Subscribe

Join our newsletter to stay up to date on the latest AI policy articles we publish!

The Case for an International AI Incident Network

October 1, 2026
Summary:
  • Missing the full picture: Frontier AI models are causing harm internationally, but governments lack visibility into incidents beyond their own borders.
  • Safety in numbers: An international network would allow incident data from one country to serve as an early warning signal for all.
  • What to build: The world needs mandatory incident reporting by AI developers in a common format, channels for governments to share information while preserving privacy, and joint cross-border investigations.
  • Path forward: A small group of willing governments should start now, working through forums like the G7, Five Eyes, or the international network of AISIs.

‍

In June 2026, OpenAI models infiltrated non-public sections of an Australian government website and attempted to hack into several others. OpenAI took eight weeks to detect the incident, and another month to inform the Australian government.

The Australia case is not an outlier. OpenAI models have also attempted to meddle with several US government websites, as well as a UN website. Google learned in late July that its models had accessed three companies’ systems in May, but said nothing until the Wall Street Journal reported it publicly in September.

Governments cannot respond effectively to AI incidents if they don’t know they are occurring. They must start treating AI incidents as they treat more conventional harms in nuclear, aviation, and health.

To close the gap, like-minded countries should build an international AI incident network, with the potential to later grow into a wider multilateral regime.

The need for collective institutional learning

The same AI models and systems are deployed across numerous countries at once. This means that a harm observed in one place is often a preview of what will likely happen elsewhere.

The incident caseload is large and rising fast – spanning cyber operations, loss-of-control behaviours, large-scale manipulation, and child safety. The OECD’s incident monitor recorded 598 incidents in January 2026 alone, against 31 in February 2020.

A network that shares findings across borders would turn isolated experiences into early warning signals, and surface patterns no single case reveals. Government agencies that manage AI risk could rehearse crisis decision-making before similar incidents arrive at home. Internationally, a common evidence base would keep countries aligned on shared risks.

Beyond safety, a shared incident record would give governments an evidence base for regulatory intervention, and offer smaller countries visibility into information they could not compel from frontier AI developers by themselves. It could also ease cross-border trade in AI services, allowing AI companies to report incidents once in a common format, rather than separately in every market.

Obstacles to international coordination

China, the EU, Vietnam, Brazil, and the US states of California, New York and Illinois have all enacted or proposed mandatory reporting obligations for serious AI incidents. However, most countries still do not exchange information about AI harms.

The first challenge is jurisdictional. Most countries do not host frontier AI companies, and AI incident evidence is scattered across a global value chain. Without channels to collect and share incident data, governments learn only what companies choose to disclose, or what whistleblowers, journalists, or independent researchers uncover.

The second challenge is information sharing. Many countries have little to share, lacking their own incident monitoring and detection capabilities. There are also no harmonised standards for what information should be shared and how. And the material is sensitive: victims’ identities, users’ private chat logs, and granular system data, which companies guard as commercial intellectual property.

What the network would do

As our recent report outlines, the core elements of an AI incident network should include:

  • A shared way of documenting AI incidents: common terminology, categories, severity thresholds and a minimum set of reported fields. The OECD’s Common Reporting Framework could be a useful starting point.
  • Mandatory domestic reporting for frontier AI companies, alongside serious incident and crisis prevention policies.
  • Information-sharing channels, tiered by sensitivity. Governments and experts need privacy-preserving ways to share incident data with each other, alongside aggregated, anonymised case studies which can be made public for wider learning.
  • The authority to act and coordinate. Governments should empower AI Safety Institutes (AISIs) and their equivalents to obtain incident-relevant data from domestic deployers and incident researchers, share this data with other governments, and run joint investigations and tabletop exercises with counterparts abroad.
Who should be involved?

Getting an AI incident network off the ground doesn’t need everyone at the table or a binding multilateral treaty. Several existing groupings could host a preliminary version.

The International Network for Advanced AI Measurement, Evaluation and Science could develop common terminology, severity scales and reporting fields, but has no mandate for live, sensitive casework.

The G7’s Hiroshima AI Process brings leader-level weight, an economic framing that reaches ministries beyond the AI safety community, and a company-facing channel under the OECD-hosted reporting framework.

The Five Eyes alliance already moves highly sensitive material through trusted channels and includes the US, the world’s leading AI developer. However, anchoring this work in intelligence sharing could make it difficult to extend to civilian regulators.

Beyond these groupings, if even two governments agree on a shared reporting template and start formally exchanging incident information, that would already constitute more international AI incident coordination than exists today.

For instance, bilateral cooperation could build on the existing partnership between the UK AI Security Institute and US Center for AI Standards and Innovation, or between bodies which already enforce incident reporting in their respective jurisdictions, such as the EU AI Office and the California Governor’s Office of Emergency Services. What works in one group could then spread to others through forums like the OECD and the UN Global Dialogue on AI Governance.

The world shouldn’t wait for the US and China

On 25 September, the US and China agreed to a bilateral communication channel for AI incidents and committed to further AI dialogue by November. While the channel is a welcome development, the details remain to be seen, including what counts as an incident and what information each side will provide. Nothing announced so far suggests that other countries will have visibility into what is shared.

An AI incident network would be more effective with US and Chinese involvement. With the two countries that host the largest AI developers at the table, the network could learn from AI model usage logs and pre-deployment evaluations – invaluable inputs for determining the causes of specific incidents.

However, a coalition without the US and China would still capture much of the benefit. AI-induced harms often surface in deployment, so every country holds a vantage point on its own users and sectors.

Future AI incidents and crises will not wait for a multilateral treaty or for the US and China to expand their bilateral channel into a broader network. Governments should start building this network now. We invite government decision-makers to engage with our full report and take up its recommendations.

Authors
Omer Bilgin
Analyst, AI Governance, The Future Society
Caio Machado
Senior Associate, AI Governance, The Future Society; affiliate at the Berkman Klein Center for Internet & Society at Harvard University
George Gor
Associate, AI Governance, The Future Society
Subscribe to our newsletter
Share
This is some text inside of a div block.

Have something to share? Please reach out to us with your pitch.

If we decide to publish your piece, we will provide thorough editorial support.