Wrivio
Get Wrivio
7 min readBy Wrivio Team

How to Tell a Client That AI Was Involved in an Incident

Somebody pasted a client’s contract into a consumer AI tool. Or a generated figure went into a deliverable and was wrong. Or an AI feature in a vendor’s product processed data nobody had approved.

These are now ordinary incidents, and they arrive with an extra difficulty. The client’s reaction to the underlying event is one thing. Their reaction to the word “AI” is another, and it is usually stronger than the facts warrant.

The message you write in the next hour determines which of those two reactions you are managing for the rest of the relationship.

Decide What Actually Happened Before You Write

Most bad incident notifications are bad because they were written before the writer knew what to say, and the uncertainty leaks out as hedging.

Answer four questions on paper first:

What was exposed or wrong. Specifically: which document, which fields, which figure. Not “some information”.

When, and when you found out. Both dates. The gap between them is what a client will focus on and you cannot hide it.

Where it went. Which system, operated by whom, under what terms, and what that provider retains. This is the question with an actual answer, and it is the one clients ask second.

What you have done and what you will do. Actions taken, actions planned, with dates.

If you cannot answer one of these, say so explicitly in the notification rather than writing around it. “We do not yet know X, and I will confirm by Thursday” is far better received than a sentence engineered to avoid the gap.

The structure is the same as any incident report; the escalation-free version is in how to write an incident report at work.

Do Not Lead With The Technology

The most common error is making the notification about AI. It centers the most alarming and least relevant fact.

A client cares that their contract terms were disclosed to a third party. Whether the third party was an AI provider, a file-sharing service, or a misdirected email is secondary to them, even though it feels primary to you. Leading with “an AI tool was involved” invites a conversation about AI policy instead of about the actual exposure and remedy.

State what happened, then name the system as a fact in the sequence.

The Example

Before:

Hi Sarah,

I wanted to reach out proactively about something that’s come up. We’ve recently become aware that there may have been an issue with how some of your project documentation was handled in relation to our use of AI-assisted tools. We take data security extremely seriously and are conducting a full review. We don’t believe there is any significant risk but wanted to make you aware in the interests of transparency. Happy to discuss.

After:

Sarah,

On 28 July a member of our team pasted section 4 of the Henderson services agreement, including the pricing schedule, into a consumer AI assistant to summarize it. That tool is not on our approved list. We identified this on 1 August during a routine review.

The text was sent to the provider’s servers. Under their consumer terms, content may be retained and may be used to improve their services. We have submitted a deletion request and will confirm the outcome.

No other client documents were involved. We have checked the three months of activity available to us.

Actions taken: the tool is blocked on our devices as of 1 August, and confidential client text is now handled by a tool that runs the model locally with no transmission.

I will send you the deletion confirmation by 12 August. Happy to speak before then if useful.

The second version is harder to write and easier to receive. It names the document, the date, the discovery date, the exposure, the remedy, and a follow-up date. It does not say “we take security seriously”, which is a sentence that appears exclusively in messages where something went wrong.

The Sentences To Cut

Four patterns that damage credibility in this genre specifically.

“Out of an abundance of caution.” Universally read as “we are legally required to tell you this and want it to sound voluntary”.

“There may have been.” If you know, say. If you do not know, say that you do not know, and by when you will.

“We take X extremely seriously.” Contributes nothing and signals a template.

“No significant risk.” A risk assessment is the client’s to make about their own information. Give them the facts and let them assess it. Asserting the conclusion reads as minimizing.

The Context For This

A Wrivio Context for incident notifications could say:

Rewrite this as a factual client incident notification. Lead with what happened and when, then what was exposed, then what has been done. Keep every date, document name, figure, and system name exactly as written. Do not add reassurance, risk assessments, or the phrase “out of an abundance of caution”. Do not soften a factual statement into a possibility. Keep the result no longer than the input.

Press Ctrl+Shift+Space, paste the draft, and check the diff. Two failures to watch for here, and they are opposite: models soften factual statements into hedged ones because the register feels defensive, and models add reassurance because incident text reads as needing comfort. Both make the message worse. The diff makes both visible.

For a rewrite of a message like this, use local mode. The draft names a client, a document, and an exposure, which puts it in exactly the category that should not be transmitted while you are apologizing for transmitting something.

Sending It

Send it before you have the full remediation done. A notification with a follow-up date beats a complete report a week later, because the delay itself becomes an issue.

Send it from the person who owns the relationship, not from a compliance address. A notification from an unfamiliar sender reads as institutional distancing.

And check whether you have a notification obligation with its own deadline and required content. If personal data was involved, Article 33 of the GDPR sets a 72 hour clock for notifying the supervisory authority, which is a separate duty from telling the client. Several client agreements now also include AI-specific clauses with their own notice requirements. AI clauses in client contracts and what they mean covers what to look for, and how to write a complaint email that gets resolved is the mirror image if you are on the receiving end.

Common Questions

Should I tell a client that AI was specifically involved?

Yes, if it is relevant to what was exposed or to how they should assess it. State it as a fact in the sequence rather than leading with it, because leading with it redirects the conversation away from the actual remedy.

How fast should the notification go out?

Once you can answer what happened, when, where it went, and what you have done. Do not wait for full remediation, and check whether your contract sets a deadline.

Should I include a risk assessment?

Give the facts and your actions. Whether the risk is significant is the client’s judgment about their own information, and asserting it for them reads as minimizing.

What if I do not know the full extent yet?

Say so explicitly, with a date by which you will know. A stated gap is much better received than a sentence written to obscure one.

Download Wrivio for Windows to draft sensitive client notifications with a local model, so the incident text does not become a second incident.