A11 · Advisory

AI Incident Tabletop

Ninety minutes, four timed injects, one decision the board has never rehearsed. The 48 hours after an AI story breaks is what decides the D&O claim.

Fee $10,000$7,500 as an add-on to a briefing or retainer
Duration 90 minutesPlus a written after-action report
Who it's for Audit Chair · GCBoard or audit committee

Boards rehearse cyber. Nobody has rehearsed this

Boards run cyber tabletops because regulators and insurers told them to. The first real AI incident most boards face will be one they have never practised: a screening tool exposed as biased in the press, an agent that took an action nobody authorised, a chatbot that gave a customer harmful advice, a model that leaked its training data.

The window that matters is the first 48 hours. What management is asked, what is disclosed and when, who speaks, and what goes in the minutes — those decisions are made under time pressure, usually badly, and they are the ones that get examined afterwards.

This is a decision exercise, not role-play. Directors are not asked to act. They are given four updates in the order they would actually arrive, and after each one they decide.

What you get

  • Setup — 10 minutes

    The board's role, ground rules, and the incident begins.

  • Four timed injects — 60 minutes

    A journalist's email, the GC's first call, a regulator's inquiry, a customer's post. After each, the board decides: what do we ask management, what do we disclose, who speaks, what goes in the minutes.

  • Debrief — 20 minutes

    What went well and what was missing. It is almost always the same three: no inventory, no named owner, no disclosure playbook.

  • Written after-action report

    Within a week, to the GC first. Three recommended fixes, ranked. Private and constructive — it is not circulated beyond the board without your say-so.

Scope

Fixed on both sides. Anything outside it is a separate engagement, quoted separately.

Included

  • Scenario selection and light customisation
  • 90-minute facilitated session
  • Four scripted injects with timing
  • Facilitated debrief
  • Written after-action report with three fixes
  • Sector variants for pharma and banking

Not included

  • A crisis communications plan
  • Incident response tooling or implementation
  • Management-level tabletops (this is board-level)
  • Media training
  • Remediation of the gaps it surfaces
  • Legal advice

How it runs

T–2 weeksScenario selection with the GC. Light customisation — company name, sector, real tool categories.
The day90-minute session with the board or audit committee.
T+1 weekAfter-action report to the GC, with three recommended fixes.

Common questions

What are the two scenarios?

Biased hiring tool. A former applicant's lawyer files a class action citing NYC Local Law 144; the company never ran the bias audit.

Rogue agent. An internal AI agent with procurement permissions placed orders nobody approved; the vendor says it worked exactly as configured.

Pharma and banking variants are available on request.

Our directors dislike role-play.

So do we. Nobody is asked to play a part or improvise. The injects are short and factual, and the board does what a board does — asks questions and makes decisions. We frame it as a decision exercise for exactly this reason.

What if it goes badly and exposes real gaps?

That is the value, and it is why the debrief is private and the report goes to the GC first. A board that discovers it has no named incident owner in a rehearsal is in a far better position than one that discovers it live.

Should we do the briefing first?

Usually, yes. The half-day briefing establishes the oversight framing; the tabletop tests it. Bundled together they are $22,500, and many boards run both on the same day.

Rehearse the 48 hours

Ninety minutes now, against the alternative of finding out live.