Close Menu
NCIJ Network NCIJ Network
    What's Hot

    An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later

    September 24, 2026

    OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

    September 24, 2026

    Solana Foundation Hires Binance’s Former Global CMO for Institutional Push

    September 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later
    • OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data
    • Solana Foundation Hires Binance’s Former Global CMO for Institutional Push
    • NASA to Study Human Health, Performance During Crew-13 Mission
    • New report reveals the environmental cost of USAID’s destruction
    • Tillamook cheese faces boycott over halal label on its packaging. How serious is it?
    • News outlets banned from White House seek emergency hearing after being denied entry despite judge’s order – live | Trump administration
    • Cristiano Ronaldo: 1,000-goal target and Portugal ambition fuel football icon
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Opinion & Analysis

    AI Incident-Reporting Standards Are Key for Safety

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 24, 2026 Opinion & Analysis No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Some of the earliest outsiders to discover the Chernobyl accident were workers at a Swedish nuclear power plant, when the building’s radiation monitors went off. After checking for leaks, the workers eventually realized the radiation came from abroad. The Swedes demanded answers from their neighbor, the Soviet Union. Yet when Soviet news acknowledged the accident, it only gave a terse description. In many cases, the Soviet government attempted to downplay the disaster to the outside world. This secrecy cost European governments valuable response time.

    That September, countries, including the United States and Soviet Union, signed a treaty to notify affected nations of nuclear accidents whose radiation may cross borders. The world needs a similar agreement for artificial intelligence: a channel by which governments, AI companies, and compute providers can inform each other when an AI system causes serious harm across international borders. The United States and China may mistrust each other over cybersecurity, but, like the Cold War rivals, they can find common ground on mutual dangers.

    Some of the earliest outsiders to discover the Chernobyl accident were workers at a Swedish nuclear power plant, when the building’s radiation monitors went off. After checking for leaks, the workers eventually realized the radiation came from abroad. The Swedes demanded answers from their neighbor, the Soviet Union. Yet when Soviet news acknowledged the accident, it only gave a terse description. In many cases, the Soviet government attempted to downplay the disaster to the outside world. This secrecy cost European governments valuable response time.

    That September, countries, including the United States and Soviet Union, signed a treaty to notify affected nations of nuclear accidents whose radiation may cross borders. The world needs a similar agreement for artificial intelligence: a channel by which governments, AI companies, and compute providers can inform each other when an AI system causes serious harm across international borders. The United States and China may mistrust each other over cybersecurity, but, like the Cold War rivals, they can find common ground on mutual dangers.

    This summer, U.S. AI labs disclosed several incidents related to AI agents. The firm Hugging Face was unexpectedly hacked by AI agents later confirmed to be from OpenAI. In another case, OpenAI agents used a public wiki to discuss ways to bypass certain restrictions. Anthropic’s AI agents broke into systems of other companies. The resulting global concerns over AI risks were further amplified by former Anthropic researcher Jacob Coxon’s recent viral resignation.

    In response, OpenAI invited METR and Redwood Research to investigate the Hugging Face incident, leading to a detailed public report. Anthropic publicly disclosed its incidents to the world a week after discovery, and in September published an assessment of four separate cases, one of which was only discovered as it prepared for outside review.

    But change a few details in these AI incidents. Imagine the AI models are hosted in data centers in the Persian Gulf, and the company hacked by the AI agents is a cloud provider in Paris, roughly 3,000 miles away.

    Not every firm will disclose incidents. So the French company will only see something similar to what Hugging Face first saw: a powerful intrusion into its systems from third-party infrastructure. The French government now has only a few days to decide if this was done by criminals, an AI experiment gone wrong, or foreign intelligence. The resulting export controls or retaliatory cyberattacks could be globally destabilizing, all because no one knew what was happening.

    This problem will only get worse. While the world’s leading AI developers are in the United States and China, nations such as France, India, and Japan may eventually become capable enough to perform such attacks. Powerful Chinese open-source models mean anyone with sufficient compute could potentially possess the cyber-capabilities to perform such an attack.

    This is why we need an international agreement to report cross-border AI incidents. Such reporting would not be unprecedented. The Organisation for Economic Co-operation and Development has an AI Incidents and Hazards Monitor and is developing a common reporting framework, but its existing Monitor tracks public media reports rather than confidential incidents. The United States and China are currently discussing a bilateral incident reporting proposal, but this remains an early proposal from the American side.

    Indeed, we do this in other domains. After Chernobyl, the world created the 1986 Convention on Early Notification of a Nuclear Accident to notify governments of nuclear accidents with transnational effects. Under the convention, nations notify affected governments and the International Atomic Energy Agency (IAEA) when a nuclear accident threatens a radioactive release that could affect other countries, disclosing details like the time, location, cause, and physical and chemical characteristics of the release and updating information as the situation evolves. In addition, they must identify a point of contact for inquiries.

    These disclosures go to governments and the notifying state can designate information as confidential. The same year as Chernobyl, a chemical fire near Basel poisoned the Rhine for hundreds of kilometers. This also contributed to a regional treaty, the Convention on the Transboundary Effects of Industrial Accidents, which requires designated government contact points to warn others of industrial accidents. Similarly, after SARS, governments agreed to notify the World Health Organization within 24 hours of assessing a health event could constitute an international public health emergency. This type of problem is not new; the international community has addressed it before.

    The 1986 Convention sparked by Chernobyl works when used. When the 2011 Tohoku earthquake hit Japan, later leading to the failure of the Fukushima reactors, the IAEA initiated contact with Japan’s designated contact point less than two hours after the earthquake, and member nations received official updates. While relying on a different part of the agreement than member state notification, this example shows the Convention can work.

    Yet, incident reporting has also fallen short at times. In 2017, European monitors traced a ruthenium-106 plume to the southern Urals in Russia. A later peer-reviewed study in 2019 further corroborated the idea that the accident came from Russia. While Western analysts now effectively assume Russia was the source, Rosatom has never acknowledged the incident.

    A cross-border AI incident convention could follow the more successful cases of this model, with governments, major compute providers, and AI companies confidentially notifying affected states, designating internal leads on the incident, and granting greater technical details to affected parties. Such a convention should also allow suspected victims of an AI attack to disclose details to help identify which actors may be involved in an attack. The Budapest Convention on Cybercrime could serve as a foundation. It already requires its members to maintain a 24/7 contact point for cross-border investigations, and an AI incident channel could mimic this approach. The challenge is that China has never joined. In contrast, the key to the nuclear disclosure regime is that the major nuclear powers signed it.

    There are good reasons to be skeptical about an incident-reporting channel. One risk is that AI labs will not disclose incidents that may incriminate them. But other fields have addressed this issue. The International Civil Aviation Organization’s Convention on International Civil Aviation has an annex that requires countries where a plane accident happened to notify affected countries with a minimum of delay, and declares that a follow-on safety investigation exists only to prevent future accidents rather than issue blame. An AI incident hotline could loosely model this mechanism. Indeed, it could provide some sorely needed credibility to the industry.

    Another concern is that foreign governments may use incident reporting as an alibi, claiming hostile cyber-actions were AI incidents. Yet AI incidents often have distinct features: Hugging Face, for example, was able to discern that the hack came from an agent, suggesting a false notification could be checked against technical data. Even if the incident were a purposeful attack, reporting would provide more information than presently collected.

    Above all, the tumultuous state of geopolitics may make implementing an incident-reporting mechanism difficult. Yet if the United States and Soviet Union could agree during the Cold War, there’s no reason we could not do so today.

    The next AI incident will likely come without warning. Governments shouldn’t be guessing about who’s responsible.

    IncidentReporting key safety standards
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Tom Watson’s move to Palantir is the latest sign of how far the rot has spread in UK politics | Clive Lewis

    Abandoned, dismissed and gaslighted: there is no excuse for the way ME sufferers have been betrayed | George Monbiot

    We’re in a crisis of loneliness – but is buying friends on an app likely to help solve it? | Elle Hunt

    The west is in freefall – and the worst part is that we were warned, but chose not to listen | Owen Jones

    Germany Under Friedrich Merz Has Lost Its Authority at Home and Abroad

    Britain would not cut up the Bayeux tapestry. So seize this moment and reunite the Parthenon sculptures in Greece | Kyriakos Mitsotakis

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later

    September 24, 2026

    OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

    September 24, 2026

    Solana Foundation Hires Binance’s Former Global CMO for Institutional Push

    September 24, 2026

    NASA to Study Human Health, Performance During Crew-13 Mission

    September 24, 2026
    Latest Posts

    Spain’s Pedro Sánchez is a progressive outlier in Europe – and over Ceuta, he is being made to pay for it | Eoghan Gilmartin

    August 6, 2026

    Putin Signs Law For Russia To Regulate Crypto Exchanges

    August 6, 2026

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later

    September 24, 2026

    OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

    September 24, 2026

    Solana Foundation Hires Binance’s Former Global CMO for Institutional Push

    September 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.