AI INVESTIGATIONS Open resources for investigating AI incidents LAST REVIEWED: 2026-07-20 ← LINK MAP

Frameworks // an overview of existing methodologies

An overview of existing frameworks and methodologies relevant to AI incident work: reporting regimes, harm and failure taxonomies, causal-factor analysis, red-team studies of agent behavior, and adjacent practice from insider-threat research. Each is a useful starting point for part of the job and worth reading further; none yet describes how to conduct an AI incident investigation end to end, which is the gap the playbooks aim to fill. Full annotations are on the repository page.

FrameworkCoversDoes not cover
Ezell, Roberts-Gaal & Chan (2025), Incident Analysis for AI AgentsCausal-factor analysis; the data categories an analysis needsGoal-directed (intentional-analog) cases; competing-hypothesis work
Microsoft AI Red Team taxonomy (2025)Misalignment / misuse / operational-failure vocabularyAny investigative procedure; categories often inseparable in practice
OECD common reporting framework (2025)Baseline definitions; 29 reporting criteriaHow to establish the facts being reported
EU AI Act Art. 73 + draft guidance (2025)What to report, to whom, by when; templateHow to conduct the investigation it mandates
Anthropic (Lynch et al., 2025); Apollo (Meinke et al., 2024); CLTR (2026)Red-team evidence and at-scale detection of scheming behaviorWhat happens after detection
MITRE ATLAS; GenAI-IRF (Jakoby, 2026)Adversarial techniques; cyber-IR bridgingAgent-initiated behavior; investigation depth
CERT insider-threat corpus (Cappelli et al., 2012); Shaw & Sellers (2015)The intentional/unintentional asymmetry: the closest existing modelAI systems; needs adaptation, which is the open problem