Berk Bayri

Observation vs. explanation

The split between recording what happened in an AI incident (observation) and the current theory of why (explanation), so early facts are preserved while explanations are revised.

Reporting and explaining are different jobs. An observation record captures what happened: the runtime conditions, the authority the system had, the external effect, how it was detected, immediate containment, and what is known, suspected and unknown. An explanation record holds the current hypotheses, supporting evidence, confidence, root cause and corrective action.

Keeping them apart protects the evidence. The observation should be difficult to improve after the fact: corrections are appended as facts, not rewritten around a later hypothesis. The explanation is expected to change, so it is versioned as understanding grows, including the root cause.

Why it matters

When the first report must contain a finished explanation, early anomalies get delayed, sanitised or lost. Separating the two lets an organization preserve the strange thing before making it make sense, which is the heart of AI incident reporting. Pair it with a separate severity and uncertainty rating.

Read more in The first AI incident report should be incomplete.