IAPP Privacy. Security. Risk. + AI Governance Global 2026
SEATTLE
6-9 October
AI Incident Response: Obligations of Providers and Deployers When AI Fails
Thursday, 8 Oct.
16:00 - 17:00 EDT
Intermediate level
Artificial intelligence systems introduce unique risks that demand unique incident response. This session explores: (i) responding to serious AI incidents under Article 73 AI Act, including triggers of a serious incident, reporting obligations, and timelines; (ii) the interplay with other regulatory regimes such as the Cyber Resilience Act, the GDPR and NIS2, highlighting overlapping obligations and synergies; and (iii) building a robust, legally sound incident response process that integrates technical, institutional and compliance measures.
What you will learn:
- Practical tips for how to prepare for an incident.
- A checklist for AI incident response policies.
- How to achieve synergies between the AI Act, the GDPR, NIS2 and the CRA when responding to an incident.
- How to structure the incident response process to protect legal privilege.
Moderator and speakers

Lukas Feiler
CIPP/E
Partner
Baker McKenzie

Seanan Murphy
Vice President of Legal, Privacy, Products and Technology
Dynatrace

Matthieu Peron
General Counsel, Cyber, Data and AI
Schneider Electric

May Sethaphanich
AIGP, CIPP/A
Global Senior Counsel, AI Governance
McDonald's