What this is.
Position in the architecture · Operational Machinery
Specification · Deposited 6 September 2026. 10.5281/zenodo.22285057, version 1.0, CC BY 4.0. That is the concept DOI and it always resolves to the latest version. The Defensible AI Framework Registry is still at version 1.0 and records this entry as having no deposited specification. Moving it is a substantive change to the entry and waits for the next registry version, so until that is issued the registry and this page disagree, and this page is the current one.
The asymmetry.
An institution can contain an incident it cannot explain. It is the explanation an authority asks for, and it is the harder of the two to produce afterwards, because the machinery that ran the system was built to move work forward rather than to record what was known at the moment a decision was taken.
The requirement in the fifth stage.
Signal, classify, contain, escalate, reconstruct, close. The fifth carries the weight. An incident is explainable only if the evidence needed to reconstruct it existed at the moment of the decision, bound to the policy version then in force. Evidence assembled after the fact reconstructs the institution’s beliefs rather than the system’s behaviour, and the difference is visible to anyone who asks what changed in between.
Why the evidence layer is not optional.
AIRP consumes the evidence of every other framework in the registry except MESA, which supplies evidence to nothing. It is the only function that fails visibly and immediately when the evidence is absent, which is why it is the framework that justifies the cost of producing evidence everywhere else.
Which institutions, and on whose authority.
An incident protocol bites wherever an authority can compel an explanation on a deadline — and the specification treats that as a property of jurisdiction rather than of sector. Notification thresholds and timelines vary by jurisdiction and by authority and are NOT stated here; they must be re-verified against the primary sources in force where the institution operates.
The record of its own revisions.
A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.
Change history
- 2026-08-30 · entry v1.0 — First registry entry
- 2026-08-30 · entry v1.0 — Records the reframing of the protocol around reconstruction rather than crisis process
Limitations recorded in the registry
These were recorded in the registry entry at version 1.0, before this framework’s specification was deposited on 6 September 2026. Where the specification has since closed one of them, the stated limits further down this page are the current account.
- Notification timelines and notifiability thresholds vary by jurisdiction and authority. An institution MUST re-verify both against the primary sources in force in its own jurisdiction. This registry states none.
- No incident taxonomy aligned to the public AI incident repositories, so an institution's incident record cannot be compared to any population outside it.
- Reconstruction is possible only to the extent that the other frameworks kept their evidence. AIRP cannot compensate for an upstream framework that produced none.
What would show this to be wrong. AIRP is falsified if institutions holding complete upstream BOE records are found no better able to reconstruct an AI incident, to a standard an external authority accepts, than institutions holding conventional application and infrastructure logs. The protocol's distinguishing claim is that decision-time evidence bound to a policy version is what reconstruction requires, and evidence that ordinary logging suffices would collapse the distinction the framework is built on.
What this does not claim.
Asserted, and jurisdiction-dependent. Notification timelines and the threshold at which an incident becomes notifiable vary by jurisdiction and by authority. This page states none of them. An institution must re-verify both against the primary sources in force where it operates.
Aligned, not endorsed. The taxonomy adopts OECD vocabulary for event class and harm category and references AI Incident Database entries by identifier alone, adopting none of that repository’s vocabulary; neither the OECD nor the Responsible AI Collaborative has reviewed or endorsed either alignment. Shared vocabulary lets an institution’s record be expressed in public terms, which is not the same as making an internal log and a public repository comparable populations.
Scope. Reconstruction is possible only to the extent that the other frameworks kept their evidence. An institution operating this over frameworks that write no records has an escalation procedure, not a reconstruction capability.
Citation.
Cite this work. AI Incident Response Protocol (AIRP), version 1.0. 10.5281/zenodo.22285057. This is the concept DOI and it always resolves to the latest version. CC BY 4.0. Registry entry REG-05 in 10.5281/zenodo.22170112 is at version 1.0 and does not yet point at this specification.
In the practice.
- Governed production AI, the discipline this framework belongs to
- Defensible AI, the family and the register
- AI Governance and Compliance Frameworks for the Middle East, the source treatment
- Model risk, the service this framework is applied through
- AI governance in the wiring, on where governance actually lives