explanation on a deadline — and the specification treats that as a property of jurisdiction rather than of sector. Notification thresholds and timelines vary by jurisdiction and by authority and are NOT stated here; they must be re-verified against the primary sources in force where the institution operates.
§ 06How it has changed
The record of its own revisions.
A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.
Change history
2026-08-30 · entry v1.0 — First registry entry
2026-08-30 · entry v1.0 — Records the reframing of the protocol around reconstruction rather than crisis process
2026-09-15 · entry v2.0 — Specification status moves from `source-treatment` to `deposited` on the deposit of the AI Incident Response Protocol specification, whose concept DOI the entry now carries
2026-09-15 · entry v2.0 — The `missing` limitation recording no incident taxonomy is closed by airp-incident-taxonomy-v1.0.json
Limitations recorded in the registry
Notification timelines and notifiability thresholds vary by jurisdiction and authority. An institution MUST re-verify both against the primary sources in force in its own jurisdiction. This registry states none.
Reconstruction is possible only to the extent that the other frameworks kept their evidence. AIRP cannot compensate for an upstream framework that produced none.
What would show this to be wrong. AIRP is falsified if institutions holding complete upstream BOE records are found no better able to reconstruct an AI incident, to a standard an external authority accepts, than institutions holding conventional application and infrastructure logs. The protocol's distinguishing claim is that decision-time evidence bound to a policy version is what reconstruction requires, and evidence that ordinary logging suffices would collapse the distinction the framework is built on.
§ 07Honest limits
What this does not claim.
Asserted, and jurisdiction-dependent. Notification timelines and the threshold at which an incident becomes notifiable vary by jurisdiction and by authority. This page states none of them. An institution must re-verify both against the primary sources in force where it operates.
Aligned, not endorsed. The taxonomy adopts OECD vocabulary for event class and harm category and references AI Incident Database entries by identifier alone, adopting none of that repository’s vocabulary; neither the OECD nor the Responsible AI Collaborative has reviewed or endorsed either alignment. Shared vocabulary lets an institution’s record be expressed in public terms, which is not the same as making an internal log and a public repository comparable populations.
Scope. Reconstruction is possible only to the extent that the other frameworks kept their evidence. An institution operating this over frameworks that write no records has an escalation procedure, not a reconstruction capability.
§ 08Cite
Citation.
Cite this work. AI Incident Response Protocol (AIRP), version 1.0. 10.5281/zenodo.22285057. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is explain_this_setup and search_knowledge, which do what this page describes rather than describe it again: the first returns how this site's machine layer is actually built, component by component, and the second queries the corpus behind this page and returns matches with the URL each came from. The page states the practice; the tools are the practice.
01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
02 · Ask
“Using Concylium, call explain_this_setup and tell me whether this site actually implements what its machine-accessible-ai-expertise page claims.”
A category page that survives being audited by the reader's own assistant is doing something a brochure cannot.
§ 11Ask an assistantLive, no key
Ask your AI assistant instead.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is search_knowledge, which searches the published corpus this framework was drawn from and returns matches with the canonical URL of each, so a definition can be checked against its source instead of recalled.
01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client and every tool, in its own words; each call is logged by tool, outcome and duration only, never with what you asked.
02 · Ask
“Using Concylium, search the corpus for this framework and return the definitions with the page each came from.”
A framework quoted from memory drifts. One returned with its source does not.
Cookies, the boring kind
No chocolate chips here, sorry. With your OK, a few cookies tell me which pages people read, so I can write more of what helps. Say no and the site works exactly the same, with no tracking cookies and no hard feelings. The fine print lives in the privacy & cookies notice.