The First 24 Hours After an AI Incident: What to Disclose
AI incident disclosure in the first 24 hours decides whether customers trust you again. Here is what to say, when to say it, and what silence actually costs.
In the first 24 hours after an AI incident, your disclosure choices matter more than your fix. Customers forgive failures. They do not forgive being kept in the dark, then finding out from someone else. The instinct is to go quiet until you fully understand what happened. That instinct is wrong. Silence reads as either incompetence or a coverup, and both cost you more than an honest "we do not know yet." Your job in the first day is not to have all the answers. It is to prove you are on it, tell people what you actually know, and set the next update time.
What should you disclose in the first 24 hours?
Disclose the shape of the problem, the scope you have confirmed, the action you have taken, and when you will update next. Do not disclose speculation dressed as fact, and do not disclose a root cause you have not verified. Guessing wrong in public is worse than saying you are still investigating.
A good first message has four parts. What happened, in plain language. Who is affected, or that you are still determining scope. What you have already done to contain it. When the next update comes. That last part is the one teams forget, and it is the one that buys you patience. A customer who knows the next update lands in four hours will wait four hours. A customer with no timeline refreshes your status page and drafts an angry email.
This only works if your incident response plan already named a communicator. Comms written by whoever is least busy will contradict each other, and contradictions are what turn an incident into a scandal.
Why silence costs more than admitting fault
Founders overestimate the legal risk of disclosure and underestimate the trust risk of silence. Yes, get counsel involved for regulated or contractual situations. But the default corporate instinct to say nothing until legal signs off usually means saying nothing while the story is written for you.
Here is the asymmetry. An honest early disclosure with an unknown root cause makes you look competent and controlled. A late disclosure, even a technically perfect one, makes you look like you were caught. The facts can be identical. The trust outcome is not. This is the whole reason I argue that trust is a feature, not a slogan: it is built and spent in exactly these moments.
The other cost of silence is that customers fill the vacuum with worst-case assumptions. If you do not tell them the blast radius, they assume it is everything. A precise "this affected exports generated between 2pm and 4pm" contains the panic. A missing scope statement lets it spread.
How to disclose without making it worse
There are ways to disclose badly. Avoid them.
- Do not minimize. "A minor issue" that turns out major destroys the credibility of every future update. Under-promise on severity, never over-promise.
- Do not blame the model. "The AI made a mistake" is not accountability. Say what you did or failed to do. Decide in advance who is accountable when the AI is wrong so this is not improvised.
- Do not publish a root cause you cannot prove. If your audit trail does not yet show the cause, say the investigation is ongoing. Retracting a wrong cause is a second incident.
- Do not disclose only to the loudest customer. Enterprise contracts often require notification within a set window. Know your obligations before you have to meet them.
After the first day
Once you are past 24 hours, disclosure shifts from "we are on it" to "here is what happened and what we changed." That is the postmortem, and it should be specific, honest, and free of jargon that hides the failure. The postmortem is also where you earn the recovery. Handled well, an incident can leave a customer trusting you more than before, because they have now seen how you behave under pressure.
I build this discipline into the products I run. My venture Girard AI treats disclosure timing as a policy, not a judgment call made by a stressed founder at 2am. The mechanics of earning trust back over the following weeks are their own discipline, covered in rebuilding trust after an AI failure. But it all starts with what you choose to say on day one. Say something true, say it early, and set the next update. That is the whole first day.