On a Friday afternoon, the AI system serving the firm's largest client began producing visibly wrong outputs, and it was the client who noticed first. For a firm where one relationship carried a decisive share of revenue, the incident was not a technical event. It was an existential one.
A small private firm of about forty people. One flagship client. No dedicated risk function. The only preparation in place was modest: a one-page first-hour runbook adopted from the free tier a quarter earlier, and a named person with the authority to stop a system without asking permission.
That modest preparation decided the outcome. The system was contained within the hour: paused, evidence preserved, the decision logged. The client received a factual holding statement the same afternoon, before rumor could outrun the facts, and the post-incident review was shared with them in full the following week. Contain before you explain, then explain completely.