finding should begin immediately. In cases where prompt action
is required—such as security incidents—emergency measures
to prevent the spread of harm may need to be taken even if full
verification of the cause is delayed. The matter should then be
reported to a body capable of resolving the issue in a responsible
manner (for example, an executive or steering committee),
and concrete response measures should be developed. Where
necessary, the organization may need to disclose the issue publicly
and issue an apology. In cases involving identifiable victims, such
as copyright infringement, the organization should apologize
to the affected parties and provide appropriate remedies or
compensation. Once the situation has been brought under control,
the organization should review whether any changes to its policies
are needed to prevent recurrence. All steps taken in this process,
along with relevant materials, should be properly documented.
Building on these general response procedures, it is necessary to
establish more detailed protocols that specifically take generative
AI into account. For example, the organization may designate the
AI officer to take primary responsibility for the initial response
to incidents involving generative AI. In addition, incident reports
may be required to include specific information such as the date
and time of the incident, the AI tool used, the relevant output, the
aspects identified as problematic, the prompts entered, and the
nature and scope of any negative impacts.
102
103