AI INVESTIGATIONS Open resources for investigating AI incidents LAST REVIEWED: 2026-07-22 ← LINK MAP
Updates to this repository are currently on hold

A New Field of AI Incident Investigations

When an AI incident occurs, whether caused by misalignment, misuse, or system failure, the immediate challenge is not only responding to the event, but also understanding what actually happened. What did the system do? When and why did it happen? What evidence can be collected? Who is accountable? And ultimately, what are the lessons that can be learned? Just as importantly, how much of this can realistically be established from the outside? In other high-risk domains, where investigation practices have long been established, there would be a way of answering these questions; for AI, most of the time, there is not yet.

What the field is. AI incident investigation is an emerging practice, still taking shape, of detecting, documenting, classifying and analysing harm events, and near-harms, involving deployed AI systems, so that they are not simply repeated and in order for what is learned to inform how these systems are governed and produce changes which lower their overall risk.

Scope map // the territory, by the AI system's role in the incident

1: AI AS ACTOR
The system itself caused the harm.An agent deletes, publishes, sends, spends, without a human directing the harmful act.
OPERATIONAL FAILUREmalfunction, no divergent goal
MISALIGNMENTgoal-directed divergence, possible concealment
CF-001 · CF-002 · CF-003
2: AI AS INSTRUMENT
Humans using AI to cause harm.Fraud and social engineering at machine scale, deepfake-enabled crime, influence operations, AI-assisted intrusion. The adversary is human; the AI is the weapon.
CASE FILES PENDING
3: AI AS TARGET
Attacks on AI systems.Prompt injection, data poisoning, model theft, adversarial manipulation. This is where AI investigation overlaps most with established cybersecurity practice, covered by frameworks such as MITRE ATLAS.
CASE FILES PENDING

note: prompt injection straddles 2 ↔ 3. The AI is target and instrument at once. Boundary cases are normal; the taxonomy serves the investigation, not the reverse.

Browse the resource // each section now on its own page