AI incident management is beginning to emerge as a discipline in its own right.
What OpenAI’s reporting framework changes
This analysis forms part of the same operational picture as AI Agents Need Identity, Authority, Boundaries and a Kill Switch and Why AI Incidents Need Forensic Readiness, Not Just Reporting.
In September 2026, OpenAI introduced a formal framework for tracking, investigating and disclosing examples of model misalignment.
It accompanied the framework with six reports covering unexpected or concerning behaviour observed during the preceding six months.
The importance of the development goes beyond any individual incident.
OpenAI acknowledged that its previous disclosures had been relatively ad hoc and said the new framework was intended to accelerate reporting even where behaviour had not yet been completely explained or mitigated.
A repeatable AI incident-management process
That points towards an important enterprise governance requirement.
When AI behaves unexpectedly, organisations need a repeatable process for determining:
what happened → what system was involved → what evidence exists → what control failed → what impact resulted → what remediation occurred → whether the incident is closed.
Traditional IT incident management provides part of the answer.
But AI introduces additional questions involving model behaviour, instructions, autonomy, permissions and human oversight.
Turning unexpected behaviour into governance evidence
As systems become capable of taking real-world actions, unexpected behaviour can become an operational event rather than simply an inaccurate output.
Organisations deploying advanced AI should therefore consider establishing an AI incident register alongside conventional security and operational incident processes.
The objective is not to classify every hallucination as a major incident.
It is to create a structured escalation path when behaviour crosses a defined risk threshold.
AI governance becomes considerably more credible when organisations can demonstrate not only how systems should behave, but what happens when they do not.
SOS perspective
This issue sits within our work on AI governance and assurance: practical systems should preserve evidence, human accountability and proportionate control while delivering useful automation.
Sources and further context
Apply this analysis to a practical, accountable AI decision.
Discuss AI incident management with SOS