Convene CISO, General Counsel, and Incident Commander. Walk the determination. Document the decision. The clock has already started.
Part of the AI IR Overlay™ framework. See CONTENT_MAP.md for the full repository map.
Materiality and Disclosure
Most AI agent incidents will not trigger regulatory disclosure. The ones that do operate under tight statutory clocks that start at incident detection, not at the close of investigation. This chapter establishes the convening protocol and the determination discipline that decide which clock applies and when it starts.
This is not a legal authority. Materiality determination is jurisdiction-specific, depends on facts the framework cannot know in advance, and is ultimately the responsibility of the registrant’s General Counsel and audit committee. This chapter operationalizes the procedure: who is convened, what they walk through, how the decision is documented. The legal substance comes from your jurisdiction’s specific regulations.
Why this discipline matters
A publicly-traded organization that takes 8 business days to determine an AI incident is material has likely violated the SEC’s without unreasonable delay materiality-determination standard, separate from the 4-business-day Form 8-K Item 1.05 disclosure window that runs from determination. A deployer who treats an EU AI Act Article 73 “serious incident” as a routine post-mortem has missed the 15-day reporting window (or the 2-day window for death or serious irreversible harm; Article 26(5)/(7) separately requires the deployer to inform the provider). A DFS-Covered Entity (financial-services licensee) that lets an AI incident’s customer-data exposure age past 72 hours from determining a Cybersecurity Event has occurred has missed NY DFS 23 NYCRR Part 500.17(a). In each case, the disclosure failure is itself a separate violation, often more consequential than the underlying incident.
The Six Triage Questions tell the responder what’s happening. The Kill-Switch Modes contain the incident. The Minimum Evidence Set preserves what occurred. None of those tell the CISO whether the General Counsel needs to be on the call. This chapter does.
The convening protocol
When an incident reaches Kill-Switch Mode M3 (Tool Tiering) or higher, OR when any of the trigger conditions below applies, the Incident Commander convenes the Materiality and Disclosure call within one hour:
| Role | Responsibility on the call |
|---|---|
| CISO | Owns the incident’s technical scope. Brings the Minimum Evidence Set snapshot and the current containment Mode. |
| General Counsel | Owns the disclosure determination. Brings the regulatory inventory: which regimes apply to this organization, which clocks run from which trigger. |
| Incident Commander | Owns the timeline. Documents who said what, when. Maintains the decision log per Playbook 01. |
| Communications lead (observer) | Listens. Does not draft external statements until General Counsel signals the materiality determination. |
The canonical convening trigger. The Materiality and Disclosure call is convened when either of the following applies. Downstream playbooks reference this canonical list rather than restating it.
Mode-based trigger:
- Kill-Switch Mode M3 (Tool Tiering) or higher is activated for the affected agent
Condition-based triggers (apply regardless of Kill-Switch Mode):
- Customer data exposure suspected or confirmed
- External recipient of an unauthorized message (email, ticket, support response)
- Financial action executed by the agent without authorization
- Regulatory data category touched (PII, PHI, payment card data, regulated AI use case)
- Customer-facing trust impact identified (incorrect information sent externally per the CIA+T framing in Playbook 05)
- Public attention (researcher disclosure, customer report, social media)
- Any incident that would be embarrassing on the front page of a financial news outlet
The framework’s convening posture is over-convene rather than under-convene. Where a playbook’s response sequence is uncertain whether to convene, the default is to convene; the materiality determination then runs through the four-question walkthrough below and may determine “not material,” which is itself a documented outcome.
The CISO does not unilaterally defer the call. General Counsel’s calendar is not a precondition. If General Counsel is unreachable, the CISO documents the unavailability and proceeds with the materiality walkthrough, then re-convenes when GC is available.
The materiality walkthrough
The call walks four questions in order. The answers are documented in the decision log. Each answer is a finding, not an opinion.
1. What clock(s) run from this incident?
For US registrants: SEC Item 1.05 of Form 8-K runs 4 business days from materiality determination. The clock starts when the registrant determines the incident is material, not when the incident occurred.
For EU deployers of high-risk AI systems: EU AI Act Article 26 requires the deployer, upon identifying a serious incident, to inform the provider, distributor, and the relevant market surveillance authority without undue delay. EU AI Act Article 73 then runs against the provider to report the serious incident to market surveillance authorities. The reporting window under Article 73 is 15 days from awareness in the default case, 2 days for incidents resulting in the death of a person or in serious and irreversible harm, and 10 days for widespread infringement. Deployer detection effectively starts the provider’s clock, so the deployer’s own materiality determination timing is load-bearing for the cumulative regulatory window.
For NY DFS-covered entities: 23 NYCRR Part 500.17(a) (as amended in November 2023) requires notification to the Superintendent within 72 hours after determining that a Cybersecurity Event has occurred.
For HIPAA covered entities or business associates: 45 CFR §164.408 requires breach notification timelines that depend on the size and category.
The General Counsel names which clock(s) apply. The Incident Commander documents the start-of-clock determination separately from the incident-detection timestamp.
2. What does the evidence currently show?
The CISO walks the A–F evidence set at its current capture state:
- Type A (Prompt and Response Record): what did the agent receive and produce
- Type B (Tool-Call Ledger): what did the agent attempt and what succeeded
- Type C (Retrieval Traces): what context entered the model
- Type D (Memory Snapshot): what state persisted
- Type E (Configuration Snapshot): what was the agent supposed to do
- Type F (Identity and SaaS Audit-Log Correlation): what actually reached downstream systems
The materiality determination is anchored to F. The agent’s intent (A, B, C, D, E) is internal. Downstream action (F) is what regulators and counterparties experience.
3. Is the evidence currently sufficient to determine materiality?
If yes: General Counsel makes the determination. The clock starts at the determination time. The Incident Commander documents the determination, the supporting evidence, and the decision rationale.
If no: General Counsel determines what additional evidence is needed and the latest acceptable time to obtain it. The Incident Commander schedules the re-convene. The clock is not paused by the inability to determine. The framework’s position is that materiality determination delay must itself be documented.
4. What action follows the determination?
Three outcomes are possible:
Outcome A: Not material. The Incident Commander documents the determination, the supporting evidence, and the rationale. The incident closes per Playbook 18: Post-Incident Hardening. The decision log is preserved in case of subsequent regulator inquiry.
Outcome B: Material. The clock runs. General Counsel notifies Communications. The disclosure is drafted to the timing window of the most-restrictive applicable clock, which varies by registrant: SEC Form 8-K Item 1.05 (4 business days from materiality determination) for publicly-traded registrants; NY DFS 23 NYCRR Part 500.17(a) (72 hours from determining a Cybersecurity Event has occurred) for DFS-Covered Entities (financial-services licensees); GDPR Article 33 (72 hours from awareness of personal-data breach) where personal data of EU subjects is affected; HIPAA Breach Notification Rule per 45 CFR §164.404/406/408 (60-day windows from breach discovery) where Protected Health Information is affected. The Incident Commander continues incident response in parallel.
Outcome C: Determination cannot be made yet. Continue the incident response. Schedule the re-convene. Document the inability to determine. A registrant that determines at the next convene is not “late” provided the inability-to-determine was itself documented and reasonable.
Where this annex is referenced from
This annex is referenced from multiple live playbooks across three roles.
Convening role (First-Hour Actions). Nine playbooks convene the Materiality and Disclosure call as part of their First-Hour Actions, once Kill-Switch Mode M3 or higher is reached or when any of the canonical convening triggers named in this annex applies:
- Playbook 01: The Agent Is a Privileged Identity: the keystone response playbook.
- Playbook 05: Executive Decision-Making: the call is convened around the Executive Decision Packet.
- Playbook 06: Prompt Injection as Workflow Threat: external recipients and regulated-data triggers are the most common condition-based triggers for workflow-injection incidents.
- Playbook 09: Leakage Without a Breach: the output distribution map drives the determination.
- Playbook 10: Vendor Copilots and Mutual Responsibility: the customer-side convening track does not wait for vendor cooperation.
- Playbook 15: Records, Retention, and Proving What Happened: PB15 certifies the evidence required to defend the determination.
- Playbook 21: Shadow AI: latent regulatory exposure surfaced through retrospective CIA+T assessment.
- Playbook 22: Model and Policy Drift: the disclosure window may have started before the drift was observed.
- Playbook 23: AI Logging and Privacy in a Multi-Stakeholder World: privacy-side disclosure obligations run alongside the standard materiality call.
Gating role. Two playbooks gate downstream discipline on the materiality determination:
- Playbook 18: Post-Incident Hardening: verifies that the materiality determination is captured in the decision log. The 5-business-day hardening SLA does not run if the materiality record is incomplete.
- Playbook 24: Board-Ready Scorecard: the Governance domain item C3 confirms that materiality determination is documented for every incident reaching Mode M3 or higher.
Referential role. Four additional playbooks reference this annex in supporting context: Playbook 02 (Evidence Lives in New Places) for the evidence foundation the determination depends on; Playbook 16 (Training Your Team) for the materiality-recognition criteria built into the team’s training scope; Playbook 17 (Communication Techniques) for the time-pressure / accuracy / accountability discipline the disclosure window imposes; and Playbook 19 (Build vs Buy) for the procurement-time evaluation of platform support for the materiality determination protocol.
What this annex is not
This annex is not a substitute for jurisdiction-specific legal counsel. The clocks, triggers, and thresholds named here are the framework’s operational discipline based on publicly-available regulation text current as of 2026. Your General Counsel reads the current regulations of your specific jurisdictions and operating contexts. The framework’s contribution is the discipline of having that conversation at minute sixty rather than minute six-thousand.
This annex is also not a specification of org-level decision rights. The canonical convening triad is CISO + General Counsel + Incident Commander, but the specific rules for who can declare an incident, who can stand down a false-positive determination, who can escalate or de-escalate Kill-Switch Modes, and who holds the tie-break vote when the triad disagrees on a materiality determination are the customer’s governance discipline. The framework names the roles; the customer’s RACI, charter, or governance policy defines who in those roles holds which decision right. A formal decision-rights specification is a v1.x candidate (see CHANGELOG.md [Unreleased] v1.1 backlog).
Flow at a glance (outbound from the convening call)
CONVENE (CISO + GC + IC) within 1 hour of trigger
↓
┌──────────────────────┼──────────────────────┐
↓ ↓ ↓
Outcome A: Outcome B: Outcome C:
NOT MATERIAL MATERIAL CANNOT DETERMINE
↓ ↓ ↓
• Document • Disclosure clock • Continue response
determination runs in parallel
• Decision log • Comms drafts • Schedule re-convene
preserved disclosure to the at next checkpoint
• Close via most-restrictive • Document the
Playbook 18 applicable clock inability to
hardening • Continue response determine; re-evaluate
in parallel at re-convene
• Playbook 17 for
stakeholder
communication
• Playbook 18 for
hardening (gate:
materiality record
complete)
• Playbook 24 item
C3 governance signal
Related
- Live response navigation:
RESPONSE-START.md(the paged-responder entry point; this file is step 4 of 4 in the response-time navigation path) - Six Triage Questions: the first-15-minutes discipline; the materiality call follows the triage
- Kill-Switch Modes: the M3-or-higher threshold that triggers the materiality call
- Minimum Evidence Set: the A–F evidence at the determination point
- Playbook 01: the response playbook the materiality call sits within
Source: AI IR Overlay newsletter and framework synthesis, by Jacob Ideji. https://www.linkedin.com/in/jacobideji/