In one survey, half of companies had no documented crisis plan at all, and rehearsal is rarer still. AI fixes that problem cheaply, which is a far better use of it than letting it write your holding statement at 11pm.
The instinct with AI and crisis comms is to reach for it in the moment, which is exactly backwards. The moment is when your facts are still moving, your liability is highest and your tolerance for a confident wrong sentence is zero. The real value sits in the preparation nobody does: in Capterra’s survey of US business leaders, only 49% had a documented crisis communications plan, and rehearsal is rarer still. AI makes that preparation cost hours instead of weeks. This guide covers what to build in advance, what AI can safely do during a live incident, the tribunal ruling and the incidents that define where the line sits, the deepfake scenario missing from every plan written before 2024, and the fact that your two regulatory clocks start at different moments.
Sprout Social surveyed 2,250 social media users across the US, UK and Australia in May 2026 and found something that should reorganise how most companies think about this. 84% said a brand’s response speed directly affects their view of the crisis. 64% said it matters that brands respond publicly on social media rather than through a press release or a statement buried on a website.[1]
The good news in the same research is that recovery is real. 51% of consumers would consider buying from a brand within a few months of a crisis being properly addressed, and 20% would come back within days.[1] People are more forgiving than comms teams assume. They are just not patient.
What is at stake, meanwhile, is not a news cycle. Weber Shandwick’s 2020 research with KRC, covering 2,227 executives across 22 markets, found they attributed on average 63% of their company’s market value to reputation.[2] And crises are not rare events you can plan around. PwC’s global survey of 1,812 business leaders across 42 countries found 91% had experienced at least one significant disruption beyond COVID, averaging 3.5 disruptions in two years, with 76% saying their most serious one had a medium to high operational impact.[3]
Here is the actual problem, and it is not a technology problem.
Capterra surveyed 243 US business leaders at director level and above in January 2023. Only 49% had a formal, documented crisis communications plan. 28% had something informal and undocumented. 23% had nothing at all or did not know.[4]
Deloitte’s 2018 study of more than 500 senior crisis management, business continuity and risk executives found the same confidence gap from the other end. 84% said their organisation had a crisis management plan, and nearly 90% were confident they could handle a corporate scandal, yet only 17% had actually tested that scenario in a simulation.[5] Organisations that involved their board in crisis exercises were far more likely to report crises declining over the decade. That study is old now, and it surveyed senior executives at large organisations rather than the businesses most of us run, but nothing in the more recent survey data suggests rehearsal has become common since.
There is one more finding from the Capterra data that quietly demolishes the single-scenario plan. Crisis triggers were spread across cyberattacks (28%), technology failures (22%), workplace violence or threats (19%), health-related issues (16%), natural disasters (9%) and public relations crises (6%).[4] If you wrote your plan around one scenario, you have prepared for a coin flip.
And yet the numbers on the other side of that research are extremely encouraging: of leaders who actually activated a plan, 98% said it was effective, including 77% who said it was very effective.[4] The plans work. Most companies just do not have one, because writing one takes a fortnight of somebody’s life and there is always something more urgent.
That is the sentence AI changes. Not the response. The preparation.
Everything below is peacetime work. A human reviews it with time to think, mistakes cost nothing, and the output is reusable. This is where I would put 80% of your AI effort.
Most plans cover the three crises the leadership team has personally experienced. Give an AI your business model, your suppliers, your channels, your regulatory footprint and your customer base, and ask it to generate forty plausible failure scenarios grouped by type, including ones you have not experienced. Then have your team score each on likelihood and severity. You will get a handful of genuinely uncomfortable additions to the list, which is the point.
This is the deliverable that actually saves you at 11pm. A grid: scenario down the side, audience across the top (customers, staff, investors, regulator, press, partners), with a pre-approved holding statement in each cell. AI is genuinely excellent at generating the first version of that grid, because it is a large, structured, repetitive drafting job with a clear format.
What matters is that a human edits every cell and legal signs the sensitive rows, in peacetime, when there is time. A holding statement written and approved in March is worth ten written in a panic in October.
This is my favourite use and almost nobody does it. The usual barrier is cost, because a properly facilitated exercise is not cheap.
You can run a decent version yourself in ninety minutes. Ask the AI to act as facilitator: it presents a scenario, your team responds, and every fifteen minutes it injects a complication (a journalist calls, a staff member posts on LinkedIn, the fix does not work, a customer’s video goes viral). Ask it to end by producing a list of every question your team could not answer. That list is your action plan, and it is worth more than the exercise itself.
Dark site page, email templates, an internal FAQ for whoever answers the phone, social bios that can be swapped, an out-of-hours contact tree. Boring, quick with AI, and completely useless if produced during the incident.
| Phase | AI does | A named human does |
|---|---|---|
| Before | Scenario generation, message matrix drafts, tabletop facilitation, template production, translation | Edits every cell, gets legal sign-off, owns the plan and the review date |
| During | Social listening and sentiment triage, summarising inbound volume, first drafts from approved templates, translating approved copy | Verifies every fact, decides materiality, approves every word before it publishes, speaks to press and regulators |
| After | Coverage analysis, sentiment recovery tracking, drafting the post-incident review, spotting patterns across inbound | Decides what changes, updates the plan, briefs the board |
Division of responsibility across the three phases of an incident. The structure follows the crisis communication and crisis leadership clauses of ISO 22361:2022.[6]
Once something is actually happening, the useful list gets short. Four things.
Monitoring and triage. This is the strongest live use case by a distance. Volume is the enemy in the first hours: hundreds of mentions, comments, emails and messages arriving faster than a small team can read them. AI clusters that into themes, flags the accounts with reach, tracks sentiment movement over time, and tells you which specific claim is spreading. That is real work, it is fast, and being slightly wrong about a sentiment score costs you nothing.
Summarising inbound for the people making decisions. Your decision-makers do not need 400 comments. They need to know that three distinct allegations are circulating, which one has traction, and what the most-shared post actually says. A rolling AI summary every thirty minutes, checked by a human before it goes into the room, is genuinely valuable.
First drafts from your approved templates. Note the phrasing. Not “write a statement.” Take the pre-approved holding statement from your matrix, feed it the confirmed facts, and ask for an adaptation for a specific channel and audience. You are asking it to adapt approved language, not to originate a position. Those are different jobs with completely different risk profiles.
Translation and channel adaptation. If you operate in multiple markets, translating an approved statement is the fastest hour AI will ever save you, provided a native speaker reviews it before it goes out. Our guide to translating marketing content with AI covers the review process properly.
For the customer-facing side of a live incident, our guides on AI in customer service and handling reviews and testimonials cover the day-to-day version of the same problem.
I want to make this argument with cases rather than opinions, because the opinion version is easy to wave away.
The liability is already settled. In Moffatt v. Air Canada, decided in February 2024, the British Columbia Civil Resolution Tribunal held Air Canada liable in negligent misrepresentation for incorrect bereavement fare information given by its website chatbot. Air Canada argued that the chatbot “was a separate legal entity that is responsible for its own actions.” The tribunal rejected that outright, holding the company responsible for all information on its website whether it came from a static page or a chatbot, and adding that a consumer cannot be expected to cross-check one part of a website against another.[7] The award was small: C$650.88 in damages plus interest and tribunal fees, roughly C$812 in total. The principle is not.
An AI channel you own can be steered into saying things, in public. DPD disabled the AI element of its customer service chatbot in January 2024 after a customer told it to disregard its rules, got it to swear, and then asked it for a poem about a chatbot that cannot do anything. The bot produced one calling itself useless and describing DPD as “a customer’s worst nightmare.” DPD’s statement: “We have operated an AI element within the chat successfully for a number of years. An error occurred after a system update yesterday. The AI element was immediately disabled and is currently being updated.”[8]
Be precise about what that shows, because both the dramatic version and the reassuring version are wrong. The customer did deliberately push it, so this was not a bot spontaneously turning on its employer. But nobody told it to name DPD, and it named DPD. And the company has never said publicly what the update actually changed. What you are left with is the bit that should concern you: a channel speaking in your name, that a determined stranger can steer, whose behaviour changed without anyone noticing until it was a screenshot. A crisis is precisely when people start pushing.
A single wrong fact in a public AI output is expensive. Google’s own promotional demo of Bard contained a factual error about which telescope took the first image of an exoplanet. Alphabet shares fell 7.7%, wiping roughly $100bn off market value.[9] That was a marketing asset with presumably several people’s eyes on it, in peacetime.
Now add the environment you are operating in. Edelman’s 2026 Trust Barometer, based on roughly 34,000 respondents across 28 countries, found that the increasing prevalence of misinformation is the second-largest shaper of trust over five years, and nearly seven in ten people fear institutional leaders are deliberately misleading the public.[10]
That last finding is the one that should decide your policy. In 2026, a hallucinated fact in a crisis statement does not get read as a mistake. It gets read as a lie. You do not get the benefit of the doubt you would have had five years ago, and you will spend the rest of the incident defending the correction rather than the original issue.
The rule I would write into your plan, in one sentence: AI can monitor, summarise, translate, draft and rehearse. No AI system speaks autonomously to customers, press or regulators during an active incident, and a named human approves every word that publishes.
Every crisis plan written before 2024 assumes the crisis originates from something your company did. There is now a category that does not.
The engineering firm Arup lost roughly $25.6m across 15 transactions after an employee in Hong Kong joined a video call populated by deepfaked versions of the CFO and colleagues. An Arup spokesperson confirmed to Fortune: “We can confirm that fake voices and images were used.” The company’s CIO, Rob Greig, went on record saying: “This is an industry, business and social issue, and I hope our experience can help raise awareness of the increasing sophistication and evolving techniques of bad actors.”[11]
This is not a one-off. The FBI’s Internet Crime Complaint Center issued a public service announcement in July 2026 warning that scammers “generate videos for real time video chats with alleged company executives, law enforcement, or other authority figures,” and noting that AI-generated videos of a senior FBI leader had been posted on social media to drive victims to a spoofed site.[12]
The World Economic Forum’s Global Cybersecurity Outlook 2026 found 94% of respondents expect AI to be the most significant driver of change in cybersecurity in the coming year, 87% identified AI-related vulnerabilities as the fastest-growing cyber risk, and CEOs now rank cyber-enabled fraud as their top concern, ahead of ransomware.[13]
So add the scenario: a convincing fake of our CEO is circulating. The response to that is a communications deliverable, not an IT one, and it needs building now:
None of this is expensive. All of it is missing from most plans I have read.
This one catches people out, and it is worth thirty seconds of your attention because the two clocks do not start at the same moment.
If you are a US public company, a material cybersecurity incident must be disclosed on Item 1.05 of Form 8-K within four business days of determining that the incident is material, not of discovering it. The determination itself must be made “without unreasonable delay.”[14]
Under UK GDPR, a reportable personal data breach must be reported to the ICO without undue delay and, where feasible, not later than 72 hours after becoming aware of it. The clock runs from awareness, not from when the breach actually happened.[15] Partial information can be filed and supplemented later.
One clock starts at determination. The other starts at awareness. Both are shorter than the internal escalation process at most companies I have worked with, where a Friday evening issue routinely reaches the right person on Monday.
Verify it is real and verify the source. Do not respond to anything you have not confirmed.
Assemble the named team. Start the AI monitoring sweep so you know what is actually circulating.
Establish the facts you can state with confidence, and write down explicitly what you do not yet know.
Decide which clocks have started and who owns each. Materiality is a human call.
Adapt the pre-approved holding statement, get a named human to approve it, publish where the audience is.
A sequence for the first hour of an incident. The clock references reflect the SEC four-business-day rule from materiality determination and the ICO 72-hour rule from becoming aware.[14][15]
Build a one-page grid alongside this: who declares an incident, who drafts, who signs off, and which clock has started. AI can pre-populate every notification template you will need. It cannot make the materiality call, and you should not want it to.
If disclosure obligations in marketing are on your list generally, our AI marketing compliance checklist covers the everyday version.
Concretely, here is what I would do with two afternoons.
Afternoon one. Generate the scenario list with AI, score it with your team, and pick the top eight. Build the message matrix for those eight across your six audiences. Edit every cell. That is 48 holding statements, which sounds enormous and takes about three hours with a tool doing the first pass.
Afternoon two. Run the AI-facilitated tabletop on the two scenarios that scored highest. Ninety minutes. Capture every question your team could not answer. Fix the top five. Send the sensitive statements to legal for sign-off while you do it.
Then put a review date in the calendar, because a crisis plan written in August and never opened again is a document, not a capability. ISO 22361:2022 is the international standard here if you want a structure to check yourself against: it covers crisis leadership, decision-making under pressure, crisis communication, and validation and learning.[6]
The honest summary is this. AI will not make you better at handling a crisis in the moment. Nothing does, except having decided most of it in advance. What AI does is make the deciding-in-advance cheap enough that you might finally do it. Given that half of businesses have no documented plan at all, and rehearsal is rarer still, that is a much bigger prize than a faster holding statement.[4][5]
For the media relationships that make all of this land, our guide on AI for public relations and media outreach covers building the contacts before you need them, and AI for brand guidelines covers keeping the voice consistent when several people are drafting under pressure.
It can adapt one you approved earlier, which is a different and much safer job. Asking AI to originate a position while facts are still moving puts fluent, confident text in front of the public at the moment your tolerance for error is lowest. In Moffatt v. Air Canada the tribunal held the company liable for incorrect information given by its own chatbot and rejected the argument that the bot was a separate legal entity.[7] Build a pre-approved message matrix in peacetime and have AI adapt from it.
Preparation, by a wide margin. Only 49% of US businesses have a documented crisis communications plan, and rehearsal is rarer still: in Deloitte’s 2018 study 84% claimed a crisis management plan, but only 17% had simulated the corporate scandal scenario they felt confident about.[4][5] AI turns scenario generation, message matrices and tabletop exercises from a fortnight of work into two afternoons. During a live incident, its strongest use is monitoring and triage: clustering hundreds of mentions into themes so your team knows what is actually spreading.
Faster than most escalation processes allow, and in public. Sprout Social found 84% of consumers say response speed directly affects their view of the crisis and 64% expect the response on social media rather than in a press release.[1] Regulatory clocks are separate: the SEC requires disclosure within four business days of determining a cyber incident is material, while the ICO requires breach reporting within 72 hours of becoming aware of it.[14][15]
Yes, and most plans written before 2024 do not. Arup lost roughly $25.6m after an employee joined a video call populated by deepfaked colleagues, and the company confirmed publicly that fake voices and images were used.[11] The FBI warned in July 2026 that criminals are generating real-time video chats impersonating company executives.[12] The comms deliverables are a pre-registered verification channel, an internal challenge protocol, a pre-drafted denial statement and primed journalist contacts.
Not autonomously. DPD disabled the AI element of its chatbot in January 2024 after a customer who had told it to disregard its rules got it to swear and to write a poem describing DPD as “a customer’s worst nightmare.” The company said only that an error had occurred after a system update.[8] During an active incident, route customer contact to humans working from approved messaging, and use AI behind the scenes to summarise inbound volume and flag the issues that are gaining traction.
This guide draws on survey research from Sprout Social, Capterra, Deloitte, PwC, Weber Shandwick, Edelman and the World Economic Forum, alongside primary sources: the SEC and ICO on disclosure timing, the FBI Internet Crime Complaint Center on deepfake fraud, ISO 22361 on crisis management, and published reporting on the Air Canada tribunal decision, the DPD chatbot incident and the Arup deepfake fraud. Widely circulated crisis statistics that could not be traced to an original study were deliberately excluded.