GDPR gives you 72 hours. Professional responsibility obligations activate immediately, with no grace period at all. And the American state law that was supposed to anchor this entire conversation collapsed in May 2026, leaving a gap most crisis teams have not yet noticed. Here is the multi-framework notification matrix your team needs before the event, not during it.
TL;DR — Read This Before Your Crisis Team Needs a Clock They Don’t Have
Most organisations responding to an AI governance incident correctly identify one notification obligation and miss the others running in parallel. GDPR’s 72-hour clock — measured from the moment the organisation has a reasonable degree of certainty that personal data was compromised, not from when the incident occurred — is the most widely known and the most consistently misapplied, because teams frequently start the clock too late, at “confirmed certainty” rather than “reasonable awareness.” Professional responsibility obligations for lawyers and other regulated professionals using AI in client-facing work have no grace period whatsoever; they apply from the moment of awareness, full stop. And the regulatory landscape that many crisis teams have been building toward — Colorado’s original AI Act — was repealed in May 2026 before it ever took effect, replaced by a narrower, later-starting disclosure framework that does not carry the same notification clock at all. A notification framework built around outdated assumptions is not a minor documentation gap. It is a missed deadline waiting to happen. This brief maps the active frameworks accurately, flags the ones that have changed since they were last covered, and delivers the matrix your crisis team should be working from this quarter. The complete notification content standard and the privilege-protected documentation sequence for the first 24 hours are in the paid tier.
Picture this: an organisation discovers, through an internal audit, that an AI-assisted tool processing customer data has been logging more personal information than its documented data flow accounted for. The general counsel correctly identifies that this is a GDPR matter and correctly remembers the 72-hour rule. What the team gets wrong is when the clock started. They wait for the forensic investigation to confirm the full scope before beginning the notification clock — treating “confirmed certainty” as the trigger, when the actual legal standard is “a reasonable degree of certainty that a security incident has compromised personal data,” which can exist well before the investigation is complete.
By the time the team files notification, four days have passed since they had enough information to know notification was likely required, even though only thirty-one hours have passed since the investigation technically “confirmed” the scope. The supervisory authority is not interested in the technical confirmation timeline. It is interested in when the organisation had reasonable awareness — and the gap between those two moments is where most missed-deadline findings actually live.
The 72-hour clock is not forgiving of teams who wait for certainty. It rewards teams who notify on reasonable awareness and supplement the notification in phases as the investigation continues — a mechanism the regulation itself explicitly permits. Most crisis teams know the number seventy-two. Far fewer know that the law was built to be started early and updated later, not started late and filed once.
An AI governance incident involving personal data, occurring inside a regulated profession, at a company with securities disclosure obligations, can trigger three or four separate notification regimes simultaneously — each with a different clock, a different trigger, and a different recipient. Treating the incident as a single-framework problem because the first framework identified happens to be the most familiar one is the single most common notification failure this series has documented. The matrix below exists to prevent exactly that narrowing.
GDPR — The 72-Hour Standard, Still the Global Benchmark
Articles 33 and 34 require notification to the relevant supervisory authority within 72 hours of the organisation becoming “aware” of a personal data breach — defined broadly to include accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data. Awareness means a reasonable degree of certainty that a breach affecting personal data has occurred, not full certainty about its scope. Where the breach is likely to result in a high risk to individuals, a separate, less rigidly timed obligation to notify the affected individuals directly also applies, governed by a “without undue delay” standard rather than a fixed 72-hour figure. Failure to notify within the window is itself a separate violation, independent of the underlying breach, carrying its own fine exposure. This standard, now law in several jurisdictions beyond the EU, remains the most influential notification benchmark globally and the one every crisis team should treat as the default starting assumption.
A Correction Worth Making Out Loud — Colorado
Colorado’s original AI Act, signed in 2024, was widely discussed throughout 2025 and early 2026 as the first comprehensive American state AI law, including a 90-day attorney general notification obligation for discovered algorithmic discrimination. That law never actually took effect. Its start date was pushed from February to June 2026, a federal court paused enforcement in late April 2026 pending legislative developments, and on May 14, 2026 the Colorado legislature repealed it outright, replacing it with a narrower automated decision-making technology framework that takes effect January 1, 2027 and is built around consumer notice and a 30-day adverse-outcome explanation right — not the algorithmic discrimination notification clock the original law contained.
If your crisis protocol currently references the original Colorado notification clock, it is referencing a law that no longer exists. This is not a minor citation update. It is the kind of correction that, left uncaught, produces exactly the scope-underestimation error this series has named repeatedly: a team confidently checking a box for an obligation that, as of today, simply is not there — while potentially missing the new framework’s different and later obligations.
A Correction Worth Making Out Loud — The EU AI Act’s High-Risk Timeline
The EU AI Act’s most consequential high-risk system obligations — the ones touching employment, credit, and other consequential-decision AI — were widely understood to take effect on 2 August 2026. On 7 May 2026, EU lawmakers reached a provisional political agreement to delay those obligations to 2 December 2027 for standalone high-risk systems, as part of a broader simplification package. The delay does not touch obligations that are already in force — the Article 5 prohibited practices and the Article 4 AI literacy duties have applied since February 2025, and the general-purpose AI model obligations under Articles 50 through 55 have applied since August 2025. But any crisis protocol or notification matrix built around an August 2026 high-risk compliance deadline needs that single date corrected before the next planning cycle, not after a regulator points it out.
Professional Responsibility — No Grace Period, Ever
For lawyers and other regulated professionals, the obligation to maintain competence in the tools used for client work, to verify AI-assisted outputs before relying on them, and to protect client confidentiality from inadvertent disclosure through AI platforms applies immediately and continuously. There is no 72-hour grace period because there is no notification clock in the conventional sense — the obligation is to have already been diligent, and a discovered failure is assessed against that ongoing standard rather than against how quickly it was reported afterward. This is the framework most likely to be underestimated by teams trained to think in notification windows, because it does not offer one.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.