ETSI TS 104 158-1 V1.1.1 (2026-03)
Securing Artificial Intelligence (SAI); AI Incident Reporting; Part 1: AI Common Incident Expression (AICIE) Global Framework
Securing Artificial Intelligence (SAI); AI Incident Reporting; Part 1: AI Common Incident Expression (AICIE) Global Framework
DTS/SAI-0020
General Information
- Status
- Not Published
- Technical Committee
- SAI - Securing Artificial Intelligence TC
- Current Stage
- 12 - Citation in the OJ (auto-insert)
- Due Date
- 08-Mar-2026
- Completion Date
- 16-Mar-2026
Frequently Asked Questions
ETSI TS 104 158-1 V1.1.1 (2026-03) is a standard published by the European Telecommunications Standards Institute (ETSI). Its full title is "Securing Artificial Intelligence (SAI); AI Incident Reporting; Part 1: AI Common Incident Expression (AICIE) Global Framework". This standard covers: DTS/SAI-0020
DTS/SAI-0020
ETSI TS 104 158-1 V1.1.1 (2026-03) is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
TECHNICAL SPECIFICATION
Securing Artificial Intelligence (SAI);
AI Incident Reporting;
Part 1: AI Common Incident Expression (AICIE)
Global Framework
2 ETSI TS 104 158-1 V1.1.1 (2026-03)
Reference
DTS/SAI-0020
Keywords
artificial intelligence, cybersecurity
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16
Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871
Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
No representation or warranty is made that this deliverable is technically accurate or sufficient or conforms to any law
and/or governmental rule and/or regulation and further, no representation or warranty is made of merchantability or fitness
for any particular purpose or against infringement of intellectual property rights.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.
Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and
microfilm except as authorized by written permission of ETSI.
The content of the PDF version shall not be modified without the written authorization of ETSI.
The copyright and the foregoing restriction extend to reproduction in all media.
© ETSI 2026.
All rights reserved.
ETSI
3 ETSI TS 104 158-1 V1.1.1 (2026-03)
Contents
Intellectual Property Rights . 4
Foreword . 4
Modal verbs terminology . 4
Executive summary . 4
Introduction . 5
1 Scope . 6
2 References . 6
2.1 Normative references . 6
2.2 Informative references . 6
3 Definition of terms, symbols and abbreviations . 8
3.1 Terms . 8
3.2 Symbols . 9
3.3 Abbreviations . 9
4 Existing Ecosystem . 9
4.1 Cybersecurity information exchange models . 9
4.2 AI incident information exchange implementations . 10
4.3 AI Incident information exchange obligations . 10
4.3.1 The exchange obligation ecosystem . 10
4.3.2 EU Artificial Intelligence Act . 11
4.3.3 ETSI TS 104 223, UK DSIT Code of Practice . 12
5 AI Common Incident Expression (AICIE) Framework . 13
5.1 The AICIE Framework architecture . 13
5.2 AICIE Framework Resource Record Format and Values . 13
5.2.0 Introduction. 13
5.2.1 AICIEverison . 13
5.2.2 AICIEresourcetype . 14
5.2.3 AICIEresourcename. 14
5.2.4 AICIEresourceaddress . 14
5.2.5 AICIEresourcecontact . 14
5.2.6 AICIEresourceaccess . 14
5.2.7 AICIEresourceadd . 14
Annex A (normative): AICIE Framework Resource Record JSON Format V1.0.1 . 15
Annex B (informative): ETSI AICIE Framework Resource Record Example . 16
Annex C (informative): Bibliography . 17
History . 18
ETSI
4 ETSI TS 104 158-1 V1.1.1 (2026-03)
Intellectual Property Rights
Essential patents
IPRs essential or potentially essential to normative deliverables may have been declared to ETSI. The declarations
pertaining to these essential IPRs, if any, are publicly available for ETSI members and non-members, and can be
found in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to
ETSI in respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the
ETSI IPR online database.
Pursuant to the ETSI Directives including the ETSI IPR Policy, no investigation regarding the essentiality of IPRs,
including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not
referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become,
essential to the present document.
Trademarks
The present document may include trademarks and/or tradenames which are asserted and/or registered by their owners.
ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no
right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does
not constitute an endorsement by ETSI of products, services or organizations associated with those trademarks.
DECT™, PLUGTESTS™, UMTS™ and the ETSI logo are trademarks of ETSI registered for the benefit of its
Members. 3GPP™, LTE™ and 5G™ logo are trademarks of ETSI registered for the benefit of its Members and of the
3GPP Organizational Partners. oneM2M™ logo is a trademark of ETSI registered for the benefit of its Members and of ®
the oneM2M Partners. GSM and the GSM logo are trademarks registered and owned by the GSM Association.
Foreword
This Technical Specification (TS) has been produced by ETSI Technical Committee Securing Artificial Intelligence
(SAI).
The present document is part 1 of a multi-part deliverable covering AI Incident Reporting, as identified below:
Part 1: "AI Common Incident Expression (AICIE) Global Framework";
Part 2: "AI Common Incident Expression (AICIE) Common Container";
Part 3: "AI Common Incident Expression (AICIE) Security Container".
Modal verbs terminology
In the present document "shall", "shall not", "should", "should not", "may", "need not", "will", "will not", "can" and
"cannot" are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of
provisions).
"must" and "must not" are NOT allowed in ETSI deliverables except when used in direct citation.
Executive summary
The present technical specification establishes a design paradigm for openness, diversity, extensibility, and
interoperability among AI reporting communities by creating a first part establishing a global decentralised,
autonomous framework for sharing structured AI incident information. The objective is described as a framework
designed to provide incentives to collaborate on AI incidents and exist as "connective tissue for sharing."
ETSI
5 ETSI TS 104 158-1 V1.1.1 (2026-03)
The preparation of the present document made clear that there were was a basic bifurcation existed between the needs
of AI incident information for "AI safety" and for "AI security". It was also clear that the requirements would be
constantly evolving and that three different user communities existed:
1) third-party incident information collectors;
2) sovereign repository instantiations by government authorities; and
3) companies with AI offerings dealing with vulnerabilities and security.
The common resource framework record described in Clause 5.2 is both extremely minimal and flexible as well as
decentralised and self-replicating on any connected server. It enables any kind of AI incident related resources to be
made known to others in almost any manner and basis of their choosing, including similar lists, specifications, and
repositories of information "containers". This enables a dynamic and autonomous ensemble of multiple AI reporting
standards, exchange mechanisms and repositories to emerge and communicate among different communities. The
approach is derived from the newly emerged Global Common Vulnerability and Exposures (GCVE) community that is
well-established and scales effectively.
A subsequent part of the present document provides a specification for a generic common incident reporting data record
container derived from work of the OECD and other current providers of AI incident reporting.
Introduction
The OECD published in 2025 a significant report that summarized several years of study by itself and numerous other
organizations urging a Common Framework for AI Incident Reporting. See [i.10] and in Annex C (Bibliography). The
OECD structure is reflected in the container specification in ETSI TS 104 158-2 [i.33]. Implementing this capability is a
matter of some substantial interest to the European Commission as its Artificial Intelligence AI Act requires several
incident reporting actions. See [i.2]. Incident reporting requirements are also instantiated in NCSC AI security guides
and Commonwealth legislative instruments and ETSI's own Baseline Cyber Security Requirements for AI Models and
Systems [i.1].
The structured expression of cyber incidents was one of the earliest standards developed among incident reporting
teams. Its evolution to exchange vulnerability information and mitigations was a significant next step. The present AI
Common Incident Expression (AICIE) specification draws upon that work and intended to meet the requirements for a
compatible and interoperable common framework that also supports government and industry compliance provisions.
The AI Common Incident Expression Framework in the present document is intended to support very diverse kinds of
AI incident resources and communities of interest, threats, and threat actors that go well beyond the cybersecurity
domain. It makes use of a decentralised open architecture pioneered by the Global CVE community supported by the
CIRCL Computer Incident Response Center Luxembourg. See [i.8]. Specifying the present framework designs for
openness, diversity, extensibility, and interoperability. This approach enables a dynamic and autonomous ensemble of
other AI reporting standards, exchange mechanisms and repositories to emerge and communicate among different user
communities.
ETSI TS 104 158-2 [i.33] provides an AI incident reporting information container. It consists of a generic common
incident reporting data record container based on the OECD reporting model structure.
ETSI
6 ETSI TS 104 158-1 V1.1.1 (2026-03)
1 Scope
The present document provides a technical specification for an AI Common Incident Expression Framework for AI
Incident Reporting.
2 References
2.1 Normative references
References are either specific (identified by date of publication and/or edition number or version number) or
non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the
referenced document (including any amendments) applies.
Referenced documents which are not found to be publicly available in the expected location might be found in the
ETSI docbox.
NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee
their long-term validity.
The following referenced documents are necessary for the application of the present document.
[1] ETSI Collaborative tools for standardized technologies.
[2] JSON Schema: "Specification".
[3] IETF RFC 3986 (January 2005): "Uniform Resource Identifier (URI): Generic Syntax".
2.2 Informative references
References are either specific (identified by date of publication and/or edition number or version number) or
non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the
referenced document (including any amendments) applies.
NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee
their long-term validity.
The following referenced documents may be useful in implementing an ETSI deliverable or add to the reader's
understanding, but are not required for conformance to the present document.
[i.1] ETSI TS 104 223 (V1.1.1): "Securing Artificial Intelligence (SAI); Baseline Cyber Security
Requirements for AI Models and Systems".
[i.2] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying
down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008,
(EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and
Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act).
[i.3] UK DSIT: "AI Cyber Security Code of Practice".
[i.4] UK NCSC: "Guidelines for secure AI system development".
[i.5] Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on
measures for a high common level of cybersecurity across the Union, amending Regulation (EU)
No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2
Directive).
ETSI
7 ETSI TS 104 158-1 V1.1.1 (2026-03)
[i.6] Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 laying down rules for
the application of Directive (EU) 2022/2555 as regards technical and methodological requirements
of cybersecurity risk-management measures and further specification of the cases in which an
incident is considered to be significant with regard to DNS service providers, TLD name registries,
cloud computing service providers, data centre service providers, content delivery network
providers, managed service providers, managed security service providers, providers of online
market places, of online search engines and of social networking services platforms, and trust
service providers.
[i.7] Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on
the resilience of critical entities and repealing Council Directive 2008/114/EC.
[i.8] GCVE.EU: "GCVE: Global CVE Allocation System".
[i.9] Cornell University SarXiv:2503.16861v1 [cs.AI], Sean McGregor et al.: "In-House Evaluation Is
Not Enough: Towards Robust Third-Party Flaw Disclosure for General-Purpose AI",
21 March 2025.
[i.10] OECD: "Towards a Common Reporting Framework for AI Incidents", OECD Artificial
Intelligence Papers, February 2025, No. 34.
[i.11] OECD: "AIM: AI Incidents and Hazards Monitor".
[i.12] OECD: "Defining AI Incidents and Related Terms", OECD Artificial Intelligence Papers,
May 2024, No. 16.
[i.13] McGregor, S. (2021): "Preventing Repeated Real World AI Failures by Cataloging Incidents: The
AI Incident Database", Proceedings of the AAAI Conference on Artificial Intelligence, 35(17),
15458-15463.
[i.14] OECD Framework for the Classification of AI Systems, February 2022, No. 323.
[i.15] NCSC: "Where to Report a Cyber Incident".
[i.16] NCSC: "Responding to a cyber incident - a guide for CEOs".
[i.17] Confédération Suisse Federal Office for Cybersecurity BACS: "Information on the reporting
obligation".
[i.18] CSET: H. Frase & R.B. L. Dixon: "AI Incidents, Key Components for a Mandatory Reporting
Regime", January 2025.
[i.19] OWASP Gen AI Incident/Exploit Round-up Submission.
[i.20] Recommendation ITU-T X.1500: "Overview of cybersecurity information exchange".
[i.21] ETSI TR 104 003: "Cyber Security (CYBER); The vulnerability disclosure ecosystem".
[i.22] ETSI TR 103 331: "Cyber Security (CYBER); Structured threat information sharing".
[i.23] CISA: "Cybersecurity Incident & Vulnerability Response Playbooks".
[i.24] NIST AI600-1: "Artificial Intelligence Risk Management Framework: Generative Artificial
Intelligence Profile".
[i.25] AIID: "AI Incident Database".
[i.26] MIT: "MIT AI Risk Repository".
[i.27] AVID: "AI Vulnerability Database".
[i.28] OECD: "Overview and methodology of the AI Incidents and Hazards Monitor".
[i.29] MIT: "MIT AI Risk Repository".
[i.30] Kaggle: "AI Incident Database".
ETSI
8 ETSI TS 104 158-1 V1.1.1 (2026-03)
[i.31] JSON-LD.org: "JSON for Linking Data".
TM
[i.32] IEEE CSR: Sharkov: "Unveiling the invisible: Knowledge Graph-Driven Discovery of Hidden
Cascade Risks in Critical Infrastructure Supply Chains".
[i.33] ETSI TS 104 158-2: "Securing Artificial Intelligence (SAI); AI Incident Reporting; Part 2: AI
Common Incident Expression (AICIE) Common Container".
3 Definition of terms, symbols and abbreviations
3.1 Terms
For the purposes of the present document, the following terms apply:
Additional Data Publication (ADP): set of additional structured information that enriches existing AICIE records
AI common incident expression identifier: alphanumeric string that uniquely identifies an AI Incident using the
present document
AI disaster: serious AI incident that disrupts the functioning of a community or a society and that may test or exceed its
capacity to cope, using its own resources. The effect of an AI disaster can be immediate and localized, or widespread
and lasting for a long period of time
NOTE: More details available in [i.12].
AI hazard: event, circumstance or series of events where the development, use or malfunction of one or more AI
systems could plausibly lead to an AI incident, i.e. any of the following harms:
a) injury or harm to the h
...




Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.
Loading comments...