Minor
Policy not followed, no data exposed and no student harmed
Serious
Prohibited content reached students, an unapproved tool touched student data, or a vendor failed its obligations
Critical
Student personal data breached, a safeguarding concern, or an AI decision affecting a student’s welfare or rights
| Criteria | P3 — Minor | P2 — Serious | P1 — Critical |
|---|---|---|---|
| Definition (policy §10) | Policy non-compliance without data exposure; student misuse of an approved tool; staff using AI without disclosure | Prohibited AI content delivered to students; unapproved tool used with student data; vendor compliance failure | Data breach involving student personal data; safeguarding concern; unauthorised AI decision affecting a student’s welfare or rights |
| Examples | A teacher used an unapproved chatbot to draft feedback, no student data entered · A tool bug lost an assignment | Inappropriate images shown to a class · Students’ work pasted into an unapproved tool · A vendor changed its data terms without notice | Deepfake imagery of a student · Student records exposed · Self-harm content served to a student · A student sanctioned on a detector score alone (see §13) |
| Deadlines | Resolved in 5 days | Panel convened in 48 hours | Alert in 1 hour · contained in 24 hours · regulator per your jurisdiction |
| Notify | AI Policy Owner · affected families if a student was affected | AI Policy Owner · Governance Panel · affected families where required | AI Policy Owner and Head of School (within 1 hour) · Governance Panel · all affected families · legal counsel · the regulator where the law requires it · police where a crime may have occurred |
| Record | Every incident, P1 to P3, goes in the Policy Incident Register: date, description, class, actions taken, resolution and lessons learned. | ||
| Jurisdiction | Who | Deadline in the policy |
|---|---|---|
| Colombia | Superintendencia de Industria y Comercio, through the RNBD portal · Ley 1581 de 2012 | 15 business days |
| Spain | AEPD, through its electronic office · GDPR Art. 33. Affected people told without delay when the risk is high · GDPR Art. 34 | 72 hours |
| United States | As your state’s breach law requires; decide within 72 hours whether education records are affected (FERPA) | Varies by state — check yours |
These are the deadlines stated in the Living AI Policy sample. Confirm them with your counsel when you adopt the policy; a deadline you have not checked is not a plan.
P3 — Minor
Resolved within 5 days- Document incident (screenshots, logs)
- Stop the use in question (the tool stays available to others unless the cause is the tool)
- Tell the AI Policy Owner
- Identify affected students (count, names)
- Interview teacher who discovered the incident
- Interview affected students (if age-appropriate)
- Review tool logs
- Contact vendor support (if tool-related)
- Send individual email to affected parents
- Include: what happened, impact, response, prevention
- Offer: opt-out, alternative assignment, meeting
- Provide alternative assignment
- Counsel affected students if needed
- Update tool settings (if configuration issue)
- Log it in the Policy Incident Register; corrective action assigned to a named person
P2 — Serious
Panel convened within 48 hours- Document incident (screenshots, logs, witness statements)
- Suspend the tool for everyone, pending investigation
- Tell the AI Policy Owner and the Head of School
- Preserve evidence (do not delete logs)
- Identify ALL affected students
- Form incident team (admin, tech, legal, counselor)
- Interview all witnesses
- Contact vendor — escalate to legal/privacy officer
- Determine scope (how many students, what data)
- Data-protection assessment under the law that applies (see Section 5)
- Does any law require a report to an authority?
- Vendor contract review (liability clauses)
- Determine if law enforcement is needed
- Individual letter to every affected family
- Include: factual description, timeline, impact, response
- Offer: counseling, opt-out, meeting with admin
- One named contact for family questions, with hours stated
- Brief the chair of the governing body
- Prepare a written briefing for the governing body
- Schedule a policy review if the incident shows a gap
- Vendor meeting — demand corrective action
- Update vendor scorecard (major deduction)
P1 — Critical
Alert in 1 hour · contained in 24 hours- Document everything (screenshots, logs, student roster)
- Suspend the tool involved; revoke its access to student data
- Call the AI Policy Owner and the Head of School — a call, not an email
- Legal hold on all evidence (do not delete anything)
- Identify ALL affected students (complete roster)
- Head of School convenes the response team
- External legal counsel engaged immediately
- Communications director prepares holding statement
- Counselling available to every affected student
- Law enforcement contacted (if criminal activity)
- Forensic data collection (preserve chain of custody)
- All witness interviews recorded
- Vendor legal team contacted (preserve evidence)
- Regulator notified within the deadline for your jurisdiction (table above)
- Individual letter to every affected family
- Individual meetings offered
- Counseling provided immediately
- One named contact for families, with hours stated, for as long as questions keep coming
- Letters in the families’ home languages
- Press release prepared (factual, no minimization)
- One spokesperson — the Head of School
- Social media monitoring — respond to misinformation
- Governing body’s statement consistent with the school’s
- Ongoing counseling for affected students
- Policy overhaul complete
- Vendor contract terminated (if applicable)
- Third-party audit commissioned
- Annual incident drill scheduled
- Comprehensive public report published
- Insurance claim filed (if applicable)
Incident Classification:
Incident Type (check all that apply):
Evidence Preserved:
Notification Timeline:
TO: [AI Policy Owner / Head of School] FROM: [Staff Name] DATE: [Date] SUBJECT: AI Incident Report — [P1/P2/P3]
An AI incident occurred on [date] at [school]. WHAT HAPPENED: [Factual description, no minimization]
STUDENTS AFFECTED: [Count, grade levels] IMMEDIATE ACTIONS: [Actions taken]
NOTIFICATION STATUS: Parents: [Yes/No] · Legal: [Yes/Pending] · Regulator: [Yes/Not required/Pending] · Governing body: [Yes/Scheduled]
RECOMMENDATION: [Next steps requested] Evidence attached: [list]
[School Letterhead] · [Date]
Dear [Parent Name], I'm writing to inform you of an incident involving [AI Tool Name] that affected your child on [date].
WHAT HAPPENED: [Clear, factual description] IMPACT ON YOUR CHILD: [Specific impact]
OUR RESPONSE: (1) Tool suspended immediately (2) Alternative assignment provided (3) Counseling offered if needed
YOUR OPTIONS: Opt-out of this tool: [URL] · Request meeting: [contact] · Review AI policy: [URL]
Sincerely, [Principal Name] / [School]
[School Letterhead] · [DATE] · URGENT: AI Incident Notification
Dear Families, We're writing to inform you of a [P1/P2] incident involving [AI Tool Name] that affected [number] students at [school(s)].
WHAT HAPPENED: [Factual, detailed description — no minimization or euphemisms]
YOUR CHILD'S STATUS: ☐ Your child WAS affected ☐ Your child was NOT affected
OUR IMMEDIATE RESPONSE: (1) Tool suspended (2) Investigation launched (3) All affected students identified (4) Support resources provided
YOUR RIGHTS: Review incident report: [URL] · Request meeting: [contact] · Opt-out of all AI tools: [URL] · File complaint: [URL]
Sincerely, [Head of School Name] / [Contact Information]
FOR IMMEDIATE RELEASE · [Date]
[School Name] is addressing an AI-related incident at [school] that affected [number] students on [date].
FACTS: [Clear, factual description — no minimization or euphemisms]
RESPONSE: Tool immediately suspended · All affected families notified within [X] hours · Counseling provided · Investigation underway · Policy review initiated
CONTACT: [Spokesperson] · [Phone] · [Email]
Questions for your counsel, not answers. Keep the block for your jurisdiction.
- Was student personal data disclosed to anyone not entitled to it?
- Did the vendor act within its data agreement?
- Was the data used only for the purpose the school approved?
- Was data sold or reused by the vendor?
- Does the law require telling the regulator? By when? (table above)
- Does it require telling the people affected?
- Has the vendor been asked to delete the data, and confirmed it in writing?
- Is the evidence preserved, with an audit trail?
- Do staff representatives need to be informed?
- Report to the SIC through the RNBD portal
- Was there authorization for the processing (Art. 9)?
- Was a child’s data processed in the child’s best interest?
- Are education records affected?
- Was the vendor acting as a “school official” under the district’s or school’s control?
- What does your state’s breach law require, and by when?
- Notify the AEPD within 72 hours unless the breach is unlikely to pose a risk (Art. 33)
- Tell the people affected without delay if the risk is high (Art. 34)
- Has the data protection officer been involved from the first hour?
| Metric | Target | Track |
|---|---|---|
| P1 — internal alert | within 1 hour (policy §10) | ___ |
| P1 — containment | within 24 hours (policy §10) | ___ |
| P1 — regulator notified | within your jurisdiction’s deadline | ___ |
| P2 — panel convened | within 48 hours (policy §10) | ___ |
| P3 — resolved | within 5 days (policy §10) | ___ |
| Incidents by class this year | recorded, not targeted | ___ |
| Repeat incidents (same root cause) | set by the panel | ___ |
| Policy revisions triggered by an incident | recorded | ___ |