Skip to Content

IAPP Privacy. Security. Risk. + AI Governance Global 2026

Seattle

6-9 October

Conference

8-9 Oct.

Training

6-7 Oct.

Workshops

7 Oct.

Back to conference agenda

AI Incident Response: Obligations of Providers and Deployers When AI Fails

Thursday, 8 Oct.

16:00 - 17:00 PDT

Intermediate level

BREAKOUT SESSIONAI GOVERNANCEAI AND MACHINE LEARNINGDATA SECURITYENFORCEMENTSTRATEGY AND GOVERNANCEINCIDENT MANAGEMENTTECHNOLOGYLEGAL

Artificial intelligence systems introduce unique risks that demand unique incident response. This session explores: (i) responding to serious AI incidents under Article 73 AI Act, including triggers of a serious incident, reporting obligations, and timelines; (ii) the interplay with other regulatory regimes such as the Cyber Resilience Act, the GDPR and NIS2, highlighting overlapping obligations and synergies; and (iii) building a robust, legally sound incident response process that integrates technical, institutional and compliance measures.

What you will learn:

  • Practical tips for how to prepare for an incident.
  • A checklist for AI incident response policies.
  • How to achieve synergies between the AI Act, the GDPR, NIS2 and the CRA when responding to an incident.
  • How to structure the incident response process to protect legal privilege. 

Featured in this session

headshot of Lukas Feiler

Lukas Feiler

CIPP/E

Partner

Baker McKenzie

generic profile silhouette

Seanan Murphy

Vice President of Legal, Privacy, Products and Technology

Dynatrace

generic profile silhouette

Matthieu Peron

General Counsel, Cyber, Data and AI

Schneider Electric