Same levels, same clock as your policy. P1, P2 and P3 here are the classes in Section 10 of the Living AI Policy, with its deadlines. If your school’s adopted policy sets different ones, the policy wins — change this sheet to match it, not the other way round.
Level Classification — At a Glance
P3

Minor

⏱ Resolved within 5 days

Policy not followed, no data exposed and no student harmed

P2

Serious

⏱ Panel responds within 48 hours

Prohibited content reached students, an unapproved tool touched student data, or a vendor failed its obligations

P1

Critical

⏱ Alert in 1 hour · contained in 24

Student personal data breached, a safeguarding concern, or an AI decision affecting a student’s welfare or rights

1 — Incident Classification System
Criteria P3 — Minor P2 — Serious P1 — Critical
Definition (policy §10) Policy non-compliance without data exposure; student misuse of an approved tool; staff using AI without disclosure Prohibited AI content delivered to students; unapproved tool used with student data; vendor compliance failure Data breach involving student personal data; safeguarding concern; unauthorised AI decision affecting a student’s welfare or rights
Examples A teacher used an unapproved chatbot to draft feedback, no student data entered · A tool bug lost an assignment Inappropriate images shown to a class · Students’ work pasted into an unapproved tool · A vendor changed its data terms without notice Deepfake imagery of a student · Student records exposed · Self-harm content served to a student · A student sanctioned on a detector score alone (see §13)
Deadlines Resolved in 5 days Panel convened in 48 hours Alert in 1 hour · contained in 24 hours · regulator per your jurisdiction
Notify AI Policy Owner · affected families if a student was affected AI Policy Owner · Governance Panel · affected families where required AI Policy Owner and Head of School (within 1 hour) · Governance Panel · all affected families · legal counsel · the regulator where the law requires it · police where a crime may have occurred
Record Every incident, P1 to P3, goes in the Policy Incident Register: date, description, class, actions taken, resolution and lessons learned.
Regulator Deadlines for a P1 Data Breach
JurisdictionWhoDeadline in the policy
ColombiaSuperintendencia de Industria y Comercio, through the RNBD portal · Ley 1581 de 201215 business days
SpainAEPD, through its electronic office · GDPR Art. 33. Affected people told without delay when the risk is high · GDPR Art. 3472 hours
United StatesAs your state’s breach law requires; decide within 72 hours whether education records are affected (FERPA)Varies by state — check yours

These are the deadlines stated in the Living AI Policy sample. Confirm them with your counsel when you adopt the policy; a deadline you have not checked is not a plan.

2 — Response Playbooks

P3 — Minor

Resolved within 5 days
Same day
  • Document incident (screenshots, logs)
  • Stop the use in question (the tool stays available to others unless the cause is the tool)
  • Tell the AI Policy Owner
  • Identify affected students (count, names)
Look into it (days 1–3)
  • Interview teacher who discovered the incident
  • Interview affected students (if age-appropriate)
  • Review tool logs
  • Contact vendor support (if tool-related)
Tell the family, if a student was affected (by day 3)
  • Send individual email to affected parents
  • Include: what happened, impact, response, prevention
  • Offer: opt-out, alternative assignment, meeting
Close it (by day 5)
  • Provide alternative assignment
  • Counsel affected students if needed
  • Update tool settings (if configuration issue)
  • Log it in the Policy Incident Register; corrective action assigned to a named person

P2 — Serious

Panel convened within 48 hours
First hours
  • Document incident (screenshots, logs, witness statements)
  • Suspend the tool for everyone, pending investigation
  • Tell the AI Policy Owner and the Head of School
  • Preserve evidence (do not delete logs)
  • Identify ALL affected students
Investigation (first 24 hours)
  • Form incident team (admin, tech, legal, counselor)
  • Interview all witnesses
  • Contact vendor — escalate to legal/privacy officer
  • Determine scope (how many students, what data)
Legal review (within 48 hours)
  • Data-protection assessment under the law that applies (see Section 5)
  • Does any law require a report to an authority?
  • Vendor contract review (liability clauses)
  • Determine if law enforcement is needed
Families (within 48 hours, where required)
  • Individual letter to every affected family
  • Include: factual description, timeline, impact, response
  • Offer: counseling, opt-out, meeting with admin
  • One named contact for family questions, with hours stated
Panel and governing body (within 48 hours)
  • Brief the chair of the governing body
  • Prepare a written briefing for the governing body
  • Schedule a policy review if the incident shows a gap
  • Vendor meeting — demand corrective action
  • Update vendor scorecard (major deduction)

P1 — Critical

Alert in 1 hour · contained in 24 hours
Within 1 hour — alert
  • Document everything (screenshots, logs, student roster)
  • Suspend the tool involved; revoke its access to student data
  • Call the AI Policy Owner and the Head of School — a call, not an email
  • Legal hold on all evidence (do not delete anything)
  • Identify ALL affected students (complete roster)
Within 24 hours — contain
  • Head of School convenes the response team
  • External legal counsel engaged immediately
  • Communications director prepares holding statement
  • Counselling available to every affected student
  • Law enforcement contacted (if criminal activity)
Investigation (first 72 hours)
  • Forensic data collection (preserve chain of custody)
  • All witness interviews recorded
  • Vendor legal team contacted (preserve evidence)
  • Regulator notified within the deadline for your jurisdiction (table above)
Families
  • Individual letter to every affected family
  • Individual meetings offered
  • Counseling provided immediately
  • One named contact for families, with hours stated, for as long as questions keep coming
  • Letters in the families’ home languages
If the incident is public
  • Press release prepared (factual, no minimization)
  • One spokesperson — the Head of School
  • Social media monitoring — respond to misinformation
  • Governing body’s statement consistent with the school’s
Long-Term Remediation (1–4 weeks)
  • Ongoing counseling for affected students
  • Policy overhaul complete
  • Vendor contract terminated (if applicable)
  • Third-party audit commissioned
  • Annual incident drill scheduled
  • Comprehensive public report published
  • Insurance claim filed (if applicable)
3 — Incident Report Form
AI Incident Report Form
Incident ID: __________ Date/Time Discovered: __________ Date/Time Occurred: __________
School: __________________________ Grade/Class: __________ Staff Who Discovered: __________________________

Incident Classification:

P3 (Minor) — policy not followed, no data exposed, no harm
P2 (Serious) — prohibited content, unapproved tool with student data, vendor failure
P1 (Critical) — data breach, safeguarding concern, AI decision affecting a student

Incident Type (check all that apply):

Inappropriate content (sexual, violent, hate)
Data breach / data-protection violation
Bias / Discrimination (targeted demographic)
Academic dishonesty (false accusation)
Deepfake / Non-Consensual Intimate Imagery
Self-harm / Suicide content
Vendor misconduct (data sale, terms violation)
Technical malfunction (data loss, corruption)
Total Students Affected: __________ Grade Levels: __________ Students with additional learning needs: ☐ Yes ☐ No
Description (factual, no minimization): _____________________________________________

Evidence Preserved:

Screenshots (count: ___)
System logs (preserved: ___)
Witness statements (count: ___)
Vendor communication

Notification Timeline:

Parents notified: __________ AI Policy Owner: __________ Head of School: __________ Legal: __________ Regulator: __________ Governing body: __________ Law enforcement: __________
Vendor contacted: __________ Vendor response: __________________________ Contract status: ☐ Continue ☐ Suspend ☐ Terminate
Reported By: __________________________ Title: __________________________ Date: __________
Reviewed By (Admin): __________________________ Date: __________
4 — Communication Templates
Internal Memo — Staff → Admin

TO: [AI Policy Owner / Head of School]   FROM: [Staff Name]   DATE: [Date]   SUBJECT: AI Incident Report — [P1/P2/P3]

An AI incident occurred on [date] at [school]. WHAT HAPPENED: [Factual description, no minimization]

STUDENTS AFFECTED: [Count, grade levels]   IMMEDIATE ACTIONS: [Actions taken]

NOTIFICATION STATUS: Parents: [Yes/No] · Legal: [Yes/Pending] · Regulator: [Yes/Not required/Pending] · Governing body: [Yes/Scheduled]

RECOMMENDATION: [Next steps requested]   Evidence attached: [list]

External Letter — Family (P3 or P2, one student)

[School Letterhead] · [Date]

Dear [Parent Name], I'm writing to inform you of an incident involving [AI Tool Name] that affected your child on [date].

WHAT HAPPENED: [Clear, factual description]   IMPACT ON YOUR CHILD: [Specific impact]

OUR RESPONSE: (1) Tool suspended immediately (2) Alternative assignment provided (3) Counseling offered if needed

YOUR OPTIONS: Opt-out of this tool: [URL] · Request meeting: [contact] · Review AI policy: [URL]

Sincerely, [Principal Name] / [School]

External Letter — Families (P1 or P2) — URGENT

[School Letterhead] · [DATE] · URGENT: AI Incident Notification

Dear Families, We're writing to inform you of a [P1/P2] incident involving [AI Tool Name] that affected [number] students at [school(s)].

WHAT HAPPENED: [Factual, detailed description — no minimization or euphemisms]

YOUR CHILD'S STATUS: ☐ Your child WAS affected   ☐ Your child was NOT affected

OUR IMMEDIATE RESPONSE: (1) Tool suspended (2) Investigation launched (3) All affected students identified (4) Support resources provided

YOUR RIGHTS: Review incident report: [URL] · Request meeting: [contact] · Opt-out of all AI tools: [URL] · File complaint: [URL]

Sincerely, [Head of School Name] / [Contact Information]

Public Statement (P1, if the incident is public)

FOR IMMEDIATE RELEASE · [Date]

[School Name] is addressing an AI-related incident at [school] that affected [number] students on [date].

FACTS: [Clear, factual description — no minimization or euphemisms]

RESPONSE: Tool immediately suspended · All affected families notified within [X] hours · Counseling provided · Investigation underway · Policy review initiated

CONTACT: [Spokesperson] · [Phone] · [Email]

5 — Legal Review Checklists

Questions for your counsel, not answers. Keep the block for your jurisdiction.

Every Jurisdiction
Colombia — Ley 1581 de 2012
  • Report to the SIC through the RNBD portal
  • Was there authorization for the processing (Art. 9)?
  • Was a child’s data processed in the child’s best interest?
United States — FERPA and state law
  • Are education records affected?
  • Was the vendor acting as a “school official” under the district’s or school’s control?
  • What does your state’s breach law require, and by when?
Spain — GDPR
  • Notify the AEPD within 72 hours unless the breach is unlikely to pose a risk (Art. 33)
  • Tell the people affected without delay if the risk is high (Art. 34)
  • Has the data protection officer been involved from the first hour?
Incident Metrics Dashboard
MetricTargetTrack
P1 — internal alertwithin 1 hour (policy §10)___
P1 — containmentwithin 24 hours (policy §10)___
P1 — regulator notifiedwithin your jurisdiction’s deadline___
P2 — panel convenedwithin 48 hours (policy §10)___
P3 — resolvedwithin 5 days (policy §10)___
Incidents by class this yearrecorded, not targeted___
Repeat incidents (same root cause)set by the panel___
Policy revisions triggered by an incidentrecorded___