finding should begin immediately. In cases where prompt action is required—such as security incidents—emergency measures to prevent the spread of harm may need to be taken even if full verification of the cause is delayed. The matter should then be reported to a body capable of resolving the issue in a responsible manner (for example, an executive or steering committee), and concrete response measures should be developed. Where necessary, the organization may need to disclose the issue publicly and issue an apology. In cases involving identifiable victims, such as copyright infringement, the organization should apologize to the affected parties and provide appropriate remedies or compensation. Once the situation has been brought under control, the organization should review whether any changes to its policies are needed to prevent recurrence. All steps taken in this process, along with relevant materials, should be properly documented. Building on these general response procedures, it is necessary to establish more detailed protocols that specifically take generative AI into account. For example, the organization may designate the AI officer to take primary responsibility for the initial response to incidents involving generative AI. In addition, incident reports may be required to include specific information such as the date and time of the incident, the AI tool used, the relevant output, the aspects identified as problematic, the prompts entered, and the nature and scope of any negative impacts. 102 103

Select target paragraph3