Your First AI Incident Is a Resilience Test, Not a Tech Failure

By Shevaun Betzler on

For cybersecurity marketing and communications leaders, AI is already part of the job. We’re using it to draft, research, summarize, analyze, and ultimately accelerate work. Most of the time, it works as intended.

The real question is what happens when it doesn't.

At some point, an AI-generated mistake will make its way into the public domain. It might be an inaccurate claim in a thought leadership piece, a fabricated citation, an off-key message, or information that should never have been published. When that happens, the instinct inside the organization will likely be to treat it as a technology problem: What tool produced the error? Where did the prompt go wrong? Who missed it in review?

Those questions matter, but they aren’t the questions your audience will ask.

Instead, they’ll look at the speed and integrity of your organization’s response. They will judge that response long before your teams have finished tracing the technical root cause. That makes your first AI incident a communications test as much as a technology test.

Consider what happened with EY Canada in May 2026. AI-detection firm GPTZero published an investigation into an EY Canada report on loyalty-program fraud, finding widespread fabrication and misattribution of citations, broken links and text identified as AI-generated. EY subsequently removed the report from its website and said it was reviewing the circumstances that led to its publication.

The important detail is what the failed asset was: a thought leadership report designed to demonstrate expertise and credibility. The failure surfaced in the very thing the content was meant to establish: trust.
That is what makes AI incidents particularly relevant to marketing and communications leaders. The failure may originate in a tool or workflow, but the moment it becomes visible outside the organization, it becomes a reputation issue.

Your first hour matters

The best time to decide how you’ll handle an AI incident is before you have one.

Start with ownership. Who speaks for the organization when something goes wrong? It’s not necessarily the person who created the content or the team that owns the technology. Decide whether the response belongs with marketing and communications, the relevant practice leader, or an executive, and establish that escalation path before there is pressure to move.

Then decide what you can say before you have every answer. In a fast-moving situation, waiting for perfect information can leave a vacuum that someone else will fill. A credible holding statement can acknowledge the issue, communicate that it is being reviewed, and give your team the space to establish the facts. It’s not meant to be the final response, and it doesn’t need to pretend that you know more than you do.

The next question is how much to disclose. There is a meaningful difference between acknowledging a mistake, explaining what happened and telling people what you are doing to prevent it from happening again. The right response depends on the severity of the issue and what you can substantiate, but the principle is consistent: credibility comes from saying what you know, being clear about what you don’t and showing that you’re taking action. And when people have been affected, lead with empathy. Acknowledging the impact — and apologizing when warranted — can matter as much as explaining what went wrong.

Finally, think about visibility. Taking down inaccurate content may be necessary, but removal is not a communications strategy. If something disappears without explanation, your audience is left to connect the dots themselves. In a sector where credibility is everything, silence can deepen the trust problem you are trying to rectify.

The response become part of your reputation

An AI incident doesn’t have to become a lasting reputational problem. In some cases, the way an organization handles a mistake can strengthen trust because it demonstrates accountability, transparency, and good judgment under pressure.

That is especially important in cybersecurity, where customers are already evaluating whether they can trust an organization to protect them when something goes wrong. How you operate when the stakes are high tells them more than anything you say when things are calm.

The strongest responses rarely come from one function operating alone. Marketing, communications, cybersecurity, legal, technology, and executive leadership each see a different part of the problem. When those teams have established roles, clear escalation paths and a shared understanding of how to communicate, organizations can move with far more confidence when an incident occurs.

Our recent survey of marketing and communications leaders across cybersecurity found that one-third do not believe their organizations are prepared to respond well in an emergency, even as AI becomes increasingly embedded in the way teams work.

Eventually, AI will create a moment that requires judgment, accountability, and a coordinated response. It is critical to close that readiness gap now.

How you respond to your first AI incident will tell your audience a lot about your organization. The question is whether you get to decide what it says.

so how are cybersecurity marketing and communications leaders preparing for this moment?

To find out, Highwire surveyed marketing and communications leaders across the cybersecurity industry about how they’re adopting AI, where they feel prepared, where they still need support, and how they’re thinking about accountability when things go wrong. The result is a new view into how the market is navigating the growing responsibility that comes with AI.


The Weight of the Remit brings those findings together, giving leaders a chance to see how their peers are approaching AI readiness, incident response, accountability, and trust. For teams figuring out their own approach, it offers a useful benchmark for understanding where the market is moving and where gaps may still exist.

The findings make one thing clear: Readiness can’t start when the incident does.

Explore the full findings in The Weight of the Remit and see how your organization compares on AI readiness, accountability, and trust. Download the report.